Commit Graph

15 Commits

Author SHA256 Message Date
Johannes Segitz
1c8daaef72 Accepting request 1058004 from home:jsegitz:branches:security:SELinux
- Rename spc_timedated.patch to spc.patch
- Update spc.patch to allow privileged containers to use
  localectl (bsc#1207077)

OBS-URL: https://build.opensuse.org/request/show/1058004
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=25
2023-01-12 13:57:32 +00:00
Johannes Segitz
7b4d27d1e7 Accepting request 1057911 from home:jsegitz:branches:security:SELinux
- Add spc_timedated.patch to allow privileged containers to use
  timedatectl (bsc#1207054)

OBS-URL: https://build.opensuse.org/request/show/1057911
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=24
2023-01-12 07:15:56 +00:00
Johannes Segitz
8736328861 Accepting request 989141 from home:jsegitz:branches:security:SELinux
- Update to version 2.188.0:
  * Allow confined containers to mount overlay filesystems
  Fixed bsc#1201348

OBS-URL: https://build.opensuse.org/request/show/989141
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=23
2022-07-14 11:30:25 +00:00
Johannes Segitz
e144fec934 Accepting request 984493 from home:fcrozat:branches:security:SELinux
- Update to version 2.187.0:
  * Allow container domains to use /dev/zero
- Changes from 2.186.0:
  * Create policy for a container_device_t 
  * Allow containers to shutdown & setopt userdomain:sockets
- Changes from 2.183.0:
  * Allow containers to inherit all socket classes from container runtimes.
- Changes from 2.182.0:
  * Allow containers to inherit all socket classes
- Changes from 2.181.0:
  * Allow socket activated domains for tcp sockets from init_t and userdomains.

OBS-URL: https://build.opensuse.org/request/show/984493
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=22
2022-06-27 07:58:47 +00:00
Thorsten Kukuk
eedde80a11 Accepting request 963880 from home:jsegitz:branches:security:SELinux
- Add udica templates to the package

OBS-URL: https://build.opensuse.org/request/show/963880
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=19
2022-03-24 10:24:18 +00:00
8c94cb033f Accepting request 962680 from home:jsegitz:branches:security:SELinux
- Update to version 2.180.0
  * Allow container domains to read/write kvm_device_t
  * Update kublet mappings to inlcude /usr/local/*
  * Allow container domains to use container runtime tcp and udp sockets
  * Alow containers to use unix_stream_sockets leaked from container runtimes
  * Allow userdomains to execute conmon_exec_t and use it as an entrypoint
  * Allow conmon_exec_t as an entrypoint
  * Add container_use_devices boolean to allow containers to use any device
  * Add explicit range transition for conmon
  * Add missing dbus class declaration into container_runtime_run()
  * Remove lockdown allow rules
  * Remove k3s fcontexts
  * Allow container domains to be used by user roles
- Changed source url to allow for download via source service

OBS-URL: https://build.opensuse.org/request/show/962680
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=17
2022-03-18 12:50:10 +00:00
Johannes Segitz
b28e2b3d9b Accepting request 931165 from home:RBrownSUSE:branches:security:SELinux
- Update to version 2.171.0
  * Define kubernetes_file_t as a config_type
  * Allow containers to be socket activated by user domains and by systemd.
  * Allow iptables to use fifo files of a container runtime
  * Allow container_runtime create all tmpfs content as container_runtime_tmpfs_t
  * Allow containers to create lnk_file on tmpfs_t directories.

OBS-URL: https://build.opensuse.org/request/show/931165
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=16
2021-11-15 07:33:53 +00:00
Thorsten Kukuk
4931cb6840 Accepting request 910787 from home:jsegitz:branches:security:SELinux
- Update to version 2.164.2
  * Don't setup users for writing to pid_sockets
  * Allow container engines to be started from the staff user.
  * Allow spc_t domains to set bpf rules on any domain
  * Add support for k3s

OBS-URL: https://build.opensuse.org/request/show/910787
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=15
2021-08-09 08:25:05 +00:00
Thorsten Kukuk
18aae90282 Accepting request 887959 from home:jsegitz:branches:security:SELinux
- Fix container runtime binary labels (bsc#1185030). You need to 
  relable at least /usr/sbin if you're affected

OBS-URL: https://build.opensuse.org/request/show/887959
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=13
2021-04-23 09:14:49 +00:00
Thorsten Kukuk
52d91d79b9 Accepting request 874614 from home:kukuk:selinux
- Update to version 2.158.0
  - Add nfs remount support
  - Allow containers to execmod on nfs, samba and cephs remote shares
  - Allow confined users to send dbus messages to container_runtime

OBS-URL: https://build.opensuse.org/request/show/874614
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=11
2021-02-24 13:31:37 +00:00
Thorsten Kukuk
68e1a8db01 Accepting request 862253 from home:kukuk:selinux
- Update to version 2.154.0
  - Allow confined user domains to run confined container domains.
  - Allow all containers to use nfs shares, iff virt_use_nfs boolean
    is enabled.
  - Allow containers to read nsfs file systems.
  - KVM Container need to use tunnel sockets created by runtime.

OBS-URL: https://build.opensuse.org/request/show/862253
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=9
2021-01-11 10:50:48 +00:00
Thorsten Kukuk
12002ddbe2 Accepting request 845598 from home:lnussel:branches:security:SELinux
- Don't use BuildRequires based on shell script output. OBS can't
  evaluate that.

OBS-URL: https://build.opensuse.org/request/show/845598
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=7
2020-11-04 07:41:50 +00:00
Thorsten Kukuk
377a7bce44 Accepting request 844785 from home:kukuk:selinux
- Update to version 2.150.0
  - Add additional allow rules for kvm based containers using
    virtiofsd.

OBS-URL: https://build.opensuse.org/request/show/844785
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=5
2020-10-29 10:32:01 +00:00
Thorsten Kukuk
e81a64dc03 Accepting request 841778 from home:kukuk:selinux
- Update to version 2.145.0
  - Add support for kubernetes_file_t
  - Allow container_t to open existing tun/tap

OBS-URL: https://build.opensuse.org/request/show/841778
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=3
2020-10-16 09:26:37 +00:00
7beff29edb Accepting request 825950 from home:kukuk:selinux
This package is needed to run Container with SELinux enabled

OBS-URL: https://build.opensuse.org/request/show/825950
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=1
2020-08-20 10:56:37 +00:00