1
0

64 Commits

Author SHA256 Message Date
7e1c88062a Accepting request 1297768 from security:SELinux
update to 2.240.0

OBS-URL: https://build.opensuse.org/request/show/1297768
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=30
2025-08-06 12:31:36 +00:00
Hu
6b164d4af3 - Update to version 2.240.0:
* Dontaudit dac_override for iptables_t
    * dropping rootless-docker_iptables.patch is upstream
  * Don't allow containers by default setexec setfscreate
  * Containers need to use hsa devices for ROCM

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=47
2025-08-05 14:36:42 +00:00
648cacb039 Accepting request 1296255 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1296255
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=29
2025-07-30 09:41:40 +00:00
3bc4afa6a2 currently a draft for upstream, ready in case there is urgency with SLE16
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=46
2025-07-29 07:39:59 +00:00
0dd6633895 Accepting request 1290993 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1290993
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=28
2025-07-08 13:28:13 +00:00
Johannes Segitz
c0548fca91 - Update to version 2.239.0:
* Allow containers to use hsa devices for ROCM

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=45
2025-07-07 08:47:09 +00:00
99ed30ae4d Accepting request 1281761 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1281761
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=27
2025-06-03 15:50:19 +00:00
Johannes Segitz
73b1a0d6ea - Update to version 2.238.0:
* label /run/sysctl.d correctly on creation

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=44
2025-06-02 07:20:10 +00:00
c7e49842dc Accepting request 1273366 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1273366
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=26
2025-04-30 17:02:39 +00:00
Johannes Segitz
da714098f0 - Update to version 2.237.0:
* bootc/install_t: allow transition to container_runtime_t
  * Allow containers to mask parts of their /proc

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=43
2025-04-29 08:53:38 +00:00
88af38b286 Accepting request 1265900 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1265900
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=25
2025-04-02 15:07:42 +00:00
Johannes Segitz
5f498f6eac - Update to version 2.236.0:
* Allow super privileged containers to use RealtimeKit for scheduling
  * Add container_ro_file_t to the podman artifact store

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=42
2025-03-31 13:15:32 +00:00
1461d30756 Accepting request 1251751 from security:SELinux
update

OBS-URL: https://build.opensuse.org/request/show/1251751
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=24
2025-03-11 19:43:58 +00:00
Hu
2637d8f52b - Update to version 2.235.0:
* Bump to v2.235.0
  * OWNERS: add wrabcak and zpytela
  * OWNERS: initial commit
  * container_log{reader,writer}_t: allow watch file
  * RPM: Update gating config
  * Enable aarch64 testing
  * TMT: simplify podman tests
  * feat: support /var/lib/crio

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=41
2025-03-07 15:30:54 +00:00
Hu
e7903160b6 Accepting request 1243135 from home:rfrohl:branches:security:SELinux
fix _service file

OBS-URL: https://build.opensuse.org/request/show/1243135
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=40
2025-02-04 15:43:03 +00:00
9c4881f7d7 Accepting request 1236910 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1236910
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=23
2025-01-12 10:09:53 +00:00
0e19467c12 container-selinux: 2.234.2 + man page
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=39
2025-01-10 16:19:24 +00:00
Hu
b846d75346 - Add BuildRequires selinux-policy-%{selinuxtype} to enable building
for SLFO. Might be removed in the future again when 1231252
  is fixed.

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=38
2025-01-09 14:23:53 +00:00
8c46c4c2ab Accepting request 1227115 from security:SELinux
container-selinux october update

OBS-URL: https://build.opensuse.org/request/show/1227115
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=22
2024-11-30 12:27:11 +00:00
Hu
174e42eff7 Accepting request 1222444 from home:cahu:security:SELinux:policyupdate102024-2
- Update to version 2.233.0:
  * container_engine_t: small change to allow non root exec in a container
  * RPM: explicitly list ghosted paths and skip mode verification
  * container-selinux install on non selinux-policy-targeted systems (#332)
  * set container_log_t type for /var/log/kube-apiserver
  * Allow kubelet_t to create a sock file kubelet_var_lib_t
  * dontaudit spc_t to mmap_zero
  * Packit: update targets (#330)
  * container_engine_t: another round of small improvements (#327)
  * Allow container_device_plugin_t to use the network (#325)
  * RPM: cleanup changelog (#324)
  * TMT: Simplify tests

OBS-URL: https://build.opensuse.org/request/show/1222444
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=37
2024-11-14 10:21:53 +00:00
0f9d68f895 Accepting request 1186819 from security:SELinux
container-selinux update

OBS-URL: https://build.opensuse.org/request/show/1186819
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=21
2024-07-14 06:48:57 +00:00
8a42958a15 Accepting request 1138077 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1138077
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=20
2024-01-12 22:44:15 +00:00
Johannes Segitz
8f38ed6e53 Accepting request 1138075 from home:jsegitz:branches:security:SELinux
- Update to version 2.228:
  * Allow container domains to watch fifo_files
  * container_engine_t: improve for podman in kubernetes case
  * Allow spc_t to transition to install_t domain
  * Default to allowing containers to use dri devices
  * Allow access to BPF Filesystems
  * Fix kubernetes transition rule
  * Label kubensenter as well as kubenswrapper
  * Allow container domains to execute container_runtime_tmpfs_t files
  * Allow container domains to ptrace themselves
  * Allow container domains to use container_runtime_tmpfs_t as an entrypoint
  * Add boolean to allow containers to use dri devices
  * Give containers access to pod resources endpoint
  * Label kubenswrapper kubelet_exec_t

OBS-URL: https://build.opensuse.org/request/show/1138075
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=33
2024-01-11 08:53:20 +00:00
8889c27875 Accepting request 1112592 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1112592
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=19
2023-10-02 18:04:17 +00:00
Johannes Segitz
e5b095d9d9 Accepting request 1112591 from home:jsegitz:branches:security:SELinux
- Update to version 2.222:
  * Allow containers to read/write inherited dri devices

OBS-URL: https://build.opensuse.org/request/show/1112591
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=32
2023-09-20 14:52:16 +00:00
Johannes Segitz
389144f849 * Allow containers to shutdown sockets inherited from container
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=31
2023-08-15 13:17:33 +00:00
Johannes Segitz
96428a8f56 Accepting request 1103976 from home:jsegitz:branches:security:SELinux
- Update to version 2.221:
  * Allow containers to shutdown sockets inheritted from container
    runtimes
  * Allow spc_t to use execmod libraries on container file systems
  * Add boolean to allow containers to read all cert files
  * More MLS Policy allow rules
  * Allow container runtimes using pasta bind icmp_socket to port_t
  * Fix spc_t transitions from container_runtime_domain

OBS-URL: https://build.opensuse.org/request/show/1103976
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=30
2023-08-15 06:16:42 +00:00
7049bbaf6b Accepting request 1088560 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1088560
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=18
2023-05-24 18:21:48 +00:00
Johannes Segitz
886f9a51c0 Accepting request 1088558 from home:jsegitz:branches:security:SELinux
- Update to version 2.215.0:
  * Add some MLS rules to policy
  * Allow container runtime to dyntransition to spc_t
  * Tighten controls on confined users
  * Add labels for /var/lib/shared
  * Cleanup entrypoint definitions
  * Allow container_device_plugin_t access to debugfs
  * Allow containers which use devices to map them

OBS-URL: https://build.opensuse.org/request/show/1088558
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=29
2023-05-23 08:12:11 +00:00
ccbc25bb93 Accepting request 1082387 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1082387
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=17
2023-04-25 14:53:19 +00:00
Johannes Segitz
1793c5b289 Accepting request 1082386 from home:jsegitz:branches:security:SELinux
- Update to version 2.211.0:
  * Don't transition to initrc_t domains from spc_t
  * Add tunable to allow sshd_t to launch container engines
  * Allow syslogd_t gettatr on inheritited runtime tmpfs files
  * Add container_file_t and container_ro_file_t as user_home_type
  * Set default context for local-path-provisioner
  * Allow daemon to send dbus messages to spc_t by

OBS-URL: https://build.opensuse.org/request/show/1082386
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=28
2023-04-24 08:23:40 +00:00
60cae76669 Accepting request 1075436 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1075436
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=16
2023-03-31 19:15:06 +00:00
Johannes Segitz
1d09fb5b55 Accepting request 1075435 from home:jsegitz:branches:security:SELinux
- Update to version 2.206.0:
  * Allow unconfined domains to transition to container_runtime_t 
  * Allow container domains to transition to install_t  
  * Allow avirt_sandbox_domain to manage container_file_t types 
  * Allow containers to watch sysfs_t directories 
  * Allow spc_t to transption to rpm_script_t 
  * Add support to new user_namespace access check 
  * Smaller permission changes for container_init_t
- Drop spc.patch, is now included

OBS-URL: https://build.opensuse.org/request/show/1075435
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=27
2023-03-30 07:03:23 +00:00
0000f5ee1e Accepting request 1059620 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1059620
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=15
2023-01-20 16:38:16 +00:00
Johannes Segitz
25cd1634d4 Accepting request 1058701 from home:fcrozat:branches:security:SELinux
- Update to version 2.198.0:
  * Fix spc_t transition rules on tmpfs_t
- Changes from 2.197.0:
  * Add boolean containers_use_ecryptfs policy
- Changes from 2.195.1:
  * Readd missing allow rules for container_t
- Changes from 2.194.0:
  * Allow syslogd_t to use tmpfs files created by container runtime
- Changes from 2.193.0:
  * Allow containers to mount tmpfs_t file systems
  * Label spc_t as a init initrc daemon
  * Allow userdomains to run containers
- Changes from 2.191.0:
  * Create container_logwriter_t type
- Changes from 2.190.1:
  * Support BuildKit
  * container.fc: Set label for kata-agent
  * support nerdctl
- Changes from 2.190.0:
  * Packit: initial enablement
  * Allow iptables to list directories labeled as container_file_t
- Changes from 2.189.0:
  * Dont audit searching other processes in /proc.

OBS-URL: https://build.opensuse.org/request/show/1058701
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=26
2023-01-19 15:12:14 +00:00
121dff4bb7 Accepting request 1058005 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1058005
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=14
2023-01-14 19:30:42 +00:00
Johannes Segitz
1c8daaef72 Accepting request 1058004 from home:jsegitz:branches:security:SELinux
- Rename spc_timedated.patch to spc.patch
- Update spc.patch to allow privileged containers to use
  localectl (bsc#1207077)

OBS-URL: https://build.opensuse.org/request/show/1058004
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=25
2023-01-12 13:57:32 +00:00
Johannes Segitz
7b4d27d1e7 Accepting request 1057911 from home:jsegitz:branches:security:SELinux
- Add spc_timedated.patch to allow privileged containers to use
  timedatectl (bsc#1207054)

OBS-URL: https://build.opensuse.org/request/show/1057911
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=24
2023-01-12 07:15:56 +00:00
89329a03ee Accepting request 989144 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/989144
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=13
2022-07-18 16:32:44 +00:00
Johannes Segitz
8736328861 Accepting request 989141 from home:jsegitz:branches:security:SELinux
- Update to version 2.188.0:
  * Allow confined containers to mount overlay filesystems
  Fixed bsc#1201348

OBS-URL: https://build.opensuse.org/request/show/989141
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=23
2022-07-14 11:30:25 +00:00
Johannes Segitz
e144fec934 Accepting request 984493 from home:fcrozat:branches:security:SELinux
- Update to version 2.187.0:
  * Allow container domains to use /dev/zero
- Changes from 2.186.0:
  * Create policy for a container_device_t 
  * Allow containers to shutdown & setopt userdomain:sockets
- Changes from 2.183.0:
  * Allow containers to inherit all socket classes from container runtimes.
- Changes from 2.182.0:
  * Allow containers to inherit all socket classes
- Changes from 2.181.0:
  * Allow socket activated domains for tcp sockets from init_t and userdomains.

OBS-URL: https://build.opensuse.org/request/show/984493
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=22
2022-06-27 07:58:47 +00:00
71c64dc840 osc copypac from project:home:fcrozat:branches:security:SELinux package:container-selinux revision:2, using expand
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=12
2022-06-22 14:18:16 +00:00
9582578ebb Accepting request 964617 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/964617
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=11
2022-03-28 14:58:29 +00:00
eedde80a11 Accepting request 963880 from home:jsegitz:branches:security:SELinux
- Add udica templates to the package

OBS-URL: https://build.opensuse.org/request/show/963880
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=19
2022-03-24 10:24:18 +00:00
40afefed5c Accepting request 962685 from security:SELinux
- Update to version 2.180.0
  * Allow container domains to read/write kvm_device_t
  * Update kublet mappings to inlcude /usr/local/*
  * Allow container domains to use container runtime tcp and udp sockets
  * Alow containers to use unix_stream_sockets leaked from container runtimes
  * Allow userdomains to execute conmon_exec_t and use it as an entrypoint
  * Allow conmon_exec_t as an entrypoint
  * Add container_use_devices boolean to allow containers to use any device
  * Add explicit range transition for conmon
  * Add missing dbus class declaration into container_runtime_run()
  * Remove lockdown allow rules
  * Remove k3s fcontexts
  * Allow container domains to be used by user roles
- Changed source url to allow for download via source service (forwarded request 962680 from jsegitz)

OBS-URL: https://build.opensuse.org/request/show/962685
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=10
2022-03-20 19:54:43 +00:00
8c94cb033f Accepting request 962680 from home:jsegitz:branches:security:SELinux
- Update to version 2.180.0
  * Allow container domains to read/write kvm_device_t
  * Update kublet mappings to inlcude /usr/local/*
  * Allow container domains to use container runtime tcp and udp sockets
  * Alow containers to use unix_stream_sockets leaked from container runtimes
  * Allow userdomains to execute conmon_exec_t and use it as an entrypoint
  * Allow conmon_exec_t as an entrypoint
  * Add container_use_devices boolean to allow containers to use any device
  * Add explicit range transition for conmon
  * Add missing dbus class declaration into container_runtime_run()
  * Remove lockdown allow rules
  * Remove k3s fcontexts
  * Allow container domains to be used by user roles
- Changed source url to allow for download via source service

OBS-URL: https://build.opensuse.org/request/show/962680
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=17
2022-03-18 12:50:10 +00:00
0c09f8870f Accepting request 931472 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/931472
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=9
2021-11-20 01:38:03 +00:00
Johannes Segitz
b28e2b3d9b Accepting request 931165 from home:RBrownSUSE:branches:security:SELinux
- Update to version 2.171.0
  * Define kubernetes_file_t as a config_type
  * Allow containers to be socket activated by user domains and by systemd.
  * Allow iptables to use fifo files of a container runtime
  * Allow container_runtime create all tmpfs content as container_runtime_tmpfs_t
  * Allow containers to create lnk_file on tmpfs_t directories.

OBS-URL: https://build.opensuse.org/request/show/931165
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=16
2021-11-15 07:33:53 +00:00
Richard Brown
82f865e98c Accepting request 910793 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/910793
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=8
2021-08-12 07:01:02 +00:00
4931cb6840 Accepting request 910787 from home:jsegitz:branches:security:SELinux
- Update to version 2.164.2
  * Don't setup users for writing to pid_sockets
  * Allow container engines to be started from the staff user.
  * Allow spc_t domains to set bpf rules on any domain
  * Add support for k3s

OBS-URL: https://build.opensuse.org/request/show/910787
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=15
2021-08-09 08:25:05 +00:00
810788a782 Accepting request 887982 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/887982
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=7
2021-04-26 14:38:51 +00:00
18aae90282 Accepting request 887959 from home:jsegitz:branches:security:SELinux
- Fix container runtime binary labels (bsc#1185030). You need to 
  relable at least /usr/sbin if you're affected

OBS-URL: https://build.opensuse.org/request/show/887959
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=13
2021-04-23 09:14:49 +00:00
Richard Brown
44a892dee2 Accepting request 874863 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/874863
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=6
2021-03-02 11:27:48 +00:00
52d91d79b9 Accepting request 874614 from home:kukuk:selinux
- Update to version 2.158.0
  - Add nfs remount support
  - Allow containers to execmod on nfs, samba and cephs remote shares
  - Allow confined users to send dbus messages to container_runtime

OBS-URL: https://build.opensuse.org/request/show/874614
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=11
2021-02-24 13:31:37 +00:00
a5bd8876ef Accepting request 862254 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/862254
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=5
2021-01-15 18:44:14 +00:00
68e1a8db01 Accepting request 862253 from home:kukuk:selinux
- Update to version 2.154.0
  - Allow confined user domains to run confined container domains.
  - Allow all containers to use nfs shares, iff virt_use_nfs boolean
    is enabled.
  - Allow containers to read nsfs file systems.
  - KVM Container need to use tunnel sockets created by runtime.

OBS-URL: https://build.opensuse.org/request/show/862253
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=9
2021-01-11 10:50:48 +00:00
f464c12f13 Accepting request 845892 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/845892
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=4
2020-11-06 22:42:45 +00:00
12002ddbe2 Accepting request 845598 from home:lnussel:branches:security:SELinux
- Don't use BuildRequires based on shell script output. OBS can't
  evaluate that.

OBS-URL: https://build.opensuse.org/request/show/845598
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=7
2020-11-04 07:41:50 +00:00
d07345c7ea Accepting request 844834 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/844834
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=3
2020-11-02 08:40:20 +00:00
377a7bce44 Accepting request 844785 from home:kukuk:selinux
- Update to version 2.150.0
  - Add additional allow rules for kvm based containers using
    virtiofsd.

OBS-URL: https://build.opensuse.org/request/show/844785
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=5
2020-10-29 10:32:01 +00:00
26a75112fd Accepting request 842071 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/842071
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=2
2020-10-20 14:00:25 +00:00
e81a64dc03 Accepting request 841778 from home:kukuk:selinux
- Update to version 2.145.0
  - Add support for kubernetes_file_t
  - Allow container_t to open existing tun/tap

OBS-URL: https://build.opensuse.org/request/show/841778
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=3
2020-10-16 09:26:37 +00:00
f674550fbd Accepting request 840502 from security:SELinux
Required to run containers on a SELinux enabled system.

OBS-URL: https://build.opensuse.org/request/show/840502
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=1
2020-10-10 17:03:43 +00:00
7beff29edb Accepting request 825950 from home:kukuk:selinux
This package is needed to run Container with SELinux enabled

OBS-URL: https://build.opensuse.org/request/show/825950
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=1
2020-08-20 10:56:37 +00:00
7 changed files with 105 additions and 9 deletions

View File

@@ -6,7 +6,7 @@
<param name="scm">git</param> <param name="scm">git</param>
<param name="changesgenerate">enable</param> <param name="changesgenerate">enable</param>
<param name="match-tag">v*</param> <param name="match-tag">v*</param>
<param name="revision">main</param> <param name="revision">@PARENT_TAG@</param>
<param name="versionrewrite-pattern">v(.*)</param> <param name="versionrewrite-pattern">v(.*)</param>
<param name="versionrewrite-replacement">\1</param> <param name="versionrewrite-replacement">\1</param>
</service> </service>

View File

@@ -1,4 +1,4 @@
<servicedata> <servicedata>
<service name="tar_scm"> <service name="tar_scm">
<param name="url">https://github.com/containers/container-selinux.git</param> <param name="url">https://github.com/containers/container-selinux.git</param>
<param name="changesrevision">a68865582e123856c191fe0ecbbba9301758e591</param></service></servicedata> <param name="changesrevision">10cc7ecacd631368e23691a77dbfe63ac6ca855f</param></service></servicedata>

View File

@@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:1acd56a634e738cfa61f469564850942c261529e4bf3557ef9723067bd536757
size 28860

View File

@@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:8cca742899b757bb775b7852cefc83defd8ba5dd4e89a1a77e5833fb002efa60
size 27832

View File

@@ -1,3 +1,98 @@
-------------------------------------------------------------------
Tue Aug 05 14:21:07 UTC 2025 - Cathy Hu <cathy.hu@suse.com>
- Update to version 2.240.0:
* Dontaudit dac_override for iptables_t
* dropping rootless-docker_iptables.patch is upstream
* Don't allow containers by default setexec setfscreate
* Containers need to use hsa devices for ROCM
-------------------------------------------------------------------
Thu Jul 24 12:22:54 UTC 2025 - Robert Frohl <rfrohl@suse.com>
- Add workaround for rootless docker iptables AVCs (bsc#1246348)
adding rootless-docker_iptables.patch
-------------------------------------------------------------------
Mon Jul 7 08:41:20 UTC 2025 - Johannes Segitz <jsegitz@suse.com>
- Update to version 2.239.0:
* Allow containers to use hsa devices for ROCM
-------------------------------------------------------------------
Mon Jun 02 07:13:46 UTC 2025 - Johannes Segitz <jsegitz@suse.com>
- Update to version 2.238.0:
* label /run/sysctl.d correctly on creation
-------------------------------------------------------------------
Tue Apr 29 08:47:24 UTC 2025 - jsegitz@suse.com
- Update to version 2.237.0:
* bootc/install_t: allow transition to container_runtime_t
* Allow containers to mask parts of their /proc
-------------------------------------------------------------------
Mon Mar 31 12:35:29 UTC 2025 - jsegitz@suse.com
- Update to version 2.236.0:
* Allow super privileged containers to use RealtimeKit for scheduling
* Add container_ro_file_t to the podman artifact store
-------------------------------------------------------------------
Wed Mar 05 17:15:45 UTC 2025 - cathy.hu@suse.com
- Update to version 2.235.0:
* Bump to v2.235.0
* OWNERS: add wrabcak and zpytela
* OWNERS: initial commit
* container_log{reader,writer}_t: allow watch file
* RPM: Update gating config
* Enable aarch64 testing
* TMT: simplify podman tests
* feat: support /var/lib/crio
-------------------------------------------------------------------
Tue Feb 4 13:56:57 UTC 2025 - Robert Frohl <rfrohl@suse.com>
- OBS service file: use the tagged commit for archive versioning and don't
just archive the latest changes from the main branch using the latest tag
-------------------------------------------------------------------
Fri Jan 10 10:08:37 UTC 2025 - rfrohl@suse.com
- Update to version 2.234.2:
* TMT: enable epel idomatically
* Packit: switch back to fedora-all
* RPM: Bump Epoch to 4
* rpm: ship manpage
* Add proper labeling for RamaLama
* Packit: remove rhel / epel jobs
* packit: remove unused file
-------------------------------------------------------------------
Thu Jan 9 14:16:15 UTC 2025 - Cathy Hu <cathy.hu@suse.com>
- Add BuildRequires selinux-policy-%{selinuxtype} to enable building
for SLFO. Might be removed in the future again when 1231252
is fixed.
-------------------------------------------------------------------
Thu Nov 07 12:04:40 UTC 2024 - cathy.hu@suse.com
- Update to version 2.233.0:
* container_engine_t: small change to allow non root exec in a container
* RPM: explicitly list ghosted paths and skip mode verification
* container-selinux install on non selinux-policy-targeted systems (#332)
* set container_log_t type for /var/log/kube-apiserver
* Allow kubelet_t to create a sock file kubelet_var_lib_t
* dontaudit spc_t to mmap_zero
* Packit: update targets (#330)
* container_engine_t: another round of small improvements (#327)
* Allow container_device_plugin_t to use the network (#325)
* RPM: cleanup changelog (#324)
* TMT: Simplify tests
------------------------------------------------------------------- -------------------------------------------------------------------
Wed Jul 10 07:52:16 UTC 2024 - cathy.hu@suse.com Wed Jul 10 07:52:16 UTC 2024 - cathy.hu@suse.com

View File

@@ -26,7 +26,7 @@
# Version of SELinux we were using # Version of SELinux we were using
%define selinux_policyver %(rpm -q selinux-policy --qf '%%{version}') %define selinux_policyver %(rpm -q selinux-policy --qf '%%{version}')
Name: container-selinux Name: container-selinux
Version: 2.232.1 Version: 2.240.0
Release: 0 Release: 0
Summary: SELinux policies for container runtimes Summary: SELinux policies for container runtimes
License: GPL-2.0-only License: GPL-2.0-only
@@ -34,6 +34,7 @@ URL: https://github.com/containers/container-selinux
Source0: container-selinux-%{version}.tar.xz Source0: container-selinux-%{version}.tar.xz
BuildRequires: selinux-policy BuildRequires: selinux-policy
BuildRequires: selinux-policy-devel BuildRequires: selinux-policy-devel
BuildRequires: selinux-policy-%{selinuxtype}
Requires: selinux-policy >= %(rpm -q selinux-policy --qf '%%{version}-%%{release}') Requires: selinux-policy >= %(rpm -q selinux-policy --qf '%%{version}-%%{release}')
Requires(posttrans): policycoreutils Requires(posttrans): policycoreutils
Requires(posttrans): /usr/bin/sed Requires(posttrans): /usr/bin/sed
@@ -62,6 +63,8 @@ install -d %{buildroot}/%{_datadir}/containers/selinux
install -m 644 container_contexts %{buildroot}/%{_datadir}/containers/selinux/contexts install -m 644 container_contexts %{buildroot}/%{_datadir}/containers/selinux/contexts
install -d %{buildroot}%{_datadir}/udica/templates install -d %{buildroot}%{_datadir}/udica/templates
install -m 0644 udica-templates/*.cil %{buildroot}%{_datadir}/udica/templates install -m 0644 udica-templates/*.cil %{buildroot}%{_datadir}/udica/templates
install -d %{buildroot}%{_mandir}/man8/
install -pm 0644 container_selinux.8 %{buildroot}%{_mandir}/man8/
%check %check
@@ -98,5 +101,6 @@ matchpathcon -qV %{_sharedstatedir}/containers || restorecon -R %{_sharedstatedi
%dir %{_datadir}/udica %dir %{_datadir}/udica
%dir %{_datadir}/udica/templates %dir %{_datadir}/udica/templates
%{_datadir}/udica/templates/* %{_datadir}/udica/templates/*
%{_mandir}/man8/container_selinux.8*
%changelog %changelog

View File

@@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:4ae7825a8460460934950f6b2a4a0928bc2f71915e71474d6d5d20c8eeb9bbdd
size 31145