1
0

20 Commits

Author SHA256 Message Date
7e1c88062a Accepting request 1297768 from security:SELinux
update to 2.240.0

OBS-URL: https://build.opensuse.org/request/show/1297768
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=30
2025-08-06 12:31:36 +00:00
Hu
6b164d4af3 - Update to version 2.240.0:
* Dontaudit dac_override for iptables_t
    * dropping rootless-docker_iptables.patch is upstream
  * Don't allow containers by default setexec setfscreate
  * Containers need to use hsa devices for ROCM

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=47
2025-08-05 14:36:42 +00:00
648cacb039 Accepting request 1296255 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1296255
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=29
2025-07-30 09:41:40 +00:00
3bc4afa6a2 currently a draft for upstream, ready in case there is urgency with SLE16
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=46
2025-07-29 07:39:59 +00:00
0dd6633895 Accepting request 1290993 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1290993
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=28
2025-07-08 13:28:13 +00:00
Johannes Segitz
c0548fca91 - Update to version 2.239.0:
* Allow containers to use hsa devices for ROCM

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=45
2025-07-07 08:47:09 +00:00
99ed30ae4d Accepting request 1281761 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1281761
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=27
2025-06-03 15:50:19 +00:00
Johannes Segitz
73b1a0d6ea - Update to version 2.238.0:
* label /run/sysctl.d correctly on creation

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=44
2025-06-02 07:20:10 +00:00
c7e49842dc Accepting request 1273366 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1273366
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=26
2025-04-30 17:02:39 +00:00
Johannes Segitz
da714098f0 - Update to version 2.237.0:
* bootc/install_t: allow transition to container_runtime_t
  * Allow containers to mask parts of their /proc

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=43
2025-04-29 08:53:38 +00:00
88af38b286 Accepting request 1265900 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1265900
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=25
2025-04-02 15:07:42 +00:00
Johannes Segitz
5f498f6eac - Update to version 2.236.0:
* Allow super privileged containers to use RealtimeKit for scheduling
  * Add container_ro_file_t to the podman artifact store

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=42
2025-03-31 13:15:32 +00:00
1461d30756 Accepting request 1251751 from security:SELinux
update

OBS-URL: https://build.opensuse.org/request/show/1251751
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=24
2025-03-11 19:43:58 +00:00
Hu
2637d8f52b - Update to version 2.235.0:
* Bump to v2.235.0
  * OWNERS: add wrabcak and zpytela
  * OWNERS: initial commit
  * container_log{reader,writer}_t: allow watch file
  * RPM: Update gating config
  * Enable aarch64 testing
  * TMT: simplify podman tests
  * feat: support /var/lib/crio

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=41
2025-03-07 15:30:54 +00:00
Hu
e7903160b6 Accepting request 1243135 from home:rfrohl:branches:security:SELinux
fix _service file

OBS-URL: https://build.opensuse.org/request/show/1243135
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=40
2025-02-04 15:43:03 +00:00
9c4881f7d7 Accepting request 1236910 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1236910
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=23
2025-01-12 10:09:53 +00:00
0e19467c12 container-selinux: 2.234.2 + man page
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=39
2025-01-10 16:19:24 +00:00
Hu
b846d75346 - Add BuildRequires selinux-policy-%{selinuxtype} to enable building
for SLFO. Might be removed in the future again when 1231252
  is fixed.

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=38
2025-01-09 14:23:53 +00:00
8c46c4c2ab Accepting request 1227115 from security:SELinux
container-selinux october update

OBS-URL: https://build.opensuse.org/request/show/1227115
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/container-selinux?expand=0&rev=22
2024-11-30 12:27:11 +00:00
Hu
174e42eff7 Accepting request 1222444 from home:cahu:security:SELinux:policyupdate102024-2
- Update to version 2.233.0:
  * container_engine_t: small change to allow non root exec in a container
  * RPM: explicitly list ghosted paths and skip mode verification
  * container-selinux install on non selinux-policy-targeted systems (#332)
  * set container_log_t type for /var/log/kube-apiserver
  * Allow kubelet_t to create a sock file kubelet_var_lib_t
  * dontaudit spc_t to mmap_zero
  * Packit: update targets (#330)
  * container_engine_t: another round of small improvements (#327)
  * Allow container_device_plugin_t to use the network (#325)
  * RPM: cleanup changelog (#324)
  * TMT: Simplify tests

OBS-URL: https://build.opensuse.org/request/show/1222444
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/container-selinux?expand=0&rev=37
2024-11-14 10:21:53 +00:00
6 changed files with 105 additions and 6 deletions

View File

@@ -6,7 +6,7 @@
<param name="scm">git</param> <param name="scm">git</param>
<param name="changesgenerate">enable</param> <param name="changesgenerate">enable</param>
<param name="match-tag">v*</param> <param name="match-tag">v*</param>
<param name="revision">main</param> <param name="revision">@PARENT_TAG@</param>
<param name="versionrewrite-pattern">v(.*)</param> <param name="versionrewrite-pattern">v(.*)</param>
<param name="versionrewrite-replacement">\1</param> <param name="versionrewrite-replacement">\1</param>
</service> </service>

View File

@@ -1,4 +1,4 @@
<servicedata> <servicedata>
<service name="tar_scm"> <service name="tar_scm">
<param name="url">https://github.com/containers/container-selinux.git</param> <param name="url">https://github.com/containers/container-selinux.git</param>
<param name="changesrevision">a68865582e123856c191fe0ecbbba9301758e591</param></service></servicedata> <param name="changesrevision">10cc7ecacd631368e23691a77dbfe63ac6ca855f</param></service></servicedata>

View File

@@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:1acd56a634e738cfa61f469564850942c261529e4bf3557ef9723067bd536757
size 28860

View File

@@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:8cca742899b757bb775b7852cefc83defd8ba5dd4e89a1a77e5833fb002efa60
size 27832

View File

@@ -1,3 +1,98 @@
-------------------------------------------------------------------
Tue Aug 05 14:21:07 UTC 2025 - Cathy Hu <cathy.hu@suse.com>
- Update to version 2.240.0:
* Dontaudit dac_override for iptables_t
* dropping rootless-docker_iptables.patch is upstream
* Don't allow containers by default setexec setfscreate
* Containers need to use hsa devices for ROCM
-------------------------------------------------------------------
Thu Jul 24 12:22:54 UTC 2025 - Robert Frohl <rfrohl@suse.com>
- Add workaround for rootless docker iptables AVCs (bsc#1246348)
adding rootless-docker_iptables.patch
-------------------------------------------------------------------
Mon Jul 7 08:41:20 UTC 2025 - Johannes Segitz <jsegitz@suse.com>
- Update to version 2.239.0:
* Allow containers to use hsa devices for ROCM
-------------------------------------------------------------------
Mon Jun 02 07:13:46 UTC 2025 - Johannes Segitz <jsegitz@suse.com>
- Update to version 2.238.0:
* label /run/sysctl.d correctly on creation
-------------------------------------------------------------------
Tue Apr 29 08:47:24 UTC 2025 - jsegitz@suse.com
- Update to version 2.237.0:
* bootc/install_t: allow transition to container_runtime_t
* Allow containers to mask parts of their /proc
-------------------------------------------------------------------
Mon Mar 31 12:35:29 UTC 2025 - jsegitz@suse.com
- Update to version 2.236.0:
* Allow super privileged containers to use RealtimeKit for scheduling
* Add container_ro_file_t to the podman artifact store
-------------------------------------------------------------------
Wed Mar 05 17:15:45 UTC 2025 - cathy.hu@suse.com
- Update to version 2.235.0:
* Bump to v2.235.0
* OWNERS: add wrabcak and zpytela
* OWNERS: initial commit
* container_log{reader,writer}_t: allow watch file
* RPM: Update gating config
* Enable aarch64 testing
* TMT: simplify podman tests
* feat: support /var/lib/crio
-------------------------------------------------------------------
Tue Feb 4 13:56:57 UTC 2025 - Robert Frohl <rfrohl@suse.com>
- OBS service file: use the tagged commit for archive versioning and don't
just archive the latest changes from the main branch using the latest tag
-------------------------------------------------------------------
Fri Jan 10 10:08:37 UTC 2025 - rfrohl@suse.com
- Update to version 2.234.2:
* TMT: enable epel idomatically
* Packit: switch back to fedora-all
* RPM: Bump Epoch to 4
* rpm: ship manpage
* Add proper labeling for RamaLama
* Packit: remove rhel / epel jobs
* packit: remove unused file
-------------------------------------------------------------------
Thu Jan 9 14:16:15 UTC 2025 - Cathy Hu <cathy.hu@suse.com>
- Add BuildRequires selinux-policy-%{selinuxtype} to enable building
for SLFO. Might be removed in the future again when 1231252
is fixed.
-------------------------------------------------------------------
Thu Nov 07 12:04:40 UTC 2024 - cathy.hu@suse.com
- Update to version 2.233.0:
* container_engine_t: small change to allow non root exec in a container
* RPM: explicitly list ghosted paths and skip mode verification
* container-selinux install on non selinux-policy-targeted systems (#332)
* set container_log_t type for /var/log/kube-apiserver
* Allow kubelet_t to create a sock file kubelet_var_lib_t
* dontaudit spc_t to mmap_zero
* Packit: update targets (#330)
* container_engine_t: another round of small improvements (#327)
* Allow container_device_plugin_t to use the network (#325)
* RPM: cleanup changelog (#324)
* TMT: Simplify tests
------------------------------------------------------------------- -------------------------------------------------------------------
Wed Jul 10 07:52:16 UTC 2024 - cathy.hu@suse.com Wed Jul 10 07:52:16 UTC 2024 - cathy.hu@suse.com

View File

@@ -26,7 +26,7 @@
# Version of SELinux we were using # Version of SELinux we were using
%define selinux_policyver %(rpm -q selinux-policy --qf '%%{version}') %define selinux_policyver %(rpm -q selinux-policy --qf '%%{version}')
Name: container-selinux Name: container-selinux
Version: 2.232.1 Version: 2.240.0
Release: 0 Release: 0
Summary: SELinux policies for container runtimes Summary: SELinux policies for container runtimes
License: GPL-2.0-only License: GPL-2.0-only
@@ -34,6 +34,7 @@ URL: https://github.com/containers/container-selinux
Source0: container-selinux-%{version}.tar.xz Source0: container-selinux-%{version}.tar.xz
BuildRequires: selinux-policy BuildRequires: selinux-policy
BuildRequires: selinux-policy-devel BuildRequires: selinux-policy-devel
BuildRequires: selinux-policy-%{selinuxtype}
Requires: selinux-policy >= %(rpm -q selinux-policy --qf '%%{version}-%%{release}') Requires: selinux-policy >= %(rpm -q selinux-policy --qf '%%{version}-%%{release}')
Requires(posttrans): policycoreutils Requires(posttrans): policycoreutils
Requires(posttrans): /usr/bin/sed Requires(posttrans): /usr/bin/sed
@@ -62,6 +63,8 @@ install -d %{buildroot}/%{_datadir}/containers/selinux
install -m 644 container_contexts %{buildroot}/%{_datadir}/containers/selinux/contexts install -m 644 container_contexts %{buildroot}/%{_datadir}/containers/selinux/contexts
install -d %{buildroot}%{_datadir}/udica/templates install -d %{buildroot}%{_datadir}/udica/templates
install -m 0644 udica-templates/*.cil %{buildroot}%{_datadir}/udica/templates install -m 0644 udica-templates/*.cil %{buildroot}%{_datadir}/udica/templates
install -d %{buildroot}%{_mandir}/man8/
install -pm 0644 container_selinux.8 %{buildroot}%{_mandir}/man8/
%check %check
@@ -98,5 +101,6 @@ matchpathcon -qV %{_sharedstatedir}/containers || restorecon -R %{_sharedstatedi
%dir %{_datadir}/udica %dir %{_datadir}/udica
%dir %{_datadir}/udica/templates %dir %{_datadir}/udica/templates
%{_datadir}/udica/templates/* %{_datadir}/udica/templates/*
%{_mandir}/man8/container_selinux.8*
%changelog %changelog