Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package selinux-policy for openSUSE:Factory
checked in at 2026-09-16 17:40:33
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/selinux-policy (Old)
and /work/SRC/openSUSE:Factory/.selinux-policy.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "selinux-policy"
Wed Sep 16 17:40:33 2026 rev:176 rq:1377997 version:20260914
Changes:
--------
--- /work/SRC/openSUSE:Factory/selinux-policy/selinux-policy.changes
2026-09-12 21:16:12.215604011 +0200
+++
/work/SRC/openSUSE:Factory/.selinux-policy.new.383539/selinux-policy.changes
2026-09-16 17:40:44.324028821 +0200
@@ -1,0 +2,96 @@
+Mon Sep 14 14:50:28 UTC 2026 - Robert Frohl <[email protected]>
+
+- Update to version 20260914:
+ * Label charon-nm as ipsec_exec_t (bsc#1278135)
+ * Fix corrupted formatting in files.if
+ * Allow nsswitch_domain connect to read xdm pid socket files
+ * nsresourced fixes for mkosi (bsc#1279902)
+ * Allow sshd-session connect to gnome remote desktop port
+ * Allow sshd-session to connect to all generic ports
+ * Allow sshd-session connect to port 443/tcp (http_port_t)
+ * Allow sshd-session connect to tcp/22 (ssh_port_t)
+ * Allow rsync to getattr pipes and sockes if rsync_export_all_ro is set
(bsc#1279051)
+ * Introduce files_getattr_non_auth_sockets
+ * Introduce files_getattr_non_auth_pipes interface
+ * Allow rsync to read var_t (bsc#1279565)
+ * Update udev_manage_pid_files() to include symlinks read
+ * Support vfs_snapper to work with samba_share_t (bsc#1265400)
+ * vfs_samba uses dbus to communicate with snapper (bsc#1265400)
+ * fix NetworkManager dnsmasq-forwarders.conf labeling (bsc#1260038)
+ * Allow cupsd_t to communicate with fprintd via dbus (bsc#1268366)
+ * Allow kmscon read cocpit's pid files
+ * fix vpnc_t setpgid permission for openconnect (bsc#1272934)
+ * Allow systemd-sysctl to create /run/sysctl.d
+ * Allow systemd to create /run/udev/control
+ * Allow systemd-coredumpd to create /run/systemd/coredumpd/kernel
+ * Allow bootupcl nnp transition to mount_t
+ * Networkmanager: Remove files_manage_etc_files for console_t
+ * Networkmanager: Allow NM to manage files under /run
+ * Allow login_userdomain read/write kmscon devpts chr_files
+ * Support console version of initial-setup
+ * ssh-session accesses gitolite ssh config files (bsc#1277259)
+ * Allow kmscon use netlink permissions (#3368)
+ * Fix NFS mount with xprtsec=tls / xprtsec=mtls (bsc#1275783)
+ * Allow ssh_agent_type manage ssh_home_t files and sock_files
+ * Allow sshd-session manage ssh_home_t socke files
+ * Allow sshd-session X11 forwarding
+ * Allow lsmd-plugin read udev pid files
+ * Allow virtstoraged domain transition on iscsiadm execution
+ * Revert "Allow virtqemud domain transition on iscsiadm execution"
+ * Allow rhsmcertd search gconf home data dirs
+ * Allow rhsmcertd read gconf home files
+ * Revert "Allow rhsmcertd read gconf home files"
+ * Allow postmap read aliases
+ * Allow lsmd-plugin use libStorageMgmt to provision storage
+ * Update dhcpc-hook policy
+ * Allow virtqemud domain transition on iscsiadm execution
+ * Allow virtqemud domain transition on udev execution
+ * Allow virtqemud relabelfrom its private fifo files
+ * Support gnome-remote-desktop's smartcard redirection support
+ * Allow qatlib manage hugetlbfs directories
+ * Allow sanlock the sys_admin capability
+ * Allow rhsmcertd read gconf home files
+ * Allow rhsmcertd read insights-client config files
+ * Allow insights-client read install_t process state
+ * Allow insights-client read the process state of the init scripts
+ * Allow namespace_init_t execute generic programs in bin directories
+ * Update the ssh_server_template() template
+ * Add rules for sshd vsock socket read/write
+ * Allow dhcpc hook query the chronyd service
+ * Allow insights-client read gconf home files
+ * Allow login_userdomain mount, remount, unmount all mount points
+ * Allow login_userdomain mount on all mount points
+ * Revert "Allow userdomain get attributes of files on an nsfs filesystem"
+ * Allow accountsd create and use its private tmpfs files
+ * Add the anaconda_read_state_install() interface
+ * Update qatlib policy
+ * Allow rhsmcertd read the file_contexts files
+ * rhsmcertd: allow bootc/ostree transient package persistence detection
+ * Allow virtproxyd connect to systemd-homed over a unix stream socket
+ * Allow system_mail_t read procmail home content
+ * Label malware-detection-config.yml with insights_client_etc_rw_t
+ * Add bcachefs as a SELinux capable filesystem
+ * Allow unconfined_service_t nnp_transition to container_runtime_t
+ * Add the files_write_system_conf_files() interface
+ * Allow haveged (entropyd_t) create and use its private tmpfs files
+ * Allow ctdbd manage access to Samba PID directories
+ * Allow rhsmcertd read selinux config and default file contexts
+ * Allow staff_t and user_t execute udev without a domain transition
+ * Allow mpd dbus chat with avahi
+ * Allow init_t nnp domain transition to mpd_t
+ * Update tuned-ppd policy
+ * Update policy for virsh_ssh_t to help with live migration
+ * Update sysadm policy for encrypted volumes usage
+ * Allow bootupd read all passwd sources
+ * Allow local login and sshd-session signull cockpit-session
+ * Allow sysadm_t read/write kvm devices
+ * Allow sysadm user run fail2ban-client
+ * Add 2 interfaces helping to handle cloud-what cache files
+ * Allow all domains to use inherited sshd-session pipes
+ * Dontaudit tlp_t dac_override (bsc#1272935)
+- Syncing with upstream rawhide selinux-policy up to:
+ * dc63e37474fac5e8f74560acfc1bfdb0f785ec24
+- Update embedded container-selinux version to commit:
+ * 4ac019955c8885496ffbd978520c905434d4273e (v2.251.0)
+
+-------------------------------------------------------------------
Old:
----
selinux-policy-20260910.tar.xz
New:
----
selinux-policy-20260914.tar.xz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ selinux-policy.spec ++++++
--- /var/tmp/diff_new_pack.HNUPni/_old 2026-09-16 17:40:46.148105038 +0200
+++ /var/tmp/diff_new_pack.HNUPni/_new 2026-09-16 17:40:46.151105163 +0200
@@ -37,7 +37,7 @@
License: GPL-2.0-or-later
Group: System/Management
Name: selinux-policy
-Version: 20260910
+Version: 20260914
Release: 0
Source0: %{name}-%{version}.tar.xz
Source1: container.fc
++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.HNUPni/_old 2026-09-16 17:40:46.275110345 +0200
+++ /var/tmp/diff_new_pack.HNUPni/_new 2026-09-16 17:40:46.282110637 +0200
@@ -1,6 +1,6 @@
<servicedata>
<service name="tar_scm">
<param
name="url">https://gitlab.suse.de/selinux/selinux-policy.git</param>
- <param
name="changesrevision">5899922f7ab64a630e62ba8b7bc241b7240762c4</param></service></servicedata>
+ <param
name="changesrevision">4bb055148d61ece058ec97af0b622094d226ac30</param></service></servicedata>
(No newline at EOF)
++++++ container.fc ++++++
--- /var/tmp/diff_new_pack.HNUPni/_old 2026-09-16 17:40:46.359113855 +0200
+++ /var/tmp/diff_new_pack.HNUPni/_new 2026-09-16 17:40:46.366114147 +0200
@@ -81,6 +81,9 @@
/var/lib/docker/init(/.*)?
gen_context(system_u:object_r:container_ro_file_t,s0)
/var/lib/docker/overlay(/.*)?
gen_context(system_u:object_r:container_ro_file_t,s0)
/var/lib/docker/overlay2(/.*)?
gen_context(system_u:object_r:container_ro_file_t,s0)
+# For Docker's embedded/supervised containerd instance.
+/var/lib/docker/containerd/daemon/[^/]*/snapshots(/.*)?
gen_context(system_u:object_r:container_file_t,s0)
+/var/lib/docker/containerd/daemon/[^/]*/sandboxes(/.*)?
gen_context(system_u:object_r:container_ro_file_t,s0)
/var/lib/containerd(/.*)?
gen_context(system_u:object_r:container_var_lib_t,s0)
# The "snapshots" directory of containerd and BuildKit must be writable, as it
is used as an upperdir as well as a lowerdir.
++++++ container.if ++++++
--- /var/tmp/diff_new_pack.HNUPni/_old 2026-09-16 17:40:46.395115359 +0200
+++ /var/tmp/diff_new_pack.HNUPni/_new 2026-09-16 17:40:46.402115651 +0200
@@ -1146,3 +1146,24 @@
allow $1 container_t:process signull;
')
+########################################
+## <summary>
+## Execute container_runtime in the container_runtime domain,
+## and allow the transition under NoNewPrivileges (NNP) or nosuid.
+## </summary>
+## <param name="domain">
+## <summary>
+## Domain allowed to transition.
+## </summary>
+## </param>
+#
+interface(`container_runtime_nnp_domtrans',`
+ gen_require(`
+ type container_runtime_t;
+ ')
+
+ container_runtime_domtrans($1)
+ allow $1 container_runtime_t:process2 { nnp_transition
nosuid_transition };
+')
+(No newline at EOF)
+
++++++ container.te ++++++
--- /var/tmp/diff_new_pack.HNUPni/_old 2026-09-16 17:40:46.453117782 +0200
+++ /var/tmp/diff_new_pack.HNUPni/_new 2026-09-16 17:40:46.458117991 +0200
@@ -1,4 +1,4 @@
-policy_module(container, 2.250.0)
+policy_module(container, 2.251.0)
gen_require(`
class passwd rootok;
@@ -830,6 +830,7 @@
admin_pattern(spc_t, kubernetes_file_t)
allow spc_t container_runtime_domain:fifo_file manage_fifo_file_perms;
+manage_dirs_pattern(spc_t, container_runtime_domain, container_runtime_domain)
allow spc_t { container_ro_file_t container_file_t }:system module_load;
allow container_runtime_domain spc_t:process { dyntransition setsched
signal_perms };
@@ -1691,6 +1692,17 @@
dontaudit systemd_logind_t iptables_var_run_t:dir read;
')
+# OpenSSH 9.8+ split sshd into sshd (listener) + sshd-session (post-auth).
+# Forwarding now runs as sshd_session_t instead of sshd_t.
+optional_policy(`
+ tunable_policy(`sshd_launch_containers',`
+ gen_require(`
+ type sshd_session_t;
+ ')
+ container_runtime_domtrans(sshd_session_t)
+ ')
+')
+
role container_user_r;
userdom_restricted_user_template(container_user)
userdom_manage_home_role(container_user_r, container_user_t)
++++++ selinux-policy-20260910.tar.xz -> selinux-policy-20260914.tar.xz ++++++
++++ 1633 lines of diff (skipped)