diff --git a/.gitignore b/.gitignore
index 148cb03..dbd2262 100644
--- a/.gitignore
+++ b/.gitignore
@@ -440,3 +440,5 @@ serefpolicy*
 /selinux-policy-4be621b.tar.gz
 /selinux-policy-contrib-6178b11.tar.gz
 /selinux-policy-a303d1d.tar.gz
+/selinux-policy-contrib-f2a3549.tar.gz
+/selinux-policy-d5268be.tar.gz
diff --git a/selinux-policy.spec b/selinux-policy.spec
index 67c09fd..29ef89e 100644
--- a/selinux-policy.spec
+++ b/selinux-policy.spec
@@ -1,11 +1,11 @@
 # github repo with selinux-policy base sources
 %global git0 https://github.com/fedora-selinux/selinux-policy
-%global commit0 a303d1d9a4d777c978b83677e5453c0dc40a5207
+%global commit0 d5268be21538b700a57f7b89399615fde06dd9bc
 %global shortcommit0 %(c=%{commit0}; echo ${c:0:7})
 
 # github repo with selinux-policy contrib sources
 %global git1 https://github.com/fedora-selinux/selinux-policy-contrib
-%global commit1 6178b11224d23f9816db53ceff7533dd844afef4
+%global commit1 f2a3549c2ffa2ad553923054809b3c8c91d0dcf0
 %global shortcommit1 %(c=%{commit1}; echo ${c:0:7})
 
 %define distro redhat
@@ -29,7 +29,7 @@
 Summary: SELinux policy configuration
 Name: selinux-policy
 Version: 3.14.6
-Release: 3%{?dist}
+Release: 4%{?dist}
 License: GPLv2+
 Source: %{git0}/archive/%{commit0}/%{name}-%{shortcommit0}.tar.gz
 Source29: %{git1}/archive/%{commit1}/%{name}-contrib-%{shortcommit1}.tar.gz
@@ -772,6 +772,12 @@ exit 0
 %endif
 
 %changelog
+* Tue Feb 18 2020 Lukas Vrabec <lvrabec@redhat.com> - 3.14.6-4
+- Update virt_read_qemu_pid_files inteface
+- Allow systemd_logind_t domain to getattr cgroup filesystem
+- Allow systemd_logind_t domain to manage user_tmp_t char and block devices
+- Allow nsswitch_domain attribute to stream connect to systemd process
+
 * Sun Feb 16 2020 Lukas Vrabec <lvrabec@redhat.com> - 3.14.6-3
 - Allow systemd labeled as init_t to manage systemd_userdbd_runtime_t symlinks
 - Allow systemd_userdbd_t domain to read efivarfs files
diff --git a/sources b/sources
index 38bdfaa..f051fe9 100644
--- a/sources
+++ b/sources
@@ -1,4 +1,4 @@
-SHA512 (selinux-policy-a303d1d.tar.gz) = f7060681f0fbe63285af8a29ac5ad2657e61bce294c73c21f8c05edc7d1ae760ea21429fc733420d23df653eea38e8d8f0c19d40de7cfdd1985f07538cf93db9
-SHA512 (selinux-policy-contrib-6178b11.tar.gz) = b3c15c91b10ec5798b800cf4ecc25abb190a510a67fc55042c5b3016ce078853ff6ce69b18e57524f62962dffa979031446df411fdd97699e87d697c66d405db
-SHA512 (container-selinux.tgz) = 8477ac0bba4611aeac827e3e23fd6eb04e753cf7b2d72cf99ffdd4e3d144dc3ac122648faa86f999d0be4f25d5b82955dca43e60dbd73e21d53fe2141b9336e2
+SHA512 (selinux-policy-contrib-f2a3549.tar.gz) = 934192496cb554e35113061ec45a01c967ad9494e209058564783f420bdbe398901515bf46d735af48e6d23516c095d531bf0668e52c39c56a241094e739ec24
+SHA512 (selinux-policy-d5268be.tar.gz) = 659f6fb8501b63ce51217bc2582608dc8da48131ab83160070b062fda5cdbf93d8286e8182d66e034c8b58634a33a7fb7789adeb303073601698d26c5496a08c
+SHA512 (container-selinux.tgz) = 84beebe9723339d93bc501667ec113a3338dd179346d76d5c5aba4924959e96ff46a8a13e05fd0870e4764b613e099f1dcbfffbff92ca62e429bc4981f41e64a
 SHA512 (macro-expander) = 243ee49f1185b78ac47e56ca9a3f3592f8975fab1a2401c0fcc7f88217be614fe31805bacec602b728e7fcfc21dcc17d90e9a54ce87f3a0c97624d9ad885aea4