|
|
|
|
Changelog for policycoreutils-gui-2.2.5-11.el7_0.1.x86_64.rpm :
* Fri Aug 29 2014 Miroslav Grepl - 2.2.5-11.el7_0.1- Make selinux-policy build working also on another architectures related to sepolicy-manpage generateResolves:#1135434 * Fri Apr 04 2014 Dan Walsh - 2.2.5-11- One more time- Update TranslationsResolves: #1030373 * Mon Mar 31 2014 Dan Walsh - 2.2.5-10- Update TranslationsResolves: #1030373 * Mon Mar 31 2014 Dan Walsh - 2.2.5-9- Update TranslationsResolves: #1030373 * Mon Mar 24 2014 Dan Walsh - 2.2.5-8- Update TranslationsResolves: #1030373 * Sun Mar 16 2014 Dan Walsh - 2.2.5-7- yum should not be required for -python package * Wed Feb 26 2014 Miroslav Grepl - 2.2.5-6Fix spec file to remove run_init which is no longer used because of systemdResolves:#825725 * Thu Jan 30 2014 Miroslav Grepl - 2.2.5-5- Remove default s0 range from semanage-login command. It is handled in seobject.py.Resolves:#1028106 * Fri Jan 24 2014 Daniel Mach - 2.2.5-4- Mass rebuild 2014-01-24 * Thu Jan 16 2014 Dan Walsh - 2.2.5-3- Add Miroslav patch to- Fix previously_modified_initialize() to show modified changes properly for all selectionsResolves: #1049977 * Wed Jan 08 2014 Dan Walsh - 2.2.5-2- Do not require /usr/share/selinux/devel/Makefile to build permissive domains * Mon Jan 06 2014 Dan Walsh - 2.2.5-1- Fix Mass Rebuild problems- Update to upstream * Ignore selevel/serange if MLS is disabled from Sven Vermeulen.Resolves: #1043489 * Fri Jan 03 2014 Dan Walsh - 2.2.4-8- Update Tranlations- Patch from Yuri Chornoivan to fix typos * Fri Dec 27 2013 Daniel Mach - 2.2.4-7- Mass rebuild 2013-12-27 * Fri Dec 20 2013 Dan Walsh - 2.2.4-6- Fix sepolicy gui selection for advanced screen- Update Translations- Move requires checkpolicy requirement into policycoreutils-pythonResolves: #1043489 * Mon Dec 16 2013 Dan Walsh - 2.2.4-5- Fix semanage man page description of import command- Fix policy kit file to allow changing to permissive mode * Mon Dec 16 2013 Dan Walsh - 2.2.4-4- Fix broken dependencies. * Fri Dec 13 2013 Dan Walsh - 2.2.4-3- Break out python3 code into separate package * Fri Dec 06 2013 Dan Walsh - 2.2.4-2- Add mgrepl patch- ptrace should be a part of deny_ptrace boolean in TEMPLATETYPE_admin * Tue Dec 03 2013 Dan Walsh - 2.2.4-1- Update to upstream * Revert automatic setting of serange and seuser in seobject; was breaking non-MLS systems.- Add patches for sepolicy gui from mgrepl to Fix advanced_item_button_push() to allow to select an application in advanced search menu Fix previously_modified_initialize() to show modified changes properly for all selections * Fri Nov 22 2013 Dan Walsh - 2.2.3-1- Update to upstream * Apply polkit check on all dbus interfaces and restrict to active user from Dan Walsh. * Fix typo in sepolicy gui dbus.relabel_on_boot call from Dan Walsh.- Apply Miroslav Grepl patch to fix TEMPLATETYPE_domtrans description in sepolicy generate * Wed Nov 20 2013 Dan Walsh - 2.2.2-2- Fix selinux-polgengui, get_all_modules call * Fri Nov 15 2013 Dan Walsh - 2.2.2-1Resolves: #1002529Resolves: #924105Resolves: #918140Resolves: #1028096- Speed up startup time of sepolicy gui- Clean up ports screen to only show enabled ports.- Update to upstream * Remove import policycoreutils.default_encoding_utf8 from semanage from Dan Walsh. * Make yum/extract_rpms optional for sepolicy generate from Dan Walsh. * Add test suite for audit2allow and sepolgen-ifgen from Dan Walsh. * Wed Nov 13 2013 Dan Walsh - 2.2-2- Shift around some of the files to more appropriate packages. * semodule_ * packages are required for devel. * Wed Nov 13 2013 Dan Walsh - 2.2-1- Update to upstream * Properly build the swig exception file from Laurent Bigonville. * Fix man pages from Laurent Bigonville. * Support overriding PATH and INITDIR in Makefile from Laurent Bigonville. * Fix LDFLAGS usage from Laurent Bigonville. * Fix init_policy warning from Laurent Bigonville. * Fix semanage logging from Laurent Bigonville. * Open newrole stdin as read/write from Sven Vermeulen. * Fix sepolicy transition from Sven Vermeulen. * Support overriding CFLAGS from Simon Ruderich. * Create correct man directory for run_init from Russell Coker. * restorecon GLOB_BRACE change from Michal Trunecka. * Extend audit2why to report additional constraint information. * Catch IOError errors within audit2allow from Dan Walsh. * semanage export/import fixes from Dan Walsh. * Improve setfiles progress reporting from Dan Walsh. * Document setfiles -o option in usage from Dan Walsh. * Change setfiles to always return -1 on failure from Dan Walsh. * Improve setsebool error r eporting from Dan Walsh. * Major overhaul of gui from Dan Walsh. * Fix sepolicy handling of non-MLS policy from Dan Walsh. * Support returning type aliases from Dan Walsh. * Add sepolicy tests from Dan Walsh. * Add org.selinux.config.policy from Dan Walsh. * Improve range and user input checking by semanage from Dan Walsh. * Prevent source or target arguments that end with / for substitutions from Dan Walsh. * Allow use of <> for semanage fcontext from Dan Walsh. * Report customized user levels from Dan Walsh. * Support deleteall for restoring disabled modules from Dan Walsh. * Improve semanage error reporting from Dan Walsh. * Only list disabled modules for module locallist from Dan Walsh. * Fix logging from Dan Walsh. * Define new constants for file type character codes from Dan Walsh. * Improve bash completions from Dan Walsh. * Convert semanage to argparse from Dan Walsh (originally by Dave Quigley). * Add semanage tests from Dan Walsh. * Split semanage man pages from Dan Walsh. * Move bash completion scripts from Dan Walsh. * Replace genhomedircon script with a link to semodule from Dan Walsh. * Fix fixfiles from Dan Walsh. * Add support for systemd service for restorecon from Dan Walsh. * Spelling corrections from Dan Walsh. * Improve sandbox support for home dir symlinks and file caps from Dan Walsh. * Switch sandbox to openbox window manager from Dan Walsh. * Coalesce audit2why and audit2allow from Dan Walsh. * Change audit2allow to append to output file from Dan Walsh. * Update translations from Dan Walsh. * Change audit2why to use selinux_current_policy_path from Dan Walsh. * Tue Nov 12 2013 Dan Walsh - 2.1.14-89- Update to latest sepolicy tool chain.- Document semodule -P- Verify input to semanage permissive -a is a valid domain.- Assigning login user with semanage login, range should default to user record * Wed Oct 16 2013 Dan Walsh - 2.1.14-88- Cleanup errors found by pychecker- Apply patch from Michal Trunecka to allow restorecon to handle {} in globsResolves: #1018913 * Fri Oct 11 2013 Dan Walsh - 2.1.14-87- sepolicy gui - mgrepl fixes for users and login- Update Translations. * Fri Oct 11 2013 Dan Walsh - 2.1.14-86- sepolicy gui - mgrepl added delete screens for users and login - Fix lots of bugs.- Update Translations. * Fri Oct 04 2013 Dan Walsh - 2.1.14-85- Fixes for fixfiles * exclude_from_dirs should apply to all types of restorecon calls * fixfiles check now works * exit with the correct status- semanage no longer import selinux * Wed Oct 02 2013 Dan Walsh - 2.1.14-84- Fixes for sepolicy gui- Fix setsebool to return 0 on success- Update Po * Mon Sep 30 2013 Dan Walsh - 2.1.14-83- Fix sizes of help screens in sepolicy gui * Sat Sep 28 2013 Dan Walsh - 2.1.14-82- Improvements to sepolicy gui - Add more help information - Cleanup code - Add deny_ptrace on lockdown screen - Make unconfined/permissivedomains lockdown work - Add more support for file equivalency * Wed Sep 18 2013 Dan Walsh - 2.1.14-81- Add back in the help png files- Begin Adding support for file equivalency. * Wed Sep 04 2013 Dan Walsh - 2.1.14-80- Random fixes for sepolicy gui * Do not prompt for password until you make a change * Add user mappings and selinux users page * lots of code cleanup- Verify homedir is owned by user before mounting over it with seunshare- Fix fixfiles to handle Relabel properly- Fix semanage fcontext -e / command to allow \"/\" * Wed Sep 04 2013 Dan Walsh - 2.1.14-79- Add Miroslav Grepl setsebool patch to give better error message on bad boolean names- Additional help screens for sepolicy gui * Tue Sep 03 2013 Dan Walsh - 2.1.14-78- Random fixes for sepolicy gui- Update Translations * Fri Aug 30 2013 Dan Walsh - 2.1.14-77- Add help screens for each page- Fixes for system page * Mon Aug 26 2013 Dan Walsh - 2.1.14-76- Add Miroslav Grepl Patch to handle semanage -i and semanage -o better- Update Translations * Thu Aug 15 2013 Dan Walsh - 2.1.14-75- Update sepolicy gui code, cleanups and add file transition tab- Fix semanage fcontext -a --ftype code to work. * Wed Aug 07 2013 Dan Walsh - 2.1.14-74- If policy is not installed get_bools should not crash * Tue Aug 06 2013 Dan Walsh - 2.1.14-72- Update sepolicy gui code, cleanups and add file transition tab- Fix semanage argparse problems * Fri Aug 02 2013 Dan Walsh - 2.1.14-71- Update sepolicy gui code, adding dbus calls- Update Translations * Fri Jul 26 2013 Dan Walsh - 2.1.14-70- Fix semanage argparse bugs- Update Translations- Add test suite for semanage command lines * Wed Jul 24 2013 Dan Walsh - 2.1.14-69- Fix semanage argparse bugs * Tue Jul 23 2013 Dan Walsh - 2.1.14-68- Fix bugs introduced by previous patch. semanage port- Update Translations- Add test suite for sepolicy command lines * Fri Jul 19 2013 Dan Walsh - 2.1.14-67- Fix bugs introduced by previous patch. semanage port- Update Translations * Wed Jul 17 2013 Dan Walsh - 2.1.14-66- Rewrite argparse code in semanage and fix reload problem. * Tue Jul 16 2013 Dan Walsh - 2.1.14-65- Do not generate shell script or spec file for sepolicy generate --newtype- Update translations- Fix sepolicy generate --admin_user man page again- Fix setsebool to print less verbose error messages by default, add -V for ve * Mon Jul 15 2013 Dan Walsh - 2.1.14-64- Move audit2allow and audit2why back into -python package * Wed Jul 10 2013 Dan Walsh - 2.1.14-63- Update sepolicy gui.- Error out of you call sepolicy gui without policycoreutils-gui package installed- Fix semanage login -d command- Update Translations * Wed Jul 10 2013 Dan Walsh - 2.1.14-62- Update sepolicy gui. * Fri Jul 05 2013 Dan Walsh - 2.1.14-61- Add Ryan Hallisey sepolicy gui.- Update Translations * Mon Jun 24 2013 Dan Walsh - 2.1.14-60- Fix semanage module error handling * Sun Jun 23 2013 Dan Walsh - 2.1.14-59- Add back default exception handling for errors, which argparse rewrite removed. * Fri Jun 21 2013 Dan Walsh - 2.1.14-58- Fix generation of booleans in man pages * Fri Jun 21 2013 Dan Walsh - 2.1.14-57- Remove requires for systemd-sysv- Move systemd-units require to restorecond section- Update Tranlasions- More sepolicy interfaces for gui- Cleanup man pages for sepolicy generate * Wed Jun 19 2013 Dan Walsh - 2.1.14-56- Fix semanage export/import commands- Fix semange module command- Remove --version option from sandbox * Tue Jun 18 2013 Dan Walsh - 2.1.14-55- Add man page doc for --role and bash complestion support for sepolicy --role * Tue Jun 18 2013 Dan Walsh - 2.1.14-54- Make fcdict return a dictionary of dictionaries- Fix for sepolicy manpage * Mon Jun 17 2013 Dan Walsh - 2.1.14-53- Add new man pages for each semanage subsection * Mon Jun 17 2013 Dan Walsh - 2.1.14-52- Fix handling of sepolicy network sorting.- Additional interfaces needed for sepolicy gui * Thu Jun 06 2013 Dan Walsh - 2.1.14-51- Fix handling of semanage args * Thu Jun 06 2013 Dan Walsh - 2.1.14-50- Fix sepolicy generate --confined_admin to generate tunables- Add new interface to generate entrypoints for use with new gui * Wed Jun 05 2013 Dan Walsh - 2.1.14-49- Fix handing of semanage with no args * Tue Jun 04 2013 Dan Walsh - 2.1.14-48- Fix audit2allow -o to open file for append- Fix the name of the spec file generated in the build script * Fri May 31 2013 Dan Walsh - 2.1.14-47- Fix mgrepl patch to support all semanage command parsing * Sun May 26 2013 Dan Walsh - 2.1.14-46- Fix the name of the spec file generated in the build script- Add mgrepl patch to support argparse for semanage command parsing * Tue May 21 2013 Dan Walsh - 2.1.14-45- Fix sandbox to always use sandbox_file_t, so generated policy will work.- Update Translations * Thu May 16 2013 Dan Walsh - 2.1.14-44- Fix sepolicy-generate man page to clear up options/policy type- Add Miroslav Grepl to not generate man page when doing sepolicy generate --customize- Add support for executing semanage user within spec file- Fix generation of confined admin domains, to handle booleans properly. * Tue May 14 2013 Dan Walsh - 2.1.14-43- Need to handle gziped policy.xml as well as not compressed. * Tue May 14 2013 Dan Walsh - 2.1.14-42- Add support for Xephyr -resizable, so sandbox can now resize window- Add support for compressed policy.xml- Miroslav Grepl patch to allow sepolicy interface on individual interface fil- Also add capability to test interfaces for correctness. * Mon May 13 2013 Dan Walsh - 2.1.14-41- Apply patches from Sven Vermeulen for sepolgen to fix typos. * Mon May 13 2013 Dan Walsh - 2.1.14-40- Only require selinux-policy-devel for policycoreutils-devel, this will shrink the size of the livecd. * Sun May 12 2013 Dan Walsh - 2.1.14-39- Run sepolgen-ifgen in audit2allow and sepolicy generate, if needed, first time- Add Sven Vermeulen patches to cleanup man pages * Fri May 10 2013 Dan Walsh - 2.1.14-38- No longer run sepolgen-ifgen at install time.- Run sepolgen-ifgen in audit2allow and sepolicy generate, if needed.- Update Translations * Mon Apr 22 2013 Dan Walsh - 2.1.14-37- Fix exceptionion hanling in audit2allow -o- Generate Man pages for everydomain, not just ones with exec_t entrypoints- sepolicy comunicate should return ValueError not TypeError- Trim header line in sepolicy manpage to use less space- Add missing options to restorecon man page * Thu Apr 11 2013 Dan Walsh - 2.1.14-36- Raise proper Exception on sepolicy communicate with invalid value * Wed Apr 10 2013 Dan Walsh - 2.1.14-35- Update translations- Add patch by Miroslav Grepl to add compile test for sepolicy interface command. * Tue Apr 09 2013 Dan Walsh - 2.1.14-34- Update translations- Add patch inspired by Miroslav Grepl to add extended information for sepolicy interface command. * Mon Apr 08 2013 Dan Walsh - 2.1.14-33- Update translations- Add missing man pages and fixup existing man pages * Wed Apr 03 2013 Dan Walsh - 2.1.14-32- Move sepolicy to policycoreutils-devel pacage, since most of it is used for devel- Apply Miroslav Grepl Patches for sepolicy-- Fix generate mutually groups option handling-- EUSER is used for existing policy-- customize options can be used together with admin_domain option-- Fix manpage.py to generate correct man pages for SELinux users-- Fix policy *.te file generated by customize+writepaths options-- Fix install script for confined_admin option * Mon Apr 01 2013 Dan Walsh - 2.1.14-31- Add post install scripts for gui to make sure Icon Cache is refreshed.- Fix grammar issue in secon man page- Update Translations * Thu Mar 28 2013 Dan Walsh - 2.1.14-30- Add buildrequires for OpenBox to prevent me from accidently building into RHEL7- Add support for returning alias data to sepolicy.info python bindings * Wed Mar 27 2013 Dan Walsh - 2.1.14-28- Fix audit2allow output to better align analysys with the allow rules- Apply Miroslav Grepl patch to clean up sepolicy generate usage- Apply Miroslav Grepl patch to fixupt handing of admin_user generation- Update Tranlslations * Wed Mar 27 2013 Dan Walsh - 2.1.14-27- Allow semanage fcontext -a -t \"<>\" ... to work * Mon Mar 25 2013 Dan Walsh - 2.1.14-26- Can not unshare IPC in sandbox, since it blows up Xephyr- Remove bogus error message sandbox about reseting setfsuid * Thu Mar 21 2013 Dan Walsh - 2.1.14-25- Fix sepolicy generate --customize to generate policy with -w commands * Thu Mar 21 2013 Dan Walsh - 2.1.14-24- sepolgen-ifgen needs to handle filename transition rules containing \":\" * Tue Mar 19 2013 Dan Walsh - 2.1.14-23- sepolicy manpage:- use nroff instead of man2html- Remove checking for name of person who created the man page- audit2allow- Fix output to show the level that is different. * Thu Mar 14 2013 Dan Walsh - 2.1.14-22- Fix newrole to not drop capabilities from the bounding set.- Stop dropping capabilities from its children.- Add better error messages.- Change location of bash_completion files to /usr/share/bash-completion/compl * Mon Mar 11 2013 Dan Walsh - 2.1.14-21- sepolicy generate should look for booleans that effect equivalence names, and add them to the man page * Thu Mar 07 2013 Dan Walsh - 2.1.14-20- Mention creation of permissive domains in sepolicy generate man page- Change sepolicy manpage to use shortname with an \"_\" to stop accidently grabbing unrelated types for a domain.- Fix audit2allow to show better information on constraint violations. * Wed Mar 06 2013 Dan Walsh - 2.1.14-19- Have restorecon exit -1 on errors for consistancy. * Tue Mar 05 2013 Dan Walsh - 2.1.14-18- Need to provide a value to semanage boolean -m * Mon Mar 04 2013 Dan Walsh - 2.1.14-17- Fix cut and paste errors for sepolicy network command * Fri Mar 01 2013 Dan Walsh - 2.1.14-16- Fix sepoicy interface to work properly * Thu Feb 28 2013 Dan Walsh - 2.1.14-15- Fix fixfiles to use exclude_dirs on fixfiles restore * Thu Feb 28 2013 Dan Walsh - 2.1.14-14- Allow users with symlinked homedirs to work. call realpath on homedir- Fix sepolicy reorganization of helper functions. * Sun Feb 24 2013 Dan Walsh - 2.1.14-13- Update trans- Fix sepolicy reorganization of helper functions. * Sun Feb 24 2013 Rahul Sundaram - 2.1.14-13- remove vendor tag from desktop file. https://fedorahosted.org/fpc/ticket/247- clean up spec to follow current guidelines * Fri Feb 22 2013 Dan Walsh - 2.1.14-12- Do not load interface file by default when sepolicy is called, mov get_all_methods to the sepolicy package * Fri Feb 22 2013 Dan Walsh - 2.1.14-11- sepolgen-ifgen should use the current policy path if selinux is enabled * Fri Feb 22 2013 Dan Walsh - 2.1.14-10- Fix sepolicy to be able to work on an SELinux disabled system.- Needed to be able to build man pages in selinux-policy package * Thu Feb 21 2013 Dan Walsh - 2.1.14-9- Add yum to requires of policycoreutils-python since sepolicy requires it. * Thu Feb 21 2013 Dan Walsh - 2.1.14-8- Sepolixy should not throw an exception on an SELinux disabled machine- Switch from using console app to using pkexec, so we will work betterwith policykit.- Add missing import to fix system-config-selinux startup- Add comment to pamd files about pam_rootok.so- Fix sepolicy generate to not comment out the first line * Wed Feb 20 2013 Dan Walsh - 2.1.14-7- Add --root/-r flag to sepolicy manpage,- This allows us to generate man pages on the fly in the selinux-policy build * Mon Feb 18 2013 Dan Walsh - 2.1.14-6- Fix newrole to retain cap_audit_write when compiled with namespace, alsodo not drop capabilities when run as root. * Thu Feb 14 2013 Dan Walsh - 2.1.14-5- Fix man page generation and public_content description * Thu Feb 14 2013 Dan Walsh - 2.1.14-4- Revert some changes which are causing the wrong policy version file to be created- Switch sandbox to start using openbox rather then matchbox- Make sepolgen a symlink to sepolicy- update translations * Wed Feb 13 2013 Dan Walsh - 2.1.14-3- Fix empty system-config-selinux.png, again * Tue Feb 12 2013 Dan Walsh - 2.1.14-2- Fix empty system-config-selinux.png * Thu Feb 07 2013 Dan Walsh - 2.1.14-1- Update to upstream * setfiles: estimate percent progress * load_policy: make link at the destination directory * Rebuild polgen.glade with glade-3 * sepolicy: new command to unite small utilities * sepolicy: Update Makefiles and po files * sandbox: use sepolicy to look for sandbox_t * gui: switch to use sepolicy * gui: sepolgen: use sepolicy to generate * semanage: use sepolicy for boolean dictionary * add po file configuration information * po: stop running update-po on all * semanage: seobject verify policy types before allowing you to assign them. * gui: Start using Popen, instead of os.spawnl * sandbox: Copy /var/tmp to /tmp as they are the same inside * qualifier to shred content * semanage: Fix handling of boolean_sub names when using the -F flag * semanage: man: roles instead of role * gui: system-config-selinux: Catch no DISPLAY= error * setfiles: print error if no default label found * semanage: list logins file entries in semanage login -l * semanage: good error message is sepolgen python module missing * gui: system-config-selinux: do not use lokkit * secon: add support for setrans color information in prompt output * restorecond: remove /etc/mtab from default list * gui: If you are not able to read enforcemode set it to False * genhomedircon: regenerate genhomedircon more often * restorecond: Add /etc/udpatedb.conf to restorecond.conf * genhomedircon generation to allow spec file to pass in SEMODULE_PATH * fixfiles: relabel only after specific date * po: update translations * sandbox: seunshare: do not reassign realloc value * seunshare: do checking on setfsuid * sestatus: rewrite to shut up coverity * Thu Jan 31 2013 Dan Walsh - 2.1.12-58- Reorginize sepolicy so all get_all functions are in main module- Add -B capability to fixfiles onboot and fixfiles restore, basically searches for all files created since the last boot. * Fri Jan 25 2013 Dan Walsh - 2.1.12-57- Update to latest patches from eparis/Upstream- fixfiles onboot will write any flags handed to it to /.autorelabel.- * Patch sent to initscripts to have fedora-autorelabel pass flags back to fixfiles restore- * This should allow fixfiles -F onboot, to force a hard relabel.- Add -p to show progress on full relabel. * Tue Jan 15 2013 Dan Walsh - 2.1.12-56- Additional changes for bash completsion and generate man page to match the w- Add newtype as a new qualifier to sepolicy generate. This new mechanism wil- a policy write to generate types after the initial policy has been written a- will autogenerate all of the interfaces.- I also added a -w options to allow policy writers from the command line to s- the writable directories of files.-- Modify network.py to include interface definitions for newly created port type- Standardize of te_types just like all of the other templates.- Change permissive domains creation to raise exception if sepolgen is not ins- get_te_results no longer needs or uses the opts parameter.- The compliler was complaining so I just removed the option.- Start returning analysis data for audit2allow * Tue Jan 15 2013 Dan Walsh - 2.1.12-55- Update Translations- Fix handling of semanage generate --cgi -n MODULE PATHTO/CGI- This fixes the spec file and script file getting wrong names for modules and types. * Wed Jan 09 2013 Dan Walsh - 2.1.12-54- Additional patch from Miroslav to handle role attributes * Wed Jan 09 2013 Dan Walsh - 2.1.12-53- Update with Miroslav patch to handle role attributes- Update Translations- import sepolicy will only throw exception on missing policy iff selinux is enabled * Sat Jan 05 2013 Dan Walsh - 2.1.12-52- Update to latest patches from eparis/Upstream- secon: add support for setrans color information in prompt output- Update translations * Fri Jan 04 2013 Dan Walsh - 2.1.12-51- Update translations- Fix sepolicy booleans to handle autogenerated booleans descriptions- Cleanups of sepolicy manpage- Fix crash on git_shell man page generation * Thu Jan 03 2013 Dan Walsh - 2.1.12-50- Update translations- update sepolicy manpage to generate fcontext equivalence data and to listdefault file context paths.- Add ability to generate policy for confined admins and domains like puppet. * Thu Dec 20 2012 Dan Walsh - 2.1.12-49- Fix semanage permissive , this time with the patch.- Update translations * Wed Dec 19 2012 Dan Walsh - 2.1.12-48- Fix semanage permissive- Change to use correct gtk forward button- Update po * Mon Dec 17 2012 Dan Walsh - 2.1.12-47- Move audit2why to -devel package * Mon Dec 17 2012 Dan Walsh - 2.1.12-46- sepolicy transition was blowing up. Also cleanup output when only source is specified.- sepolicy generate should allow policy modules names that include - or _ * Mon Dec 10 2012 Dan Walsh - 2.1.12-45- Apply patch from Miroslav to display proper range description in man pages g- Should print warning on missing default label when run in recusive mode iff- Remove extra -R description, and fix recursive description * Thu Dec 06 2012 Dan Walsh - 2.1.12-44- Additional fixes for disabled SELinux Box- system-config-selinux no longer relies on lokkit for /etc/selinux/config * Thu Dec 06 2012 Dan Walsh - 2.1.12-43- sepolicy should failover to installed policy file on a disabled SELinux box, if it exists. * Wed Dec 05 2012 Dan Walsh - 2.1.12-42- Update Translations- sepolicy network -d needs to accept multiple domains * Fri Nov 30 2012 Dan Walsh - 2.1.12-41- Add --path as a parameter to sepolicy generate- Print warning message if program does not exists when generating policy, and do not attempt to run nm command- Fix sepolicy generate -T to not take an argument, and supress the help message- Since this is really just a testing tool * Fri Nov 30 2012 Dan Walsh - 2.1.12-40- Fix sepolicy communicate to handle invalid input * Thu Nov 29 2012 Dan Walsh - 2.1.12-39- Fix sepolicy network -p to handle high ports * Thu Nov 29 2012 Dan Walsh - 2.1.12-38- Fix handling of manpages without entrypoints, nsswitch domains- Update Translations * Wed Nov 28 2012 Dan Walsh - 2.1.12-37- Move sepogen python bindings back into policycoreutils-python out of -devel, since sepolicy is using the * Tue Nov 27 2012 Dan Walsh - 2.1.12-36- Fix sepolicy/__init__.py to handle _() * Wed Nov 21 2012 Dan Walsh - 2.1.12-35- Add Miroslav Grepl patch to create etc_rw_t sock files policy * Fri Nov 16 2012 Dan Walsh - 2.1.12-34- Fix semanage to work without policycoreutils-devel installed- Update translations * Tue Nov 13 2012 Dan Walsh - 2.1.12-33- Fix semanage login -l to list contents of /etc/selinux/POLICY/logins directory * Tue Nov 13 2012 Dan Walsh - 2.1.12-32- Fix booleansPage not showing booleans- Fix audit2allow -b * Tue Nov 13 2012 Dan Walsh - 2.1.12-31- Fix sepolicy booleans again- Fix man page * Mon Nov 12 2012 Dan Walsh - 2.1.12-30- Move policy generation tools into policycoreutils-devel * Mon Nov 12 2012 Dan Walsh - 2.1.12-29- Document and fix sepolicy booleans- Update Translations- Fix several spelling mistakes * Wed Nov 07 2012 Dan Walsh - 2.1.12-27- Only report restorecon warning for missing default label, if not runningrecusively- Update translations * Mon Nov 05 2012 Dan Walsh - 2.1.12-26- Fix semanage booleans -l, move more boolean_dict handling into sepolicy- Update translations- Fixup sepolicy generate to discover /var/log, /var/run and /var/lib directories if they match the name- Fix kill function call should indicate signal_perms not kill capability- Error out cleanly in system-config-selinux, if it can not contact XServer * Mon Nov 05 2012 Dan Walsh - 2.1.12-25- Remove run_init, no longer needed with systemd.- Fix sepolicy generate to not include subdirs in generated fcontext file. (mgrepl patch) * Sat Nov 03 2012 Dan Walsh - 2.1.12-24- Fix manpage to generate proper man pages for alternate policy,basically allow me to build RHEL6 man pages on a Fedora 18 box, as long asI pull the policy, policy.xml and file_contexts and file_contexts.homedir * Thu Nov 01 2012 Dan Walsh - 2.1.12-23- Fix some build problems in sepolicy manpage and sepolicy transition * Tue Oct 30 2012 Dan Walsh - 2.1.12-22- Add alias man pages to sepolicy manpage * Mon Oct 29 2012 Dan Walsh - 2.1.12-21- Redesign sepolicy to only read the policy file once, not for every call * Mon Oct 29 2012 Dan Walsh - 2.1.12-20- Fixes to sepolicy transition, allow it to list all transitions from a domain * Sat Oct 27 2012 Dan Walsh - 2.1.12-19- Change sepolicy python bindings to have python pick policy file, fixes weird memory problems in sepolicy network * Fri Oct 26 2012 Dan Walsh - 2.1.12-18- Allow sepolicy to specify the policy to generate content from * Thu Oct 25 2012 Dan Walsh - 2.1.12-17- Fix semanage boolean -F to handle boolean subs * Thu Oct 25 2012 Dan Walsh - 2.1.12-16- Add Miroslav Grepl patch to generate html man pages- Update Translations- Add option to sandbox to shred files before deleting * Mon Oct 22 2012 Dan Walsh - 2.1.12-15- Add Requires(post) PKGNAME to sepolicy generate /usr/bin/pkg * Fri Oct 19 2012 Dan Walsh - 2.1.12-14- Add role_allow to sepolicy.search python bindings, this allows us to remove last requirement for setools-cmdline in gui tools.- Fix man page generator. * Wed Oct 17 2012 Dan Walsh - 2.1.12-13- Remove dwalshAATTredhat.com from man pages- Fix spec file for sepolicy generate * Wed Oct 17 2012 Dan Walsh - 2.1.12-12- Add missing spec.py from templates directory needed for sepolicy generate- Add /var/tmp as collection point for sandbox apps. * Tue Oct 16 2012 Dan Walsh - 2.1.12-11- Handle audit2allow -b in foreign locales * Tue Oct 16 2012 Dan Walsh - 2.1.12-10- Update sepolicy generate with patch to create spec file and man page.- Patch initiated by Miroslav Grepl * Wed Oct 10 2012 Dan Walsh - 2.1.12-9- Fix semanage to verify that types are appropriate for commands. * Patch initiated by mgrepl * Fixes problem of specifying non file_types for fcontext, or not port_types for semanage port * Tue Oct 09 2012 Dan Walsh - 2.1.12-8- Fix typo in preunstall line for restorecond- Add mgrepl patch to consolidate file context generated by sepolicy generate * Mon Oct 08 2012 Dan Walsh - 2.1.12-7- Fix manpage generation, missing import- Add equiv_dict to get samba booleans into smbd_selinux- Add proper translations for booleans and remove selinux.tbl * Sat Oct 06 2012 Dan Walsh - 2.1.12-6- Fix system-config-selinux to use sepolicy.generate instead of sepolgen * Thu Oct 04 2012 Dan Walsh - 2.1.12-5- Add sepolicy commands, and change tools to use them. * Tue Sep 25 2012 Dan Walsh - 2.1.12-4- Rebuild without bogus prebuild 64 bit seunshare app * Sun Sep 16 2012 Dan Walsh - 2.1.12-3- Allow fixfiles to specify -v, so they can get verbosity rather then progress.- Fix load_file Makefile to use SBINDIR rather then real OS.- Fix man pages in setfiles and restorecon to reflect what happens when you relabel the entire OS. * Sun Sep 16 2012 Dan Walsh - 2.1.12-2- Use systemd post install scriptlets * Thu Sep 13 2012 Dan Walsh - 2.1.12-1- Update to upstream * genhomedircon: manual page improvements * setfiles/restorecon minor improvements * run_init: If open_init_pty is not available then just use exec * newrole: do not drop capabilities when newrole is run as * restorecon: only update type by default * scripts: Don\'t syslog setfiles changes on a fixfiles restore * setfiles: do not syslog if no changes * Disable user restorecond by default * Make restorecon return 0 when a file has changed context * setfiles: Fix process_glob error handling * semanage: allow enable/disable under -m * add .tx to gitignore * translations: commit translations from Fedora community * po: silence build process * gui: Checking in policy to support polgengui and sepolgen. * gui: polgen: search for systemd subpackage when generating policy * gui: for exploring booleans * gui: system-config-selinux gui * Add Makefiles to support new gui code * gui: remove lockdown wizard * return equivalency records in fcontext customized * semanage: option to not load new policy into kernel after * sandbox: manpage update to describe standard types * setsebool: -N should not reload policy on changes * semodule: Add -N qualifier to no reload kernel policy * gui: polgen: sort selinux types of user controls * gui: polgen: follow symlinks and get the real path to * gui: Fix missing error function * setfiles: return errors when bad paths are given * fixfiles: tell restorecon to ignore missing paths * setsebool: error when setting multiple options * semanage: use boolean subs. * sandbox: Make sure Xephyr never listens on tcp ports * sepolgen: return and output constraint violation information * semanage: skip comments while reading external configuration files * restorecond: relabel all mount runtime files in the restorecond example * genhomedircon: dynamically create genhomedircon * Allow returning of bastard matches * sepolgen: return and output constraint violation information * audit2allow: one role/type pair per line * Wed Aug 08 2012 Dan Walsh - 2.1.11-6- Change polgen to generate dbus apps as optional so they can compile on minimal policy system, patch from Miroslav Grepl * Fri Jul 27 2012 Dan Walsh - 2.1.11-5- Fix sepolgen/audit2allow to handle multiple role/types in avc messages properly * Thu Jul 19 2012 Dan Walsh - 2.1.11-4- Fix restorecon to generate a better percentage of completion on restorecon -R /.- Have audit2allow look at the constaint violation and tell the user whether it- is because of user,role or level * Wed Jul 11 2012 Dan Walsh - 2.1.11-3- userapps is generating sandbox code in polgengui * Thu Jul 05 2012 Dan Walsh - 2.1.11-2- Remove load_policy symbolic link on usrmove systems this breaks the system * Wed Jul 04 2012 Dan Walsh - 2.1.11-1- Update to upstream - policycoreutils * restorecond: wrong options should exit with non-zero error code * restorecond: Add -h option to get usage command * resorecond: user: fix fd leak * mcstrans: add -f to run in foreground * semanage: fix man page range and level defaults * semanage: bash completion for modules should include -a,-m, -d * semanage: manpage update for -e * semanage: dontaudit off should work * semanage: locallist option does not take an argument * sepolgen: Make use of setools optional within sepolgen - sepolgen * Make use of setools optional within sepolgen * We need to support files that have a + in them * Thu May 24 2012 Dan Walsh - 2.1.11-18- Make restorecon exit with an error on a bad path * Thu May 24 2012 Dan Walsh - 2.1.11-17- Fix setsebool command, handling of = broken.- Add missing error option in booleansPage * Sun May 20 2012 Dan Walsh - 2.1.11-16- Fix sepolgen to use realpath on executables handed to it. - Brian Bickford * Fri May 18 2012 Dan Walsh - 2.1.11-15- Allow stream sock_files to be stored in /tmp and etc_rw_t directories by sepolgen- Trigger on selinux-policy needs to change to selinux-policy-devel- Update translations- Fix semanage dontaudit off/on exception * Tue May 08 2012 Dan Walsh - 2.1.11-12- Add -N qualifier to semanage, setsebool and semodule to allow you to update- policy without reloading it into the kernel. * Thu May 03 2012 Dan Walsh - 2.1.11-11- add some definition to the standard types available for sandboxes * Tue May 01 2012 Dan Walsh - 2.1.11-10- Remove lockdown wizard * Mon Apr 30 2012 Dan Walsh - 2.1.11-9- Fix semanage fcontext -E to extract the equivalance customizations. * Thu Apr 26 2012 Dan Walsh - 2.1.11-8- Add mgrepl patch to have sepolgen search for -systemd rpm packages * Tue Apr 24 2012 Dan Walsh - 2.1.11-7- Apply Stef Walter patch for semanage man page * Mon Apr 23 2012 Dan Walsh - 2.1.11-6- Rebuild to get latest libsepol which fixes the file_name transition problems- Update translations- Fix calls to close fd for restorecond * Fri Apr 13 2012 Dan Walsh - 2.1.11-5- Update translations- Fix sepolgen to discover unit files in /lib/systemd/ * Tue Apr 03 2012 Dan Walsh - 2.1.11-4- Update translations- Fix segfault on restorecon * Tue Apr 03 2012 Dan Walsh - 2.1.11-3- Allow filename transitions to use + in a file name * Fri Mar 30 2012 Dan Walsh - 2.1.11-2- Change policycoreutils-python to require selinux-policy-devel package * Thu Mar 29 2012 Dan Walsh - 2.1.11-1- Update to upstream - policycoreutils * sandbox: do not propogate inside mounts outside * sandbox: Removing sandbox init script, should no longer be necessary * restorecond: Stop using deprecated interfaces for g_io * semanage: proper auditting of user changes for LSPP * semanage: audit message to show what record(s) and item(s) have chaged * scripts: Update Makefiles to handle /usrmove * mcstrans: Version should have been bumped on last check in * seunshare: Only drop caps not the Bounding Set from seunshare * Add bash-completion scripts for setsebool and semanage * newrole: Use correct capng calls in newrole * Fix infinite loop with inotify on 2.6.31 kernels * fix ftbfs with hardening flags * Only run setfiles if we found read-write filesystems to run it on * update .po files * remove empty po files * do not fail to install if unable to make load_policy lnk file - sepolgen * Fix dead links to www.nsa.gov/selinux * audit.py Dont crash if empty data is passed to sepolgen * do not use md5 when calculating hash signatures * fix detection of policy loads * Wed Mar 28 2012 Dan Walsh - 2.1.10-30- Have sepolgen script specify the pp file with the make command. From mgrepl. * Wed Mar 21 2012 Dan Walsh - 2.1.10-29- Fix sepolgen handling of unit files. * Thu Mar 08 2012 Dan Walsh - 2.1.10-28- Require selinux-policy-doc * Thu Mar 08 2012 Dan Walsh - 2.1.10-27- Fix unit file handling in sepolgen * Wed Feb 29 2012 Dan Walsh - 2.1.10-26- Add bash_command completion for setsebool/getsebool * Mon Feb 27 2012 Dan Walsh - 2.1.10-25- Disable restorecond on desktop by default- Change seunshare to not modify the bounding set * Mon Feb 20 2012 Dan Walsh - 2.1.10-24- Stop using sandbox init in post install since it no longer exists. * Thu Feb 16 2012 Dan Walsh - 2.1.10-23- Change to use new selinux_current_policy_path() * Wed Feb 15 2012 Dan Walsh - 2.1.10-22- Change to use new selinux_binary_policy_path()- Add systemd_passwd_agent_exec($1), and systemd_read_fifo_file_passwd_run($1) to templates for _admin interface * Fri Feb 03 2012 Dan Walsh - 2.1.10-21- On full relabels we will now show a estimated percent complete rather thenjust *s. * Wed Feb 01 2012 Dan Walsh - 2.1.10-20- Add unit_file.py for sepolgen * Tue Jan 31 2012 Dan Walsh - 2.1.10-19- Change sepolgen to use sha256 instead of md5 * Mon Jan 30 2012 Dan Walsh - 2.1.10-18- Stop syslogging on full restore- Stop syslogging when restorecon is not changing values * Fri Jan 27 2012 Dan Walsh - 2.1.10-17- Change semanage to produce proper audit records for Common Criteria- Cleanup packaging for usrmove * Thu Jan 26 2012 Harald Hoyer 2.1.10-16- fixed load_policy location * Thu Jan 26 2012 Harald Hoyer 2.1.10-15- fixed load_policy location * Thu Jan 26 2012 Harald Hoyer 2.1.10-14- fixed load_policy location * Wed Jan 25 2012 Harald Hoyer 2.1.10-13- add filesystem guard * Wed Jan 25 2012 Harald Hoyer 2.1.10-12- install everything in /usr https://fedoraproject.org/wiki/Features/UsrMove * Tue Jan 24 2012 Dan Walsh - 2.1.10-11- restorecond fixes: Stop using depracated g_io interfaces Exit with non zero exit code if wrong options given Add -h option * Thu Jan 19 2012 Dan Walsh - 2.1.10-10- Eliminate not needed Requires * Wed Jan 18 2012 Dan Walsh - 2.1.10-9- fix sepolgen to not crash on echo \"\" | audit2allow * Mon Jan 16 2012 Dan Walsh - 2.1.10-8- Remove sandbox init script, should no longer be necessary * Sun Jan 15 2012 Dan Walsh - 2.1.10-7- Add unit file support to sepolgen, and cleanup some of the output. * Mon Jan 09 2012 Dan Walsh - 2.1.10-5- Fix English in templates for sepolgen * Fri Dec 23 2011 Dan Walsh - 2.1.10-4- Fix the handling of namespaces in seunshare/sandbox.- Currently mounting of directories within sandbox is propogating to the- parent namesspace. * Thu Dec 22 2011 Dan Walsh - 2.1.10-3- Add umount code to seunshare to cleanup left over mounts of /var/tmp * Wed Dec 21 2011 Dan Walsh - 2.1.10-2- Remove open_init_pty * Wed Dec 21 2011 Dan Walsh - 2.1.10-1-Update to upstream- sepolgen * better analysis of why things broke- policycoreutils * Remove excess whitespace * sandbox: Add back in . functions to sandbox.init script * Fix Makefile to match other policycoreutils Makefiles * semanage: drop unused translation getopt * Thu Dec 15 2011 Dan Walsh - 2.1.9-3- Bump libsepol version requires rebuild * Wed Dec 07 2011 Dan Walsh - 2.1.9-2- Add back accidently dropped patches for semanage * Tue Dec 06 2011 Dan Walsh - 2.1.9-1- Upgrade to upstream * sandbox: move sandbox.conf.5 to just sandbox.5 * po: Makefile use -p to preserve times to allow multilib simultatious installs * of po files * sandbox: Allow user to specify the DPI value for X in a sandbox * sandbox: make sure the domain launching sandbox has at least 100 categories * sandbox: do not try forever to find available category set * sandbox: only complain if sandbox unable to launch * sandbox: init script run twice is still successful * semanage: print local and dristo equiv rules * semanage: check file equivalence rules for conflict * semanage: Make sure semanage fcontext -l -C prints even if local keys * are not defined * semanage: change src,dst to target,substitute for equivalency * sestatus: Updated sestatus and man pages. * Added SELinux config file man page. * add clean target to man Makefile * Wed Nov 30 2011 Dan Walsh - 2.1.8-8- Fix semange fcontext -a to check for more conflicts on equivalency * Tue Nov 29 2011 Dan Walsh - 2.1.8-7- Fix dpi handling in sandbox- Make sure semanage fcontext -l -C prints if only local equiv have changed * Wed Nov 16 2011 Dan Walsh - 2.1.8-6- Add listing of distribution equivalence class from semanage fcontext -l- Add checking to semanage fcontext -a to guarantee a file specification will not be masked by an equivalence * Wed Nov 16 2011 Dan Walsh - 2.1.8-5- Allow ~ as a valid part of a filename in sepolgen * Fri Nov 11 2011 Dan Walsh - 2.1.8-4- sandbox init script should always return 0- sandbox command needs to check range of categories and report error if not big enough * Mon Nov 07 2011 Dan Walsh - 2.1.8-3- Allow user to specify DPI when running sandbox * Mon Nov 07 2011 Dan Walsh - 2.1.8-2- Add Miroslav patch to return all attributes * Fri Nov 04 2011 Dan Walsh - 2.1.8-1- Upgrade to policycoreutils upstream * sandbox: Maintain the LANG environment into the sandbox * audit2allow: use audit2why internally * fixfiles: label /root but not /var/lib/BackupPC * semanage: update local boolean settings is dealing with localstore * semanage: missing modify=True * semanage: set modified correctly * restorecond: make restorecond dbuss-able * restorecon: Always check return code on asprintf * restorecond: make restorecond -u exit when terminal closes * sandbox: introduce package name and language stuff * semodule_package: remove semodule_unpackage on clean * fix sandbox Makefile to support DESTDIR * semanage: Add -o description to the semanage man page * make use of the new realpath_not_final function * setfiles: close /proc/mounts file when finished * semodule: Document semodule -p in man page * setfiles: fix use before initialized * restorecond: Add .local/share as a directory to watch- Upgrade to sepolgen upstream * Ignore permissive qualifier if found in an interface * Return name field in avc data * Mon Oct 31 2011 Dan Walsh - 2.1.7-6- Rebuild versus newer libsepol * Fri Oct 28 2011 Dan Walsh - 2.1.7-5- A couple of minor coverity fixes for a potential leaked file descriptor- An an unchecked return code.- Add ~/.local/share/ * to restorecond_user watches * Thu Oct 13 2011 Dan Walsh - 2.1.7-4- Have sepolgen return name field in AVC * Thu Oct 06 2011 Dan Walsh - 2.1.7-3- restorecond -u needs to watch terminal for exit if run outside of dbus. * Tue Oct 04 2011 Dan Walsh - 2.1.7-2- Do not drop capabilities if running newrole as root * Fri Sep 30 2011 Dan Walsh - 2.1.7-1-Update to upstream * semanage: fix indentation error in seobject * Thu Sep 29 2011 Dan Walsh - 2.1.6-3- Ignore permissive commands in interfaces * Thu Sep 29 2011 Dan Walsh - 2.1.6-2- Remove gnome requirement from polgengui * Mon Sep 19 2011 Dan Walsh - 2.1.6-1-Update to upstream policycoreutils-2.1.6 * sepolgen-ifgen: new attr-helper does something * audit2allow: use alternate policy file * audit2allow: sepolgen-ifgen use the attr helper * setfiles: switch from stat to stat64 * setfiles: Fix potential crash using dereferenced ftsent * setfiles: do not wrap * output at 80 characters * sandbox: add -Wall and -Werror to makefile * sandbox: add sandbox cgroup support * sandbox: rewrite /tmp handling * sandbox: do not bind mount so much * sandbox: add level based kill option * sandbox: cntrl-c should kill entire process control group * Create a new preserve_tunables flag in sepol_handle_t. * semanage: show running and disk setting for booleans * semanage: Dont print heading if no items selected * sepolgen: audit2allow is mistakakenly not allowing valid module names * semanage: Catch RuntimeErrors, that can be generated when SELinux is disabled * More files to ignore * tree: default make target to all not install * sandbox: do not load unused generic init functions sepolgen-1.1.2 * src: sepolgen: add attribute storing infrastructure * Change perm-map and add open to try to get better results on * look for booleans that might solve problems * sepolgen: audit2allow is mistakakenly not allowing valid module names * tree: default make target to all not install * Wed Sep 14 2011 Dan Walsh - 2.1.5-6- Change separator on -L from ; to : * Thu Sep 08 2011 Dan Walsh - 2.1.5-5- Add back lockdown wizard for booleans using pywebkitgtk | |