1
0

287 Commits

Author SHA256 Message Date
Dominique Leuenberger
9ea1b50e02 Accepting request 1219778 from security:SELinux
- Update to version 20241031:
  * Label /var/livepatches as lib_t for ULP on micro (bsc#1228879)

OBS-URL: https://build.opensuse.org/request/show/1219778
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=84
2024-11-01 20:00:49 +00:00
Hu
3c53700573 - Update to version 20241031:
* Label /var/livepatches as lib_t for ULP on micro (bsc#1228879)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=288
2024-10-31 07:39:51 +00:00
Ana Guerrero
e65ffcabd8 Accepting request 1216718 from security:SELinux
- Update to version 20241021:
  * rsync: add rsync_exec_commands boolean and enable it by default (bsc#1231494)
  * Allow snapperd to execute systemctl (bsc#1231489)

OBS-URL: https://build.opensuse.org/request/show/1216718
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=83
2024-10-22 12:51:15 +00:00
Hu
1ed8974058 rsync fix
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=286
2024-10-21 12:18:41 +00:00
Hu
96c5622eed - Update to version 20241021:
* Allow snapperd to execute systemctl (bsc#1231489)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=285
2024-10-21 07:24:23 +00:00
Ana Guerrero
6afcac9730 Accepting request 1208868 from security:SELinux
- Update to version 20241018:
  * Allow slpd to create TCPDIAG netlink socket (bsc#1231491)
  * Allow slpd to use sys_chroot (bsc#1231491)
  * Allow openvswitch-ipsec use strongswan (bsc#1231493)

OBS-URL: https://build.opensuse.org/request/show/1208868
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=82
2024-10-20 08:08:57 +00:00
Hu
0a02f57980 - Update to version 20241018:
* Allow slpd to create TCPDIAG netlink socket (bsc#1231491)
  * Allow slpd to use sys_chroot (bsc#1231491)
  * Allow openvswitch-ipsec use strongswan (bsc#1231493)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=283
2024-10-18 12:34:55 +00:00
Ana Guerrero
accf007cd1 Accepting request 1204680 from security:SELinux
- Update to version 20240930:
  * Label yast binaries correctly

OBS-URL: https://build.opensuse.org/request/show/1204680
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=81
2024-10-01 15:11:19 +00:00
Hu
3d7db12b13 fix changelog
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=281
2024-09-30 07:26:35 +00:00
Hu
55f3e0d374 - Update to version 20240930:
* Label auutyast binaries correctly

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=280
2024-09-30 07:16:02 +00:00
Ana Guerrero
26b7385b38 Accepting request 1203343 from security:SELinux
- Update to version 20240925:
  * Allow snapperd to manage unlabeled_t files (bsc#1230966)
- Update to version 20240924:
  * Revert "Allow virtstoraged to manage images (bsc#1228742)"
  * Label /etc/mdevctl.d with mdevctl_conf_t
  * Sync users with Fedora targeted users
  * Update policy for rpc-virtstorage
  * Allow virtstoraged get attributes of configfs dirs
  * Fix SELinux policy for sandbox X server to fix 'sandbox -X' command
  * Update bootupd policy when ESP is not mounted
  * Allow thumb_t map dri devices
  * Allow samba use the io_uring API
  * Allow the sysadm user use the secretmem API
  * Allow nut-upsmon read systemd-logind session files
  * Allow sysadm_t to create PF_KEY sockets
  * Update bootupd policy for the removing-state-file test
- Fix macros.selinux-policy (bsc#1230897)
  - %selinux_relabel_post should not relabel files in
    transactional systems in %post as the policy is not loaded
    into the kernel directly after install, instead the relabelling
    will happen on the next boot

OBS-URL: https://build.opensuse.org/request/show/1203343
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=80
2024-09-25 19:53:00 +00:00
Hu
0c3d4440ae - Update to version 20240925:
* Allow snapperd to manage unlabeled_t files (bsc#1230966)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=278
2024-09-25 08:23:52 +00:00
Hu
f6d9c79526 - Update to version 20240924:
* Revert "Allow virtstoraged to manage images (bsc#1228742)"
  * Label /etc/mdevctl.d with mdevctl_conf_t
  * Sync users with Fedora targeted users
  * Update policy for rpc-virtstorage
  * Allow virtstoraged get attributes of configfs dirs
  * Fix SELinux policy for sandbox X server to fix 'sandbox -X' command
  * Update bootupd policy when ESP is not mounted
  * Allow thumb_t map dri devices
  * Allow samba use the io_uring API
  * Allow the sysadm user use the secretmem API
  * Allow nut-upsmon read systemd-logind session files
  * Allow sysadm_t to create PF_KEY sockets
  * Update bootupd policy for the removing-state-file test

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=277
2024-09-24 09:39:30 +00:00
Hu
ee9959537f - Fix macros.selinux-policy (bsc#1230897)
- %selinux_relabel_post should not relabel files in
    transactional systems in %post as the policy is not loaded
    into the kernel directly after install, instead the relabelling
    will happen on the next boot

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=276
2024-09-24 09:36:01 +00:00
Ana Guerrero
3752e2304c Accepting request 1200261 from security:SELinux
- Update to version 20240912:
  * Allow systemd_ibft_rule_generator_t to create udev_rules_t dirs (bsc#1230011)
  * Allow systemd_udev_trigger_generator_t list and read sysctls (bsc#1230315)
  * Initial policy for udev-trigger-generator (bsc#1230315)
- Update to version 20240910:
  * Allow init_t mount syslog socket (bsc#1230134)
  * Allow init_t create syslog files (bsc#1230134)
  * Introduce initial policy for btrfs-soft-reboot-generator (bsc#1230134)

OBS-URL: https://build.opensuse.org/request/show/1200261
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=79
2024-09-12 14:54:06 +00:00
Hu
64c9b9378c - Update to version 20240912:
* Allow systemd_ibft_rule_generator_t to create udev_rules_t dirs (bsc#1230011)
  * Allow systemd_udev_trigger_generator_t list and read sysctls (bsc#1230315)
  * Initial policy for udev-trigger-generator (bsc#1230315)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=274
2024-09-12 07:35:07 +00:00
Ana Guerrero
33c24240a2 Accepting request 1199629 from security:SELinux
- Update to version 20240905:
  * Allow coreos-installer-generator manage mdadm_conf_t files
  * Allow setsebool_t relabel selinux data files
  * Allow virtqemud relabelfrom virtqemud_var_run_t dirs
  * Use better escape method for "interface"
  * Allow init and systemd-logind to inherit fds from sshd
  * Allow systemd-ssh-generator read sysctl files
  * Sync modules.conf with Fedora targeted modules
  * Allow virtqemud relabel user tmp files and socket files
  * Add missing sys_chroot capability to groupadd policy
  * Label /run/libvirt/qemu/channel with virtqemud_var_run_t
  * Allow virtqemud relabelfrom also for file and sock_file
  * Add virt_create_log() and virt_write_log() interfaces
  - Sync modules-targeted-contrib.conf with Fedora targeted modules.conf

OBS-URL: https://build.opensuse.org/request/show/1199629
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=78
2024-09-10 19:12:21 +00:00
Hu
b9406bac0c Accepting request 1199900 from home:cahu:branches:security:SELinux
- Update to version 20240910:
  * Allow init_t mount syslog socket (bsc#1230134)
  * Allow init_t create syslog files (bsc#1230134)
  * Introduce initial policy for btrfs-soft-reboot-generator (bsc#1230134)

OBS-URL: https://build.opensuse.org/request/show/1199900
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=272
2024-09-10 15:01:13 +00:00
Hu
2112d5575b - Update to version 20240905:
* Allow coreos-installer-generator manage mdadm_conf_t files
  * Allow setsebool_t relabel selinux data files
  * Allow virtqemud relabelfrom virtqemud_var_run_t dirs
  * Use better escape method for "interface"
  * Allow init and systemd-logind to inherit fds from sshd
  * Allow systemd-ssh-generator read sysctl files
  * Sync modules.conf with Fedora targeted modules
  * Allow virtqemud relabel user tmp files and socket files
  * Add missing sys_chroot capability to groupadd policy
  * Label /run/libvirt/qemu/channel with virtqemud_var_run_t
  * Allow virtqemud relabelfrom also for file and sock_file
  * Add virt_create_log() and virt_write_log() interfaces
  - Sync modules-targeted-contrib.conf with Fedora targeted modules.conf

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=271
2024-09-09 08:08:07 +00:00
Ana Guerrero
b2a6a4d472 Accepting request 1198764 from security:SELinux
- Fix macros.selinux-policy (bsc#1229132)
  - %selinux_modules_install and %selinux_modules_uninstall will
    now only execute load_policy if $TRANSACTIONAL_UPDATE is not set
    (aka only if they are not in a transactional system)
  - $TRANSACTIONAL_UPDATE is set here:
    bd524d3ddf/lib/Transaction.cpp (L428)
- Disable build of the MLS policy. We currently don't know if it works
  and don't want to encourage users to apply it

OBS-URL: https://build.opensuse.org/request/show/1198764
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=77
2024-09-05 13:46:23 +00:00
Hu
3d27365c20 - Fix macros.selinux-policy (bsc#1229132)
- %selinux_modules_install and %selinux_modules_uninstall will
    now only execute load_policy if $TRANSACTIONAL_UPDATE is not set
    (aka only if they are not in a transactional system)
  - $TRANSACTIONAL_UPDATE is set here:
    bd524d3ddf/lib/Transaction.cpp (L428)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=269
2024-09-04 13:57:36 +00:00
Hu
c15b34e13f - Disable build of the MLS policy. We currently don't know if it works
and don't want to encourage users to apply it

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=268
2024-09-03 11:46:59 +00:00
Dominique Leuenberger
7f06e6d1b3 Accepting request 1198426 from security:SELinux
- Update to version 20240903:
  * allow sshd_t and sshd_net_t access to ssh vsockets (bsc#1228831)
- Update to version 20240902:
  * Allow xen to use qemu as dom0 disk backend (bsc#1228540)
  * Label /var/lib/xen/xenstore as xenstored_var_lib_t (bsc#1228540)
  * Allow xl to access hypercall interfaces to xen hypervisor (bsc#1228540)

OBS-URL: https://build.opensuse.org/request/show/1198426
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=76
2024-09-03 11:37:49 +00:00
Hu
9c1224b86d - Update to version 20240903:
* allow sshd_t and sshd_net_t access to ssh vsockets (bsc#1228831)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=266
2024-09-03 08:04:07 +00:00
Hu
7e521cf496 Accepting request 1198253 from home:cahu:branches:security:SELinux
- Update to version 20240902:
  * Allow xen to use qemu as dom0 disk backend (bsc#1228540)
  * Label /var/lib/xen/xenstore as xenstored_var_lib_t (bsc#1228540)
  * Allow xl to access hypercall interfaces to xen hypervisor (bsc#1228540)

OBS-URL: https://build.opensuse.org/request/show/1198253
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=265
2024-09-02 08:36:23 +00:00
Dominique Leuenberger
81e37981ae Accepting request 1197845 from security:SELinux
- Update to version 20240830:
  * Allow virtstoraged to manage images (bsc#1228742)
  * Allow virtstoraged_t domtrans to udev (bsc#1228742)

OBS-URL: https://build.opensuse.org/request/show/1197845
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=75
2024-09-01 17:20:56 +00:00
Hu
34097e449f - Update to version 20240830:
* Allow virtstoraged to manage images (bsc#1228742)
  * Allow virtstoraged_t domtrans to udev (bsc#1228742)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=263
2024-08-30 11:52:05 +00:00
Dominique Leuenberger
5d9d3aec92 Accepting request 1196426 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1196426
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=74
2024-08-29 13:42:54 +00:00
Hu
9ea4bcbe6d - Update to version 20240828:
* Allow systemd-ssh-generator to load net-pf-40 (bsc#1229766)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=261
2024-08-28 09:10:00 +00:00
Ana Guerrero
1295c6efea Accepting request 1196084 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1196084
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=73
2024-08-27 17:38:31 +00:00
Hu
6514d3f42b - Enable named_write_master_zones boolean by default (bsc#1229479)
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=259
2024-08-26 14:29:53 +00:00
Ana Guerrero
ef2794ca22 Accepting request 1195681 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1195681
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=72
2024-08-25 10:09:35 +00:00
Hu
40eb8e68ec - Update to version 20240823:
* Allow rasdaemon write access to sysfs (bsc#1229587)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=257
2024-08-23 08:42:36 +00:00
Ana Guerrero
4bc48cd130 Accepting request 1194650 from security:SELinux
- Update to version 20240816:
  * Initial policy for syslog-ng (bsc#1229153)

OBS-URL: https://build.opensuse.org/request/show/1194650
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=71
2024-08-20 14:12:40 +00:00
Hu
06983f62a3 - Update to version 20240816:
* Initial policy for syslog-ng (bsc#1229153)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=255
2024-08-16 12:31:26 +00:00
Dominique Leuenberger
3743169a39 Accepting request 1193871 from security:SELinux
- Update to version 20240814:
  * Dontaudit dac_override of fstab generator (bsc#1229127)
- Drop varrun-convert.sh script as it causes issues with
  container-selinux update (bsc#1228951)
- Update to version 20240812:
  * Update libvirt policy
  * Add port 80/udp and 443/udp to http_port_t definition
  * Additional updates stalld policy for bpf usage
  * Label systemd-pcrextend and systemd-pcrlock properly
  * Allow coreos_installer_t work with partitions
  * Revert "Allow coreos-installer-generator work with partitions"
  * Add policy for systemd-pcrextend
  * Update policy for systemd-getty-generator
  * Allow ip command write to ipsec's logs
  * Allow virt_driver_domain read virtd-lxc files in /proc
  * Revert "Allow svirt read virtqemud fifo files"
  * Update virtqemud policy for libguestfs usage
  * Allow virtproxyd create and use its private tmp files
  * Allow virtproxyd read network state
  * Allow virt_driver_domain create and use log files in /var/log
  * Allow samba-dcerpcd work with ctdb cluster
  * Allow NetworkManager_dispatcher_t send SIGKILL to plugins
  * Allow setroubleshootd execute sendmail with a domain transition
  * Allow key.dns_resolve set attributes on the kernel key ring
  * Update qatlib policy for v24.02 with new features
  * Label /var/lib/systemd/sleep with systemd_sleep_var_lib_t
  * Allow tlp status power services
  * Allow virtqemud domain transition on passt execution
  * Allow virt_driver_domain connect to systemd-userdbd over a unix socket
  * Allow boothd connect to systemd-userdbd over a unix socket
  * Update policy for awstats scripts
  * Allow bitlbee execute generic programs in system bin directories
  * Allow login_userdomain read aliases file
  * Allow login_userdomain read ipsec config files
  * Allow login_userdomain read all pid files
  * Allow rsyslog read systemd-logind session files
  * Allow libvirt-dbus stream connect to virtlxcd

OBS-URL: https://build.opensuse.org/request/show/1193871
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=70
2024-08-15 07:57:36 +00:00
Hu
3425be62a3 - Update to version 20240814:
* Dontaudit dac_override of fstab generator (bsc#1229127)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=253
2024-08-14 12:12:40 +00:00
Hu
4d1c914703 - Drop varrun-convert.sh script as it causes issues with
container-selinux update (bsc#1228951)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=252
2024-08-14 12:09:35 +00:00
Hu
83d1f9398e - Update to version 20240812:
* Update libvirt policy
  * Add port 80/udp and 443/udp to http_port_t definition
  * Additional updates stalld policy for bpf usage
  * Label systemd-pcrextend and systemd-pcrlock properly
  * Allow coreos_installer_t work with partitions
  * Revert "Allow coreos-installer-generator work with partitions"
  * Add policy for systemd-pcrextend
  * Update policy for systemd-getty-generator
  * Allow ip command write to ipsec's logs
  * Allow virt_driver_domain read virtd-lxc files in /proc
  * Revert "Allow svirt read virtqemud fifo files"
  * Update virtqemud policy for libguestfs usage
  * Allow virtproxyd create and use its private tmp files
  * Allow virtproxyd read network state
  * Allow virt_driver_domain create and use log files in /var/log
  * Allow samba-dcerpcd work with ctdb cluster
  * Allow NetworkManager_dispatcher_t send SIGKILL to plugins
  * Allow setroubleshootd execute sendmail with a domain transition
  * Allow key.dns_resolve set attributes on the kernel key ring
  * Update qatlib policy for v24.02 with new features
  * Label /var/lib/systemd/sleep with systemd_sleep_var_lib_t
  * Allow tlp status power services
  * Allow virtqemud domain transition on passt execution
  * Allow virt_driver_domain connect to systemd-userdbd over a unix socket
  * Allow boothd connect to systemd-userdbd over a unix socket
  * Update policy for awstats scripts
  * Allow bitlbee execute generic programs in system bin directories
  * Allow login_userdomain read aliases file
  * Allow login_userdomain read ipsec config files
  * Allow login_userdomain read all pid files
  * Allow rsyslog read systemd-logind session files
  * Allow libvirt-dbus stream connect to virtlxcd

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=251
2024-08-12 15:39:19 +00:00
Dominique Leuenberger
7ad5616cbb Accepting request 1192931 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1192931
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=69
2024-08-10 17:06:12 +00:00
Hu
2254b47412 - Update to version 20240809:
* Label /run/udev/rules.d as udev_rules_t
  * Provide type for sysstat lock files (bsc#1228247)
  * Allow snapper to delete unlabeled_t files (bsc#1228889)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=249
2024-08-09 12:56:11 +00:00
Hu
fade960df6 - Update to version 20240808:
* Use new kanidm interfaces
  * Initial module for kanidm
  * Update bootupd policy
  * Allow rhsmcertd read/write access to /dev/papr-sysparm
  * Label /dev/papr-sysparm and /dev/papr-vpd
  * Allow abrt-dump-journal-core connect to winbindd
  * Allow systemd-hostnamed shut down nscd
  * Allow systemd-pstore send a message to syslogd over a unix domain
  * Allow postfix_domain map postfix_etc_t files
  * Allow microcode create /sys/devices/system/cpu/microcode/reload
  * Allow rhsmcertd read, write, and map ica tmpfs files
  * Support SGX devices
  * Allow initrc_t transition to passwd_t
  * Update fstab and cryptsetup generators policy
  * Allow xdm_t read and write the dma device
  * Update stalld policy for bpf usage
  * Allow systemd_gpt_generator to getattr on DOS directories
  * Make cgroup_memory_pressure_t a part of the file_type attribute
  * Allow ssh_t to change role to system_r
  * Update policy for coreos generators
  * Allow init_t nnp domain transition to firewalld_t
  * Label /run/modprobe.d with modules_conf_t
  * Allow virtnodedevd run udev with a domain transition
  * Allow virtnodedev_t create and use virtnodedev_lock_t
  * Allow virtstoraged manage files with virt_content_t type
  * Allow virtqemud unmount a filesystem with extended attributes
  * Allow svirt_t connect to unconfined_t over a unix domain socket
  * Update afterburn file transition policy
  * Allow systemd_generator read attributes of all filesystems
  * Allow fstab-generator read and write cryptsetup-generator unit file
  * Allow cryptsetup-generator read and write fstab-generator unit file
  * Allow systemd_generator map files in /etc
  * Allow systemd_generator read init's process state
  * Allow coreos-installer-generator read sssd public files
  * Allow coreos-installer-generator work with partitions
  * Label /etc/mdadm.conf.d with mdadm_conf_t
  * Confine coreos generators
  * Label /run/metadata with afterburn_runtime_t
  * Allow afterburn list ssh home directory
  * Label samba certificates with samba_cert_t
  * Label /run/coreos-installer-reboot with coreos_installer_var_run_t
  * Allow virtqemud read virt-dbus process state
  * Allow staff user dbus chat with virt-dbus
  * Allow staff use watch /run/systemd
  * Allow systemd_generator to write kmsg
  * Allow virtqemud connect to sanlock over a unix stream socket
  * Allow virtqemud relabel virt_var_run_t directories
  * Allow svirt_tcg_t read vm sysctls
  * Allow virtnodedevd connect to systemd-userdbd over a unix socket
  * Allow svirt read virtqemud fifo files
  * Allow svirt attach_queue to a virtqemud tun_socket
  * Allow virtqemud run ssh client with a transition
  * Allow virt_dbus_t connect to virtqemud_t over a unix stream socket
  * Update keyutils policy
  * Allow sshd_keygen_t connect to userdbd over a unix stream socket
  * Allow postfix-smtpd read mysql config files
  * Allow locate stream connect to systemd-userdbd
  * Allow the staff user use wireshark
  * Allow updatedb connect to userdbd over a unix stream socket
  * Allow gpg_t set attributes of public-keys.d
  * Allow gpg_t get attributes of login_userdomain stream
  * Allow systemd_getty_generator_t read /proc/1/environ
  * Allow systemd_getty_generator_t to read and write to tty_device_t
  * Drop publicfile module
  * Remove permissive domain for systemd_nsresourced_t
  * Change fs_dontaudit_write_cgroup_files() to apply to cgroup_t
  * Label /usr/bin/samba-gpupdate with samba_gpupdate_exec_t
  * Allow to create and delete socket files created by rhsm.service
  * Allow virtnetworkd exec shell when virt_hooks_unconfined is on
  * Allow unconfined_service_t transition to passwd_t
  * Support /var is empty
  * Allow abrt-dump-journal read all non_security socket files
  * Allow timemaster write to sysfs files
  * Dontaudit domain write cgroup files
  * Label /usr/lib/node_modules/npm/bin with bin_t
  * Allow ip the setexec permission
  * Allow systemd-networkd write files in /var/lib/systemd/network
  * Fix typo in systemd_nsresourced_prog_run_bpf()

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=248
2024-08-08 12:42:54 +00:00
Dominique Leuenberger
013d5e9091 Accepting request 1191606 from security:SELinux
- Update to version 20240802:
  * Dontaudit search of snapper grub plugin to nscd socket (bsc#1228745)
- Update to version 20240731:
  * Initial policy for ibft-rule-generator (bsc#1228402)
  * Initial policy for systemd-status-mail (bsc#1228402)

OBS-URL: https://build.opensuse.org/request/show/1191606
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=68
2024-08-07 04:09:59 +00:00
Hu
1436280589 Accepting request 1191198 from home:cahu:branches:security:SELinux
- Update to version 20240802:
  * Dontaudit search of snapper grub plugin to nscd socket (bsc#1228745)

OBS-URL: https://build.opensuse.org/request/show/1191198
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=246
2024-08-02 14:03:51 +00:00
Dominique Leuenberger
abf987f230 Accepting request 1190665 from security:SELinux
- Update to version 20240731:
  * Fix labels for bind/named (bsc#1228372)
- Update to version 20240729:
  * Label /usr/libexec/netconfig/ppp/ip-up pppd_initrc_exec_t (bsc#1228385)
  * Allow pppd to manage sysnet directories (bsc#1228385)

OBS-URL: https://build.opensuse.org/request/show/1190665
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=67
2024-08-01 20:03:52 +00:00
Hu
221bf4c937 Accepting request 1190779 from home:cahu:branches:security:SELinux
- Update to version 20240731:
  * Initial policy for ibft-rule-generator (bsc#1228402)
  * Initial policy for systemd-status-mail (bsc#1228402)

OBS-URL: https://build.opensuse.org/request/show/1190779
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=244
2024-07-31 16:19:05 +00:00
Hu
b0b931a7b7 Accepting request 1190664 from home:cahu:branches:security:SELinux
- Update to version 20240731:
  * Fix labels for bind/named (bsc#1228372)

OBS-URL: https://build.opensuse.org/request/show/1190664
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=243
2024-07-31 12:58:43 +00:00
Dominique Leuenberger
ed825bf91e Accepting request 1189796 from security:SELinux
OBS-URL: https://build.opensuse.org/request/show/1189796
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=66
2024-07-30 09:53:15 +00:00
Hu
27400b7c6d Accepting request 1190295 from home:cahu:branches:security:SELinux
- Update to version 20240729:
  * Label /usr/libexec/netconfig/ppp/ip-up pppd_initrc_exec_t (bsc#1228385)
  * Allow pppd to manage sysnet directories (bsc#1228385)

OBS-URL: https://build.opensuse.org/request/show/1190295
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=241
2024-07-29 15:55:16 +00:00
Hu
a861cc4c16 - Update to version 20240726:
* Allow snapper grub plugin to manage unlabeled_t and read link files

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=240
2024-07-26 13:40:33 +00:00