Bug 1915264

Summary: Add new capabilities to selinux-policy
Product: [Fedora] Fedora Reporter: Zdenek Pytela <zpytela>
Component: selinux-policyAssignee: Zdenek Pytela <zpytela>
Status: CLOSED RAWHIDE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: high    
Version: 34CC: dwalsh, grepl.miroslav, lvrabec, mmalik, omosnace, plautrba, vmojzis, zpytela
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-02-09 16:29:41 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Zdenek Pytela 2021-01-12 11:07:06 UTC
Add new capabilities to selinux-policy. As the number of capabilities in the "capability" class has already reached the limit of 32, they are to be added to the "capability2" class.

Comment 1 Zdenek Pytela 2021-01-12 11:56:24 UTC
The capabilities list:
- perfmon
- bpf
- checkpoint_restore

Comment 2 Zdenek Pytela 2021-01-12 12:40:52 UTC
I've submitted a Fedora rawhide PR to add the capabilities:
https://github.com/fedora-selinux/selinux-policy/pull/537

Comment 3 Milos Malik 2021-01-19 14:06:53 UTC
Test coverage for this bug exists in a form of PR:
 * https://src.fedoraproject.org/tests/selinux/pull-request/173

The PR waits for review.

Comment 4 Ben Cotton 2021-02-09 16:22:48 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 34 development cycle.
Changing version to 34.