- Add the systemd_logind_stream_connect() interface Resolves: RHEL-163438 - Add files_mounton_generic_tmp_dirs() interface Resolves: RHEL-163438 - Allow staff user mounton /var/lib dirs Resolves: RHEL-163438 - Allow staff user read nsfs files Resolves: RHEL-163438 - Allow staff user additional sandboxing permissions Resolves: RHEL-163438 - Allow staff_sudo_t read PID1's process state Resolves: RHEL-163438 - Allow staff_sudo_t read logind sessions files Resolves: RHEL-163438 - Allow staff user delete thump_tmp_t files Resolves: RHEL-163438 - Allow login_userdomain read thumb tmp files Resolves: RHEL-163438 - Allow staff user connect to systemd-logind over a unix stream socket Resolves: RHEL-163438 - Allow staff user mount /proc Resolves: RHEL-163438 - Support confined users usage of bubblewrap Resolves: RHEL-163438 - Add anaconda_ioctl_fifo_files_install() and anaconda_write_fifo_files_install() Resolves: RHEL-179125 - Allow rhsmcertd read anaconda run files Resolves: RHEL-179125 - Allow any domain to inherit fds from rpm-ostree Resolves: RHEL-179125 - Allow install_t domain transition to insights_client_t Resolves: RHEL-179125 - Allow logrotate stop all systemd services Resolves: RHEL-169534 - Allow staff and sysadm execute iotop using sudo Resolves: RHEL-172235 - Allow sysadm_t to connect to iscsid using a unix domain stream socket Resolves: RHEL-155605 |
||
|---|---|---|
| .fmf | ||
| plans | ||
| tests | ||
| .gitignore | ||
| booleans-automotive.conf | ||
| booleans-minimum.conf | ||
| booleans-mls.conf | ||
| booleans-targeted.conf | ||
| booleans.subs_dist | ||
| COPYING | ||
| customizable_types | ||
| file_contexts.subs_dist | ||
| gating.yaml | ||
| ifndefy.py | ||
| make-rhat-patches.sh | ||
| Makefile.devel | ||
| modules-automotive-base.conf | ||
| modules-automotive-contrib.conf | ||
| modules-minimum.conf | ||
| modules-mls-base.conf | ||
| modules-mls-contrib.conf | ||
| modules-targeted-base.conf | ||
| modules-targeted-contrib.conf | ||
| modules-targeted.conf | ||
| permissivedomains.cil | ||
| readme-automotive | ||
| README.md | ||
| rpm.macros | ||
| securetty_types-automotive | ||
| securetty_types-minimum | ||
| securetty_types-mls | ||
| securetty_types-targeted | ||
| selinux-check-proper-disable.service | ||
| selinux-policy.conf | ||
| selinux-policy.spec | ||
| setrans-automotive.conf | ||
| setrans-minimum.conf | ||
| setrans-mls.conf | ||
| setrans-targeted.conf | ||
| sources | ||
| users-automotive | ||
| users-minimum | ||
| users-mls | ||
| users-targeted | ||
Purpose
SELinux Fedora Policy is a fork of the SELinux reference policy. The fedora-selinux/selinux-policy repo makes Fedora packaging simpler and more transparent for packagers, upstream developers, and users. It is used for applying downstream Fedora fixes, for communication about proposed/committed changes, and for communication with upstream and the community. It reflects the upstream repository structure to make submitting patches to upstream easy.
Structure
GitHub
On GitHub, we have one repository containing the policy sources.
$ cd selinux-policy
$ git remote -v
origin git@github.com:fedora-selinux/selinux-policy.git (fetch)
$ git branch -r
origin/HEAD -> origin/master
origin/f27
origin/f28
origin/master
origin/rawhide
Note: As opposed to dist-git, the Rawhide content resides in the rawhide branch rather than master.
dist-git
Package sources in dist-git are composed from the selinux-policy repository snapshot tarball, container-selinux policy files snapshot, the macro-expander script snapshot, and from other config files.
Build process
-
Clone the fedora-selinux/selinux-policy repository.
$ cd ~/devel/github $ git clone git@github.com:fedora-selinux/selinux-policy.git $ cd selinux-policy -
Create, backport, or cherry-pick needed changes to a particular branch and push them.
-
Clone the selinux-policy dist-git repository.
$ cd ~/devel/dist-git $ fedpkg clone selinux-policy $ cd selinux-policy -
Download the latest snapshot from the selinux-policy GitHub repository.
$ ./make-rhat-patches.sh -
Add changes to the dist-git repository, bump release, create a changelog entry, commit, and push.
-
Build the package.
$ fedpkg build