-
Tue Mar 31 2026 Darren Archibald <darren.archibald@oracle.com> - 38.1.75-2.0.1
- Fixed avc for agetty checkpoint restore denied [Orabug: 36893425]
- Change reference in /etc/selinux/config to point to Oracle doc [Orabug: 36899915]
- Allow user_mail_domain to manage exim_log_t and exim_spool_t link files [Orabug: 36617121]
- Allow exim read network sysctls [Orabug: 36606051]
- Allow exim_t to read exim_log_t and manage exim_spool_t link files [Orabug: 36430005]
- Allow cgred_t to get attributes of cgroup filesystems [Orabug: 36176655]
- Allow kdumpctl_t to execmem [Orabug: 35381156]
- Allow NetworkManager_dispatcher_dhclient_t to execute shells without a domain transition [Orabug: 35091334]
- Allow NetworkManager_dispatcher_dhclient_t to read the DHCP configuration files [Orabug: 35122619]
- Label /var/log/kdump.log with kdump_log_t [Orabug: 33810371]
- Allow rpm_t sys_admin capability [Orabug: 34250651]
- Make systemd_tmpfiles_t MLS trusted for lowering the level of files [Orabug: 33841245]
- Allow nfsd_t to list exports_t dirs [Orabug: 33844301]
- Allow fsadm_t to get attributes of cgroup filesystems [Orabug: 33841268]
- Make import-state work with mls policy [Orabug: 32636699]
- Add map permission to lvm_t on lvm_metadata_t. [Orabug: 31405325]
- Add comment for map on lvm_metadata_t. [Orabug: 31405325]
- Make iscsiadm work with mls policy [Orabug: 32725411]
- Make cloud-init work with mls policy [Orabug: 32430460]
- Allow systemd-pstore to transfer files from /sys/fs/pstore [Orabug: 31594666]
- Make smartd work with mls policy [Orabug: 32430379]
- Allow sysadm_t to mmap modules_object_t files [Orabug: 32411855]
- Make udev work with mls policy [Orabug: 31405299]
- Make lsmd, rngd, and kdumpctl work with mls policy [Orabug: 31405378]
- Allow virt_domain to mmap virt_content_t files [Orabug: 30932671]
- Enable NetworkManager and dhclient to use initramfs-configured DHCP connection [Orabug: 30537515]
- Allow udev_t to load modules [Orabug: 28260775]
- Add vhost-scsi to be vhost_device_t type [Orabug: 27774921]
- Fix container selinux policy [Orabug: 26427364]
- Allow ocfs2_dlmfs to be mounted with ocfs2_dlmfs_t type. [Orabug: 13333429]
-
Mon Mar 09 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.75-2
- Rebuild with the target::exception flag
Resolves: RHEL-148247
-
Fri Mar 06 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.75-1
- Allow nfsd_t domain setuid and setgid capability for rpc.mountd
Resolves: RHEL-148247
-
Mon Feb 23 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.74-1
- Label /run/insights-client.ppid with insights_client_run_t
Resolves: RHEL-146688
- Update gpg_role() interface with unix_stream_socket permissions
Resolves: RHEL-128542
-
Thu Jan 29 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.73-1
- Add the fs_write_tmpfs_files() interface
Resolves: RHEL-142141
- Dontaudit aide the execmem permission
Resolves: RHEL-121480
- Update gpg policy for interactions with rhc-playbook-verifier
Resolves: RHEL-132748
- Allow rhc_playbook_verifier_t stream connect to itself
Resolves: RHEL-132748
- Update policy for rhc-worker-playbook
Resolves: RHEL-132748
- Allow traceroute_t bind rawip sockets to unreserved ports
Resolves: RHEL-130267
- Revert "Allow traceroute_t bind rawip sockets to unreserved ports"
Related: RHEL-130267
- Allow sudodomain connect to gkeyringd over a unix stream socket
Resolves: RHEL-121158
- Allow samba-bgqd send to smbd over a unix datagram socket
Resolves: RHEL-95985
- Allow ssh_agent_type manage generic cache home files
Resolves: RHEL-121165
- Label /usr/libexec/openssh/ssh-pkcs11-helper with ssh_agent_exec_t
Resolves: RHEL-121165
- Allow boothd connect to systemd-machined over a unix socket
Resolves: RHEL-140882
-
Tue Jan 27 2026 Vit Mojzis <vmojzis@redhat.com> - 38.1.72-2
- Macros: Require only "stable" version of selinux-policy (RHEL-141433)
-
Fri Jan 23 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.72-1
- Add insights_client service interfaces
Related: RHEL-140893
- Confine rhc-worker-playbook.worker and rhc-playbook-verifier
Resolves: RHEL-132748
- Allow gpg manage rpm cache
Related: RHEL-108775
- Allow gpg read rpm cache
Related: RHEL-108775
- Allow aide get attributes of tmpfs and devtmpfs filesystems
Resolves: RHEL-121480
- Allow rules for confined users logged in plasma
Resolves: RHEL-133898
- Allow login_userdomain watch lnk_files in /usr
Resolves: RHEL-133898
-
Mon Jan 12 2026 Zdenek Pytela <zpytela@redhat.com> - 38.1.71-1
- Revert "Allow NM nvme dispatcher script start systemd services"
Resolves: RHEL-111946
- Allow ssh_agent_type create a sockfile in /run/user/USERID
Resolves: RHEL-121936
- Allow NM nvme dispatcher script start systemd services
Resolves: RHEL-111946
- Allow aide get attributes of a filesystem with extended attributes
Resolves: RHEL-121480
- Label miscellaneous /dev/papr-* devices
Resolves: RHEL-129879
-
Fri Dec 12 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.70-1
- Add the rpm_signal() interface
Related: RHEL-108826
- Allow tuned_t use its private tmpfs files
Related: RHEL-108826
- Allow kdump search kdumpctl_tmp_t directories
Resolves: RHEL-66119
-
Fri Nov 28 2025 Zdenek Pytela <zpytela@redhat.com> - 38.1.69-1
- Allow sysadm access to TPM
Resolves: RHEL-119055
- Update policy for dhcpc_hook_t
Resolves: RHEL-113941
- Allow stap server read virtual memory sysctls
Resolves: RHEL-114157
- Allow login_userdomain watch /home and /var directories
Resolves: RHEL-119686
- Allow login_userdomain read lastlog
Resolves: RHEL-119686
- Allow staff role read/write cockpit-session unix stream sockets
Resolves: RHEL-108068
- Label /usr/libexec/dhcpcd-run-hooks with dhcpc_hook_exec_t
Resolves: RHEL-113941