diff --git a/SOURCES/openvswitch-3.2.0.patch b/SOURCES/openvswitch-3.2.0.patch index d1b82e1..3486247 100644 --- a/SOURCES/openvswitch-3.2.0.patch +++ b/SOURCES/openvswitch-3.2.0.patch @@ -7115,6 +7115,32 @@ index 49dc06e38c..558632320c 100644 ${OVS_USER_OPT} \ --no-monitor restart $OPTIONS +TimeoutSec=300 +diff --git a/selinux/openvswitch-custom.te.in b/selinux/openvswitch-custom.te.in +index beb0ab0d66..fe2c5bb61a 100644 +--- a/selinux/openvswitch-custom.te.in ++++ b/selinux/openvswitch-custom.te.in +@@ -49,8 +49,8 @@ require { + class fifo_file { getattr read write append ioctl lock open }; + class filesystem getattr; + class lnk_file { read open }; +- class netlink_audit_socket { create nlmsg_relay audit_write read write }; +- class netlink_netfilter_socket { create nlmsg_relay audit_write read write }; ++ class netlink_audit_socket { create nlmsg_relay read write }; ++ class netlink_netfilter_socket { create read write }; + @begin_dpdk@ + class netlink_rdma_socket { setopt bind create }; + @end_dpdk@ +@@ -79,8 +79,8 @@ domtrans_pattern(openvswitch_t, openvswitch_load_module_exec_t, openvswitch_load + + #============= openvswitch_t ============== + allow openvswitch_t self:capability { dac_override audit_write net_broadcast net_raw }; +-allow openvswitch_t self:netlink_audit_socket { create nlmsg_relay audit_write read write }; +-allow openvswitch_t self:netlink_netfilter_socket { create nlmsg_relay audit_write read write }; ++allow openvswitch_t self:netlink_audit_socket { create nlmsg_relay read write }; ++allow openvswitch_t self:netlink_netfilter_socket { create read write }; + @begin_dpdk@ + allow openvswitch_t self:netlink_rdma_socket { setopt bind create }; + @end_dpdk@ diff --git a/tests/.gitignore b/tests/.gitignore index 83b1cb3b48..3a8c459756 100644 --- a/tests/.gitignore diff --git a/SPECS/openvswitch3.2.spec b/SPECS/openvswitch3.2.spec index 6beb6f2..1dc63ee 100644 --- a/SPECS/openvswitch3.2.spec +++ b/SPECS/openvswitch3.2.spec @@ -57,7 +57,7 @@ Summary: Open vSwitch Group: System Environment/Daemons daemon/database/utilities URL: http://www.openvswitch.org/ Version: 3.2.0 -Release: 101%{?dist} +Release: 102%{?dist} # Nearly all of openvswitch is ASL 2.0. The bugtool is LGPLv2+, and the # lib/sflow*.[ch] files are SISSL @@ -763,6 +763,12 @@ exit 0 %endif %changelog +* Fri Sep 20 2024 Open vSwitch CI - 3.2.0-102 +- Merging upstream branch-3.2 [RH git: 62e58d201b] + Commit list: + ba4b28b1ec selinux: Update policy file. + + * Fri Sep 20 2024 Open vSwitch CI - 3.2.0-101 - Merging upstream branch-3.2 [RH git: bda1be9c38] Commit list: