Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package selinux-policy for openSUSE:Factory 
checked in at 2026-08-05 17:46:27
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/selinux-policy (Old)
 and      /work/SRC/openSUSE:Factory/.selinux-policy.new.16738 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "selinux-policy"

Wed Aug  5 17:46:27 2026 rev:170 rq:1369476 version:20260804

Changes:
--------
--- /work/SRC/openSUSE:Factory/selinux-policy/selinux-policy.changes    
2026-07-29 18:58:43.584563348 +0200
+++ /work/SRC/openSUSE:Factory/.selinux-policy.new.16738/selinux-policy.changes 
2026-08-05 17:46:53.098645479 +0200
@@ -1,0 +2,31 @@
+Tue Aug 04 09:41:45 UTC 2026 - Robert Frohl <[email protected]>
+
+- Update to version 20260804:
+  * Use NetworkManager_t instead of networkmanager_t
+  * Changes adapting to bind packages with suffixes
+  * Dontaudit unconfined_t map its private directories
+  * Support cronie create crontab backups
+  * Allow nfsidmapd read virt lib files
+  * Allow sysadm_t run and read/write networkmanager bpf programs
+  * Allow dhcpc_hook_t connect to init_t over a unix stream socket
+  * Allow unconfined_t mounton its lnk_files
+  * Allow wireguard read cgroup files
+  * Label /usr/local/share/man with man_t
+  * Allow pcscd get attributes of a pty filesystem
+  * Allow geoclue read cgroup files
+  * Allow init_t nnp domain transition to postgresql_t
+  * Move bootupd systemd interface to 2 optional blocks
+  * Allow net_admin to the nfsd_t domain
+  * Allow kernel write to unconfined and sysadm users' keys
+  * Allow staff user ioctl cockpit-session stream sockets
+  * Allow the staff user mount on tmpfs directories
+  * Allow staff user the dac_override capability in the user namespace
+  * Allow aide get attributes of all filesystems
+  * Make insights_client_t accessible from the system cronjob
+  * Support systemtap on a UEFI+SecureBoot system
+  * Allow systemd-coredump signull spc container
+  * Allow dhcpcd hook scripts read generic files in /proc
+- Syncing with upstream rawhide selinux-policy up to:
+  * 5c9bff8fbdaeb41b724b68937c706dc5e42a490a
+
+-------------------------------------------------------------------

Old:
----
  selinux-policy-20260727.tar.xz

New:
----
  selinux-policy-20260804.tar.xz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ selinux-policy.spec ++++++
--- /var/tmp/diff_new_pack.0hSxrj/_old  2026-08-05 17:46:53.866672379 +0200
+++ /var/tmp/diff_new_pack.0hSxrj/_new  2026-08-05 17:46:53.866672379 +0200
@@ -37,7 +37,7 @@
 License:        GPL-2.0-or-later
 Group:          System/Management
 Name:           selinux-policy
-Version:        20260727
+Version:        20260804
 Release:        0
 Source0:        %{name}-%{version}.tar.xz
 Source1:        container.fc

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.0hSxrj/_old  2026-08-05 17:46:53.950675321 +0200
+++ /var/tmp/diff_new_pack.0hSxrj/_new  2026-08-05 17:46:53.954675461 +0200
@@ -1,6 +1,6 @@
 <servicedata>
 <service name="tar_scm">
                 <param 
name="url">https://gitlab.suse.de/selinux/selinux-policy.git</param>
-              <param 
name="changesrevision">0befca7b7a306691c4ee32243fd640e29ea6dd4b</param></service></servicedata>
+              <param 
name="changesrevision">2e4ad0986b296e4f0a33675f8b5f78e12f49bf26</param></service></servicedata>
 (No newline at EOF)
 


++++++ selinux-policy-20260727.tar.xz -> selinux-policy-20260804.tar.xz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/aide.te 
new/selinux-policy-20260804/policy/modules/contrib/aide.te
--- old/selinux-policy-20260727/policy/modules/contrib/aide.te  2026-07-27 
10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/aide.te  2026-08-04 
11:39:55.000000000 +0200
@@ -47,8 +47,7 @@
 files_getattr_all_pipes(aide_t)
 files_getattr_all_sockets(aide_t)
 
-fs_getattr_tmpfs(aide_t)
-fs_getattr_xattr_fs(aide_t)
+fs_getattr_all_fs(aide_t)
 
 init_stream_connectto(aide_t)
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/bind.fc 
new/selinux-policy-20260804/policy/modules/contrib/bind.fc
--- old/selinux-policy-20260727/policy/modules/contrib/bind.fc  2026-07-27 
10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/bind.fc  2026-08-04 
11:39:55.000000000 +0200
@@ -12,16 +12,16 @@
 /usr/lib/systemd/system/named.*        --      
gen_context(system_u:object_r:named_unit_file_t,s0)
 /usr/lib/systemd/system/named-sdb.* -- 
gen_context(system_u:object_r:named_unit_file_t,s0)
 
-/usr/bin/lwresd        --      gen_context(system_u:object_r:named_exec_t,s0)
-/usr/bin/named         --      gen_context(system_u:object_r:named_exec_t,s0)
-/usr/bin/named-sdb     --      gen_context(system_u:object_r:named_exec_t,s0)
-/usr/bin/named-pkcs11  --      gen_context(system_u:object_r:named_exec_t,s0)
-/usr/bin/named-checkconf --    
gen_context(system_u:object_r:named_checkconf_exec_t,s0)
-/usr/bin/r?ndc         --      gen_context(system_u:object_r:ndc_exec_t,s0)
 /usr/bin/unbound       --      gen_context(system_u:object_r:named_exec_t,s0)
 /usr/bin/unbound-anchor --     gen_context(system_u:object_r:named_exec_t,s0)
 /usr/bin/unbound-checkconf --  gen_context(system_u:object_r:named_exec_t,s0)
 /usr/bin/unbound-control   --  gen_context(system_u:object_r:named_exec_t,s0)
+/usr/bin/lwresd(-9\.[^/]+)?    --      
gen_context(system_u:object_r:named_exec_t,s0)
+/usr/bin/named(-9\.[^/]+)?     --      
gen_context(system_u:object_r:named_exec_t,s0)
+/usr/bin/named-sdb(-9\.[^/]+)? --      
gen_context(system_u:object_r:named_exec_t,s0)
+/usr/bin/named-pkcs11(-9\.[^/]+)? --   
gen_context(system_u:object_r:named_exec_t,s0)
+/usr/bin/named-checkconf(-9\.[^/]+)? --        
gen_context(system_u:object_r:named_checkconf_exec_t,s0)
+/usr/bin/r?ndc(-9\.[^/]+)?     --      
gen_context(system_u:object_r:ndc_exec_t,s0)
 
 /var/log/named.*       --      gen_context(system_u:object_r:named_log_t,s0)
 
@@ -51,16 +51,19 @@
 /etc/named(/.*)?               gen_context(system_u:object_r:named_conf_t,s0)
 /etc/named\.rfc1912.zones --   gen_context(system_u:object_r:named_conf_t,s0)
 /etc/named\.root\.hints        --      
gen_context(system_u:object_r:named_conf_t,s0)
+/etc/named\.root\.key  --      gen_context(system_u:object_r:named_conf_t,s0)
+/etc/named\.ca         --      gen_context(system_u:object_r:named_conf_t,s0)
 /etc/named\.conf       --      gen_context(system_u:object_r:named_conf_t,s0)
 /etc/named\.caching-nameserver\.conf -- 
gen_context(system_u:object_r:named_conf_t,s0)
 /var/lib/softhsm(/.*)?                 
gen_context(system_u:object_r:named_cache_t,s0)
 /var/lib/unbound(/.*)?                 
gen_context(system_u:object_r:named_cache_t,s0)
-/var/lib/named(/.*)?           gen_context(system_u:object_r:named_zone_t,s0)
+/var/lib/named(/.*)?           gen_context(system_u:object_r:named_cache_t,s0)
 /var/lib/named/slaves(/.*)?            
gen_context(system_u:object_r:named_cache_t,s0)
 /var/lib/named/data(/.*)?              
gen_context(system_u:object_r:named_cache_t,s0)
 /var/lib/named/named\.ca       --      
gen_context(system_u:object_r:named_conf_t,s0)
 /var/lib/named/chroot(/.*)?            
gen_context(system_u:object_r:named_conf_t,s0)
 /var/lib/named/chroot/etc/rndc\.key -- 
gen_context(system_u:object_r:dnssec_t,s0)
+/var/lib/named/chroot/etc/named(/.*)? -- 
gen_context(system_u:object_r:named_conf_t,s0)
 /var/lib/named/chroot/etc/named\.conf -- 
gen_context(system_u:object_r:named_conf_t,s0)
 /var/lib/named/chroot/etc/named\.rfc1912.zones -- 
gen_context(system_u:object_r:named_conf_t,s0)
 /var/lib/named/chroot/etc/named\.root\.hints -- 
gen_context(system_u:object_r:named_conf_t,s0)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/bootupd.te 
new/selinux-policy-20260804/policy/modules/contrib/bootupd.te
--- old/selinux-policy-20260727/policy/modules/contrib/bootupd.te       
2026-07-27 10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/bootupd.te       
2026-08-04 11:39:55.000000000 +0200
@@ -86,11 +86,14 @@
 ')
 
 optional_policy(`
-       systemd_homed_stream_connect(bootupd_t)
        systemd_userdbd_stream_connect(bootupd_t)
 ')
 
 optional_policy(`
+       systemd_homed_stream_connect(bootupd_t)
+')
+
+optional_policy(`
        udev_domtrans(bootupd_t)
        udev_read_pid_files(bootupd_t)
 ')
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/cockpit.if 
new/selinux-policy-20260804/policy/modules/contrib/cockpit.if
--- old/selinux-policy-20260727/policy/modules/contrib/cockpit.if       
2026-07-27 10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/cockpit.if       
2026-08-04 11:39:55.000000000 +0200
@@ -84,6 +84,26 @@
 
 ########################################
 ## <summary>
+##     Ioctl cockpit_session_t unix stream sockets.
+## </summary>
+## <param name="domain">
+##     <summary>
+##     Domain allowed access.
+##     </summary>
+## </param>
+#
+ifndef(`cockpit_session_ioctl_stream_sockets',`
+       interface(`cockpit_session_ioctl_stream_sockets',`
+               gen_require(`
+                       type cockpit_session_t;
+               ')
+
+               allow $1 cockpit_session_t:unix_stream_socket { getattr ioctl };
+       ')
+')
+
+########################################
+## <summary>
 ##     Create cockpit unix_stream_sockets.
 ## </summary>
 ## <param name="domain">
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/cron.te 
new/selinux-policy-20260804/policy/modules/contrib/cron.te
--- old/selinux-policy-20260727/policy/modules/contrib/cron.te  2026-07-27 
10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/cron.te  2026-08-04 
11:39:55.000000000 +0200
@@ -174,6 +174,13 @@
        allow admin_crontab_t self:process setfscreate;
 ')
 
+optional_policy(`
+       # cronie 1.7+ saves crontab backups to ~/.cache/crontab/
+       gnome_create_generic_admin_cache_dir(admin_crontab_t)
+       gnome_manage_cache_home_dir(admin_crontab_t)
+       gnome_manage_generic_cache_files(admin_crontab_t)
+')
+
 ########################################
 #
 # Cron daemon local policy
@@ -885,6 +892,13 @@
 ')
 
 optional_policy(`
+       # cronie 1.7+ saves crontab backups to ~/.cache/crontab/
+       gnome_create_generic_cache_dir(crontab_t)
+       gnome_manage_cache_home_dir(crontab_t)
+       gnome_manage_generic_cache_files(crontab_t)
+')
+
+optional_policy(`
        ssh_dontaudit_use_ptys(crontab_domain)
 ')
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/geoclue.te 
new/selinux-policy-20260804/policy/modules/contrib/geoclue.te
--- old/selinux-policy-20260727/policy/modules/contrib/geoclue.te       
2026-07-27 10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/geoclue.te       
2026-08-04 11:39:55.000000000 +0200
@@ -54,6 +54,7 @@
 fs_getattr_cgroup(geoclue_t)
 fs_getattr_tmpfs(geoclue_t)
 fs_getattr_xattr_fs(geoclue_t)
+fs_read_cgroup_files(geoclue_t)
 
 init_dbus_chat(geoclue_t)
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/gnome.if 
new/selinux-policy-20260804/policy/modules/contrib/gnome.if
--- old/selinux-policy-20260727/policy/modules/contrib/gnome.if 2026-07-27 
10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/gnome.if 2026-08-04 
11:39:55.000000000 +0200
@@ -489,6 +489,25 @@
 
 ########################################
 ## <summary>
+##     Create generic admin cache dir (.cache)
+## </summary>
+## <param name="domain">
+##     <summary>
+##     Domain allowed access.
+##     </summary>
+## </param>
+#
+interface(`gnome_create_generic_admin_cache_dir',`
+       gen_require(`
+               type cache_home_t;
+       ')
+
+       allow $1 cache_home_t:dir create_dir_perms;
+       userdom_admin_home_dir_filetrans($1, cache_home_t, dir, ".cache")
+')
+
+########################################
+## <summary>
 ##     Set attributes of cache home dir (.cache)
 ## </summary>
 ## <param name="domain">
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/insights_client.te 
new/selinux-policy-20260804/policy/modules/contrib/insights_client.te
--- old/selinux-policy-20260727/policy/modules/contrib/insights_client.te       
2026-07-27 10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/insights_client.te       
2026-08-04 11:39:55.000000000 +0200
@@ -234,11 +234,12 @@
 #      container_runtime_domtrans(insights_client_t)
 #')
 #
-#optional_policy(`
+
+optional_policy(`
 #      cron_signull_system_job(insights_client_t)
-#      cron_system_entry(insights_client_t, insights_client_exec_t)
-#')
-#
+       cron_system_entry(insights_client_t, insights_client_exec_t)
+')
+
 #optional_policy(`
 #      dbus_system_bus_client(insights_client_t)
 #')
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/networkmanager.if 
new/selinux-policy-20260804/policy/modules/contrib/networkmanager.if
--- old/selinux-policy-20260727/policy/modules/contrib/networkmanager.if        
2026-07-27 10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/networkmanager.if        
2026-08-04 11:39:55.000000000 +0200
@@ -659,6 +659,42 @@
 
 ########################################
 ## <summary>
+##     Run networkmanager BPF programs.
+## </summary>
+## <param name="domain">
+## <summary>
+##     Domain allowed access.
+## </summary>
+## </param>
+#
+interface(`networkmanager_run_bpf',`
+       gen_require(`
+               type NetworkManager_t;
+       ')
+
+       allow $1 NetworkManager_t:bpf prog_run;
+')
+
+########################################
+## <summary>
+##     Read and write networkmanager BPF programs.
+## </summary>
+## <param name="domain">
+## <summary>
+##     Domain allowed access.
+## </summary>
+## </param>
+#
+interface(`networkmanager_rw_bpf',`
+       gen_require(`
+               type NetworkManager_t;
+       ')
+
+       allow $1 NetworkManager_t:bpf { map_read map_write };
+')
+
+########################################
+## <summary>
 ##     Transition to networkmanager named content
 ## </summary>
 ## <param name="domain">
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/pcscd.te 
new/selinux-policy-20260804/policy/modules/contrib/pcscd.te
--- old/selinux-policy-20260727/policy/modules/contrib/pcscd.te 2026-07-27 
10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/pcscd.te 2026-08-04 
11:39:55.000000000 +0200
@@ -64,6 +64,7 @@
 fs_getattr_pidfs(pcscd_t)
 fs_search_cgroup_dirs(pcscd_t)
 
+term_getattr_pty_fs(pcscd_t)
 term_use_unallocated_ttys(pcscd_t)
 term_dontaudit_getattr_pty_dirs(pcscd_t)
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/rpc.te 
new/selinux-policy-20260804/policy/modules/contrib/rpc.te
--- old/selinux-policy-20260727/policy/modules/contrib/rpc.te   2026-07-27 
10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/rpc.te   2026-08-04 
11:39:55.000000000 +0200
@@ -237,7 +237,7 @@
 # NFSD local policy
 #
 
-allow nfsd_t self:capability { dac_read_search dac_override setgid setuid 
sys_admin sys_chroot sys_rawio sys_resource };
+allow nfsd_t self:capability { dac_read_search dac_override net_admin setgid 
setuid sys_admin sys_chroot sys_rawio sys_resource };
 
 allow nfsd_t self:process { setcap };
 
@@ -482,7 +482,7 @@
 ')
 
 optional_policy(`
-       virt_search_lib(nfsidmap_t)
+       virt_read_lib_files(nfsidmap_t)
 ')
 
 optional_policy(`
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/stapserver.te 
new/selinux-policy-20260804/policy/modules/contrib/stapserver.te
--- old/selinux-policy-20260727/policy/modules/contrib/stapserver.te    
2026-07-27 10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/stapserver.te    
2026-08-04 11:39:55.000000000 +0200
@@ -66,9 +66,9 @@
 
 kernel_read_system_state(stapserver_t)
 kernel_read_kernel_sysctls(stapserver_t)
+kernel_read_network_state(stapserver_t)
 kernel_read_vm_sysctls(stapserver_t)
 kernel_read_fs_sysctls(stapserver_t)
-files_list_kernel_modules(stapserver_t)
 
 corecmd_exec_bin(stapserver_t)
 corecmd_exec_shell(stapserver_t)
@@ -81,7 +81,9 @@
 dev_read_urand(stapserver_t)
 
 files_list_tmp(stapserver_t)
+files_getattr_kernel_modules(stapserver_t)
 files_search_kernel_modules(stapserver_t)
+files_list_kernel_modules(stapserver_t)
 
 fs_search_cgroup_dirs(stapserver_t)
 fs_getattr_all_fs(stapserver_t)
@@ -117,6 +119,10 @@
 ')
 
 optional_policy(`
+       modutils_getattr_module_deps(stapserver_t)
+')
+
+optional_policy(`
        plymouthd_exec_plymouth(stapserver_t)
 ')
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/contrib/wireguard.te 
new/selinux-policy-20260804/policy/modules/contrib/wireguard.te
--- old/selinux-policy-20260727/policy/modules/contrib/wireguard.te     
2026-07-27 10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/contrib/wireguard.te     
2026-08-04 11:39:55.000000000 +0200
@@ -41,6 +41,8 @@
 
 files_read_etc_files(wireguard_t)
 
+fs_read_cgroup_files(wireguard_t)
+
 # openSUSE only >>
 ## DNS hatchet part
 allow wireguard_t self:capability sys_admin;
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/kernel/kernel.te 
new/selinux-policy-20260804/policy/modules/kernel/kernel.te
--- old/selinux-policy-20260727/policy/modules/kernel/kernel.te 2026-07-27 
10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/kernel/kernel.te 2026-08-04 
11:39:55.000000000 +0200
@@ -557,6 +557,10 @@
 ')
 
 optional_policy(`
+       sysadm_write_keys(kernel_t)
+')
+
+optional_policy(`
        systemd_coredump_domtrans(kernel_t)
 
        # Systemd symlinks /usr/bin/{poweroff,reboot} (which are invoked by
@@ -576,6 +580,10 @@
 ')
 
 optional_policy(`
+       unconfined_write_keys(kernel_t)
+')
+
+optional_policy(`
        virt_filetrans_home_content(kernel_t)
 ')
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/roles/staff.te 
new/selinux-policy-20260804/policy/modules/roles/staff.te
--- old/selinux-policy-20260727/policy/modules/roles/staff.te   2026-07-27 
10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/roles/staff.te   2026-08-04 
11:39:55.000000000 +0200
@@ -22,7 +22,7 @@
 # Local policy
 #
 
-allow staff_t self:cap_userns { setpcap };
+allow staff_t self:cap_userns { dac_override setpcap };
 allow staff_t self:io_uring sqpoll;
 allow staff_t self:netlink_generic_socket { create_socket_perms };
 allow staff_t self:netlink_route_socket nlmsg_write;
@@ -48,6 +48,7 @@
 fs_read_binfmt_misc(staff_t)
 fs_read_nsfs_files(staff_t)
 fs_mount_tmpfs(staff_t)
+fs_mounton_tmpfs(staff_t)
 fs_unmount_tmpfs(staff_t)
 fs_remount_all_fs(staff_t)
 fs_unmount_xattr_fs(staff_t)
@@ -140,6 +141,7 @@
 ')
 
 optional_policy(`
+       cockpit_session_ioctl_stream_sockets(staff_t)
        cockpit_session_rw_stream_sockets(staff_t)
 ')
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/roles/sysadm.if 
new/selinux-policy-20260804/policy/modules/roles/sysadm.if
--- old/selinux-policy-20260727/policy/modules/roles/sysadm.if  2026-07-27 
10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/roles/sysadm.if  2026-08-04 
11:39:55.000000000 +0200
@@ -271,3 +271,21 @@
 
        allow $1 sysadm_t:unix_dgram_socket sendto;
 ')
+
+########################################
+## <summary>
+##     Write keys for the sysadm user.
+## </summary>
+## <param name="domain">
+##     <summary>
+##     Domain allowed access.
+##     </summary>
+## </param>
+#
+interface(`sysadm_write_keys',`
+       gen_require(`
+               type sysadm_t;
+       ')
+
+       allow $1 sysadm_t:key write;
+')
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/roles/sysadm.te 
new/selinux-policy-20260804/policy/modules/roles/sysadm.te
--- old/selinux-policy-20260727/policy/modules/roles/sysadm.te  2026-07-27 
10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/roles/sysadm.te  2026-08-04 
11:39:55.000000000 +0200
@@ -459,6 +459,8 @@
 
 optional_policy(`
        networkmanager_filetrans_named_content(sysadm_t)
+       networkmanager_run_bpf(sysadm_t)
+       networkmanager_rw_bpf(sysadm_t)
        networkmanager_stream_connect(sysadm_t)
 ')
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/roles/unconfineduser.te 
new/selinux-policy-20260804/policy/modules/roles/unconfineduser.te
--- old/selinux-policy-20260727/policy/modules/roles/unconfineduser.te  
2026-07-27 10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/roles/unconfineduser.te  
2026-08-04 11:39:55.000000000 +0200
@@ -62,8 +62,8 @@
 # Local policy
 #
 
-allow unconfined_t self:{dir file} mounton;
-dontaudit unconfined_t self:dir write;
+allow unconfined_t self:{ dir file lnk_file } mounton;
+dontaudit unconfined_t self:dir { map write };
 dontaudit unconfined_t self:file setattr;
 
 allow unconfined_t self:system syslog_read;
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/services/postgresql.te 
new/selinux-policy-20260804/policy/modules/services/postgresql.te
--- old/selinux-policy-20260727/policy/modules/services/postgresql.te   
2026-07-27 10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/services/postgresql.te   
2026-08-04 11:39:55.000000000 +0200
@@ -49,6 +49,7 @@
 type postgresql_t;
 type postgresql_exec_t;
 init_daemon_domain(postgresql_t, postgresql_exec_t)
+init_nnp_daemon_domain(postgresql_t)
 
 type postgresql_db_t;
 files_type(postgresql_db_t)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/system/miscfiles.fc 
new/selinux-policy-20260804/policy/modules/system/miscfiles.fc
--- old/selinux-policy-20260727/policy/modules/system/miscfiles.fc      
2026-07-27 10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/system/miscfiles.fc      
2026-08-04 11:39:55.000000000 +0200
@@ -43,6 +43,8 @@
 
 /usr/lib/perl5/man(/.*)?       gen_context(system_u:object_r:man_t,s0)
 
+/usr/local/share/man(/.*)?                     
gen_context(system_u:object_r:man_t,s0)
+
 /usr/man(/.*)?                 gen_context(system_u:object_r:man_t,s0)
 
 /usr/share/ca-certificates(/.*)?       gen_context(system_u:object_r:cert_t,s0)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/system/sysnetwork.te 
new/selinux-policy-20260804/policy/modules/system/sysnetwork.te
--- old/selinux-policy-20260727/policy/modules/system/sysnetwork.te     
2026-07-27 10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/system/sysnetwork.te     
2026-08-04 11:39:55.000000000 +0200
@@ -323,6 +323,7 @@
 allow dhcpc_hook_t self:netlink_route_socket create_netlink_socket_perms;
 allow dhcpc_hook_t self:unix_dgram_socket { create ioctl };
 
+kernel_read_proc_files(dhcpc_hook_t)
 kernel_request_load_module(dhcpc_hook_t)
 
 manage_dirs_pattern(dhcpc_hook_t, dhcpc_var_run_t, dhcpc_var_run_t)
@@ -345,6 +346,7 @@
 
 optional_policy(`
        init_ioctl_stream_sockets(dhcpc_hook_t)
+       init_stream_connect(dhcpc_hook_t)
 ')
 
 optional_policy(`
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260727/policy/modules/system/systemd.te 
new/selinux-policy-20260804/policy/modules/system/systemd.te
--- old/selinux-policy-20260727/policy/modules/system/systemd.te        
2026-07-27 10:49:08.000000000 +0200
+++ new/selinux-policy-20260804/policy/modules/system/systemd.te        
2026-08-04 11:39:55.000000000 +0200
@@ -1419,6 +1419,7 @@
 optional_policy(`
        container_signull(systemd_coredump_t)
        container_runtime_signull(systemd_coredump_t)
+       container_spc_signull(systemd_coredump_t)
 ')
 
 optional_policy(`

Reply via email to