Compare commits
No commits in common. "c8" and "c9-beta" have entirely different histories.
@ -1 +1 @@
|
|||||||
02f70f06068fd32d7b9cd2394500e3eb8e7b1667 SOURCES/tpm2-abrmd-2.3.1.tar.gz
|
54a4c097520d6726fd19c04131dfafce2c4e6be8 SOURCES/tpm2-abrmd-2.3.1.tar.gz
|
||||||
|
@ -0,0 +1,68 @@
|
|||||||
|
From d319a1a6723ad20766c18964c289d47c06e19182 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Patrik Koncity <pkoncity@redhat.com>
|
||||||
|
Date: Fri, 19 Aug 2022 14:03:49 +0200
|
||||||
|
Subject: [PATCH 1/2] Add new interfaces for communication with keylime
|
||||||
|
|
||||||
|
Policy need rules to communicate with keylime.
|
||||||
|
|
||||||
|
AVC:
|
||||||
|
allow keylime_agent_t tabrmd_t:dbus send_msg;
|
||||||
|
allow keylime_agent_t tabrmd_t:unix_stream_socket { getattr getopt read write };
|
||||||
|
|
||||||
|
Create new interfaces to allow keylime
|
||||||
|
communicate with keylime.
|
||||||
|
|
||||||
|
Signed-off-by: Patrik Koncity <pkoncity@redhat.com>
|
||||||
|
---
|
||||||
|
selinux/tabrmd.if | 40 ++++++++++++++++++++++++++++++++++++++++
|
||||||
|
1 file changed, 40 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/selinux/tabrmd.if b/selinux/tabrmd.if
|
||||||
|
index 3eb6a30..c04eca0 100644
|
||||||
|
--- a/selinux/tabrmd.if
|
||||||
|
+++ b/selinux/tabrmd.if
|
||||||
|
@@ -1 +1,41 @@
|
||||||
|
## <summary></summary>
|
||||||
|
+
|
||||||
|
+########################################
|
||||||
|
+## <summary>
|
||||||
|
+## Create and use a unix stream socket
|
||||||
|
+## </summary>
|
||||||
|
+## <param name="domain">
|
||||||
|
+## <summary>
|
||||||
|
+## Domain allowed access.
|
||||||
|
+## </summary>
|
||||||
|
+## </param>
|
||||||
|
+#
|
||||||
|
+interface(`tabrmd_create_unix_stream_sockets',`
|
||||||
|
+ gen_require(`
|
||||||
|
+ type tabrmd_t;
|
||||||
|
+ ')
|
||||||
|
+
|
||||||
|
+ allow $1 tabrmd_t:unix_stream_socket create_stream_socket_perms;
|
||||||
|
+')
|
||||||
|
+
|
||||||
|
+########################################
|
||||||
|
+## <summary>
|
||||||
|
+## Send messages to and from
|
||||||
|
+## tabrmd over DBUS.
|
||||||
|
+## </summary>
|
||||||
|
+## <param name="domain">
|
||||||
|
+## <summary>
|
||||||
|
+## Domain allowed access.
|
||||||
|
+## </summary>
|
||||||
|
+## </param>
|
||||||
|
+#
|
||||||
|
+interface(`tabr,d_dbus_chat',`
|
||||||
|
+ gen_require(`
|
||||||
|
+ type tabrmd_t;
|
||||||
|
+ class dbus send_msg;
|
||||||
|
+ ')
|
||||||
|
+
|
||||||
|
+ allow $1 tabrmd_t:dbus send_msg;
|
||||||
|
+ allow tabrmd_t $1:dbus send_msg;
|
||||||
|
+')
|
||||||
|
+
|
||||||
|
--
|
||||||
|
2.39.0
|
||||||
|
|
29
SOURCES/0002-Fix-in-SELinux-interface-file-a-typo.patch
Normal file
29
SOURCES/0002-Fix-in-SELinux-interface-file-a-typo.patch
Normal file
@ -0,0 +1,29 @@
|
|||||||
|
From 64994388056b9b8c687eef3bc6030f2f40888440 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Patrik Koncity <pkoncity@redhat.com>
|
||||||
|
Date: Mon, 9 Jan 2023 12:30:42 +0100
|
||||||
|
Subject: [PATCH 2/2] Fix in SELinux interface file a typo
|
||||||
|
|
||||||
|
In name of interface in SELinux policy is
|
||||||
|
typo issue.
|
||||||
|
|
||||||
|
Signed-off-by: Patrik Koncity <pkoncity@redhat.com>
|
||||||
|
---
|
||||||
|
selinux/tabrmd.if | 2 +-
|
||||||
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/selinux/tabrmd.if b/selinux/tabrmd.if
|
||||||
|
index c04eca0..81c7853 100644
|
||||||
|
--- a/selinux/tabrmd.if
|
||||||
|
+++ b/selinux/tabrmd.if
|
||||||
|
@@ -29,7 +29,7 @@ interface(`tabrmd_create_unix_stream_sockets',`
|
||||||
|
## </summary>
|
||||||
|
## </param>
|
||||||
|
#
|
||||||
|
-interface(`tabr,d_dbus_chat',`
|
||||||
|
+interface(`tabrmd_dbus_chat',`
|
||||||
|
gen_require(`
|
||||||
|
type tabrmd_t;
|
||||||
|
class dbus send_msg;
|
||||||
|
--
|
||||||
|
2.39.0
|
||||||
|
|
@ -1,27 +1,32 @@
|
|||||||
# defining macros needed by SELinux
|
# defining macros needed by SELinux
|
||||||
%global selinuxtype targeted
|
%global selinuxtype targeted
|
||||||
%global selinux_policyver 3.14.1
|
%global selinux_policyver 3.14.3-22
|
||||||
%global moduletype contrib
|
%global moduletype contrib
|
||||||
%global modulename tabrmd
|
%global modulename tabrmd
|
||||||
|
|
||||||
Name: tpm2-abrmd-selinux
|
Name: tpm2-abrmd-selinux
|
||||||
Version: 2.3.1
|
Version: 2.3.1
|
||||||
Release: 1%{?dist}
|
Release: 7%{?dist}
|
||||||
Summary: SELinux policies for tpm2-abrmd
|
Summary: SELinux policies for tpm2-abrmd
|
||||||
|
|
||||||
License: BSD
|
License: BSD
|
||||||
URL: https://github.com/tpm2-software/tpm2-abrmd
|
URL: https://github.com/tpm2-software/tpm2-abrmd
|
||||||
Source0: https://github.com/tpm2-software/tpm2-abrmd/archive/%{version}/tpm2-abrmd-%{version}.tar.gz
|
Source0: https://github.com/tpm2-software/tpm2-abrmd/archive/%{version}/tpm2-abrmd-%{version}.tar.gz
|
||||||
|
|
||||||
Patch0: selinux-allow-fwupd-to-communicate-with-tpm2-abrmd.patch
|
Patch0: selinux-allow-fwupd-to-communicate-with-tpm2-abrmd.patch
|
||||||
|
Patch1: 0001-Add-new-interfaces-for-communication-with-keylime.patch
|
||||||
|
Patch2: 0002-Fix-in-SELinux-interface-file-a-typo.patch
|
||||||
|
|
||||||
BuildArch: noarch
|
BuildArch: noarch
|
||||||
Requires: selinux-policy >= %{selinux_policyver}
|
Requires: selinux-policy >= %{selinux_policyver}
|
||||||
Requires: selinux-policy-%{selinuxtype} >= %{selinux_policyver}
|
BuildRequires: make
|
||||||
BuildRequires: git
|
BuildRequires: git
|
||||||
BuildRequires: pkgconfig(systemd)
|
BuildRequires: pkgconfig(systemd)
|
||||||
BuildRequires: selinux-policy
|
BuildRequires: selinux-policy
|
||||||
BuildRequires: selinux-policy-devel
|
BuildRequires: selinux-policy-devel
|
||||||
Requires(pre): libselinux-utils
|
BuildRequires: selinux-policy-%{selinuxtype}
|
||||||
|
Requires(post): selinux-policy-base >= %{selinux_policyver}
|
||||||
|
Requires(post): libselinux-utils
|
||||||
Requires(post): policycoreutils
|
Requires(post): policycoreutils
|
||||||
Requires(post): policycoreutils-python-utils
|
Requires(post): policycoreutils-python-utils
|
||||||
|
|
||||||
@ -68,18 +73,49 @@ fi
|
|||||||
%{_datadir}/selinux/devel/include/%{moduletype}/%{modulename}.if
|
%{_datadir}/selinux/devel/include/%{moduletype}/%{modulename}.if
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
* Mon Nov 16 2020 Jerry Snitselaar <jsnitsel@redhat.com> - 2.3.3-1
|
* Fri Jan 6 2023 Štěpán Horáček <shoracek@redhat.com> - 2.3.1-7
|
||||||
- Rebase to 2.3.1 release
|
- Include interface for Keylime
|
||||||
resolves: rhbz#1898384
|
Resolves: rhbz#2157894
|
||||||
|
|
||||||
* Tue May 14 2019 Jerry Snitselaar <jsnitsel@redhat.com> - 2.0.0-3
|
* Tue Aug 10 2021 Mohan Boddu <mboddu@redhat.com> - 2.3.1-6
|
||||||
- Fix Requires issue.
|
- Rebuilt for IMA sigs, glibc 2.34, aarch64 flags
|
||||||
- Add initial CI gating support.
|
Related: rhbz#1991688
|
||||||
resolves: rhbz#1642000, rhbz#1682415
|
|
||||||
|
|
||||||
* Tue Sep 11 2018 Jerry Snitselaar <jsnitsel@redhat.com> - 2.0.0-2
|
* Fri Apr 16 2021 Mohan Boddu <mboddu@redhat.com> - 2.3.1-5
|
||||||
- Fix dependency
|
- Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937
|
||||||
resolves: rhbz#1628771
|
|
||||||
|
* Wed Feb 17 2021 Jerry Snitselaar <jsnitsel@redhat.com> - 2.3.1-4
|
||||||
|
- Fix dependency.
|
||||||
|
Resolves: rhbz#1929701
|
||||||
|
|
||||||
|
* Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org> - 2.3.1-3
|
||||||
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
|
||||||
|
|
||||||
|
* Wed Jul 29 2020 Fedora Release Engineering <releng@fedoraproject.org> - 2.3.1-2
|
||||||
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
|
||||||
|
|
||||||
|
* Wed Feb 12 2020 Javier Martinez Canillas <javierm@redhat.com> - 2.3.1-1
|
||||||
|
- Update to 2.3.1 release
|
||||||
|
|
||||||
|
* Fri Jan 31 2020 Fedora Release Engineering <releng@fedoraproject.org> - 2.1.0-4
|
||||||
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
|
||||||
|
|
||||||
|
* Sat Jul 27 2019 Fedora Release Engineering <releng@fedoraproject.org> - 2.1.0-3
|
||||||
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
|
||||||
|
|
||||||
|
* Fri Mar 08 2019 Javier Martinez Canillas <javierm@redhat.com> - 2.1.0-2
|
||||||
|
- selinux: allow tpm2-abrmd to communicate with fwupd
|
||||||
|
Resolves: rhbz#1665701
|
||||||
|
|
||||||
|
* Fri Feb 22 2019 Javier Martinez Canillas <javierm@redhat.com> - 2.1.0-1
|
||||||
|
- Update to 2.1.0 release
|
||||||
|
- Add selinux-policy-%{selinuxtype} BuildRequires
|
||||||
|
|
||||||
|
* Sun Feb 03 2019 Fedora Release Engineering <releng@fedoraproject.org> - 2.0.0-3
|
||||||
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
|
||||||
|
|
||||||
|
* Sat Jul 14 2018 Fedora Release Engineering <releng@fedoraproject.org> - 2.0.0-2
|
||||||
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
|
||||||
|
|
||||||
* Wed Jul 04 2018 Javier Martinez Canillas <javierm@redhat.com> - 2.0.0-1
|
* Wed Jul 04 2018 Javier Martinez Canillas <javierm@redhat.com> - 2.0.0-1
|
||||||
- Initial import (rhbz#1550595)
|
- Initial import (rhbz#1550595)
|
||||||
|
Loading…
Reference in New Issue
Block a user