rpms/selinux-policy/F-12 policy-20100106.patch, 1.43, 1.44 selinux-policy.spec, 1.1028, 1.1029
Miroslav Grepl
mgrepl at fedoraproject.org
Wed Mar 3 14:24:09 UTC 2010
Author: mgrepl
Update of /cvs/pkgs/rpms/selinux-policy/F-12
In directory cvs1.fedora.phx.redhat.com:/tmp/cvs-serv12970
Modified Files:
policy-20100106.patch selinux-policy.spec
Log Message:
- Fixes for xserver from Dan Walsh
policy-20100106.patch:
config/appconfig-mcs/x_contexts | 109 ----
config/appconfig-mls/x_contexts | 109 ----
config/appconfig-standard/x_contexts | 109 ----
policy/flask/access_vectors | 55 +-
policy/flask/security_classes | 4
policy/modules/admin/consoletype.if | 4
policy/modules/admin/dmesg.fc | 1
policy/modules/admin/logrotate.te | 4
policy/modules/admin/logwatch.te | 5
policy/modules/admin/mcelog.fc | 2
policy/modules/admin/mcelog.if | 20
policy/modules/admin/mcelog.te | 31 +
policy/modules/admin/netutils.fc | 1
policy/modules/admin/netutils.te | 6
policy/modules/admin/prelink.te | 1
policy/modules/admin/quota.te | 1
policy/modules/admin/readahead.te | 2
policy/modules/admin/rpm.if | 60 ++
policy/modules/admin/rpm.te | 2
policy/modules/admin/smoltclient.te | 2
policy/modules/admin/usermanage.te | 6
policy/modules/admin/vbetool.te | 13
policy/modules/apps/cdrecord.te | 2
policy/modules/apps/chrome.te | 11
policy/modules/apps/execmem.if | 6
policy/modules/apps/firewallgui.te | 6
policy/modules/apps/gnome.fc | 9
policy/modules/apps/gnome.if | 81 ++-
policy/modules/apps/gnome.te | 8
policy/modules/apps/gpg.fc | 2
policy/modules/apps/gpg.te | 7
policy/modules/apps/java.if | 1
policy/modules/apps/java.te | 1
policy/modules/apps/kdumpgui.te | 4
policy/modules/apps/mozilla.fc | 1
policy/modules/apps/nsplugin.fc | 1
policy/modules/apps/nsplugin.if | 38 +
policy/modules/apps/nsplugin.te | 6
policy/modules/apps/openoffice.if | 1
policy/modules/apps/podsleuth.te | 1
policy/modules/apps/pulseaudio.fc | 2
policy/modules/apps/pulseaudio.if | 6
policy/modules/apps/pulseaudio.te | 17
policy/modules/apps/qemu.te | 1
policy/modules/apps/sambagui.te | 4
policy/modules/apps/sandbox.if | 54 +-
policy/modules/apps/sandbox.te | 49 +-
policy/modules/apps/slocate.te | 1
policy/modules/apps/vmware.if | 18
policy/modules/apps/vmware.te | 10
policy/modules/apps/wine.if | 5
policy/modules/apps/wine.te | 17
policy/modules/kernel/corecommands.fc | 5
policy/modules/kernel/corenetwork.if.in | 18
policy/modules/kernel/corenetwork.te.in | 6
policy/modules/kernel/devices.fc | 6
policy/modules/kernel/devices.if | 200 +++++++-
policy/modules/kernel/devices.te | 25 -
policy/modules/kernel/domain.if | 22
policy/modules/kernel/domain.te | 6
policy/modules/kernel/files.fc | 2
policy/modules/kernel/files.if | 334 +++++++++++---
policy/modules/kernel/files.te | 6
policy/modules/kernel/filesystem.if | 156 ++++++
policy/modules/kernel/filesystem.te | 12
policy/modules/kernel/kernel.if | 36 +
policy/modules/kernel/terminal.if | 247 ++++++++++
policy/modules/roles/auditadm.te | 2
policy/modules/roles/secadm.te | 2
policy/modules/roles/staff.te | 18
policy/modules/roles/sysadm.te | 5
policy/modules/roles/unconfineduser.fc | 5
policy/modules/roles/unconfineduser.te | 6
policy/modules/roles/xguest.te | 6
policy/modules/services/abrt.if | 5
policy/modules/services/abrt.te | 18
policy/modules/services/afs.te | 6
policy/modules/services/aisexec.fc | 2
policy/modules/services/aisexec.te | 8
policy/modules/services/amavis.te | 1
policy/modules/services/apache.fc | 9
policy/modules/services/apache.if | 48 ++
policy/modules/services/apache.te | 35 +
policy/modules/services/apcupsd.te | 2
policy/modules/services/arpwatch.te | 2
policy/modules/services/asterisk.te | 1
policy/modules/services/avahi.fc | 2
policy/modules/services/bind.if | 19
policy/modules/services/cachefilesd.fc | 28 +
policy/modules/services/cachefilesd.if | 41 +
policy/modules/services/cachefilesd.te | 146 ++++++
policy/modules/services/ccs.te | 6
policy/modules/services/chronyd.fc | 2
policy/modules/services/chronyd.te | 15
policy/modules/services/clogd.if | 24 -
policy/modules/services/clogd.te | 7
policy/modules/services/cobbler.fc | 5
policy/modules/services/cobbler.if | 156 ++++++
policy/modules/services/cobbler.te | 132 +++++
policy/modules/services/consolekit.te | 15
policy/modules/services/corosync.fc | 2
policy/modules/services/corosync.te | 9
policy/modules/services/cron.te | 9
policy/modules/services/cups.te | 7
policy/modules/services/dbus.if | 7
policy/modules/services/dcc.te | 2
policy/modules/services/devicekit.fc | 4
policy/modules/services/devicekit.te | 14
policy/modules/services/dhcp.if | 19
policy/modules/services/dhcp.te | 4
policy/modules/services/djbdns.if | 38 +
policy/modules/services/djbdns.te | 8
policy/modules/services/dnsmasq.fc | 2
policy/modules/services/dnsmasq.if | 38 +
policy/modules/services/dnsmasq.te | 8
policy/modules/services/dovecot.te | 6
policy/modules/services/exim.if | 18
policy/modules/services/fail2ban.if | 18
policy/modules/services/ftp.fc | 2
policy/modules/services/ftp.if | 37 +
policy/modules/services/ftp.te | 116 ++++
policy/modules/services/git.fc | 17
policy/modules/services/git.if | 466 +++++++++++++++----
policy/modules/services/git.te | 145 +++---
policy/modules/services/gpm.fc | 2
policy/modules/services/hal.te | 9
policy/modules/services/inn.te | 1
policy/modules/services/kerberos.if | 2
policy/modules/services/ldap.fc | 3
policy/modules/services/ldap.te | 7
policy/modules/services/lircd.te | 7
policy/modules/services/mailman.te | 1
policy/modules/services/memcached.te | 14
policy/modules/services/modemmanager.te | 2
policy/modules/services/mta.if | 38 +
policy/modules/services/mta.te | 1
policy/modules/services/munin.te | 1
policy/modules/services/mysql.te | 5
policy/modules/services/nagios.fc | 46 +
policy/modules/services/nagios.if | 28 +
policy/modules/services/nagios.te | 87 +++
policy/modules/services/networkmanager.fc | 1
policy/modules/services/networkmanager.te | 1
policy/modules/services/nis.fc | 5
policy/modules/services/nis.te | 8
policy/modules/services/nx.if | 18
policy/modules/services/openvpn.te | 4
policy/modules/services/plymouth.fc | 5
policy/modules/services/plymouth.if | 304 ------------
policy/modules/services/plymouth.te | 102 ----
policy/modules/services/plymouthd.fc | 9
policy/modules/services/plymouthd.if | 322 +++++++++++++
policy/modules/services/plymouthd.te | 105 ++++
policy/modules/services/policykit.te | 20
policy/modules/services/postfix.if | 37 +
policy/modules/services/postfix.te | 5
policy/modules/services/ppp.fc | 2
policy/modules/services/ppp.te | 8
policy/modules/services/prelude.te | 2
policy/modules/services/qmail.if | 18
policy/modules/services/rgmanager.if | 40 +
policy/modules/services/rgmanager.te | 58 ++
policy/modules/services/rhcs.fc | 9
policy/modules/services/rhcs.if | 58 ++
policy/modules/services/rhcs.te | 278 ++---------
policy/modules/services/ricci.te | 6
policy/modules/services/rpc.if | 1
policy/modules/services/rpc.te | 8
policy/modules/services/rsync.if | 38 +
policy/modules/services/samba.te | 18
policy/modules/services/sendmail.te | 4
policy/modules/services/setroubleshoot.te | 4
policy/modules/services/snmp.te | 4
policy/modules/services/snort.te | 1
policy/modules/services/spamassassin.if | 18
policy/modules/services/spamassassin.te | 6
policy/modules/services/ssh.if | 4
policy/modules/services/ssh.te | 84 ---
policy/modules/services/sssd.fc | 2
policy/modules/services/sssd.if | 85 ++-
policy/modules/services/sssd.te | 16
policy/modules/services/tftp.if | 20
policy/modules/services/tftp.te | 1
policy/modules/services/tgtd.te | 1
policy/modules/services/tuned.fc | 3
policy/modules/services/tuned.te | 15
policy/modules/services/ucspitcp.te | 5
policy/modules/services/usbmuxd.fc | 6
policy/modules/services/usbmuxd.if | 64 ++
policy/modules/services/usbmuxd.te | 49 ++
policy/modules/services/virt.if | 8
policy/modules/services/virt.te | 15
policy/modules/services/xserver.fc | 17
policy/modules/services/xserver.if | 711 +++++++++---------------------
policy/modules/services/xserver.te | 379 ++++++++-------
policy/modules/system/application.te | 12
policy/modules/system/daemontools.if | 62 ++
policy/modules/system/daemontools.te | 26 +
policy/modules/system/fstools.fc | 2
policy/modules/system/hostname.te | 3
policy/modules/system/hotplug.te | 4
policy/modules/system/init.if | 35 +
policy/modules/system/init.te | 27 +
policy/modules/system/ipsec.te | 11
policy/modules/system/iptables.if | 10
policy/modules/system/iptables.te | 6
policy/modules/system/iscsi.fc | 3
policy/modules/system/iscsi.te | 10
policy/modules/system/libraries.fc | 19
policy/modules/system/locallogin.te | 19
policy/modules/system/logging.fc | 7
policy/modules/system/logging.if | 18
policy/modules/system/logging.te | 10
policy/modules/system/lvm.fc | 1
policy/modules/system/lvm.te | 3
policy/modules/system/miscfiles.fc | 5
policy/modules/system/miscfiles.if | 37 +
policy/modules/system/modutils.te | 2
policy/modules/system/mount.if | 4
policy/modules/system/mount.te | 16
policy/modules/system/selinuxutil.if | 21
policy/modules/system/selinuxutil.te | 1
policy/modules/system/sysnetwork.fc | 1
policy/modules/system/sysnetwork.if | 4
policy/modules/system/sysnetwork.te | 3
policy/modules/system/udev.te | 5
policy/modules/system/unconfined.if | 2
policy/modules/system/userdomain.fc | 1
policy/modules/system/userdomain.if | 42 +
policy/modules/system/xen.if | 2
policy/modules/system/xen.te | 22
policy/support/obj_perm_sets.spt | 8
policy/users | 2
233 files changed, 5238 insertions(+), 2267 deletions(-)
Index: policy-20100106.patch
===================================================================
RCS file: /cvs/pkgs/rpms/selinux-policy/F-12/policy-20100106.patch,v
retrieving revision 1.43
retrieving revision 1.44
diff -u -p -r1.43 -r1.44
--- policy-20100106.patch 3 Mar 2010 11:48:06 -0000 1.43
+++ policy-20100106.patch 3 Mar 2010 14:24:08 -0000 1.44
@@ -10243,8 +10243,8 @@ diff -b -B --ignore-all-space --exclude-
+')
diff -b -B --ignore-all-space --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/usbmuxd.te serefpolicy-3.6.32/policy/modules/services/usbmuxd.te
--- nsaserefpolicy/policy/modules/services/usbmuxd.te 1970-01-01 01:00:00.000000000 +0100
-+++ serefpolicy-3.6.32/policy/modules/services/usbmuxd.te 2010-02-11 18:39:18.455708622 +0100
-@@ -0,0 +1,48 @@
++++ serefpolicy-3.6.32/policy/modules/services/usbmuxd.te 2010-03-03 15:06:35.322862650 +0100
+@@ -0,0 +1,49 @@
+
+policy_module(usbmuxd,1.0.0)
+
@@ -10256,6 +10256,7 @@ diff -b -B --ignore-all-space --exclude-
+type usbmuxd_t;
+type usbmuxd_exec_t;
+application_domain(usbmuxd_t, usbmuxd_exec_t)
++role system_r types usbmuxd_t;
+
+type usbmuxd_var_run_t;
+files_pid_file(usbmuxd_var_run_t)
Index: selinux-policy.spec
===================================================================
RCS file: /cvs/pkgs/rpms/selinux-policy/F-12/selinux-policy.spec,v
retrieving revision 1.1028
retrieving revision 1.1029
diff -u -p -r1.1028 -r1.1029
--- selinux-policy.spec 3 Mar 2010 11:48:06 -0000 1.1028
+++ selinux-policy.spec 3 Mar 2010 14:24:09 -0000 1.1029
@@ -202,13 +202,13 @@ Based off of reference policy: Checked o
%setup -n serefpolicy-%{version} -q
%patch1 -p1
%patch2 -p1
+
+%install
mkdir selinux_config
for i in %{SOURCE1} %{SOURCE2} %{SOURCE3} %{SOURCE4} %{SOURCE5} %{SOURCE6} %{SOURCE8} %{SOURCE9} %{SOURCE10} %{SOURCE11} %{SOURCE12} %{SOURCE13} %{SOURCE14} %{SOURCE15} %{SOURCE16} %{SOURCE17} %{SOURCE18} %{SOURCE19} %{SOURCE20} %{SOURCE21} %{SOURCE22} %{SOURCE23} %{SOURCE24} %{SOURCE25};do
cp $i selinux_config
done
tar zxvf selinux_config/config.tgz
-
-%install
# Build targeted policy
%{__rm} -fR %{buildroot}
mkdir -p %{buildroot}%{_mandir}
More information about the scm-commits
mailing list