↵ Return to the main page of selinux-policy-targeted
View build
Search for updates
Package Info
🠗 Changelog
🠗 Dependencies
🠗 Provides
🠗 Files
| Date | Author | Change |
|---|---|---|
| 2026-06-30 | Zdenek Pytela <zpytela at redhat dot com> - 45.8-1 | - Include key_socket in socket_class_set - Remove 14 permissive domains - ci: Run cockpit-machines tests in PRs - Remove the lockdown class from the policy |
| 2026-06-26 | Zdenek Pytela <zpytela at redhat dot com> - 45.7-1 | - Allow systemd-logind the sys_ptrace capability in the user namespace - Allow systemd-sleep the perfmon capability - Allow sshd_session_t dyntransition to sftpd_t - Allow lttng kernel tracing - Allow loadkeys create and use its private tmpfs files - Allow journald create and use netlink_tcpdiag_socket - Fix typo in the comment of build.conf - Allow gpg_pinentry_t to write session dbus socket files |
| 2026-06-22 | Zdenek Pytela <zpytela at redhat dot com> - 45.6-1 | - Allow systemd-hostnamed read hwdb files - Allow systemd-machined to manage nspawn runtime directory - Allow pcm-sensor-server the sys_admin capability - Allow nut/upsmon read nut_conf_t symlinks - Support new sanlock features - using libdm and SG_IO - Allow thumb_t mount proc filesystem - Allow aide connect to the GDM userdb provider socket - Allow postfix_postdrop_t/system_mail_t append to init unix domain stream sockets - Allow nfsd_t to create netlink_generic_socket (bsc#1267826) |
| 2026-06-12 | Zdenek Pytela <zpytela at redhat dot com> - 45.5-1 | - Add anaconda_ioctl_fifo_files_install() and anaconda_write_fifo_files_install() - Allow install_t domain transition to insights_client_t - Allow staff user mounton /var/lib dirs - Allow systemd-coredump signull container runtime - Allow blueman get the attributes of a tmpfs filesystem - portage_compile_domain: Require xdm_xserver_tmp_t type - Add missing interface requirements - Dontaudit virt_driver_domain execmem - fixed file after comment from zpytela. - added caddy related paths. - Remove extra parameters from interface headers - Update bootupd policy for running lsblk - Allow pcscd_t to search cgroup |
| 2026-06-04 | Zdenek Pytela <zpytela at redhat dot com> - 45.4-1 | - Update dbus_role_template() with communication over unix dgram socket - Allow staff user read nsfs files - Allow staff user additional sandboxing permissions - Dontaudit sa-update perfmon and sys_admin capabilities - packit: Stop notifying martinpitt for Cockpit test failures - Allow the kernel to execute also special files - Bring back execmem permission for svirt_tcg_t - Dontaudit tlp_t requesting dac_read_search (bsc#1265386) - Leave content of virtqemud_use_execmem empty - Dontaudit libvirt-daemons execmem - Allow virtstoraged to setattr fixed disk devices - Dontaudit ksmtuned dac_read_search and dac_override capabilities - Remove unused hypervkvp_unit_file_t - Allow mock create and use its private tmpfs files - Allow samba-bgqd send to nmbd over a unix datagram socket - Dontaudit apcupsd dac_override (bsc#1261232) - Allow virtqemud_t to call and transition into udev |
| 2026-05-20 | Rachel Menge <rlmenge at gmail dot com> - 45.3-2 | - Remove deprecated checkreqprot tmpfiles write in selinux-policy.conf |
| 2026-05-18 | Zdenek Pytela <zpytela at redhat dot com> - 45.3-1 | - Allow sys_resource on execution of generic executables conditionally - Label bootloader-migrate-generator with coreos_bootloader_migrate_generator_exec_t - Label /run/coreos with coreos_installer_var_run_t - Add systemd_create_generator_unit_file() and systemd_write_generator_unit_file() - Allow virtnwfilterd_t r/w on packet_socket (bsc#1264273) - Update fstools swap interfaces with dir search - Allow go-fdo-server to read system information - Add missing fc rule for org.gnome.DisplayManager (bsc#1264182) - config: make /etc/systemd/user same as /usr/lib/systemd/user - Do not audit iptables attempts to read other process state - Policy for go-fdo-server - Allow setroubleshoot_fixit_t to touch /.autorelabel and reboot |
| 2026-04-27 | Zdenek Pytela <zpytela at redhat dot com> - 45.2-1 | - Allow init nnp domain transition do dirsrv_t and dirsrv_snmp_t - Allow NetworkManager_dispatcher_nvme_t check status of systemd services - Allow iptables_t read state of some processes - Label /dev/HID-SENSOR-.* with hid_sensor_device_t - Allow thump_t setattr on thumb_tmp_t lnk_files - Allow accounts-daemon read accountsd_share_t symlinks - Label /usr/bin/sudo-rs and /usr/bin/su-rs - Allow gpsd the setcap process capability |
| 2026-04-20 | Zdenek Pytela <zpytela at redhat dot com> - 45.1-1 | - Do not backslash-escape underscores in file context specifications - Allow systemd_homework_t to delete systemd_homed_record_t dirs (bsc#1261359) - Allow sshd-auth/sshd-session get attributes of their sshd parent - Allow systemd-tmpfiles to adjust resource limits - Allow logwatch to getattr nsfs files - Allow xdm dbus chat with rhsmcertd - Allow dhcpc_hook_t unix_dgram_socket and module_request - Allow accountsd list accountsd_share_t dirs - Allow cloud init to domtrans into ssh keygen (bsc#1249964) |
| 2026-04-08 | Vit Mojzis <vmojzis at redhat dot com> - 43.6-2 | - Advertise ownership of DPS-related file paths - Remove trigger{in|preun} triggers for binsbin and varrun - Rebuild policy before running {binsbin|varrun}-convert.sh - Use docdir for documentation data directory - Move the awk post-requires to the minimum subpackage - Fix disabling modules in "%post minimum" |