Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package selinux-policy for openSUSE:Factory checked in at 2026-08-05 17:46:27 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/selinux-policy (Old) and /work/SRC/openSUSE:Factory/.selinux-policy.new.16738 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "selinux-policy" Wed Aug 5 17:46:27 2026 rev:170 rq:1369476 version:20260804 Changes: -------- --- /work/SRC/openSUSE:Factory/selinux-policy/selinux-policy.changes 2026-07-29 18:58:43.584563348 +0200 +++ /work/SRC/openSUSE:Factory/.selinux-policy.new.16738/selinux-policy.changes 2026-08-05 17:46:53.098645479 +0200 @@ -1,0 +2,31 @@ +Tue Aug 04 09:41:45 UTC 2026 - Robert Frohl <[email protected]> + +- Update to version 20260804: + * Use NetworkManager_t instead of networkmanager_t + * Changes adapting to bind packages with suffixes + * Dontaudit unconfined_t map its private directories + * Support cronie create crontab backups + * Allow nfsidmapd read virt lib files + * Allow sysadm_t run and read/write networkmanager bpf programs + * Allow dhcpc_hook_t connect to init_t over a unix stream socket + * Allow unconfined_t mounton its lnk_files + * Allow wireguard read cgroup files + * Label /usr/local/share/man with man_t + * Allow pcscd get attributes of a pty filesystem + * Allow geoclue read cgroup files + * Allow init_t nnp domain transition to postgresql_t + * Move bootupd systemd interface to 2 optional blocks + * Allow net_admin to the nfsd_t domain + * Allow kernel write to unconfined and sysadm users' keys + * Allow staff user ioctl cockpit-session stream sockets + * Allow the staff user mount on tmpfs directories + * Allow staff user the dac_override capability in the user namespace + * Allow aide get attributes of all filesystems + * Make insights_client_t accessible from the system cronjob + * Support systemtap on a UEFI+SecureBoot system + * Allow systemd-coredump signull spc container + * Allow dhcpcd hook scripts read generic files in /proc +- Syncing with upstream rawhide selinux-policy up to: + * 5c9bff8fbdaeb41b724b68937c706dc5e42a490a + +------------------------------------------------------------------- Old: ---- selinux-policy-20260727.tar.xz New: ---- selinux-policy-20260804.tar.xz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ selinux-policy.spec ++++++ --- /var/tmp/diff_new_pack.0hSxrj/_old 2026-08-05 17:46:53.866672379 +0200 +++ /var/tmp/diff_new_pack.0hSxrj/_new 2026-08-05 17:46:53.866672379 +0200 @@ -37,7 +37,7 @@ License: GPL-2.0-or-later Group: System/Management Name: selinux-policy -Version: 20260727 +Version: 20260804 Release: 0 Source0: %{name}-%{version}.tar.xz Source1: container.fc ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.0hSxrj/_old 2026-08-05 17:46:53.950675321 +0200 +++ /var/tmp/diff_new_pack.0hSxrj/_new 2026-08-05 17:46:53.954675461 +0200 @@ -1,6 +1,6 @@ <servicedata> <service name="tar_scm"> <param name="url">https://gitlab.suse.de/selinux/selinux-policy.git</param> - <param name="changesrevision">0befca7b7a306691c4ee32243fd640e29ea6dd4b</param></service></servicedata> + <param name="changesrevision">2e4ad0986b296e4f0a33675f8b5f78e12f49bf26</param></service></servicedata> (No newline at EOF) ++++++ selinux-policy-20260727.tar.xz -> selinux-policy-20260804.tar.xz ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/aide.te new/selinux-policy-20260804/policy/modules/contrib/aide.te --- old/selinux-policy-20260727/policy/modules/contrib/aide.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/aide.te 2026-08-04 11:39:55.000000000 +0200 @@ -47,8 +47,7 @@ files_getattr_all_pipes(aide_t) files_getattr_all_sockets(aide_t) -fs_getattr_tmpfs(aide_t) -fs_getattr_xattr_fs(aide_t) +fs_getattr_all_fs(aide_t) init_stream_connectto(aide_t) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/bind.fc new/selinux-policy-20260804/policy/modules/contrib/bind.fc --- old/selinux-policy-20260727/policy/modules/contrib/bind.fc 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/bind.fc 2026-08-04 11:39:55.000000000 +0200 @@ -12,16 +12,16 @@ /usr/lib/systemd/system/named.* -- gen_context(system_u:object_r:named_unit_file_t,s0) /usr/lib/systemd/system/named-sdb.* -- gen_context(system_u:object_r:named_unit_file_t,s0) -/usr/bin/lwresd -- gen_context(system_u:object_r:named_exec_t,s0) -/usr/bin/named -- gen_context(system_u:object_r:named_exec_t,s0) -/usr/bin/named-sdb -- gen_context(system_u:object_r:named_exec_t,s0) -/usr/bin/named-pkcs11 -- gen_context(system_u:object_r:named_exec_t,s0) -/usr/bin/named-checkconf -- gen_context(system_u:object_r:named_checkconf_exec_t,s0) -/usr/bin/r?ndc -- gen_context(system_u:object_r:ndc_exec_t,s0) /usr/bin/unbound -- gen_context(system_u:object_r:named_exec_t,s0) /usr/bin/unbound-anchor -- gen_context(system_u:object_r:named_exec_t,s0) /usr/bin/unbound-checkconf -- gen_context(system_u:object_r:named_exec_t,s0) /usr/bin/unbound-control -- gen_context(system_u:object_r:named_exec_t,s0) +/usr/bin/lwresd(-9\.[^/]+)? -- gen_context(system_u:object_r:named_exec_t,s0) +/usr/bin/named(-9\.[^/]+)? -- gen_context(system_u:object_r:named_exec_t,s0) +/usr/bin/named-sdb(-9\.[^/]+)? -- gen_context(system_u:object_r:named_exec_t,s0) +/usr/bin/named-pkcs11(-9\.[^/]+)? -- gen_context(system_u:object_r:named_exec_t,s0) +/usr/bin/named-checkconf(-9\.[^/]+)? -- gen_context(system_u:object_r:named_checkconf_exec_t,s0) +/usr/bin/r?ndc(-9\.[^/]+)? -- gen_context(system_u:object_r:ndc_exec_t,s0) /var/log/named.* -- gen_context(system_u:object_r:named_log_t,s0) @@ -51,16 +51,19 @@ /etc/named(/.*)? gen_context(system_u:object_r:named_conf_t,s0) /etc/named\.rfc1912.zones -- gen_context(system_u:object_r:named_conf_t,s0) /etc/named\.root\.hints -- gen_context(system_u:object_r:named_conf_t,s0) +/etc/named\.root\.key -- gen_context(system_u:object_r:named_conf_t,s0) +/etc/named\.ca -- gen_context(system_u:object_r:named_conf_t,s0) /etc/named\.conf -- gen_context(system_u:object_r:named_conf_t,s0) /etc/named\.caching-nameserver\.conf -- gen_context(system_u:object_r:named_conf_t,s0) /var/lib/softhsm(/.*)? gen_context(system_u:object_r:named_cache_t,s0) /var/lib/unbound(/.*)? gen_context(system_u:object_r:named_cache_t,s0) -/var/lib/named(/.*)? gen_context(system_u:object_r:named_zone_t,s0) +/var/lib/named(/.*)? gen_context(system_u:object_r:named_cache_t,s0) /var/lib/named/slaves(/.*)? gen_context(system_u:object_r:named_cache_t,s0) /var/lib/named/data(/.*)? gen_context(system_u:object_r:named_cache_t,s0) /var/lib/named/named\.ca -- gen_context(system_u:object_r:named_conf_t,s0) /var/lib/named/chroot(/.*)? gen_context(system_u:object_r:named_conf_t,s0) /var/lib/named/chroot/etc/rndc\.key -- gen_context(system_u:object_r:dnssec_t,s0) +/var/lib/named/chroot/etc/named(/.*)? -- gen_context(system_u:object_r:named_conf_t,s0) /var/lib/named/chroot/etc/named\.conf -- gen_context(system_u:object_r:named_conf_t,s0) /var/lib/named/chroot/etc/named\.rfc1912.zones -- gen_context(system_u:object_r:named_conf_t,s0) /var/lib/named/chroot/etc/named\.root\.hints -- gen_context(system_u:object_r:named_conf_t,s0) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/bootupd.te new/selinux-policy-20260804/policy/modules/contrib/bootupd.te --- old/selinux-policy-20260727/policy/modules/contrib/bootupd.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/bootupd.te 2026-08-04 11:39:55.000000000 +0200 @@ -86,11 +86,14 @@ ') optional_policy(` - systemd_homed_stream_connect(bootupd_t) systemd_userdbd_stream_connect(bootupd_t) ') optional_policy(` + systemd_homed_stream_connect(bootupd_t) +') + +optional_policy(` udev_domtrans(bootupd_t) udev_read_pid_files(bootupd_t) ') diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/cockpit.if new/selinux-policy-20260804/policy/modules/contrib/cockpit.if --- old/selinux-policy-20260727/policy/modules/contrib/cockpit.if 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/cockpit.if 2026-08-04 11:39:55.000000000 +0200 @@ -84,6 +84,26 @@ ######################################## ## <summary> +## Ioctl cockpit_session_t unix stream sockets. +## </summary> +## <param name="domain"> +## <summary> +## Domain allowed access. +## </summary> +## </param> +# +ifndef(`cockpit_session_ioctl_stream_sockets',` + interface(`cockpit_session_ioctl_stream_sockets',` + gen_require(` + type cockpit_session_t; + ') + + allow $1 cockpit_session_t:unix_stream_socket { getattr ioctl }; + ') +') + +######################################## +## <summary> ## Create cockpit unix_stream_sockets. ## </summary> ## <param name="domain"> diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/cron.te new/selinux-policy-20260804/policy/modules/contrib/cron.te --- old/selinux-policy-20260727/policy/modules/contrib/cron.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/cron.te 2026-08-04 11:39:55.000000000 +0200 @@ -174,6 +174,13 @@ allow admin_crontab_t self:process setfscreate; ') +optional_policy(` + # cronie 1.7+ saves crontab backups to ~/.cache/crontab/ + gnome_create_generic_admin_cache_dir(admin_crontab_t) + gnome_manage_cache_home_dir(admin_crontab_t) + gnome_manage_generic_cache_files(admin_crontab_t) +') + ######################################## # # Cron daemon local policy @@ -885,6 +892,13 @@ ') optional_policy(` + # cronie 1.7+ saves crontab backups to ~/.cache/crontab/ + gnome_create_generic_cache_dir(crontab_t) + gnome_manage_cache_home_dir(crontab_t) + gnome_manage_generic_cache_files(crontab_t) +') + +optional_policy(` ssh_dontaudit_use_ptys(crontab_domain) ') diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/geoclue.te new/selinux-policy-20260804/policy/modules/contrib/geoclue.te --- old/selinux-policy-20260727/policy/modules/contrib/geoclue.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/geoclue.te 2026-08-04 11:39:55.000000000 +0200 @@ -54,6 +54,7 @@ fs_getattr_cgroup(geoclue_t) fs_getattr_tmpfs(geoclue_t) fs_getattr_xattr_fs(geoclue_t) +fs_read_cgroup_files(geoclue_t) init_dbus_chat(geoclue_t) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/gnome.if new/selinux-policy-20260804/policy/modules/contrib/gnome.if --- old/selinux-policy-20260727/policy/modules/contrib/gnome.if 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/gnome.if 2026-08-04 11:39:55.000000000 +0200 @@ -489,6 +489,25 @@ ######################################## ## <summary> +## Create generic admin cache dir (.cache) +## </summary> +## <param name="domain"> +## <summary> +## Domain allowed access. +## </summary> +## </param> +# +interface(`gnome_create_generic_admin_cache_dir',` + gen_require(` + type cache_home_t; + ') + + allow $1 cache_home_t:dir create_dir_perms; + userdom_admin_home_dir_filetrans($1, cache_home_t, dir, ".cache") +') + +######################################## +## <summary> ## Set attributes of cache home dir (.cache) ## </summary> ## <param name="domain"> diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/insights_client.te new/selinux-policy-20260804/policy/modules/contrib/insights_client.te --- old/selinux-policy-20260727/policy/modules/contrib/insights_client.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/insights_client.te 2026-08-04 11:39:55.000000000 +0200 @@ -234,11 +234,12 @@ # container_runtime_domtrans(insights_client_t) #') # -#optional_policy(` + +optional_policy(` # cron_signull_system_job(insights_client_t) -# cron_system_entry(insights_client_t, insights_client_exec_t) -#') -# + cron_system_entry(insights_client_t, insights_client_exec_t) +') + #optional_policy(` # dbus_system_bus_client(insights_client_t) #') diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/networkmanager.if new/selinux-policy-20260804/policy/modules/contrib/networkmanager.if --- old/selinux-policy-20260727/policy/modules/contrib/networkmanager.if 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/networkmanager.if 2026-08-04 11:39:55.000000000 +0200 @@ -659,6 +659,42 @@ ######################################## ## <summary> +## Run networkmanager BPF programs. +## </summary> +## <param name="domain"> +## <summary> +## Domain allowed access. +## </summary> +## </param> +# +interface(`networkmanager_run_bpf',` + gen_require(` + type NetworkManager_t; + ') + + allow $1 NetworkManager_t:bpf prog_run; +') + +######################################## +## <summary> +## Read and write networkmanager BPF programs. +## </summary> +## <param name="domain"> +## <summary> +## Domain allowed access. +## </summary> +## </param> +# +interface(`networkmanager_rw_bpf',` + gen_require(` + type NetworkManager_t; + ') + + allow $1 NetworkManager_t:bpf { map_read map_write }; +') + +######################################## +## <summary> ## Transition to networkmanager named content ## </summary> ## <param name="domain"> diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/pcscd.te new/selinux-policy-20260804/policy/modules/contrib/pcscd.te --- old/selinux-policy-20260727/policy/modules/contrib/pcscd.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/pcscd.te 2026-08-04 11:39:55.000000000 +0200 @@ -64,6 +64,7 @@ fs_getattr_pidfs(pcscd_t) fs_search_cgroup_dirs(pcscd_t) +term_getattr_pty_fs(pcscd_t) term_use_unallocated_ttys(pcscd_t) term_dontaudit_getattr_pty_dirs(pcscd_t) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/rpc.te new/selinux-policy-20260804/policy/modules/contrib/rpc.te --- old/selinux-policy-20260727/policy/modules/contrib/rpc.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/rpc.te 2026-08-04 11:39:55.000000000 +0200 @@ -237,7 +237,7 @@ # NFSD local policy # -allow nfsd_t self:capability { dac_read_search dac_override setgid setuid sys_admin sys_chroot sys_rawio sys_resource }; +allow nfsd_t self:capability { dac_read_search dac_override net_admin setgid setuid sys_admin sys_chroot sys_rawio sys_resource }; allow nfsd_t self:process { setcap }; @@ -482,7 +482,7 @@ ') optional_policy(` - virt_search_lib(nfsidmap_t) + virt_read_lib_files(nfsidmap_t) ') optional_policy(` diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/stapserver.te new/selinux-policy-20260804/policy/modules/contrib/stapserver.te --- old/selinux-policy-20260727/policy/modules/contrib/stapserver.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/stapserver.te 2026-08-04 11:39:55.000000000 +0200 @@ -66,9 +66,9 @@ kernel_read_system_state(stapserver_t) kernel_read_kernel_sysctls(stapserver_t) +kernel_read_network_state(stapserver_t) kernel_read_vm_sysctls(stapserver_t) kernel_read_fs_sysctls(stapserver_t) -files_list_kernel_modules(stapserver_t) corecmd_exec_bin(stapserver_t) corecmd_exec_shell(stapserver_t) @@ -81,7 +81,9 @@ dev_read_urand(stapserver_t) files_list_tmp(stapserver_t) +files_getattr_kernel_modules(stapserver_t) files_search_kernel_modules(stapserver_t) +files_list_kernel_modules(stapserver_t) fs_search_cgroup_dirs(stapserver_t) fs_getattr_all_fs(stapserver_t) @@ -117,6 +119,10 @@ ') optional_policy(` + modutils_getattr_module_deps(stapserver_t) +') + +optional_policy(` plymouthd_exec_plymouth(stapserver_t) ') diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/contrib/wireguard.te new/selinux-policy-20260804/policy/modules/contrib/wireguard.te --- old/selinux-policy-20260727/policy/modules/contrib/wireguard.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/contrib/wireguard.te 2026-08-04 11:39:55.000000000 +0200 @@ -41,6 +41,8 @@ files_read_etc_files(wireguard_t) +fs_read_cgroup_files(wireguard_t) + # openSUSE only >> ## DNS hatchet part allow wireguard_t self:capability sys_admin; diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/kernel/kernel.te new/selinux-policy-20260804/policy/modules/kernel/kernel.te --- old/selinux-policy-20260727/policy/modules/kernel/kernel.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/kernel/kernel.te 2026-08-04 11:39:55.000000000 +0200 @@ -557,6 +557,10 @@ ') optional_policy(` + sysadm_write_keys(kernel_t) +') + +optional_policy(` systemd_coredump_domtrans(kernel_t) # Systemd symlinks /usr/bin/{poweroff,reboot} (which are invoked by @@ -576,6 +580,10 @@ ') optional_policy(` + unconfined_write_keys(kernel_t) +') + +optional_policy(` virt_filetrans_home_content(kernel_t) ') diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/roles/staff.te new/selinux-policy-20260804/policy/modules/roles/staff.te --- old/selinux-policy-20260727/policy/modules/roles/staff.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/roles/staff.te 2026-08-04 11:39:55.000000000 +0200 @@ -22,7 +22,7 @@ # Local policy # -allow staff_t self:cap_userns { setpcap }; +allow staff_t self:cap_userns { dac_override setpcap }; allow staff_t self:io_uring sqpoll; allow staff_t self:netlink_generic_socket { create_socket_perms }; allow staff_t self:netlink_route_socket nlmsg_write; @@ -48,6 +48,7 @@ fs_read_binfmt_misc(staff_t) fs_read_nsfs_files(staff_t) fs_mount_tmpfs(staff_t) +fs_mounton_tmpfs(staff_t) fs_unmount_tmpfs(staff_t) fs_remount_all_fs(staff_t) fs_unmount_xattr_fs(staff_t) @@ -140,6 +141,7 @@ ') optional_policy(` + cockpit_session_ioctl_stream_sockets(staff_t) cockpit_session_rw_stream_sockets(staff_t) ') diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/roles/sysadm.if new/selinux-policy-20260804/policy/modules/roles/sysadm.if --- old/selinux-policy-20260727/policy/modules/roles/sysadm.if 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/roles/sysadm.if 2026-08-04 11:39:55.000000000 +0200 @@ -271,3 +271,21 @@ allow $1 sysadm_t:unix_dgram_socket sendto; ') + +######################################## +## <summary> +## Write keys for the sysadm user. +## </summary> +## <param name="domain"> +## <summary> +## Domain allowed access. +## </summary> +## </param> +# +interface(`sysadm_write_keys',` + gen_require(` + type sysadm_t; + ') + + allow $1 sysadm_t:key write; +') diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/roles/sysadm.te new/selinux-policy-20260804/policy/modules/roles/sysadm.te --- old/selinux-policy-20260727/policy/modules/roles/sysadm.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/roles/sysadm.te 2026-08-04 11:39:55.000000000 +0200 @@ -459,6 +459,8 @@ optional_policy(` networkmanager_filetrans_named_content(sysadm_t) + networkmanager_run_bpf(sysadm_t) + networkmanager_rw_bpf(sysadm_t) networkmanager_stream_connect(sysadm_t) ') diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/roles/unconfineduser.te new/selinux-policy-20260804/policy/modules/roles/unconfineduser.te --- old/selinux-policy-20260727/policy/modules/roles/unconfineduser.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/roles/unconfineduser.te 2026-08-04 11:39:55.000000000 +0200 @@ -62,8 +62,8 @@ # Local policy # -allow unconfined_t self:{dir file} mounton; -dontaudit unconfined_t self:dir write; +allow unconfined_t self:{ dir file lnk_file } mounton; +dontaudit unconfined_t self:dir { map write }; dontaudit unconfined_t self:file setattr; allow unconfined_t self:system syslog_read; diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/services/postgresql.te new/selinux-policy-20260804/policy/modules/services/postgresql.te --- old/selinux-policy-20260727/policy/modules/services/postgresql.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/services/postgresql.te 2026-08-04 11:39:55.000000000 +0200 @@ -49,6 +49,7 @@ type postgresql_t; type postgresql_exec_t; init_daemon_domain(postgresql_t, postgresql_exec_t) +init_nnp_daemon_domain(postgresql_t) type postgresql_db_t; files_type(postgresql_db_t) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/system/miscfiles.fc new/selinux-policy-20260804/policy/modules/system/miscfiles.fc --- old/selinux-policy-20260727/policy/modules/system/miscfiles.fc 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/system/miscfiles.fc 2026-08-04 11:39:55.000000000 +0200 @@ -43,6 +43,8 @@ /usr/lib/perl5/man(/.*)? gen_context(system_u:object_r:man_t,s0) +/usr/local/share/man(/.*)? gen_context(system_u:object_r:man_t,s0) + /usr/man(/.*)? gen_context(system_u:object_r:man_t,s0) /usr/share/ca-certificates(/.*)? gen_context(system_u:object_r:cert_t,s0) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/system/sysnetwork.te new/selinux-policy-20260804/policy/modules/system/sysnetwork.te --- old/selinux-policy-20260727/policy/modules/system/sysnetwork.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/system/sysnetwork.te 2026-08-04 11:39:55.000000000 +0200 @@ -323,6 +323,7 @@ allow dhcpc_hook_t self:netlink_route_socket create_netlink_socket_perms; allow dhcpc_hook_t self:unix_dgram_socket { create ioctl }; +kernel_read_proc_files(dhcpc_hook_t) kernel_request_load_module(dhcpc_hook_t) manage_dirs_pattern(dhcpc_hook_t, dhcpc_var_run_t, dhcpc_var_run_t) @@ -345,6 +346,7 @@ optional_policy(` init_ioctl_stream_sockets(dhcpc_hook_t) + init_stream_connect(dhcpc_hook_t) ') optional_policy(` diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/selinux-policy-20260727/policy/modules/system/systemd.te new/selinux-policy-20260804/policy/modules/system/systemd.te --- old/selinux-policy-20260727/policy/modules/system/systemd.te 2026-07-27 10:49:08.000000000 +0200 +++ new/selinux-policy-20260804/policy/modules/system/systemd.te 2026-08-04 11:39:55.000000000 +0200 @@ -1419,6 +1419,7 @@ optional_policy(` container_signull(systemd_coredump_t) container_runtime_signull(systemd_coredump_t) + container_spc_signull(systemd_coredump_t) ') optional_policy(`
