Zdenek Pytela
3da8da0406
* Mon Mar 09 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.75-2
...
- Rebuild with the target::exception flag
Resolves: RHEL-148247
2026-03-09 13:44:36 +01:00
Zdenek Pytela
92a689a320
* Fri Mar 06 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.75-1
...
- Allow nfsd_t domain setuid and setgid capability for rpc.mountd
Resolves: RHEL-148247
2026-03-06 14:05:58 +01:00
Zdenek Pytela
6290908257
* Mon Feb 23 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.74-1
...
- Label /run/insights-client.ppid with insights_client_run_t
Resolves: RHEL-146688
- Update gpg_role() interface with unix_stream_socket permissions
Resolves: RHEL-128542
2026-02-23 17:20:12 +01:00
Zdenek Pytela
679180708f
* Thu Jan 29 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.73-1
...
- Add the fs_write_tmpfs_files() interface
Resolves: RHEL-142141
- Dontaudit aide the execmem permission
Resolves: RHEL-121480
- Update gpg policy for interactions with rhc-playbook-verifier
Resolves: RHEL-132748
- Allow rhc_playbook_verifier_t stream connect to itself
Resolves: RHEL-132748
- Update policy for rhc-worker-playbook
Resolves: RHEL-132748
- Allow traceroute_t bind rawip sockets to unreserved ports
Resolves: RHEL-130267
- Revert "Allow traceroute_t bind rawip sockets to unreserved ports"
Related: RHEL-130267
- Allow sudodomain connect to gkeyringd over a unix stream socket
Resolves: RHEL-121158
- Allow samba-bgqd send to smbd over a unix datagram socket
Resolves: RHEL-95985
- Allow ssh_agent_type manage generic cache home files
Resolves: RHEL-121165
- Label /usr/libexec/openssh/ssh-pkcs11-helper with ssh_agent_exec_t
Resolves: RHEL-121165
- Allow boothd connect to systemd-machined over a unix socket
Resolves: RHEL-140882
2026-01-29 22:55:35 +01:00
Vit Mojzis
42110703d6
Macros: Require only "stable" version of selinux-policy
...
In special circumstances it is possible that selinux-policy used to
build a DSP package is later not available for installation.
Work around this problem by only recommending the latest policy version
and adding a fallback "Requires" to a hardcoded "stable" version. This
version should be updated when major policy changes take place.
Resolves: RHEL-141433
2026-01-27 11:53:33 +01:00
Zdenek Pytela
662b06031d
* Fri Jan 23 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.72-1
...
- Add insights_client service interfaces
Related: RHEL-140893
- Confine rhc-worker-playbook.worker and rhc-playbook-verifier
Resolves: RHEL-132748
- Allow gpg manage rpm cache
Related: RHEL-108775
- Allow gpg read rpm cache
Related: RHEL-108775
- Allow aide get attributes of tmpfs and devtmpfs filesystems
Resolves: RHEL-121480
- Allow rules for confined users logged in plasma
Resolves: RHEL-133898
- Allow login_userdomain watch lnk_files in /usr
Resolves: RHEL-133898
2026-01-23 14:52:04 +01:00
Zdenek Pytela
bbde26dd4b
* Mon Jan 12 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.71-1
...
- Revert "Allow NM nvme dispatcher script start systemd services"
Resolves: RHEL-111946
- Allow ssh_agent_type create a sockfile in /run/user/USERID
Resolves: RHEL-121936
- Allow NM nvme dispatcher script start systemd services
Resolves: RHEL-111946
- Allow aide get attributes of a filesystem with extended attributes
Resolves: RHEL-121480
- Label miscellaneous /dev/papr-* devices
Resolves: RHEL-129879
2026-01-12 17:41:10 +01:00
Zdenek Pytela
d14300c899
* Fri Dec 12 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.70-1
...
- Add the rpm_signal() interface
Related: RHEL-108826
- Allow tuned_t use its private tmpfs files
Related: RHEL-108826
- Allow kdump search kdumpctl_tmp_t directories
Resolves: RHEL-66119
2025-12-12 13:54:45 +01:00
Zdenek Pytela
56f29d6f02
* Fri Nov 28 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.69-1
...
- Allow sysadm access to TPM
Resolves: RHEL-119055
- Update policy for dhcpc_hook_t
Resolves: RHEL-113941
- Allow stap server read virtual memory sysctls
Resolves: RHEL-114157
- Allow login_userdomain watch /home and /var directories
Resolves: RHEL-119686
- Allow login_userdomain read lastlog
Resolves: RHEL-119686
- Allow staff role read/write cockpit-session unix stream sockets
Resolves: RHEL-108068
- Label /usr/libexec/dhcpcd-run-hooks with dhcpc_hook_exec_t
Resolves: RHEL-113941
2025-11-28 17:52:17 +01:00
Zdenek Pytela
983611f594
* Fri Nov 14 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.68-1
...
- Allow insights-client manage /etc symlinks
Resolves: RHEL-108826
- Allow insights-client get attributes of the rpm executable
Resolves: RHEL-127329
- Allow ras-mc-ctl get attributes of the kmod executable
Resolves: RHEL-103975
- Fix files_delete_boot_symlinks() to contain delete_lnk_files_pattern
Resolves: RHEL-101155
- Allow bootupd delete symlinks in the /boot directory
Resolves: RHEL-101155
- Update policy for bootupd
Resolves: RHEL-101155
- Allow create kerberos files in postgresql db home
Resolves: RHEL-123225
2025-11-14 11:34:08 +01:00
Zdenek Pytela
e038978281
Disable the epel repository temporarily at the system is build time
2025-10-17 16:06:26 +02:00
Zdenek Pytela
3065afefae
* Tue Oct 14 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.67-1
...
- Allow login_userdomain dbus chat with tuned-ppd
Resolves: RHEL-113906
- selinux-policy: add allow rule for tuned_ppd_t
Resolves: RHEL-113906
- Add ppd_base_profile to file transition to get tuned_rw_etc_t type
Resolves: RHEL-113906
- Allow tuned-ppd manage tuned log files
Resolves: RHEL-113906
- Allow tuned-ppd connect to sssd over a unix stream socket
Resolves: RHEL-113906
- Allow tuned-ppd create ppd_base_profile with a file transition
Resolves: RHEL-113906
- Allow init create and use vsock socket
Resolves: RHEL-113647
- Add Valkey rules to Redis module
Resolves: RHEL-108982
- Allow ras-mc-ctl write to sysfs files
Resolves: RHEL-103975
- Allow kdump search kdumpctl_tmp_t directories
Resolves: RHEL-66119
2025-10-14 18:57:50 +02:00
Zdenek Pytela
658757d2e5
* Fri Sep 19 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.66-1
...
- Reapply "Add insights_core interfaces"
Resolves: RHEL-112367
- Reapply "Add policy for insights-core"
Resolves: RHEL-112367
2025-09-19 14:12:23 +02:00
Zdenek Pytela
cddb1b4173
* Thu Aug 21 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.65-1
...
- Revert "Add policy for insights-core"
Resolves: RHEL-110650
- Revert "Add insights_core interfaces"
Resolves: RHEL-110650
2025-08-21 20:11:18 +02:00
Zdenek Pytela
6e716e8c7f
* Tue Aug 12 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.64-1
...
- Add insights_core and insights_client interfaces
Related: RHEL-59145
- Label /usr/libexec/postfix/tlsproxy with postfix_smtp_exec_t
Resolves: RHEL-77101
- Remove "minimum" as a SELINUXTYPE from /etc/selinux/config
Resolves: RHEL-101140
2025-08-12 14:18:55 +02:00
Zdenek Pytela
c81ce1ec7a
* Wed Jul 30 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.63-1
...
- Allow samba-dcerpcd send sigkills to passwd
Resolves: RHEL-100032
- Allow power-profiles-daemon watch sysfs directories
Resolves: RHEL-100718
- Allow power-profiles-daemon write sysfs files
Resolves: RHEL-100718
- Allow hostapd write to socket files in /tmp
Resolves: RHEL-59683
- Allow irqbalance search sssd lib directories
Resolves: RHEL-1556
- Add insights_client_delete_lib_dirs() interface
Related: RHEL-59145
2025-07-30 17:33:34 +02:00
Zdenek Pytela
dd9a8d890f
* Fri Jul 18 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.62-1
...
- Allow "hostapd_cli ping" run as a systemd service
Resolves: RHEL-59683
- Allow systemd-timedated start/stop timemaster services
Resolves: RHEL-95690
- Allow lldpd connect to systemd-machined over a unix socket
Resolves: RHEL-96167
- Allow power-profiles-daemon get attributes of filesystems with extended attributes
Resolves: RHEL-100718
- Allow tuned-ppd watch_reads sysfs directories
Resolves: RHEL-101687
- Allow tuned-ppd watch sysfs directories
Resolves: RHEL-101687
2025-07-18 12:12:57 +02:00
Zdenek Pytela
f9fa6984ee
* Mon Jul 14 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.61-1
...
- Fix incorrect /run and /usr/bin file context entries
Resolves: SELINUX-4392
- Dontaudit irqbalance read sssd public files
Resolves: RHEL-1556
- Update sssd_dontaudit_read_public_files()
Resolves: RHEL-1556
- Allow insights-client file transition for files in /var/tmp
Resolves: SELINUX-4392
- Add the virt_exec_virsh() interface
Resolves: SELINUX-4392
- Add the ssh_exec_sshd() interface
Resolves: SELINUX-4392
- Add rhsmcertd interfaces
Resolves: SELINUX-4392
- Add the bind_exec_named_checkconf() interface
Resolves: SELINUX-4392
- Add the auth_write_motd_var_run_files() interface
Resolves: SELINUX-4392
- Add the gpg_domtrans_agent() interface
Resolves: SELINUX-4392
- Add the gpg_read_user_secrets() interface
Resolves: SELINUX-4392
- Add policy for insights-core
Resolves: SELINUX-4392
2025-07-14 13:46:45 +02:00
Zdenek Pytela
3c140941f4
* Thu Jul 03 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.60-1
...
- Allow irqbalance execute shell if irqbalance_run_unconfined is on
Resolves: RHEL-1556
- Update irqbalance policy for using unconfined scripts
Resolves: RHEL-1556
2025-07-03 13:01:41 +02:00
Zdenek Pytela
df59df50d8
* Tue Jul 01 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.59-1
...
- virt: allow QEMU use of the qgs daemon for attestation
Resolves: RHEL-87744
- qgs: add contrib module for TDX "qgs" daemon
Resolves: RHEL-87744
- kernel: add interfaces for using SGX enclaves
Resolves: RHEL-87744
- Allow coreos-installer search sssd library directory
Resolves: RHEL-95689
- Label /dev/diag as diagnostic_device_t
Resolves: RHEL-95342
- Allow irqbalance execute shell if irqbalance_run_unconfined is on
Resolves: RHEL-1556
2025-07-01 21:35:27 +02:00
Zdenek Pytela
c2458cfb92
* Mon Jun 09 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.58-1
...
- Allow mptcpd the net_admin capability
Resolves: RHEL-81729
- Allow networkmanager send a general signal to iptables
Resolves: RHEL-93741
- Make bootupd use bootupd_tmp_t as its private type for files in /tmp
Resolves: RHEL-94508
- Update bootupd policy
Resolves: RHEL-94508
- Allow switcheroo-control dbus chat with xdm
Resolves: RHEL-93335
- Update the files_search_mnt() interface
Resolves: RHEL-94184
2025-06-09 17:27:48 +02:00
Zdenek Pytela
d12a3cf84e
* Thu May 29 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.57-1
...
- Update policy for haproxyd
Resolves: RHEL-88045
- Allow NetworkManager manage NetworkManager_etc_rw_t symlinks
Resolves: RHEL-86178
- Allow lldpad connect to systemd-userdbd over a unix socket
Resolves: RHEL-84046
- Allow gconfd connect to system dbus
Resolves: RHEL-77984
- Allow login_pgm read filesystem sysctls
Resolves: RHEL-77745
- Allow login_userdomain create /run/tlog directory with user_tmp_t
Resolves: RHEL-47241
2025-05-29 17:34:44 +02:00
Zdenek Pytela
78047d2717
* Tue May 06 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.56-1
...
- Remove 3 permissive domains
Resolves: RHEL-82674
- Allow tuned-ppd dbus chat with xdm
Resolves: RHEL-87203
- Allow system-dbusd list systemd-machined directories
Resolves: RHEL-85379
- Allow NetworkManager create and use icmp_socket
Resolves: RHEL-83529
- Allow journalctl connect to systemd-userdbd over a unix socket
Resolves: RHEL-82673
- allow gdm and iiosensorproxy talk to each other via D-bus
Resolves: RHEL-80697
- Allow varnishd execute the prlimit64() syscall
Resolves: RHEL-77995
- Allow system_dbusd_t r/w unix stream sockets of unconfined_service_t
Resolves: RHEL-61928
- Add the getattr permission to 2 dontaudit interfaces
Resolves: RHEL-59145
2025-05-06 13:41:19 +02:00
Vit Mojzis
b89cd0cff3
automotive: Deny unknown classes/permissions
...
Set deny_unknown to "deny" in the automotive policy (the policy treats
all queries on undefined object classes or permissions as being denied).
Resolves: RHEL-86827
2025-04-14 21:48:27 +02:00
Zdenek Pytela
8430de8220
* Fri Apr 11 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.55-1
...
- Allow tuned-ppd read sssd public files
Resolves: RHEL-69526
- Allow systemd-journal-upload read init pid files
Resolves: RHEL-62196
- Label SetroubleshootPrivileged.py with setroubleshootd_exec_t
Resolves: RHEL-77319
- Allow chronyd-restricted sendto to chronyc
Resolves: RHEL-82308
- Allow chronyc sendto to chronyd-restricted
Resolves: RHEL-82308
2025-04-11 15:16:25 +02:00
Zdenek Pytela
2ec69036cd
* Mon Mar 31 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.54-1
...
- Confine tuned-ppd
Resolves: RHEL-69526
- Make tuned work with mls policy
Resolves: RHEL-69526
- Allow afterburn to mount and read config drives
Resolves: RHEL-79319
2025-03-31 17:52:52 +02:00
Zdenek Pytela
b26904931e
* Fri Mar 14 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.53-4
...
- Allow afterburn to mount and read config drives
Resolves: RHEL-82276
2025-03-14 19:01:37 +01:00
Vit Mojzis
d094438fe9
automotive: remove dependency on policycoreutils-python-utils
...
Since selinux-policy-automotive does not use the triggerpostun scriptlet
that targeted/mls/minimum use, there is no need for
policycoreutils-python-utils (only semodule, restorecon and load_policy
are used, all of which is provided by policycoreutils).
Resolves: RHEL-82883
2025-03-10 14:43:18 +01:00
Vit Mojzis
bbd06ec607
Add selinux-policy-automotive sub-package
...
The package is modeled after selinux-policy-minimum in that it contains
all the modules that are present in selinux-policy-targeted, but most of
them are disabled (content of module-automotive-contrib.conf).
The rest of the configuration files is copied from targeted, only
booleans-automotive.conf and users-automotive are missing booleans and
users defined in disabled modules.
Resolves: RHEL-69666
2025-02-17 10:54:59 +01:00
Zdenek Pytela
b7b5e03b7e
* Fri Feb 07 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.53-1
...
- Allow svirt_t to connect to nbdkit over a unix stream socket
Resolves: RHEL-56029
- Allow power-profiles-daemon the bpf capability
Resolves: RHEL-61117
- Allow systemd-machined the kill user-namespace capability
Resolves: RHEL-76352
2025-02-07 17:43:02 +01:00
Zdenek Pytela
bbd11ae656
* Fri Jan 31 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.52-1
...
- Add the files_read_root_files() interface
Resolves: RHEL-70849
- Dontaudit systemd-logind remove all files
Resolves: RHEL-59145
- Add the files_dontaudit_read_all_dirs() interface
Resolves: RHEL-59145
- Add the files_dontaudit_delete_all_files() interface
Resolves: RHEL-59145
- Allow rhsmcertd notify virt-who
Resolves: RHEL-77152
- Allow irqbalance to run unconfined scripts conditionally
Resolves: RHEL-1556
- Backport bootupd policy from current Fedora rawhide
Resolves: RHEL-70849
- Support using systemd containers
Resolves: RHEL-76352
- Allow svirt_t connect to unconfined_t over a unix domain socket
Resolves: RHEL-37539
- Allow virt_domain to use pulseaudio - conditional
Resolves: RHEL-1379
- Allow telnetd read network sysctls
Resolves: RHEL-58825
- Allow alsa watch generic device directories
Resolves: RHEL-61472
- Update switcheroo policy
Resolves: RHEL-24268
2025-02-01 00:21:27 +01:00
Zdenek Pytela
adb3a2ba50
* Wed Jan 15 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.51-1
...
- Allow rsyslog read systemd-logind session files
Resolves: RHEL-73839
- Allow samba-bgqd connect to cupsd over an unix domain stream socket
Resolves: RHEL-72860
- Allow svirt_t read sysfs files
Resolves: RHEL-70839
- Allow xdm dbus chat with power-profiles-daemon
Resolves: RHEL-61117
- Update power-profiles-daemon policy
Resolves: RHEL-61117
- Confine power-profiles-daemon
Resolves: RHEL-61117
- Allow virtqemud domain transition to nbdkit
Resolves: RHEL-56029
- Add nbdkit interfaces defined conditionally
Resolves: RHEL-56029
- Confine the switcheroo-control service
Resolves: RHEL-24268
2025-01-15 18:34:17 +01:00
Zdenek Pytela
ac1613aab5
Add powerprofiles and switcheroo modules
...
Resolves: RHEL-24268
2025-01-15 18:29:54 +01:00
Zdenek Pytela
9484341286
* Fri Dec 13 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.50-1
...
- Allow auditctl signal auditd
Resolves: RHEL-68969
- Fix the cups_read_pid_files() interface to use read_files_pattern
Resolves: RHEL-69517
- Dontaudit systemd-coredump the sys_resource capability
Resolves: RHEL-46339
- Allow rpcd read network sysctls
Resolves: RHEL-1558
- Allow irqbalance setpcap capability in the user namespace
Resolves: RHEL-69564
- Allow traceroute_t bind rawip sockets to unreserved ports
Resolves: RHEL-54561
- Allow svirt_t the sys_rawio capability
Resolves: RHEL-56955
- Change /run/sysctl\.d(/.*)? fc entry to /var/run/sysctl\.d(/.*)?
Resolves: RHEL-56988
- Exclude container-selinux manpage from selinux-policy-doc
Resolves: RHEL-69916
2024-12-13 15:45:13 +01:00
Zdenek Pytela
655176404c
Exclude container-selinux manpage from selinux-policy-doc
...
The container_selinux.8 manpage is a part of the upstream
container-selinux package and it should rather be a part
of container-selinux.
Resolves: RHEL-69916
2024-12-13 14:47:24 +01:00
Zdenek Pytela
93f4aed9d6
* Fri Dec 06 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.49-1
...
- Update virtlogd policy
Resolves: RHEL-69433
- Allow svirt_t the sys_rawio capability
Resolves: RHEL-56955
- Allow qemu-ga the dac_override and dac_read_search capabilities
Resolves: RHEL-52476
- Allow ip the setexec permission
Resolves: RHEL-62923
- Allow alsa get attributes filesystems with extended attributes
Resolves: RHEL-61472
- Allow bacula execute container in the container domain
Resolves: RHEL-21168
- Allow httpd get attributes of dirsrv unit files
Resolves: RHEL-46808
- Update samba-bgqd policy
Resolves: RHEL-69517
- Allow samba-bgqd read cups config files
Resolves: RHEL-69517
- Update policy for samba-bgqd
Resolves: RHEL-69517
- Update bootupd policy for the removing-state-file test
Resolves: RHEL-66584
- Allow qatlib search the content of the kernel debugging filesystem
Resolves: RHEL-53864
- Allow qatlib connect to systemd-machined over a unix socket
Resolves: RHEL-53864
- Update qatlib policy for v24.02 with new features
Resolves: RHEL-53864
2024-12-06 17:19:42 +00:00
Milos Malik
29816f1443
try to enable CRB and EPEL repositories
...
Try to enable the following repositories:
* EPEL
* CRB
Do not fail when something goes wrong.
2024-12-03 15:51:58 +01:00
Zdenek Pytela
ea341191c4
* Tue Nov 12 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.48-1
...
- Revert "Allow unconfined_t execute kmod in the kmod domain"
Resolves: RHEL-65008
- Add policy for /usr/libexec/samba/samba-bgqd
Resolves: RHEL-53124
2024-11-12 17:57:29 +01:00
Zdenek Pytela
a79b0f387d
* Wed Oct 23 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.47-1
...
- Label /etc/sysctl.d and /run/sysctl.d with system_conf_t
Resolves: RHEL-56988
- Allow lldpad create and use netlink_generic_socket
Resolves: RHEL-61832
- Allow unconfined_t execute kmod in the kmod domain
Resolves: RHEL-54710
- Allow confined users r/w to screen unix stream socket
Resolves: RHEL-50379
- Label /root/.screenrc and /root/.tmux.conf with screen_home_t
Resolves: RHEL-50375
- Allow iio-sensor-proxy the bpf capability
Resolves: RHEL-17346
2024-10-23 13:11:34 +02:00
Zdenek Pytela
b21b210b94
* Fri Oct 11 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.46-1
...
- Rebuild
2024-10-11 15:33:47 +02:00
Zdenek Pytela
93538d0a93
* Thu Oct 10 2024 Zdenek Pytela <zpytela@redhat.com> - 35.1.46-1
...
- Label /run/modprobe.d with modules_conf_t
Resolves: RHEL-61453
- Allow boothd connect to kernel over a unix socket
Resolves: RHEL-57104
- Allow boothd connect to systemd-userdbd over a unix socket
Resolves: RHEL-57104
- Additional updates stalld policy for bpf usage
Resolves: RHEL-57075
- Update stalld policy for bpf usage
Resolves: RHEL-57075
- Allow ptp4l the sys_admin capability
Resolves: RHEL-55133
- Label /dev/hfi1_[0-9]+ devices
Resolves: RHEL-54996
- Confine iio-sensor-proxy
Resolves: RHEL-17346
2024-10-10 21:54:48 +02:00
Zdenek Pytela
6d48c6e32c
* Mon Sep 16 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.45-3
...
- Rebuild
Resolves: RHEL-55414
2024-09-16 17:29:25 +02:00
Zdenek Pytela
5273cf04c1
* Wed Sep 04 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.45-2
...
- Rebuild
Resolves: RHEL-55414
2024-09-04 12:11:27 +02:00
Zdenek Pytela
6b28f7d202
* Thu Aug 29 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.45-1
...
- Allow setsebool_t relabel selinux data files
Resolves: RHEL-55414
2024-08-29 14:28:06 +02:00
Zdenek Pytela
c72977faea
* Mon Aug 12 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.44-1
...
- Allow coreos-installer-generator work with partitions
Resolves: RHEL-38614
- Label /etc/mdadm.conf.d with mdadm_conf_t
Resolves: RHEL-38614
- Change file context specification to /var/run/metadata
Resolves: RHEL-49735
- Allow initrc_t transition to passwd_t
Resolves: RHEL-17404
- systemd: allow systemd_notify_t to send data to kernel_t datagram sockets
Resolves: RHEL-25514
- systemd: allow sys_admin capability for systemd_notify_t
Resolves: RHEL-25514
- Change systemd-network-generator transition to include class file
Resolves: RHEL-47033
- Allow sshd_keygen_t connect to userdbd over a unix stream socket
Resolves: RHEL-47033
2024-08-12 22:55:56 +02:00
Zdenek Pytela
a922a23d90
* Wed Jul 31 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.43-1
...
- Allow rhsmcertd read/write access to /dev/papr-sysparm
Resolves: RHEL-49599
- Label /dev/papr-sysparm and /dev/papr-vpd
Resolves: RHEL-49599
- Allow rhsmcertd read, write, and map ica tmpfs files
Resolves: RHEL-50926
- Update afterburn file transition policy
Resolves: RHEL-49735
- Label /run/metadata with afterburn_runtime_t
Resolves: RHEL-49735
- Allow afterburn list ssh home directory
Resolves: RHEL-49735
- Support SGX devices
Resolves: RHEL-50922
- Allow systemd-pstore send a message to syslogd over a unix domain
Resolves: RHEL-45528
- Allow postfix_domain map postfix_etc_t files
Resolves: RHEL-46332
- Allow microcode create /sys/devices/system/cpu/microcode/reload
Resolves: RHEL-26821
- Allow svirt_tcg_t map svirt_image_t files
Resolves: RHEL-27141
- Allow systemd-hostnamed shut down nscd
Resolves: RHEL-45033
- Allow postfix_domain connect to postgresql over a unix socket
Resolves: RHEL-6776
2024-07-31 18:07:13 +02:00
Zdenek Pytela
2271084e56
* Thu Jul 18 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.42-1
...
- Label samba certificates with samba_cert_t
Resolves: RHEL-25724
- Allow systemd-coredumpd the sys_chroot capability
Resolves: RHEL-45245
- Allow svirt_tcg_t read vm sysctls
Resolves: RHEL-27141
- Label /usr/sbin/samba-gpupdate with samba_gpupdate_exec_t
Resolves: RHEL-25724
- Label /var/run/coreos-installer-reboot with coreos_installer_var_run_t
Resolves: RHEL-38614
- Allow coreos-installer add systemd unit file links
Resolves: RHEL-38614
2024-07-18 13:52:06 +02:00
Zdenek Pytela
c74c6d2868
* Sun Jul 07 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.41-1
...
- Differentiate between staff and sysadm when executing crontab with sudo
Resolves: RHEL-31888
- Label /usr/bin/samba-gpupdate with samba_gpupdate_exec_t
Resolves: RHEL-25724
- Allow unconfined_service_t transition to passwd_t
Resolves: RHEL-17404
- Allow sbd to trace processes in user namespace
Resolves: RHEL-44680
- Allow systemd-coredumpd sys_admin and sys_resource capabilities
Resolves: RHEL-45245
- Label /usr/lib/node_modules/npm/bin with bin_t
Resolves: RHEL-36587
- Support /var is empty
Resolves: RHEL-29331
- Allow timemaster write to sysfs files
Resolves: RHEL-28777
- Don't audit crontab_domain write attempts to user home
Resolves: RHEL-31888
- Transition from sudodomains to crontab_t when executing crontab_exec_t
Resolves: RHEL-31888
- Fix label of pseudoterminals created from sudodomain
Resolves: RHEL-31888
2024-07-07 22:17:56 +02:00
Zdenek Pytela
9ff33f15d5
* Tue Jun 18 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.40-1
...
- Allow systemd-coredump read nsfs files
Resolves: RHEL-39937
- Allow login_userdomain execute systemd-tmpfiles in the caller domain
Resolves: RHEL-40374
- Allow ptp4l_t request that the kernel load a kernel module
Resolves: RHEL-38905
- Allow collectd to trace processes in user namespace
Resolves: RHEL-36293
2024-06-18 22:32:39 +02:00
Zdenek Pytela
89ceaca299
* Thu Jun 06 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.39-1
...
- Add interfaces for watching and reading ifconfig_var_run_t
Resolves: RHEL-39408
- Allow dhcpcd use unix_stream_socket
Resolves: RHEL-39408
- Allow dhcpc read /run/netns files
Resolves: RHEL-39408
- Allow all domains read and write z90crypt device
Resolves: RHEL-38833
- Allow bootupd search efivarfs dirs
Resolves: RHEL-36289
- Move unconfined_domain(sap_unconfined_t) to an optional block
Resolves: RHEL-37663
2024-06-06 23:54:31 +02:00