Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package selinux-policy for openSUSE:Factory
checked in at 2026-10-06 19:14:16
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/selinux-policy (Old)
and /work/SRC/openSUSE:Factory/.selinux-policy.new.3698736 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "selinux-policy"
Tue Oct 6 19:14:16 2026 rev:180 rq:1382712 version:20261006
Changes:
--------
--- /work/SRC/openSUSE:Factory/selinux-policy/selinux-policy.changes
2026-10-03 20:12:41.292479037 +0200
+++
/work/SRC/openSUSE:Factory/.selinux-policy.new.3698736/selinux-policy.changes
2026-10-06 19:14:47.897434330 +0200
@@ -1,0 +2,7 @@
+Tue Oct 06 07:54:00 UTC 2026 - Cathy Hu <[email protected]>
+
+- Update to version 20261006:
+ * Fix typo in screen.fc
+ * Allow cscreend to start screen as unconfined domain (bsc#1257101)
+
+-------------------------------------------------------------------
Old:
----
selinux-policy-20261002.tar.xz
New:
----
selinux-policy-20261006.tar.xz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ selinux-policy.spec ++++++
--- /var/tmp/diff_new_pack.VH9R6D/_old 2026-10-06 19:14:49.415498197 +0200
+++ /var/tmp/diff_new_pack.VH9R6D/_new 2026-10-06 19:14:49.418498323 +0200
@@ -37,7 +37,7 @@
License: GPL-2.0-or-later
Group: System/Management
Name: selinux-policy
-Version: 20261002
+Version: 20261006
Release: 0
Source0: %{name}-%{version}.tar.xz
Source1: container.fc
++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.VH9R6D/_old 2026-10-06 19:14:49.512502278 +0200
+++ /var/tmp/diff_new_pack.VH9R6D/_new 2026-10-06 19:14:49.516502447 +0200
@@ -1,6 +1,6 @@
<servicedata>
<service name="tar_scm">
<param
name="url">https://gitlab.suse.de/selinux/selinux-policy.git</param>
- <param
name="changesrevision">072d1ccb57f80c1ed78d02ae7c157114d1453f8c</param></service></servicedata>
+ <param
name="changesrevision">91399b935bb1cd2f50f68e2d1cd6e7e49f67b97d</param></service></servicedata>
(No newline at EOF)
++++++ selinux-policy-20261002.tar.xz -> selinux-policy-20261006.tar.xz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/selinux-policy-20261002/policy/modules/contrib/screen.fc
new/selinux-policy-20261006/policy/modules/contrib/screen.fc
--- old/selinux-policy-20261002/policy/modules/contrib/screen.fc
2026-10-02 14:52:18.000000000 +0200
+++ new/selinux-policy-20261006/policy/modules/contrib/screen.fc
2026-10-06 09:53:13.000000000 +0200
@@ -11,5 +11,5 @@
/usr/bin/tmux --
gen_context(system_u:object_r:screen_exec_t,s0)
/run/screen(/.*)?
gen_context(system_u:object_r:screen_var_run_t,s0)
-/run/uscreens(/.*)?'
gen_context(system_u:object_r:screen_var_run_t,s0)
+/run/uscreens(/.*)?
gen_context(system_u:object_r:screen_var_run_t,s0)
/run/tmux(/.*)?
gen_context(system_u:object_r:screen_var_run_t,s0)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/selinux-policy-20261002/policy/modules/contrib/screen.te
new/selinux-policy-20261006/policy/modules/contrib/screen.te
--- old/selinux-policy-20261002/policy/modules/contrib/screen.te
2026-10-02 14:52:18.000000000 +0200
+++ new/selinux-policy-20261006/policy/modules/contrib/screen.te
2026-10-06 09:53:13.000000000 +0200
@@ -18,6 +18,10 @@
type screen_exec_t;
application_executable_file(screen_exec_t)
+# screen started by systemd, e.g. cscreend.service
+type unconfined_screen_t;
+init_system_domain(unconfined_screen_t, screen_exec_t)
+
type screen_home_t;
typealias screen_home_t alias { user_screen_home_t staff_screen_home_t
sysadm_screen_home_t };
typealias screen_home_t alias { auditadm_screen_home_t secadm_screen_home_t };
@@ -108,3 +112,13 @@
tunable_policy(`screen_allow_session_sharing',`
allow screen_domain self:capability { fsetid setgid setuid };
')
+
+
+########################################
+#
+# unconfined_screen_t local policy
+#
+
+optional_policy(`
+ unconfined_domain(unconfined_screen_t)
+')