Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package selinux-policy for openSUSE:Factory 
checked in at 2026-09-23 14:32:58
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/selinux-policy (Old)
 and      /work/SRC/openSUSE:Factory/.selinux-policy.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "selinux-policy"

Wed Sep 23 14:32:58 2026 rev:177 rq:1379922 version:20260923

Changes:
--------
--- /work/SRC/openSUSE:Factory/selinux-policy/selinux-policy.changes    
2026-09-16 17:40:44.324028821 +0200
+++ 
/work/SRC/openSUSE:Factory/.selinux-policy.new.383539/selinux-policy.changes    
    2026-09-23 14:34:24.640982785 +0200
@@ -1,0 +2,13 @@
+Wed Sep 23 08:28:45 UTC 2026 - Cathy Hu <[email protected]>
+
+- Update to version 20260923:
+  * Add common criteria banner labels (bsc#1282303)
+
+-------------------------------------------------------------------
+Tue Sep 22 09:11:04 UTC 2026 - Cathy Hu <[email protected]>
+
+- Fail cleanoldsepoldir.service with a warning instead of an error
+  when snapper is not installed, as snapper is not installed by default
+  in public cloud images (bsc#1271814)
+
+-------------------------------------------------------------------

Old:
----
  selinux-policy-20260914.tar.xz

New:
----
  selinux-policy-20260923.tar.xz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ selinux-policy.spec ++++++
--- /var/tmp/diff_new_pack.7IUiUk/_old  2026-09-23 14:34:25.651025010 +0200
+++ /var/tmp/diff_new_pack.7IUiUk/_new  2026-09-23 14:34:25.654025136 +0200
@@ -37,7 +37,7 @@
 License:        GPL-2.0-or-later
 Group:          System/Management
 Name:           selinux-policy
-Version:        20260914
+Version:        20260923
 Release:        0
 Source0:        %{name}-%{version}.tar.xz
 Source1:        container.fc

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.7IUiUk/_old  2026-09-23 14:34:25.728028229 +0200
+++ /var/tmp/diff_new_pack.7IUiUk/_new  2026-09-23 14:34:25.732028397 +0200
@@ -1,6 +1,6 @@
 <servicedata>
 <service name="tar_scm">
                 <param 
name="url">https://gitlab.suse.de/selinux/selinux-policy.git</param>
-              <param 
name="changesrevision">4bb055148d61ece058ec97af0b622094d226ac30</param></service></servicedata>
+              <param 
name="changesrevision">8f46d2387ebb2f2f1b9eda3b2f9c02f36b61f357</param></service></servicedata>
 (No newline at EOF)
 

++++++ cleanoldsepoldir.service.in ++++++
--- /var/tmp/diff_new_pack.7IUiUk/_old  2026-09-23 14:34:25.755029358 +0200
+++ /var/tmp/diff_new_pack.7IUiUk/_new  2026-09-23 14:34:25.759029525 +0200
@@ -11,6 +11,8 @@
 RemainAfterExit=no
 User=root
 ExecStart=@LIBEXECDIR@/selinux/cleanoldsepoldir.sh
+# this is for the cases where snapper is not installed, so retry next boot:
+SuccessExitStatus=5
 TimeoutSec=300
 StandardOutput=journal
 StandardError=journal

++++++ cleanoldsepoldir.sh ++++++
--- /var/tmp/diff_new_pack.7IUiUk/_old  2026-09-23 14:34:25.781030445 +0200
+++ /var/tmp/diff_new_pack.7IUiUk/_new  2026-09-23 14:34:25.787030696 +0200
@@ -272,8 +272,10 @@
             fi
         fi
     else
-        echo "ERROR: snapper command not found on a Btrfs system. This script 
requires snapper for Btrfs." >&2
-        exit 1
+        echo "<4>WARNING: snapper command not found on a Btrfs system. This 
script requires snapper for Btrfs." >&2
+        echo "<4>WARNING: Cannot verify that all snapshots are migrated, 
keeping /var/lib/selinux and trying again next boot." >&2
+        # Exit as NOTINSTALLED, will allow cleanoldsepoldir systemd service to 
exit with success status and retry next time
+        exit 5
     fi
 fi
 


++++++ selinux-policy-20260914.tar.xz -> selinux-policy-20260923.tar.xz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/selinux-policy-20260914/policy/modules/kernel/corecommands.fc 
new/selinux-policy-20260923/policy/modules/kernel/corecommands.fc
--- old/selinux-policy-20260914/policy/modules/kernel/corecommands.fc   
2026-09-14 16:50:09.000000000 +0200
+++ new/selinux-policy-20260923/policy/modules/kernel/corecommands.fc   
2026-09-23 10:27:53.000000000 +0200
@@ -293,6 +293,12 @@
 # also covers /usr/lib64/libexec due to equivalency rule '/usr/lib64 /usr/lib'
 /usr/lib/libexec(/.*)?                 gen_context(system_u:object_r:bin_t,s0)
 
+# (open)SUSE only for certification-sles-eal4
+/usr/lib/common-criteria/apply --      gen_context(system_u:object_r:bin_t,s0)
+/usr/lib/common-criteria/check --      gen_context(system_u:object_r:bin_t,s0)
+/usr/lib/common-criteria/render-banner --      
gen_context(system_u:object_r:bin_t,s0)
+/usr/lib/common-criteria/scripts(/.*)?         
gen_context(system_u:object_r:bin_t,s0)
+
 /usr/libexec/git-core/git-shell        --      
gen_context(system_u:object_r:shell_exec_t,s0)
 /usr/libexec/cockpit-agent      --  
gen_context(system_u:object_r:shell_exec_t,s0)
 /usr/bin/cockpit-bridge         -- 
gen_context(system_u:object_r:shell_exec_t,s0)

Reply via email to