1
0

Compare commits

...

16 Commits

Author SHA256 Message Date
Ana Guerrero
eef1aee96a Accepting request 1221514 from security:SELinux
- Update to version 20241105:
  * Allow virt_dbus_t to connect to virtd_t over unix_stream_socket (bsc#1232655)

OBS-URL: https://build.opensuse.org/request/show/1221514
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=85
2024-11-06 15:50:05 +00:00
Hu
03f97d0b62 - Update to version 20241105:
* Allow virt_dbus_t to connect to virtd_t over unix_stream_socket (bsc#1232655)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=290
2024-11-05 16:24:49 +00:00
Dominique Leuenberger
9ea1b50e02 Accepting request 1219778 from security:SELinux
- Update to version 20241031:
  * Label /var/livepatches as lib_t for ULP on micro (bsc#1228879)

OBS-URL: https://build.opensuse.org/request/show/1219778
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=84
2024-11-01 20:00:49 +00:00
Hu
3c53700573 - Update to version 20241031:
* Label /var/livepatches as lib_t for ULP on micro (bsc#1228879)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=288
2024-10-31 07:39:51 +00:00
Ana Guerrero
e65ffcabd8 Accepting request 1216718 from security:SELinux
- Update to version 20241021:
  * rsync: add rsync_exec_commands boolean and enable it by default (bsc#1231494)
  * Allow snapperd to execute systemctl (bsc#1231489)

OBS-URL: https://build.opensuse.org/request/show/1216718
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=83
2024-10-22 12:51:15 +00:00
Hu
1ed8974058 rsync fix
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=286
2024-10-21 12:18:41 +00:00
Hu
96c5622eed - Update to version 20241021:
* Allow snapperd to execute systemctl (bsc#1231489)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=285
2024-10-21 07:24:23 +00:00
Ana Guerrero
6afcac9730 Accepting request 1208868 from security:SELinux
- Update to version 20241018:
  * Allow slpd to create TCPDIAG netlink socket (bsc#1231491)
  * Allow slpd to use sys_chroot (bsc#1231491)
  * Allow openvswitch-ipsec use strongswan (bsc#1231493)

OBS-URL: https://build.opensuse.org/request/show/1208868
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=82
2024-10-20 08:08:57 +00:00
Hu
0a02f57980 - Update to version 20241018:
* Allow slpd to create TCPDIAG netlink socket (bsc#1231491)
  * Allow slpd to use sys_chroot (bsc#1231491)
  * Allow openvswitch-ipsec use strongswan (bsc#1231493)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=283
2024-10-18 12:34:55 +00:00
Ana Guerrero
accf007cd1 Accepting request 1204680 from security:SELinux
- Update to version 20240930:
  * Label yast binaries correctly

OBS-URL: https://build.opensuse.org/request/show/1204680
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=81
2024-10-01 15:11:19 +00:00
Hu
3d7db12b13 fix changelog
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=281
2024-09-30 07:26:35 +00:00
Hu
55f3e0d374 - Update to version 20240930:
* Label auutyast binaries correctly

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=280
2024-09-30 07:16:02 +00:00
Ana Guerrero
26b7385b38 Accepting request 1203343 from security:SELinux
- Update to version 20240925:
  * Allow snapperd to manage unlabeled_t files (bsc#1230966)
- Update to version 20240924:
  * Revert "Allow virtstoraged to manage images (bsc#1228742)"
  * Label /etc/mdevctl.d with mdevctl_conf_t
  * Sync users with Fedora targeted users
  * Update policy for rpc-virtstorage
  * Allow virtstoraged get attributes of configfs dirs
  * Fix SELinux policy for sandbox X server to fix 'sandbox -X' command
  * Update bootupd policy when ESP is not mounted
  * Allow thumb_t map dri devices
  * Allow samba use the io_uring API
  * Allow the sysadm user use the secretmem API
  * Allow nut-upsmon read systemd-logind session files
  * Allow sysadm_t to create PF_KEY sockets
  * Update bootupd policy for the removing-state-file test
- Fix macros.selinux-policy (bsc#1230897)
  - %selinux_relabel_post should not relabel files in
    transactional systems in %post as the policy is not loaded
    into the kernel directly after install, instead the relabelling
    will happen on the next boot

OBS-URL: https://build.opensuse.org/request/show/1203343
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/selinux-policy?expand=0&rev=80
2024-09-25 19:53:00 +00:00
Hu
0c3d4440ae - Update to version 20240925:
* Allow snapperd to manage unlabeled_t files (bsc#1230966)

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=278
2024-09-25 08:23:52 +00:00
Hu
f6d9c79526 - Update to version 20240924:
* Revert "Allow virtstoraged to manage images (bsc#1228742)"
  * Label /etc/mdevctl.d with mdevctl_conf_t
  * Sync users with Fedora targeted users
  * Update policy for rpc-virtstorage
  * Allow virtstoraged get attributes of configfs dirs
  * Fix SELinux policy for sandbox X server to fix 'sandbox -X' command
  * Update bootupd policy when ESP is not mounted
  * Allow thumb_t map dri devices
  * Allow samba use the io_uring API
  * Allow the sysadm user use the secretmem API
  * Allow nut-upsmon read systemd-logind session files
  * Allow sysadm_t to create PF_KEY sockets
  * Update bootupd policy for the removing-state-file test

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=277
2024-09-24 09:39:30 +00:00
Hu
ee9959537f - Fix macros.selinux-policy (bsc#1230897)
- %selinux_relabel_post should not relabel files in
    transactional systems in %post as the policy is not loaded
    into the kernel directly after install, instead the relabelling
    will happen on the next boot

OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=276
2024-09-24 09:36:01 +00:00
6 changed files with 72 additions and 6 deletions

View File

@ -1,7 +1,7 @@
<servicedata>
<service name="tar_scm">
<param name="url">https://gitlab.suse.de/selinux/selinux-policy.git</param>
<param name="changesrevision">f8d70ad2b8a5d2628cd1ee881ccedbcebf189d3d</param></service><service name="tar_scm">
<param name="changesrevision">6e8cf2b0a771eddc3ae1bee3be0042bd3d9d8ba1</param></service><service name="tar_scm">
<param name="url">https://github.com/containers/container-selinux.git</param>
<param name="changesrevision">07b3034f6d9625ab84508a2f46515d8ff79b4204</param></service><service name="tar_scm">
<param name="url">https://gitlab.suse.de/jsegitz/selinux-policy.git</param>

View File

@ -117,7 +117,7 @@ if [ -z "${_policytype}" ]; then \
_policytype="targeted" \
fi \
if %{_sbindir}/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then \
if [ -f %{_file_context_file_pre} ]; then \
if [ -f %{_file_context_file_pre} ] && [ -z "${TRANSACTIONAL_UPDATE}" ]; then \
%{_sbindir}/fixfiles -C %{_file_context_file_pre} restore &> /dev/null \
rm -f %{_file_context_file_pre} \
fi \

View File

@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:2e46dccf26669df2e4cb81b47ade54d28892113ad73308f60bb4300f216cb39c
size 774376

View File

@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:e5ea1d19388cfee6c2d8b7c95a17bf541872cec56ca3d761f501ef1487ecc5b9
size 775060

View File

@ -1,3 +1,69 @@
-------------------------------------------------------------------
Tue Nov 05 16:21:44 UTC 2024 - cathy.hu@suse.com
- Update to version 20241105:
* Allow virt_dbus_t to connect to virtd_t over unix_stream_socket (bsc#1232655)
-------------------------------------------------------------------
Thu Oct 31 07:35:49 UTC 2024 - cathy.hu@suse.com
- Update to version 20241031:
* Label /var/livepatches as lib_t for ULP on micro (bsc#1228879)
-------------------------------------------------------------------
Mon Oct 21 07:23:25 UTC 2024 - cathy.hu@suse.com
- Update to version 20241021:
* rsync: add rsync_exec_commands boolean and enable it by default (bsc#1231494)
* Allow snapperd to execute systemctl (bsc#1231489)
-------------------------------------------------------------------
Fri Oct 18 12:34:06 UTC 2024 - cathy.hu@suse.com
- Update to version 20241018:
* Allow slpd to create TCPDIAG netlink socket (bsc#1231491)
* Allow slpd to use sys_chroot (bsc#1231491)
* Allow openvswitch-ipsec use strongswan (bsc#1231493)
-------------------------------------------------------------------
Mon Sep 30 07:15:18 UTC 2024 - cathy.hu@suse.com
- Update to version 20240930:
* Label yast binaries correctly
-------------------------------------------------------------------
Wed Sep 25 08:23:22 UTC 2024 - cathy.hu@suse.com
- Update to version 20240925:
* Allow snapperd to manage unlabeled_t files (bsc#1230966)
-------------------------------------------------------------------
Tue Sep 24 09:37:13 UTC 2024 - cathy.hu@suse.com
- Update to version 20240924:
* Revert "Allow virtstoraged to manage images (bsc#1228742)"
* Label /etc/mdevctl.d with mdevctl_conf_t
* Sync users with Fedora targeted users
* Update policy for rpc-virtstorage
* Allow virtstoraged get attributes of configfs dirs
* Fix SELinux policy for sandbox X server to fix 'sandbox -X' command
* Update bootupd policy when ESP is not mounted
* Allow thumb_t map dri devices
* Allow samba use the io_uring API
* Allow the sysadm user use the secretmem API
* Allow nut-upsmon read systemd-logind session files
* Allow sysadm_t to create PF_KEY sockets
* Update bootupd policy for the removing-state-file test
-------------------------------------------------------------------
Tue Sep 24 08:50:16 UTC 2024 - Cathy Hu <cathy.hu@suse.com>
- Fix macros.selinux-policy (bsc#1230897)
- %selinux_relabel_post should not relabel files in
transactional systems in %post as the policy is not loaded
into the kernel directly after install, instead the relabelling
will happen on the next boot
-------------------------------------------------------------------
Thu Sep 12 07:34:20 UTC 2024 - cathy.hu@suse.com

View File

@ -36,7 +36,7 @@ Summary: SELinux policy configuration
License: GPL-2.0-or-later
Group: System/Management
Name: selinux-policy
Version: 20240912
Version: 20241105
Release: 0
Source0: %{name}-%{version}.tar.xz
Source1: container.fc