diff --git a/.gitignore b/.gitignore
index fb858f0..02f3fc7 100644
--- a/.gitignore
+++ b/.gitignore
@@ -276,3 +276,5 @@ serefpolicy*
 /selinux-policy-contrib-6c883f6.tar.gz
 /selinux-policy-301aa80.tar.gz
 /selinux-policy-contrib-01b5dd1.tar.gz
+/selinux-policy-17160ee.tar.gz
+/selinux-policy-contrib-4f6a859.tar.gz
diff --git a/selinux-policy.spec b/selinux-policy.spec
index c8e0a44..9424c96 100644
--- a/selinux-policy.spec
+++ b/selinux-policy.spec
@@ -1,11 +1,11 @@
 # github repo with selinux-policy base sources
 %global git0 https://github.com/fedora-selinux/selinux-policy
-%global commit0 301aa80a689f78da6b0299c0e332ea56d510b309
+%global commit0 17160eea7a10d81693754759c561c9b83fc2d422
 %global shortcommit0 %(c=%{commit0}; echo ${c:0:7})
 
 # github repo with selinux-policy contrib sources
 %global git1 https://github.com/fedora-selinux/selinux-policy-contrib
-%global commit1 01b5dd12bfe7adebc57458c30a924ba81e83e3ad
+%global commit1 4f6a859548cce112341679e720b88f7d1cb674d7
 %global shortcommit1 %(c=%{commit1}; echo ${c:0:7})
 
 %define distro redhat
@@ -29,7 +29,7 @@
 Summary: SELinux policy configuration
 Name: selinux-policy
 Version: 3.14.2
-Release: 15%{?dist}
+Release: 16%{?dist}
 License: GPLv2+
 Group: System Environment/Base
 Source: %{git0}/archive/%{commit0}/%{name}-%{shortcommit0}.tar.gz
@@ -718,6 +718,10 @@ exit 0
 %endif
 
 %changelog
+* Mon Apr 30 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.2-16
+- Allow systemd to mmap files with var_log_t label
+- Allow x_userdomains read/write to xserver session
+
 * Sat Apr 28 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.2-15
 - Allow unconfined_domain_type to create libs filetrans named content BZ(1513806)
 
diff --git a/sources b/sources
index 674c254..9c61b7b 100644
--- a/sources
+++ b/sources
@@ -1,3 +1,3 @@
-SHA512 (selinux-policy-301aa80.tar.gz) = 6435e0af67e972ebd476668880d49c810b5f616b4a1dab43428c7ec9845887406d190fcc7a01a84c32deab4613d414c4f72e948114ecf7f0d2f2dcccbe0a856a
-SHA512 (selinux-policy-contrib-01b5dd1.tar.gz) = 8285a8caa1f71c4438640b9cc63b8ea4addb590dd7fac8c17c7499ce879763c348f0a4d375ea9923f881d9318bd4b2697be27da39b9b6acb9279858955c43a64
-SHA512 (container-selinux.tgz) = d645fd3432429ae0af6fa5f4aff85a09bf58c139ef1296e33349558045af2c7f0c72491df06b9922e95931e4d69bfb1353c46333c251e0178006d04250bf9f80
+SHA512 (container-selinux.tgz) = fd71df0f8489c5763dd254aed5f27ef1e11c3c64c199986dbb471c6376f251f88ccb3a89706976a73ee5b8706c03bb8839c916aaf23e8d66b4b9693c6783af13
+SHA512 (selinux-policy-17160ee.tar.gz) = 9b2ffc5e51d8c3be9aeae6234a5509792dfe0220ba2fcb9be6f2e8783ce3d556bb44df98d4b02da498c2d78eeea4d63b4258eb88adeb4ccac5f9c1b986a1b7ef
+SHA512 (selinux-policy-contrib-4f6a859.tar.gz) = 3f2ac4cf26466a324adcc952286c20254cbd0e40149b9948eb623b03804ec056355deefa231dd9e4910097f5b0874f358f1731b68b47c746859a2f02adab23a6