From 4f9ed76f50888c8ad3b274a53fc3a956dd68f512 Mon Sep 17 00:00:00 2001 From: CentOS Sources Date: Nov 02 2021 10:39:03 +0000 Subject: import container-selinux-2.167.0-1.module+el8.4.0+12448+09f02219 --- diff --git a/.container-selinux.metadata b/.container-selinux.metadata index 04580f6..e0a457b 100644 --- a/.container-selinux.metadata +++ b/.container-selinux.metadata @@ -1 +1 @@ -bb18101c1ab06b47a88b51df2fd87dcfa3d51412 SOURCES/v2.158.0.tar.gz +98b7f05ef0e86a3c21f9da1c315eb0f9a1c58df4 SOURCES/v2.167.0.tar.gz diff --git a/.gitignore b/.gitignore index ba31b2b..60737f9 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1 @@ -SOURCES/v2.158.0.tar.gz +SOURCES/v2.167.0.tar.gz diff --git a/SOURCES/container-selinux-1957904.patch b/SOURCES/container-selinux-1957904.patch new file mode 100644 index 0000000..9efeeea --- /dev/null +++ b/SOURCES/container-selinux-1957904.patch @@ -0,0 +1,12 @@ +diff -up container-selinux-2.163.0/container.te.orig container-selinux-2.163.0/container.te +--- container-selinux-2.163.0/container.te.orig 2021-06-16 16:14:04.107700701 +0200 ++++ container-selinux-2.163.0/container.te 2021-06-16 16:14:29.756010679 +0200 +@@ -454,7 +454,7 @@ modutils_domtrans_kmod(container_runtime + systemd_status_all_unit_files(container_runtime_domain) + systemd_start_systemd_services(container_runtime_domain) + systemd_dbus_chat_logind(container_runtime_domain) +-systemd_chat_resolved(container_runtime_domain) ++#systemd_chat_resolved(container_runtime_domain) + + userdom_stream_connect(container_runtime_domain) + userdom_search_user_home_content(container_runtime_domain) diff --git a/SOURCES/rhel-fix.patch b/SOURCES/rhel-fix.patch new file mode 100644 index 0000000..90293df --- /dev/null +++ b/SOURCES/rhel-fix.patch @@ -0,0 +1,12 @@ +diff -up container-selinux-2.161.1/container.te.orig container-selinux-2.161.1/container.te +--- container-selinux-2.161.1/container.te.orig 2021-05-06 14:55:57.952216763 +0200 ++++ container-selinux-2.161.1/container.te 2021-05-06 14:56:02.027287991 +0200 +@@ -114,7 +114,7 @@ mls_trusted_object(container_runtime_t) + # + allow container_runtime_domain self:capability { chown kill fowner fsetid mknod net_admin net_bind_service net_raw setfcap sys_resource }; + allow container_runtime_domain self:tun_socket { create_socket_perms relabelto }; +-allow container_runtime_domain self:lockdown { confidentiality integrity }; ++#allow container_runtime_domain self:lockdown { confidentiality integrity }; + allow container_runtime_domain self:process ~setcurrent; + allow container_runtime_domain self:passwd rootok; + allow container_runtime_domain self:fd use; diff --git a/SPECS/container-selinux.spec b/SPECS/container-selinux.spec index 0c541aa..d369d74 100644 --- a/SPECS/container-selinux.spec +++ b/SPECS/container-selinux.spec @@ -19,12 +19,14 @@ Epoch: 2 Name: container-selinux -Version: 2.158.0 +Version: 2.167.0 Release: 1%{?dist} License: GPLv2 URL: %{git0} Summary: SELinux policies for container runtimes Source0: %{git0}/archive/v%{version}.tar.gz +Patch0: rhel-fix.patch +Patch1: container-selinux-1957904.patch BuildArch: noarch BuildRequires: git BuildRequires: pkgconfig(systemd) @@ -106,6 +108,10 @@ fi %{_datadir}/containers/selinux/contexts %changelog +* Tue Aug 31 2021 Jindrich Novy - 2:2.167.0-1 +- update to https://github.com/containers/container-selinux/releases/tag/v2.167.0 +- Related: #1999245 + * Fri Feb 12 2021 Jindrich Novy - 2:2.158.0-1 - update to https://github.com/containers/container-selinux/releases/tag/v2.158.0 - Related: #1883490