Commit Graph

6226 Commits

Author SHA1 Message Date
Zdenek Pytela
767de9739d * Fri Jul 18 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.3-1
- Allow svirt read virtqemud fifo files
Resolves: RHEL-104069
- Allow virtqemud handle virt_content_t chr files
Resolves: RHEL-76104
- Allow "hostapd_cli ping" run as a systemd service
Resolves: RHEL-77047
- All sblim-sfcbd the dac_read_search capability
Resolves: RHEL-98287
- Allow sblim domain read systemd session files
Resolves: RHEL-98287
- Allow sblim-sfcbd execute dnsdomainname
Resolves: RHEL-98287
- Allow systemd-importd create and unlink init pid socket
Resolves: RHEL-98490
2025-07-18 19:29:08 +02:00
Zdenek Pytela
831808b791 * Wed Jul 16 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.2-1
- Remove permissive domains
Resolves: RHEL-103661
- Adjust modules list
Resolves: RHEL-103661
2025-07-16 17:05:53 +02:00
Zdenek Pytela
3c58b106cf * Mon Jul 14 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.1-1
- Rebase selinux-policy to the newest one available in Fedora 42
Resolves: RHEL-54303
2025-07-14 17:07:34 +02:00
Zdenek Pytela
5f13f86c60 * Wed Jul 02 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.35-1
- Remove duplicate summary header
Related: RHEL-87742
- Allow irqbalance execute shell if irqbalance_run_unconfined is on
Resolves: RHEL-54019
- virt: allow QEMU use of the qgs daemon for attestation
Resolves: RHEL-87742
- qgs: add contrib module for TDX "qgs" daemon
Resolves: RHEL-87742
- kernel: add interfaces for using SGX enclaves
Resolves: RHEL-87742
2025-07-02 16:34:29 +02:00
Zdenek Pytela
a43247ed31 * Tue Jul 01 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.34-1
- Allow systemd-coredump the sys_admin capability
Resolves: RHEL-97586
- Dontaudit systemd-coredump the sys_resource capability
Resolves: RHEL-97586
- Allow systemd-coredumpd sys_admin and sys_resource capabilities
Resolves: RHEL-97586
- Allow systemd-coredump read nsfs files
Resolves: RHEL-97586
- Dontaudit systemd-coredump sys_admin capability
Resolves: RHEL-97586
- Allow svirt-tcg read init state
Resolves: RHEL-95725
- Allow virtqemud create and unlink files in /etc/libvirt/
Resolves: RHEL-95725
- Allow virtqemud send a generic signal to passt
Resolves: RHEL-44994
- Allow openvswitch ioctl vduse devices
Resolves: RHEL-93041
- Label /dev/vduse/control and /dev/vduse/NAME devices
Resolves: RHEL-93041
- Allow virtstoraged the sys_rawio capability
Resolves: RHEL-44639
- Allow virtstoraged fsetid capability
Resolves: RHEL-44639
- Allow virtqemud additional permissions on scsi generic chr files
Resolves: RHEL-44628
- Allow irqbalance execute shell if irqbalance_run_unconfined is on
Resolves: RHEL-54019
- Fix files_dontaudit_delete_all_files()
Resolves: RHEL-86789
- Allow virtnodedev create mdevctl config dirs
Resolves: RHEL-98559
- Allow cryptsetup-generator manage systemd unit files
Resolves: RHEL-98656
2025-07-01 17:04:08 +02:00
Zdenek Pytela
1ba9a90255 * Fri Jun 06 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.33-1
- Allow systemd_generator read files in /proc and /sys
Resolves: RHEL-36740
- Update irqbalance policy for using unconfined scripts
Resolves: RHEL-54019
- Allow utempter use terminal multiplexor
Resolves: RHEL-56344
- Allow virtqemud execute ovs-vsctl with a domain transition
Resolves: RHEL-65322
- Allow mptcpd the net_admin capability
Resolves: RHEL-70730
- Allow tomcat execute cracklib-check with a domain transition
Resolves: RHEL-82090
- Update the files_search_mnt() interface
Resolves: RHEL-85178
- Allow key.dns_resolve set attributes on the kernel key ring
Resolves: RHEL-91602
- Allow switcheroo-control dbus chat with xdm
Resolves: RHEL-93535
- Revert "Allow virt_domain write to virt_image_t files"
Resolves: RHEL-93773
2025-06-06 10:19:29 +02:00
Zdenek Pytela
fd51330eda * Thu May 29 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.32-1
- Backport policy for additional systemd generators from rawhide
Resolves: RHEL-36740
- Allow login_userdomain create /run/tlog directory with user_tmp_t
Resolves: RHEL-56344
- Backport bootupd policy from current Fedora rawhide
Resolves: RHEL-86588
2025-05-30 15:15:52 +02:00
Petr Lautrbach
c69e93c91c Revert "Add selinux-policy-epel test plan"
This reverts commit 94ea41534e.

selinux-policy-epel will be obsoleted when
redhat/centos-stream/rpms/selinux-policy!197
is merged and RHEL-89587 is resolved

Related: RHEL-89587
2025-05-21 10:03:23 +02:00
Petr Lautrbach
dbae004177 Revert "Make make-rhat-patches.sh selinux-policy-epel aware"
This reverts commit 61db7c0bba.

selinux-policy-epel will be obsoleted when
https://gitlab.com/redhat/centos-stream/rpms/selinux-policy/-/merge_requests/197
is merged and RHEL-89587 is resolved

Related: RHEL-89587
2025-05-21 10:03:23 +02:00
Petr Lautrbach
8dea43b936 Build selinux-policy-extra
In 40.13.26-1 modules related to EPEL repository were filtered out and
shipped in selinux-policy-epel in EPEL repository. But it was not
possible to let epel-release to automatically install
selinux-policy-epel when it was enabled.

With this change:
- EPEL related modules are build in repository again
- selinux-policy-extra is introduced to require -targeted-extra or
  -mls-extra when -targeted or -mls are installed
- some modules which are related to 3rd party and which are already
  dropped in selinux-policy-epel are filtered out completely

Resolves: RHEL-89587
2025-05-21 10:03:16 +02:00
Zdenek Pytela
7010f47ab1 * Tue May 20 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.31-1
- Label /dev/diag as diagnostic_device_t
Resolves: RHEL-89804
- Label SetroubleshootPrivileged.py with setroubleshootd_exec_t
Resolves: RHEL-87727
- Allow syslogd watch syslog_conf_t directories
Resolves: RHEL-87648
- Allow networkmanager send a general signal to iptables
Resolves: RHEL-86780
- Define file equivalency for /var/etc
Resolves: RHEL-86678
- Update bootupd policy when ESP is not mounted
Resolves: RHEL-86588
- dontaudit execmem for modemmanager
Resolves: RHEL-86176
- Allow systemd create journal pid files
Resolves: RHEL-72692
- Allow virtqemud read/write/setattr input event devices
Resolves: RHEL-46385
2025-05-20 15:22:39 +02:00
Zdenek Pytela
399d79b252 * Mon Apr 28 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.30-1
- Allow auditctl signal auditd
Resolves: RHEL-87418
- Update bootupd policy for the removing-state-file test
Resolves: RHEL-87372
- Allow systemd-user-runtime-dir get/set tmpfs quotas
Resolves: RHEL-86789
- Allow systemd-user-runtime-dir delete gnome homedir content
Resolves: RHEL-86789
- Confine /usr/lib/systemd/systemd-user-runtime-dir
Resolves: RHEL-86789
- Allow system-dbusd list systemd-machined directories
Resolves: RHEL-86528
- Allow NetworkManager create and use icmp_socket
Resolves: RHEL-86258
- Allow tuned-ppd dbus chat with xdm
Resolves: RHEL-85849
- Allow virt_domain write to virt_image_t files
Resolves: RHEL-85319
- Allow rhsmcertd connect to systemd-machined
Resolves: RHEL-83925
- Allow varnishd execute the prlimit64() syscall
Resolves: RHEL-77779
- Allow systemd-machined the kill user-namespace capability
Resolves: RHEL-77087
- Allow system_dbusd_t r/w unix stream sockets of unconfined_service_t
Resolves: RHEL-62185
- Allow tlshd read network sysctls
Resolves: RHEL-74424
2025-04-28 17:13:57 +02:00
Zdenek Pytela
04dfd0db74 * Tue Apr 15 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.29-1
- Revert "Dontaudit access of virt-related permissive domains"
Resolves: RHEL-79833
- Remove permissive domains
Resolves: RHEL-82672
2025-04-15 14:08:02 +02:00
Petr Lautrbach
94ea41534e Add selinux-policy-epel test plan
- should be triggered only in CI by commit
- should check current selinux-policy version and latest
  selinux-policy-epel version and fail if they're different to notify
  maintainer about needed action

Related: RHEL-74424
2025-04-11 07:44:41 +02:00
Petr Lautrbach
61db7c0bba Make make-rhat-patches.sh selinux-policy-epel aware
In case of change commit id it will warn user to update
also selinux-policy-epel.spec

Adds the following script output:

WARNING: selinux-policy-epel needs to be updated to use 56617809a873ce441278ef56a5b7e92c3c2cb56d:

    cd <selinux-policy-epel directory>
    fedpkg switch-brach epel10
    fedpkg new-sources /home/plautrba/devel/centos/rpms/selinux-policy/make-rhat-patches-epel/selinux-policy-5661780.tar.gz container-selinux.tgz
    git apply /home/plautrba/devel/centos/rpms/selinux-policy/make-rhat-patches-epel/selinux-policy-epel-5661780.patch

Related: RHEL-74424
2025-04-11 07:44:41 +02:00
Zdenek Pytela
30a191682d * Tue Apr 08 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.28-1
- Change path of tuned and tuned-ppd to /usr/sbin
Resolves: RHEL-69450
- Update the pcmsensor policy
Resolves: RHEL-80452
- Allow dovecot-deliver read mail aliases
Resolves: RHEL-80153
- Allow boothd connect to systemd-machined over a unix socket
Resolves: RHEL-75471
- Allow chronyd-restricted sendto to chronyc
Resolves: RHEL-82299
- Allow chronyc sendto to chronyd-restricted
Resolves: RHEL-82299
- Allow cifs.idmap helper to set attributes on kernel keys
Resolves: RHEL-83921
- Remove ktls from modules-filtered.lst
Resolves: RHEL-74424
2025-04-08 18:37:43 +02:00
Zdenek Pytela
fab9313c6d Remove ktls from modules-filtered.lst
The module was added to RHEL 10 during RHEL 10.1 development phase.

Resolves: RHEL-74424
2025-04-08 18:33:03 +02:00
Zdenek Pytela
b148e340be * Mon Mar 31 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.27-1
- Allow afterburn to mount and read config drives
Resolves: RHEL-82120
- Update afterburn file transition policy
Resolves: RHEL-82120
- Label /run/metadata with afterburn_runtime_t
Resolves: RHEL-82120
- Allow afterburn list ssh home directory
Resolves: RHEL-82120
- Confine tuned-ppd
Resolves: RHEL-69450
- Update ktls policy
Resolves: RHEL-74424
- Add the switcheroo module
Resolves: RHEL-83267
- Update switcheroo policy
Resolves: RHEL-83267
- Confine the switcheroo-control service
Resolves: RHEL-83267
2025-03-31 16:20:52 +02:00
Zdenek Pytela
09fc1276e0 * Mon Feb 17 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.26-1
- Rename winbind_rpcd_* types to samba_dcerpcd_*
Resolves: RHEL-14759
- Allow samba-dcerpcd work with ctdb cluster
Resolves: RHEL-14759
- Revert "Remove socket from unconfined_domain_type allow rule"
Resolves: RHEL-77327
- Dontaudit access of virt-related permissive domains
Resolves: RHEL-77808
- Add selinux_requires_min macro
Resolves: RHEL-54715
- Filter out EPEL related modules
Resolves: RHEL-73505
2025-02-17 15:35:52 +01:00
Vit Mojzis
17418f272b Add selinux_requires_min macro
DSP adopters who don't set any booleans should not require
policycoreutils-python-utils.
In order not to break established packages that use the selinux_requires
macro, a new one is introduced (can be adopted over time).

Also drop policycoreutils-python, since that is only relevant for
RHEL-7 and older.

Resolves: RHEL-54715
2025-02-17 14:29:07 +01:00
Petr Lautrbach
0ebb49f063 Filter out EPEL related modules
Resolves: RHEL-73505
2025-02-07 17:20:00 +01:00
Zdenek Pytela
1f5673f9d0 * Thu Feb 06 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.25-1
- Update ktlshd policy to read /proc/keys and domain keyrings
Resolves: RHEL-42672
- Allow pcmsensor read nmi_watchdog state information
Resolves: RHEL-52838
- Support peer-to-peer migration of vms using ssh
Resolves: RHEL-77351
- Allow virt_domain read hardware state information unconditionally
Resolves: RHEL-71270
- Allow timemaster write to sysfs files
Resolves: RHEL-44637
- Allow virtqemud map svirt_image_t plain files
Resolves: RHEL-40080
- Allow virtqemud unmount a filesystem with extended attributes
Resolves: RHEL-40080
- Allow virtqemud work with nvdimm devices
Resolves: RHEL-71656
- Update virtqemud policy regarding the svirt_tcg_t domain
Resolves: RHEL-71270
- Allow virtqemud use hostdev usb devices conditionally
Resolves: RHEL-74230
- Support saving and restoring a VM to/from a block device
Resolves: RHEL-76138
- Allow virtnwfilterd dbus chat with firewalld
Resolves: RHEL-76138
- Allow virt_domain to use pulseaudio - conditional
Resolves: RHEL-62763
- Allow virtstoraged write to sysfs files
Resolves: RHEL-44637
- Allow irqbalance to run unconfined scripts conditionally
Resolves: RHEL-54019
- Allow rhsmcertd notify virt-who
Resolves: RHEL-77114
- Allow init mounton crypto sysctl files
Resolves: RHEL-56250
2025-02-07 11:54:25 +01:00
Zdenek Pytela
90793b11a8 * Mon Jan 27 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.24-1
- Allow systemd-generator connect to syslog over a unix datagram socket
Resolves: RHEL-75879
- Allow ssh_t to change role to system_r
Resolves: RHEL-53972
- Allow virtnodedev create /etc/mdevctl.d/scripts.d with bin_t type
Resolves: RHEL-39893
- Allow virtqemud manage fixed disk device nodes
Resolves: RHEL-71656
- Allow samba-bgqd connect to cupsd over an unix domain stream socket
Resolves: RHEL-72861
- Allow systemd-machined read the vsock device
Resolves: RHEL-74280
- Allow pcmsensor write nmi_watchdog state information
Resolves: RHEL-52838
- Label /proc/sys/kernel/nmi_watchdog with sysctl_nmi_watchdog_t
Resolves: RHEL-52838
2025-01-27 22:55:53 +01:00
Zdenek Pytela
998e8bfebb * Fri Jan 24 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.23-2
- Rebuild other packages with with selinux-policy-40.13.23
Resolves: RHEL-36741
2025-01-24 09:56:46 +01:00
Zdenek Pytela
a8e3dc5636 * Thu Jan 23 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.23-1
- Remove the lockdown class from the policy
Resolves: RHEL-36741
- Remove socket from unconfined_domain_type allow rule
Resolves: RHEL-36741
- Include key_socket in socket_class_set
Resolves: RHEL-36741
2025-01-23 14:49:22 +01:00
Zdenek Pytela
06af1e2772 * Thu Jan 16 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.22-1
- Allow staff user dbus chat with virt-dbus
Resolves: RHEL-73914
- Allow virtqemud domain transition to nbdkit
Resolves: RHEL-69118
- Add nbdkit interfaces defined conditionally
Resolves: RHEL-69118
- Allow svirt_t read sysfs files
Resolves: RHEL-71270
- Label /dev/pmem[0-9]+ with fixed_disk_device_t
Resolves: RHEL-71656
- Add support for the KVM guest memfd anon inodes
Resolves: RHEL-69128
- Allow sysadm user dbus chat with virt-dbus
Resolves: RHEL-73914
- Allow initrc_t transition to passwd_t
Resolves: RHEL-71665
- Allow unconfined_service_t transition to passwd_t
Resolves: RHEL-71665
2025-01-16 21:45:16 +01:00
Zdenek Pytela
f64670faa3 * Wed Jan 08 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.21-1
- Allow init create vsock socket for sshd
Resolves: RHEL-72549
- Support ssh connections via systemd-ssh-generator
Resolves: RHEL-72549
- Allow ssh generator work with systemd unit files
Resolves: RHEL-72549
- Confine systemd system-ssh-generator
Resolves: RHEL-72549
- Allow login_userdomain getattr nsfs files
Resolves: RHEL-72549
- Allow virtqemud send a generic signal to the ssh client domain
Resolves: RHEL-53972
- Add the auth_dontaudit_read_passwd_file() interface
Resolves: RHEL-71490
- Dontaudit request-key read /etc/passwd
Resolves: RHEL-71490
2025-01-08 19:16:22 +01:00
Zdenek Pytela
e863f070bd * Fri Jan 03 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.20-1
- Allow virtqemud domain transition on numad execution
Resolves: RHEL-65789
- Support virt live migration using ssh
Resolves: RHEL-53972
- Allow ssh_t read systemd config files
Resolves: RHEL-53972
- Allow virtqemud permissions needed for live migration
Resolves: RHEL-43217
- Allow virtqemud the getpgid process permission
Resolves: RHEL-46357
- Allow virtqemud manage nfs dirs when virt_use_nfs boolean is on
Resolves: RHEL-71068
- Allow virtqemud relabelfrom virt_log_t files
Resolves: RHEL-48236
- Allow virtqemud relabel tun_socket
Resolves: RHEL-71394
- Allow gnome-remote-desktop dbus chat with policykit
Resolves: RHEL-35877
- Update ktlsh policy
Resolves: RHEL-42672
- Confine the ktls service
Resolves: RHEL-42672
- Allow request-key to read /etc/passwd
Resolves: RHEL-71490
- Allow request-key to manage all domains' keys
Resolves: RHEL-71490
2025-01-03 16:59:30 +01:00
Petr Lautrbach
046dc6f583 * Fri Dec 20 2024 Petr Lautrbach <lautrbach@redhat.com> - 40.13.19-2
- Rebuild with SELinux Userspace 3.8

Resolves: RHEL-69451
2024-12-20 09:08:58 +01:00
Zdenek Pytela
9ffb04b099 * Wed Dec 18 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.19-1
- Allow systemd-journald getattr nsfs files
Resolves: RHEL-71803
- Allow systemd-related domains getattr nsfs files
Resolves: RHEL-71803
2024-12-18 23:43:40 +01:00
Zdenek Pytela
dfb01e2dd7 * Fri Dec 13 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.18-1
- Sync dist/targeted/modules.conf with Fedora 42
Resolves: RHEL-70850
- Add support for sap
Resolves: RHEL-70850
- Allow sssd_selinux_manager_t the setcap process permission
Resolves: RHEL-70822
- Allow virtqemud open svirt_devpts_t char files
Resolves: RHEL-43446
- Fix the cups_read_pid_files() interface to use read_files_pattern
Resolves: RHEL-69512
2024-12-13 17:43:37 +01:00
Zdenek Pytela
a789dba85b * Thu Dec 12 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.17-1
- Update samba-bgqd policy
Resolves: RHEL-69512
- Allow samba-bgqd read cups config files
Resolves: RHEL-69512
- Allow virtqemud additional permissions for tmpfs_t blk devices
Resolves: RHEL-61235
- Allow virtqemud rw access to svirt_image_t chr files
Resolves: RHEL-61235
- Allow virtqemud rw and setattr access to fixed block devices
Resolves: RHEL-61235
- Label /etc/mdevctl.d/scripts.d with bin_t
Resolves: RHEL-39893
- Fix the /etc/mdevctl\.d(/.*)? regexp
Resolves: RHEL-39893
- Allow virtnodedev watch mdevctl config dirs
Resolves: RHEL-39893
- Make mdevctl_conf_t member of the file_type attribute
Resolves: RHEL-39893
- Label /etc/mdevctl.d with mdevctl_conf_t
Resolves: RHEL-39893
- Allow virtqemud relabelfrom virt_log_t files
Resolves: RHEL-48236
- Allow virtqemud_t relabel virtqemud_var_run_t sock_files
Resolves: RHEL-48236
- Allow virtqemud relabelfrom virtqemud_var_run_t dirs
Resolves: RHEL-48236
- Allow svirt_tcg_t read virtqemud_t fifo_files
Resolves: RHEL-48236
- Allow virtqemud rw and setattr access to sev devices
Resolves: RHEL-69128
- Allow virtqemud directly read and write to a fixed disk
Resolves: RHEL-61235
- Allow svirt_t the sys_rawio capability
Resolves: RHEL-61235
- Allow svirt_t the sys_rawio capability
Resolves: RHEL-61235
- Allow virtqemud connect to sanlock over a unix stream socket
Resolves: RHEL-44352
- allow gdm and iiosensorproxy talk to each other via D-bus
Resolves: RHEL-70850
- Allow sendmail to map mail server configuration files
Related: RHEL-54014
- Allow procmail to read mail aliases
Resolves: RHEL-54014
- Grant rhsmcertd chown capability & userdb access
Resolves: RHEL-68481
2024-12-12 21:18:45 +01:00
Zdenek Pytela
bfa35b4ec0 * Fri Nov 29 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.16-1
- Fix the file type for /run/systemd/generator
Resolves: RHEL-68313
2024-11-29 15:11:11 +01:00
Zdenek Pytela
d246bfd939 * Thu Nov 28 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.15-1
- Allow qatlib search the content of the kernel debugging filesystem
Resolves: RHEL-66334
- Allow qatlib connect to systemd-machined over a unix socket
Resolves: RHEL-66334
- Update policy for samba-bgqd
Resolves: RHEL-64908
- Allow httpd get attributes of dirsrv unit files
Resolves: RHEL-62706
- Allow virtstoraged read vm sysctls
Resolves: RHEL-61742
- Allow virtstoraged execute mount programs in the mount domain
Resolves: RHEL-61742
- Update policy for rpc-virtstorage
Resolves: RHEL-61742
- Allow virtstoraged get attributes of configfs dirs
Resolves: RHEL-61742
- Allow virt_driver_domain read virtd-lxc files in /proc
Resolves: RHEL-61742
- Allow virtstoraged manage files with virt_content_t type
Resolves: RHEL-61742
- Allow virtstoraged use the io_uring API
Resolves: RHEL-61742
- Allow virtstoraged execute lvm programs in the lvm domain
Resolves: RHEL-61742
- Allow svirt_t connect to unconfined_t over a unix domain socket
Resolves: RHEL-61246
- Label /usr/lib/node_modules_22/npm/bin with bin_t
Resolves: RHEL-56350
- Allow bacula execute container in the container domain
Resolves: RHEL-39529
- Label /run/systemd/generator with systemd_unit_file_t
Resolves: RHEL-68313
2024-11-28 22:16:34 +01:00
Zdenek Pytela
efbe8c4f78 * Tue Nov 19 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.14-1
- mls/modules.conf - fix typo
Related: RHEL-54303
- Use dist/targeted/modules.conf in build workflow
Related: RHEL-54303
- Fix default and dist config files
Related: RHEL-54303
- CI: update to actions/checkout@v4
Related: RHEL-54303
- Clean up and sync securetty_types
Related: RHEL-54303
- Bring config files from dist-git into the source repo
Related: RHEL-54303
- Sync users with Fedora targeted users
Related: RHEL-54303
2024-11-19 19:42:04 +01:00
Petr Lautrbach
698afe1ad8 Update sources
Recent dist-git changes require changes in
fedora-selinux/selinux-policy project which were already merged.

Related: RHEL-54303

[skip changelog]
2024-11-19 17:15:18 +01:00
Petr Lautrbach
1584866ea6 Use install instead of cp
and preserve timestamps using `install -p`

https://docs.fedoraproject.org/en-US/packaging-guidelines/#_timestamps

[skip changelog]

Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Petr Lautrbach
9f39950991 Remove old triggers
3.12.1-74 was released 2013
3.13.1-138 was release 2015

Both versions are not relevant anymore

[skip changelog]

Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Petr Lautrbach
7dcb603438 Drop ru man pages
They were not updated since 2007

Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Zdenek Pytela
ed293503c6 Run restorecon on /etc/mdevctl.d temporarily
Resolves: rhbz#2311359

Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Ondrej Mosnacek
ddc0446829 Remove most config files from dist-git and take them from sources
The content of these files is more or less tied to the policy source
code. Therefore, moving these files to the source repo rather than
dist-git will make it easier to do changes that would formerly need
coordinated modification both in the sources and in dist-git (e.g.
adding or removing a module). It will also make it easier for other
distributions seeking to package a Fedora-like SELinux policy.

[skip changelog]

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>

Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Petr Lautrbach
de68c21d87 BuildRequires: groff
groff is necessary for generating html man pages

Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=2294821

Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Petr Lautrbach
4bb6c144e3 Move %postInstall to %posttrans
If policy update removes a module, %postInstall and therefore policy
rebuild - `semodule -B -n ...` was run when old module is still
installed, see
https://docs.fedoraproject.org/en-US/packaging-guidelines/Scriptlets/#ordering
It resulted to state when the old module is still built in the policy
after update until another `semodule -B` is triggered.

Moving %postInstall to %posttrans should solve this problem

[skip changelog]

Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Colin Walters
3fed54cdcc Use Requires(meta): (rpm-plugin-selinux if rpm-libs)
We support two ways to update the operating system:

- `/usr/bin/rpm` (and `dnf` etc.) where SELinux labels are
  computed and written client side
- ostree (and other image-based systems) where SELinux labels
  were computed server side.

In the ostree case, I'd like the ability to generate smaller
images that do not even have `rpm` installed.

This hard dependency from `selinux-policy` -> `rpm` is one of
the only main blockers.

RPM supports these "alternative" conditionals, it's easy to do.

Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Ondrej Mosnacek
ac73ffca09 Drop obsolete modules from config
Remove modules for packages retired from Fedora that are not present in
refpolicy sources. There is no need to ship or build them as the
associated software is not supported on Fedora nor RHEL (I checked).

References:
https://src.fedoraproject.org/rpms/Ajaxterm
https://src.fedoraproject.org/rpms/authconfig
https://docs.fedoraproject.org/en-US/quick-docs/bumblebee/
https://src.fedoraproject.org/rpms/389-admin
https://src.fedoraproject.org/rpms/kmscon
mip6d - not much info can be found, seems to predate RHEL-7
https://src.fedoraproject.org/rpms/mirrormanager
naemon - https://bugzilla.redhat.com/show_bug.cgi?id=1069988
https://src.fedoraproject.org/rpms/piranha
pkcs11proxyd - https://src.fedoraproject.org/rpms/caml-crush
https://src.fedoraproject.org/rpms/rkt
https://src.fedoraproject.org/rpms/rolekit
sge - https://src.fedoraproject.org/rpms/gridengine
smsd - https://src.fedoraproject.org/rpms/smstools
https://src.fedoraproject.org/rpms/timedatex

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>

Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Petr Lautrbach
53fd0a7aa2 Install dnf protected files only when policy is built
If an user builds package with `%bcond mls 0` it ended with
    RPM build errors:
    error: Installed (but unpackaged) file(s) found:
       /etc/dnf/protected.d/selinux-policy-mls.conf
        Installed (but unpackaged) file(s) found:
       /etc/dnf/protected.d/selinux-policy-mls.conf

With this change, dnf procted files for a policy is installed only when
the policy is built.

[skip changelog]

Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Zbigniew Jędrzejewski-Szmek
488e7b1b79 Also relabel files under /usr/sbin
I forgot that this needs to apply to pre-sbin-merge systems too. Let's
cover those too.

Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Zbigniew Jędrzejewski-Szmek
5e1af34521 Relabel files under /usr/bin to fix stale context after sbin merge
Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Petr Lautrbach
fc93f2b404 Merge -base and -contrib
Contrib was merged to main repo long time ago.

Makes the build process simpler.

Modules enabled in minimum lives in
%{_datadir}/selinux/minimum/modules.lst now.

Fixes:
RPM build warnings:
    File listed twice: /var/lib/selinux/mls/active/modules/100/unprivuser
    File listed twice: /var/lib/selinux/mls/active/modules/100/unprivuser/cil
    File listed twice: /var/lib/selinux/mls/active/modules/100/unprivuser/hll
    File listed twice: /var/lib/selinux/mls/active/modules/100/unprivuser/lang_ext

[skip changelog]

Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Zdenek Pytela
4b190446b9 Include "mode" in the %verify-not configuration for extra_varrun
rpm-verify reports the following problem:
.M.......  g /var/lib/selinux/targeted/active/modules/400/extra_varrun
.M.......  g /var/lib/selinux/targeted/active/modules/400/extra_varrun/cil
.M.......  g /var/lib/selinux/targeted/active/modules/400/extra_varrun/lang_ext

Related: RHEL-54303
2024-11-14 17:16:04 +01:00