Zdenek Pytela 814aa8
* Thu Jul 25 2024 Zdenek Pytela <zpytela@redhat.com> - 41.11-1
Zdenek Pytela 814aa8
- Make cgroup_memory_pressure_t a part of the file_type attribute
Zdenek Pytela 814aa8
- Allow ssh_t to change role to system_r
Zdenek Pytela 814aa8
- Update policy for coreos generators
Zdenek Pytela 814aa8
- Allow init_t nnp domain transition to firewalld_t
Zdenek Pytela 814aa8
- Label /run/modprobe.d with modules_conf_t
Zdenek Pytela 814aa8
- Allow virtnodedevd run udev with a domain transition
Zdenek Pytela 814aa8
- Allow virtnodedev_t create and use virtnodedev_lock_t
Zdenek Pytela 814aa8
- Allow virtstoraged manage files with virt_content_t type
Zdenek Pytela 814aa8
- Allow virtqemud unmount a filesystem with extended attributes
Zdenek Pytela 814aa8
- Allow svirt_t connect to unconfined_t over a unix domain socket
Zdenek Pytela 814aa8
Zdenek Pytela 6a2602
* Mon Jul 22 2024 Zdenek Pytela <zpytela@redhat.com> - 41.10-1
Zdenek Pytela 6a2602
- Update afterburn file transition policy
Zdenek Pytela 6a2602
- Allow systemd_generator read attributes of all filesystems
Zdenek Pytela 6a2602
- Allow fstab-generator read and write cryptsetup-generator unit file
Zdenek Pytela 6a2602
- Allow cryptsetup-generator read and write fstab-generator unit file
Zdenek Pytela 6a2602
- Allow systemd_generator map files in /etc
Zdenek Pytela 6a2602
- Allow systemd_generator read init's process state
Zdenek Pytela 6a2602
- Allow coreos-installer-generator read sssd public files
Zdenek Pytela 6a2602
- Allow coreos-installer-generator work with partitions
Zdenek Pytela 6a2602
- Label /etc/mdadm.conf.d with mdadm_conf_t
Zdenek Pytela 6a2602
- Confine coreos generators
Zdenek Pytela 6a2602
- Label /run/metadata with afterburn_runtime_t
Zdenek Pytela 6a2602
- Allow afterburn list ssh home directory
Zdenek Pytela 6a2602
- Label samba certificates with samba_cert_t
Zdenek Pytela 6a2602
- Label /run/coreos-installer-reboot with coreos_installer_var_run_t
Zdenek Pytela 6a2602
- Allow virtqemud read virt-dbus process state
Zdenek Pytela 6a2602
- Allow staff user dbus chat with virt-dbus
Zdenek Pytela 6a2602
- Allow staff use watch /run/systemd
Zdenek Pytela 6a2602
- Allow systemd_generator to write kmsg
Zdenek Pytela 6a2602
Zdenek Pytela 6a2602
* Sat Jul 20 2024 Fedora Release Engineering <releng@fedoraproject.org> - 41.9-2
Zdenek Pytela 6a2602
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
Zdenek Pytela 6a2602
Zdenek Pytela fd1451
* Tue Jul 16 2024 Zdenek Pytela <zpytela@redhat.com> - 41.9-1
Zdenek Pytela fd1451
- Allow virtqemud connect to sanlock over a unix stream socket
Zdenek Pytela fd1451
- Allow virtqemud relabel virt_var_run_t directories
Zdenek Pytela fd1451
- Allow svirt_tcg_t read vm sysctls
Zdenek Pytela fd1451
- Allow virtnodedevd connect to systemd-userdbd over a unix socket
Zdenek Pytela fd1451
- Allow svirt read virtqemud fifo files
Zdenek Pytela fd1451
- Allow svirt attach_queue to a virtqemud tun_socket
Zdenek Pytela fd1451
- Allow virtqemud run ssh client with a transition
Zdenek Pytela fd1451
- Allow virt_dbus_t connect to virtqemud_t over a unix stream socket
Zdenek Pytela fd1451
- Update keyutils policy
Zdenek Pytela fd1451
- Allow sshd_keygen_t connect to userdbd over a unix stream socket
Zdenek Pytela fd1451
- Allow postfix-smtpd read mysql config files
Zdenek Pytela fd1451
- Allow locate stream connect to systemd-userdbd
Zdenek Pytela fd1451
- Allow the staff user use wireshark
Zdenek Pytela fd1451
- Allow updatedb connect to userdbd over a unix stream socket
Zdenek Pytela fd1451
- Allow gpg_t set attributes of public-keys.d
Zdenek Pytela fd1451
- Allow gpg_t get attributes of login_userdomain stream
Zdenek Pytela fd1451
- Allow systemd_getty_generator_t read /proc/1/environ
Zdenek Pytela fd1451
- Allow systemd_getty_generator_t to read and write to tty_device_t
Zdenek Pytela fd1451
Zdenek Pytela fd1451
* Thu Jul 11 2024 Petr Lautrbach <lautrbach@redhat.com> 41.8-4
Zdenek Pytela fd1451
- Move %%postInstall to %%posttrans
Zdenek Pytela fd1451
- Use `Requires(meta): (rpm-plugin-selinux if rpm-libs)`
Zdenek Pytela fd1451
- Drop obsolete modules from config
Zdenek Pytela fd1451
- Install dnf protected files only when policy is built
Zdenek Pytela fd1451
Zdenek Pytela fd1451
* Thu Jul 11 2024 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> - 41.8-3
Zdenek Pytela fd1451
- Relabel files under /usr/bin to fix stale context after sbin merge
Zdenek Pytela fd1451
Zdenek Pytela fd1451
* Mon Jun 24 2024 Petr Lautrbach <lautrbach@redhat.com> 41.8-2
Zdenek Pytela fd1451
- Merge -base and -contrib
Zdenek Pytela fd1451
Zdenek Pytela 915415
* Wed Jul 10 2024 Zdenek Pytela <zpytela@redhat.com> - 41.8-1
Zdenek Pytela 915415
- Drop publicfile module
Zdenek Pytela 915415
- Remove permissive domain for systemd_nsresourced_t
Zdenek Pytela 915415
- Change fs_dontaudit_write_cgroup_files() to apply to cgroup_t
Zdenek Pytela 915415
- Label /usr/bin/samba-gpupdate with samba_gpupdate_exec_t
Zdenek Pytela 915415
- Allow to create and delete socket files created by rhsm.service
Zdenek Pytela 915415
- Allow virtnetworkd exec shell when virt_hooks_unconfined is on
Zdenek Pytela 915415
- Allow unconfined_service_t transition to passwd_t
Zdenek Pytela 915415
- Support /var is empty
Zdenek Pytela 915415
- Allow abrt-dump-journal read all non_security socket files
Zdenek Pytela 915415
- Allow timemaster write to sysfs files
Zdenek Pytela 915415
- Dontaudit domain write cgroup files
Zdenek Pytela 915415
- Label /usr/lib/node_modules/npm/bin with bin_t
Zdenek Pytela 915415
- Allow ip the setexec permission
Zdenek Pytela 915415
- Allow systemd-networkd write files in /var/lib/systemd/network
Zdenek Pytela 915415
- Fix typo in systemd_nsresourced_prog_run_bpf()
Zdenek Pytela 915415
Zdenek Pytela 77fce7
* Fri Jun 28 2024 Zdenek Pytela <zpytela@redhat.com> - 41.7-1
Zdenek Pytela 77fce7
- Confine libvirt-dbus
Zdenek Pytela 77fce7
- Allow virtqemud the kill capability in user namespace
Zdenek Pytela 77fce7
- Allow rshim get options of the netlink class for KOBJECT_UEVENT family
Zdenek Pytela 77fce7
- Allow dhcpcd the kill capability
Zdenek Pytela 77fce7
- Allow systemd-networkd list /var/lib/systemd/network
Zdenek Pytela 77fce7
- Allow sysadm_t run systemd-nsresourced bpf programs
Zdenek Pytela 77fce7
- Update policy for systemd generators interactions
Zdenek Pytela 77fce7
- Allow create memory.pressure files with cgroup_memory_pressure_t
Zdenek Pytela 77fce7
- Add support for libvirt hooks
Zdenek Pytela 77fce7
Zdenek Pytela 78f4e5
* Wed Jun 19 2024 Zdenek Pytela <zpytela@redhat.com> - 41.6-1
Zdenek Pytela 78f4e5
- Allow certmonger read and write tpm devices
Zdenek Pytela 78f4e5
- Allow all domains to connect to systemd-nsresourced over a unix socket
Zdenek Pytela 78f4e5
- Allow systemd-machined read the vsock device
Zdenek Pytela 78f4e5
- Update policy for systemd generators
Zdenek Pytela 78f4e5
- Allow ptp4l_t request that the kernel load a kernel module
Zdenek Pytela 78f4e5
- Allow sbd to trace processes in user namespace
Zdenek Pytela 78f4e5
- Allow request-key execute scripts
Zdenek Pytela 78f4e5
- Update policy for haproxyd
Zdenek Pytela 78f4e5
Zdenek Pytela ba644b
* Tue Jun 18 2024 Zdenek Pytela <zpytela@redhat.com> - 41.5-1
Zdenek Pytela ba644b
- Update policy for systemd-nsresourced
Zdenek Pytela ba644b
- Correct sbin-related file context entries
Zdenek Pytela ba644b
Zdenek Pytela 26af38
* Mon Jun 17 2024 Zdenek Pytela <zpytela@redhat.com> - 41.4-1
Zdenek Pytela 26af38
- Allow login_userdomain execute systemd-tmpfiles in the caller domain
Zdenek Pytela 26af38
- Allow virt_driver_domain read files labeled unconfined_t
Zdenek Pytela 26af38
- Allow virt_driver_domain dbus chat with policykit
Zdenek Pytela 26af38
- Allow virtqemud manage nfs files when virt_use_nfs boolean is on
Zdenek Pytela 26af38
- Add rules for interactions between generators
Zdenek Pytela 26af38
- Label memory.pressure files with cgroup_memory_pressure_t
Zdenek Pytela 26af38
- Revert "Allow some systemd services write to cgroup files"
Zdenek Pytela 26af38
- Update policy for systemd-nsresourced
Zdenek Pytela 26af38
- Label /usr/bin/ntfsck with fsadm_exec_t
Zdenek Pytela 26af38
- Allow systemd_fstab_generator_t read tmpfs files
Zdenek Pytela 26af38
- Update policy for systemd-nsresourced
Zdenek Pytela 26af38
- Alias /usr/sbin to /usr/bin and change all /usr/sbin paths to /usr/bin
Zdenek Pytela 26af38
- Remove a few lines duplicated between {dkim,milter}.fc
Zdenek Pytela 26af38
- Alias /bin → /usr/bin and remove redundant paths
Zdenek Pytela 26af38
- Drop duplicate line for /usr/sbin/unix_chkpwd
Zdenek Pytela 26af38
- Drop duplicate paths for /usr/sbin
Zdenek Pytela 26af38
Zdenek Pytela dd75a9
* Tue Jun 11 2024 Zdenek Pytela <zpytela@redhat.com> - 41.3-1
Zdenek Pytela dd75a9
- Update systemd-generator policy
Zdenek Pytela dd75a9
- Remove permissive domain for bootupd_t
Zdenek Pytela dd75a9
- Remove permissive domain for coreos_installer_t
Zdenek Pytela dd75a9
- Remove permissive domain for afterburn_t
Zdenek Pytela dd75a9
- Add the sap module to modules.conf
Zdenek Pytela dd75a9
- Move unconfined_domain(sap_unconfined_t) to an optional block
Zdenek Pytela dd75a9
- Create the sap module
Zdenek Pytela dd75a9
- Allow systemd-coredumpd sys_admin and sys_resource capabilities
Zdenek Pytela dd75a9
- Allow systemd-coredump read nsfs files
Zdenek Pytela dd75a9
- Allow generators auto file transition only for plain files
Zdenek Pytela dd75a9
- Allow systemd-hwdb write to the kernel messages device
Zdenek Pytela dd75a9
- Escape "interface" as a file name in a virt filetrans pattern
Zdenek Pytela dd75a9
- Allow gnome-software work for login_userdomain
Zdenek Pytela dd75a9
- Allow systemd-machined manage runtime sockets
Zdenek Pytela dd75a9
- Revert "Allow systemd-machined manage runtime sockets"
Zdenek Pytela dd75a9
Zdenek Pytela 3dce5f
* Fri Jun 07 2024 Zdenek Pytela <zpytela@redhat.com> - 41.2-1
Zdenek Pytela 3dce5f
- Allow postfix_domain connect to postgresql over a unix socket
Zdenek Pytela 3dce5f
- Dontaudit systemd-coredump sys_admin capability
Zdenek Pytela 3dce5f
- Allow all domains read and write z90crypt device
Zdenek Pytela 3dce5f
- Allow tpm2 generator setfscreate
Zdenek Pytela 3dce5f
- Allow systemd (PID 1) manage systemd conf files
Zdenek Pytela 3dce5f
- Allow pulseaudio map its runtime files
Zdenek Pytela 3dce5f
- Update policy for getty-generator
Zdenek Pytela 3dce5f
- Allow systemd-hwdb send messages to kernel unix datagram sockets
Zdenek Pytela 3dce5f
- Allow systemd-machined manage runtime sockets
Zdenek Pytela 3dce5f
Petr Lautrbach cd2c1d
* Mon Jun 03 2024 Zdenek Pytela <zpytela@redhat.com> - 41.1-1
Petr Lautrbach cd2c1d
- Allow fstab-generator create unit file symlinks
Petr Lautrbach cd2c1d
- Update policy for cryptsetup-generator
Petr Lautrbach cd2c1d
- Update policy for fstab-generator
Petr Lautrbach cd2c1d
- Allow virtqemud read vm sysctls
Petr Lautrbach cd2c1d
- Allow collectd to trace processes in user namespace
Petr Lautrbach cd2c1d
- Allow bootupd search efivarfs dirs
Petr Lautrbach cd2c1d
- Add policy for systemd-mountfsd
Petr Lautrbach cd2c1d
- Add policy for systemd-nsresourced
Petr Lautrbach cd2c1d
- Update policy generators
Petr Lautrbach cd2c1d
- Add policy for anaconda-generator
Petr Lautrbach cd2c1d
- Update policy for fstab and gpt generators
Petr Lautrbach cd2c1d
- Add policy for kdump-dep-generator
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu May 30 2024 Zdenek Pytela <zpytela@redhat.com> - 40.21-1
Petr Lautrbach cd2c1d
- Add policy for a generic generator
Petr Lautrbach cd2c1d
- Add policy for tpm2 generator
Petr Lautrbach cd2c1d
- Add policy for ssh-generator
Petr Lautrbach cd2c1d
- Add policy for second batch of generators
Petr Lautrbach cd2c1d
- Update policy for systemd generators
Petr Lautrbach cd2c1d
- ci: Adjust Cockpit test plans
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Sun May 19 2024 Zdenek Pytela <zpytela@redhat.com> - 40.20-1
Petr Lautrbach cd2c1d
- Allow journald read systemd config files and directories
Petr Lautrbach cd2c1d
- Allow systemd_domain read systemd_conf_t dirs
Petr Lautrbach cd2c1d
- Fix bad Python regexp escapes
Petr Lautrbach cd2c1d
- Allow fido services connect to postgres database
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri May 17 2024 Zdenek Pytela <zpytela@redhat.com> - 40.19-1
Petr Lautrbach cd2c1d
- Allow postfix smtpd map aliases file
Petr Lautrbach cd2c1d
- Ensure dbus communication is allowed bidirectionally
Petr Lautrbach cd2c1d
- Label systemd configuration files with systemd_conf_t
Petr Lautrbach cd2c1d
- Label /run/systemd/machine with systemd_machined_var_run_t
Petr Lautrbach cd2c1d
- Allow systemd-hostnamed read the vsock device
Petr Lautrbach cd2c1d
- Allow sysadm execute dmidecode using sudo
Petr Lautrbach cd2c1d
- Allow sudodomain list files in /var
Petr Lautrbach cd2c1d
- Allow setroubleshootd get attributes of all sysctls
Petr Lautrbach cd2c1d
- Allow various services read and write z90crypt device
Petr Lautrbach cd2c1d
- Allow nfsidmap connect to systemd-homed
Petr Lautrbach cd2c1d
- Allow sandbox_x_client_t dbus chat with accountsd
Petr Lautrbach cd2c1d
- Allow system_cronjob_t dbus chat with avahi_t
Petr Lautrbach cd2c1d
- Allow staff_t the io_uring sqpoll permission
Petr Lautrbach cd2c1d
- Allow staff_t use the io_uring API
Petr Lautrbach cd2c1d
- Add support for secretmem anon inode
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu May 16 2024 Adam Williamson <awilliam@redhat.com> - 40.18-3
Petr Lautrbach cd2c1d
- Correct some errors in the RPM macro changes from -2
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon May 06 2024 Zdenek Pytela <zpytela@redhat.com> - 40.18-2
Petr Lautrbach cd2c1d
- Update rpm configuration for the /var/run equivalency change
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon May 06 2024 Zdenek Pytela <zpytela@redhat.com> - 40.18-1
Petr Lautrbach cd2c1d
- Allow virtqemud read vfio devices
Petr Lautrbach cd2c1d
- Allow virtqemud get attributes of a tmpfs filesystem
Petr Lautrbach cd2c1d
- Allow svirt_t read vm sysctls
Petr Lautrbach cd2c1d
- Allow virtqemud create and unlink files in /etc/libvirt/
Petr Lautrbach cd2c1d
- Allow virtqemud get attributes of cifs files
Petr Lautrbach cd2c1d
- Allow virtqemud get attributes of filesystems with extended attributes
Petr Lautrbach cd2c1d
- Allow virtqemud get attributes of NFS filesystems
Petr Lautrbach cd2c1d
- Allow virt_domain read and write usb devices conditionally
Petr Lautrbach cd2c1d
- Allow virtstoraged use the io_uring API
Petr Lautrbach cd2c1d
- Allow virtstoraged execute lvm programs in the lvm domain
Petr Lautrbach cd2c1d
- Allow virtnodevd_t map /var/lib files
Petr Lautrbach cd2c1d
- Allow svirt_tcg_t map svirt_image_t files
Petr Lautrbach cd2c1d
- Allow abrt-dump-journal-core connect to systemd-homed
Petr Lautrbach cd2c1d
- Allow abrt-dump-journal-core connect to systemd-machined
Petr Lautrbach cd2c1d
- Allow sssd create and use io_uring
Petr Lautrbach cd2c1d
- Allow selinux-relabel-generator create units dir
Petr Lautrbach cd2c1d
- Allow dbus-broker read/write inherited user ttys
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Apr 25 2024 Zdenek Pytela <zpytela@redhat.com> - 40.17-1
Petr Lautrbach cd2c1d
- Define transitions for /run/libvirt/common and /run/libvirt/qemu
Petr Lautrbach cd2c1d
- Allow systemd-sleep read raw disk data
Petr Lautrbach cd2c1d
- Allow numad to trace processes in user namespace
Petr Lautrbach cd2c1d
- Allow abrt-dump-journal-core connect to systemd-userdbd
Petr Lautrbach cd2c1d
- Allow plymouthd read efivarfs files
Petr Lautrbach cd2c1d
- Update the auth_dontaudit_read_passwd_file() interface
Petr Lautrbach cd2c1d
- Label /dev/mmcblk0rpmb character device with removable_device_t
Petr Lautrbach cd2c1d
- fix hibernate on btrfs swapfile (F40)
Petr Lautrbach cd2c1d
- Allow nut to statfs()
Petr Lautrbach cd2c1d
- Allow system dbusd service status systemd services
Petr Lautrbach cd2c1d
- Allow systemd-timedated get the timemaster service status
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Apr 09 2024 Zdenek Pytela <zpytela@redhat.com> - 40.16-1
Petr Lautrbach cd2c1d
- Allow keyutils-dns-resolver connect to the system log service
Petr Lautrbach cd2c1d
- Allow qemu-ga read vm sysctls
Petr Lautrbach cd2c1d
- postfix: allow qmgr to delete mails in bounce/ directory
Petr Lautrbach cd2c1d
- policy: support pidfs
Petr Lautrbach cd2c1d
- Confine selinux-autorelabel-generator.sh
Petr Lautrbach cd2c1d
- Allow logwatch_mail_t read/write to init over a unix stream socket
Petr Lautrbach cd2c1d
- Allow logwatch read logind sessions files
Petr Lautrbach cd2c1d
- files_dontaudit_getattr_tmpfs_files allowed the access and didn't dontaudit it
Petr Lautrbach cd2c1d
- files_dontaudit_mounton_modules_object allowed the access and didn't dontaudit it
Petr Lautrbach cd2c1d
- Allow NetworkManager the sys_ptrace capability in user namespace
Petr Lautrbach cd2c1d
- dontaudit execmem for modemmanager
Petr Lautrbach cd2c1d
- Allow dhcpcd use unix_stream_socket
Petr Lautrbach cd2c1d
- Allow dhcpc read /run/netns files
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Fri Mar 15 2024 Zdenek Pytela <zpytela@redhat.com> - 40.15-1
Petr Lautrbach cd2c1d
- Update mmap_rw_file_perms to include the lock permission
Petr Lautrbach cd2c1d
- Allow plymouthd log during shutdown
Petr Lautrbach cd2c1d
- Add logging_watch_all_log_dirs() and logging_watch_all_log_files()
Petr Lautrbach cd2c1d
- Allow journalctl_t read filesystem sysctls
Petr Lautrbach cd2c1d
- Allow cgred_t to get attributes of cgroup filesystems
Petr Lautrbach cd2c1d
- Allow wdmd read hardware state information
Petr Lautrbach cd2c1d
- Allow wdmd list the contents of the sysfs directories
Petr Lautrbach cd2c1d
- Allow linuxptp configure phc2sys and chronyd over a unix domain socket
Petr Lautrbach cd2c1d
- Allow sulogin relabel tty1
Petr Lautrbach cd2c1d
- Dontaudit sulogin the checkpoint_restore capability
Petr Lautrbach cd2c1d
- Modify sudo_role_template() to allow getpgid
Petr Lautrbach cd2c1d
- Remove incorrect "local" usage in varrun-convert.sh
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Mar 07 2024 Zdenek Pytela <zpytela@redhat.com> - 40.14-2
Petr Lautrbach cd2c1d
- Update varrun-convert.sh script to check for existing duplicate entries
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon Feb 26 2024 Zdenek Pytela <zpytela@redhat.com> - 40.14-1
Petr Lautrbach cd2c1d
- Allow userdomain get attributes of files on an nsfs filesystem
Petr Lautrbach cd2c1d
- Allow opafm create NFS files and directories
Petr Lautrbach cd2c1d
- Allow virtqemud create and unlink files in /etc/libvirt/
Petr Lautrbach cd2c1d
- Allow virtqemud domain transition on swtpm execution
Petr Lautrbach cd2c1d
- Add the swtpm.if interface file for interactions with other domains
Petr Lautrbach cd2c1d
- Allow samba to have dac_override capability
Petr Lautrbach cd2c1d
- systemd: allow sys_admin capability for systemd_notify_t
Petr Lautrbach cd2c1d
- systemd: allow systemd_notify_t to send data to kernel_t datagram sockets
Petr Lautrbach cd2c1d
- Allow thumb_t to watch and watch_reads mount_var_run_t
Petr Lautrbach cd2c1d
- Allow krb5kdc_t map krb5kdc_principal_t files
Petr Lautrbach cd2c1d
- Allow unprivileged confined user dbus chat with setroubleshoot
Petr Lautrbach cd2c1d
- Allow login_userdomain map files in /var
Petr Lautrbach cd2c1d
- Allow wireguard work with firewall-cmd
Petr Lautrbach cd2c1d
- Differentiate between staff and sysadm when executing crontab with sudo
Petr Lautrbach cd2c1d
- Add crontab_admin_domtrans interface
Petr Lautrbach cd2c1d
- Allow abrt_t nnp domain transition to abrt_handle_event_t
Petr Lautrbach cd2c1d
- Allow xdm_t to watch and watch_reads mount_var_run_t
Petr Lautrbach cd2c1d
- Dontaudit subscription manager setfscreate and read file contexts
Petr Lautrbach cd2c1d
- Don't audit crontab_domain write attempts to user home
Petr Lautrbach cd2c1d
- Transition from sudodomains to crontab_t when executing crontab_exec_t
Petr Lautrbach cd2c1d
- Add crontab_domtrans interface
Petr Lautrbach cd2c1d
- Fix label of pseudoterminals created from sudodomain
Petr Lautrbach cd2c1d
- Allow utempter_t use ptmx
Petr Lautrbach cd2c1d
- Dontaudit rpmdb attempts to connect to sssd over a unix stream socket
Petr Lautrbach cd2c1d
- Allow admin user read/write on fixed_disk_device_t
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon Feb 12 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13-1
Petr Lautrbach cd2c1d
- Only allow confined user domains to login locally without unconfined_login
Petr Lautrbach cd2c1d
- Add userdom_spec_domtrans_confined_admin_users interface
Petr Lautrbach cd2c1d
- Only allow admindomain to execute shell via ssh with ssh_sysadm_login
Petr Lautrbach cd2c1d
- Add userdom_spec_domtrans_admin_users interface
Petr Lautrbach cd2c1d
- Move ssh dyntrans to unconfined inside unconfined_login tunable policy
Petr Lautrbach cd2c1d
- Update ssh_role_template() for user ssh-agent type
Petr Lautrbach cd2c1d
- Allow init to inherit system DBus file descriptors
Petr Lautrbach cd2c1d
- Allow init to inherit fds from syslogd
Petr Lautrbach cd2c1d
- Allow any domain to inherit fds from rpm-ostree
Petr Lautrbach cd2c1d
- Update afterburn policy
Petr Lautrbach cd2c1d
- Allow init_t nnp domain transition to abrtd_t
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Feb 06 2024 Zdenek Pytela <zpytela@redhat.com> - 40.12-1
Petr Lautrbach cd2c1d
- Rename all /var/lock file context entries to /run/lock
Petr Lautrbach cd2c1d
- Rename all /var/run file context entries to /run
Petr Lautrbach cd2c1d
- Invert the "/var/run = /run" equivalency
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Mon Feb 05 2024 Zdenek Pytela <zpytela@redhat.com> - 40.11-1
Petr Lautrbach cd2c1d
- Replace init domtrans rule for confined users to allow exec init
Petr Lautrbach cd2c1d
- Update dbus_role_template() to allow user service status
Petr Lautrbach cd2c1d
- Allow polkit status all systemd services
Petr Lautrbach cd2c1d
- Allow setroubleshootd create and use inherited io_uring
Petr Lautrbach cd2c1d
- Allow load_policy read and write generic ptys
Petr Lautrbach cd2c1d
- Allow gpg manage rpm cache
Petr Lautrbach cd2c1d
- Allow login_userdomain name_bind to howl and xmsg udp ports
Petr Lautrbach cd2c1d
- Allow rules for confined users logged in plasma
Petr Lautrbach cd2c1d
- Label /dev/iommu with iommu_device_t
Petr Lautrbach cd2c1d
- Remove duplicate file context entries in /run
Petr Lautrbach cd2c1d
- Dontaudit getty and plymouth the checkpoint_restore capability
Petr Lautrbach cd2c1d
- Allow su domains write login records
Petr Lautrbach cd2c1d
- Revert "Allow su domains write login records"
Petr Lautrbach cd2c1d
- Allow login_userdomain delete session dbusd tmp socket files
Petr Lautrbach cd2c1d
- Allow unix dgram sendto between exim processes
Petr Lautrbach cd2c1d
- Allow su domains write login records
Petr Lautrbach cd2c1d
- Allow smbd_t to watch user_home_dir_t if samba_enable_home_dirs is on
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Wed Jan 24 2024 Zdenek Pytela <zpytela@redhat.com> - 40.10-1
Petr Lautrbach cd2c1d
- Allow chronyd-restricted read chronyd key files
Petr Lautrbach cd2c1d
- Allow conntrackd_t to use bpf capability2
Petr Lautrbach cd2c1d
- Allow systemd-networkd manage its runtime socket files
Petr Lautrbach cd2c1d
- Allow init_t nnp domain transition to colord_t
Petr Lautrbach cd2c1d
- Allow polkit status systemd services
Petr Lautrbach cd2c1d
- nova: Fix duplicate declarations
Petr Lautrbach cd2c1d
- Allow httpd work with PrivateTmp
Petr Lautrbach cd2c1d
- Add interfaces for watching and reading ifconfig_var_run_t
Petr Lautrbach cd2c1d
- Allow collectd read raw fixed disk device
Petr Lautrbach cd2c1d
- Allow collectd read udev pid files
Petr Lautrbach cd2c1d
- Set correct label on /etc/pki/pki-tomcat/kra
Petr Lautrbach cd2c1d
- Allow systemd domains watch system dbus pid socket files
Petr Lautrbach cd2c1d
- Allow certmonger read network sysctls
Petr Lautrbach cd2c1d
- Allow mdadm list stratisd data directories
Petr Lautrbach cd2c1d
- Allow syslog to run unconfined scripts conditionally
Petr Lautrbach cd2c1d
- Allow syslogd_t nnp_transition to syslogd_unconfined_script_t
Petr Lautrbach cd2c1d
- Allow qatlib set attributes of vfio device files
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Jan 09 2024 Zdenek Pytela <zpytela@redhat.com> - 40.9-1
Petr Lautrbach cd2c1d
- Allow systemd-sleep set attributes of efivarfs files
Petr Lautrbach cd2c1d
- Allow samba-dcerpcd read public files
Petr Lautrbach cd2c1d
- Allow spamd_update_t the sys_ptrace capability in user namespace
Petr Lautrbach cd2c1d
- Allow bluetooth devices work with alsa
Petr Lautrbach cd2c1d
- Allow alsa get attributes filesystems with extended attributes
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Jan 02 2024 Yaakov Selkowitz <yselkowi@redhat.com> - 40.8-2
Petr Lautrbach cd2c1d
- Limit %%selinux_requires to version, not release
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Dec 21 2023 Zdenek Pytela <zpytela@redhat.com> - 40.8-1
Petr Lautrbach cd2c1d
- Allow hypervkvp_t write access to NetworkManager_etc_rw_t
Petr Lautrbach cd2c1d
- Add interface for write-only access to NetworkManager rw conf
Petr Lautrbach cd2c1d
- Allow systemd-sleep send a message to syslog over a unix dgram socket
Petr Lautrbach cd2c1d
- Allow init create and use netlink netfilter socket
Petr Lautrbach cd2c1d
- Allow qatlib load kernel modules
Petr Lautrbach cd2c1d
- Allow qatlib run lspci
Petr Lautrbach cd2c1d
- Allow qatlib manage its private runtime socket files
Petr Lautrbach cd2c1d
- Allow qatlib read/write vfio devices
Petr Lautrbach cd2c1d
- Label /etc/redis.conf with redis_conf_t
Petr Lautrbach cd2c1d
- Remove the lockdown-class rules from the policy
Petr Lautrbach cd2c1d
- Allow init read all non-security socket files
Petr Lautrbach cd2c1d
- Replace redundant dnsmasq pattern macros
Petr Lautrbach cd2c1d
- Remove unneeded symlink perms in dnsmasq.if
Petr Lautrbach cd2c1d
- Add additions to dnsmasq interface
Petr Lautrbach cd2c1d
- Allow nvme_stas_t create and use netlink kobject uevent socket
Petr Lautrbach cd2c1d
- Allow collectd connect to statsd port
Petr Lautrbach cd2c1d
- Allow keepalived_t to use sys_ptrace of cap_userns
Petr Lautrbach cd2c1d
- Allow dovecot_auth_t connect to postgresql using UNIX socket
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Wed Dec 13 2023 Zdenek Pytela <zpytela@redhat.com> - 40.7-1
Petr Lautrbach cd2c1d
- Make named_zone_t and named_var_run_t a part of the mountpoint attribute
Petr Lautrbach cd2c1d
- Allow sysadm execute traceroute in sysadm_t domain using sudo
Petr Lautrbach cd2c1d
- Allow sysadm execute tcpdump in sysadm_t domain using sudo
Petr Lautrbach cd2c1d
- Allow opafm search nfs directories
Petr Lautrbach cd2c1d
- Add support for syslogd unconfined scripts
Petr Lautrbach cd2c1d
- Allow gpsd use /dev/gnss devices
Petr Lautrbach cd2c1d
- Allow gpg read rpm cache
Petr Lautrbach cd2c1d
- Allow virtqemud additional permissions
Petr Lautrbach cd2c1d
- Allow virtqemud manage its private lock files
Petr Lautrbach cd2c1d
- Allow virtqemud use the io_uring api
Petr Lautrbach cd2c1d
- Allow ddclient send e-mail notifications
Petr Lautrbach cd2c1d
- Allow postfix_master_t map postfix data files
Petr Lautrbach cd2c1d
- Allow init create and use vsock sockets
Petr Lautrbach cd2c1d
- Allow thumb_t append to init unix domain stream sockets
Petr Lautrbach cd2c1d
- Label /dev/vas with vas_device_t
Petr Lautrbach cd2c1d
- Change domain_kernel_load_modules boolean to true
Petr Lautrbach cd2c1d
- Create interface selinux_watch_config and add it to SELinux users
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Nov 28 2023 Zdenek Pytela <zpytela@redhat.com> - 40.6-1
Petr Lautrbach cd2c1d
- Add afterburn to modules-targeted-contrib.conf
Petr Lautrbach cd2c1d
- Update cifs interfaces to include fs_search_auto_mountpoints()
Petr Lautrbach cd2c1d
- Allow sudodomain read var auth files
Petr Lautrbach cd2c1d
- Allow spamd_update_t read hardware state information
Petr Lautrbach cd2c1d
- Allow virtnetworkd domain transition on tc command execution
Petr Lautrbach cd2c1d
- Allow sendmail MTA connect to sendmail LDA
Petr Lautrbach cd2c1d
- Allow auditd read all domains process state
Petr Lautrbach cd2c1d
- Allow rsync read network sysctls
Petr Lautrbach cd2c1d
- Add dhcpcd bpf capability to run bpf programs
Petr Lautrbach cd2c1d
- Dontaudit systemd-hwdb dac_override capability
Petr Lautrbach cd2c1d
- Allow systemd-sleep create efivarfs files
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Nov 14 2023 Zdenek Pytela <zpytela@redhat.com> - 40.5-1
Petr Lautrbach cd2c1d
- Allow map xserver_tmpfs_t files when xserver_clients_write_xshm is on
Petr Lautrbach cd2c1d
- Allow graphical applications work in Wayland
Petr Lautrbach cd2c1d
- Allow kdump work with PrivateTmp
Petr Lautrbach cd2c1d
- Allow dovecot-auth work with PrivateTmp
Petr Lautrbach cd2c1d
- Allow nfsd get attributes of all filesystems
Petr Lautrbach cd2c1d
- Allow unconfined_domain_type use io_uring cmd on domain
Petr Lautrbach cd2c1d
- ci: Only run Rawhide revdeps tests on the rawhide branch
Petr Lautrbach cd2c1d
- Label /var/run/auditd.state as auditd_var_run_t
Petr Lautrbach cd2c1d
- Allow fido-device-onboard (FDO) read the crack database
Petr Lautrbach cd2c1d
- Allow ip an explicit domain transition to other domains
Petr Lautrbach cd2c1d
- Label /usr/libexec/selinux/selinux-autorelabel with semanage_exec_t
Petr Lautrbach cd2c1d
- Allow  winbind_rpcd_t processes access when samba_export_all_* is on
Petr Lautrbach cd2c1d
- Enable NetworkManager and dhclient to use initramfs-configured DHCP connection
Petr Lautrbach cd2c1d
- Allow ntp to bind and connect to ntske port.
Petr Lautrbach cd2c1d
- Allow system_mail_t manage exim spool files and dirs
Petr Lautrbach cd2c1d
- Dontaudit keepalived setattr on keepalived_unconfined_script_exec_t
Petr Lautrbach cd2c1d
- Label /run/pcsd.socket with cluster_var_run_t
Petr Lautrbach cd2c1d
- ci: Run cockpit tests in PRs
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Thu Oct 19 2023 Zdenek Pytela <zpytela@redhat.com> - 40.4-1
Petr Lautrbach cd2c1d
- Add map_read map_write to kernel_prog_run_bpf
Petr Lautrbach cd2c1d
- Allow systemd-fstab-generator read all symlinks
Petr Lautrbach cd2c1d
- Allow systemd-fstab-generator the dac_override capability
Petr Lautrbach cd2c1d
- Allow rpcbind read network sysctls
Petr Lautrbach cd2c1d
- Support using systemd containers
Petr Lautrbach cd2c1d
- Allow sysadm_t to connect to iscsid using a unix domain stream socket
Petr Lautrbach cd2c1d
- Add policy for coreos installer
Petr Lautrbach cd2c1d
- Add coreos_installer to modules-targeted-contrib.conf
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Oct 17 2023 Zdenek Pytela <zpytela@redhat.com> - 40.3-1
Petr Lautrbach cd2c1d
- Add policy for nvme-stas
Petr Lautrbach cd2c1d
- Confine systemd fstab,sysv,rc-local
Petr Lautrbach cd2c1d
- Label /etc/aliases.lmdb with etc_aliases_t
Petr Lautrbach cd2c1d
- Create policy for afterburn
Petr Lautrbach cd2c1d
- Add nvme_stas to modules-targeted-contrib.conf
Petr Lautrbach cd2c1d
- Add plans/tests.fmf
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Oct 10 2023 Zdenek Pytela <zpytela@redhat.com> - 40.2-1
Petr Lautrbach cd2c1d
- Add the virt_supplementary module to modules-targeted-contrib.conf
Petr Lautrbach cd2c1d
- Make new virt drivers permissive
Petr Lautrbach cd2c1d
- Split virt policy, introduce virt_supplementary module
Petr Lautrbach cd2c1d
- Allow apcupsd cgi scripts read /sys
Petr Lautrbach cd2c1d
- Merge pull request #1893 from WOnder93/more-early-boot-overlay-fixes
Petr Lautrbach cd2c1d
- Allow kernel_t to manage and relabel all files
Petr Lautrbach cd2c1d
- Add missing optional_policy() to files_relabel_all_files()
Petr Lautrbach cd2c1d
Petr Lautrbach cd2c1d
* Tue Oct 03 2023 Zdenek Pytela <zpytela@redhat.com> - 40.1-1
Petr Lautrbach cd2c1d
- Allow named and ndc use the io_uring api
Petr Lautrbach cd2c1d
- Deprecate common_anon_inode_perms usage
Petr Lautrbach cd2c1d
- Improve default file context(None) of /var/lib/authselect/backups
Petr Lautrbach cd2c1d
- Allow udev_t to search all directories with a filesystem type
Petr Lautrbach cd2c1d
- Implement proper anon_inode support
Petr Lautrbach cd2c1d
- Allow targetd write to the syslog pid sock_file
Petr Lautrbach cd2c1d
- Add ipa_pki_retrieve_key_exec() interface
Petr Lautrbach cd2c1d
- Allow kdumpctl_t to list all directories with a filesystem type
Petr Lautrbach cd2c1d
- Allow udev additional permissions
Petr Lautrbach cd2c1d
- Allow udev load kernel module
Petr Lautrbach cd2c1d
- Allow sysadm_t to mmap modules_object_t files
Petr Lautrbach cd2c1d
- Add the unconfined_read_files() and unconfined_list_dirs() interfaces
Petr Lautrbach cd2c1d
- Set default file context of HOME_DIR/tmp/.* to <<none>>
Petr Lautrbach cd2c1d
- Allow kernel_generic_helper_t to execute mount(1)