Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

selinux-policy-38.1.83-1.el9 RPM for noarch

From CentOS Stream 9 BaseOS for aarch64

Name: selinux-policy Distribution: CentOS
Version: 38.1.83 Vendor: CentOS
Release: 1.el9 Build date: Sat Jul 4 10:33:09 2026
Group: Unspecified Build host: ppc64le-02.stream.rdu2.redhat.com
Size: 25929 Source RPM: selinux-policy-38.1.83-1.el9.src.rpm
Packager: builder@centos.org
Url: https://github.com/fedora-selinux/selinux-policy
Summary: SELinux policy configuration
SELinux core policy package.
Originally based off of reference policy,
the policy has been adjusted to provide support for Fedora.

Provides

Requires

License

GPLv2+

Changelog

* Sat Jul 04 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.83-1
  - Remove systemd_homed_stream_connect() reference for bootupd_t
  Resolves: RHEL-174888
  - Allow postfix_postdrop_t/system_mail_t append to init unix domain stream sockets
  Resolves: RHEL-145322
  - Update bootupd policy for running lsblk
  Resolves: RHEL-174888
  - Allow aide get attributes of all filesystems
  Resolves: RHEL-182787
  - Allow the staff user mount on tmpfs directories
  Resolves: RHEL-183237
  - Allow staff user the dac_override capability in the user namespace
  Resolves: RHEL-183237
  - Allow userdomain get attributes of files on an nsfs filesystem
  Resolves: RHEL-163438
* Mon Jun 22 2026 Veronika Syncakova <vsyncako@redhat.com> - 38.1.82-1
  - Allow systemd-machined to manage nspawn runtime directory
  Resloves: RHEL-108849
* Fri Jun 12 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.81-1
  - Add the systemd_logind_stream_connect() interface
  Resolves: RHEL-163438
  - Add files_mounton_generic_tmp_dirs() interface
  Resolves: RHEL-163438
  - Allow staff user mounton /var/lib dirs
  Resolves: RHEL-163438
  - Allow staff user read nsfs files
  Resolves: RHEL-163438
  - Allow staff user additional sandboxing permissions
  Resolves: RHEL-163438
  - Allow staff_sudo_t read PID1's process state
  Resolves: RHEL-163438
  - Allow staff_sudo_t read logind sessions files
  Resolves: RHEL-163438
  - Allow staff user delete thump_tmp_t files
  Resolves: RHEL-163438
  - Allow login_userdomain read thumb tmp files
  Resolves: RHEL-163438
  - Allow staff user connect to systemd-logind over a unix stream socket
  Resolves: RHEL-163438
  - Allow staff user mount /proc
  Resolves: RHEL-163438
  - Support confined users usage of bubblewrap
  Resolves: RHEL-163438
  - Add anaconda_ioctl_fifo_files_install() and anaconda_write_fifo_files_install()
  Resolves: RHEL-179125
  - Allow rhsmcertd read anaconda run files
  Resolves: RHEL-179125
  - Allow any domain to inherit fds from rpm-ostree
  Resolves: RHEL-179125
  - Allow install_t domain transition to insights_client_t
  Resolves: RHEL-179125
  - Allow logrotate stop all systemd services
  Resolves: RHEL-169534
  - Allow staff and sysadm execute iotop using sudo
  Resolves: RHEL-172235
  - Allow sysadm_t to connect to iscsid using a unix domain stream socket
  Resolves: RHEL-155605
* Mon May 18 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.80-1
  - Allow fido services connect to postgres database
  Resolves: RHEL-28814
  - Allow qatlib map kernel modules
  Resolves: RHEL-133799
* Tue May 12 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.79-1
  - Do not audit iptables attempts to read other process state
  Resolves: RHEL-152287
  - Allow iptables_t read state of some processes
  Resolves: RHEL-152287
  - Allow iptables read firewalld process state
  Resolves: RHEL-152287
  - Allow systemd-machined read virtd process state
  Resolves: RHEL-152287
  - Allow systemd-machined read svirt process state
  Resolves: RHEL-152287
  - Label /dev/HID-SENSOR-.* with hid_sensor_device_t
  Resolves: RHEL-166739
* Tue Apr 21 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.78-1
  - Allow dbus-broker to use inherited user ttys
  Resolves: RHEL-86925
  - Allow sysadm user connect to lvm over a unix stream socket
  Resolves: RHEL-150996
* Thu Apr 16 2026 Vit Mojzis <vmojzis@redhat.com> - 38.1.77-2
  - Advertise ownership of DPS-related file paths
  Resolves: RHEL-157952
* Fri Apr 10 2026 Veronika Syncakova <vsyncako@redhat.com> - 38.1.77-1
  - Allow pkcsslotd map its private tmpfs files
  - Allow pkcsslotd read files in /proc and /sys
  Resolves: RHEL-155929
  - Allow dhcpc_hook_t unix_dgram_socket and module_request
  Resolves: RHEL-147155
  - Allow xdm dbus chat with rhsmcertd
  Resolves: RHEL-157008
  - Allow logwatch to getattr nsfs files
  Resolves: RHEL-160896
  - Allow systemd-tmpfiles to adjust resource limits
  Resolves: RHEL-163080
  - Dontaudit setroubleshootd read root's home files like .rpmmacros
  Resolves: RHEL-147470
  - Allow redis_t to create netlink_rdma_socket
  Resolves: RHEL-161115
* Thu Mar 12 2026 Veronika Syncakova <vsyncako@redhat.com> - 38.1.76-1
  - Allow mdadm to use CAP_BPF during RAID monitoring
  Resolves: RHEL-135764
* Mon Mar 09 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.75-2
  - Rebuild with the target::exception flag
  Resolves: RHEL-148247
* Fri Mar 06 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.75-1
  - Allow nfsd_t domain setuid and setgid capability for rpc.mountd
  Resolves: RHEL-148247
* Mon Feb 23 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.74-1
  - Label /run/insights-client.ppid with insights_client_run_t
  Resolves: RHEL-146688
  - Update gpg_role() interface with unix_stream_socket permissions
  Resolves: RHEL-128542
* Thu Jan 29 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.73-1
  - Add the fs_write_tmpfs_files() interface
  Resolves: RHEL-142141
  - Dontaudit aide the execmem permission
  Resolves: RHEL-121480
  - Update gpg policy for interactions with rhc-playbook-verifier
  Resolves: RHEL-132748
  - Allow rhc_playbook_verifier_t stream connect to itself
  Resolves: RHEL-132748
  - Update policy for rhc-worker-playbook
  Resolves: RHEL-132748
  - Allow traceroute_t bind rawip sockets to unreserved ports
  Resolves: RHEL-130267
  - Revert "Allow traceroute_t bind rawip sockets to unreserved ports"
  Related: RHEL-130267
  - Allow sudodomain connect to gkeyringd over a unix stream socket
  Resolves: RHEL-121158
  - Allow samba-bgqd send to smbd over a unix datagram socket
  Resolves: RHEL-95985
  - Allow ssh_agent_type manage generic cache home files
  Resolves: RHEL-121165
  - Label /usr/libexec/openssh/ssh-pkcs11-helper with ssh_agent_exec_t
  Resolves: RHEL-121165
  - Allow boothd connect to systemd-machined over a unix socket
  Resolves: RHEL-140882
* Tue Jan 27 2026 Vit Mojzis <vmojzis@redhat.com> - 38.1.72-2
  - Macros: Require only "stable" version of selinux-policy (RHEL-141433)
* Fri Jan 23 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.72-1
  - Add insights_client service interfaces
  Related: RHEL-140893
  - Confine rhc-worker-playbook.worker and rhc-playbook-verifier
  Resolves: RHEL-132748
  - Allow gpg manage rpm cache
  Related: RHEL-108775
  - Allow gpg read rpm cache
  Related: RHEL-108775
  - Allow aide get attributes of tmpfs and devtmpfs filesystems
  Resolves: RHEL-121480
  - Allow rules for confined users logged in plasma
  Resolves: RHEL-133898
  - Allow login_userdomain watch lnk_files in /usr
  Resolves: RHEL-133898
* Mon Jan 12 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.71-1
  - Revert "Allow NM nvme dispatcher script start systemd services"
  Resolves: RHEL-111946
  - Allow ssh_agent_type create a sockfile in /run/user/USERID
  Resolves: RHEL-121936
  - Allow NM nvme dispatcher script start systemd services
  Resolves: RHEL-111946
  - Allow aide get attributes of a filesystem with extended attributes
  Resolves: RHEL-121480
  - Label miscellaneous /dev/papr-* devices
  Resolves: RHEL-129879
* Fri Dec 12 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.70-1
  - Add the rpm_signal() interface
  Related: RHEL-108826
  - Allow tuned_t use its private tmpfs files
  Related: RHEL-108826
  - Allow kdump search kdumpctl_tmp_t directories
  Resolves: RHEL-66119
* Fri Nov 28 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.69-1
  - Allow sysadm access to TPM
  Resolves: RHEL-119055
  - Update policy for dhcpc_hook_t
  Resolves: RHEL-113941
  - Allow stap server read virtual memory sysctls
  Resolves: RHEL-114157
  - Allow login_userdomain watch /home and /var directories
  Resolves: RHEL-119686
  - Allow login_userdomain read lastlog
  Resolves: RHEL-119686
  - Allow staff role read/write cockpit-session unix stream sockets
  Resolves: RHEL-108068
  - Label /usr/libexec/dhcpcd-run-hooks with dhcpc_hook_exec_t
  Resolves: RHEL-113941
* Fri Nov 14 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.68-1
  - Allow insights-client manage /etc symlinks
  Resolves: RHEL-108826
  - Allow insights-client get attributes of the rpm executable
  Resolves: RHEL-127329
  - Allow ras-mc-ctl get attributes of the kmod executable
  Resolves: RHEL-103975
  - Fix files_delete_boot_symlinks() to contain delete_lnk_files_pattern
  Resolves: RHEL-101155
  - Allow bootupd delete symlinks in the /boot directory
  Resolves: RHEL-101155
  - Update policy for bootupd
  Resolves: RHEL-101155
  - Allow create kerberos files in postgresql db home
  Resolves: RHEL-123225
* Tue Oct 14 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.67-1
  - Allow login_userdomain dbus chat with tuned-ppd
  Resolves: RHEL-113906
  - selinux-policy: add allow rule for tuned_ppd_t
  Resolves: RHEL-113906
  - Add ppd_base_profile to file transition to get tuned_rw_etc_t type
  Resolves: RHEL-113906
  - Allow tuned-ppd manage tuned log files
  Resolves: RHEL-113906
  - Allow tuned-ppd connect to sssd over a unix stream socket
  Resolves: RHEL-113906
  - Allow tuned-ppd create ppd_base_profile with a file transition
  Resolves: RHEL-113906
  - Allow init create and use vsock socket
  Resolves: RHEL-113647
  - Add Valkey rules to Redis module
  Resolves: RHEL-108982
  - Allow ras-mc-ctl write to sysfs files
  Resolves: RHEL-103975
  - Allow kdump search kdumpctl_tmp_t directories
  Resolves: RHEL-66119
* Fri Sep 19 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.66-1
  - Reapply "Add insights_core interfaces"
  Resolves: RHEL-112367
  - Reapply "Add policy for insights-core"
  Resolves: RHEL-112367
* Thu Aug 21 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.65-1
  - Revert "Add policy for insights-core"
  Resolves: RHEL-110650
  - Revert "Add insights_core interfaces"
  Resolves: RHEL-110650
* Tue Aug 12 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.64-1
  - Add insights_core and insights_client interfaces
  Related: RHEL-59145
  - Label /usr/libexec/postfix/tlsproxy with postfix_smtp_exec_t
  Resolves: RHEL-77101
  - Remove "minimum" as a SELINUXTYPE from /etc/selinux/config
  Resolves: RHEL-101140
* Wed Jul 30 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.63-1
  - Allow samba-dcerpcd send sigkills to passwd
  Resolves: RHEL-100032
  - Allow power-profiles-daemon watch sysfs directories
  Resolves: RHEL-100718
  - Allow power-profiles-daemon write sysfs files
  Resolves: RHEL-100718
  - Allow hostapd write to socket files in /tmp
  Resolves: RHEL-59683
  - Allow irqbalance search sssd lib directories
  Resolves: RHEL-1556
  - Add insights_client_delete_lib_dirs() interface
  Related: RHEL-59145
* Fri Jul 18 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.62-1
  - Allow "hostapd_cli ping" run as a systemd service
  Resolves: RHEL-59683
  - Allow systemd-timedated start/stop timemaster services
  Resolves: RHEL-95690
  - Allow lldpd connect to systemd-machined over a unix socket
  Resolves: RHEL-96167
  - Allow power-profiles-daemon get attributes of filesystems with extended attributes
  Resolves: RHEL-100718
  - Allow tuned-ppd watch_reads sysfs directories
  Resolves: RHEL-101687
  - Allow tuned-ppd watch sysfs directories
  Resolves: RHEL-101687
* Mon Jul 14 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.61-1
  - Fix incorrect /run and /usr/bin file context entries
  Resolves: SELINUX-4392
  - Dontaudit irqbalance read sssd public files
  Resolves: RHEL-1556
  - Update sssd_dontaudit_read_public_files()
  Resolves: RHEL-1556
  - Allow insights-client file transition for files in /var/tmp
  Resolves: SELINUX-4392
  - Add the virt_exec_virsh() interface
  Resolves: SELINUX-4392
  - Add the ssh_exec_sshd() interface
  Resolves: SELINUX-4392
  - Add rhsmcertd interfaces
  Resolves: SELINUX-4392
  - Add the bind_exec_named_checkconf() interface
  Resolves: SELINUX-4392
  - Add the auth_write_motd_var_run_files() interface
  Resolves: SELINUX-4392
  - Add the gpg_domtrans_agent() interface
  Resolves: SELINUX-4392
  - Add the gpg_read_user_secrets() interface
  Resolves: SELINUX-4392
  - Add policy for insights-core
  Resolves: SELINUX-4392
* Thu Jul 03 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.60-1
  - Allow irqbalance execute shell if irqbalance_run_unconfined is on
  Resolves: RHEL-1556
  - Update irqbalance policy for using unconfined scripts
  Resolves: RHEL-1556
* Tue Jul 01 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.59-1
  - virt: allow QEMU use of the qgs daemon for attestation
  Resolves: RHEL-87744
  - qgs: add contrib module for TDX "qgs" daemon
  Resolves: RHEL-87744
  - kernel: add interfaces for using SGX enclaves
  Resolves: RHEL-87744
  - Allow coreos-installer search sssd library directory
  Resolves: RHEL-95689
  - Label /dev/diag as diagnostic_device_t
  Resolves: RHEL-95342
  - Allow irqbalance execute shell if irqbalance_run_unconfined is on
  Resolves: RHEL-1556
* Mon Jun 09 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.58-1
  - Allow mptcpd the net_admin capability
  Resolves: RHEL-81729
  - Allow networkmanager send a general signal to iptables
  Resolves: RHEL-93741
  - Make bootupd use bootupd_tmp_t as its private type for files in /tmp
  Resolves: RHEL-94508
  - Update bootupd policy
  Resolves: RHEL-94508
  - Allow switcheroo-control dbus chat with xdm
  Resolves: RHEL-93335
  - Update the files_search_mnt() interface
  Resolves: RHEL-94184
* Thu May 29 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.57-1
  - Update policy for haproxyd
  Resolves: RHEL-88045
  - Allow NetworkManager manage NetworkManager_etc_rw_t symlinks
  Resolves: RHEL-86178
  - Allow lldpad connect to systemd-userdbd over a unix socket
  Resolves: RHEL-84046
  - Allow gconfd connect to system dbus
  Resolves: RHEL-77984
  - Allow login_pgm read filesystem sysctls
  Resolves: RHEL-77745
  - Allow login_userdomain create /run/tlog directory with user_tmp_t
  Resolves: RHEL-47241
* Tue May 06 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.56-1
  - Remove 3 permissive domains
  Resolves: RHEL-82674
  - Allow tuned-ppd dbus chat with xdm
  Resolves: RHEL-87203
  - Allow system-dbusd list systemd-machined directories
  Resolves: RHEL-85379
  - Allow NetworkManager create and use icmp_socket
  Resolves: RHEL-83529
  - Allow journalctl connect to systemd-userdbd over a unix socket
  Resolves: RHEL-82673
  - allow gdm and iiosensorproxy talk to each other via D-bus
  Resolves: RHEL-80697
  - Allow varnishd execute the prlimit64() syscall
  Resolves: RHEL-77995
  - Allow system_dbusd_t r/w unix stream sockets of unconfined_service_t
  Resolves: RHEL-61928
  - Add the getattr permission to 2 dontaudit interfaces
  Resolves: RHEL-59145
* Fri Apr 11 2025 Vit Mojzis <vmojzis@redhat.com> - 38.1.55-2
  - automotive: Deny unknown classes/permissions (RHEL-86827)
* Fri Apr 11 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.55-1
  - Allow tuned-ppd read sssd public files
  Resolves: RHEL-69526
  - Allow systemd-journal-upload read init pid files
  Resolves: RHEL-62196
  - Label SetroubleshootPrivileged.py with setroubleshootd_exec_t
  Resolves: RHEL-77319
  - Allow chronyd-restricted sendto to chronyc
  Resolves: RHEL-82308
  - Allow chronyc sendto to chronyd-restricted
  Resolves: RHEL-82308
* Mon Mar 31 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.54-1
  - Confine tuned-ppd
  Resolves: RHEL-69526
  - Make tuned work with mls policy
  Resolves: RHEL-69526
  - Allow afterburn to mount and read config drives
  Resolves: RHEL-79319
* Fri Mar 14 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.53-4
  - Allow afterburn to mount and read config drives
  Resolves: RHEL-82276
* Fri Feb 07 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.53-1
  - Allow svirt_t to connect to nbdkit over a unix stream socket
  Resolves: RHEL-56029
  - Allow power-profiles-daemon the bpf capability
  Resolves: RHEL-61117
  - Allow systemd-machined the kill user-namespace capability
  Resolves: RHEL-76352
* Fri Jan 31 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.52-1
  - Add the files_read_root_files() interface
  Resolves: RHEL-70849
  - Dontaudit systemd-logind remove all files
  Resolves: RHEL-59145
  - Add the files_dontaudit_read_all_dirs() interface
  Resolves: RHEL-59145
  - Add the files_dontaudit_delete_all_files() interface
  Resolves: RHEL-59145
  - Allow rhsmcertd notify virt-who
  Resolves: RHEL-77152
  - Allow irqbalance to run unconfined scripts conditionally
  Resolves: RHEL-1556
  - Backport bootupd policy from current Fedora rawhide
  Resolves: RHEL-70849
  - Support using systemd containers
  Resolves: RHEL-76352
  - Allow svirt_t connect to unconfined_t over a unix domain socket
  Resolves: RHEL-37539
  - Allow virt_domain to use pulseaudio - conditional
  Resolves: RHEL-1379
  - Allow telnetd read network sysctls
  Resolves: RHEL-58825
  - Allow alsa watch generic device directories
  Resolves: RHEL-61472
  - Update switcheroo policy
  Resolves: RHEL-24268
* Wed Jan 15 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.51-1
  - Allow rsyslog read systemd-logind session files
  Resolves: RHEL-73839
  - Allow samba-bgqd connect to cupsd over an unix domain stream socket
  Resolves: RHEL-72860
  - Allow svirt_t read sysfs files
  Resolves: RHEL-70839
  - Allow xdm dbus chat with power-profiles-daemon
  Resolves: RHEL-61117
  - Update power-profiles-daemon policy
  Resolves: RHEL-61117
  - Confine power-profiles-daemon
  Resolves: RHEL-61117
  - Allow virtqemud domain transition to nbdkit
  Resolves: RHEL-56029
  - Add nbdkit interfaces defined conditionally
  Resolves: RHEL-56029
  - Confine the switcheroo-control service
  Resolves: RHEL-24268
* Fri Dec 13 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.50-1
  - Allow auditctl signal auditd
  Resolves: RHEL-68969
  - Fix the cups_read_pid_files() interface to use read_files_pattern
  Resolves: RHEL-69517
  - Dontaudit systemd-coredump the sys_resource capability
  Resolves: RHEL-46339
  - Allow rpcd read network sysctls
  Resolves: RHEL-1558
  - Allow irqbalance setpcap capability in the user namespace
  Resolves: RHEL-69564
  - Allow traceroute_t bind rawip sockets to unreserved ports
  Resolves: RHEL-54561
  - Allow svirt_t the sys_rawio capability
  Resolves: RHEL-56955
  - Change /run/sysctl\.d(/.*)? fc entry to /var/run/sysctl\.d(/.*)?
  Resolves: RHEL-56988
  - Exclude container-selinux manpage from selinux-policy-doc
  Resolves: RHEL-69916
* Fri Dec 06 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.49-1
  - Update virtlogd policy
  Resolves: RHEL-69433
  - Allow svirt_t the sys_rawio capability
  Resolves: RHEL-56955
  - Allow qemu-ga the dac_override and dac_read_search capabilities
  Resolves: RHEL-52476
  - Allow ip the setexec permission
  Resolves: RHEL-62923
  - Allow alsa get attributes filesystems with extended attributes
  Resolves: RHEL-61472
  - Allow bacula execute container in the container domain
  Resolves: RHEL-21168
  - Allow httpd get attributes of dirsrv unit files
  Resolves: RHEL-46808
  - Update samba-bgqd policy
  Resolves: RHEL-69517
  - Allow samba-bgqd read cups config files
  Resolves: RHEL-69517
  - Update policy for samba-bgqd
  Resolves: RHEL-69517
  - Update bootupd policy for the removing-state-file test
  Resolves: RHEL-66584
  - Allow qatlib search the content of the kernel debugging filesystem
  Resolves: RHEL-53864
  - Allow qatlib connect to systemd-machined over a unix socket
  Resolves: RHEL-53864
  - Update qatlib policy for v24.02 with new features
  Resolves: RHEL-53864
* Tue Nov 12 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.48-1
  - Revert "Allow unconfined_t execute kmod in the kmod domain"
  Resolves: RHEL-65008
  - Add policy for /usr/libexec/samba/samba-bgqd
  Resolves: RHEL-53124
* Wed Oct 23 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.47-1
  - Label /etc/sysctl.d and /run/sysctl.d with system_conf_t
  Resolves: RHEL-56988
  - Allow lldpad create and use netlink_generic_socket
  Resolves: RHEL-61832
  - Allow unconfined_t execute kmod in the kmod domain
  Resolves: RHEL-54710
  - Allow confined users r/w to screen unix stream socket
  Resolves: RHEL-50379
  - Label /root/.screenrc and /root/.tmux.conf with screen_home_t
  Resolves: RHEL-50375
  - Allow iio-sensor-proxy the bpf capability
  Resolves: RHEL-17346
* Fri Oct 11 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.46-1
  - Rebuild
* Thu Oct 10 2024 Zdenek Pytela <zpytela@redhat.com> - 35.1.46-1
  - Label /run/modprobe.d with modules_conf_t
  Resolves: RHEL-61453
  - Allow boothd connect to kernel over a unix socket
  Resolves: RHEL-57104
  - Allow boothd connect to systemd-userdbd over a unix socket
  Resolves: RHEL-57104
  - Additional updates stalld policy for bpf usage
  Resolves: RHEL-57075
  - Update stalld policy for bpf usage
  Resolves: RHEL-57075
  - Allow ptp4l the sys_admin capability
  Resolves: RHEL-55133
  - Label /dev/hfi1_[0-9]+ devices
  Resolves: RHEL-54996
  - Confine iio-sensor-proxy
  Resolves: RHEL-17346
* Mon Sep 16 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.45-3
  - Rebuild
  Resolves: RHEL-55414
* Wed Sep 04 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.45-2
  - Rebuild
  Resolves: RHEL-55414
* Thu Aug 29 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.45-1
  - Allow setsebool_t relabel selinux data files
  Resolves: RHEL-55414
* Mon Aug 12 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.44-1
  - Allow coreos-installer-generator work with partitions
  Resolves: RHEL-38614
  - Label /etc/mdadm.conf.d with mdadm_conf_t
  Resolves: RHEL-38614
  - Change file context specification to /var/run/metadata
  Resolves: RHEL-49735
  - Allow initrc_t transition to passwd_t
  Resolves: RHEL-17404
  - systemd: allow systemd_notify_t to send data to kernel_t datagram sockets
  Resolves: RHEL-25514
  - systemd: allow sys_admin capability for systemd_notify_t
  Resolves: RHEL-25514
  - Change systemd-network-generator transition to include class file
  Resolves: RHEL-47033
  - Allow sshd_keygen_t connect to userdbd over a unix stream socket
  Resolves: RHEL-47033
* Wed Jul 31 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.43-1
  - Allow rhsmcertd read/write access to /dev/papr-sysparm
  Resolves: RHEL-49599
  - Label /dev/papr-sysparm and /dev/papr-vpd
  Resolves: RHEL-49599
  - Allow rhsmcertd read, write, and map ica tmpfs files
  Resolves: RHEL-50926
  - Update afterburn file transition policy
  Resolves: RHEL-49735
  - Label /run/metadata with afterburn_runtime_t
  Resolves: RHEL-49735
  - Allow afterburn list ssh home directory
  Resolves: RHEL-49735
  - Support SGX devices
  Resolves: RHEL-50922
  - Allow systemd-pstore send a message to syslogd over a unix domain
  Resolves: RHEL-45528
  - Allow postfix_domain map postfix_etc_t files
  Resolves: RHEL-46332
  - Allow microcode create /sys/devices/system/cpu/microcode/reload
  Resolves: RHEL-26821
  - Allow svirt_tcg_t map svirt_image_t files
  Resolves: RHEL-27141
  - Allow systemd-hostnamed shut down nscd
  Resolves: RHEL-45033
  - Allow postfix_domain connect to postgresql over a unix socket
  Resolves: RHEL-6776
* Thu Jul 18 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.42-1
  - Label samba certificates with samba_cert_t
  Resolves: RHEL-25724
  - Allow systemd-coredumpd the sys_chroot capability
  Resolves: RHEL-45245
  - Allow svirt_tcg_t read vm sysctls
  Resolves: RHEL-27141
  - Label /usr/sbin/samba-gpupdate with samba_gpupdate_exec_t
  Resolves: RHEL-25724
  - Label /var/run/coreos-installer-reboot with coreos_installer_var_run_t
  Resolves: RHEL-38614
  - Allow coreos-installer add systemd unit file links
  Resolves: RHEL-38614
* Sun Jul 07 2024 Zdenek Pytela <zpytela@redhat.com> - 38.1.41-1
  - Differentiate between staff and sysadm when executing crontab with sudo
  Resolves: RHEL-31888
  - Label /usr/bin/samba-gpupdate with samba_gpupdate_exec_t
  Resolves: RHEL-25724
  - Allow unconfined_service_t transition to passwd_t
  Resolves: RHEL-17404
  - Allow sbd to trace processes in user namespace
  Resolves: RHEL-44680
  - Allow systemd-coredumpd sys_admin and sys_resource capabilities
  Resolves: RHEL-45245
  - Label /usr/lib/node_modules/npm/bin with bin_t
  Resolves: RHEL-36587
  - Support /var is empty
  Resolves: RHEL-29331
  - Allow timemaster write to sysfs files
  Resolves: RHEL-28777
  - Don't audit crontab_domain write attempts to user home
  Resolves: RHEL-31888
  - Transition from sudodomains to crontab_t when executing crontab_exec_t
  Resolves: RHEL-31888
  - Fix label of pseudoterminals created from sudodomain
  Resolves: RHEL-31888

Files

/etc/selinux
/etc/selinux/config
/etc/sysconfig/selinux
/usr/lib/rpm/macros.d/macros.selinux-policy
/usr/lib/systemd/system/selinux-check-proper-disable.service
/usr/lib/tmpfiles.d/selinux-policy.conf
/usr/share/licenses/selinux-policy
/usr/share/licenses/selinux-policy/COPYING
/usr/share/selinux
/usr/share/selinux/devel
/usr/share/selinux/devel/include
/usr/share/selinux/devel/include/distributed
/usr/share/selinux/packages
/usr/share/selinux/packages/minimum
/usr/share/selinux/packages/mls
/usr/share/selinux/packages/targeted


Generated by rpm2html 1.8.1

Fabrice Bellet, Sun Aug 9 18:23:48 2026