Lukas Vrabec
6e1369286b
* Wed Aug 07 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.4-29
...
- Allow dlm_controld_t domain setgid capability
- Fix SELinux modules not installing in chroots.
Resolves: rhbz#1665643
2019-08-07 17:38:17 +02:00
Lukas Vrabec
1d650f7cbb
* Tue Jan 15 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.3-18
...
- Allow plymouthd_t search efivarfs directory BZ(1664143)
- Allow arpwatch send e-mail notifications BZ(1657327)
- Allow tangd_t domain to bind on tcp ports labeled as tangd_port_t
- Allow gssd_t domain to read/write kernel keyrings of every domain.
- Allow systemd_timedated_t domain nnp_transition BZ(1666222)
- Add the fs_search_efivarfs_dir interface
- Create tangd_port_t with default label tcp/7406
- Add interface domain_rw_all_domains_keyrings()
- Some of the selinux-policy macros doesn't work in chroots/initial installs. BZ(1665643)
2019-01-15 18:29:10 +01:00
Lukas Vrabec
146094f7a3
* Sat Oct 13 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.3-7
...
- Update rpm macros for selinux policy from sources repository: https://github.com/fedora-selinux/selinux-policy-macros
2018-10-13 00:13:10 +02:00
Lukas Vrabec
5c972253e7
Update selinux policy macros to reflect the latest changes in
...
selinux-policy-macros repo
2018-04-25 21:48:43 +02:00
Lukas Vrabec
4caea74068
Updated rpm.macros
2018-02-05 17:01:34 +01:00
Lukas Vrabec
723bc03d9a
Add new rpm macro %{selinux_requires}
2017-11-23 15:48:40 +01:00
Lukas Vrabec
21c53d34a6
Use %{_sbindir} macro instead of full path
2017-09-14 09:02:59 +02:00
Lukas Vrabec
37cf7d764b
Backport new selinux-policy rpm macros from github repo:
...
https://github.com/fedora-selinux/selinux-policy-macros.git
Main point of this change is to allow set SELinux Module priority in
selinux_modules_(u)install() macros.
2017-07-11 17:56:49 +02:00
Lukas Vrabec
29c9d82cda
Update rpm macros
2017-03-14 10:48:34 +01:00
Lukas Vrabec
6fa7bc6ada
Add handling booleans via selinux-policy macros in custom policy spec files.
2017-03-13 16:27:05 +01:00
Petr Lautrbach
c49229e77f
Provide rpm macros for packages installing SELinux modules
...
There's no unified practice how to install SELinux modules from packages
and how to relabel a filesystem after the change. This update provides
several new macros which should help maintainers with the process.
%selinux_relabel_pre [-s <policytype>]
- backups the current file_contexts for later use with fixfiles
%selinux_relabel_post [-s <policytype>]
- relabels a filesystem based on changes in file_contexts using fixfiles
%selinux_modules_install [-s <policytype>] module [module]...
%selinux_modules_uninstall [-s <policytype>] module [module]...
- install and uninstall modules to the priority 200
2016-09-20 09:40:52 +02:00