Ana Guerrero
8889c27875
Accepting request 1112592 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/1112592
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=19
2023-10-02 18:04:17 +00:00
Johannes Segitz
e5b095d9d9
Accepting request 1112591 from home:jsegitz:branches:security:SELinux
...
- Update to version 2.222:
* Allow containers to read/write inherited dri devices
OBS-URL: https://build.opensuse.org/request/show/1112591
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=32
2023-09-20 14:52:16 +00:00
Johannes Segitz
389144f849
* Allow containers to shutdown sockets inherited from container
...
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=31
2023-08-15 13:17:33 +00:00
Johannes Segitz
96428a8f56
Accepting request 1103976 from home:jsegitz:branches:security:SELinux
...
- Update to version 2.221:
* Allow containers to shutdown sockets inheritted from container
runtimes
* Allow spc_t to use execmod libraries on container file systems
* Add boolean to allow containers to read all cert files
* More MLS Policy allow rules
* Allow container runtimes using pasta bind icmp_socket to port_t
* Fix spc_t transitions from container_runtime_domain
OBS-URL: https://build.opensuse.org/request/show/1103976
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=30
2023-08-15 06:16:42 +00:00
Dominique Leuenberger
7049bbaf6b
Accepting request 1088560 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/1088560
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=18
2023-05-24 18:21:48 +00:00
Johannes Segitz
886f9a51c0
Accepting request 1088558 from home:jsegitz:branches:security:SELinux
...
- Update to version 2.215.0:
* Add some MLS rules to policy
* Allow container runtime to dyntransition to spc_t
* Tighten controls on confined users
* Add labels for /var/lib/shared
* Cleanup entrypoint definitions
* Allow container_device_plugin_t access to debugfs
* Allow containers which use devices to map them
OBS-URL: https://build.opensuse.org/request/show/1088558
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=29
2023-05-23 08:12:11 +00:00
Dominique Leuenberger
ccbc25bb93
Accepting request 1082387 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/1082387
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=17
2023-04-25 14:53:19 +00:00
Johannes Segitz
1793c5b289
Accepting request 1082386 from home:jsegitz:branches:security:SELinux
...
- Update to version 2.211.0:
* Don't transition to initrc_t domains from spc_t
* Add tunable to allow sshd_t to launch container engines
* Allow syslogd_t gettatr on inheritited runtime tmpfs files
* Add container_file_t and container_ro_file_t as user_home_type
* Set default context for local-path-provisioner
* Allow daemon to send dbus messages to spc_t by
OBS-URL: https://build.opensuse.org/request/show/1082386
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=28
2023-04-24 08:23:40 +00:00
Dominique Leuenberger
60cae76669
Accepting request 1075436 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/1075436
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=16
2023-03-31 19:15:06 +00:00
Johannes Segitz
1d09fb5b55
Accepting request 1075435 from home:jsegitz:branches:security:SELinux
...
- Update to version 2.206.0:
* Allow unconfined domains to transition to container_runtime_t
* Allow container domains to transition to install_t
* Allow avirt_sandbox_domain to manage container_file_t types
* Allow containers to watch sysfs_t directories
* Allow spc_t to transption to rpm_script_t
* Add support to new user_namespace access check
* Smaller permission changes for container_init_t
- Drop spc.patch, is now included
OBS-URL: https://build.opensuse.org/request/show/1075435
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=27
2023-03-30 07:03:23 +00:00
Dominique Leuenberger
0000f5ee1e
Accepting request 1059620 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/1059620
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=15
2023-01-20 16:38:16 +00:00
Johannes Segitz
25cd1634d4
Accepting request 1058701 from home:fcrozat:branches:security:SELinux
...
- Update to version 2.198.0:
* Fix spc_t transition rules on tmpfs_t
- Changes from 2.197.0:
* Add boolean containers_use_ecryptfs policy
- Changes from 2.195.1:
* Readd missing allow rules for container_t
- Changes from 2.194.0:
* Allow syslogd_t to use tmpfs files created by container runtime
- Changes from 2.193.0:
* Allow containers to mount tmpfs_t file systems
* Label spc_t as a init initrc daemon
* Allow userdomains to run containers
- Changes from 2.191.0:
* Create container_logwriter_t type
- Changes from 2.190.1:
* Support BuildKit
* container.fc: Set label for kata-agent
* support nerdctl
- Changes from 2.190.0:
* Packit: initial enablement
* Allow iptables to list directories labeled as container_file_t
- Changes from 2.189.0:
* Dont audit searching other processes in /proc.
OBS-URL: https://build.opensuse.org/request/show/1058701
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=26
2023-01-19 15:12:14 +00:00
Dominique Leuenberger
121dff4bb7
Accepting request 1058005 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/1058005
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=14
2023-01-14 19:30:42 +00:00
Johannes Segitz
1c8daaef72
Accepting request 1058004 from home:jsegitz:branches:security:SELinux
...
- Rename spc_timedated.patch to spc.patch
- Update spc.patch to allow privileged containers to use
localectl (bsc#1207077)
OBS-URL: https://build.opensuse.org/request/show/1058004
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=25
2023-01-12 13:57:32 +00:00
Johannes Segitz
7b4d27d1e7
Accepting request 1057911 from home:jsegitz:branches:security:SELinux
...
- Add spc_timedated.patch to allow privileged containers to use
timedatectl (bsc#1207054)
OBS-URL: https://build.opensuse.org/request/show/1057911
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=24
2023-01-12 07:15:56 +00:00
Richard Brown
89329a03ee
Accepting request 989144 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/989144
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=13
2022-07-18 16:32:44 +00:00
Johannes Segitz
8736328861
Accepting request 989141 from home:jsegitz:branches:security:SELinux
...
- Update to version 2.188.0:
* Allow confined containers to mount overlay filesystems
Fixed bsc#1201348
OBS-URL: https://build.opensuse.org/request/show/989141
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=23
2022-07-14 11:30:25 +00:00
Johannes Segitz
e144fec934
Accepting request 984493 from home:fcrozat:branches:security:SELinux
...
- Update to version 2.187.0:
* Allow container domains to use /dev/zero
- Changes from 2.186.0:
* Create policy for a container_device_t
* Allow containers to shutdown & setopt userdomain:sockets
- Changes from 2.183.0:
* Allow containers to inherit all socket classes from container runtimes.
- Changes from 2.182.0:
* Allow containers to inherit all socket classes
- Changes from 2.181.0:
* Allow socket activated domains for tcp sockets from init_t and userdomains.
OBS-URL: https://build.opensuse.org/request/show/984493
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=22
2022-06-27 07:58:47 +00:00
Dominique Leuenberger
71c64dc840
osc copypac from project:home:fcrozat:branches:security:SELinux package:container-selinux revision:2, using expand
...
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=12
2022-06-22 14:18:16 +00:00
Dominique Leuenberger
9582578ebb
Accepting request 964617 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/964617
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=11
2022-03-28 14:58:29 +00:00
Thorsten Kukuk
eedde80a11
Accepting request 963880 from home:jsegitz:branches:security:SELinux
...
- Add udica templates to the package
OBS-URL: https://build.opensuse.org/request/show/963880
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=19
2022-03-24 10:24:18 +00:00
Dominique Leuenberger
40afefed5c
Accepting request 962685 from security:SELinux
...
- Update to version 2.180.0
* Allow container domains to read/write kvm_device_t
* Update kublet mappings to inlcude /usr/local/*
* Allow container domains to use container runtime tcp and udp sockets
* Alow containers to use unix_stream_sockets leaked from container runtimes
* Allow userdomains to execute conmon_exec_t and use it as an entrypoint
* Allow conmon_exec_t as an entrypoint
* Add container_use_devices boolean to allow containers to use any device
* Add explicit range transition for conmon
* Add missing dbus class declaration into container_runtime_run()
* Remove lockdown allow rules
* Remove k3s fcontexts
* Allow container domains to be used by user roles
- Changed source url to allow for download via source service (forwarded request 962680 from jsegitz)
OBS-URL: https://build.opensuse.org/request/show/962685
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=10
2022-03-20 19:54:43 +00:00
8c94cb033f
Accepting request 962680 from home:jsegitz:branches:security:SELinux
...
- Update to version 2.180.0
* Allow container domains to read/write kvm_device_t
* Update kublet mappings to inlcude /usr/local/*
* Allow container domains to use container runtime tcp and udp sockets
* Alow containers to use unix_stream_sockets leaked from container runtimes
* Allow userdomains to execute conmon_exec_t and use it as an entrypoint
* Allow conmon_exec_t as an entrypoint
* Add container_use_devices boolean to allow containers to use any device
* Add explicit range transition for conmon
* Add missing dbus class declaration into container_runtime_run()
* Remove lockdown allow rules
* Remove k3s fcontexts
* Allow container domains to be used by user roles
- Changed source url to allow for download via source service
OBS-URL: https://build.opensuse.org/request/show/962680
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=17
2022-03-18 12:50:10 +00:00
Dominique Leuenberger
0c09f8870f
Accepting request 931472 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/931472
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=9
2021-11-20 01:38:03 +00:00
Johannes Segitz
b28e2b3d9b
Accepting request 931165 from home:RBrownSUSE:branches:security:SELinux
...
- Update to version 2.171.0
* Define kubernetes_file_t as a config_type
* Allow containers to be socket activated by user domains and by systemd.
* Allow iptables to use fifo files of a container runtime
* Allow container_runtime create all tmpfs content as container_runtime_tmpfs_t
* Allow containers to create lnk_file on tmpfs_t directories.
OBS-URL: https://build.opensuse.org/request/show/931165
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=16
2021-11-15 07:33:53 +00:00
Richard Brown
82f865e98c
Accepting request 910793 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/910793
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=8
2021-08-12 07:01:02 +00:00
Thorsten Kukuk
4931cb6840
Accepting request 910787 from home:jsegitz:branches:security:SELinux
...
- Update to version 2.164.2
* Don't setup users for writing to pid_sockets
* Allow container engines to be started from the staff user.
* Allow spc_t domains to set bpf rules on any domain
* Add support for k3s
OBS-URL: https://build.opensuse.org/request/show/910787
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=15
2021-08-09 08:25:05 +00:00
Dominique Leuenberger
810788a782
Accepting request 887982 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/887982
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=7
2021-04-26 14:38:51 +00:00
Thorsten Kukuk
18aae90282
Accepting request 887959 from home:jsegitz:branches:security:SELinux
...
- Fix container runtime binary labels (bsc#1185030). You need to
relable at least /usr/sbin if you're affected
OBS-URL: https://build.opensuse.org/request/show/887959
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=13
2021-04-23 09:14:49 +00:00
Richard Brown
44a892dee2
Accepting request 874863 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/874863
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=6
2021-03-02 11:27:48 +00:00
Thorsten Kukuk
52d91d79b9
Accepting request 874614 from home:kukuk:selinux
...
- Update to version 2.158.0
- Add nfs remount support
- Allow containers to execmod on nfs, samba and cephs remote shares
- Allow confined users to send dbus messages to container_runtime
OBS-URL: https://build.opensuse.org/request/show/874614
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=11
2021-02-24 13:31:37 +00:00
Dominique Leuenberger
a5bd8876ef
Accepting request 862254 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/862254
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=5
2021-01-15 18:44:14 +00:00
Thorsten Kukuk
68e1a8db01
Accepting request 862253 from home:kukuk:selinux
...
- Update to version 2.154.0
- Allow confined user domains to run confined container domains.
- Allow all containers to use nfs shares, iff virt_use_nfs boolean
is enabled.
- Allow containers to read nsfs file systems.
- KVM Container need to use tunnel sockets created by runtime.
OBS-URL: https://build.opensuse.org/request/show/862253
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=9
2021-01-11 10:50:48 +00:00
Dominique Leuenberger
f464c12f13
Accepting request 845892 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/845892
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=4
2020-11-06 22:42:45 +00:00
Thorsten Kukuk
12002ddbe2
Accepting request 845598 from home:lnussel:branches:security:SELinux
...
- Don't use BuildRequires based on shell script output. OBS can't
evaluate that.
OBS-URL: https://build.opensuse.org/request/show/845598
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=7
2020-11-04 07:41:50 +00:00
Dominique Leuenberger
d07345c7ea
Accepting request 844834 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/844834
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=3
2020-11-02 08:40:20 +00:00
Thorsten Kukuk
377a7bce44
Accepting request 844785 from home:kukuk:selinux
...
- Update to version 2.150.0
- Add additional allow rules for kvm based containers using
virtiofsd.
OBS-URL: https://build.opensuse.org/request/show/844785
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=5
2020-10-29 10:32:01 +00:00
Dominique Leuenberger
26a75112fd
Accepting request 842071 from security:SELinux
...
OBS-URL: https://build.opensuse.org/request/show/842071
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=2
2020-10-20 14:00:25 +00:00
Thorsten Kukuk
e81a64dc03
Accepting request 841778 from home:kukuk:selinux
...
- Update to version 2.145.0
- Add support for kubernetes_file_t
- Allow container_t to open existing tun/tap
OBS-URL: https://build.opensuse.org/request/show/841778
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=3
2020-10-16 09:26:37 +00:00
Dominique Leuenberger
f674550fbd
Accepting request 840502 from security:SELinux
...
Required to run containers on a SELinux enabled system.
OBS-URL: https://build.opensuse.org/request/show/840502
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=1
2020-10-10 17:03:43 +00:00
7beff29edb
Accepting request 825950 from home:kukuk:selinux
...
This package is needed to run Container with SELinux enabled
OBS-URL: https://build.opensuse.org/request/show/825950
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=1
2020-08-20 10:56:37 +00:00