Bug 2079276
| Summary: | Update to selinux-3.4 | |||
|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | Reporter: | Petr Lautrbach <plautrba> | |
| Component: | libsepol | Assignee: | Petr Lautrbach <plautrba> | |
| Status: | CLOSED ERRATA | QA Contact: | Milos Malik <mmalik> | |
| Severity: | high | Docs Contact: | Jan Fiala <jafiala> | |
| Priority: | high | |||
| Version: | 9.1 | CC: | gfialova, hubert.quarantel, lvrabec, mjahoda, mmalik, omosnace, pkis, plautrba, vmojzis, zpytela | |
| Target Milestone: | rc | Keywords: | Triaged | |
| Target Release: | 9.1 | Flags: | pm-rhel:
mirror+
|
|
| Hardware: | All | |||
| OS: | Linux | |||
| Whiteboard: | ||||
| Fixed In Version: | libsepol-3.4-1.1.el9 | Doc Type: | Enhancement | |
| Doc Text: |
.SELinux user-space packages updated
SELinux user-space packages `libsepol`, `libselinux`, `libsemanage`, `policycoreutils`, `checkpolicy`, and `mcstrans` were updated to the latest upstream release 3.4. The most notable changes are:
* Added support for parallel relabeling through the `-T` option in the `setfiles`, `restorecon`, and `fixfiles` tools.
** You can either specify the number of process threads in this option or use `-T 0` for using the maximum of available processor cores. This reduces the time required for relabeling significantly.
* Added the new `--checksum` option, which prints SHA-256 hashes of modules.
* Added new policy utilities in the `libsepol-utils` package.
|
Story Points: | --- | |
| Clone Of: | ||||
| : | 2079283 2079290 (view as bug list) | Environment: | ||
| Last Closed: | 2022-11-15 11:19:08 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 2079283, 2079285, 2079286, 2079287, 2079288, 2079290 | |||
|
Description
Petr Lautrbach
2022-04-27 10:17:49 UTC
libsepol in 3.4 contains new utilities - for details see https://github.com/SELinuxProject/selinux/commit/fed78faaa375297ed6ab2fa772e5a5f643d9553e These utilitis will be part of new libsepol-utils subpackage *** Bug 2069718 has been marked as a duplicate of this bug. *** Beware ! Versions 3.4 of libsepol prior to commit https://github.com/SELinuxProject/selinux/commit/88a703399f3f44be2502fd4ecd22ac3d3c560694 of June 15th (2022) will have a serious problem with SELinux policy modules containing SEuser definitions. Such policy modules will be rejected with error messages like: libsepol.validate_user_datum: Invalid user datum libsepol.validate_datum_array_entries: Invalid datum array entries libsepol.validate_policydb: Invalid policydb The source code of such modules will compile successfully at the `checkmodule` stage but will fail at the `semodule_package` stage. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (libsepol bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2022:8337 |