1
0
Commit Graph

225 Commits

Author SHA256 Message Date
Dominique Leuenberger
c8394980d8 Accepting request 909370 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/909370
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=15
2021-08-02 10:04:33 +00:00
Johannes Segitz
72477b3ac5 Accepting request 909369 from home:jsegitz:branches:security:SELinux
- Update to version 20210716
- Remove interfaces for container module before building the package
  (bsc#1188184)
- Updated
  * fix_init.patch
  * fix_systemd_watch.patch
  to adapt to upstream changes

- Use tabrmd SELinux modules from tpm2.0-abrmd instead of storing
  here

- Update to version 20210419
- Dropped fix_gift.patch, module was removed
- Updated wicked.te to removed dropped interface
- Refreshed:
  * fix_cockpit.patch
  * fix_hadoop.patch
  * fix_init.patch
  * fix_logging.patch
  * fix_logrotate.patch
  * fix_networkmanager.patch
  * fix_nscd.patch
  * fix_rpm.patch
  * fix_selinuxutil.patch
  * fix_systemd.patch
  * fix_systemd_watch.patch
  * fix_thunderbird.patch
  * fix_unconfined.patch
  * fix_unconfineduser.patch
  * fix_unprivuser.patch

OBS-URL: https://build.opensuse.org/request/show/909369
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=113
2021-07-30 09:07:13 +00:00
Dominique Leuenberger
b82ea14783 Accepting request 904732 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/904732
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=14
2021-07-11 23:24:43 +00:00
Dominique Leuenberger
3baf5bcdf6 Accepting request 904732 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/904732
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=14
2021-07-11 23:24:43 +00:00
Johannes Segitz
0b03ae6097 Accepting request 904546 from home:aplanas:branches:security:SELinux
- Add tabrmd SELinux modules from upstream (bsc#1187925)
  https://github.com/tpm2-software/tpm2-abrmd/tree/master/selinux
- Automatic spec-cleaner to fix ordering and misaligned spaces

OBS-URL: https://build.opensuse.org/request/show/904546
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=112
2021-07-08 09:30:22 +00:00
Dominique Leuenberger
77831e640c Accepting request 894727 from security:SELinux
- allow systemd to watch /usr, /usr/lib, /etc, /etc/pki as we have path units
  that trigger on changes in those.
  Added fix_systemd_watch.patch
- own /usr/share/selinux/packages/$SELINUXTYPE/ and
  /var/lib/selinux/$SELINUXTYPE/active/modules/* to allow packages to install
  files there

OBS-URL: https://build.opensuse.org/request/show/894727
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=13
2021-05-23 21:30:29 +00:00
Dominique Leuenberger
aea4a827c0 Accepting request 894727 from security:SELinux
- allow systemd to watch /usr, /usr/lib, /etc, /etc/pki as we have path units
  that trigger on changes in those.
  Added fix_systemd_watch.patch
- own /usr/share/selinux/packages/$SELINUXTYPE/ and
  /var/lib/selinux/$SELINUXTYPE/active/modules/* to allow packages to install
  files there

OBS-URL: https://build.opensuse.org/request/show/894727
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=13
2021-05-23 21:30:29 +00:00
Johannes Segitz
4cc65efd18 Added fix_systemd_watch.patch
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=110
2021-05-21 07:16:10 +00:00
Dominique Leuenberger
06c67ef4c2 Accepting request 893917 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/893917
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=12
2021-05-20 17:24:24 +00:00
Dominique Leuenberger
e5ddc01c22 Accepting request 893917 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/893917
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=12
2021-05-20 17:24:24 +00:00
Johannes Segitz
b8952f6e0d Accepting request 894639 from home:lnussel:branches:systemsmanagement:cockpit
- allow systemd to watch /usr, /usr/lib, /etc, /etc/pki as we have path units
  that trigger on changes in those.
- own /usr/share/selinux/packages/$SELINUXTYPE/ and
  /var/lib/selinux/$SELINUXTYPE/active/modules/* to allow packages to install
  files there

OBS-URL: https://build.opensuse.org/request/show/894639
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=108
2021-05-20 15:02:09 +00:00
Johannes Segitz
d46782358c Accepting request 893763 from home:lnussel:usrmove
- allow cockpit socket to bind nodes (fix_cockpit.patch)
- use %autosetup to get rid of endless patch lines

OBS-URL: https://build.opensuse.org/request/show/893763
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=107
2021-05-18 07:46:13 +00:00
Dominique Leuenberger
4f868ac4c7 Accepting request 890550 from security:SELinux
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/890550
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=11
2021-05-07 14:45:22 +00:00
Dominique Leuenberger
231c1bddcc Accepting request 890550 from security:SELinux
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/890550
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=11
2021-05-07 14:45:22 +00:00
Johannes Segitz
3b70ecf210 Accepting request 890549 from home:jsegitz:branches:security:SELinux
- Updated fix_networkmanager.patch to allow NetworkManager to watch
  its configuration directories
- Added fix_dovecot.patch to fix dovecot authentication (bsc#1182207)

OBS-URL: https://build.opensuse.org/request/show/890549
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=105
2021-05-05 07:01:43 +00:00
Dominique Leuenberger
58cf3360bf Accepting request 888543 from security:SELinux
- Added Recommends for selinux-autorelabel (bsc#1181837)
- Prevent libreoffice fonts from changing types on every relabel 
  (bsc#1185265). Added fix_libraries.patch

- Transition unconfined users to ldconfig type (bsc#1183121).
  Extended fix_unconfineduser.patch

OBS-URL: https://build.opensuse.org/request/show/888543
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=10
2021-04-29 20:44:23 +00:00
Dominique Leuenberger
9770640975 Accepting request 888543 from security:SELinux
- Added Recommends for selinux-autorelabel (bsc#1181837)
- Prevent libreoffice fonts from changing types on every relabel 
  (bsc#1185265). Added fix_libraries.patch

- Transition unconfined users to ldconfig type (bsc#1183121).
  Extended fix_unconfineduser.patch

OBS-URL: https://build.opensuse.org/request/show/888543
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=10
2021-04-29 20:44:23 +00:00
Johannes Segitz
81f34f7fca (bsc#1185265). Added fix_libraries.patch
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=103
2021-04-26 16:08:25 +00:00
Johannes Segitz
5a087ac379 Accepting request 888474 from home:jsegitz:branches:security:SELinux
- Added Recommends for selinux-autorelabel (bsc#1181837)
- Prevent libreoffice fonts from changing types on every relabel 
  (bsc#1185265)

OBS-URL: https://build.opensuse.org/request/show/888474
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=102
2021-04-26 12:07:40 +00:00
Johannes Segitz
0bda3469f4 Accepting request 888009 from home:jsegitz:branches:security:SELinux
- Transition unconfined users to ldconfig type (bsc#1183121).
  Extended fix_unconfineduser.patch

OBS-URL: https://build.opensuse.org/request/show/888009
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=101
2021-04-23 11:50:03 +00:00
Dominique Leuenberger
2b7ba1f084 Accepting request 886701 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/886701
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=9
2021-04-22 16:03:46 +00:00
Dominique Leuenberger
46cba05af6 Accepting request 886701 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/886701
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=9
2021-04-22 16:03:46 +00:00
Johannes Segitz
8ca14f4905 Accepting request 886700 from home:jsegitz:branches:security:SELinux
- Update to version 20210419
- Refreshed:
  * fix_dbus.patch
  * fix_hadoop.patch
  * fix_init.patch
  * fix_unprivuser.patch

OBS-URL: https://build.opensuse.org/request/show/886700
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=99
2021-04-19 13:39:08 +00:00
Dominique Leuenberger
5329db915c Accepting request 878582 from security:SELinux
big toolchain update, please stage together. so versions change, so this has high potential to break stuff. Probably best to stage it isolated

OBS-URL: https://build.opensuse.org/request/show/878582
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=8
2021-03-24 15:08:51 +00:00
Dominique Leuenberger
b3cf18cf4d Accepting request 878582 from security:SELinux
big toolchain update, please stage together. so versions change, so this has high potential to break stuff. Probably best to stage it isolated

OBS-URL: https://build.opensuse.org/request/show/878582
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=8
2021-03-24 15:08:51 +00:00
Johannes Segitz
095423f93a Accepting request 878541 from home:akedroutek:branches:security:SELinux
bsc#1183177

OBS-URL: https://build.opensuse.org/request/show/878541
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=97
2021-03-12 14:43:38 +00:00
Johannes Segitz
21d0a40c65 OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=96 2021-03-12 07:59:19 +00:00
Richard Brown
fc04e57b85 Accepting request 874853 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/874853
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=7
2021-03-02 11:27:42 +00:00
Richard Brown
2deb9860fa Accepting request 874853 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/874853
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=7
2021-03-02 11:27:42 +00:00
Johannes Segitz
8c9c1d2173 Accepting request 874817 from home:kukuk:selinux
- Update to version 20210223
- Change name of tar file to a more common schema to allow
  parallel installation of several source versions
- Adjust fix_init.patch

OBS-URL: https://build.opensuse.org/request/show/874817
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=94
2021-02-24 13:12:28 +00:00
Dominique Leuenberger
0a5898fa12 Accepting request 862277 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/862277
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=6
2021-01-15 18:44:19 +00:00
Dominique Leuenberger
4ffa4ec7ef Accepting request 862277 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/862277
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=6
2021-01-15 18:44:19 +00:00
Ales Kedroutek
0ebcd6f872 Accepting request 862245 from home:kukuk:selinux
- Update to version 20210111
  - Drop fix_policykit.patch (integrated upstream)
  - Adjust fix_iptables.patch
  - update container policy

OBS-URL: https://build.opensuse.org/request/show/862245
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=92
2021-01-11 12:17:10 +00:00
Dominique Leuenberger
54f8cdf045 Accepting request 847443 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/847443
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=5
2020-11-13 17:54:46 +00:00
Dominique Leuenberger
6c79f08d5b Accepting request 847443 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/847443
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=5
2020-11-13 17:54:46 +00:00
Johannes Segitz
cc07b260a6 Accepting request 847442 from home:jsegitz:branches:security:SELinux
- Updated fix_corecommand.patch to set correct types for the OBS
  build tools

OBS-URL: https://build.opensuse.org/request/show/847442
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=90
2020-11-10 09:33:20 +00:00
Dominique Leuenberger
a22fb6b6d3 Accepting request 844986 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/844986
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=4
2020-11-02 13:04:02 +00:00
Dominique Leuenberger
ef24e4da10 Accepting request 844986 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/844986
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=4
2020-11-02 13:04:02 +00:00
Johannes Segitz
4877d5cafa Accepting request 844783 from home:kukuk:selinux
- wicked.fc: add libexec directories
- Update to version 20201029
  - update container policy

OBS-URL: https://build.opensuse.org/request/show/844783
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=88
2020-10-30 08:59:42 +00:00
Dominique Leuenberger
2453061091 Accepting request 842814 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/842814
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=3
2020-10-23 10:20:12 +00:00
Dominique Leuenberger
b4b02dcd1a Accepting request 842814 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/842814
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=3
2020-10-23 10:20:12 +00:00
Johannes Segitz
4477ef8a3c Accepting request 842070 from home:kukuk:selinux
- Update to version 20201016
- Use python3 to build (fc_sort.c was replaced by fc_sort.py which
  uses python3)
- Drop SELINUX=disabled, "selinux=0" kernel commandline option has
  to be used instead. New default is "permissive" [bsc#1176923].

OBS-URL: https://build.opensuse.org/request/show/842070
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=86
2020-10-20 12:57:14 +00:00
Dominique Leuenberger
4b6a0b8466 Accepting request 839873 from security:SELinux
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/839873
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=2
2020-10-07 12:18:21 +00:00
Dominique Leuenberger
2425f1bc15 Accepting request 839873 from security:SELinux
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/839873
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=2
2020-10-07 12:18:21 +00:00
Dominique Leuenberger
ded584ab59 Accepting request 832021 from security:SELinux
Policy is in better state now and should be fine for people with basic SELinux knowledge

OBS-URL: https://build.opensuse.org/request/show/832021
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=1
2020-10-06 15:06:19 +00:00
Dominique Leuenberger
3de9778fbc Accepting request 832021 from security:SELinux
Policy is in better state now and should be fine for people with basic SELinux knowledge

OBS-URL: https://build.opensuse.org/request/show/832021
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=1
2020-10-06 15:06:19 +00:00
Johannes Segitz
6fa6803f18 Accepting request 833509 from home:jsegitz:branches:security:SELinux
- Update to version 20200910. Refreshed
  * fix_authlogin.patch
  * fix_nagios.patch
  * fix_systemd.patch
  * fix_usermanage.patch
- Delete suse_specific.patch, moved content into fix_selinuxutil.patch
- Cleanup of booleans-* presets
  * Enabled
    user_rw_noexattrfile
    unconfined_chrome_sandbox_transition
    unconfined_mozilla_plugin_transition
    for the minimal policy
  * Disabled
    xserver_object_manager
    for the MLS policy
  * Disabled
    openvpn_enable_homedirs
    privoxy_connect_any
    selinuxuser_direct_dri_enabled
    selinuxuser_ping (aka user_ping)
    squid_connect_any
    telepathy_tcp_connect_generic_network_ports
    for the targeted policy
  Change your local config if you need them
- Build HTML version of manpages for the -devel package

OBS-URL: https://build.opensuse.org/request/show/833509
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=83
2020-09-10 15:07:50 +00:00
Johannes Segitz
7a2750f7a0 Accepting request 831657 from home:jsegitz:branches:security:SELinux
- Drop BuildRequires for python, python-xml. It's not needed anymore

OBS-URL: https://build.opensuse.org/request/show/831657
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=82
2020-09-03 11:35:20 +00:00
Johannes Segitz
83bae1c6b9 Accepting request 831126 from home:jsegitz:branches:security:SELinux
- Drop fix_dbus.patch_orig, was included by accident
- Drop segenxml_interpreter.patch, not used anymore

OBS-URL: https://build.opensuse.org/request/show/831126
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=81
2020-09-01 13:35:46 +00:00
6410182343 Accepting request 825946 from home:kukuk:selinux
- macros.selinux-policy: move rpm-state directory to /run and
  make sure it exists

OBS-URL: https://build.opensuse.org/request/show/825946
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=80
2020-08-20 10:56:43 +00:00