-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2018-352f18aa25 2018-06-28 13:33:04.633445 --------------------------------------------------------------------------------
Name : container-selinux Product : Fedora 27 Version : 2.65 Release : 1.gitbf5b26b.fc27 URL : https://github.com/projectatomic/container-selinux Summary : SELinux policies for container runtimes Description : SELinux policy modules for use with container runtimes. -------------------------------------------------------------------------------- Update Information: Several bug fixes. -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 11 2018 Dan Walsh <[email protected]> - 2.65-1 - Add new type to handle containers running with a non priv user in a userns - allow containers to map all sockets * Sun Jun 3 2018 Dan Walsh <[email protected]> - 2.64-1 - Allow containers to create all socket classes * Wed May 30 2018 Dan Walsh <[email protected]> - 2.63-1 - Allow containers to create icmp packets * Fri May 25 2018 Lokesh Mandvekar (Bot) <[email protected]> - 2:2.62-1.git1ecf953 - bump to 2.62 - autobuilt 1ecf953 * Mon May 21 2018 Dan Walsh <[email protected]> - 2.61-1 - Allow spc_t to load kernel modules from inside of container * Mon May 21 2018 Dan Walsh <[email protected]> - 2.60-1 - Allow containers to list cgroup directories * Mon May 21 2018 Dan Walsh <[email protected]> - 2.59-1 - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t. * Mon May 21 2018 Dan Walsh <[email protected]> - 2.58-2 - Run restorecon /usr/bin/podman in postinstall * Fri May 18 2018 Dan Walsh <[email protected]> - 2.58-1 - Add labels to allow podman to be run from a systemd unit file * Tue Apr 17 2018 Lokesh Mandvekar (Bot) <[email protected]> - 2:2.55-12.gitd248f91 - autobuilt commit d248f91 * Tue Apr 17 2018 Lokesh Mandvekar (Bot) <[email protected]> - 2:2.55-11.gitd248f91 - autobuilt commit d248f91 * Mon Apr 16 2018 Lokesh Mandvekar (Bot) <[email protected]> - 2:2.55-10.gitd248f91 - autobuilt commit d248f91 * Mon Apr 16 2018 Lokesh Mandvekar (Bot) <[email protected]> - 2:2.55-9.gitd248f91 - autobuilt commit d248f91 * Mon Apr 16 2018 Lokesh Mandvekar (Bot) <[email protected]> - 2:2.55-8 - autobuilt commit d248f91 * Mon Apr 16 2018 Lokesh Mandvekar (Bot) <[email protected]> - 2:2.55-7 - autobuilt commit d248f91 * Mon Apr 16 2018 Lokesh Mandvekar (Bot) <[email protected]> - 2:2.55-6 - autobuilt commit d248f91 * Mon Apr 9 2018 Lokesh Mandvekar (Bot) <[email protected]> - 2:2.55-5 - autobuilt commit d248f91 * Mon Apr 9 2018 Lokesh Mandvekar (Bot) <[email protected]> - 2:2.55-4 - autobuilt commit d248f91 * Mon Apr 9 2018 Lokesh Mandvekar <[email protected]> - 2:2.55-3 - autobuilt commit d248f91 * Mon Apr 9 2018 Lokesh Mandvekar <[email protected]> - 2:2.55-2 - autobuilt commit d248f91 * Thu Mar 15 2018 Dan Walsh <[email protected]> - 2.55-1 - Dontaudit attempts by containers to write to /proc/self * Wed Mar 14 2018 Dan Walsh <[email protected]> - 2.54-1 - Add rules for container domains to make writing custom policy easier - Allow shell_exec_t as a container_runtime_t entrypoint * Thu Mar 8 2018 Dan Walsh <[email protected]> - 2.52-1 - Add rules for container domains to make writing custom policy easier * Thu Mar 8 2018 Dan Walsh <[email protected]> - 2.51-1 - Allow shell_exec_t as a container_runtime_t entrypoint * Wed Mar 7 2018 Dan Walsh <[email protected]> - 2.50-1 - Allow bin_t as a container_runtime_t entrypoint - Add rules for running container runtimes on mls * Thu Feb 15 2018 Dan Walsh <[email protected]> - 2.48-1 - Allow container domains to map container_file_t directories * Sat Feb 10 2018 Dan Walsh <[email protected]> - 2.47-1 - Change default label of /exports to container_var_lib_t * Fri Feb 9 2018 Igor Gnatenko <[email protected]> - 2:2.46-3 - Escape macros in %CHANGELOG * Wed Feb 7 2018 Fedora Release Engineering <[email protected]> - 2:2.46-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Sat Feb 3 2018 Dan Walsh <[email protected]> - 2.46-1 - Add support for nosuid_transition flags for container_runtime and unconfined domains * Fri Feb 2 2018 Dan Walsh <[email protected]> - 2.45-1 - Allow containers to sendto their own stream sockets * Mon Jan 29 2018 Dan Walsh <[email protected]> - 2.44-1 - Allow container domains to read kernel ipc info * Mon Jan 22 2018 Dan Walsh <[email protected]> - 2.43-1 - Allow containers to memory map the fifo_files leaked into container from container runtimes. * Tue Jan 16 2018 Dan Walsh <[email protected]> - 2.42-1 - Allow unconfined domains to transition to container types, when no-new-privs is set. * Tue Jan 9 2018 Dan Walsh <[email protected]> - 2.41-1 - Add support to nnp_transition for container domains - Eliminates need for typebounds. * Tue Jan 9 2018 Dan Walsh <[email protected]> - 2.40-1 - Allow container_runtime_t to use user ttys - Fixes bounds check for container_t * Mon Jan 8 2018 Dan Walsh <[email protected]> - 2.39-1 - Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t. * Sat Jan 6 2018 Dan Walsh <[email protected]> - 2.38-1 - Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin * Tue Dec 12 2017 Dan Walsh <[email protected]> - 2.37-1 - Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree * Mon Nov 27 2017 Dan Walsh <[email protected]> - 2.36-1 - Allow containers to relabelto/from all file types to container_file_t * Mon Nov 27 2017 Dan Walsh <[email protected]> - 2.35-1 - Allow container to map chr_files labeled container_file_t * Wed Nov 22 2017 Dan Walsh <[email protected]> - 2.34-1 - Dontaudit container processes getattr on kernel file systems * Sun Nov 19 2017 Dan Walsh <[email protected]> - 2.33-1 - Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container. * Wed Nov 8 2017 Dan Walsh <[email protected]> - 2.32-1 - Make sure users creating content in /var/lib with right labels * Thu Oct 26 2017 Dan Walsh <[email protected]> - 2.31-1 - Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc * Tue Oct 10 2017 Dan Walsh <[email protected]> - 2.29-1 - Add support for lxcd - Add support for labeling of tmpfs storage created within a container. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1589555 - SELinux is preventing nmap from 'map' accesses on the packet_socket packet_socket. https://bugzilla.redhat.com/show_bug.cgi?id=1589555 [ 2 ] Bug #1591988 - container-selinux-v2.65.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1591988 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-352f18aa25' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected]/message/AIR6OVW5WEBVXO76PKJAYDCJAVDIPXHL/
