Changelog for
libsepol1-2.5-68.35.x86_64.rpm :
Fri Jul 15 14:00:00 2016 jengelhAATTinai.de
- Update RPM groups, trim description and combine filelist entries.
Thu Jul 14 14:00:00 2016 mpluskalAATTsuse.com
- Cleanup spec file with spec-cleaner
- Make spec file a bit more easy
- Ship new supbackage (-tools)
Thu Jul 14 14:00:00 2016 jsegitzAATTnovell.com
- Without bug number no submit to SLE 12 SP2 is possible, so to make
sle-changelog-checker happy: bsc#988977
Thu Jul 14 14:00:00 2016 jsegitzAATTnovell.com
- Adjusted source link
Tue Jul 5 14:00:00 2016 iAATTmarguerite.su
- update version 2.5
* Fix unused variable annotations
* Fix uninitialized variable in CIL
* Validate extended avrules and permissionxs in CIL
* Add support in CIL for neverallowx
* Fully expand neverallowxperm rules
* Add support for unordered classes to CIL
* Add neverallow support for ioctl extended permissions
* Improve CIL block and macro call recursion detection
* Fix CIL uninitialized false positive in cil_binary
* Provide error in CIL if classperms are empty
* Add userattribute{set} functionality to CIL
* fix CIL blockinherit copying segfault and add macro restrictions
* fix CIL NULL pointer dereference when copying classpermission/set
* Add CIL support for ioctl whitelists
* Fix memory leak when destroying avtab
* Replace sscanf in module_to_cil
* Improve CIL resolution error messages
* Fix policydb_read for policy versions < 24
* Added CIL bounds checking and refactored CIL Neverallow checking
* Refactored libsepol Neverallow and bounds (hierarchy) checking
* Treat types like an attribute in the attr_type_map
* Add new ebitmap function named ebitmap_match_any()
* switch operations to extended perms
* Write auditadm_r and secadm_r roles to base module when writing CIL
* Fix module to CIL to only associate declared roleattributes with in-scope types
* Don\'t allow categories/sensitivities inside blocks in CIL
* Replace fmemopen() with internal function in libsepol
* Verify users prior to evaluating users in cil
* Binary modules do not support ioctl rules
* Add support for ioctl command whitelisting
* Don\'t use symbol versioning for static object files
* Add sepol_module_policydb_to_cil(), sepol_module_package_to_cil(),
and sepol_ppfile_to_module_package()
* Move secilc out of libsepol
* fix building Xen policy with devicetreecon, and add devicetreecon
CIL documentation
* bool_copy_callback set state on creation
* Add device tree ocontext nodes to Xen policy
* Widen Xen IOMEM context entries
* Fix error path in mls_semantic_level_expand()
* Update to latest CIL, includes new name resolution and fixes ordering
issues with blockinherit statements, and bug fixes
- changes in 2.4
* Remove assumption that SHLIBDIR is ../../ relative to LIBDIR
* Fix bugs found by hardened gcc flags
* Build CIL into libsepol. libsepol can be built without CIL by setting the
DISABLE_CIL flag to \'y\'
* Add an API function to set target_platform
* Report all neverallow violations
* Improve check_assertions performance
* Allow libsepol C++ static library on device
Fri May 16 14:00:00 2014 vcizekAATTsuse.com
- update to 2.3
* Improve error message for name-based transition conflicts.
* Revert libsepol: filename_trans: use some better sorting to compare and merge.
* Report source file and line information for neverallow failures.
* Fix valgrind errors in constraint_expr_eval_reason from Richard Haines.
* Add sepol_validate_transition_reason_buffer function from Richard Haines.
- dropped libsepol-2.1.4-role_fix_callback.patch (upstream)
Thu Oct 31 13:00:00 2013 p.drouandAATTgmail.com
- Update to version 2.2
* Allow constraint denial cause to be determined
- Add kernel policy version 29.
- Add modular policy version 17.
- Add sepol_compute_av_reason_buffer(), sepol_string_to_security
_class(), sepol_string_to_av_perm().
* Support overriding Makefile RANLIB
* Fix man pages
- Remove libsepol-rhat.patch; merged on upstream
Thu Jun 27 14:00:00 2013 vcizekAATTsuse.com
- change the source url to the official 2.1.9 release tarball
Sat Jun 22 14:00:00 2013 crrodriguezAATTopensuse.org
- Build with LFS_CFLAGS for 32 bit archs
Fri Apr 5 14:00:00 2013 vcizekAATTsuse.com
- remove a debugging artifact in spec
Thu Apr 4 14:00:00 2013 vcizekAATTsuse.com
- fixed source url
Wed Feb 13 13:00:00 2013 vcizekAATTsuse.com
- update to 2.1.9
* filename_trans: use some better sorting to compare and merge
* coverity fixes
* implement default type policy syntax
* Fix memory leak issues found by Klocwork
- added libsepol-rhat.patch
Mon Jan 7 13:00:00 2013 jengelhAATTinai.de
- Remove obsolete defines/sections
Mon Dec 10 13:00:00 2012 p.drouandAATTgmail.com
- Update to 2.1.8 version:
* fix neverallow checking on attributes
* Move context_copy() after switch block in ocontext_copy_
*().
* check for missing initial SID labeling statement.
* Add always_check_network policy capability
* role_fix_callback skips out-of-scope roles during expansion.
Thu Oct 25 14:00:00 2012 vcizekAATTsuse.com
- skip roles which are out of scope when expanding attributes
- needed for building selinux-policy
Wed Jul 25 14:00:00 2012 meissnerAATTsuse.com
- updated to 2.1.4
- lots of updates
Wed Oct 5 14:00:00 2011 uliAATTsuse.com
- cross-build fix: use %__cc macro
Mon Jun 28 14:00:00 2010 jengelhAATTmedozas.de
- use %_smp_mflags
Sat Apr 24 14:00:00 2010 cooloAATTnovell.com
- buildrequire pkg-config to fix provides
Thu Feb 25 13:00:00 2010 prusnakAATTsuse.cz
- updated to 2.0.41
* changes too numerous to list
Sun Dec 13 13:00:00 2009 jengelhAATTmedozas.de
- add baselibs.conf as a source
Wed Nov 11 13:00:00 2009 crrodriguezAATTopensuse.org
- libsepol-devel Requires glibc-devel
Fri Jun 19 14:00:00 2009 prusnakAATTsuse.cz
- put static library in libsepol-devel-static
Wed May 27 14:00:00 2009 prusnakAATTsuse.cz
- updated to 2.0.36
* fix alias field in module format, caused by boundary format
change from Caleb Case
* fix boolean state smashing from Joshua Brindle