Zdenek Pytela
d386a97bbf
* Mon Oct 27 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.10-1
...
- Allow sshd-auth read generic proc files
Resolves: RHEL-107732
- Allow sshd-auth read and write user domain ptys
Resolves: RHEL-107732
- Allow sshd-session get attributes of sshd vsock socket
Resolves: RHEL-107732
- Adjust guest and xguest users policy for sshd-session
Resolves: RHEL-107732
- Update files_search_base_file_types()
Resolves: RHEL-107732
- Allow sshd-session read cockpit pid files
Resolves: RHEL-107732
- Add default contexts for sshd-seesion
Resolves: RHEL-107732
- Define types for new openssh executables
Resolves: RHEL-107732
- Allow ras-mc-ctl get attributes of the kmod executable
Resolves: RHEL-102535
- Define file equivalency for /var/opt
Resolves: RHEL-116512
- Update specfile triggers for DSP modules
Resolves: RHEL-116044
2025-10-28 11:52:07 +01:00
Zdenek Pytela
932ca30f2d
* Wed Oct 08 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.9-1
...
- Allow systemd-oomd watch tmpfs dirs
Resolves: RHEL-106998
- Allow systemd-oomd watch dbus pid sock files
Resolves: RHEL-106998
- Allow userdomain to connect to systemd-oomd over a unix socket
Resolves: RHEL-106998
- Allow 'oomctl dump' to interact with systemd-oomd
Resolves: RHEL-106998
- Basic functionality for systemd-oomd
Resolves: RHEL-106998
- Basic enablement for systemd-oomd
Resolves: RHEL-106998
- Remove permissive domains
Resolves: RHEL-107038
- Allow iptables manage its private fifo_files in /tmp
Resolves: RHEL-83775
- Allow ras-mc-ctl write to sysfs files
Resolves: RHEL-86926
- Allow nfs generator create and use netlink sockets
Resolves: RHEL-111556
- Revert "Allow virt_domain write to virt_image_t files"
Resolves: RHEL-93773
2025-10-08 15:45:52 +02:00
Zdenek Pytela
697ef79028
* Fri Sep 19 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.8-1
...
- Reapply "Add insights_core interfaces"
Resolves: RHEL-112368
- Reapply "Add policy for insights-core"
Resolves: RHEL-112368
2025-09-24 13:51:25 +02:00
jan janasek
29a65ab4d4
selinux-policy: eliminate overlapping test plans
...
component-filtered and tier1-filtered plans are overlapping with tests that have metadata:
"tier: 1" and "component:selinux-policy", therefore condition "tier:-1" added to component-filtered
plan to not run those those tests twice.
Signed-off-by: Jan Janasek <jjanasek@redhat.com>
2025-08-25 13:11:18 +02:00
Zdenek Pytela
9448d92f10
* Thu Aug 21 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.7-1
...
- Revert "Add policy for insights-core"
Resolves: RHEL-110651
- Revert "Add insights_core interfaces"
Resolves: RHEL-110651
2025-08-21 22:21:55 +02:00
Vit Mojzis
f9b8f17b4f
Add selinux-policy-automotive sub-package
...
The package is modeled after selinux-policy-minimum in that it contains
all the modules that are present in selinux-policy-targeted, but most of
them are disabled (all that are not present in modules-automotive.lst).
Requires dist/automotive directory containing config files in the
selinux-policy tar.
Resolves: RHEL-105410
2025-08-13 13:19:09 +02:00
Zdenek Pytela
e37d06d30f
Add binsbin-convert.sh script
...
After selinux-policy part of Changes/Unify_bin_and_sbin [1] has been
done, some packages shipping their own policy modules still contain
entries in /usr/sbin. For such entries not to be overriden by the
/usr/sbin=/usr/bin equivalency, this script is meant as a temporary
measure to create an extra SELinux local module with equivalent entries,
but in /usr/bin.
Debugging:
DEBUG=yes /usr/libexec/selinux/binsbin-convert.sh targeted
[1] https://fedoraproject.org/wiki/Changes/Unify_bin_and_sbin
Resolves: RHEL-69118
2025-08-12 16:21:34 +02:00
Zdenek Pytela
c4ebc6797d
* Tue Aug 12 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.6-1
...
- Apply generator template to selinux-autorelabel generator
Resolves: RHEL-107516
- Allow systemd-coredumpd capabilities in the user namespace
Resolves: RHEL-97586
- Allow virtqemud start a vm which uses nbdkit
Resolves: RHEL-69118
- Add nbdkit_signal() and nbdkit_signull() interfaces
Resolves: RHEL-69118
- Allow openvswitch read virtqemud process state
Resolves: RHEL-65322
- Add binsbin-convert.sh script
Resolves: RHEL-69118
2025-08-12 16:13:11 +02:00
Zdenek Pytela
2a666c944a
* Fri Aug 08 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.5-1
...
- Confine nfs-server generator
Resolves: RHEL-106119
- Support virtqemud handle hotplug hostdev devices
Resolves: RHEL-65266
- Allow virtstoraged create qemu /var/run files
Resolves: RHEL-104344
- Allow virtqemud write to sysfs files
Resolves: RHEL-104378
- Allow unconfined_domain_type cap2_userns capabilities
Resolves: RHEL-93656
2025-08-08 18:12:56 +02:00
Zdenek Pytela
7126ba3cdf
* Thu Jul 31 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.4-1
...
- Allow systemd-coredump the sys_chroot capability
Resolves: RHEL-97586
- Add the rhcd_rw_fifo_files() interface
Related: RHEL-99318
- Add insights_client_delete_lib_dirs() interface
Related: RHEL-99318
2025-07-31 13:35:04 +02:00
Vit Mojzis
c682b95984
Rebuild for SELinux userspace 3.9
...
Related: RHEL-104006
2025-07-23 20:07:12 +02:00
Zdenek Pytela
767de9739d
* Fri Jul 18 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.3-1
...
- Allow svirt read virtqemud fifo files
Resolves: RHEL-104069
- Allow virtqemud handle virt_content_t chr files
Resolves: RHEL-76104
- Allow "hostapd_cli ping" run as a systemd service
Resolves: RHEL-77047
- All sblim-sfcbd the dac_read_search capability
Resolves: RHEL-98287
- Allow sblim domain read systemd session files
Resolves: RHEL-98287
- Allow sblim-sfcbd execute dnsdomainname
Resolves: RHEL-98287
- Allow systemd-importd create and unlink init pid socket
Resolves: RHEL-98490
2025-07-18 19:29:08 +02:00
Zdenek Pytela
831808b791
* Wed Jul 16 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.2-1
...
- Remove permissive domains
Resolves: RHEL-103661
- Adjust modules list
Resolves: RHEL-103661
2025-07-16 17:05:53 +02:00
Zdenek Pytela
3c58b106cf
* Mon Jul 14 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.1-1
...
- Rebase selinux-policy to the newest one available in Fedora 42
Resolves: RHEL-54303
2025-07-14 17:07:34 +02:00
Zdenek Pytela
5f13f86c60
* Wed Jul 02 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.35-1
...
- Remove duplicate summary header
Related: RHEL-87742
- Allow irqbalance execute shell if irqbalance_run_unconfined is on
Resolves: RHEL-54019
- virt: allow QEMU use of the qgs daemon for attestation
Resolves: RHEL-87742
- qgs: add contrib module for TDX "qgs" daemon
Resolves: RHEL-87742
- kernel: add interfaces for using SGX enclaves
Resolves: RHEL-87742
2025-07-02 16:34:29 +02:00
Zdenek Pytela
a43247ed31
* Tue Jul 01 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.34-1
...
- Allow systemd-coredump the sys_admin capability
Resolves: RHEL-97586
- Dontaudit systemd-coredump the sys_resource capability
Resolves: RHEL-97586
- Allow systemd-coredumpd sys_admin and sys_resource capabilities
Resolves: RHEL-97586
- Allow systemd-coredump read nsfs files
Resolves: RHEL-97586
- Dontaudit systemd-coredump sys_admin capability
Resolves: RHEL-97586
- Allow svirt-tcg read init state
Resolves: RHEL-95725
- Allow virtqemud create and unlink files in /etc/libvirt/
Resolves: RHEL-95725
- Allow virtqemud send a generic signal to passt
Resolves: RHEL-44994
- Allow openvswitch ioctl vduse devices
Resolves: RHEL-93041
- Label /dev/vduse/control and /dev/vduse/NAME devices
Resolves: RHEL-93041
- Allow virtstoraged the sys_rawio capability
Resolves: RHEL-44639
- Allow virtstoraged fsetid capability
Resolves: RHEL-44639
- Allow virtqemud additional permissions on scsi generic chr files
Resolves: RHEL-44628
- Allow irqbalance execute shell if irqbalance_run_unconfined is on
Resolves: RHEL-54019
- Fix files_dontaudit_delete_all_files()
Resolves: RHEL-86789
- Allow virtnodedev create mdevctl config dirs
Resolves: RHEL-98559
- Allow cryptsetup-generator manage systemd unit files
Resolves: RHEL-98656
2025-07-01 17:04:08 +02:00
Zdenek Pytela
1ba9a90255
* Fri Jun 06 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.33-1
...
- Allow systemd_generator read files in /proc and /sys
Resolves: RHEL-36740
- Update irqbalance policy for using unconfined scripts
Resolves: RHEL-54019
- Allow utempter use terminal multiplexor
Resolves: RHEL-56344
- Allow virtqemud execute ovs-vsctl with a domain transition
Resolves: RHEL-65322
- Allow mptcpd the net_admin capability
Resolves: RHEL-70730
- Allow tomcat execute cracklib-check with a domain transition
Resolves: RHEL-82090
- Update the files_search_mnt() interface
Resolves: RHEL-85178
- Allow key.dns_resolve set attributes on the kernel key ring
Resolves: RHEL-91602
- Allow switcheroo-control dbus chat with xdm
Resolves: RHEL-93535
- Revert "Allow virt_domain write to virt_image_t files"
Resolves: RHEL-93773
2025-06-06 10:19:29 +02:00
Zdenek Pytela
fd51330eda
* Thu May 29 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.32-1
...
- Backport policy for additional systemd generators from rawhide
Resolves: RHEL-36740
- Allow login_userdomain create /run/tlog directory with user_tmp_t
Resolves: RHEL-56344
- Backport bootupd policy from current Fedora rawhide
Resolves: RHEL-86588
2025-05-30 15:15:52 +02:00
Petr Lautrbach
c69e93c91c
Revert "Add selinux-policy-epel test plan"
...
This reverts commit 94ea41534e .
selinux-policy-epel will be obsoleted when
redhat/centos-stream/rpms/selinux-policy!197
is merged and RHEL-89587 is resolved
Related: RHEL-89587
2025-05-21 10:03:23 +02:00
Petr Lautrbach
dbae004177
Revert "Make make-rhat-patches.sh selinux-policy-epel aware"
...
This reverts commit 61db7c0bba .
selinux-policy-epel will be obsoleted when
https://gitlab.com/redhat/centos-stream/rpms/selinux-policy/-/merge_requests/197
is merged and RHEL-89587 is resolved
Related: RHEL-89587
2025-05-21 10:03:23 +02:00
Petr Lautrbach
8dea43b936
Build selinux-policy-extra
...
In 40.13.26-1 modules related to EPEL repository were filtered out and
shipped in selinux-policy-epel in EPEL repository. But it was not
possible to let epel-release to automatically install
selinux-policy-epel when it was enabled.
With this change:
- EPEL related modules are build in repository again
- selinux-policy-extra is introduced to require -targeted-extra or
-mls-extra when -targeted or -mls are installed
- some modules which are related to 3rd party and which are already
dropped in selinux-policy-epel are filtered out completely
Resolves: RHEL-89587
2025-05-21 10:03:16 +02:00
Zdenek Pytela
7010f47ab1
* Tue May 20 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.31-1
...
- Label /dev/diag as diagnostic_device_t
Resolves: RHEL-89804
- Label SetroubleshootPrivileged.py with setroubleshootd_exec_t
Resolves: RHEL-87727
- Allow syslogd watch syslog_conf_t directories
Resolves: RHEL-87648
- Allow networkmanager send a general signal to iptables
Resolves: RHEL-86780
- Define file equivalency for /var/etc
Resolves: RHEL-86678
- Update bootupd policy when ESP is not mounted
Resolves: RHEL-86588
- dontaudit execmem for modemmanager
Resolves: RHEL-86176
- Allow systemd create journal pid files
Resolves: RHEL-72692
- Allow virtqemud read/write/setattr input event devices
Resolves: RHEL-46385
2025-05-20 15:22:39 +02:00
Zdenek Pytela
399d79b252
* Mon Apr 28 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.30-1
...
- Allow auditctl signal auditd
Resolves: RHEL-87418
- Update bootupd policy for the removing-state-file test
Resolves: RHEL-87372
- Allow systemd-user-runtime-dir get/set tmpfs quotas
Resolves: RHEL-86789
- Allow systemd-user-runtime-dir delete gnome homedir content
Resolves: RHEL-86789
- Confine /usr/lib/systemd/systemd-user-runtime-dir
Resolves: RHEL-86789
- Allow system-dbusd list systemd-machined directories
Resolves: RHEL-86528
- Allow NetworkManager create and use icmp_socket
Resolves: RHEL-86258
- Allow tuned-ppd dbus chat with xdm
Resolves: RHEL-85849
- Allow virt_domain write to virt_image_t files
Resolves: RHEL-85319
- Allow rhsmcertd connect to systemd-machined
Resolves: RHEL-83925
- Allow varnishd execute the prlimit64() syscall
Resolves: RHEL-77779
- Allow systemd-machined the kill user-namespace capability
Resolves: RHEL-77087
- Allow system_dbusd_t r/w unix stream sockets of unconfined_service_t
Resolves: RHEL-62185
- Allow tlshd read network sysctls
Resolves: RHEL-74424
2025-04-28 17:13:57 +02:00
Zdenek Pytela
04dfd0db74
* Tue Apr 15 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.29-1
...
- Revert "Dontaudit access of virt-related permissive domains"
Resolves: RHEL-79833
- Remove permissive domains
Resolves: RHEL-82672
2025-04-15 14:08:02 +02:00
Petr Lautrbach
94ea41534e
Add selinux-policy-epel test plan
...
- should be triggered only in CI by commit
- should check current selinux-policy version and latest
selinux-policy-epel version and fail if they're different to notify
maintainer about needed action
Related: RHEL-74424
2025-04-11 07:44:41 +02:00
Petr Lautrbach
61db7c0bba
Make make-rhat-patches.sh selinux-policy-epel aware
...
In case of change commit id it will warn user to update
also selinux-policy-epel.spec
Adds the following script output:
WARNING: selinux-policy-epel needs to be updated to use 56617809a873ce441278ef56a5b7e92c3c2cb56d:
cd <selinux-policy-epel directory>
fedpkg switch-brach epel10
fedpkg new-sources /home/plautrba/devel/centos/rpms/selinux-policy/make-rhat-patches-epel/selinux-policy-5661780.tar.gz container-selinux.tgz
git apply /home/plautrba/devel/centos/rpms/selinux-policy/make-rhat-patches-epel/selinux-policy-epel-5661780.patch
Related: RHEL-74424
2025-04-11 07:44:41 +02:00
Zdenek Pytela
30a191682d
* Tue Apr 08 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.28-1
...
- Change path of tuned and tuned-ppd to /usr/sbin
Resolves: RHEL-69450
- Update the pcmsensor policy
Resolves: RHEL-80452
- Allow dovecot-deliver read mail aliases
Resolves: RHEL-80153
- Allow boothd connect to systemd-machined over a unix socket
Resolves: RHEL-75471
- Allow chronyd-restricted sendto to chronyc
Resolves: RHEL-82299
- Allow chronyc sendto to chronyd-restricted
Resolves: RHEL-82299
- Allow cifs.idmap helper to set attributes on kernel keys
Resolves: RHEL-83921
- Remove ktls from modules-filtered.lst
Resolves: RHEL-74424
2025-04-08 18:37:43 +02:00
Zdenek Pytela
fab9313c6d
Remove ktls from modules-filtered.lst
...
The module was added to RHEL 10 during RHEL 10.1 development phase.
Resolves: RHEL-74424
2025-04-08 18:33:03 +02:00
Zdenek Pytela
b148e340be
* Mon Mar 31 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.27-1
...
- Allow afterburn to mount and read config drives
Resolves: RHEL-82120
- Update afterburn file transition policy
Resolves: RHEL-82120
- Label /run/metadata with afterburn_runtime_t
Resolves: RHEL-82120
- Allow afterburn list ssh home directory
Resolves: RHEL-82120
- Confine tuned-ppd
Resolves: RHEL-69450
- Update ktls policy
Resolves: RHEL-74424
- Add the switcheroo module
Resolves: RHEL-83267
- Update switcheroo policy
Resolves: RHEL-83267
- Confine the switcheroo-control service
Resolves: RHEL-83267
2025-03-31 16:20:52 +02:00
Zdenek Pytela
09fc1276e0
* Mon Feb 17 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.26-1
...
- Rename winbind_rpcd_* types to samba_dcerpcd_*
Resolves: RHEL-14759
- Allow samba-dcerpcd work with ctdb cluster
Resolves: RHEL-14759
- Revert "Remove socket from unconfined_domain_type allow rule"
Resolves: RHEL-77327
- Dontaudit access of virt-related permissive domains
Resolves: RHEL-77808
- Add selinux_requires_min macro
Resolves: RHEL-54715
- Filter out EPEL related modules
Resolves: RHEL-73505
2025-02-17 15:35:52 +01:00
Vit Mojzis
17418f272b
Add selinux_requires_min macro
...
DSP adopters who don't set any booleans should not require
policycoreutils-python-utils.
In order not to break established packages that use the selinux_requires
macro, a new one is introduced (can be adopted over time).
Also drop policycoreutils-python, since that is only relevant for
RHEL-7 and older.
Resolves: RHEL-54715
2025-02-17 14:29:07 +01:00
Petr Lautrbach
0ebb49f063
Filter out EPEL related modules
...
Resolves: RHEL-73505
2025-02-07 17:20:00 +01:00
Zdenek Pytela
1f5673f9d0
* Thu Feb 06 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.25-1
...
- Update ktlshd policy to read /proc/keys and domain keyrings
Resolves: RHEL-42672
- Allow pcmsensor read nmi_watchdog state information
Resolves: RHEL-52838
- Support peer-to-peer migration of vms using ssh
Resolves: RHEL-77351
- Allow virt_domain read hardware state information unconditionally
Resolves: RHEL-71270
- Allow timemaster write to sysfs files
Resolves: RHEL-44637
- Allow virtqemud map svirt_image_t plain files
Resolves: RHEL-40080
- Allow virtqemud unmount a filesystem with extended attributes
Resolves: RHEL-40080
- Allow virtqemud work with nvdimm devices
Resolves: RHEL-71656
- Update virtqemud policy regarding the svirt_tcg_t domain
Resolves: RHEL-71270
- Allow virtqemud use hostdev usb devices conditionally
Resolves: RHEL-74230
- Support saving and restoring a VM to/from a block device
Resolves: RHEL-76138
- Allow virtnwfilterd dbus chat with firewalld
Resolves: RHEL-76138
- Allow virt_domain to use pulseaudio - conditional
Resolves: RHEL-62763
- Allow virtstoraged write to sysfs files
Resolves: RHEL-44637
- Allow irqbalance to run unconfined scripts conditionally
Resolves: RHEL-54019
- Allow rhsmcertd notify virt-who
Resolves: RHEL-77114
- Allow init mounton crypto sysctl files
Resolves: RHEL-56250
2025-02-07 11:54:25 +01:00
Zdenek Pytela
90793b11a8
* Mon Jan 27 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.24-1
...
- Allow systemd-generator connect to syslog over a unix datagram socket
Resolves: RHEL-75879
- Allow ssh_t to change role to system_r
Resolves: RHEL-53972
- Allow virtnodedev create /etc/mdevctl.d/scripts.d with bin_t type
Resolves: RHEL-39893
- Allow virtqemud manage fixed disk device nodes
Resolves: RHEL-71656
- Allow samba-bgqd connect to cupsd over an unix domain stream socket
Resolves: RHEL-72861
- Allow systemd-machined read the vsock device
Resolves: RHEL-74280
- Allow pcmsensor write nmi_watchdog state information
Resolves: RHEL-52838
- Label /proc/sys/kernel/nmi_watchdog with sysctl_nmi_watchdog_t
Resolves: RHEL-52838
2025-01-27 22:55:53 +01:00
Zdenek Pytela
998e8bfebb
* Fri Jan 24 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.23-2
...
- Rebuild other packages with with selinux-policy-40.13.23
Resolves: RHEL-36741
2025-01-24 09:56:46 +01:00
Zdenek Pytela
a8e3dc5636
* Thu Jan 23 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.23-1
...
- Remove the lockdown class from the policy
Resolves: RHEL-36741
- Remove socket from unconfined_domain_type allow rule
Resolves: RHEL-36741
- Include key_socket in socket_class_set
Resolves: RHEL-36741
2025-01-23 14:49:22 +01:00
Zdenek Pytela
06af1e2772
* Thu Jan 16 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.22-1
...
- Allow staff user dbus chat with virt-dbus
Resolves: RHEL-73914
- Allow virtqemud domain transition to nbdkit
Resolves: RHEL-69118
- Add nbdkit interfaces defined conditionally
Resolves: RHEL-69118
- Allow svirt_t read sysfs files
Resolves: RHEL-71270
- Label /dev/pmem[0-9]+ with fixed_disk_device_t
Resolves: RHEL-71656
- Add support for the KVM guest memfd anon inodes
Resolves: RHEL-69128
- Allow sysadm user dbus chat with virt-dbus
Resolves: RHEL-73914
- Allow initrc_t transition to passwd_t
Resolves: RHEL-71665
- Allow unconfined_service_t transition to passwd_t
Resolves: RHEL-71665
2025-01-16 21:45:16 +01:00
Zdenek Pytela
f64670faa3
* Wed Jan 08 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.21-1
...
- Allow init create vsock socket for sshd
Resolves: RHEL-72549
- Support ssh connections via systemd-ssh-generator
Resolves: RHEL-72549
- Allow ssh generator work with systemd unit files
Resolves: RHEL-72549
- Confine systemd system-ssh-generator
Resolves: RHEL-72549
- Allow login_userdomain getattr nsfs files
Resolves: RHEL-72549
- Allow virtqemud send a generic signal to the ssh client domain
Resolves: RHEL-53972
- Add the auth_dontaudit_read_passwd_file() interface
Resolves: RHEL-71490
- Dontaudit request-key read /etc/passwd
Resolves: RHEL-71490
2025-01-08 19:16:22 +01:00
Zdenek Pytela
e863f070bd
* Fri Jan 03 2025 Zdenek Pytela <zpytela@redhat.com> - 40.13.20-1
...
- Allow virtqemud domain transition on numad execution
Resolves: RHEL-65789
- Support virt live migration using ssh
Resolves: RHEL-53972
- Allow ssh_t read systemd config files
Resolves: RHEL-53972
- Allow virtqemud permissions needed for live migration
Resolves: RHEL-43217
- Allow virtqemud the getpgid process permission
Resolves: RHEL-46357
- Allow virtqemud manage nfs dirs when virt_use_nfs boolean is on
Resolves: RHEL-71068
- Allow virtqemud relabelfrom virt_log_t files
Resolves: RHEL-48236
- Allow virtqemud relabel tun_socket
Resolves: RHEL-71394
- Allow gnome-remote-desktop dbus chat with policykit
Resolves: RHEL-35877
- Update ktlsh policy
Resolves: RHEL-42672
- Confine the ktls service
Resolves: RHEL-42672
- Allow request-key to read /etc/passwd
Resolves: RHEL-71490
- Allow request-key to manage all domains' keys
Resolves: RHEL-71490
2025-01-03 16:59:30 +01:00
Petr Lautrbach
046dc6f583
* Fri Dec 20 2024 Petr Lautrbach <lautrbach@redhat.com> - 40.13.19-2
...
- Rebuild with SELinux Userspace 3.8
Resolves: RHEL-69451
2024-12-20 09:08:58 +01:00
Zdenek Pytela
9ffb04b099
* Wed Dec 18 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.19-1
...
- Allow systemd-journald getattr nsfs files
Resolves: RHEL-71803
- Allow systemd-related domains getattr nsfs files
Resolves: RHEL-71803
2024-12-18 23:43:40 +01:00
Zdenek Pytela
dfb01e2dd7
* Fri Dec 13 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.18-1
...
- Sync dist/targeted/modules.conf with Fedora 42
Resolves: RHEL-70850
- Add support for sap
Resolves: RHEL-70850
- Allow sssd_selinux_manager_t the setcap process permission
Resolves: RHEL-70822
- Allow virtqemud open svirt_devpts_t char files
Resolves: RHEL-43446
- Fix the cups_read_pid_files() interface to use read_files_pattern
Resolves: RHEL-69512
2024-12-13 17:43:37 +01:00
Zdenek Pytela
a789dba85b
* Thu Dec 12 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.17-1
...
- Update samba-bgqd policy
Resolves: RHEL-69512
- Allow samba-bgqd read cups config files
Resolves: RHEL-69512
- Allow virtqemud additional permissions for tmpfs_t blk devices
Resolves: RHEL-61235
- Allow virtqemud rw access to svirt_image_t chr files
Resolves: RHEL-61235
- Allow virtqemud rw and setattr access to fixed block devices
Resolves: RHEL-61235
- Label /etc/mdevctl.d/scripts.d with bin_t
Resolves: RHEL-39893
- Fix the /etc/mdevctl\.d(/.*)? regexp
Resolves: RHEL-39893
- Allow virtnodedev watch mdevctl config dirs
Resolves: RHEL-39893
- Make mdevctl_conf_t member of the file_type attribute
Resolves: RHEL-39893
- Label /etc/mdevctl.d with mdevctl_conf_t
Resolves: RHEL-39893
- Allow virtqemud relabelfrom virt_log_t files
Resolves: RHEL-48236
- Allow virtqemud_t relabel virtqemud_var_run_t sock_files
Resolves: RHEL-48236
- Allow virtqemud relabelfrom virtqemud_var_run_t dirs
Resolves: RHEL-48236
- Allow svirt_tcg_t read virtqemud_t fifo_files
Resolves: RHEL-48236
- Allow virtqemud rw and setattr access to sev devices
Resolves: RHEL-69128
- Allow virtqemud directly read and write to a fixed disk
Resolves: RHEL-61235
- Allow svirt_t the sys_rawio capability
Resolves: RHEL-61235
- Allow svirt_t the sys_rawio capability
Resolves: RHEL-61235
- Allow virtqemud connect to sanlock over a unix stream socket
Resolves: RHEL-44352
- allow gdm and iiosensorproxy talk to each other via D-bus
Resolves: RHEL-70850
- Allow sendmail to map mail server configuration files
Related: RHEL-54014
- Allow procmail to read mail aliases
Resolves: RHEL-54014
- Grant rhsmcertd chown capability & userdb access
Resolves: RHEL-68481
2024-12-12 21:18:45 +01:00
Zdenek Pytela
bfa35b4ec0
* Fri Nov 29 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.16-1
...
- Fix the file type for /run/systemd/generator
Resolves: RHEL-68313
2024-11-29 15:11:11 +01:00
Zdenek Pytela
d246bfd939
* Thu Nov 28 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.15-1
...
- Allow qatlib search the content of the kernel debugging filesystem
Resolves: RHEL-66334
- Allow qatlib connect to systemd-machined over a unix socket
Resolves: RHEL-66334
- Update policy for samba-bgqd
Resolves: RHEL-64908
- Allow httpd get attributes of dirsrv unit files
Resolves: RHEL-62706
- Allow virtstoraged read vm sysctls
Resolves: RHEL-61742
- Allow virtstoraged execute mount programs in the mount domain
Resolves: RHEL-61742
- Update policy for rpc-virtstorage
Resolves: RHEL-61742
- Allow virtstoraged get attributes of configfs dirs
Resolves: RHEL-61742
- Allow virt_driver_domain read virtd-lxc files in /proc
Resolves: RHEL-61742
- Allow virtstoraged manage files with virt_content_t type
Resolves: RHEL-61742
- Allow virtstoraged use the io_uring API
Resolves: RHEL-61742
- Allow virtstoraged execute lvm programs in the lvm domain
Resolves: RHEL-61742
- Allow svirt_t connect to unconfined_t over a unix domain socket
Resolves: RHEL-61246
- Label /usr/lib/node_modules_22/npm/bin with bin_t
Resolves: RHEL-56350
- Allow bacula execute container in the container domain
Resolves: RHEL-39529
- Label /run/systemd/generator with systemd_unit_file_t
Resolves: RHEL-68313
2024-11-28 22:16:34 +01:00
Zdenek Pytela
efbe8c4f78
* Tue Nov 19 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.14-1
...
- mls/modules.conf - fix typo
Related: RHEL-54303
- Use dist/targeted/modules.conf in build workflow
Related: RHEL-54303
- Fix default and dist config files
Related: RHEL-54303
- CI: update to actions/checkout@v4
Related: RHEL-54303
- Clean up and sync securetty_types
Related: RHEL-54303
- Bring config files from dist-git into the source repo
Related: RHEL-54303
- Sync users with Fedora targeted users
Related: RHEL-54303
2024-11-19 19:42:04 +01:00
Petr Lautrbach
698afe1ad8
Update sources
...
Recent dist-git changes require changes in
fedora-selinux/selinux-policy project which were already merged.
Related: RHEL-54303
[skip changelog]
2024-11-19 17:15:18 +01:00
Petr Lautrbach
1584866ea6
Use install instead of cp
...
and preserve timestamps using `install -p`
https://docs.fedoraproject.org/en-US/packaging-guidelines/#_timestamps
[skip changelog]
Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Petr Lautrbach
9f39950991
Remove old triggers
...
3.12.1-74 was released 2013
3.13.1-138 was release 2015
Both versions are not relevant anymore
[skip changelog]
Related: RHEL-54303
2024-11-14 17:16:04 +01:00
Petr Lautrbach
7dcb603438
Drop ru man pages
...
They were not updated since 2007
Related: RHEL-54303
2024-11-14 17:16:04 +01:00