From: "Jason Zaman" <perfinion@gentoo.org>
To: gentoo-commits@lists.gentoo.org
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: /
Date: Sun, 10 Feb 2019 04:14:46 +0000 (UTC) [thread overview]
Message-ID: <1549771885.744101042e9ae8eab4f942963b64dcaf5f2c738a.perfinion@gentoo> (raw)
commit: 744101042e9ae8eab4f942963b64dcaf5f2c738a
Author: Chris PeBenito <pebenito <AT> ieee <DOT> org>
AuthorDate: Fri Feb 1 20:03:42 2019 +0000
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
CommitDate: Sun Feb 10 04:11:25 2019 +0000
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=74410104
Update Changelog and VERSION for release.
Signed-off-by: Jason Zaman <jason <AT> perfinion.com>
Changelog | 234 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
VERSION | 2 +-
2 files changed, 235 insertions(+), 1 deletion(-)
diff --git a/Changelog b/Changelog
index 116e228a..75d5fae0 100644
--- a/Changelog
+++ b/Changelog
@@ -1,3 +1,237 @@
+* Fri Feb 01 2019 Chris PeBenito <pebenito@ieee.org> - 2.20190201
+Alexander Miroshnichenko (16):
+ Add signal_perms setpgid setsched permissions to syncthing_t.
+ Add corecmd_exec_bin permissions to syncthing_t.
+ Allow syncthing_t to read network state.
+ Allow syncthing_t to execute ifconfig/iproute2.
+ Add required permissions for nsd_t to be able running.
+ Add nsd_admin interface to sysadm.te.
+ Add map permission to lvm_t on lvm_metadata_t.
+ Add comment for map on lvm_metadata_t.
+ Remove syncthing tunable_policy.
+ Remove unneeded braces from nsd.te.
+ Add new interface fs_rmw_hugetlbfs_files.
+ Add map permission for postgresql_t to postgresql_tmp_t files.
+ Add dovecot_can_connect_db boolean.
+ fs_mmap_rw_hugetlbfs_files is a more appropriate name for the interface
+ Add hostapd service module
+ minor updates redis module to be able to start the app
+
+Chris PeBenito (85):
+ mozilla, devices, selinux, xserver, init, iptables: Module version bump.
+ devices: Module version bump.
+ misc_patterns.spt: Remove unnecessary brackets.
+ ipsec: Module version bump.
+ fstools: Module version bump.
+ corecommands: Module version bump.
+ xserver: Module version bump.
+ Merge pull request #1 from bigon/fix-sepolgen-ifgen
+ Remove unused translate permission in context userspace class.
+ logrotate: Module version bump.
+ miscfiles: Module version bump.
+ Merge pull request #3 from bigon/xdp-socket
+ obj_perm_sets.spt: Add xdp_socket to socket_class_set.
+ clamav, ssh, init: Module version bump.
+ amavis, apache, clamav, exim, mta, udev: Module version bump.
+ dnsmasq: Whitespace fix in file contexts.
+ dnsmasq: Reorder lines in file contexts.
+ Merge branch 'master' of https://github.com/bigon/refpolicy
+ Merge branch 'resolved' of https://github.com/bigon/refpolicy
+ Merge branch 'iscsi' of https://github.com/bigon/refpolicy
+ Various modules: Version bump.
+ dnsmasq: Module version bump.
+ Merge branch 'minissdpd' of https://github.com/bigon/refpolicy
+ cron, minissdpd, ntp, systemd: Module version bump.
+ dbus, xserver, init, logging, modutils: Module version bump.
+ Merge branch 'syncthing' of https://github.com/alexminder/refpolicy
+ syncthing: Whitespace change
+ Merge branch 'lvm' of https://github.com/alexminder/refpolicy
+ lvm, syncthing: Module version bump.
+ sigrok: Remove extra comments.
+ networkmanager: Add ICMPv6 comment
+ sysnetwork: Move optional block in sysnet_dns_name_resolve().
+ sysnetwork: Move lines.
+ dpkg: Rename dpkg_read_script_tmp_links().
+ apt, rpm: Remove and move lines to fix fc conflicts.
+ sudo: Whitespace fix.
+ many: Module version bumps for changes from Russell Coker.
+ systemd: Rename systemd_list_netif() to systemd_list_networkd_runtime().
+ init: Remove inadvertent merge.
+ Merge branch 'nsd' of https://github.com/alexminder/refpolicy
+ nsd: Merge two rules into one.
+ Merge branch 'ssh_dac_read_search' of
+ git://github.com/fishilico/selinux-refpolicy
+ Merge branch 'restorecond_getattr_cgroupfs' of
+ git://github.com/fishilico/selinux-refpolicy
+ Merge branch 'systemd-logind-getutxent' of
+ git://github.com/fishilico/selinux-refpolicy
+ various: Module version bump.
+ iptables: Module version bump.
+ Add CONTRIBUTING file.
+ kernel, systemd: Move lines.
+ kernel, jabber, ntp, init, logging, systemd: Module version bump.
+ Merge branch 'systemd-journald_units_symlinks' of
+ git://github.com/fishilico/selinux-refpolicy
+ init, logging: Module version bump.
+ Merge branch 'services_single_usr_bin' of
+ git://github.com/fishilico/selinux-refpolicy
+ Merge branch 'init_rename_pid_interfaces' of
+ git://github.com/fishilico/selinux-refpolicy
+ various: Module name bump.
+ Merge branch 'systemd-rfkill' of
+ git://github.com/fishilico/selinux-refpolicy
+ systemd: Whitespace change
+ systemd: Module version bump.
+ Merge branch 'restorecond-symlinks' of
+ git://github.com/fishilico/selinux-refpolicy
+ Merge branch 'add_comment' of git://github.com/DefenSec/refpolicy
+ usermanage, cron, selinuxutil: Module version bump.
+ logging, sysnetwork, systemd: Module version bump.
+ Merge branch 'restorecond-dontaudit-symlinks' of
+ git://github.com/fishilico/selinux-refpolicy
+ selinuxutil: Module version bump.
+ Merge branch 'dbus-dynamic-uid' of
+ git://github.com/fishilico/selinux-refpolicy
+ xserver: Move line
+ systemd: Move interface implementation.
+ various: Module version bump.
+ dpkg: Rename dpkg_nnp_transition() to dpkg_nnp_domtrans().
+ dpkg: Move interface implementations.
+ init: Rename init_read_generic_units_links() to
+ init_read_generic_units_symlinks().
+ init: Drop unnecessary userspace class dependence in
+ init_read_generic_units_symlinks().
+ chromium: Whitespace fixes.
+ chromium: Move line.
+ Merge branch 'dovecot' of git://github.com/alexminder/refpolicy
+ dovecot: Move lines.
+ various: Module version bump.
+ Merge branch 'postgres' of git://github.com/alexminder/refpolicy
+ filesystem, postgresql: Module version bump.
+ hostapd: Whitespace change.
+ hostapd: Move line.
+ various: Module version bump.
+ redis: Move line.
+ redis: Module version bump.
+ corecommands, staff, unprivuser, ssh, locallogin, systemd: Module version
+ bump.
+ Bump module versions for release.
+
+David Sugar (15):
+ Interface to allow reading of virus signature files.
+ Update CUSTOM_BUILDOPT
+ Add interface udev_run_domain
+ Allow clamd_t to read /proc/sys/crypt/fips_enabled
+ Interface to add domain allowed to be read by ClamAV for scanning.
+ Add interfaces to control clamav_unit_t systemd services
+ Allow clamd to use sent file descriptor
+ Add interfaces to control ntpd_unit_t systemd services
+ interface to enable/disable systemd_networkd service
+ Interface to read cron_system_spool_t
+ Allow X (xserver_t) to read /proc/sys/crypto/fips_enabled
+ Allow kmod to read /proc/sys/crypto/fips_enabled
+ Allow dbus to access /proc/sys/crypto/fips_enabled
+ Add missing require for 'daemon' attribute.
+ Allow auditctl_t to read bin_t symlinks.
+
+Dominick Grift (1):
+ unconfined: add a note about DBUS
+
+Guido Trentalancia (1):
+ Add sigrok contrib module
+
+Jagannathan Raman (1):
+ vhost: Add /dev/vhost-scsi device of type vhost_device_t.
+
+Jason Zaman (10):
+ selinux: compute_access_vector requires creating netlink_selinux_sockets
+ mozilla: xdg updates
+ xserver: label .cache/fontconfig as user_fonts_cache_t
+ Allow map xserver_misc_device_t for nvidia driver
+ iptables: fcontexts for 1.8.0
+ devices: introduce dev_dontaudit_read_sysfs
+ files: introduce files_dontaudit_read_etc_files
+ kernel: introduce kernel_dontaudit_read_kernel_sysctl
+ userdomain: introduce userdom_user_home_dir_filetrans_user_cert
+ Add chromium policy upstreamed from Gentoo
+
+Laurent Bigonville (10):
+ policy/support/obj_perm_sets.spt: modify indentation of mmap_file_perms to
+ make sepolgen-ifgen happy
+ Add xdp_socket security class and access vectors
+ irqbalance now creates an abstract socket
+ Allow semanage_t to connect to system D-Bus bus
+ Allow ntpd_t to read init state
+ Add systemd_dbus_chat_resolved() interface
+ Allow sysnet_dns_name_resolve() to use resolved to resolve DNS names
+ Allow systemd_resolved_t to bind to port 53 and use net_raw
+ Allow iscsid_t to create a netlink_iscsi_socket
+ Allow minissdpd_t to create a unix_stream_socket
+
+Luis Ressel (7):
+ corecommands: Fix /usr/share/apr* fc
+ xserver: Allow user fonts (and caches) to be mmap()ed.
+ Add fc for /var/lib/misc/logrotate.status
+ Realign logrotate.fc, remove an obvious comment
+ miscfiles: Label /usr/share/texmf*/fonts/ as fonts_t
+ services/ssh: Don't audit accesses from ssh_t to /dev/random
+ system/init: Give init_spec_daemon_domain()s the "daemon" attribute
+
+Lukas Vrabec (1):
+ Improve domain_transition_pattern to allow mmap entrypoint bin file.
+
+Nicolas Iooss (11):
+ fstools: label e2mmpstatus as fsadm_exec_t
+ ssh: use dac_read_search instead of dac_override
+ selinuxutil: allow restorecond to try counting the number of files in
+ cgroup fs
+ systemd: allow systemd-logind to use getutxent()
+ Allow systemd-journald to read systemd unit symlinks
+ Label service binaries in /usr/bin like /usr/sbin
+ init: rename *_pid_* interfaces to use "runtime"
+ systemd: add policy for systemd-rfkill
+ selinuxutil: allow restorecond to read symlinks
+ selinuxutil: restorecond is buggy when it dereferencies symlinks
+ dbus: allow using dynamic UID
+
+Petr Vorel (1):
+ dnsmasq: Require log files to have .log suffix
+
+Russell Coker (19):
+ misc services patches
+ misc interfaces
+ last misc stuff
+ systemd related interfaces
+ systemd misc
+ missing from previous
+ cron trivial
+ mls stuff
+ logging
+ some little stuff
+ trivial system cronjob
+ another trivial
+ more tiny stuff
+ map systemd private dirs
+ tiny stuff for today
+ yet more tiny stuff
+ yet another little patch
+ chromium
+ more misc stuff
+
+Sugar, David (9):
+ Allow greeter to start dbus
+ pam_faillock creates files in /run/faillock
+ Add interface to get status of iptables service
+ Add interface to start/stop iptables service
+ label journald configuraiton files syslog_conf_t
+ Interface with systemd_hostnamed over dbus to set hostname
+ Modify type for /etc/hostname
+ Add interface clamav_run
+ Add interface to read journal files
+
+Yuli Khodorkovskiy (1):
+ ipsec: add missing permissions for pluto
+
* Sun Jul 01 2018 Chris PeBenito <pebenito@ieee.org> - 2.20180701
Chris PeBenito (28):
Enable cgroup_seclabel and nnp_nosuid_transition.
diff --git a/VERSION b/VERSION
index b40612cc..b93d30a8 100644
--- a/VERSION
+++ b/VERSION
@@ -1 +1 @@
-2.20180701
+2.20190201
next reply other threads:[~2019-02-10 4:15 UTC|newest]
Thread overview: 103+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-02-10 4:14 Jason Zaman [this message]
-- strict thread matches above, loose matches on Subject: below --
2025-03-08 23:55 [gentoo-commits] proj/hardened-refpolicy:master commit in: / Jason Zaman
2025-03-08 23:55 Jason Zaman
2024-09-22 0:03 Jason Zaman
2024-09-22 0:03 Jason Zaman
2024-03-01 19:56 Kenton Groombridge
2024-03-01 19:56 Kenton Groombridge
2024-03-01 19:56 Kenton Groombridge
2024-03-01 19:56 Kenton Groombridge
2024-03-01 19:56 Kenton Groombridge
2023-02-10 20:30 Kenton Groombridge
2022-03-31 3:31 Jason Zaman
2022-03-31 3:31 Jason Zaman
2022-03-31 3:31 Jason Zaman
2022-03-31 3:31 Jason Zaman
2021-11-11 21:27 Jason Zaman
2021-04-03 3:10 Jason Zaman
2021-02-07 3:21 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-01-11 1:27 Jason Zaman
2020-10-13 3:02 Jason Zaman
2019-12-16 17:48 Jason Zaman
2019-07-13 7:01 Jason Zaman
2019-07-13 7:01 Jason Zaman
2018-07-08 11:47 Jason Zaman
2018-06-24 8:46 Jason Zaman
2018-03-25 10:29 Sven Vermeulen
2018-01-18 16:37 Sven Vermeulen
2017-06-13 8:25 Jason Zaman
2017-04-10 16:59 Sven Vermeulen
2017-03-30 17:06 Jason Zaman
2017-03-30 17:06 Jason Zaman
2017-03-02 10:17 Sven Vermeulen
2017-02-27 10:50 Jason Zaman
2017-02-25 16:58 Jason Zaman
2017-02-21 7:11 Jason Zaman
2017-02-21 7:11 Jason Zaman
2017-02-05 6:29 Jason Zaman
2017-01-23 15:44 Jason Zaman
2017-01-23 15:44 Jason Zaman
2017-01-23 15:44 Jason Zaman
2017-01-13 18:43 Sven Vermeulen
2017-01-13 18:43 Sven Vermeulen
2017-01-13 18:43 Sven Vermeulen
2016-12-06 13:39 Jason Zaman
2016-10-24 16:02 [gentoo-commits] proj/hardened-refpolicy:swift " Sven Vermeulen
2016-10-24 16:02 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2016-10-24 16:02 [gentoo-commits] proj/hardened-refpolicy:swift " Sven Vermeulen
2016-10-24 16:02 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2016-10-24 16:02 Sven Vermeulen
2016-08-31 16:38 Jason Zaman
2016-08-31 16:38 Jason Zaman
2016-05-13 5:37 Jason Zaman
2016-05-13 5:37 Jason Zaman
2015-12-17 16:10 Jason Zaman
2015-10-26 5:36 [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman
2015-10-26 5:48 ` [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman
2015-03-29 9:59 Jason Zaman
2015-02-15 17:39 Sven Vermeulen
2014-12-04 1:46 Jason Zaman
2014-11-27 8:31 Jason Zaman
2014-11-22 16:25 Sven Vermeulen
2014-09-21 14:08 [gentoo-commits] proj/hardened-refpolicy:mailinfra " Sven Vermeulen
2014-09-13 9:38 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2014-06-25 19:06 Sven Vermeulen
2014-03-17 8:24 Sven Vermeulen
2014-03-17 8:24 Sven Vermeulen
2014-03-17 8:24 Sven Vermeulen
2014-03-06 15:20 Sven Vermeulen
2014-01-19 19:01 Sven Vermeulen
2013-09-30 19:03 Sven Vermeulen
2013-09-30 19:03 Sven Vermeulen
2013-09-26 13:19 Sven Vermeulen
2013-09-23 13:31 Sven Vermeulen
2013-09-23 6:29 [gentoo-commits] proj/hardened-refpolicy:merge " Sven Vermeulen
2013-09-23 13:31 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2013-09-23 6:29 [gentoo-commits] proj/hardened-refpolicy:merge " Sven Vermeulen
2013-09-23 13:31 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2013-05-01 18:23 Sven Vermeulen
2013-05-01 18:23 Sven Vermeulen
2013-01-16 19:48 Sven Vermeulen
2012-12-08 12:41 Sven Vermeulen
2012-12-03 21:03 Sven Vermeulen
2012-12-03 9:35 Sven Vermeulen
2012-11-06 20:21 Sven Vermeulen
2012-10-27 11:06 Sven Vermeulen
2012-10-22 18:15 Sven Vermeulen
2012-10-17 17:41 Sven Vermeulen
2012-10-16 17:39 Sven Vermeulen
2012-10-16 17:39 Sven Vermeulen
2012-10-16 17:39 Sven Vermeulen
2012-10-06 17:14 Sven Vermeulen
2012-10-06 17:05 Sven Vermeulen
2012-10-06 17:05 Sven Vermeulen
2012-10-06 15:56 Sven Vermeulen
2012-10-06 15:56 Sven Vermeulen
2012-10-04 17:36 Sven Vermeulen
2012-10-04 17:36 Sven Vermeulen
2012-10-04 17:36 Sven Vermeulen
2012-10-02 18:11 Sven Vermeulen
2012-10-02 18:11 Sven Vermeulen
2012-09-27 18:05 Sven Vermeulen
2012-09-27 18:05 Sven Vermeulen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1549771885.744101042e9ae8eab4f942963b64dcaf5f2c738a.perfinion@gentoo \
--to=perfinion@gentoo.org \
--cc=gentoo-commits@lists.gentoo.org \
--cc=gentoo-dev@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox