diff --git a/.gitignore b/.gitignore index c65dceb..effc12d 100644 --- a/.gitignore +++ b/.gitignore @@ -401,3 +401,5 @@ serefpolicy* /selinux-policy-contrib-f2b24ff.tar.gz /selinux-policy-4ab5862.tar.gz /selinux-policy-contrib-c198f5d.tar.gz +/selinux-policy-536f614.tar.gz +/selinux-policy-contrib-1eaee03.tar.gz diff --git a/selinux-policy.spec b/selinux-policy.spec index 3b11a25..a3a1f64 100644 --- a/selinux-policy.spec +++ b/selinux-policy.spec @@ -1,11 +1,11 @@ # github repo with selinux-policy base sources %global git0 https://github.com/fedora-selinux/selinux-policy -%global commit0 4ab58624752645a7a0e81727956eff6808ab6348 +%global commit0 536f614aff5bd7091a2ff3204a8114e8fd126223 %global shortcommit0 %(c=%{commit0}; echo ${c:0:7}) # github repo with selinux-policy contrib sources %global git1 https://github.com/fedora-selinux/selinux-policy-contrib -%global commit1 c198f5d4fe3a73fa9550ef40a6d8c369d929a025 +%global commit1 1eaee03980622e121ed0b01adcf90dd3f2239805 %global shortcommit1 %(c=%{commit1}; echo ${c:0:7}) %define distro redhat @@ -29,7 +29,7 @@ Summary: SELinux policy configuration Name: selinux-policy Version: 3.14.3 -Release: 52%{?dist} +Release: 53%{?dist} License: GPLv2+ Source: %{git0}/archive/%{commit0}/%{name}-%{shortcommit0}.tar.gz Source29: %{git1}/archive/%{commit1}/%{name}-contrib-%{shortcommit1}.tar.gz @@ -714,6 +714,17 @@ exit 0 %endif %changelog +* Mon Dec 02 2019 Zdenek Pytela - 3.14.3-53 +- Allow spamd_update_t access antivirus_unit_file_t BZ(1774092) +- Allow ksmtuned_t domain to trace processes in user namespace +- Fix typo bugs in rtas_errd_read_lock() interface +- cockpit: Allow cockpit-session to read cockpit-tls state directory +- Update lldpad_t policy module +- Dontaudit tmpreaper_t getting attributes from sysctl_type files +- cockpit: Support https instance factory +- Allow systemd to create and bindmount dirs. +- Allow strongswan start using swanctl method BZ(1773381) + * Sun Nov 03 2019 Lukas Vrabec - 3.14.3-52 - Label /var/cache/nginx as httpd_cache_t - Allow abrt_upload_watch_t domain to send dgram msgs to kernel processes and stream connect to journald diff --git a/sources b/sources index 30e3852..5db0098 100644 --- a/sources +++ b/sources @@ -1,4 +1,4 @@ -SHA512 (selinux-policy-contrib-c198f5d.tar.gz) = 07736040c1c5af9cc6fe5b03918e522210ee5a727b04f87a1eb7073bfc202a1a041b14d488c47dcb995097a6eb289eaab9456875435ab79989aa46a01e66658a -SHA512 (selinux-policy-4ab5862.tar.gz) = c8786482b7580b44b35058698e5927237ed6303ce174246df08108e1a207b34b868ae18879a789f8547620b7cd297b8dbeaff7db1d24a7d0d76f1bbfc09ee245 -SHA512 (container-selinux.tgz) = 3041c86c47c99f700e5d4264109187d492f9c79c9b3d9ab9dae7e294443bfcd40c799f7c216c912ff6783876f16c819ba71b1ae1af98d7e05693ea6b650de3bc +SHA512 (selinux-policy-536f614.tar.gz) = da4c84b00ad66b1a474f3a7b6d069cedefdc4ab37a33d57f0f741f2a22e70f8ca8480e1d219be17eac53a9ad04922e45dea379a079c6014398884c0ad6a270ad +SHA512 (selinux-policy-contrib-1eaee03.tar.gz) = c2b1089546f8b809b9aeadaff5d02b61c8cfa9fba54d1580163448a376c7b477787a5afc7364cdebb36baac06d228ccc19e6bd60c0523c5b1ca56b3f2fdf07a8 +SHA512 (container-selinux.tgz) = d3290eb68150463f66fd395c4021dfb4b6cf22e8d24390feb5447a9870cb6b2d62605fcd5895c5e6594925338bde4d46e284d1abfffa91718409021451900740 SHA512 (macro-expander) = 243ee49f1185b78ac47e56ca9a3f3592f8975fab1a2401c0fcc7f88217be614fe31805bacec602b728e7fcfc21dcc17d90e9a54ce87f3a0c97624d9ad885aea4