- Label malware-detection-config.yml with insights_client_etc_rw_t Resolves: RHEL-176040 - Add the files_write_system_conf_files() interface Resolves: RHEL-176040 - Allow bluez dbus api pass sockets over dbus Resolves: RHEL-227725 - Support sandboxing features for sysadm_t Resolves: RHEL-227725 - Update dhcpc-hook policy Resolves: RHEL-236646 - Allow dhcpc hook query the chronyd service Resolves: RHEL-240723 - Support gnome-remote-desktop's smartcard redirection support Resolves: RHEL-227725 - Allow gnome-remote-desktop read sssd public files Resolves: RHEL-227725 - Allow gnome-remote-desktop connect to unreserved ports Resolves: RHEL-227725 - Allow gnome-remote-desktop speak with tabrmd over dbus Resolves: RHEL-227725 - Label /run/audit with auditd_var_run_t Resolves: RHEL-224026 - Allow auditd manage its private run dirs Resolves: RHEL-224026 - Allow virtqemud relabelfrom its private fifo files Resolves: RHEL-222520 - Update the ssh_server_template() template Resolves: RHEL-211174 Resolves: RHEL-240887 - Add rules for sshd vsock socket read/write Resolves: RHEL-211174 - Allow sshd-auth/sshd-session get attributes of their sshd parent Resolves: RHEL-211174 - Allow qatlib manage hugetlbfs directories Resolves: RHEL-211089 - Allow sanlock the sys_admin capability Resolves: RHEL-180192 - Allow lsmd-plugin use libStorageMgmt to provision storage Resolves: RHEL-179467 - Allow insights-client read gconf home files Resolves: RHEL-176040 - rhsmcertd: allow bootc/ostree transient package persistence detection Resolves: RHEL-152111 - Allow rhsmcertd read the file_contexts files Resolves: RHEL-152111 - Allow rhsmcertd read selinux config and default file contexts Resolves: RHEL-152111 - Use NetworkManager_t instead of networkmanager_t Resolves: RHEL-145714 |
||
|---|---|---|
| .fmf | ||
| plans | ||
| tests | ||
| .gitignore | ||
| binsbin-convert.sh | ||
| changelog | ||
| COPYING | ||
| gating.yaml | ||
| ifndefy.py | ||
| make-rhat-patches.sh | ||
| Makefile.devel | ||
| modules-automotive.lst | ||
| modules-dropped.lst | ||
| modules-extra.lst | ||
| modules-minimum.lst | ||
| permissivedomains.cil | ||
| process-modules-filtered.py | ||
| readme-automotive | ||
| README.md | ||
| rpm.macros | ||
| selinux-check-proper-disable.service | ||
| selinux-policy-mls.conf | ||
| selinux-policy-targeted.conf | ||
| selinux-policy.conf | ||
| selinux-policy.spec | ||
| sources | ||
| varrun-convert.sh | ||
Purpose
SELinux Fedora Policy is a fork of the SELinux reference policy. The fedora-selinux/selinux-policy repo makes Fedora packaging simpler and more transparent for packagers, upstream developers, and users. It is used for applying downstream Fedora fixes, for communication about proposed/committed changes, and for communication with upstream and the community. It reflects the upstream repository structure to make submitting patches to upstream easy.
Structure
GitHub
On GitHub, we have one repository containing the policy sources.
$ cd selinux-policy
$ git remote -v
origin git@github.com:fedora-selinux/selinux-policy.git (fetch)
$ git branch -r
origin/HEAD -> origin/master
origin/f27
origin/f28
origin/master
origin/rawhide
Note: As opposed to dist-git, the Rawhide content resides in the rawhide branch rather than master.
dist-git
Package sources in dist-git are composed from the selinux-policy repository snapshot tarball, container-selinux policy files snapshot, the macro-expander script snapshot, and from other config files.
Build process
-
Clone the fedora-selinux/selinux-policy repository.
$ cd ~/devel/github $ git clone git@github.com:fedora-selinux/selinux-policy.git $ cd selinux-policy -
Create, backport, or cherry-pick needed changes to a particular branch and push them.
-
Clone the selinux-policy dist-git repository.
$ cd ~/devel/dist-git $ fedpkg clone selinux-policy $ cd selinux-policy -
Download the latest snapshot from the selinux-policy GitHub repository.
$ ./make-rhat-patches.sh -
Add changes to the dist-git repository, bump release, create a changelog entry, commit, and push.
-
Build the package.
$ fedpkg build