Compare commits

...

No commits in common. 'c9' and 'i10cs' have entirely different histories.
c9 ... i10cs

@ -1,68 +0,0 @@
From d319a1a6723ad20766c18964c289d47c06e19182 Mon Sep 17 00:00:00 2001
From: Patrik Koncity <pkoncity@redhat.com>
Date: Fri, 19 Aug 2022 14:03:49 +0200
Subject: [PATCH 1/2] Add new interfaces for communication with keylime
Policy need rules to communicate with keylime.
AVC:
allow keylime_agent_t tabrmd_t:dbus send_msg;
allow keylime_agent_t tabrmd_t:unix_stream_socket { getattr getopt read write };
Create new interfaces to allow keylime
communicate with keylime.
Signed-off-by: Patrik Koncity <pkoncity@redhat.com>
---
selinux/tabrmd.if | 40 ++++++++++++++++++++++++++++++++++++++++
1 file changed, 40 insertions(+)
diff --git a/selinux/tabrmd.if b/selinux/tabrmd.if
index 3eb6a30..c04eca0 100644
--- a/selinux/tabrmd.if
+++ b/selinux/tabrmd.if
@@ -1 +1,41 @@
## <summary></summary>
+
+########################################
+## <summary>
+## Create and use a unix stream socket
+## </summary>
+## <param name="domain">
+## <summary>
+## Domain allowed access.
+## </summary>
+## </param>
+#
+interface(`tabrmd_create_unix_stream_sockets',`
+ gen_require(`
+ type tabrmd_t;
+ ')
+
+ allow $1 tabrmd_t:unix_stream_socket create_stream_socket_perms;
+')
+
+########################################
+## <summary>
+## Send messages to and from
+## tabrmd over DBUS.
+## </summary>
+## <param name="domain">
+## <summary>
+## Domain allowed access.
+## </summary>
+## </param>
+#
+interface(`tabr,d_dbus_chat',`
+ gen_require(`
+ type tabrmd_t;
+ class dbus send_msg;
+ ')
+
+ allow $1 tabrmd_t:dbus send_msg;
+ allow tabrmd_t $1:dbus send_msg;
+')
+
--
2.39.0

@ -1,29 +0,0 @@
From 64994388056b9b8c687eef3bc6030f2f40888440 Mon Sep 17 00:00:00 2001
From: Patrik Koncity <pkoncity@redhat.com>
Date: Mon, 9 Jan 2023 12:30:42 +0100
Subject: [PATCH 2/2] Fix in SELinux interface file a typo
In name of interface in SELinux policy is
typo issue.
Signed-off-by: Patrik Koncity <pkoncity@redhat.com>
---
selinux/tabrmd.if | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/selinux/tabrmd.if b/selinux/tabrmd.if
index c04eca0..81c7853 100644
--- a/selinux/tabrmd.if
+++ b/selinux/tabrmd.if
@@ -29,7 +29,7 @@ interface(`tabrmd_create_unix_stream_sockets',`
## </summary>
## </param>
#
-interface(`tabr,d_dbus_chat',`
+interface(`tabrmd_dbus_chat',`
gen_require(`
type tabrmd_t;
class dbus send_msg;
--
2.39.0

@ -6,16 +6,14 @@
Name: tpm2-abrmd-selinux Name: tpm2-abrmd-selinux
Version: 2.3.1 Version: 2.3.1
Release: 7%{?dist} Release: 13%{?dist}
Summary: SELinux policies for tpm2-abrmd Summary: SELinux policies for tpm2-abrmd
License: BSD License: BSD-2-Clause
URL: https://github.com/tpm2-software/tpm2-abrmd URL: https://github.com/tpm2-software/tpm2-abrmd
Source0: https://github.com/tpm2-software/tpm2-abrmd/archive/%{version}/tpm2-abrmd-%{version}.tar.gz Source0: https://github.com/tpm2-software/tpm2-abrmd/archive/%{version}/tpm2-abrmd-%{version}.tar.gz
Patch0: selinux-allow-fwupd-to-communicate-with-tpm2-abrmd.patch Patch0: selinux-allow-fwupd-to-communicate-with-tpm2-abrmd.patch
Patch1: 0001-Add-new-interfaces-for-communication-with-keylime.patch
Patch2: 0002-Fix-in-SELinux-interface-file-a-typo.patch
BuildArch: noarch BuildArch: noarch
Requires: selinux-policy >= %{selinux_policyver} Requires: selinux-policy >= %{selinux_policyver}
@ -28,7 +26,11 @@ BuildRequires: selinux-policy-%{selinuxtype}
Requires(post): selinux-policy-base >= %{selinux_policyver} Requires(post): selinux-policy-base >= %{selinux_policyver}
Requires(post): libselinux-utils Requires(post): libselinux-utils
Requires(post): policycoreutils Requires(post): policycoreutils
%if 0%{?fedora} || 0%{?rhel} >= 8
Requires(post): policycoreutils-python-utils Requires(post): policycoreutils-python-utils
%else
Requires(post): policycoreutils-python
%endif
%description %description
SELinux policy modules for tpm2-abrmd. SELinux policy modules for tpm2-abrmd.
@ -73,20 +75,39 @@ fi
%{_datadir}/selinux/devel/include/%{moduletype}/%{modulename}.if %{_datadir}/selinux/devel/include/%{moduletype}/%{modulename}.if
%changelog %changelog
* Fri Jan 6 2023 Štěpán Horáček <shoracek@redhat.com> - 2.3.1-7 * Tue Oct 29 2024 Troy Dawson <tdawson@redhat.com> - 2.3.1-13
- Include interface for Keylime - Bump release for October 2024 mass rebuild:
Resolves: rhbz#2157894 Resolves: RHEL-64018
* Tue Aug 10 2021 Mohan Boddu <mboddu@redhat.com> - 2.3.1-6 * Fri Oct 25 2024 MSVSphere Packaging Team <packager@msvsphere-os.ru> - 2.3.1-12
- Rebuilt for IMA sigs, glibc 2.34, aarch64 flags - Rebuilt for MSVSphere 10
Related: rhbz#1991688
* Fri Apr 16 2021 Mohan Boddu <mboddu@redhat.com> - 2.3.1-5 * Mon Jun 24 2024 Troy Dawson <tdawson@redhat.com> - 2.3.1-12
- Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937 - Bump release for June 2024 mass rebuild
* Wed Feb 17 2021 Jerry Snitselaar <jsnitsel@redhat.com> - 2.3.1-4 * Mon Feb 19 2024 Yaakov Selkowitz <yselkowi@redhat.com> - 2.3.1-11
- Fix dependency. - Fix policycoreutils-python-utils dependency for RHEL 8+
Resolves: rhbz#1929701
* Sat Jan 27 2024 Fedora Release Engineering <releng@fedoraproject.org> - 2.3.1-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Tue Sep 26 2023 Štěpán Horáček <shoracek@redhat.com> - 2.3.1-9
- Migrate license to SPDX
* Sat Jul 22 2023 Fedora Release Engineering <releng@fedoraproject.org> - 2.3.1-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Sat Jan 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 2.3.1-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 2.3.1-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Sat Jan 22 2022 Fedora Release Engineering <releng@fedoraproject.org> - 2.3.1-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 2.3.1-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org> - 2.3.1-3 * Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org> - 2.3.1-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild

Loading…
Cancel
Save