public inbox for gentoo-commits@lists.gentoo.org
 help / color / mirror / Atom feed
From: "Jason Zaman" <perfinion@gentoo.org>
To: gentoo-commits@lists.gentoo.org
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: /
Date: Sun, 10 Feb 2019 04:14:46 +0000 (UTC)	[thread overview]
Message-ID: <1549771885.744101042e9ae8eab4f942963b64dcaf5f2c738a.perfinion@gentoo> (raw)

commit:     744101042e9ae8eab4f942963b64dcaf5f2c738a
Author:     Chris PeBenito <pebenito <AT> ieee <DOT> org>
AuthorDate: Fri Feb  1 20:03:42 2019 +0000
Commit:     Jason Zaman <perfinion <AT> gentoo <DOT> org>
CommitDate: Sun Feb 10 04:11:25 2019 +0000
URL:        https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=74410104

Update Changelog and VERSION for release.

Signed-off-by: Jason Zaman <jason <AT> perfinion.com>

 Changelog | 234 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 VERSION   |   2 +-
 2 files changed, 235 insertions(+), 1 deletion(-)

diff --git a/Changelog b/Changelog
index 116e228a..75d5fae0 100644
--- a/Changelog
+++ b/Changelog
@@ -1,3 +1,237 @@
+* Fri Feb 01 2019 Chris PeBenito <pebenito@ieee.org> - 2.20190201
+Alexander Miroshnichenko (16):
+      Add signal_perms setpgid setsched permissions to syncthing_t.
+      Add corecmd_exec_bin permissions to syncthing_t.
+      Allow syncthing_t to read network state.
+      Allow syncthing_t to execute ifconfig/iproute2.
+      Add required permissions for nsd_t to be able running.
+      Add nsd_admin interface to sysadm.te.
+      Add map permission to lvm_t on lvm_metadata_t.
+      Add comment for map on lvm_metadata_t.
+      Remove syncthing tunable_policy.
+      Remove unneeded braces from nsd.te.
+      Add new interface fs_rmw_hugetlbfs_files.
+      Add map permission for postgresql_t to postgresql_tmp_t files.
+      Add dovecot_can_connect_db boolean.
+      fs_mmap_rw_hugetlbfs_files is a more appropriate name for the interface
+      Add hostapd service module
+      minor updates redis module to be able to start the app
+
+Chris PeBenito (85):
+      mozilla, devices, selinux, xserver, init, iptables: Module version bump.
+      devices: Module version bump.
+      misc_patterns.spt: Remove unnecessary brackets.
+      ipsec: Module version bump.
+      fstools: Module version bump.
+      corecommands: Module version bump.
+      xserver: Module version bump.
+      Merge pull request #1 from bigon/fix-sepolgen-ifgen
+      Remove unused translate permission in context userspace class.
+      logrotate: Module version bump.
+      miscfiles: Module version bump.
+      Merge pull request #3 from bigon/xdp-socket
+      obj_perm_sets.spt: Add xdp_socket to socket_class_set.
+      clamav, ssh, init: Module version bump.
+      amavis, apache, clamav, exim, mta, udev: Module version bump.
+      dnsmasq: Whitespace fix in file contexts.
+      dnsmasq: Reorder lines in file contexts.
+      Merge branch 'master' of https://github.com/bigon/refpolicy
+      Merge branch 'resolved' of https://github.com/bigon/refpolicy
+      Merge branch 'iscsi' of https://github.com/bigon/refpolicy
+      Various modules: Version bump.
+      dnsmasq: Module version bump.
+      Merge branch 'minissdpd' of https://github.com/bigon/refpolicy
+      cron, minissdpd, ntp, systemd: Module version bump.
+      dbus, xserver, init, logging, modutils: Module version bump.
+      Merge branch 'syncthing' of https://github.com/alexminder/refpolicy
+      syncthing: Whitespace change
+      Merge branch 'lvm' of https://github.com/alexminder/refpolicy
+      lvm, syncthing: Module version bump.
+      sigrok: Remove extra comments.
+      networkmanager: Add ICMPv6 comment
+      sysnetwork: Move optional block in sysnet_dns_name_resolve().
+      sysnetwork: Move lines.
+      dpkg: Rename dpkg_read_script_tmp_links().
+      apt, rpm: Remove and move lines to fix fc conflicts.
+      sudo: Whitespace fix.
+      many: Module version bumps for changes from Russell Coker.
+      systemd: Rename systemd_list_netif() to systemd_list_networkd_runtime().
+      init: Remove inadvertent merge.
+      Merge branch 'nsd' of https://github.com/alexminder/refpolicy
+      nsd: Merge two rules into one.
+      Merge branch 'ssh_dac_read_search' of
+         git://github.com/fishilico/selinux-refpolicy
+      Merge branch 'restorecond_getattr_cgroupfs' of
+         git://github.com/fishilico/selinux-refpolicy
+      Merge branch 'systemd-logind-getutxent' of
+         git://github.com/fishilico/selinux-refpolicy
+      various: Module version bump.
+      iptables: Module version bump.
+      Add CONTRIBUTING file.
+      kernel, systemd: Move lines.
+      kernel, jabber, ntp, init, logging, systemd: Module version bump.
+      Merge branch 'systemd-journald_units_symlinks' of
+         git://github.com/fishilico/selinux-refpolicy
+      init, logging: Module version bump.
+      Merge branch 'services_single_usr_bin' of
+         git://github.com/fishilico/selinux-refpolicy
+      Merge branch 'init_rename_pid_interfaces' of
+         git://github.com/fishilico/selinux-refpolicy
+      various: Module name bump.
+      Merge branch 'systemd-rfkill' of
+         git://github.com/fishilico/selinux-refpolicy
+      systemd: Whitespace change
+      systemd: Module version bump.
+      Merge branch 'restorecond-symlinks' of
+         git://github.com/fishilico/selinux-refpolicy
+      Merge branch 'add_comment' of git://github.com/DefenSec/refpolicy
+      usermanage, cron, selinuxutil: Module version bump.
+      logging, sysnetwork, systemd: Module version bump.
+      Merge branch 'restorecond-dontaudit-symlinks' of
+         git://github.com/fishilico/selinux-refpolicy
+      selinuxutil: Module version bump.
+      Merge branch 'dbus-dynamic-uid' of
+         git://github.com/fishilico/selinux-refpolicy
+      xserver: Move line
+      systemd: Move interface implementation.
+      various: Module version bump.
+      dpkg: Rename dpkg_nnp_transition() to dpkg_nnp_domtrans().
+      dpkg: Move interface implementations.
+      init: Rename init_read_generic_units_links() to
+         init_read_generic_units_symlinks().
+      init: Drop unnecessary userspace class dependence in
+         init_read_generic_units_symlinks().
+      chromium: Whitespace fixes.
+      chromium: Move line.
+      Merge branch 'dovecot' of git://github.com/alexminder/refpolicy
+      dovecot: Move lines.
+      various: Module version bump.
+      Merge branch 'postgres' of git://github.com/alexminder/refpolicy
+      filesystem, postgresql: Module version bump.
+      hostapd: Whitespace change.
+      hostapd: Move line.
+      various: Module version bump.
+      redis: Move line.
+      redis: Module version bump.
+      corecommands, staff, unprivuser, ssh, locallogin, systemd: Module version
+         bump.
+      Bump module versions for release.
+
+David Sugar (15):
+      Interface to allow reading of virus signature files.
+      Update CUSTOM_BUILDOPT
+      Add interface udev_run_domain
+      Allow clamd_t to read /proc/sys/crypt/fips_enabled
+      Interface to add domain allowed to be read by ClamAV for scanning.
+      Add interfaces to control clamav_unit_t systemd services
+      Allow clamd to use sent file descriptor
+      Add interfaces to control ntpd_unit_t systemd services
+      interface to enable/disable systemd_networkd service
+      Interface to read cron_system_spool_t
+      Allow X (xserver_t) to read /proc/sys/crypto/fips_enabled
+      Allow kmod to read /proc/sys/crypto/fips_enabled
+      Allow dbus to access /proc/sys/crypto/fips_enabled
+      Add missing require for 'daemon' attribute.
+      Allow auditctl_t to read bin_t symlinks.
+
+Dominick Grift (1):
+      unconfined: add a note about DBUS
+
+Guido Trentalancia (1):
+      Add sigrok contrib module
+
+Jagannathan Raman (1):
+      vhost: Add /dev/vhost-scsi device of type vhost_device_t.
+
+Jason Zaman (10):
+      selinux: compute_access_vector requires creating netlink_selinux_sockets
+      mozilla: xdg updates
+      xserver: label .cache/fontconfig as user_fonts_cache_t
+      Allow map xserver_misc_device_t for nvidia driver
+      iptables: fcontexts for 1.8.0
+      devices: introduce dev_dontaudit_read_sysfs
+      files: introduce files_dontaudit_read_etc_files
+      kernel: introduce kernel_dontaudit_read_kernel_sysctl
+      userdomain: introduce userdom_user_home_dir_filetrans_user_cert
+      Add chromium policy upstreamed from Gentoo
+
+Laurent Bigonville (10):
+      policy/support/obj_perm_sets.spt: modify indentation of mmap_file_perms to
+         make sepolgen-ifgen happy
+      Add xdp_socket security class and access vectors
+      irqbalance now creates an abstract socket
+      Allow semanage_t to connect to system D-Bus bus
+      Allow ntpd_t to read init state
+      Add systemd_dbus_chat_resolved() interface
+      Allow sysnet_dns_name_resolve() to use resolved to resolve DNS names
+      Allow systemd_resolved_t to bind to port 53 and use net_raw
+      Allow iscsid_t to create a netlink_iscsi_socket
+      Allow minissdpd_t to create a unix_stream_socket
+
+Luis Ressel (7):
+      corecommands: Fix /usr/share/apr* fc
+      xserver: Allow user fonts (and caches) to be mmap()ed.
+      Add fc for /var/lib/misc/logrotate.status
+      Realign logrotate.fc, remove an obvious comment
+      miscfiles: Label /usr/share/texmf*/fonts/ as fonts_t
+      services/ssh: Don't audit accesses from ssh_t to /dev/random
+      system/init: Give init_spec_daemon_domain()s the "daemon" attribute
+
+Lukas Vrabec (1):
+      Improve domain_transition_pattern to allow mmap entrypoint bin file.
+
+Nicolas Iooss (11):
+      fstools: label e2mmpstatus as fsadm_exec_t
+      ssh: use dac_read_search instead of dac_override
+      selinuxutil: allow restorecond to try counting the number of files in
+         cgroup fs
+      systemd: allow systemd-logind to use getutxent()
+      Allow systemd-journald to read systemd unit symlinks
+      Label service binaries in /usr/bin like /usr/sbin
+      init: rename *_pid_* interfaces to use "runtime"
+      systemd: add policy for systemd-rfkill
+      selinuxutil: allow restorecond to read symlinks
+      selinuxutil: restorecond is buggy when it dereferencies symlinks
+      dbus: allow using dynamic UID
+
+Petr Vorel (1):
+      dnsmasq: Require log files to have .log suffix
+
+Russell Coker (19):
+      misc services patches
+      misc interfaces
+      last misc stuff
+      systemd related interfaces
+      systemd misc
+      missing from previous
+      cron trivial
+      mls stuff
+      logging
+      some little stuff
+      trivial system cronjob
+      another trivial
+      more tiny stuff
+      map systemd private dirs
+      tiny stuff for today
+      yet more tiny stuff
+      yet another little patch
+      chromium
+      more misc stuff
+
+Sugar, David (9):
+      Allow greeter to start dbus
+      pam_faillock creates files in /run/faillock
+      Add interface to get status of iptables service
+      Add interface to start/stop iptables service
+      label journald configuraiton files syslog_conf_t
+      Interface with systemd_hostnamed over dbus to set hostname
+      Modify type for /etc/hostname
+      Add interface clamav_run
+      Add interface to read journal files
+
+Yuli Khodorkovskiy (1):
+      ipsec: add missing permissions for pluto
+
 * Sun Jul 01 2018 Chris PeBenito <pebenito@ieee.org> - 2.20180701
 Chris PeBenito (28):
       Enable cgroup_seclabel and nnp_nosuid_transition.

diff --git a/VERSION b/VERSION
index b40612cc..b93d30a8 100644
--- a/VERSION
+++ b/VERSION
@@ -1 +1 @@
-2.20180701
+2.20190201


             reply	other threads:[~2019-02-10  4:15 UTC|newest]

Thread overview: 103+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2019-02-10  4:14 Jason Zaman [this message]
  -- strict thread matches above, loose matches on Subject: below --
2025-03-08 23:55 [gentoo-commits] proj/hardened-refpolicy:master commit in: / Jason Zaman
2025-03-08 23:55 Jason Zaman
2024-09-22  0:03 Jason Zaman
2024-09-22  0:03 Jason Zaman
2024-03-01 19:56 Kenton Groombridge
2024-03-01 19:56 Kenton Groombridge
2024-03-01 19:56 Kenton Groombridge
2024-03-01 19:56 Kenton Groombridge
2024-03-01 19:56 Kenton Groombridge
2023-02-10 20:30 Kenton Groombridge
2022-03-31  3:31 Jason Zaman
2022-03-31  3:31 Jason Zaman
2022-03-31  3:31 Jason Zaman
2022-03-31  3:31 Jason Zaman
2021-11-11 21:27 Jason Zaman
2021-04-03  3:10 Jason Zaman
2021-02-07  3:21 Jason Zaman
2021-02-07  3:20 Jason Zaman
2021-02-07  3:20 Jason Zaman
2021-02-07  3:20 Jason Zaman
2021-02-07  3:20 Jason Zaman
2021-02-07  3:20 Jason Zaman
2021-02-07  3:20 Jason Zaman
2021-02-07  3:20 Jason Zaman
2021-01-11  1:27 Jason Zaman
2020-10-13  3:02 Jason Zaman
2019-12-16 17:48 Jason Zaman
2019-07-13  7:01 Jason Zaman
2019-07-13  7:01 Jason Zaman
2018-07-08 11:47 Jason Zaman
2018-06-24  8:46 Jason Zaman
2018-03-25 10:29 Sven Vermeulen
2018-01-18 16:37 Sven Vermeulen
2017-06-13  8:25 Jason Zaman
2017-04-10 16:59 Sven Vermeulen
2017-03-30 17:06 Jason Zaman
2017-03-30 17:06 Jason Zaman
2017-03-02 10:17 Sven Vermeulen
2017-02-27 10:50 Jason Zaman
2017-02-25 16:58 Jason Zaman
2017-02-21  7:11 Jason Zaman
2017-02-21  7:11 Jason Zaman
2017-02-05  6:29 Jason Zaman
2017-01-23 15:44 Jason Zaman
2017-01-23 15:44 Jason Zaman
2017-01-23 15:44 Jason Zaman
2017-01-13 18:43 Sven Vermeulen
2017-01-13 18:43 Sven Vermeulen
2017-01-13 18:43 Sven Vermeulen
2016-12-06 13:39 Jason Zaman
2016-10-24 16:02 [gentoo-commits] proj/hardened-refpolicy:swift " Sven Vermeulen
2016-10-24 16:02 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2016-10-24 16:02 [gentoo-commits] proj/hardened-refpolicy:swift " Sven Vermeulen
2016-10-24 16:02 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2016-10-24 16:02 Sven Vermeulen
2016-08-31 16:38 Jason Zaman
2016-08-31 16:38 Jason Zaman
2016-05-13  5:37 Jason Zaman
2016-05-13  5:37 Jason Zaman
2015-12-17 16:10 Jason Zaman
2015-10-26  5:36 [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman
2015-10-26  5:48 ` [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman
2015-03-29  9:59 Jason Zaman
2015-02-15 17:39 Sven Vermeulen
2014-12-04  1:46 Jason Zaman
2014-11-27  8:31 Jason Zaman
2014-11-22 16:25 Sven Vermeulen
2014-09-21 14:08 [gentoo-commits] proj/hardened-refpolicy:mailinfra " Sven Vermeulen
2014-09-13  9:38 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2014-06-25 19:06 Sven Vermeulen
2014-03-17  8:24 Sven Vermeulen
2014-03-17  8:24 Sven Vermeulen
2014-03-17  8:24 Sven Vermeulen
2014-03-06 15:20 Sven Vermeulen
2014-01-19 19:01 Sven Vermeulen
2013-09-30 19:03 Sven Vermeulen
2013-09-30 19:03 Sven Vermeulen
2013-09-26 13:19 Sven Vermeulen
2013-09-23 13:31 Sven Vermeulen
2013-09-23  6:29 [gentoo-commits] proj/hardened-refpolicy:merge " Sven Vermeulen
2013-09-23 13:31 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2013-09-23  6:29 [gentoo-commits] proj/hardened-refpolicy:merge " Sven Vermeulen
2013-09-23 13:31 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2013-05-01 18:23 Sven Vermeulen
2013-05-01 18:23 Sven Vermeulen
2013-01-16 19:48 Sven Vermeulen
2012-12-08 12:41 Sven Vermeulen
2012-12-03 21:03 Sven Vermeulen
2012-12-03  9:35 Sven Vermeulen
2012-11-06 20:21 Sven Vermeulen
2012-10-27 11:06 Sven Vermeulen
2012-10-22 18:15 Sven Vermeulen
2012-10-17 17:41 Sven Vermeulen
2012-10-16 17:39 Sven Vermeulen
2012-10-16 17:39 Sven Vermeulen
2012-10-16 17:39 Sven Vermeulen
2012-10-06 17:14 Sven Vermeulen
2012-10-06 17:05 Sven Vermeulen
2012-10-06 17:05 Sven Vermeulen
2012-10-06 15:56 Sven Vermeulen
2012-10-06 15:56 Sven Vermeulen
2012-10-04 17:36 Sven Vermeulen
2012-10-04 17:36 Sven Vermeulen
2012-10-04 17:36 Sven Vermeulen
2012-10-02 18:11 Sven Vermeulen
2012-10-02 18:11 Sven Vermeulen
2012-09-27 18:05 Sven Vermeulen
2012-09-27 18:05 Sven Vermeulen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1549771885.744101042e9ae8eab4f942963b64dcaf5f2c738a.perfinion@gentoo \
    --to=perfinion@gentoo.org \
    --cc=gentoo-commits@lists.gentoo.org \
    --cc=gentoo-dev@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox