Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package selinux-policy for openSUSE:Factory 
checked in at 2026-09-16 17:40:33
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/selinux-policy (Old)
 and      /work/SRC/openSUSE:Factory/.selinux-policy.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "selinux-policy"

Wed Sep 16 17:40:33 2026 rev:176 rq:1377997 version:20260914

Changes:
--------
--- /work/SRC/openSUSE:Factory/selinux-policy/selinux-policy.changes    
2026-09-12 21:16:12.215604011 +0200
+++ 
/work/SRC/openSUSE:Factory/.selinux-policy.new.383539/selinux-policy.changes    
    2026-09-16 17:40:44.324028821 +0200
@@ -1,0 +2,96 @@
+Mon Sep 14 14:50:28 UTC 2026 - Robert Frohl <[email protected]>
+
+- Update to version 20260914:
+  * Label charon-nm as ipsec_exec_t (bsc#1278135)
+  * Fix corrupted formatting in files.if
+  * Allow nsswitch_domain connect to read xdm pid socket files
+  * nsresourced fixes for mkosi (bsc#1279902)
+  * Allow sshd-session connect to gnome remote desktop port
+  * Allow sshd-session to connect to all generic ports
+  * Allow sshd-session connect to port 443/tcp (http_port_t)
+  * Allow sshd-session connect to tcp/22 (ssh_port_t)
+  * Allow rsync to getattr pipes and sockes if rsync_export_all_ro is set 
(bsc#1279051)
+  * Introduce files_getattr_non_auth_sockets
+  * Introduce files_getattr_non_auth_pipes interface
+  * Allow rsync to read var_t (bsc#1279565)
+  * Update udev_manage_pid_files() to include symlinks read
+  * Support vfs_snapper to work with samba_share_t (bsc#1265400)
+  * vfs_samba uses dbus to communicate with snapper (bsc#1265400)
+  * fix NetworkManager dnsmasq-forwarders.conf labeling (bsc#1260038)
+  * Allow cupsd_t to communicate with fprintd via dbus (bsc#1268366)
+  * Allow kmscon read cocpit's pid files
+  * fix vpnc_t setpgid permission for openconnect (bsc#1272934)
+  * Allow systemd-sysctl to create /run/sysctl.d
+  * Allow systemd to create /run/udev/control
+  * Allow systemd-coredumpd to create /run/systemd/coredumpd/kernel
+  * Allow bootupcl nnp transition to mount_t
+  * Networkmanager: Remove files_manage_etc_files for console_t
+  * Networkmanager: Allow NM to manage files under /run
+  * Allow login_userdomain read/write kmscon devpts chr_files
+  * Support console version of initial-setup
+  * ssh-session accesses gitolite ssh config files (bsc#1277259)
+  * Allow kmscon use netlink permissions (#3368)
+  * Fix NFS mount with xprtsec=tls / xprtsec=mtls (bsc#1275783)
+  * Allow ssh_agent_type manage ssh_home_t files and sock_files
+  * Allow sshd-session manage ssh_home_t socke files
+  * Allow sshd-session X11 forwarding
+  * Allow lsmd-plugin read udev pid files
+  * Allow virtstoraged domain transition on iscsiadm execution
+  * Revert "Allow virtqemud domain transition on iscsiadm execution"
+  * Allow rhsmcertd search gconf home data dirs
+  * Allow rhsmcertd read gconf home files
+  * Revert "Allow rhsmcertd read gconf home files"
+  * Allow postmap read aliases
+  * Allow lsmd-plugin use libStorageMgmt to provision storage
+  * Update dhcpc-hook policy
+  * Allow virtqemud domain transition on iscsiadm execution
+  * Allow virtqemud domain transition on udev execution
+  * Allow virtqemud relabelfrom its private fifo files
+  * Support gnome-remote-desktop's smartcard redirection support
+  * Allow qatlib manage hugetlbfs directories
+  * Allow sanlock the sys_admin capability
+  * Allow rhsmcertd read gconf home files
+  * Allow rhsmcertd read insights-client config files
+  * Allow insights-client read install_t process state
+  * Allow insights-client read the process state of the init scripts
+  * Allow namespace_init_t execute generic programs in bin directories
+  * Update the ssh_server_template() template
+  * Add rules for sshd vsock socket read/write
+  * Allow dhcpc hook query the chronyd service
+  * Allow insights-client read gconf home files
+  * Allow login_userdomain mount, remount, unmount all mount points
+  * Allow login_userdomain mount on all mount points
+  * Revert "Allow userdomain get attributes of files on an nsfs filesystem"
+  * Allow accountsd create and use its private tmpfs files
+  * Add the anaconda_read_state_install() interface
+  * Update qatlib policy
+  * Allow rhsmcertd read the file_contexts files
+  * rhsmcertd: allow bootc/ostree transient package persistence detection
+  * Allow virtproxyd connect to systemd-homed over a unix stream socket
+  * Allow system_mail_t read procmail home content
+  * Label malware-detection-config.yml with insights_client_etc_rw_t
+  * Add bcachefs as a SELinux capable filesystem
+  * Allow unconfined_service_t nnp_transition to container_runtime_t
+  * Add the files_write_system_conf_files() interface
+  * Allow haveged (entropyd_t)  create and use its private tmpfs files
+  * Allow ctdbd manage access to Samba PID directories
+  * Allow rhsmcertd read selinux config and default file contexts
+  * Allow staff_t and user_t execute udev without a domain transition
+  * Allow mpd dbus chat with avahi
+  * Allow init_t nnp domain transition to mpd_t
+  * Update tuned-ppd policy
+  * Update policy for virsh_ssh_t to help with live migration
+  * Update sysadm policy for encrypted volumes usage
+  * Allow bootupd read all passwd sources
+  * Allow local login and sshd-session signull cockpit-session
+  * Allow sysadm_t read/write kvm devices
+  * Allow sysadm user run fail2ban-client
+  * Add 2 interfaces helping to handle cloud-what cache files
+  * Allow all domains to use inherited sshd-session pipes
+  * Dontaudit tlp_t dac_override (bsc#1272935)
+- Syncing with upstream rawhide selinux-policy up to:
+  * dc63e37474fac5e8f74560acfc1bfdb0f785ec24
+- Update embedded container-selinux version to commit:
+  * 4ac019955c8885496ffbd978520c905434d4273e (v2.251.0)
+
+-------------------------------------------------------------------

Old:
----
  selinux-policy-20260910.tar.xz

New:
----
  selinux-policy-20260914.tar.xz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ selinux-policy.spec ++++++
--- /var/tmp/diff_new_pack.HNUPni/_old  2026-09-16 17:40:46.148105038 +0200
+++ /var/tmp/diff_new_pack.HNUPni/_new  2026-09-16 17:40:46.151105163 +0200
@@ -37,7 +37,7 @@
 License:        GPL-2.0-or-later
 Group:          System/Management
 Name:           selinux-policy
-Version:        20260910
+Version:        20260914
 Release:        0
 Source0:        %{name}-%{version}.tar.xz
 Source1:        container.fc

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.HNUPni/_old  2026-09-16 17:40:46.275110345 +0200
+++ /var/tmp/diff_new_pack.HNUPni/_new  2026-09-16 17:40:46.282110637 +0200
@@ -1,6 +1,6 @@
 <servicedata>
 <service name="tar_scm">
                 <param 
name="url">https://gitlab.suse.de/selinux/selinux-policy.git</param>
-              <param 
name="changesrevision">5899922f7ab64a630e62ba8b7bc241b7240762c4</param></service></servicedata>
+              <param 
name="changesrevision">4bb055148d61ece058ec97af0b622094d226ac30</param></service></servicedata>
 (No newline at EOF)
 

++++++ container.fc ++++++
--- /var/tmp/diff_new_pack.HNUPni/_old  2026-09-16 17:40:46.359113855 +0200
+++ /var/tmp/diff_new_pack.HNUPni/_new  2026-09-16 17:40:46.366114147 +0200
@@ -81,6 +81,9 @@
 /var/lib/docker/init(/.*)?             
gen_context(system_u:object_r:container_ro_file_t,s0)
 /var/lib/docker/overlay(/.*)?  
gen_context(system_u:object_r:container_ro_file_t,s0)
 /var/lib/docker/overlay2(/.*)? 
gen_context(system_u:object_r:container_ro_file_t,s0)
+# For Docker's embedded/supervised containerd instance.
+/var/lib/docker/containerd/daemon/[^/]*/snapshots(/.*)?        
gen_context(system_u:object_r:container_file_t,s0)
+/var/lib/docker/containerd/daemon/[^/]*/sandboxes(/.*)?        
gen_context(system_u:object_r:container_ro_file_t,s0)
 
 /var/lib/containerd(/.*)?      
gen_context(system_u:object_r:container_var_lib_t,s0)
 # The "snapshots" directory of containerd and BuildKit must be writable, as it 
is used as an upperdir as well as a lowerdir.

++++++ container.if ++++++
--- /var/tmp/diff_new_pack.HNUPni/_old  2026-09-16 17:40:46.395115359 +0200
+++ /var/tmp/diff_new_pack.HNUPni/_new  2026-09-16 17:40:46.402115651 +0200
@@ -1146,3 +1146,24 @@
         allow $1 container_t:process signull;
 ')
 
+########################################
+## <summary>
+##     Execute container_runtime in the container_runtime domain, 
+##     and allow the transition under NoNewPrivileges (NNP) or nosuid.
+## </summary>
+## <param name="domain">
+##     <summary>
+##     Domain allowed to transition.
+##     </summary>
+## </param>
+#
+interface(`container_runtime_nnp_domtrans',`
+       gen_require(`
+               type container_runtime_t;
+       ')
+
+       container_runtime_domtrans($1)
+       allow $1 container_runtime_t:process2 { nnp_transition 
nosuid_transition };
+')
+(No newline at EOF)
+

++++++ container.te ++++++
--- /var/tmp/diff_new_pack.HNUPni/_old  2026-09-16 17:40:46.453117782 +0200
+++ /var/tmp/diff_new_pack.HNUPni/_new  2026-09-16 17:40:46.458117991 +0200
@@ -1,4 +1,4 @@
-policy_module(container, 2.250.0)
+policy_module(container, 2.251.0)
 
 gen_require(`
        class passwd rootok;
@@ -830,6 +830,7 @@
 admin_pattern(spc_t, kubernetes_file_t)
 
 allow spc_t container_runtime_domain:fifo_file manage_fifo_file_perms;
+manage_dirs_pattern(spc_t, container_runtime_domain, container_runtime_domain)
 allow spc_t { container_ro_file_t container_file_t }:system module_load;
 
 allow container_runtime_domain spc_t:process { dyntransition setsched 
signal_perms };
@@ -1691,6 +1692,17 @@
        dontaudit systemd_logind_t iptables_var_run_t:dir read;
 ')
 
+# OpenSSH 9.8+ split sshd into sshd (listener) + sshd-session (post-auth).
+# Forwarding now runs as sshd_session_t instead of sshd_t.
+optional_policy(`
+       tunable_policy(`sshd_launch_containers',`
+               gen_require(`
+                       type sshd_session_t;
+               ')
+               container_runtime_domtrans(sshd_session_t)
+       ')
+')
+
 role container_user_r;
 userdom_restricted_user_template(container_user)
 userdom_manage_home_role(container_user_r, container_user_t)

++++++ selinux-policy-20260910.tar.xz -> selinux-policy-20260914.tar.xz ++++++
++++ 1633 lines of diff (skipped)

Reply via email to