diff --git a/SOURCES/openvswitch-3.1.0.patch b/SOURCES/openvswitch-3.1.0.patch index 1e662df..4347b19 100644 --- a/SOURCES/openvswitch-3.1.0.patch +++ b/SOURCES/openvswitch-3.1.0.patch @@ -11404,6 +11404,32 @@ index 49dc06e38c..558632320c 100644 ${OVS_USER_OPT} \ --no-monitor restart $OPTIONS +TimeoutSec=300 +diff --git a/selinux/openvswitch-custom.te.in b/selinux/openvswitch-custom.te.in +index beb0ab0d66..fe2c5bb61a 100644 +--- a/selinux/openvswitch-custom.te.in ++++ b/selinux/openvswitch-custom.te.in +@@ -49,8 +49,8 @@ require { + class fifo_file { getattr read write append ioctl lock open }; + class filesystem getattr; + class lnk_file { read open }; +- class netlink_audit_socket { create nlmsg_relay audit_write read write }; +- class netlink_netfilter_socket { create nlmsg_relay audit_write read write }; ++ class netlink_audit_socket { create nlmsg_relay read write }; ++ class netlink_netfilter_socket { create read write }; + @begin_dpdk@ + class netlink_rdma_socket { setopt bind create }; + @end_dpdk@ +@@ -79,8 +79,8 @@ domtrans_pattern(openvswitch_t, openvswitch_load_module_exec_t, openvswitch_load + + #============= openvswitch_t ============== + allow openvswitch_t self:capability { dac_override audit_write net_broadcast net_raw }; +-allow openvswitch_t self:netlink_audit_socket { create nlmsg_relay audit_write read write }; +-allow openvswitch_t self:netlink_netfilter_socket { create nlmsg_relay audit_write read write }; ++allow openvswitch_t self:netlink_audit_socket { create nlmsg_relay read write }; ++allow openvswitch_t self:netlink_netfilter_socket { create read write }; + @begin_dpdk@ + allow openvswitch_t self:netlink_rdma_socket { setopt bind create }; + @end_dpdk@ diff --git a/tests/.gitignore b/tests/.gitignore index 83b1cb3b48..3a8c459756 100644 --- a/tests/.gitignore diff --git a/SPECS/openvswitch3.1.spec b/SPECS/openvswitch3.1.spec index 8c7ea69..6d6bb46 100644 --- a/SPECS/openvswitch3.1.spec +++ b/SPECS/openvswitch3.1.spec @@ -57,7 +57,7 @@ Summary: Open vSwitch Group: System Environment/Daemons daemon/database/utilities URL: http://www.openvswitch.org/ Version: 3.1.0 -Release: 131%{?dist} +Release: 132%{?dist} # Nearly all of openvswitch is ASL 2.0. The bugtool is LGPLv2+, and the # lib/sflow*.[ch] files are SISSL @@ -756,6 +756,12 @@ exit 0 %endif %changelog +* Fri Sep 20 2024 Open vSwitch CI - 3.1.0-132 +- Merging upstream branch-3.1 [RH git: 1d07e7a1d1] + Commit list: + dc2e4ea5ef selinux: Update policy file. + + * Fri Sep 20 2024 Open vSwitch CI - 3.1.0-131 - Merging upstream branch-3.1 [RH git: 165fcefe62] Commit list: