Petr Lautrbach cd2c1d
* Mon Jun 03 2024 Zdenek Pytela <zpytela@redhat.com> - 41.1-1
Petr Lautrbach cd2c1d
- Allow fstab-generator create unit file symlinks
Petr Lautrbach cd2c1d
- Update policy for cryptsetup-generator
Petr Lautrbach cd2c1d
- Update policy for fstab-generator
Petr Lautrbach cd2c1d
- Allow virtqemud read vm sysctls
Petr Lautrbach cd2c1d
- Allow collectd to trace processes in user namespace
Petr Lautrbach cd2c1d
- Allow bootupd search efivarfs dirs
Petr Lautrbach cd2c1d
- Add policy for systemd-mountfsd
Petr Lautrbach cd2c1d
- Add policy for systemd-nsresourced
Petr Lautrbach cd2c1d
- Update policy generators
Petr Lautrbach cd2c1d
- Add policy for anaconda-generator
Petr Lautrbach cd2c1d
- Update policy for fstab and gpt generators
Petr Lautrbach cd2c1d
- Add policy for kdump-dep-generator
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu May 30 2024 Zdenek Pytela <zpytela@redhat.com> - 40.21-1
Petr Lautrbach cd2c1d
- Add policy for a generic generator
Petr Lautrbach cd2c1d
- Add policy for tpm2 generator
Petr Lautrbach cd2c1d
- Add policy for ssh-generator
Petr Lautrbach cd2c1d
- Add policy for second batch of generators
Petr Lautrbach cd2c1d
- Update policy for systemd generators
Petr Lautrbach cd2c1d
- ci: Adjust Cockpit test plans
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Sun May 19 2024 Zdenek Pytela <zpytela@redhat.com> - 40.20-1
Petr Lautrbach cd2c1d
- Allow journald read systemd config files and directories
Petr Lautrbach cd2c1d
- Allow systemd_domain read systemd_conf_t dirs
Petr Lautrbach cd2c1d
- Fix bad Python regexp escapes
Petr Lautrbach cd2c1d
- Allow fido services connect to postgres database
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri May 17 2024 Zdenek Pytela <zpytela@redhat.com> - 40.19-1
Petr Lautrbach cd2c1d
- Allow postfix smtpd map aliases file
Petr Lautrbach cd2c1d
- Ensure dbus communication is allowed bidirectionally
Petr Lautrbach cd2c1d
- Label systemd configuration files with systemd_conf_t
Petr Lautrbach cd2c1d
- Label /run/systemd/machine with systemd_machined_var_run_t
Petr Lautrbach cd2c1d
- Allow systemd-hostnamed read the vsock device
Petr Lautrbach cd2c1d
- Allow sysadm execute dmidecode using sudo
Petr Lautrbach cd2c1d
- Allow sudodomain list files in /var
Petr Lautrbach cd2c1d
- Allow setroubleshootd get attributes of all sysctls
Petr Lautrbach cd2c1d
- Allow various services read and write z90crypt device
Petr Lautrbach cd2c1d
- Allow nfsidmap connect to systemd-homed
Petr Lautrbach cd2c1d
- Allow sandbox_x_client_t dbus chat with accountsd
Petr Lautrbach cd2c1d
- Allow system_cronjob_t dbus chat with avahi_t
Petr Lautrbach cd2c1d
- Allow staff_t the io_uring sqpoll permission
Petr Lautrbach cd2c1d
- Allow staff_t use the io_uring API
Petr Lautrbach cd2c1d
- Add support for secretmem anon inode
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu May 16 2024 Adam Williamson <awilliam@redhat.com> - 40.18-3
Petr Lautrbach cd2c1d
- Correct some errors in the RPM macro changes from -2
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon May 06 2024 Zdenek Pytela <zpytela@redhat.com> - 40.18-2
Petr Lautrbach cd2c1d
- Update rpm configuration for the /var/run equivalency change
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon May 06 2024 Zdenek Pytela <zpytela@redhat.com> - 40.18-1
Petr Lautrbach cd2c1d
- Allow virtqemud read vfio devices
Petr Lautrbach cd2c1d
- Allow virtqemud get attributes of a tmpfs filesystem
Petr Lautrbach cd2c1d
- Allow svirt_t read vm sysctls
Petr Lautrbach cd2c1d
- Allow virtqemud create and unlink files in /etc/libvirt/
Petr Lautrbach cd2c1d
- Allow virtqemud get attributes of cifs files
Petr Lautrbach cd2c1d
- Allow virtqemud get attributes of filesystems with extended attributes
Petr Lautrbach cd2c1d
- Allow virtqemud get attributes of NFS filesystems
Petr Lautrbach cd2c1d
- Allow virt_domain read and write usb devices conditionally
Petr Lautrbach cd2c1d
- Allow virtstoraged use the io_uring API
Petr Lautrbach cd2c1d
- Allow virtstoraged execute lvm programs in the lvm domain
Petr Lautrbach cd2c1d
- Allow virtnodevd_t map /var/lib files
Petr Lautrbach cd2c1d
- Allow svirt_tcg_t map svirt_image_t files
Petr Lautrbach cd2c1d
- Allow abrt-dump-journal-core connect to systemd-homed
Petr Lautrbach cd2c1d
- Allow abrt-dump-journal-core connect to systemd-machined
Petr Lautrbach cd2c1d
- Allow sssd create and use io_uring
Petr Lautrbach cd2c1d
- Allow selinux-relabel-generator create units dir
Petr Lautrbach cd2c1d
- Allow dbus-broker read/write inherited user ttys
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Apr 25 2024 Zdenek Pytela <zpytela@redhat.com> - 40.17-1
Petr Lautrbach cd2c1d
- Define transitions for /run/libvirt/common and /run/libvirt/qemu
Petr Lautrbach cd2c1d
- Allow systemd-sleep read raw disk data
Petr Lautrbach cd2c1d
- Allow numad to trace processes in user namespace
Petr Lautrbach cd2c1d
- Allow abrt-dump-journal-core connect to systemd-userdbd
Petr Lautrbach cd2c1d
- Allow plymouthd read efivarfs files
Petr Lautrbach cd2c1d
- Update the auth_dontaudit_read_passwd_file() interface
Petr Lautrbach cd2c1d
- Label /dev/mmcblk0rpmb character device with removable_device_t
Petr Lautrbach cd2c1d
- fix hibernate on btrfs swapfile (F40)
Petr Lautrbach cd2c1d
- Allow nut to statfs()
Petr Lautrbach cd2c1d
- Allow system dbusd service status systemd services
Petr Lautrbach cd2c1d
- Allow systemd-timedated get the timemaster service status
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Apr 09 2024 Zdenek Pytela <zpytela@redhat.com> - 40.16-1
Petr Lautrbach cd2c1d
- Allow keyutils-dns-resolver connect to the system log service
Petr Lautrbach cd2c1d
- Allow qemu-ga read vm sysctls
Petr Lautrbach cd2c1d
- postfix: allow qmgr to delete mails in bounce/ directory
Petr Lautrbach cd2c1d
- policy: support pidfs
Petr Lautrbach cd2c1d
- Confine selinux-autorelabel-generator.sh
Petr Lautrbach cd2c1d
- Allow logwatch_mail_t read/write to init over a unix stream socket
Petr Lautrbach cd2c1d
- Allow logwatch read logind sessions files
Petr Lautrbach cd2c1d
- files_dontaudit_getattr_tmpfs_files allowed the access and didn't dontaudit it
Petr Lautrbach cd2c1d
- files_dontaudit_mounton_modules_object allowed the access and didn't dontaudit it
Petr Lautrbach cd2c1d
- Allow NetworkManager the sys_ptrace capability in user namespace
Petr Lautrbach cd2c1d
- dontaudit execmem for modemmanager
Petr Lautrbach cd2c1d
- Allow dhcpcd use unix_stream_socket
Petr Lautrbach cd2c1d
- Allow dhcpc read /run/netns files
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri Mar 15 2024 Zdenek Pytela <zpytela@redhat.com> - 40.15-1
Petr Lautrbach cd2c1d
- Update mmap_rw_file_perms to include the lock permission
Petr Lautrbach cd2c1d
- Allow plymouthd log during shutdown
Petr Lautrbach cd2c1d
- Add logging_watch_all_log_dirs() and logging_watch_all_log_files()
Petr Lautrbach cd2c1d
- Allow journalctl_t read filesystem sysctls
Petr Lautrbach cd2c1d
- Allow cgred_t to get attributes of cgroup filesystems
Petr Lautrbach cd2c1d
- Allow wdmd read hardware state information
Petr Lautrbach cd2c1d
- Allow wdmd list the contents of the sysfs directories
Petr Lautrbach cd2c1d
- Allow linuxptp configure phc2sys and chronyd over a unix domain socket
Petr Lautrbach cd2c1d
- Allow sulogin relabel tty1
Petr Lautrbach cd2c1d
- Dontaudit sulogin the checkpoint_restore capability
Petr Lautrbach cd2c1d
- Modify sudo_role_template() to allow getpgid
Petr Lautrbach cd2c1d
- Remove incorrect "local" usage in varrun-convert.sh
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Mar 07 2024 Zdenek Pytela <zpytela@redhat.com> - 40.14-2
Petr Lautrbach cd2c1d
- Update varrun-convert.sh script to check for existing duplicate entries
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon Feb 26 2024 Zdenek Pytela <zpytela@redhat.com> - 40.14-1
Petr Lautrbach cd2c1d
- Allow userdomain get attributes of files on an nsfs filesystem
Petr Lautrbach cd2c1d
- Allow opafm create NFS files and directories
Petr Lautrbach cd2c1d
- Allow virtqemud create and unlink files in /etc/libvirt/
Petr Lautrbach cd2c1d
- Allow virtqemud domain transition on swtpm execution
Petr Lautrbach cd2c1d
- Add the swtpm.if interface file for interactions with other domains
Petr Lautrbach cd2c1d
- Allow samba to have dac_override capability
Petr Lautrbach cd2c1d
- systemd: allow sys_admin capability for systemd_notify_t
Petr Lautrbach cd2c1d
- systemd: allow systemd_notify_t to send data to kernel_t datagram sockets
Petr Lautrbach cd2c1d
- Allow thumb_t to watch and watch_reads mount_var_run_t
Petr Lautrbach cd2c1d
- Allow krb5kdc_t map krb5kdc_principal_t files
Petr Lautrbach cd2c1d
- Allow unprivileged confined user dbus chat with setroubleshoot
Petr Lautrbach cd2c1d
- Allow login_userdomain map files in /var
Petr Lautrbach cd2c1d
- Allow wireguard work with firewall-cmd
Petr Lautrbach cd2c1d
- Differentiate between staff and sysadm when executing crontab with sudo
Petr Lautrbach cd2c1d
- Add crontab_admin_domtrans interface
Petr Lautrbach cd2c1d
- Allow abrt_t nnp domain transition to abrt_handle_event_t
Petr Lautrbach cd2c1d
- Allow xdm_t to watch and watch_reads mount_var_run_t
Petr Lautrbach cd2c1d
- Dontaudit subscription manager setfscreate and read file contexts
Petr Lautrbach cd2c1d
- Don't audit crontab_domain write attempts to user home
Petr Lautrbach cd2c1d
- Transition from sudodomains to crontab_t when executing crontab_exec_t
Petr Lautrbach cd2c1d
- Add crontab_domtrans interface
Petr Lautrbach cd2c1d
- Fix label of pseudoterminals created from sudodomain
Petr Lautrbach cd2c1d
- Allow utempter_t use ptmx
Petr Lautrbach cd2c1d
- Dontaudit rpmdb attempts to connect to sssd over a unix stream socket
Petr Lautrbach cd2c1d
- Allow admin user read/write on fixed_disk_device_t
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon Feb 12 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13-1
Petr Lautrbach cd2c1d
- Only allow confined user domains to login locally without unconfined_login
Petr Lautrbach cd2c1d
- Add userdom_spec_domtrans_confined_admin_users interface
Petr Lautrbach cd2c1d
- Only allow admindomain to execute shell via ssh with ssh_sysadm_login
Petr Lautrbach cd2c1d
- Add userdom_spec_domtrans_admin_users interface
Petr Lautrbach cd2c1d
- Move ssh dyntrans to unconfined inside unconfined_login tunable policy
Petr Lautrbach cd2c1d
- Update ssh_role_template() for user ssh-agent type
Petr Lautrbach cd2c1d
- Allow init to inherit system DBus file descriptors
Petr Lautrbach cd2c1d
- Allow init to inherit fds from syslogd
Petr Lautrbach cd2c1d
- Allow any domain to inherit fds from rpm-ostree
Petr Lautrbach cd2c1d
- Update afterburn policy
Petr Lautrbach cd2c1d
- Allow init_t nnp domain transition to abrtd_t
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Feb 06 2024 Zdenek Pytela <zpytela@redhat.com> - 40.12-1
Petr Lautrbach cd2c1d
- Rename all /var/lock file context entries to /run/lock
Petr Lautrbach cd2c1d
- Rename all /var/run file context entries to /run
Petr Lautrbach cd2c1d
- Invert the "/var/run = /run" equivalency
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon Feb 05 2024 Zdenek Pytela <zpytela@redhat.com> - 40.11-1
Petr Lautrbach cd2c1d
- Replace init domtrans rule for confined users to allow exec init
Petr Lautrbach cd2c1d
- Update dbus_role_template() to allow user service status
Petr Lautrbach cd2c1d
- Allow polkit status all systemd services
Petr Lautrbach cd2c1d
- Allow setroubleshootd create and use inherited io_uring
Petr Lautrbach cd2c1d
- Allow load_policy read and write generic ptys
Petr Lautrbach cd2c1d
- Allow gpg manage rpm cache
Petr Lautrbach cd2c1d
- Allow login_userdomain name_bind to howl and xmsg udp ports
Petr Lautrbach cd2c1d
- Allow rules for confined users logged in plasma
Petr Lautrbach cd2c1d
- Label /dev/iommu with iommu_device_t
Petr Lautrbach cd2c1d
- Remove duplicate file context entries in /run
Petr Lautrbach cd2c1d
- Dontaudit getty and plymouth the checkpoint_restore capability
Petr Lautrbach cd2c1d
- Allow su domains write login records
Petr Lautrbach cd2c1d
- Revert "Allow su domains write login records"
Petr Lautrbach cd2c1d
- Allow login_userdomain delete session dbusd tmp socket files
Petr Lautrbach cd2c1d
- Allow unix dgram sendto between exim processes
Petr Lautrbach cd2c1d
- Allow su domains write login records
Petr Lautrbach cd2c1d
- Allow smbd_t to watch user_home_dir_t if samba_enable_home_dirs is on
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Wed Jan 24 2024 Zdenek Pytela <zpytela@redhat.com> - 40.10-1
Petr Lautrbach cd2c1d
- Allow chronyd-restricted read chronyd key files
Petr Lautrbach cd2c1d
- Allow conntrackd_t to use bpf capability2
Petr Lautrbach cd2c1d
- Allow systemd-networkd manage its runtime socket files
Petr Lautrbach cd2c1d
- Allow init_t nnp domain transition to colord_t
Petr Lautrbach cd2c1d
- Allow polkit status systemd services
Petr Lautrbach cd2c1d
- nova: Fix duplicate declarations
Petr Lautrbach cd2c1d
- Allow httpd work with PrivateTmp
Petr Lautrbach cd2c1d
- Add interfaces for watching and reading ifconfig_var_run_t
Petr Lautrbach cd2c1d
- Allow collectd read raw fixed disk device
Petr Lautrbach cd2c1d
- Allow collectd read udev pid files
Petr Lautrbach cd2c1d
- Set correct label on /etc/pki/pki-tomcat/kra
Petr Lautrbach cd2c1d
- Allow systemd domains watch system dbus pid socket files
Petr Lautrbach cd2c1d
- Allow certmonger read network sysctls
Petr Lautrbach cd2c1d
- Allow mdadm list stratisd data directories
Petr Lautrbach cd2c1d
- Allow syslog to run unconfined scripts conditionally
Petr Lautrbach cd2c1d
- Allow syslogd_t nnp_transition to syslogd_unconfined_script_t
Petr Lautrbach cd2c1d
- Allow qatlib set attributes of vfio device files
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Jan 09 2024 Zdenek Pytela <zpytela@redhat.com> - 40.9-1
Petr Lautrbach cd2c1d
- Allow systemd-sleep set attributes of efivarfs files
Petr Lautrbach cd2c1d
- Allow samba-dcerpcd read public files
Petr Lautrbach cd2c1d
- Allow spamd_update_t the sys_ptrace capability in user namespace
Petr Lautrbach cd2c1d
- Allow bluetooth devices work with alsa
Petr Lautrbach cd2c1d
- Allow alsa get attributes filesystems with extended attributes
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Jan 02 2024 Yaakov Selkowitz <yselkowi@redhat.com> - 40.8-2
Petr Lautrbach cd2c1d
- Limit %%selinux_requires to version, not release
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Dec 21 2023 Zdenek Pytela <zpytela@redhat.com> - 40.8-1
Petr Lautrbach cd2c1d
- Allow hypervkvp_t write access to NetworkManager_etc_rw_t
Petr Lautrbach cd2c1d
- Add interface for write-only access to NetworkManager rw conf
Petr Lautrbach cd2c1d
- Allow systemd-sleep send a message to syslog over a unix dgram socket
Petr Lautrbach cd2c1d
- Allow init create and use netlink netfilter socket
Petr Lautrbach cd2c1d
- Allow qatlib load kernel modules
Petr Lautrbach cd2c1d
- Allow qatlib run lspci
Petr Lautrbach cd2c1d
- Allow qatlib manage its private runtime socket files
Petr Lautrbach cd2c1d
- Allow qatlib read/write vfio devices
Petr Lautrbach cd2c1d
- Label /etc/redis.conf with redis_conf_t
Petr Lautrbach cd2c1d
- Remove the lockdown-class rules from the policy
Petr Lautrbach cd2c1d
- Allow init read all non-security socket files
Petr Lautrbach cd2c1d
- Replace redundant dnsmasq pattern macros
Petr Lautrbach cd2c1d
- Remove unneeded symlink perms in dnsmasq.if
Petr Lautrbach cd2c1d
- Add additions to dnsmasq interface
Petr Lautrbach cd2c1d
- Allow nvme_stas_t create and use netlink kobject uevent socket
Petr Lautrbach cd2c1d
- Allow collectd connect to statsd port
Petr Lautrbach cd2c1d
- Allow keepalived_t to use sys_ptrace of cap_userns
Petr Lautrbach cd2c1d
- Allow dovecot_auth_t connect to postgresql using UNIX socket
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Wed Dec 13 2023 Zdenek Pytela <zpytela@redhat.com> - 40.7-1
Petr Lautrbach cd2c1d
- Make named_zone_t and named_var_run_t a part of the mountpoint attribute
Petr Lautrbach cd2c1d
- Allow sysadm execute traceroute in sysadm_t domain using sudo
Petr Lautrbach cd2c1d
- Allow sysadm execute tcpdump in sysadm_t domain using sudo
Petr Lautrbach cd2c1d
- Allow opafm search nfs directories
Petr Lautrbach cd2c1d
- Add support for syslogd unconfined scripts
Petr Lautrbach cd2c1d
- Allow gpsd use /dev/gnss devices
Petr Lautrbach cd2c1d
- Allow gpg read rpm cache
Petr Lautrbach cd2c1d
- Allow virtqemud additional permissions
Petr Lautrbach cd2c1d
- Allow virtqemud manage its private lock files
Petr Lautrbach cd2c1d
- Allow virtqemud use the io_uring api
Petr Lautrbach cd2c1d
- Allow ddclient send e-mail notifications
Petr Lautrbach cd2c1d
- Allow postfix_master_t map postfix data files
Petr Lautrbach cd2c1d
- Allow init create and use vsock sockets
Petr Lautrbach cd2c1d
- Allow thumb_t append to init unix domain stream sockets
Petr Lautrbach cd2c1d
- Label /dev/vas with vas_device_t
Petr Lautrbach cd2c1d
- Change domain_kernel_load_modules boolean to true
Petr Lautrbach cd2c1d
- Create interface selinux_watch_config and add it to SELinux users
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Nov 28 2023 Zdenek Pytela <zpytela@redhat.com> - 40.6-1
Petr Lautrbach cd2c1d
- Add afterburn to modules-targeted-contrib.conf
Petr Lautrbach cd2c1d
- Update cifs interfaces to include fs_search_auto_mountpoints()
Petr Lautrbach cd2c1d
- Allow sudodomain read var auth files
Petr Lautrbach cd2c1d
- Allow spamd_update_t read hardware state information
Petr Lautrbach cd2c1d
- Allow virtnetworkd domain transition on tc command execution
Petr Lautrbach cd2c1d
- Allow sendmail MTA connect to sendmail LDA
Petr Lautrbach cd2c1d
- Allow auditd read all domains process state
Petr Lautrbach cd2c1d
- Allow rsync read network sysctls
Petr Lautrbach cd2c1d
- Add dhcpcd bpf capability to run bpf programs
Petr Lautrbach cd2c1d
- Dontaudit systemd-hwdb dac_override capability
Petr Lautrbach cd2c1d
- Allow systemd-sleep create efivarfs files
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Nov 14 2023 Zdenek Pytela <zpytela@redhat.com> - 40.5-1
Petr Lautrbach cd2c1d
- Allow map xserver_tmpfs_t files when xserver_clients_write_xshm is on
Petr Lautrbach cd2c1d
- Allow graphical applications work in Wayland
Petr Lautrbach cd2c1d
- Allow kdump work with PrivateTmp
Petr Lautrbach cd2c1d
- Allow dovecot-auth work with PrivateTmp
Petr Lautrbach cd2c1d
- Allow nfsd get attributes of all filesystems
Petr Lautrbach cd2c1d
- Allow unconfined_domain_type use io_uring cmd on domain
Petr Lautrbach cd2c1d
- ci: Only run Rawhide revdeps tests on the rawhide branch
Petr Lautrbach cd2c1d
- Label /var/run/auditd.state as auditd_var_run_t
Petr Lautrbach cd2c1d
- Allow fido-device-onboard (FDO) read the crack database
Petr Lautrbach cd2c1d
- Allow ip an explicit domain transition to other domains
Petr Lautrbach cd2c1d
- Label /usr/libexec/selinux/selinux-autorelabel with semanage_exec_t
Petr Lautrbach cd2c1d
- Allow  winbind_rpcd_t processes access when samba_export_all_* is on
Petr Lautrbach cd2c1d
- Enable NetworkManager and dhclient to use initramfs-configured DHCP connection
Petr Lautrbach cd2c1d
- Allow ntp to bind and connect to ntske port.
Petr Lautrbach cd2c1d
- Allow system_mail_t manage exim spool files and dirs
Petr Lautrbach cd2c1d
- Dontaudit keepalived setattr on keepalived_unconfined_script_exec_t
Petr Lautrbach cd2c1d
- Label /run/pcsd.socket with cluster_var_run_t
Petr Lautrbach cd2c1d
- ci: Run cockpit tests in PRs
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Oct 19 2023 Zdenek Pytela <zpytela@redhat.com> - 40.4-1
Petr Lautrbach cd2c1d
- Add map_read map_write to kernel_prog_run_bpf
Petr Lautrbach cd2c1d
- Allow systemd-fstab-generator read all symlinks
Petr Lautrbach cd2c1d
- Allow systemd-fstab-generator the dac_override capability
Petr Lautrbach cd2c1d
- Allow rpcbind read network sysctls
Petr Lautrbach cd2c1d
- Support using systemd containers
Petr Lautrbach cd2c1d
- Allow sysadm_t to connect to iscsid using a unix domain stream socket
Petr Lautrbach cd2c1d
- Add policy for coreos installer
Petr Lautrbach cd2c1d
- Add coreos_installer to modules-targeted-contrib.conf
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Oct 17 2023 Zdenek Pytela <zpytela@redhat.com> - 40.3-1
Petr Lautrbach cd2c1d
- Add policy for nvme-stas
Petr Lautrbach cd2c1d
- Confine systemd fstab,sysv,rc-local
Petr Lautrbach cd2c1d
- Label /etc/aliases.lmdb with etc_aliases_t
Petr Lautrbach cd2c1d
- Create policy for afterburn
Petr Lautrbach cd2c1d
- Add nvme_stas to modules-targeted-contrib.conf
Petr Lautrbach cd2c1d
- Add plans/tests.fmf
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Oct 10 2023 Zdenek Pytela <zpytela@redhat.com> - 40.2-1
Petr Lautrbach cd2c1d
- Add the virt_supplementary module to modules-targeted-contrib.conf
Petr Lautrbach cd2c1d
- Make new virt drivers permissive
Petr Lautrbach cd2c1d
- Split virt policy, introduce virt_supplementary module
Petr Lautrbach cd2c1d
- Allow apcupsd cgi scripts read /sys
Petr Lautrbach cd2c1d
- Merge pull request #1893 from WOnder93/more-early-boot-overlay-fixes
Petr Lautrbach cd2c1d
- Allow kernel_t to manage and relabel all files
Petr Lautrbach cd2c1d
- Add missing optional_policy() to files_relabel_all_files()
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Oct 03 2023 Zdenek Pytela <zpytela@redhat.com> - 40.1-1
Petr Lautrbach cd2c1d
- Allow named and ndc use the io_uring api
Petr Lautrbach cd2c1d
- Deprecate common_anon_inode_perms usage
Petr Lautrbach cd2c1d
- Improve default file context(None) of /var/lib/authselect/backups
Petr Lautrbach cd2c1d
- Allow udev_t to search all directories with a filesystem type
Petr Lautrbach cd2c1d
- Implement proper anon_inode support
Petr Lautrbach cd2c1d
- Allow targetd write to the syslog pid sock_file
Petr Lautrbach cd2c1d
- Add ipa_pki_retrieve_key_exec() interface
Petr Lautrbach cd2c1d
- Allow kdumpctl_t to list all directories with a filesystem type
Petr Lautrbach cd2c1d
- Allow udev additional permissions
Petr Lautrbach cd2c1d
- Allow udev load kernel module
Petr Lautrbach cd2c1d
- Allow sysadm_t to mmap modules_object_t files
Petr Lautrbach cd2c1d
- Add the unconfined_read_files() and unconfined_list_dirs() interfaces
Petr Lautrbach cd2c1d
- Set default file context of HOME_DIR/tmp/.* to <<none>>
Petr Lautrbach cd2c1d
- Allow kernel_generic_helper_t to execute mount(1)
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri Sep 29 2023 Zdenek Pytela <zpytela@redhat.com> - 38.29-1
Petr Lautrbach cd2c1d
- Allow sssd send SIGKILL to passkey_child running in ipa_otpd_t
Petr Lautrbach cd2c1d
- Allow systemd-localed create Xserver config dirs
Petr Lautrbach cd2c1d
- Allow sssd read symlinks in /etc/sssd
Petr Lautrbach cd2c1d
- Label /dev/gnss[0-9] with gnss_device_t
Petr Lautrbach cd2c1d
- Allow systemd-sleep read/write efivarfs variables
Petr Lautrbach cd2c1d
- ci: Fix version number of packit generated srpms
Petr Lautrbach cd2c1d
- Dontaudit rhsmcertd write memory device
Petr Lautrbach cd2c1d
- Allow ssh_agent_type create a sockfile in /run/user/USERID
Petr Lautrbach cd2c1d
- Set default file context of /var/lib/authselect/backups to <<none>>
Petr Lautrbach cd2c1d
- Allow prosody read network sysctls
Petr Lautrbach cd2c1d
- Allow cupsd_t to use bpf capability
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri Sep 15 2023 Zdenek Pytela <zpytela@redhat.com> - 38.28-1
Petr Lautrbach cd2c1d
- Allow sssd domain transition on passkey_child execution conditionally
Petr Lautrbach cd2c1d
- Allow login_userdomain watch lnk_files in /usr
Petr Lautrbach cd2c1d
- Allow login_userdomain watch video4linux devices
Petr Lautrbach cd2c1d
- Change systemd-network-generator transition to include class file
Petr Lautrbach cd2c1d
- Revert "Change file transition for systemd-network-generator"
Petr Lautrbach cd2c1d
- Allow nm-dispatcher winbind plugin read/write samba var files
Petr Lautrbach cd2c1d
- Allow systemd-networkd write to cgroup files
Petr Lautrbach cd2c1d
- Allow kdump create and use its memfd: objects
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Aug 31 2023 Zdenek Pytela <zpytela@redhat.com> - 38.27-1
Petr Lautrbach cd2c1d
- Allow fedora-third-party get generic filesystem attributes
Petr Lautrbach cd2c1d
- Allow sssd use usb devices conditionally
Petr Lautrbach cd2c1d
- Update policy for qatlib
Petr Lautrbach cd2c1d
- Allow ssh_agent_type manage generic cache home files
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Aug 24 2023 Zdenek Pytela <zpytela@redhat.com> - 38.26-1
Petr Lautrbach cd2c1d
- Change file transition for systemd-network-generator
Petr Lautrbach cd2c1d
- Additional support for gnome-initial-setup
Petr Lautrbach cd2c1d
- Update gnome-initial-setup policy for geoclue
Petr Lautrbach cd2c1d
- Allow openconnect vpn open vhost net device
Petr Lautrbach cd2c1d
- Allow cifs.upcall to connect to SSSD also through the /var/run socket
Petr Lautrbach cd2c1d
- Grant cifs.upcall more required capabilities
Petr Lautrbach cd2c1d
- Allow xenstored map xenfs files
Petr Lautrbach cd2c1d
- Update policy for fdo
Petr Lautrbach cd2c1d
- Allow keepalived watch var_run dirs
Petr Lautrbach cd2c1d
- Allow svirt to rw /dev/udmabuf
Petr Lautrbach cd2c1d
- Allow qatlib  to modify hardware state information.
Petr Lautrbach cd2c1d
- Allow key.dns_resolve connect to avahi over a unix stream socket
Petr Lautrbach cd2c1d
- Allow key.dns_resolve create and use unix datagram socket
Petr Lautrbach cd2c1d
- Use quay.io as the container image source for CI
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri Aug 11 2023 Zdenek Pytela <zpytela@redhat.com> - 38.25-1
Petr Lautrbach cd2c1d
- ci: Move srpm/rpm build to packit
Petr Lautrbach cd2c1d
- .copr: Avoid subshell and changing directory
Petr Lautrbach cd2c1d
- Allow gpsd, oddjob and oddjob_mkhomedir_t write user_tty_device_t chr_file
Petr Lautrbach cd2c1d
- Label /usr/libexec/openssh/ssh-pkcs11-helper with ssh_agent_exec_t
Petr Lautrbach cd2c1d
- Make insights_client_t an unconfined domain
Petr Lautrbach cd2c1d
- Allow insights-client manage user temporary files
Petr Lautrbach cd2c1d
- Allow insights-client create all rpm logs with a correct label
Petr Lautrbach cd2c1d
- Allow insights-client manage generic logs
Petr Lautrbach cd2c1d
- Allow cloud_init create dhclient var files and init_t manage net_conf_t
Petr Lautrbach cd2c1d
- Allow insights-client read and write cluster tmpfs files
Petr Lautrbach cd2c1d
- Allow ipsec read nsfs files
Petr Lautrbach cd2c1d
- Make tuned work with mls policy
Petr Lautrbach cd2c1d
- Remove nsplugin_role from mozilla.if
Petr Lautrbach cd2c1d
- allow mon_procd_t self:cap_userns sys_ptrace
Petr Lautrbach cd2c1d
- Allow pdns name_bind and name_connect all ports
Petr Lautrbach cd2c1d
- Set the MLS range of fsdaemon_t to s0 - mls_systemhigh
Petr Lautrbach cd2c1d
- ci: Move to actions/checkout@v3 version
Petr Lautrbach cd2c1d
- .copr: Replace chown call with standard workflow safe.directory setting
Petr Lautrbach cd2c1d
- .copr: Enable `set -u` for robustness
Petr Lautrbach cd2c1d
- .copr: Simplify root directory variable
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri Aug 04 2023 Zdenek Pytela <zpytela@redhat.com> - 38.24-1
Petr Lautrbach cd2c1d
- Allow rhsmcertd dbus chat with policykit
Petr Lautrbach cd2c1d
- Allow polkitd execute pkla-check-authorization with nnp transition
Petr Lautrbach cd2c1d
- Allow user_u and staff_u get attributes of non-security dirs
Petr Lautrbach cd2c1d
- Allow unconfined user filetrans chrome_sandbox_home_t
Petr Lautrbach cd2c1d
- Allow svnserve execute postdrop with a transition
Petr Lautrbach cd2c1d
- Do not make postfix_postdrop_t type an MTA executable file
Petr Lautrbach cd2c1d
- Allow samba-dcerpc service manage samba tmp files
Petr Lautrbach cd2c1d
- Add use_nfs_home_dirs boolean for mozilla_plugin
Petr Lautrbach cd2c1d
- Fix labeling for no-stub-resolv.conf
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Wed Aug 02 2023 Zdenek Pytela <zpytela@redhat.com> - 38.23-1
Petr Lautrbach cd2c1d
- Revert "Allow winbind-rpcd use its private tmp files"
Petr Lautrbach cd2c1d
- Allow upsmon execute upsmon via a helper script
Petr Lautrbach cd2c1d
- Allow openconnect vpn read/write inherited vhost net device
Petr Lautrbach cd2c1d
- Allow winbind-rpcd use its private tmp files
Petr Lautrbach cd2c1d
- Update samba-dcerpc policy for printing
Petr Lautrbach cd2c1d
- Allow gpsd,oddjob,oddjob_mkhomedir rw user domain pty
Petr Lautrbach cd2c1d
- Allow nscd watch system db dirs
Petr Lautrbach cd2c1d
- Allow qatlib to read sssd public files
Petr Lautrbach cd2c1d
- Allow fedora-third-party read /sys and proc
Petr Lautrbach cd2c1d
- Allow systemd-gpt-generator mount a tmpfs filesystem
Petr Lautrbach cd2c1d
- Allow journald write to cgroup files
Petr Lautrbach cd2c1d
- Allow rpc.mountd read network sysctls
Petr Lautrbach cd2c1d
- Allow blueman read the contents of the sysfs filesystem
Petr Lautrbach cd2c1d
- Allow logrotate_t to map generic files in /etc
Petr Lautrbach cd2c1d
- Boolean: Allow virt_qemu_ga create ssh directory
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Jul 25 2023 Zdenek Pytela <zpytela@redhat.com> - 38.22-1
Petr Lautrbach cd2c1d
- Allow systemd-network-generator send system log messages
Petr Lautrbach cd2c1d
- Dontaudit the execute permission on sock_file globally
Petr Lautrbach cd2c1d
- Allow fsadm_t the file mounton permission
Petr Lautrbach cd2c1d
- Allow named and ndc the io_uring sqpoll permission
Petr Lautrbach cd2c1d
- Allow sssd io_uring sqpoll permission
Petr Lautrbach cd2c1d
- Fix location for /run/nsd
Petr Lautrbach cd2c1d
- Allow qemu-ga get fixed disk devices attributes
Petr Lautrbach cd2c1d
- Update bitlbee policy
Petr Lautrbach cd2c1d
- Label /usr/sbin/sos with sosreport_exec_t
Petr Lautrbach cd2c1d
- Update policy for the sblim-sfcb service
Petr Lautrbach cd2c1d
- Add the files_getattr_non_auth_dirs() interface
Petr Lautrbach cd2c1d
- Fix the CI to work with DNF5
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Sat Jul 22 2023 Fedora Release Engineering <releng@fedoraproject.org> - 38.21-2
Petr Lautrbach cd2c1d
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Jul 13 2023 Zdenek Pytela <zpytela@redhat.com> - 38.21-1
Petr Lautrbach cd2c1d
- Make systemd_tmpfiles_t MLS trusted for lowering the level of files
Petr Lautrbach cd2c1d
- Revert "Allow insights client map cache_home_t"
Petr Lautrbach cd2c1d
- Allow nfsidmapd connect to systemd-machined over a unix socket
Petr Lautrbach cd2c1d
- Allow snapperd connect to kernel over a unix domain stream socket
Petr Lautrbach cd2c1d
- Allow virt_qemu_ga_t create .ssh dir with correct label
Petr Lautrbach cd2c1d
- Allow targetd read network sysctls
Petr Lautrbach cd2c1d
- Set the abrt_handle_event boolean to on
Petr Lautrbach cd2c1d
- Permit kernel_t to change the user identity in object contexts
Petr Lautrbach cd2c1d
- Allow insights client map cache_home_t
Petr Lautrbach cd2c1d
- Label /usr/sbin/mariadbd with mysqld_exec_t
Petr Lautrbach cd2c1d
- Trim changelog so that it starts at F37 time
Petr Lautrbach cd2c1d
- Define equivalency for /run/systemd/generator.early
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Jun 29 2023 Zdenek Pytela <zpytela@redhat.com> - 38.20-1
Petr Lautrbach cd2c1d
- Allow httpd tcp connect to redis port conditionally
Petr Lautrbach cd2c1d
- Label only /usr/sbin/ripd and ripngd with zebra_exec_t
Petr Lautrbach cd2c1d
- Dontaudit aide the execmem permission
Petr Lautrbach cd2c1d
- Remove permissive from fdo
Petr Lautrbach cd2c1d
- Allow sa-update manage spamc home files
Petr Lautrbach cd2c1d
- Allow sa-update connect to systemlog services
Petr Lautrbach cd2c1d
- Label /usr/lib/systemd/system/mimedefang.service with antivirus_unit_file_t
Petr Lautrbach cd2c1d
- Allow nsd_crond_t write nsd_var_run_t & connectto nsd_t
Petr Lautrbach cd2c1d
- Allow bootupd search EFI directory
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Jun 27 2023 Zdenek Pytela <zpytela@redhat.com> - 38.19-1
Petr Lautrbach cd2c1d
- Change init_audit_control default value to true
Petr Lautrbach cd2c1d
- Allow nfsidmapd connect to systemd-userdbd with a unix socket
Petr Lautrbach cd2c1d
- Add the qatlib  module
Petr Lautrbach cd2c1d
- Add the fdo module
Petr Lautrbach cd2c1d
- Add the bootupd module
Petr Lautrbach cd2c1d
- Set default ports for keylime policy
Petr Lautrbach cd2c1d
- Create policy for qatlib
Petr Lautrbach cd2c1d
- Add policy for FIDO Device Onboard
Petr Lautrbach cd2c1d
- Add policy for bootupd
Petr Lautrbach cd2c1d
- Add the qatlib module
Petr Lautrbach cd2c1d
- Add the fdo module
Petr Lautrbach cd2c1d
- Add the bootupd module
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Sun Jun 25 2023 Zdenek Pytela <zpytela@redhat.com> - 38.18-1
Petr Lautrbach cd2c1d
- Add support for kafs-dns requested by keyutils
Petr Lautrbach cd2c1d
- Allow insights-client execmem
Petr Lautrbach cd2c1d
- Add support for chronyd-restricted
Petr Lautrbach cd2c1d
- Add init_explicit_domain() interface
Petr Lautrbach cd2c1d
- Allow fsadm_t to get attributes of cgroup filesystems
Petr Lautrbach cd2c1d
- Add list_dir_perms to kerberos_read_keytab
Petr Lautrbach cd2c1d
- Label /var/run/tmpfiles.d/static-nodes.conf with kmod_var_run_t
Petr Lautrbach cd2c1d
- Allow sendmail manage its runtime files
Petr Lautrbach cd2c1d
- Allow keyutils_dns_resolver_exec_t be an entrypoint
Petr Lautrbach cd2c1d
- Allow collectd_t read network state symlinks
Petr Lautrbach cd2c1d
- Revert "Allow collectd_t read proc_net link files"
Petr Lautrbach cd2c1d
- Allow nfsd_t to list exports_t dirs
Petr Lautrbach cd2c1d
- Allow cupsd dbus chat with xdm
Petr Lautrbach cd2c1d
- Allow haproxy read hardware state information
Petr Lautrbach cd2c1d
- Add the kafs module
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Jun 15 2023 Zdenek Pytela <zpytela@redhat.com> - 38.17-1
Petr Lautrbach cd2c1d
- Label /dev/userfaultfd with userfaultfd_t
Petr Lautrbach cd2c1d
- Allow blueman send general signals to unprivileged user domains
Petr Lautrbach cd2c1d
- Allow dkim-milter domain transition to sendmail
Petr Lautrbach cd2c1d
- Label /usr/sbin/cifs.idmap with cifs_helper_exec_t
Petr Lautrbach cd2c1d
- Allow cifs-helper read sssd kerberos configuration files
Petr Lautrbach cd2c1d
- Allow rpm_t sys_admin capability
Petr Lautrbach cd2c1d
- Allow dovecot_deliver_t create/map dovecot_spool_t dir/file
Petr Lautrbach cd2c1d
- Allow collectd_t read proc_net link files
Petr Lautrbach cd2c1d
- Allow insights-client getsession process permission
Petr Lautrbach cd2c1d
- Allow insights-client work with pipe and socket tmp files
Petr Lautrbach cd2c1d
- Allow insights-client map generic log files
Petr Lautrbach cd2c1d
- Update cyrus_stream_connect() to use sockets in /run
Petr Lautrbach cd2c1d
- Allow keyutils-dns-resolver read/view kernel key ring
Petr Lautrbach cd2c1d
- Label /var/log/kdump.log with kdump_log_t
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri Jun 09 2023 Zdenek Pytela <zpytela@redhat.com> - 38.16-1
Petr Lautrbach cd2c1d
- Add support for the systemd-pstore service
Petr Lautrbach cd2c1d
- Allow kdumpctl_t to execmem
Petr Lautrbach cd2c1d
- Update sendmail policy module for opensmtpd
Petr Lautrbach cd2c1d
- Allow nagios-mail-plugin exec postfix master
Petr Lautrbach cd2c1d
- Allow subscription-manager execute ip
Petr Lautrbach cd2c1d
- Allow ssh client connect with a user dbus instance
Petr Lautrbach cd2c1d
- Add support for ksshaskpass
Petr Lautrbach cd2c1d
- Allow rhsmcertd file transition in /run also for socket files
Petr Lautrbach cd2c1d
- Allow keyutils_dns_resolver_t execute keyutils_dns_resolver_exec_t
Petr Lautrbach cd2c1d
- Allow plymouthd read/write X server miscellaneous devices
Petr Lautrbach cd2c1d
- Allow systemd-sleep read udev pid files
Petr Lautrbach cd2c1d
- Allow exim read network sysctls
Petr Lautrbach cd2c1d
- Allow sendmail request load module
Petr Lautrbach cd2c1d
- Allow named map its conf files
Petr Lautrbach cd2c1d
- Allow squid map its cache files
Petr Lautrbach cd2c1d
- Allow NetworkManager_dispatcher_dhclient_t to execute shells without a domain transition
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue May 30 2023 Zdenek Pytela <zpytela@redhat.com> - 38.15-1
Petr Lautrbach cd2c1d
- Update policy for systemd-sleep
Petr Lautrbach cd2c1d
- Remove permissive domain for rshim_t
Petr Lautrbach cd2c1d
- Remove permissive domain for mptcpd_t
Petr Lautrbach cd2c1d
- Allow systemd-bootchartd the sys_ptrace userns capability
Petr Lautrbach cd2c1d
- Allow sysadm_t read nsfs files
Petr Lautrbach cd2c1d
- Allow sysadm_t run kernel bpf programs
Petr Lautrbach cd2c1d
- Update ssh_role_template for ssh-agent
Petr Lautrbach cd2c1d
- Update ssh_role_template to allow read/write unallocated ttys
Petr Lautrbach cd2c1d
- Add the booth module to modules.conf
Petr Lautrbach cd2c1d
- Allow firewalld rw ica_tmpfs_t files
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri May 26 2023 Zdenek Pytela <zpytela@redhat.com> - 38.14-1
Petr Lautrbach cd2c1d
- Remove permissive domain for cifs_helper_t
Petr Lautrbach cd2c1d
- Update the cifs-helper policy
Petr Lautrbach cd2c1d
- Replace cifsutils_helper_domtrans() with keyutils_request_domtrans_to()
Petr Lautrbach cd2c1d
- Update pkcsslotd policy for sandboxing
Petr Lautrbach cd2c1d
- Allow abrt_t read kernel persistent storage files
Petr Lautrbach cd2c1d
- Dontaudit targetd search httpd config dirs
Petr Lautrbach cd2c1d
- Allow init_t nnp domain transition to policykit_t
Petr Lautrbach cd2c1d
- Allow rpcd_lsad setcap and use generic ptys
Petr Lautrbach cd2c1d
- Allow samba-dcerpcd connect to systemd_machined over a unix socket
Petr Lautrbach cd2c1d
- Allow wireguard to rw network sysctls
Petr Lautrbach cd2c1d
- Add policy for boothd
Petr Lautrbach cd2c1d
- Allow kernel to manage its own BPF objects
Petr Lautrbach cd2c1d
- Label /usr/lib/systemd/system/proftpd.* & vsftpd.* with ftpd_unit_file_t
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon May 22 2023 Zdenek Pytela <zpytela@redhat.com> - 38.13-1
Petr Lautrbach cd2c1d
- Add initial policy for cifs-helper
Petr Lautrbach cd2c1d
- Label key.dns_resolver with keyutils_dns_resolver_exec_t
Petr Lautrbach cd2c1d
- Allow unconfined_service_t to create .gnupg labeled as gpg_secret_t
Petr Lautrbach cd2c1d
- Allow some systemd services write to cgroup files
Petr Lautrbach cd2c1d
- Allow NetworkManager_dispatcher_dhclient_t to read the DHCP configuration files
Petr Lautrbach cd2c1d
- Allow systemd resolved to bind to arbitrary nodes
Petr Lautrbach cd2c1d
- Allow plymouthd_t bpf capability to run bpf programs
Petr Lautrbach cd2c1d
- Allow cupsd to create samba_var_t files
Petr Lautrbach cd2c1d
- Allow rhsmcert request the kernel to load a module
Petr Lautrbach cd2c1d
- Allow virsh name_connect virt_port_t
Petr Lautrbach cd2c1d
- Allow certmonger manage cluster library files
Petr Lautrbach cd2c1d
- Allow plymouthd read init process state
Petr Lautrbach cd2c1d
- Add chromium_sandbox_t setcap capability
Petr Lautrbach cd2c1d
- Allow snmpd read raw disk data
Petr Lautrbach cd2c1d
- Allow samba-rpcd work with passwords
Petr Lautrbach cd2c1d
- Allow unconfined service inherit signal state from init
Petr Lautrbach cd2c1d
- Allow cloud-init manage gpg admin home content
Petr Lautrbach cd2c1d
- Allow cluster_t dbus chat with various services
Petr Lautrbach cd2c1d
- Allow nfsidmapd work with systemd-userdbd and sssd
Petr Lautrbach cd2c1d
- Allow unconfined_domain_type use IORING_OP_URING_CMD on all device nodes
Petr Lautrbach cd2c1d
- Allow plymouthd map dri and framebuffer devices
Petr Lautrbach cd2c1d
- Allow rpmdb_migrate execute rpmdb
Petr Lautrbach cd2c1d
- Allow logrotate dbus chat with systemd-hostnamed
Petr Lautrbach cd2c1d
- Allow icecast connect to kernel using a unix stream socket
Petr Lautrbach cd2c1d
- Allow lldpad connect to systemd-userdbd over a unix socket
Petr Lautrbach cd2c1d
- Allow journalctl open user domain ptys and ttys
Petr Lautrbach cd2c1d
- Allow keepalived to manage its tmp files
Petr Lautrbach cd2c1d
- Allow ftpd read network sysctls
Petr Lautrbach cd2c1d
- Label /run/bgpd with zebra_var_run_t
Petr Lautrbach cd2c1d
- Allow gssproxy read network sysctls
Petr Lautrbach cd2c1d
- Add the cifsutils module
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Apr 25 2023 Zdenek Pytela <zpytela@redhat.com> - 38.12-1
Petr Lautrbach cd2c1d
- Allow telnetd read network sysctls
Petr Lautrbach cd2c1d
- Allow munin system plugin read generic SSL certificates
Petr Lautrbach cd2c1d
- Allow munin system plugin create and use netlink generic socket
Petr Lautrbach cd2c1d
- Allow login_userdomain create user namespaces
Petr Lautrbach cd2c1d
- Allow request-key to send syslog messages
Petr Lautrbach cd2c1d
- Allow request-key to read/view any key
Petr Lautrbach cd2c1d
- Add fs_delete_pstore_files() interface
Petr Lautrbach cd2c1d
- Allow insights-client work with teamdctl
Petr Lautrbach cd2c1d
- Allow insights-client read unconfined service semaphores
Petr Lautrbach cd2c1d
- Allow insights-client get quotas of all filesystems
Petr Lautrbach cd2c1d
- Add fs_read_pstore_files() interface
Petr Lautrbach cd2c1d
- Allow generic kernel helper to read inherited kernel pipes
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri Apr 14 2023 Zdenek Pytela <zpytela@redhat.com> - 38.11-1
Petr Lautrbach cd2c1d
- Allow dovecot-deliver write to the main process runtime fifo files
Petr Lautrbach cd2c1d
- Allow dmidecode write to cloud-init tmp files
Petr Lautrbach cd2c1d
- Allow chronyd send a message to cloud-init over a datagram socket
Petr Lautrbach cd2c1d
- Allow cloud-init domain transition to insights-client domain
Petr Lautrbach cd2c1d
- Allow mongodb read filesystem sysctls
Petr Lautrbach cd2c1d
- Allow mongodb read network sysctls
Petr Lautrbach cd2c1d
- Allow accounts-daemon read generic systemd unit lnk files
Petr Lautrbach cd2c1d
- Allow blueman watch generic device dirs
Petr Lautrbach cd2c1d
- Allow nm-dispatcher tlp plugin create tlp dirs
Petr Lautrbach cd2c1d
- Allow systemd-coredump mounton /usr
Petr Lautrbach cd2c1d
- Allow rabbitmq to read network sysctls
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Apr 04 2023 Zdenek Pytela <zpytela@redhat.com> - 38.10-1
Petr Lautrbach cd2c1d
- Allow certmonger dbus chat with the cron system domain
Petr Lautrbach cd2c1d
- Allow geoclue read network sysctls
Petr Lautrbach cd2c1d
- Allow geoclue watch the /etc directory
Petr Lautrbach cd2c1d
- Allow logwatch_mail_t read network sysctls
Petr Lautrbach cd2c1d
- Allow insights-client read all sysctls
Petr Lautrbach cd2c1d
- Allow passt manage qemu pid sock files
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri Mar 24 2023 Zdenek Pytela <zpytela@redhat.com> - 38.9-1
Petr Lautrbach cd2c1d
- Allow sssd read accountsd fifo files
Petr Lautrbach cd2c1d
- Add support for the passt_t domain
Petr Lautrbach cd2c1d
- Allow virtd_t and svirt_t work with passt
Petr Lautrbach cd2c1d
- Add new interfaces in the virt module
Petr Lautrbach cd2c1d
- Add passt interfaces defined conditionally
Petr Lautrbach cd2c1d
- Allow tshark the setsched capability
Petr Lautrbach cd2c1d
- Allow poweroff create connections to system dbus
Petr Lautrbach cd2c1d
- Allow wg load kernel modules, search debugfs dir
Petr Lautrbach cd2c1d
- Boolean: allow qemu-ga manage ssh home directory
Petr Lautrbach cd2c1d
- Label smtpd with sendmail_exec_t
Petr Lautrbach cd2c1d
- Label msmtp and msmtpd with sendmail_exec_t
Petr Lautrbach cd2c1d
- Allow dovecot to map files in /var/spool/dovecot
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri Mar 03 2023 Zdenek Pytela <zpytela@redhat.com> - 38.8-1
Petr Lautrbach cd2c1d
- Confine gnome-initial-setup
Petr Lautrbach cd2c1d
- Allow qemu-guest-agent create and use vsock socket
Petr Lautrbach cd2c1d
- Allow login_pgm setcap permission
Petr Lautrbach cd2c1d
- Allow chronyc read network sysctls
Petr Lautrbach cd2c1d
- Enhancement of the /usr/sbin/request-key helper policy
Petr Lautrbach cd2c1d
- Fix opencryptoki file names in /dev/shm
Petr Lautrbach cd2c1d
- Allow system_cronjob_t transition to rpm_script_t
Petr Lautrbach cd2c1d
- Revert "Allow system_cronjob_t domtrans to rpm_script_t"
Petr Lautrbach cd2c1d
- Add tunable to allow squid bind snmp port
Petr Lautrbach cd2c1d
- Allow staff_t getattr init pid chr & blk files and read krb5
Petr Lautrbach cd2c1d
- Allow firewalld to rw z90crypt device
Petr Lautrbach cd2c1d
- Allow httpd work with tokens in /dev/shm
Petr Lautrbach cd2c1d
- Allow svirt to map svirt_image_t char files
Petr Lautrbach cd2c1d
- Allow sysadm_t run initrc_t script and sysadm_r role access
Petr Lautrbach cd2c1d
- Allow insights-client manage fsadm pid files
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Wed Feb 08 2023 Zdenek Pytela <zpytela@redhat.com> - 38.7-1
Petr Lautrbach cd2c1d
- Allowing snapper to create snapshots of /home/ subvolume/partition
Petr Lautrbach cd2c1d
- Add boolean qemu-ga to run unconfined script
Petr Lautrbach cd2c1d
- Label systemd-journald feature LogNamespace
Petr Lautrbach cd2c1d
- Add none file context for polyinstantiated tmp dirs
Petr Lautrbach cd2c1d
- Allow certmonger read the contents of the sysfs filesystem
Petr Lautrbach cd2c1d
- Add journalctl the sys_resource capability
Petr Lautrbach cd2c1d
- Allow nm-dispatcher plugins read generic files in /proc
Petr Lautrbach cd2c1d
- Add initial policy for the /usr/sbin/request-key helper
Petr Lautrbach cd2c1d
- Additional support for rpmdb_migrate
Petr Lautrbach cd2c1d
- Add the keyutils module
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon Jan 30 2023 Zdenek Pytela <zpytela@redhat.com> - 38.6-1
Petr Lautrbach cd2c1d
- Boolean: allow qemu-ga read ssh home directory
Petr Lautrbach cd2c1d
- Allow kernel_t to read/write all sockets
Petr Lautrbach cd2c1d
- Allow kernel_t to UNIX-stream connect to all domains
Petr Lautrbach cd2c1d
- Allow systemd-resolved send a datagram to journald
Petr Lautrbach cd2c1d
- Allow kernel_t to manage and have "execute" access to all files
Petr Lautrbach cd2c1d
- Fix the files_manage_all_files() interface
Petr Lautrbach cd2c1d
- Allow rshim bpf cap2 and read sssd public files
Petr Lautrbach cd2c1d
- Allow insights-client work with su and lpstat
Petr Lautrbach cd2c1d
- Allow insights-client tcp connect to all ports
Petr Lautrbach cd2c1d
- Allow nm-cloud-setup dispatcher plugin restart nm services
Petr Lautrbach cd2c1d
- Allow unconfined user filetransition for sudo log files
Petr Lautrbach cd2c1d
- Allow modemmanager create hardware state information files
Petr Lautrbach cd2c1d
- Allow ModemManager all permissions for netlink route socket
Petr Lautrbach cd2c1d
- Allow wg to send msg to kernel, write to syslog and dbus connections
Petr Lautrbach cd2c1d
- Allow hostname_t to read network sysctls.
Petr Lautrbach cd2c1d
- Dontaudit ftpd the execmem permission
Petr Lautrbach cd2c1d
- Allow svirt request the kernel to load a module
Petr Lautrbach cd2c1d
- Allow icecast rename its log files
Petr Lautrbach cd2c1d
- Allow upsd to send signal to itself
Petr Lautrbach cd2c1d
- Allow wireguard to create udp sockets and read net_conf
Petr Lautrbach cd2c1d
- Use '%autosetup' instead of '%setup'
Petr Lautrbach cd2c1d
- Pass -p 1 to '%autosetup'
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Sat Jan 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 38.5-2
Petr Lautrbach cd2c1d
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri Jan 13 2023 Zdenek Pytela <zpytela@redhat.com> - 38.5-1
Petr Lautrbach cd2c1d
- Allow insights client work with gluster and pcp
Petr Lautrbach cd2c1d
- Add insights additional capabilities
Petr Lautrbach cd2c1d
- Add interfaces in domain, files, and unconfined modules
Petr Lautrbach cd2c1d
- Label fwupdoffline and fwupd-detect-cet with fwupd_exec_t
Petr Lautrbach cd2c1d
- Allow sudodomain use sudo.log as a logfile
Petr Lautrbach cd2c1d
- Allow pdns server map its library files and bind to unreserved ports
Petr Lautrbach cd2c1d
- Allow sysadm_t read/write ipmi devices
Petr Lautrbach cd2c1d
- Allow prosody manage its runtime socket files
Petr Lautrbach cd2c1d
- Allow kernel threads manage kernel keys
Petr Lautrbach cd2c1d
- Allow systemd-userdbd the sys_resource capability
Petr Lautrbach cd2c1d
- Allow systemd-journal list cgroup directories
Petr Lautrbach cd2c1d
- Allow apcupsd dbus chat with systemd-logind
Petr Lautrbach cd2c1d
- Allow nut_domain manage also files and sock_files in /var/run
Petr Lautrbach cd2c1d
- Allow winbind-rpcd make a TCP connection to the ldap port
Petr Lautrbach cd2c1d
- Label /usr/lib/rpm/rpmdb_migrate with rpmdb_exec_t
Petr Lautrbach cd2c1d
- Allow tlp read generic SSL certificates
Petr Lautrbach cd2c1d
- Allow systemd-resolved watch tmpfs directories
Petr Lautrbach cd2c1d
- Revert "Allow systemd-resolved watch tmpfs directories"
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon Dec 19 2022 Zdenek Pytela <zpytela@redhat.com> - 38.4-1
Petr Lautrbach cd2c1d
- Allow NetworkManager and wpa_supplicant the bpf capability
Petr Lautrbach cd2c1d
- Allow systemd-rfkill the bpf capability
Petr Lautrbach cd2c1d
- Allow winbind-rpcd manage samba_share_t files and dirs
Petr Lautrbach cd2c1d
- Label /var/lib/httpd/md(/.*)? with httpd_sys_rw_content_t
Petr Lautrbach cd2c1d
- Allow gpsd the sys_ptrace userns capability
Petr Lautrbach cd2c1d
- Introduce gpsd_tmp_t for sockfiles managed by gpsd_t
Petr Lautrbach cd2c1d
- Allow load_policy_t write to unallocated ttys
Petr Lautrbach cd2c1d
- Allow ndc read hardware state information
Petr Lautrbach cd2c1d
- Allow system mail service read inherited certmonger runtime files
Petr Lautrbach cd2c1d
- Add lpr_roles  to system_r roles
Petr Lautrbach cd2c1d
- Revert "Allow insights-client run lpr and allow the proper role"
Petr Lautrbach cd2c1d
- Allow stalld to read /sys/kernel/security/lockdown file
Petr Lautrbach cd2c1d
- Allow keepalived to set resource limits
Petr Lautrbach cd2c1d
- Add policy for mptcpd
Petr Lautrbach cd2c1d
- Add policy for rshim
Petr Lautrbach cd2c1d
- Allow admin users to create user namespaces
Petr Lautrbach cd2c1d
- Allow journalctl relabel with var_log_t and syslogd_var_run_t files
Petr Lautrbach cd2c1d
- Do not run restorecon /etc/NetworkManager/dispatcher.d in targeted
Petr Lautrbach cd2c1d
- Trim changelog so that it starts at F35 time
Petr Lautrbach cd2c1d
- Add mptcpd and rshim modules
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Wed Dec 14 2022 Zdenek Pytela <zpytela@redhat.com> - 38.3-1
Petr Lautrbach cd2c1d
- Allow insights-client dbus chat with various services
Petr Lautrbach cd2c1d
- Allow insights-client tcp connect to various ports
Petr Lautrbach cd2c1d
- Allow insights-client run lpr and allow the proper role
Petr Lautrbach cd2c1d
- Allow insights-client work with pcp and manage user config files
Petr Lautrbach cd2c1d
- Allow redis get user names
Petr Lautrbach cd2c1d
- Allow kernel threads to use fds from all domains
Petr Lautrbach cd2c1d
- Allow systemd-modules-load load kernel modules
Petr Lautrbach cd2c1d
- Allow login_userdomain watch systemd-passwd pid dirs
Petr Lautrbach cd2c1d
- Allow insights-client dbus chat with abrt
Petr Lautrbach cd2c1d
- Grant kernel_t certain permissions in the system class
Petr Lautrbach cd2c1d
- Allow systemd-resolved watch tmpfs directories
Petr Lautrbach cd2c1d
- Allow systemd-timedated watch init runtime dir
Petr Lautrbach cd2c1d
- Make `bootc` be `install_exec_t`
Petr Lautrbach cd2c1d
- Allow systemd-coredump create user_namespace
Petr Lautrbach cd2c1d
- Allow syslog the setpcap capability
Petr Lautrbach cd2c1d
- donaudit virtlogd and dnsmasq execmem
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Dec 06 2022 Zdenek Pytela <zpytela@redhat.com> - 38.2-1
Petr Lautrbach cd2c1d
- Don't make kernel_t an unconfined domain
Petr Lautrbach cd2c1d
- Don't allow kernel_t to execute bin_t/usr_t binaries without a transition
Petr Lautrbach cd2c1d
- Allow kernel_t to execute systemctl to do a poweroff/reboot
Petr Lautrbach cd2c1d
- Grant basic permissions to the domain created by systemd_systemctl_domain()
Petr Lautrbach cd2c1d
- Allow kernel_t to request module loading
Petr Lautrbach cd2c1d
- Allow kernel_t to do compute_create
Petr Lautrbach cd2c1d
- Allow kernel_t to manage perf events
Petr Lautrbach cd2c1d
- Grant almost all capabilities to kernel_t
Petr Lautrbach cd2c1d
- Allow kernel_t to fully manage all devices
Petr Lautrbach cd2c1d
- Revert "In domain_transition_pattern there is no permission allowing caller domain to execu_no_trans on entrypoint, this patch fixing this issue"
Petr Lautrbach cd2c1d
- Allow pulseaudio to write to session_dbusd tmp socket files
Petr Lautrbach cd2c1d
- Allow systemd and unconfined_domain_type create user_namespace
Petr Lautrbach cd2c1d
- Add the user_namespace security class
Petr Lautrbach cd2c1d
- Reuse tmpfs_t also for the ramfs filesystem
Petr Lautrbach cd2c1d
- Label udf tools with fsadm_exec_t
Petr Lautrbach cd2c1d
- Allow networkmanager_dispatcher_plugin work with nscd
Petr Lautrbach cd2c1d
- Watch_sb all file type directories.
Petr Lautrbach cd2c1d
- Allow spamc read hardware state information files
Petr Lautrbach cd2c1d
- Allow sysadm read ipmi devices
Petr Lautrbach cd2c1d
- Allow insights client communicate with cupsd, mysqld, openvswitch, redis
Petr Lautrbach cd2c1d
- Allow insights client read raw memory devices
Petr Lautrbach cd2c1d
- Allow the spamd_update_t domain get generic filesystem attributes
Petr Lautrbach cd2c1d
- Dontaudit systemd-gpt-generator the sys_admin capability
Petr Lautrbach cd2c1d
- Allow ipsec_t only read tpm devices
Petr Lautrbach cd2c1d
- Allow cups-pdf connect to the system log service
Petr Lautrbach cd2c1d
- Allow postfix/smtpd read kerberos key table
Petr Lautrbach cd2c1d
- Allow syslogd read network sysctls
Petr Lautrbach cd2c1d
- Allow cdcc mmap dcc-client-map files
Petr Lautrbach cd2c1d
- Add watch and watch_sb dosfs interface
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon Nov 21 2022 Zdenek Pytela <zpytela@redhat.com> - 38.1-1
Petr Lautrbach cd2c1d
- Revert "Allow sysadm_t read raw memory devices"
Petr Lautrbach cd2c1d
- Allow systemd-socket-proxyd get attributes of cgroup filesystems
Petr Lautrbach cd2c1d
- Allow rpc.gssd read network sysctls
Petr Lautrbach cd2c1d
- Allow winbind-rpcd get attributes of device and pty filesystems
Petr Lautrbach cd2c1d
- Allow insights-client domain transition on semanage execution
Petr Lautrbach cd2c1d
- Allow insights-client create gluster log dir with a transition
Petr Lautrbach cd2c1d
- Allow insights-client manage generic locks
Petr Lautrbach cd2c1d
- Allow insights-client unix_read all domain semaphores
Petr Lautrbach cd2c1d
- Add domain_unix_read_all_semaphores() interface
Petr Lautrbach cd2c1d
- Allow winbind-rpcd use the terminal multiplexor
Petr Lautrbach cd2c1d
- Allow mrtg send mails
Petr Lautrbach cd2c1d
- Allow systemd-hostnamed dbus chat with init scripts
Petr Lautrbach cd2c1d
- Allow sssd dbus chat with system cronjobs
Petr Lautrbach cd2c1d
- Add interface to watch all filesystems
Petr Lautrbach cd2c1d
- Add watch_sb interfaces
Petr Lautrbach cd2c1d
- Add watch interfaces
Petr Lautrbach cd2c1d
- Allow dhcpd bpf capability to run bpf programs
Petr Lautrbach cd2c1d
- Allow netutils and traceroute bpf capability to run bpf programs
Petr Lautrbach cd2c1d
- Allow pkcs_slotd_t bpf capability to run bpf programs
Petr Lautrbach cd2c1d
- Allow xdm bpf capability to run bpf programs
Petr Lautrbach cd2c1d
- Allow pcscd bpf capability to run bpf programs
Petr Lautrbach cd2c1d
- Allow lldpad bpf capability to run bpf programs
Petr Lautrbach cd2c1d
- Allow keepalived bpf capability to run bpf programs
Petr Lautrbach cd2c1d
- Allow ipsec bpf capability to run bpf programs
Petr Lautrbach cd2c1d
- Allow fprintd bpf capability to run bpf programs
Petr Lautrbach cd2c1d
- Allow systemd-socket-proxyd get filesystems attributes
Petr Lautrbach cd2c1d
- Allow dirsrv_snmp_t to manage dirsrv_config_t & dirsrv_var_run_t files
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon Oct 31 2022 Zdenek Pytela <zpytela@redhat.com> - 37.14-1
Petr Lautrbach cd2c1d
- Allow rotatelogs read httpd_log_t symlinks
Petr Lautrbach cd2c1d
- Add winbind-rpcd to samba_enable_home_dirs boolean
Petr Lautrbach cd2c1d
- Allow system cronjobs dbus chat with setroubleshoot
Petr Lautrbach cd2c1d
- Allow setroubleshootd read device sysctls
Petr Lautrbach cd2c1d
- Allow virt_domain read device sysctls
Petr Lautrbach cd2c1d
- Allow rhcd compute selinux access vector
Petr Lautrbach cd2c1d
- Allow insights-client manage samba var dirs
Petr Lautrbach cd2c1d
- Label ports 10161-10162 tcp/udp with snmp
Petr Lautrbach cd2c1d
- Allow aide to connect to systemd_machined with a unix socket.
Petr Lautrbach cd2c1d
- Allow samba-dcerpcd use NSCD services over a unix stream socket
Petr Lautrbach cd2c1d
- Allow vlock search the contents of the /dev/pts directory
Petr Lautrbach cd2c1d
- Allow insights-client send null signal to rpm and system cronjob
Petr Lautrbach cd2c1d
- Label port 15354/tcp and 15354/udp with opendnssec
Petr Lautrbach cd2c1d
- Allow ftpd map ftpd_var_run files
Petr Lautrbach cd2c1d
- Allow targetclid to manage tmp files
Petr Lautrbach cd2c1d
- Allow insights-client connect to postgresql with a unix socket
Petr Lautrbach cd2c1d
- Allow insights-client domtrans on unix_chkpwd execution
Petr Lautrbach cd2c1d
- Add file context entries for insights-client and rhc
Petr Lautrbach cd2c1d
- Allow pulseaudio create gnome content (~/.config)
Petr Lautrbach cd2c1d
- Allow login_userdomain dbus chat with rhsmcertd
Petr Lautrbach cd2c1d
- Allow sbd the sys_ptrace capability
Petr Lautrbach cd2c1d
- Allow ptp4l_t name_bind ptp_event_port_t
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon Oct 03 2022 Zdenek Pytela <zpytela@redhat.com> - 37.13-1
Petr Lautrbach cd2c1d
- Remove the ipa module
Petr Lautrbach cd2c1d
- Allow sss daemons read/write unnamed pipes of cloud-init
Petr Lautrbach cd2c1d
- Allow postfix_mailqueue create and use unix dgram sockets
Petr Lautrbach cd2c1d
- Allow xdm watch user home directories
Petr Lautrbach cd2c1d
- Allow nm-dispatcher ddclient plugin load a kernel module
Petr Lautrbach cd2c1d
- Stop ignoring standalone interface files
Petr Lautrbach cd2c1d
- Drop cockpit module
Petr Lautrbach cd2c1d
- Allow init map its private tmp files
Petr Lautrbach cd2c1d
- Allow xenstored change its hard resource limits
Petr Lautrbach cd2c1d
- Allow system_mail-t read network sysctls
Petr Lautrbach cd2c1d
- Add bgpd sys_chroot capability
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Sep 22 2022 Zdenek Pytela <zpytela@redhat.com> - 37.12-1
Petr Lautrbach cd2c1d
- nut-upsd: kernel_read_system_state, fs_getattr_cgroup
Petr Lautrbach cd2c1d
- Add numad the ipc_owner capability
Petr Lautrbach cd2c1d
- Allow gst-plugin-scanner read virtual memory sysctls
Petr Lautrbach cd2c1d
- Allow init read/write inherited user fifo files
Petr Lautrbach cd2c1d
- Update dnssec-trigger policy: setsched, module_request
Petr Lautrbach cd2c1d
- added policy for systemd-socket-proxyd
Petr Lautrbach cd2c1d
- Add the new 'cmd' permission to the 'io_uring' class
Petr Lautrbach cd2c1d
- Allow winbind-rpcd read and write its key ring
Petr Lautrbach cd2c1d
- Label /run/NetworkManager/no-stub-resolv.conf net_conf_t
Petr Lautrbach cd2c1d
- blueman-mechanism can read ~/.local/lib/python*/site-packages directory
Petr Lautrbach cd2c1d
- pidof executed by abrt can readlink /proc/*/exe
Petr Lautrbach cd2c1d
- Fix typo in comment
Petr Lautrbach cd2c1d
- Do not run restorecon /etc/NetworkManager/dispatcher.d in mls and minimum
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Wed Sep 14 2022 Zdenek Pytela <zpytela@redhat.com> - 37.11-1
Petr Lautrbach cd2c1d
- Allow tor get filesystem attributes
Petr Lautrbach cd2c1d
- Allow utempter append to login_userdomain stream
Petr Lautrbach cd2c1d
- Allow login_userdomain accept a stream connection to XDM
Petr Lautrbach cd2c1d
- Allow login_userdomain write to boltd named pipes
Petr Lautrbach cd2c1d
- Allow staff_u and user_u users write to bolt pipe
Petr Lautrbach cd2c1d
- Allow login_userdomain watch various directories
Petr Lautrbach cd2c1d
- Update rhcd policy for executing additional commands 5
Petr Lautrbach cd2c1d
- Update rhcd policy for executing additional commands 4
Petr Lautrbach cd2c1d
- Allow rhcd create rpm hawkey logs with correct label
Petr Lautrbach cd2c1d
- Allow systemd-gpt-auto-generator to check for empty dirs
Petr Lautrbach cd2c1d
- Update rhcd policy for executing additional commands 3
Petr Lautrbach cd2c1d
- Allow journalctl read rhcd fifo files
Petr Lautrbach cd2c1d
- Update insights-client policy for additional commands execution 5
Petr Lautrbach cd2c1d
- Allow init remount all file_type filesystems
Petr Lautrbach cd2c1d
- Confine insights-client systemd unit
Petr Lautrbach cd2c1d
- Update insights-client policy for additional commands execution 4
Petr Lautrbach cd2c1d
- Allow pcp pmcd search tracefs and acct_data dirs
Petr Lautrbach cd2c1d
- Allow httpd read network sysctls
Petr Lautrbach cd2c1d
- Dontaudit domain map permission on directories
Petr Lautrbach cd2c1d
- Revert "Allow X userdomains to mmap user_fonts_cache_t dirs"
Petr Lautrbach cd2c1d
- Revert "Allow xdm_t domain to mmap /var/lib/gdm/.cache/fontconfig BZ(1725509)"
Petr Lautrbach cd2c1d
- Update insights-client policy for additional commands execution 3
Petr Lautrbach cd2c1d
- Allow systemd permissions needed for sandboxed services
Petr Lautrbach cd2c1d
- Add rhcd module
Petr Lautrbach cd2c1d
- Make dependency on rpm-plugin-selinux unordered
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri Sep 02 2022 Zdenek Pytela <zpytela@redhat.com> - 37.10-1
Petr Lautrbach cd2c1d
- Allow ipsec_t read/write tpm devices
Petr Lautrbach cd2c1d
- Allow rhcd execute all executables
Petr Lautrbach cd2c1d
- Update rhcd policy for executing additional commands 2
Petr Lautrbach cd2c1d
- Update insights-client policy for additional commands execution 2
Petr Lautrbach cd2c1d
- Allow sysadm_t read raw memory devices
Petr Lautrbach cd2c1d
- Allow chronyd send and receive chronyd/ntp client packets
Petr Lautrbach cd2c1d
- Allow ssh client read kerberos homedir config files
Petr Lautrbach cd2c1d
- Label /var/log/rhc-worker-playbook with rhcd_var_log_t
Petr Lautrbach cd2c1d
- Update insights-client policy (auditctl, gpg, journal)
Petr Lautrbach cd2c1d
- Allow system_cronjob_t domtrans to rpm_script_t
Petr Lautrbach cd2c1d
- Allow smbd_t process noatsecure permission for winbind_rpcd_t
Petr Lautrbach cd2c1d
- Update tor_bind_all_unreserved_ports interface
Petr Lautrbach cd2c1d
- Allow chronyd bind UDP sockets to ptp_event ports.
Petr Lautrbach cd2c1d
- Allow unconfined and sysadm users transition for /root/.gnupg
Petr Lautrbach cd2c1d
- Add gpg_filetrans_admin_home_content() interface
Petr Lautrbach cd2c1d
- Update rhcd policy for executing additional commands
Petr Lautrbach cd2c1d
- Update insights-client policy for additional commands execution
Petr Lautrbach cd2c1d
- Add userdom_view_all_users_keys() interface
Petr Lautrbach cd2c1d
- Allow gpg read and write generic pty type
Petr Lautrbach cd2c1d
- Allow chronyc read and write generic pty type
Petr Lautrbach cd2c1d
- Allow system_dbusd ioctl kernel with a unix stream sockets
Petr Lautrbach cd2c1d
- Allow samba-bgqd to read a printer list
Petr Lautrbach cd2c1d
- Allow stalld get and set scheduling policy of all domains.
Petr Lautrbach cd2c1d
- Allow unconfined_t transition to targetclid_home_t
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Aug 11 2022 Zdenek Pytela <zpytela@redhat.com> - 37.9-1
Petr Lautrbach cd2c1d
- Allow nm-dispatcher custom plugin dbus chat with nm
Petr Lautrbach cd2c1d
- Allow nm-dispatcher sendmail plugin get status of systemd services
Petr Lautrbach cd2c1d
- Allow xdm read the kernel key ring
Petr Lautrbach cd2c1d
- Allow login_userdomain check status of mount units
Petr Lautrbach cd2c1d
- Allow postfix/smtp and postfix/virtual read kerberos key table
Petr Lautrbach cd2c1d
- Allow services execute systemd-notify
Petr Lautrbach cd2c1d
- Do not allow login_userdomain use sd_notify()
Petr Lautrbach cd2c1d
- Allow launch-xenstored read filesystem sysctls
Petr Lautrbach cd2c1d
- Allow systemd-modules-load write to /dev/kmsg and send a message to syslogd
Petr Lautrbach cd2c1d
- Allow openvswitch fsetid capability
Petr Lautrbach cd2c1d
- Allow openvswitch use its private tmpfs files and dirs
Petr Lautrbach cd2c1d
- Allow openvswitch search tracefs dirs
Petr Lautrbach cd2c1d
- Allow pmdalinux read files on an nfsd filesystem
Petr Lautrbach cd2c1d
- Allow winbind-rpcd write to winbind pid files
Petr Lautrbach cd2c1d
- Allow networkmanager to signal unconfined process
Petr Lautrbach cd2c1d
- Allow systemd_hostnamed label /run/systemd/* as hostnamed_etc_t
Petr Lautrbach cd2c1d
- Allow samba-bgqd get a printer list
Petr Lautrbach cd2c1d
- fix(init.fc): Fix section description
Petr Lautrbach cd2c1d
- Allow fedora-third-party read the passwords file
Petr Lautrbach cd2c1d
- Remove permissive domain for rhcd_t
Petr Lautrbach cd2c1d
- Allow pmie read network state information and network sysctls
Petr Lautrbach cd2c1d
- Revert "Dontaudit domain the fowner capability"
Petr Lautrbach cd2c1d
- Allow sysadm_t to run bpftool on the userdomain attribute
Petr Lautrbach cd2c1d
- Add the userdom_prog_run_bpf_userdomain() interface
Petr Lautrbach cd2c1d
- Allow insights-client rpm named file transitions
Petr Lautrbach cd2c1d
- Add /var/tmp/insights-archive to insights_client_filetrans_named_content
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon Aug 01 2022 Zdenek Pytela <zpytela@redhat.com> - 37.8-1
Petr Lautrbach cd2c1d
- Allow sa-update to get init status and start systemd files
Petr Lautrbach cd2c1d
- Use insights_client_filetrans_named_content
Petr Lautrbach cd2c1d
- Make default file context match with named transitions
Petr Lautrbach cd2c1d
- Allow nm-dispatcher tlp plugin send system log messages
Petr Lautrbach cd2c1d
- Allow nm-dispatcher tlp plugin create and use unix_dgram_socket
Petr Lautrbach cd2c1d
- Add permissions to manage lnk_files into gnome_manage_home_config
Petr Lautrbach cd2c1d
- Allow rhsmcertd to read insights config files
Petr Lautrbach cd2c1d
- Label /etc/insights-client/machine-id
Petr Lautrbach cd2c1d
- fix(devices.fc): Replace single quote in comment to solve parsing issues
Petr Lautrbach cd2c1d
- Make NetworkManager_dispatcher_custom_t an unconfined domain
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 37.7-2
Petr Lautrbach cd2c1d
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Jul 14 2022 Zdenek Pytela <zpytela@redhat.com> - 37.7-1
Petr Lautrbach cd2c1d
- Update winbind_rpcd_t
Petr Lautrbach cd2c1d
- Allow some domains use sd_notify()
Petr Lautrbach cd2c1d
- Revert "Allow rabbitmq to use systemd notify"
Petr Lautrbach cd2c1d
- fix(sedoctool.py): Fix syntax warning: "is not" with a literal
Petr Lautrbach cd2c1d
- Allow nm-dispatcher console plugin manage etc files
Petr Lautrbach cd2c1d
- Allow networkmanager_dispatcher_plugin list NetworkManager_etc_t dirs
Petr Lautrbach cd2c1d
- Allow nm-dispatcher console plugin setfscreate
Petr Lautrbach cd2c1d
- Support using systemd-update-helper in rpm scriptlets
Petr Lautrbach cd2c1d
- Allow nm-dispatcher winbind plugin read samba config files
Petr Lautrbach cd2c1d
- Allow domain use userfaultfd over all domains
Petr Lautrbach cd2c1d
- Allow cups-lpd read network sysctls
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Wed Jun 29 2022 Zdenek Pytela <zpytela@redhat.com> - 37.6-1
Petr Lautrbach cd2c1d
- Allow stalld set scheduling policy of kernel threads
Petr Lautrbach cd2c1d
- Allow targetclid read /var/target files
Petr Lautrbach cd2c1d
- Allow targetclid read generic SSL certificates (fixed)
Petr Lautrbach cd2c1d
- Allow firewalld read the contents of the sysfs filesystem
Petr Lautrbach cd2c1d
- Fix file context pattern for /var/target
Petr Lautrbach cd2c1d
- Use insights_client_etc_t in insights_search_config()
Petr Lautrbach cd2c1d
- Allow nm-dispatcher ddclient plugin handle systemd services
Petr Lautrbach cd2c1d
- Allow nm-dispatcher winbind plugin run smbcontrol
Petr Lautrbach cd2c1d
- Allow nm-dispatcher custom plugin create and use unix dgram socket
Petr Lautrbach cd2c1d
- Update samba-dcerpcd policy for kerberos usage 2
Petr Lautrbach cd2c1d
- Allow keepalived read the contents of the sysfs filesystem
Petr Lautrbach cd2c1d
- Allow amandad read network sysctls
Petr Lautrbach cd2c1d
- Allow cups-lpd read network sysctls
Petr Lautrbach cd2c1d
- Allow kpropd read network sysctls
Petr Lautrbach cd2c1d
- Update insights_client_filetrans_named_content()
Petr Lautrbach cd2c1d
- Allow rabbitmq to use systemd notify
Petr Lautrbach cd2c1d
- Label /var/target with targetd_var_t
Petr Lautrbach cd2c1d
- Allow targetclid read generic SSL certificates
Petr Lautrbach cd2c1d
- Update rhcd policy
Petr Lautrbach cd2c1d
- Allow rhcd search insights configuration directories
Petr Lautrbach cd2c1d
- Add the kernel_read_proc_files() interface
Petr Lautrbach cd2c1d
- Require policycoreutils >= 3.4-1
Petr Lautrbach cd2c1d
- Add a script for enclosing interfaces in ifndef statements
Petr Lautrbach cd2c1d
- Disable rpm verification on interface_info
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Wed Jun 22 2022 Zdenek Pytela <zpytela@redhat.com> - 37.5-1
Petr Lautrbach cd2c1d
- Allow transition to insights_client named content
Petr Lautrbach cd2c1d
- Add the insights_client_filetrans_named_content() interface
Petr Lautrbach cd2c1d
- Update policy for insights-client to run additional commands 3
Petr Lautrbach cd2c1d
- Allow dhclient manage pid files used by chronyd
Petr Lautrbach cd2c1d
- Allow stalld get scheduling policy of kernel threads
Petr Lautrbach cd2c1d
- Allow samba-dcerpcd work with sssd
Petr Lautrbach cd2c1d
- Allow dlm_controld send a null signal to a cluster daemon
Petr Lautrbach cd2c1d
- Allow ksmctl create hardware state information files
Petr Lautrbach cd2c1d
- Allow winbind_rpcd_t connect to self over a unix_stream_socket
Petr Lautrbach cd2c1d
- Update samba-dcerpcd policy for kerberos usage
Petr Lautrbach cd2c1d
- Allow insights-client execute its private memfd: objects
Petr Lautrbach cd2c1d
- Update policy for insights-client to run additional commands 2
Petr Lautrbach cd2c1d
- Use insights_client_tmp_t instead of insights_client_var_tmp_t
Petr Lautrbach cd2c1d
- Change space indentation to tab in insights-client
Petr Lautrbach cd2c1d
- Use socket permissions sets in insights-client
Petr Lautrbach cd2c1d
- Update policy for insights-client to run additional commands
Petr Lautrbach cd2c1d
- Change rpm_setattr_db_files() to use a pattern
Petr Lautrbach cd2c1d
- Allow init_t to rw insights_client unnamed pipe
Petr Lautrbach cd2c1d
- Add rpm setattr db files macro
Petr Lautrbach cd2c1d
- Fix insights client
Petr Lautrbach cd2c1d
- Update kernel_read_unix_sysctls() for sysctl_net_unix_t handling
Petr Lautrbach cd2c1d
- Allow rabbitmq to access its private memfd: objects
Petr Lautrbach cd2c1d
- Update policy for samba-dcerpcd
Petr Lautrbach cd2c1d
- Allow stalld setsched and sys_nice
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Jun 07 2022 Zdenek Pytela <zpytela@redhat.com> - 37.4-1
Petr Lautrbach cd2c1d
- Allow auditd_t noatsecure for a transition to audisp_remote_t
Petr Lautrbach cd2c1d
- Allow ctdbd nlmsg_read on netlink_tcpdiag_socket
Petr Lautrbach cd2c1d
- Allow pcp_domain execute its private memfd: objects
Petr Lautrbach cd2c1d
- Add support for samba-dcerpcd
Petr Lautrbach cd2c1d
- Add policy for wireguard
Petr Lautrbach cd2c1d
- Confine targetcli
Petr Lautrbach cd2c1d
- Allow systemd work with install_t unix stream sockets
Petr Lautrbach cd2c1d
- Allow iscsid the sys_ptrace userns capability
Petr Lautrbach cd2c1d
- Allow xdm connect to unconfined_service_t over a unix stream socket
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri May 27 2022 Zdenek Pytela <zpytela@redhat.com> - 37.3-1
Petr Lautrbach cd2c1d
- Allow nm-dispatcher custom plugin execute systemctl
Petr Lautrbach cd2c1d
- Allow nm-dispatcher custom plugin dbus chat with nm
Petr Lautrbach cd2c1d
- Allow nm-dispatcher custom plugin create and use udp socket
Petr Lautrbach cd2c1d
- Allow nm-dispatcher custom plugin create and use netlink_route_socket
Petr Lautrbach cd2c1d
- Use create_netlink_socket_perms in netlink_route_socket class permissions
Petr Lautrbach cd2c1d
- Add support for nm-dispatcher sendmail scripts
Petr Lautrbach cd2c1d
- Allow sslh net_admin capability
Petr Lautrbach cd2c1d
- Allow insights-client manage gpg admin home content
Petr Lautrbach cd2c1d
- Add the gpg_manage_admin_home_content() interface
Petr Lautrbach cd2c1d
- Allow rhsmcertd create generic log files
Petr Lautrbach cd2c1d
- Update logging_create_generic_logs() to use create_files_pattern()
Petr Lautrbach cd2c1d
- Label /var/cache/insights with insights_client_cache_t
Petr Lautrbach cd2c1d
- Allow insights-client search gconf homedir
Petr Lautrbach cd2c1d
- Allow insights-client create and use unix_dgram_socket
Petr Lautrbach cd2c1d
- Allow blueman execute its private memfd: files
Petr Lautrbach cd2c1d
- Move the chown call into make-srpm.sh
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri May 06 2022 Zdenek Pytela <zpytela@redhat.com> - 37.2-1
Petr Lautrbach cd2c1d
- Use the networkmanager_dispatcher_plugin attribute in allow rules
Petr Lautrbach cd2c1d
- Make a custom nm-dispatcher plugin transition
Petr Lautrbach cd2c1d
- Label port 4784/tcp and 4784/udp with bfd_multi
Petr Lautrbach cd2c1d
- Allow systemd watch and watch_reads user ptys
Petr Lautrbach cd2c1d
- Allow sblim-gatherd the kill capability
Petr Lautrbach cd2c1d
- Label more vdsm utils with virtd_exec_t
Petr Lautrbach cd2c1d
- Add ksm service to ksmtuned
Petr Lautrbach cd2c1d
- Add rhcd policy
Petr Lautrbach cd2c1d
- Dontaudit guest attempts to dbus chat with systemd domains
Petr Lautrbach cd2c1d
- Dontaudit guest attempts to dbus chat with system bus types
Petr Lautrbach cd2c1d
- Use a named transition in systemd_hwdb_manage_config()
Petr Lautrbach cd2c1d
- Add default fc specifications for patterns in /opt
Petr Lautrbach cd2c1d
- Add the files_create_etc_files() interface
Petr Lautrbach cd2c1d
- Allow nm-dispatcher console plugin create and write files in /etc
Petr Lautrbach cd2c1d
- Allow nm-dispatcher console plugin transition to the setfiles domain
Petr Lautrbach cd2c1d
- Allow more nm-dispatcher plugins append to init stream sockets
Petr Lautrbach cd2c1d
- Allow nm-dispatcher tlp plugin dbus chat with nm
Petr Lautrbach cd2c1d
- Reorder networkmanager_dispatcher_plugin_template() calls
Petr Lautrbach cd2c1d
- Allow svirt connectto virtlogd
Petr Lautrbach cd2c1d
- Allow blueman map its private memfd: files
Petr Lautrbach cd2c1d
- Allow sysadm user execute init scripts with a transition
Petr Lautrbach cd2c1d
- Allow sblim-sfcbd connect to sblim-reposd stream
Petr Lautrbach cd2c1d
- Allow keepalived_unconfined_script_t dbus chat with init
Petr Lautrbach cd2c1d
- Run restorecon with "-i" not to report errors
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon May 02 2022 Zdenek Pytela <zpytela@redhat.com> - 37.1-1
Petr Lautrbach cd2c1d
- Fix users for SELinux userspace 3.4
Petr Lautrbach cd2c1d
- Label /var/run/machine-id as machineid_t
Petr Lautrbach cd2c1d
- Add stalld to modules.conf
Petr Lautrbach cd2c1d
- Use files_tmpfs_file() for rhsmcertd_tmpfs_t
Petr Lautrbach cd2c1d
- Allow blueman read/write its private memfd: objects
Petr Lautrbach cd2c1d
- Allow insights-client read rhnsd config files
Petr Lautrbach cd2c1d
- Allow insights-client create_socket_perms for tcp/udp sockets