All of lore.kernel.org
 help / color / mirror / Atom feed
From: Petr Lautrbach <lautrbach@redhat.com>
To: selinux@vger.kernel.org
Subject: ANN: SELinux userspace 3.9-rc1 release
Date: Wed, 11 Jun 2025 21:35:05 +0200	[thread overview]
Message-ID: <87frg6dqc6.fsf@redhat.com> (raw)

Hello!

The 3.9-rc1 release for the SELinux userspace is now available at:

https://github.com/SELinuxProject/selinux/releases/tag/3.9-rc1
https://github.com/SELinuxProject/selinux/wiki/Releases

I signed all tarballs using my gpg key, see .asc files.
You can download the public key from
https://github.com/bachradsusi.gpg

Thanks to all the contributors, reviewers, testers and reporters!

If you miss something important not mentioned bellow, please let me
know.

User-visible changes
--------------------

* Support static-only builds with DISABLE_SHARED=y

* Add restore option to modify user and role portions

* setfiles: Add -U option to modify user and role portions

* semanage.conf: Add relabel_store config option

* semodule: Add [-g PATH |--config=PATH] for an alternate path for the semanage config

* libselinux: Fix local literal fcontext definitions priority

* libselinux: Fix order for path substitutions

* Bug fixes


Shortlog of the changes since 3.8.1 release
-------------------------------------------
Alyssa Ross (2):
      Support static-only builds
      libselinux: be careful with non-portable LFS macro

Christian Göttsche (18):
      checkpolicy: rework cleanup in define_te_avtab_xperms_helper()
      checkpolicy: free left hand conditional expression on error
      checkpolicy: abort on mismatched declarations
      checkpolicy: perform cleanup on error in define_filename_trans()
      libselinux: add restore option to modify user and role portions
      setfiles: add option to modify user and role portions
      libselinux: introduce context_to_str(3)
      mcstrans: make use of context_to_str(3)
      libselinux: constify global strings
      libselinux: use local instead of global error buffer
      libselinux: initialize regex arch string in a thread safe way
      libselinux: limit fcontext regex path length
      checkpolicy: free ebitmap on error in define_compute_type_helper()
      libselinux: limit node depth while parsing compiled fcontexts
      libsemanage: fix handling errors during child execution
      semanage: improve -e documentation and fix delete operation
      libselinux: prioritize local literal fcontext definitions
      libselinux: retain LIFO order for path substitutions

Daniel Burgener (1):
      Switch from bison name-prefix to api.prefix

Inseob Kim (6):
      libsepol: Fix markers for info nodes w/o children
      libsepol: Allow booleanif to have info nodes
      libsepol: Make line markers of rules configurable
      checkpolicy: Support line markers for allow rules
      checkmodule: Support line markers for allow rules
      checkpolicy: Allow lineno > 1 for source file line

James Carter (1):
      libselinux: Do not inline compile_regex()

Petr Lautrbach (2):
      README: update subscribe information
      Update VERSIONs to 3.9-rc1 for release.

Rahul Sandhu (1):
      libsemanage: create semanage_basename to ensure posix compliance

Robert Marko (1):
      policycoreutils: run_init: define _GNU_SOURCE

Stephen Smalley (1):
      libsepol,checkpolicy: introduce neveraudit types

Thiébaud Weksteen (1):
      libselinux: warn on identical duplicate properties

Tristan Ross (3):
      libsemanage: add relabel_store config option
      libsemanage: add semanage_handle_create_with_path
      semodule: add config argument

наб (2):
      Insert -I../../libselinux/include and -L../../libselinux/src into subprograms where needed
      Inject matchpathcon_filespec_add64() if !defined(__INO_T_MATCHES_INO64_T) instead of using __BITS_PER_LONG < 64 as proxy


                 reply	other threads:[~2025-06-11 19:35 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87frg6dqc6.fsf@redhat.com \
    --to=lautrbach@redhat.com \
    --cc=selinux@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.