Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package selinux-policy for openSUSE:Factory
checked in at 2026-09-23 14:32:58
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/selinux-policy (Old)
and /work/SRC/openSUSE:Factory/.selinux-policy.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "selinux-policy"
Wed Sep 23 14:32:58 2026 rev:177 rq:1379922 version:20260923
Changes:
--------
--- /work/SRC/openSUSE:Factory/selinux-policy/selinux-policy.changes
2026-09-16 17:40:44.324028821 +0200
+++
/work/SRC/openSUSE:Factory/.selinux-policy.new.383539/selinux-policy.changes
2026-09-23 14:34:24.640982785 +0200
@@ -1,0 +2,13 @@
+Wed Sep 23 08:28:45 UTC 2026 - Cathy Hu <[email protected]>
+
+- Update to version 20260923:
+ * Add common criteria banner labels (bsc#1282303)
+
+-------------------------------------------------------------------
+Tue Sep 22 09:11:04 UTC 2026 - Cathy Hu <[email protected]>
+
+- Fail cleanoldsepoldir.service with a warning instead of an error
+ when snapper is not installed, as snapper is not installed by default
+ in public cloud images (bsc#1271814)
+
+-------------------------------------------------------------------
Old:
----
selinux-policy-20260914.tar.xz
New:
----
selinux-policy-20260923.tar.xz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ selinux-policy.spec ++++++
--- /var/tmp/diff_new_pack.7IUiUk/_old 2026-09-23 14:34:25.651025010 +0200
+++ /var/tmp/diff_new_pack.7IUiUk/_new 2026-09-23 14:34:25.654025136 +0200
@@ -37,7 +37,7 @@
License: GPL-2.0-or-later
Group: System/Management
Name: selinux-policy
-Version: 20260914
+Version: 20260923
Release: 0
Source0: %{name}-%{version}.tar.xz
Source1: container.fc
++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.7IUiUk/_old 2026-09-23 14:34:25.728028229 +0200
+++ /var/tmp/diff_new_pack.7IUiUk/_new 2026-09-23 14:34:25.732028397 +0200
@@ -1,6 +1,6 @@
<servicedata>
<service name="tar_scm">
<param
name="url">https://gitlab.suse.de/selinux/selinux-policy.git</param>
- <param
name="changesrevision">4bb055148d61ece058ec97af0b622094d226ac30</param></service></servicedata>
+ <param
name="changesrevision">8f46d2387ebb2f2f1b9eda3b2f9c02f36b61f357</param></service></servicedata>
(No newline at EOF)
++++++ cleanoldsepoldir.service.in ++++++
--- /var/tmp/diff_new_pack.7IUiUk/_old 2026-09-23 14:34:25.755029358 +0200
+++ /var/tmp/diff_new_pack.7IUiUk/_new 2026-09-23 14:34:25.759029525 +0200
@@ -11,6 +11,8 @@
RemainAfterExit=no
User=root
ExecStart=@LIBEXECDIR@/selinux/cleanoldsepoldir.sh
+# this is for the cases where snapper is not installed, so retry next boot:
+SuccessExitStatus=5
TimeoutSec=300
StandardOutput=journal
StandardError=journal
++++++ cleanoldsepoldir.sh ++++++
--- /var/tmp/diff_new_pack.7IUiUk/_old 2026-09-23 14:34:25.781030445 +0200
+++ /var/tmp/diff_new_pack.7IUiUk/_new 2026-09-23 14:34:25.787030696 +0200
@@ -272,8 +272,10 @@
fi
fi
else
- echo "ERROR: snapper command not found on a Btrfs system. This script
requires snapper for Btrfs." >&2
- exit 1
+ echo "<4>WARNING: snapper command not found on a Btrfs system. This
script requires snapper for Btrfs." >&2
+ echo "<4>WARNING: Cannot verify that all snapshots are migrated,
keeping /var/lib/selinux and trying again next boot." >&2
+ # Exit as NOTINSTALLED, will allow cleanoldsepoldir systemd service to
exit with success status and retry next time
+ exit 5
fi
fi
++++++ selinux-policy-20260914.tar.xz -> selinux-policy-20260923.tar.xz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/selinux-policy-20260914/policy/modules/kernel/corecommands.fc
new/selinux-policy-20260923/policy/modules/kernel/corecommands.fc
--- old/selinux-policy-20260914/policy/modules/kernel/corecommands.fc
2026-09-14 16:50:09.000000000 +0200
+++ new/selinux-policy-20260923/policy/modules/kernel/corecommands.fc
2026-09-23 10:27:53.000000000 +0200
@@ -293,6 +293,12 @@
# also covers /usr/lib64/libexec due to equivalency rule '/usr/lib64 /usr/lib'
/usr/lib/libexec(/.*)? gen_context(system_u:object_r:bin_t,s0)
+# (open)SUSE only for certification-sles-eal4
+/usr/lib/common-criteria/apply -- gen_context(system_u:object_r:bin_t,s0)
+/usr/lib/common-criteria/check -- gen_context(system_u:object_r:bin_t,s0)
+/usr/lib/common-criteria/render-banner --
gen_context(system_u:object_r:bin_t,s0)
+/usr/lib/common-criteria/scripts(/.*)?
gen_context(system_u:object_r:bin_t,s0)
+
/usr/libexec/git-core/git-shell --
gen_context(system_u:object_r:shell_exec_t,s0)
/usr/libexec/cockpit-agent --
gen_context(system_u:object_r:shell_exec_t,s0)
/usr/bin/cockpit-bridge --
gen_context(system_u:object_r:shell_exec_t,s0)