rpms/selinux-policy/devel policy-20070219.patch, 1.38, 1.39 selinux-policy.spec, 1.425, 1.426
fedora-cvs-commits at redhat.com
fedora-cvs-commits at redhat.com
Wed Apr 4 20:46:09 UTC 2007
- Previous message (by thread): rpms/kernel/devel patch-2.6.21-rc5-git12.bz2.sign, NONE, 1.1 .cvsignore, 1.598, 1.599 kernel-2.6.spec, 1.3044, 1.3045 linux-2.6-debug-taint-vm.patch, 1.10, 1.11 sources, 1.561, 1.562 upstream, 1.489, 1.490 patch-2.6.21-rc5-git10.bz2.sign, 1.1, NONE
- Next message (by thread): rpms/anaconda/devel .cvsignore, 1.397, 1.398 anaconda.spec, 1.525, 1.526 sources, 1.522, 1.523
- Messages sorted by:
[ date ]
[ thread ]
[ subject ]
[ author ]
Author: dwalsh
Update of /cvs/dist/rpms/selinux-policy/devel
In directory cvs.devel.redhat.com:/tmp/cvs-serv19837
Modified Files:
policy-20070219.patch selinux-policy.spec
Log Message:
* Wed Apr 4 2007 Dan Walsh <dwalsh at redhat.com> 2.5.11-4
- Fixes for samba domain controller.
- Allow ConsoleKit to look at ttys
policy-20070219.patch:
Rules.modular | 12 +
policy/flask/access_vectors | 4
policy/global_booleans | 2
policy/global_tunables | 39 +++-
policy/mls | 31 ++-
policy/modules/admin/acct.te | 1
policy/modules/admin/acct.xml | 43 +++++
policy/modules/admin/alsa.xml | 43 +++++
policy/modules/admin/amanda.xml | 85 ++++++++++
policy/modules/admin/amtu.fc | 3
policy/modules/admin/amtu.if | 53 ++++++
policy/modules/admin/amtu.te | 56 ++++++
policy/modules/admin/amtu.xml | 36 ++++
policy/modules/admin/anaconda.xml | 3
policy/modules/admin/apt.xml | 95 +++++++++++
policy/modules/admin/backup.xml | 35 ++++
policy/modules/admin/bootloader.te | 2
policy/modules/admin/bootloader.xml | 79 +++++++++
policy/modules/admin/certwatch.xml | 37 ++++
policy/modules/admin/consoletype.te | 8
policy/modules/admin/consoletype.xml | 47 +++++
policy/modules/admin/ddcprobe.xml | 35 ++++
policy/modules/admin/dmesg.te | 1
policy/modules/admin/dmesg.xml | 24 ++
policy/modules/admin/dmidecode.xml | 35 ++++
policy/modules/admin/dpkg.xml | 125 +++++++++++++++
policy/modules/admin/firstboot.if | 18 ++
policy/modules/admin/firstboot.xml | 88 ++++++++++
policy/modules/admin/kudzu.te | 2
policy/modules/admin/kudzu.xml | 45 +++++
policy/modules/admin/logrotate.xml | 75 +++++++++
policy/modules/admin/logwatch.te | 2
policy/modules/admin/logwatch.xml | 23 ++
policy/modules/admin/netutils.te | 1
policy/modules/admin/rpm.fc | 3
policy/modules/admin/rpm.if | 65 +++++++
policy/modules/admin/rpm.te | 2
policy/modules/admin/su.if | 6
policy/modules/admin/usermanage.te | 42 +++--
policy/modules/apps/games.fc | 1
policy/modules/apps/gnome.if | 26 +++
policy/modules/apps/gpg.fc | 2
policy/modules/apps/loadkeys.if | 44 +----
policy/modules/apps/mozilla.if | 1
policy/modules/apps/slocate.te | 4
policy/modules/apps/usernetctl.te | 10 -
policy/modules/kernel/corecommands.fc | 7
policy/modules/kernel/corecommands.if | 20 ++
policy/modules/kernel/corenetwork.if.in | 54 ++++++
policy/modules/kernel/corenetwork.te.in | 18 +-
policy/modules/kernel/devices.if | 36 ++++
policy/modules/kernel/domain.if | 18 ++
policy/modules/kernel/domain.te | 46 +++++
policy/modules/kernel/files.fc | 1
policy/modules/kernel/files.if | 81 ++++++++-
policy/modules/kernel/filesystem.if | 39 ++++
policy/modules/kernel/filesystem.te | 11 +
policy/modules/kernel/kernel.if | 23 ++
policy/modules/kernel/kernel.te | 2
policy/modules/kernel/mls.if | 20 ++
policy/modules/kernel/mls.te | 3
policy/modules/kernel/selinux.if | 38 ++++
policy/modules/kernel/storage.if | 2
policy/modules/kernel/terminal.if | 2
policy/modules/kernel/terminal.te | 1
policy/modules/services/apache.fc | 14 -
policy/modules/services/apache.if | 161 +++++++++++++++++++
policy/modules/services/apache.te | 59 +++++++
policy/modules/services/apcupsd.fc | 9 +
policy/modules/services/apcupsd.if | 108 +++++++++++++
policy/modules/services/apcupsd.te | 81 +++++++++
policy/modules/services/automount.te | 2
policy/modules/services/ccs.te | 12 +
policy/modules/services/consolekit.fc | 1
policy/modules/services/consolekit.te | 28 ++-
policy/modules/services/cron.fc | 1
policy/modules/services/cron.if | 33 +---
policy/modules/services/cron.te | 51 ++++--
policy/modules/services/cups.te | 2
policy/modules/services/cvs.te | 2
policy/modules/services/cyrus.te | 5
policy/modules/services/dbus.if | 63 +++++++
policy/modules/services/dhcp.te | 2
policy/modules/services/djbdns.te | 5
policy/modules/services/dovecot.te | 5
policy/modules/services/ftp.te | 5
policy/modules/services/hal.fc | 6
policy/modules/services/hal.te | 130 +++++++++++++++
policy/modules/services/inetd.te | 5
policy/modules/services/kerberos.if | 58 ++-----
policy/modules/services/kerberos.te | 36 ++++
policy/modules/services/mta.if | 19 ++
policy/modules/services/mta.te | 2
policy/modules/services/networkmanager.te | 2
policy/modules/services/nis.if | 4
policy/modules/services/nscd.te | 10 +
policy/modules/services/ntp.te | 1
policy/modules/services/pegasus.if | 18 ++
policy/modules/services/pegasus.te | 6
policy/modules/services/postfix.if | 1
policy/modules/services/postfix.te | 8
policy/modules/services/ppp.te | 9 -
policy/modules/services/procmail.te | 1
policy/modules/services/pyzor.te | 1
policy/modules/services/radius.te | 4
policy/modules/services/rpc.if | 5
policy/modules/services/rsync.te | 1
policy/modules/services/samba.fc | 3
policy/modules/services/samba.if | 63 +++++++
policy/modules/services/samba.te | 77 +++++++++
policy/modules/services/sasl.te | 11 +
policy/modules/services/sendmail.if | 20 ++
policy/modules/services/smartmon.te | 1
policy/modules/services/snmp.te | 10 +
policy/modules/services/spamassassin.te | 7
policy/modules/services/squid.fc | 2
policy/modules/services/squid.if | 22 ++
policy/modules/services/squid.te | 12 +
policy/modules/services/ssh.if | 39 ++++
policy/modules/services/ssh.te | 5
policy/modules/services/xserver.te | 10 -
policy/modules/services/zabbix.fc | 4
policy/modules/services/zabbix.if | 87 ++++++++++
policy/modules/services/zabbix.te | 64 +++++++
policy/modules/system/application.fc | 1
policy/modules/system/application.if | 104 ++++++++++++
policy/modules/system/application.te | 14 +
policy/modules/system/authlogin.if | 83 ++++++++--
policy/modules/system/authlogin.te | 3
policy/modules/system/fstools.fc | 1
policy/modules/system/fstools.te | 1
policy/modules/system/fusermount.fc | 6
policy/modules/system/fusermount.if | 41 +++++
policy/modules/system/fusermount.te | 45 +++++
policy/modules/system/getty.te | 3
policy/modules/system/hostname.te | 14 +
policy/modules/system/init.if | 3
policy/modules/system/init.te | 35 +++-
policy/modules/system/ipsec.if | 20 ++
policy/modules/system/iptables.te | 4
policy/modules/system/libraries.fc | 8
policy/modules/system/libraries.te | 20 ++
policy/modules/system/locallogin.te | 7
policy/modules/system/logging.if | 21 ++
policy/modules/system/logging.te | 2
policy/modules/system/lvm.te | 5
policy/modules/system/modutils.te | 11 +
policy/modules/system/mount.fc | 3
policy/modules/system/mount.if | 37 ++++
policy/modules/system/mount.te | 64 +++++++
policy/modules/system/raid.te | 1
policy/modules/system/selinuxutil.fc | 1
policy/modules/system/selinuxutil.if | 5
policy/modules/system/selinuxutil.te | 68 +++-----
policy/modules/system/udev.fc | 2
policy/modules/system/udev.te | 11 +
policy/modules/system/unconfined.fc | 1
policy/modules/system/unconfined.if | 10 -
policy/modules/system/unconfined.te | 24 ++
policy/modules/system/userdomain.if | 246 ++++++++++++++++--------------
policy/modules/system/userdomain.te | 46 ++++-
policy/modules/system/xen.te | 35 ++++
policy/support/obj_perm_sets.spt | 12 +
163 files changed, 3823 insertions(+), 424 deletions(-)
Index: policy-20070219.patch
===================================================================
RCS file: /cvs/dist/rpms/selinux-policy/devel/policy-20070219.patch,v
retrieving revision 1.38
retrieving revision 1.39
diff -u -r1.38 -r1.39
--- policy-20070219.patch 4 Apr 2007 19:44:58 -0000 1.38
+++ policy-20070219.patch 4 Apr 2007 20:46:07 -0000 1.39
@@ -3034,11 +3034,11 @@
+
diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/apcupsd.fc serefpolicy-2.5.11/policy/modules/services/apcupsd.fc
--- nsaserefpolicy/policy/modules/services/apcupsd.fc 1969-12-31 19:00:00.000000000 -0500
-+++ serefpolicy-2.5.11/policy/modules/services/apcupsd.fc 2007-04-04 15:36:00.000000000 -0400
++++ serefpolicy-2.5.11/policy/modules/services/apcupsd.fc 2007-04-04 16:18:34.000000000 -0400
@@ -0,0 +1,9 @@
+
+/usr/sbin/apcupsd -- gen_context(system_u:object_r:apcupsd_exec_t,s0)
-+/var/log/apcupsd\.events\* -- gen_context(system_u:object_r:apcupsd_log_t,s0)
++/var/log/apcupsd\.events.* -- gen_context(system_u:object_r:apcupsd_log_t,s0)
+/var/run/apcupsd\.pid -- gen_context(system_u:object_r:apcupsd_var_run_t,s0)
+
+/var/www/apcupsd/multimon.cgi -- gen_context(system_u:object_r:httpd_apcupsd_cgi_script_exec_t,s0)
@@ -3301,7 +3301,7 @@
+/var/run/consolekit.pid -- gen_context(system_u:object_r:consolekit_var_run_t,s0)
diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/consolekit.te serefpolicy-2.5.11/policy/modules/services/consolekit.te
--- nsaserefpolicy/policy/modules/services/consolekit.te 2007-03-20 23:38:12.000000000 -0400
-+++ serefpolicy-2.5.11/policy/modules/services/consolekit.te 2007-04-04 13:46:37.000000000 -0400
++++ serefpolicy-2.5.11/policy/modules/services/consolekit.te 2007-04-04 16:22:50.000000000 -0400
@@ -10,13 +10,16 @@
type consolekit_exec_t;
init_daemon_domain(consolekit_t, consolekit_exec_t)
@@ -3321,7 +3321,7 @@
allow consolekit_t self:fifo_file rw_fifo_file_perms;
allow consolekit_t self:unix_stream_socket create_stream_socket_perms;
-@@ -27,6 +30,8 @@
+@@ -27,21 +30,38 @@
domain_use_interactive_fds(consolekit_t)
files_read_etc_files(consolekit_t)
@@ -3330,8 +3330,16 @@
libs_use_ld_so(consolekit_t)
libs_use_shared_libs(consolekit_t)
-@@ -38,10 +43,23 @@
- term_dontaudit_use_generic_ptys(consolekit_t)
+
+ miscfiles_read_localization(consolekit_t)
+
++term_use_all_terms(consolekit_t)
++
+ ifdef(`targeted_policy',`
+- term_dontaudit_use_unallocated_ttys(consolekit_t)
+- term_dontaudit_use_generic_ptys(consolekit_t)
++ term_use_unallocated_ttys(consolekit_t)
++ term_use_generic_ptys(consolekit_t)
')
+# pid file
Index: selinux-policy.spec
===================================================================
RCS file: /cvs/dist/rpms/selinux-policy/devel/selinux-policy.spec,v
retrieving revision 1.425
retrieving revision 1.426
diff -u -r1.425 -r1.426
--- selinux-policy.spec 4 Apr 2007 19:44:58 -0000 1.425
+++ selinux-policy.spec 4 Apr 2007 20:46:07 -0000 1.426
@@ -17,7 +17,7 @@
Summary: SELinux policy configuration
Name: selinux-policy
Version: 2.5.11
-Release: 3%{?dist}
+Release: 4%{?dist}
License: GPL
Group: System Environment/Base
Source: serefpolicy-%{version}.tgz
@@ -358,6 +358,10 @@
%endif
%changelog
+* Wed Apr 4 2007 Dan Walsh <dwalsh at redhat.com> 2.5.11-4
+- Fixes for samba domain controller.
+- Allow ConsoleKit to look at ttys
+
* Tue Apr 3 2007 Dan Walsh <dwalsh at redhat.com> 2.5.11-3
- Fix interface call
- Previous message (by thread): rpms/kernel/devel patch-2.6.21-rc5-git12.bz2.sign, NONE, 1.1 .cvsignore, 1.598, 1.599 kernel-2.6.spec, 1.3044, 1.3045 linux-2.6-debug-taint-vm.patch, 1.10, 1.11 sources, 1.561, 1.562 upstream, 1.489, 1.490 patch-2.6.21-rc5-git10.bz2.sign, 1.1, NONE
- Next message (by thread): rpms/anaconda/devel .cvsignore, 1.397, 1.398 anaconda.spec, 1.525, 1.526 sources, 1.522, 1.523
- Messages sorted by:
[ date ]
[ thread ]
[ subject ]
[ author ]
More information about the fedora-cvs-commits
mailing list