SELinux policy configuration
Go to file
Zdenek Pytela da72c8245e * Fri Aug 21 2026 Zdenek Pytela <zpytela@redhat.com> - 42.1.27-1
- Label malware-detection-config.yml with insights_client_etc_rw_t
Resolves: RHEL-176040
- Add the files_write_system_conf_files() interface
Resolves: RHEL-176040
- Allow bluez dbus api pass sockets over dbus
Resolves: RHEL-227725
- Support sandboxing features for sysadm_t
Resolves: RHEL-227725
- Update dhcpc-hook policy
Resolves: RHEL-236646
- Allow dhcpc hook query the chronyd service
Resolves: RHEL-240723
- Support gnome-remote-desktop's smartcard redirection support
Resolves: RHEL-227725
- Allow gnome-remote-desktop read sssd public files
Resolves: RHEL-227725
- Allow gnome-remote-desktop connect to unreserved ports
Resolves: RHEL-227725
- Allow gnome-remote-desktop speak with tabrmd over dbus
Resolves: RHEL-227725
- Label /run/audit with auditd_var_run_t
Resolves: RHEL-224026
- Allow auditd manage its private run dirs
Resolves: RHEL-224026
- Allow virtqemud relabelfrom its private fifo files
Resolves: RHEL-222520
- Update the ssh_server_template() template
Resolves: RHEL-211174
Resolves: RHEL-240887
- Add rules for sshd vsock socket read/write
Resolves: RHEL-211174
- Allow sshd-auth/sshd-session get attributes of their sshd parent
Resolves: RHEL-211174
- Allow qatlib manage hugetlbfs directories
Resolves: RHEL-211089
- Allow sanlock the sys_admin capability
Resolves: RHEL-180192
- Allow lsmd-plugin use libStorageMgmt to provision storage
Resolves: RHEL-179467
- Allow insights-client read gconf home files
Resolves: RHEL-176040
- rhsmcertd: allow bootc/ostree transient package persistence detection
Resolves: RHEL-152111
- Allow rhsmcertd read the file_contexts files
Resolves: RHEL-152111
- Allow rhsmcertd read selinux config and default file contexts
Resolves: RHEL-152111
- Use NetworkManager_t instead of networkmanager_t
Resolves: RHEL-145714
2026-08-21 17:02:26 +02:00
.fmf Add plans/tests.fmf 2023-10-11 13:27:51 +02:00
plans selinux-policy: eliminate overlapping test plans 2025-08-25 13:11:18 +02:00
tests Revert "Add selinux-policy-epel test plan" 2025-05-21 10:03:23 +02:00
.gitignore * Mon Feb 12 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13-1 2024-02-12 12:26:33 +01:00
binsbin-convert.sh Replace "\_" (backslash underscore) with "_" (just underscore) 2026-04-30 10:50:37 +02:00
changelog * Fri Aug 21 2026 Zdenek Pytela <zpytela@redhat.com> - 42.1.27-1 2026-08-21 17:02:26 +02:00
COPYING remove extra level of directory 2006-07-12 20:32:27 +00:00
gating.yaml Drop baseos-ci gating 2024-05-21 11:09:54 +02:00
ifndefy.py Add a script for enclosing interfaces in ifndef statements 2022-06-29 18:34:21 +00:00
make-rhat-patches.sh Revert "Make make-rhat-patches.sh selinux-policy-epel aware" 2025-05-21 10:03:23 +02:00
Makefile.devel Hard code to MLSENABLED 2011-08-22 16:30:20 -04:00
modules-automotive.lst Add selinux-policy-automotive sub-package 2025-08-13 13:19:09 +02:00
modules-dropped.lst * Mon Jul 14 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.1-1 2025-07-14 17:07:34 +02:00
modules-extra.lst * Wed Jul 16 2025 Zdenek Pytela <zpytela@redhat.com> - 42.1.2-1 2025-07-16 17:05:53 +02:00
modules-minimum.lst Merge -base and -contrib 2024-11-14 17:16:04 +01:00
permissivedomains.cil Remove all domains from permissive domains, it looks these policies are tested already 2019-01-13 19:28:55 +01:00
process-modules-filtered.py Build selinux-policy-extra 2025-05-21 10:03:16 +02:00
readme-automotive Add selinux-policy-automotive sub-package 2025-08-13 13:19:09 +02:00
README.md Fix typos and grammar in README 2020-12-02 09:41:43 +01:00
rpm.macros Macros: Require only "stable" version of selinux-policy 2026-01-27 11:50:02 +01:00
selinux-check-proper-disable.service Add a systemd service to check that SELinux is disabled properly 2021-06-22 09:38:56 +00:00
selinux-policy-mls.conf Protect the targeted and mls subpackages 2024-11-14 17:14:03 +01:00
selinux-policy-targeted.conf Protect the targeted and mls subpackages 2024-11-14 17:14:03 +01:00
selinux-policy.conf We need to setcheckreqprot to 0 for security purposes 2015-04-16 14:00:38 -04:00
selinux-policy.spec * Fri Aug 21 2026 Zdenek Pytela <zpytela@redhat.com> - 42.1.27-1 2026-08-21 17:02:26 +02:00
sources * Fri Aug 21 2026 Zdenek Pytela <zpytela@redhat.com> - 42.1.27-1 2026-08-21 17:02:26 +02:00
varrun-convert.sh varrun-convert.sh: Backport changes from Rawhide 2024-11-14 17:14:03 +01:00

Purpose

SELinux Fedora Policy is a fork of the SELinux reference policy. The fedora-selinux/selinux-policy repo makes Fedora packaging simpler and more transparent for packagers, upstream developers, and users. It is used for applying downstream Fedora fixes, for communication about proposed/committed changes, and for communication with upstream and the community. It reflects the upstream repository structure to make submitting patches to upstream easy.

Structure

GitHub

On GitHub, we have one repository containing the policy sources.

$ cd selinux-policy
$ git remote -v
origin	git@github.com:fedora-selinux/selinux-policy.git (fetch)

$ git branch -r
origin/HEAD -> origin/master
origin/f27
origin/f28
origin/master
origin/rawhide

Note: As opposed to dist-git, the Rawhide content resides in the rawhide branch rather than master.

dist-git

Package sources in dist-git are composed from the selinux-policy repository snapshot tarball, container-selinux policy files snapshot, the macro-expander script snapshot, and from other config files.

Build process

  1. Clone the fedora-selinux/selinux-policy repository.

     $ cd ~/devel/github
     $ git clone git@github.com:fedora-selinux/selinux-policy.git
     $ cd selinux-policy
    
  2. Create, backport, or cherry-pick needed changes to a particular branch and push them.

  3. Clone the selinux-policy dist-git repository.

     $ cd ~/devel/dist-git
     $ fedpkg clone selinux-policy
     $ cd selinux-policy
    
  4. Download the latest snapshot from the selinux-policy GitHub repository.

     $ ./make-rhat-patches.sh
    
  5. Add changes to the dist-git repository, bump release, create a changelog entry, commit, and push.

  6. Build the package.

     $ fedpkg build