[PATCH] selinux-policy: update version to v2.8

Dominick Grift dominick.grift at defensec.nl
Thu May 29 04:02:19 PDT 2025


Ignore this please. Most likely has incorrect package mirror hash.

Dominick Grift <dominick.grift at defensec.nl> writes:

> Changes since v2.6
>
> 3e93844 related to bpi-r4 Linux 6.12
> 449cb74 sysagent: use logintermdev (no differences)
> 20ad31d unlabeled/invalid: these are relative to .
> 9c85622 iproute2sysagent: ss
> c2a7863 README
> 6d7ad1c adds swaptools swapfile
> 5b69b63 rpcd related to luci mount tab
> afeee67 hotplugcall: iwinfo
> 6ca7996 adds ttyGS0 tty login serial
> f8b2fba wget: read shouldnt be needed
> e2faf89 bmon adds ~/.bmonrc
> 5ede79b adds seccompconffile
> 3034b20 some comments
> 9b4b44e loginsysagent: loose end
> fe0973c README
> ea06908 loginsysagent
> 2405c46 loginsysagent
> 9413988 loginsysagent: adds skel for wrapper retry
> 22929cb Revert "login.cil: skel for login.sh wrapper"
> fbcccf4 login.cil: skel for login.sh wrapper
> 1addde4 Revert "iproute2 ip protocol not supported"
> f38fd20 iproute2 ip protocol not supported
> 5abde97 openssl for openssl s_client -connect ip:port
> 642ddd9 ttyd
> be00125 iproute2 ip
> 1fbba89 iproute2 ip
> 342c981 no cap_userns
> d241cfb iproute2 ip netns related
> 6778504 iproute2 ip netns related
> 491d3c4 iproute2 ip
> d2dce16 iproute ip
> 8b43b1c iproute2 ip basic netns support
> 107e63f iproute2 ip
> 1b39905 README: looks like this is a no-go
> b081dba acme note about expected removal of /tmp/run/acme/lock
> 4df51dd haproxy
> ee825c8 coreutils: these dont have busybox equivalent
> 46f4a8b Revert "ucode: needed for custom rules in /etc/nftables.d"
> 048337a ucode: needed for custom rules in /etc/nftables.d
> 76b5a69 haproxy pid file
> c90f840 openssl s_client -connect
> dbbe475 haproxy local logging
> 7f58831 haproxy /etc/haproxy for stuff like proxy maps
> 050afc7 acmesysagent
> 031e0f3 README
> 2acf047 haproxy and iproute2
> c5d1ce4 README
> b9304a5 haproxy whitespace
> b07c524 adds haproxy and iproute2 ss rules
> 9bc53b1 acme
> 6031379 openssl
> 8d6aaba adds sysfsutils skel
> fc24d0c README
> 12cc1d4 openssl
> 79cf372 apk leaks memfd
> 9912075 adds socat dataexecfile
> 011bf9a adds wget (consolidate uclient-fetch)
> 0ba70c0 adds ftp reserved ports
> 5b35e96 README
> bd02d73 README
> 4f6895f netifd comment fix
> bd46c1f coreutils
> ad13688 dnsmasq: more robust filecon
> d5d6dd3 README
> 74f73d1 fwtool: do_stage2: online sysupgrade sdcard
> 8251117 README
> badfb57 iw/tmux socket creation is implied in macros
> 5663f89 iwsysagent and readme
> 6815a6c README
> bde5a56 README
> 6b89f0a hotplug and netif unconfined.exec.file underline "trusted"
> 862da9b unknown netifd protocols with netif.unconfined.exec.file
>
> Signed-off-by: Dominick Grift <dominick.grift at defensec.nl>
> ---
>  package/system/selinux-policy/Makefile | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/package/system/selinux-policy/Makefile b/package/system/selinux-policy/Makefile
> index b3a3165b49..56b38b7cee 100644
> --- a/package/system/selinux-policy/Makefile
> +++ b/package/system/selinux-policy/Makefile
> @@ -8,8 +8,8 @@ include $(TOPDIR)/rules.mk
>  PKG_NAME:=selinux-policy
>  PKG_SOURCE_PROTO:=git
>  PKG_SOURCE_URL:=https://git.defensec.nl/selinux-policy.git
> -PKG_VERSION:=2.6
> -PKG_MIRROR_HASH:=3604ce2d2874f58a7fc03998daa81628fca43aa8ac0a7436f07612365b6ce7ad
> +PKG_VERSION:=2.8
> +PKG_MIRROR_HASH:=e0abeefc23c5b549595170065e31ca63c631bf0a0d177767d058d7f0bb57542f
>  PKG_SOURCE_VERSION:=v$(PKG_VERSION)
>  PKG_BUILD_DEPENDS:=secilc/host policycoreutils/host

-- 
gpg --locate-keys dominick.grift at defensec.nl (wkd)
Key fingerprint = FCD2 3660 5D6B 9D27 7FC6  E0FF DA7E 521F 10F6 4098
Dominick Grift
Mastodon: @kcinimod at defensec.nl



More information about the openwrt-devel mailing list