From: "Jason Zaman" <perfinion@gentoo.org>
To: gentoo-commits@lists.gentoo.org
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: /
Date: Tue, 15 Jul 2025 07:54:15 +0000 (UTC) [thread overview]
Message-ID: <1752565943.a04001906d684a477ff1d0747bcdfe4270ac6d7f.perfinion@gentoo> (raw)
commit: a04001906d684a477ff1d0747bcdfe4270ac6d7f
Author: Chris PeBenito <pebenito <AT> ieee <DOT> org>
AuthorDate: Wed Jun 18 18:02:16 2025 +0000
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
CommitDate: Tue Jul 15 07:52:23 2025 +0000
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=a0400190
Update Changelog and VERSION for release 2.20250618.
Signed-off-by: Chris PeBenito <pebenito <AT> ieee.org>
Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org>
Changelog | 104 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
VERSION | 2 +-
2 files changed, 105 insertions(+), 1 deletion(-)
diff --git a/Changelog b/Changelog
index 0527405ac..5795df588 100644
--- a/Changelog
+++ b/Changelog
@@ -1,3 +1,107 @@
+* Wed Jun 18 2025 Chris PeBenito <pebenito@ieee.org> - 2.20250618
+Antonio Enrico Russo (1):
+ Remove unneeded backticks from gen_tunable
+
+Benstone Zhang (1):
+ filesystem: support bcachefs
+
+Chris PeBenito (57):
+ lvm: Add fc entries for veritysetup.
+ bootloader: Chane efibootmgr from fsadm.
+ lldpad: Configure FW-LLDP on i40e NICs.
+ networkmanager: Watch systemd directories for nm-session-monitor.
+ systemd: Add log env to systemd-machine-id-setup.
+ validate-policy.yml: Change sechecker output to stdout and use tee to
+ collect the log.
+
+Clayton Casciato (15):
+ chronyd: fix dac_read_search denials
+ unconfined: fix oddjob security_compute_sid
+ firewalld: fix lib_t Python cache denial auditing
+ firewalld: fix firewalld_t firewalld_tmpfs_t exec
+ files, init: filetrans /run/machine-id etc_runtime_t
+ locallogin: dontaudit sulogin_t checkpoint_restore
+ locallogin: allow sulogin_t unconfined domtrans
+ locallogin: allow sulogin_t user_tty_device_t rw
+ oddjob: allow oddjob_mkhomedir_t privfd:fd use
+ oddjob: allow oddjob_mkhomedir_t user_terminals
+ systemd: allow systemd_generator_t use user ttys
+ files: add files_delete_var_chr_files interface
+ unconfined: allow firewalld_t unconfined_t:dbus send_msg
+ chronyd: allow chronyd_t kernel_t:system module_request
+ ssh: allow sshd_t kernel_t:system module_request
+
+Daniel Burgener (1):
+ Don't build the fc subs dist install path in the builtappfiles target
+
+Daniel De Graaf (1):
+ systemd: allow reading /dev/cpu/0/msr
+
+Dave Sugar (7):
+ Fix mislabeling of /etc/shadow
+ Module for ipmitool
+ Label snmp unit files
+ NNP transition interface for dmesg
+ Let modules-load.d call commands from modprobe.d
+ NNP transition interface for chronyc
+ fix building when dbus module is not enabled
+
+Guido Trentalancia (6):
+ Add the minimum set of additional permissions to the screen module, as
+ required to run version 5.
+ Revert db33386c014fce3890b0b3832a605bc5d1762d8c
+ Improve the style of the screen module by removing a recently added
+ unneeded interface.
+ Fix the file context definition for the screen utility executable file
+ according to the new install rules in place since at least version
+ 4.5.1.
+ Since version 5.0.1 the screen utility also requires the
+ CAP_DAC_READ_SEARCH capability.
+ Add a comment in the xserver module about the need to read and write
+ xserver tmpfs files for the Qt library version 5 (boolean).
+
+Maciej Czarnecki (2):
+ Allow to specify module version
+ fixup! Allow to specify module version
+
+Nicolas PARLANT (4):
+ Add setcap to knotd / add knotc_initrc_domtrans
+ use init_use_script_ptys for knotc in initscript
+ sshd: label sshd-auth as sshd_exec_t #797
+
+Pat Riehecky (1):
+ Permit init_t to start a detached screen session
+
+Rahul Sandhu (1):
+ auditd: don't grant write as implied by manage_files_pattern for logs
+
+Russell Coker (15):
+ This patch removed the sysadmin capability from cups. This is the one
+ change needed to dramatically reduce the potential damage from a
+ compromise of cupsd.
+ Policy for needrestart to run with minimum privs so it can't be exploited
+ Policy for the userspace feedback daemon for handsets, for vibration etc
+ Fix for thunderbolt, laben the run dir, dontaudit the net_admin capability
+ for the usual reasons, allow writing to sysfs for the force_power file,
+ and allow reading udev runtime files
+ New version of the kea PR with the order issues fixed
+ Made the changes requested
+ File contexts for new files for xdm/xserver
+ apt and aptcacher changes
+ Updates for recent versions of ntpd interacting with systemd
+ Some small phone related patches
+ fwupd-fixed-more (#928)
+ changed the order as requested
+ changed the netlink_route_socket operations to { create_socket_perms
+ nlmsg_write } as requested
+ networking (#937)
+ device (#939)
+
+Yi Zhao (2):
+ systemd: allow system --user to get attributes of nsfs inodes
+ systemd: allow systemd-hostnamed and systemd-rfkill to get attributes of
+ nsfs inodes
+
* Thu Feb 13 2025 Chris PeBenito <pebenito@ieee.org> - 2.20250213
Björn Esser (1):
authlogin: fix regex for /etc/tcb
diff --git a/VERSION b/VERSION
index 22fcf3aad..e64e7b05d 100644
--- a/VERSION
+++ b/VERSION
@@ -1 +1 @@
-2.20250213
+2.20250618
next reply other threads:[~2025-07-15 7:54 UTC|newest]
Thread overview: 105+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-07-15 7:54 Jason Zaman [this message]
-- strict thread matches above, loose matches on Subject: below --
2025-09-02 22:15 [gentoo-commits] proj/hardened-refpolicy:master commit in: / Jason Zaman
2025-03-08 23:55 Jason Zaman
2025-03-08 23:55 Jason Zaman
2024-09-22 0:03 Jason Zaman
2024-09-22 0:03 Jason Zaman
2024-03-01 19:56 Kenton Groombridge
2024-03-01 19:56 Kenton Groombridge
2024-03-01 19:56 Kenton Groombridge
2024-03-01 19:56 Kenton Groombridge
2024-03-01 19:56 Kenton Groombridge
2023-02-10 20:30 Kenton Groombridge
2022-03-31 3:31 Jason Zaman
2022-03-31 3:31 Jason Zaman
2022-03-31 3:31 Jason Zaman
2022-03-31 3:31 Jason Zaman
2021-11-11 21:27 Jason Zaman
2021-04-03 3:10 Jason Zaman
2021-02-07 3:21 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-02-07 3:20 Jason Zaman
2021-01-11 1:27 Jason Zaman
2020-10-13 3:02 Jason Zaman
2019-12-16 17:48 Jason Zaman
2019-07-13 7:01 Jason Zaman
2019-07-13 7:01 Jason Zaman
2019-02-10 4:14 Jason Zaman
2018-07-08 11:47 Jason Zaman
2018-06-24 8:46 Jason Zaman
2018-03-25 10:29 Sven Vermeulen
2018-01-18 16:37 Sven Vermeulen
2017-06-13 8:25 Jason Zaman
2017-04-10 16:59 Sven Vermeulen
2017-03-30 17:06 Jason Zaman
2017-03-30 17:06 Jason Zaman
2017-03-02 10:17 Sven Vermeulen
2017-02-27 10:50 Jason Zaman
2017-02-25 16:58 Jason Zaman
2017-02-21 7:11 Jason Zaman
2017-02-21 7:11 Jason Zaman
2017-02-05 6:29 Jason Zaman
2017-01-23 15:44 Jason Zaman
2017-01-23 15:44 Jason Zaman
2017-01-23 15:44 Jason Zaman
2017-01-13 18:43 Sven Vermeulen
2017-01-13 18:43 Sven Vermeulen
2017-01-13 18:43 Sven Vermeulen
2016-12-06 13:39 Jason Zaman
2016-10-24 16:02 [gentoo-commits] proj/hardened-refpolicy:swift " Sven Vermeulen
2016-10-24 16:02 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2016-10-24 16:02 [gentoo-commits] proj/hardened-refpolicy:swift " Sven Vermeulen
2016-10-24 16:02 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2016-10-24 16:02 Sven Vermeulen
2016-08-31 16:38 Jason Zaman
2016-08-31 16:38 Jason Zaman
2016-05-13 5:37 Jason Zaman
2016-05-13 5:37 Jason Zaman
2015-12-17 16:10 Jason Zaman
2015-10-26 5:36 [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman
2015-10-26 5:48 ` [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman
2015-03-29 9:59 Jason Zaman
2015-02-15 17:39 Sven Vermeulen
2014-12-04 1:46 Jason Zaman
2014-11-27 8:31 Jason Zaman
2014-11-22 16:25 Sven Vermeulen
2014-09-21 14:08 [gentoo-commits] proj/hardened-refpolicy:mailinfra " Sven Vermeulen
2014-09-13 9:38 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2014-06-25 19:06 Sven Vermeulen
2014-03-17 8:24 Sven Vermeulen
2014-03-17 8:24 Sven Vermeulen
2014-03-17 8:24 Sven Vermeulen
2014-03-06 15:20 Sven Vermeulen
2014-01-19 19:01 Sven Vermeulen
2013-09-30 19:03 Sven Vermeulen
2013-09-30 19:03 Sven Vermeulen
2013-09-26 13:19 Sven Vermeulen
2013-09-23 13:31 Sven Vermeulen
2013-09-23 6:29 [gentoo-commits] proj/hardened-refpolicy:merge " Sven Vermeulen
2013-09-23 13:31 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2013-09-23 6:29 [gentoo-commits] proj/hardened-refpolicy:merge " Sven Vermeulen
2013-09-23 13:31 ` [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen
2013-05-01 18:23 Sven Vermeulen
2013-05-01 18:23 Sven Vermeulen
2013-01-16 19:48 Sven Vermeulen
2012-12-08 12:41 Sven Vermeulen
2012-12-03 21:03 Sven Vermeulen
2012-12-03 9:35 Sven Vermeulen
2012-11-06 20:21 Sven Vermeulen
2012-10-27 11:06 Sven Vermeulen
2012-10-22 18:15 Sven Vermeulen
2012-10-17 17:41 Sven Vermeulen
2012-10-16 17:39 Sven Vermeulen
2012-10-16 17:39 Sven Vermeulen
2012-10-16 17:39 Sven Vermeulen
2012-10-06 17:14 Sven Vermeulen
2012-10-06 17:05 Sven Vermeulen
2012-10-06 17:05 Sven Vermeulen
2012-10-06 15:56 Sven Vermeulen
2012-10-06 15:56 Sven Vermeulen
2012-10-04 17:36 Sven Vermeulen
2012-10-04 17:36 Sven Vermeulen
2012-10-04 17:36 Sven Vermeulen
2012-10-02 18:11 Sven Vermeulen
2012-10-02 18:11 Sven Vermeulen
2012-09-27 18:05 Sven Vermeulen
2012-09-27 18:05 Sven Vermeulen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1752565943.a04001906d684a477ff1d0747bcdfe4270ac6d7f.perfinion@gentoo \
--to=perfinion@gentoo.org \
--cc=gentoo-commits@lists.gentoo.org \
--cc=gentoo-dev@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox