diff --git a/.gitignore b/.gitignore
index 7262057..308110c 100644
--- a/.gitignore
+++ b/.gitignore
@@ -1,3 +1,3 @@
 SOURCES/container-selinux.tgz
 SOURCES/selinux-policy-4411b2b.tar.gz
-SOURCES/selinux-policy-contrib-b10e5e7.tar.gz
+SOURCES/selinux-policy-contrib-b63613a.tar.gz
diff --git a/.selinux-policy.metadata b/.selinux-policy.metadata
index 42c4c17..cc09f88 100644
--- a/.selinux-policy.metadata
+++ b/.selinux-policy.metadata
@@ -1,3 +1,3 @@
-76cfc3eaa9784a4be53730aee2ae998f280d281d SOURCES/container-selinux.tgz
+adcd65ca56a1a96bb6ecdcb99125d6de667496e0 SOURCES/container-selinux.tgz
 023b94bf24221d16d192f49d13cc9fa656eed60a SOURCES/selinux-policy-4411b2b.tar.gz
-a70ce3396639945b1dff5f773c30712883742fe1 SOURCES/selinux-policy-contrib-b10e5e7.tar.gz
+6a00e1e086470d5b9ac291a6f3e97cc9b7bdd5c6 SOURCES/selinux-policy-contrib-b63613a.tar.gz
diff --git a/SPECS/selinux-policy.spec b/SPECS/selinux-policy.spec
index fef3d34..ab02dae 100644
--- a/SPECS/selinux-policy.spec
+++ b/SPECS/selinux-policy.spec
@@ -5,7 +5,7 @@
 
 # github repo with selinux-policy contrib sources
 %global git1 https://github.com/fedora-selinux/selinux-policy-contrib
-%global commit1 b10e5e72663f3aa1ef0bd01f4bbc1ca71d161406
+%global commit1 b63613a565d84edf3d70d093df15a98a832219fa
 %global shortcommit1 %(c=%{commit1}; echo ${c:0:7})
 
 %define distro redhat
@@ -29,7 +29,7 @@
 Summary: SELinux policy configuration
 Name: selinux-policy
 Version: 3.14.3
-Release: 88%{?dist}
+Release: 89%{?dist}
 License: GPLv2+
 Source: %{git0}/archive/%{commit0}/%{name}-%{shortcommit0}.tar.gz
 Source29: %{git1}/archive/%{commit1}/%{name}-contrib-%{shortcommit1}.tar.gz
@@ -141,7 +141,7 @@ SELinux policy development and man page package
 %dir %{_usr}/share/selinux/devel
 %dir %{_usr}/share/selinux/devel/include
 %{_usr}/share/selinux/devel/include/*
-%exclude %{_usr}/selinux/devel/include/contrib/container.if
+%exclude %{_usr}/share/selinux/devel/include/contrib/container.if
 %dir %{_usr}/share/selinux/devel/html
 %{_usr}/share/selinux/devel/html/*html
 %{_usr}/share/selinux/devel/html/*css
@@ -716,6 +716,22 @@ exit 0
 %endif
 
 %changelog
+* Wed Jan 26 2022 Zdenek Pytela <zpytela@redhat.com> - 3.14.3-89
+- Allow NetworkManager talk with unconfined user over unix domain dgram socket
+Resolves: rhbz#2044048
+- Allow system_mail_t read inherited apache system content rw files
+Resolves: rhbz#1988339
+- Add apache_read_inherited_sys_content_rw_files() interface
+Related: rhbz#1988339
+- Allow rhsm-service execute its private memfd: objects
+Resolves: rhbz#2029873
+- Allow dirsrv read configfs files and directories
+Resolves: rhbz#2042568
+- Label /run/stratisd with stratisd_var_run_t
+Resolves: rhbz#1879585
+- Fix path for excluding container.if from selinux-policy-devel
+Resolves: rhbz#1861968
+
 * Thu Jan 20 2022 Zdenek Pytela <zpytela@redhat.com> - 3.14.3-88
 - Revert "Label /etc/cockpit/ws-certs.d with cert_t"
 Related: rhbz#1907473