|
|
|
|
Changelog for policycoreutils-2.7-18.fc28.i686.rpm :
* Tue Apr 03 2018 Petr Lautrbach - 2.7-18- Move semodule_ * utilities to policycoreutils package (#1562549) * Thu Mar 22 2018 Petr Lautrbach - 2.7-17- semanage/seobject.py: Fix undefined store check (#1559174) * Fri Mar 16 2018 Petr Lautrbach - 2.7-16- Build python only subpackages as noarch- Move semodule_package to policycoreutils-devel * Tue Mar 13 2018 Petr Lautrbach - 2.7-15- sepolicy: Fix translated strings with parameters- sepolicy: Support non-MLS policy- sepolicy: Initialize policy.ports as a dict in generate.py- gui/polgengui.py: Use stop_emission_by_name instead of emit_stop_by_name- Minor update for bash completion- semodule_package: fix semodule_unpackage man page- gui/semanagePage: Close \"edit\" and \"add\" dialogues when successfull- gui/fcontextPage: Set default object class in addDialog\\- sepolgen: fix typo in PolicyGenerator- build: follow standard semantics for DESTDIR and PREFIX * Mon Feb 26 2018 Petr Lautrbach - 2.7-14- Use Fedora RPM build flags (#1548740) * Tue Feb 20 2018 Petr Lautrbach - 2.7-13- Fix mangling of python shebangs * Mon Feb 19 2018 Miro Hrončok - 2.7-12- Rename the python3 subpackage to have prefix, not suffix- Use python3 prefixes in requires where possible * Thu Feb 15 2018 Petr Lautrbach - 2.7-11- Rewrite selinux-polgengui to use Gtk3- Drop python2 and gnome-python2 from gui Requires * Fri Feb 09 2018 Fedora Release Engineering - 2.7-10- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Wed Jan 31 2018 Petr Lautrbach - 2.7-9- Require audit-libs-python2 * Thu Jan 18 2018 Igor Gnatenko - 2.7-8- Remove obsolete scriptlets * Wed Dec 20 2017 Petr Lautrbach - 2.7-7- semanage: bring semanageRecords.set_reload back to seobject.py (#1527745) * Wed Dec 13 2017 Petr Lautrbach - 2.7-6- semanage: make seobject.py backward compatible- Own %{pythonX_sitelib}/site-packages/sepolicy directories (#1522942) * Wed Nov 22 2017 Petr Lautrbach - 2.7-5- sepolicy: Fix sepolicy manpage- semanage: Update Infiniband code to work on python3- semanage: Fix export of ibendport entries- semanage: Enforce noreload only if it\'s requested by -N option * Fri Oct 20 2017 Petr Lautrbach - 2.7-4- restorecond: check write() and daemon() results- sepolicy: do not fail when file_contexts.local or .subs do not exist- sepolicy: remove stray space in section \"SEE ALSO\"- sepolicy: fix misspelling of _ra_content_t suffix- gui: port to Python 3 by migrating to PyGI- gui: remove the status bar- gui: fix parsing of \"semodule -lfull\" in tab Modules- gui: delete overridden definition of usersPage.delete()- Enable listing file_contexts.homedirs (#1409813)- remove semodule_deps * Sat Aug 19 2017 Zbigniew Jędrzejewski-Szmek - 2.7-3- Also add Provides for the old name without %_isa * Sat Aug 19 2017 Zbigniew Jędrzejewski-Szmek - 2.7-2- Python 2 binary package renamed to python2-policycoreutils See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3 * Mon Aug 07 2017 Petr Lautrbach - 2.7-1- Update to upstream release 2017-08-04- Move DBUS API from -gui to -dbus package * Thu Aug 03 2017 Fedora Release Engineering - 2.6-9- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild * Sun Jul 30 2017 Florian Weimer - 2.6-8- Rebuild with binutils fix for ppc64le (#1475636) * Fri Jul 28 2017 Petr Lautrbach - 2.6-7- Make \'sepolicy manpage\' and \'sepolicy transition\' faster- open_init_pty: restore stdin/stdout to blocking upon exit- fixfiles: do not dereference link files in tmp- fixfiles: use a consistent order for options to restorecon- fixfiles: don\'t ignore `-F` when run in `-C` mode- fixfiles: remove bad modes of \"relabel\" command- fixfiles: refactor into the `set -u` dialect- fixfiles: if restorecon aborts, we should too- fixfiles: usage errors are fatal- fixfiles: syntax error- fixfiles: remove two unused variables- fixfiles: tidy up usage(), manpage synopsis- fixfiles: deprecate -l option- fixfiles: move logit call outside of redirected function- fixfiles: fix logging about R/O filesystems- fixfiles: clarify exclude_dirs()- fixfiles: remove (broken) redundant code * Thu Jul 27 2017 Fedora Release Engineering - 2.6-6- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild * Thu Apr 06 2017 Petr Lautrbach - 2.6-5- semanage: Unify argument handling (#1398987)- setfiles: set up a logging callback for libselinux- setfiles: Fix setfiles progress indicator- setfiles: stdout messages don\'t need program prefix- setfiles: don\'t scramble stdout and stderr together (#1435894)- restorecond: Decrease loglevel of termination message (#1264505)- fixfiles should handle path arguments more robustly- fixfiles: handle unexpected spaces in command- fixfiles: remove useless use of cat (#1435894)- semanage: Add checks if a module name is passed in (#1420707)- semanage: fix export of fcontext socket entries (#1435127)- selinux-autorelabel: remove incorrect redirection to /dev/null (#1415674) * Fri Mar 17 2017 Petr Lautrbach - 2.6-4- Fix selinux-polgengui (#1432337)- sepolicy - fix obtaining domain name in HTMLManPages * Tue Feb 28 2017 Petr Lautrbach - 2.6-3- Fix several issues in gui and \'sepolicy manpage\' (#1416372) * Thu Feb 23 2017 Petr Lautrbach - 2.6-2- Use %{__python3} instead of python3 * Mon Feb 20 2017 Petr Lautrbach - 2.6-1.1- Fix pp crash when processing base module (#1417200)- Update to upstream release 2016-10-14 * Wed Feb 15 2017 Igor Gnatenko - 2.5-22- Rebuild for brp-python-bytecompile * Sat Feb 11 2017 Fedora Release Engineering - 2.5-21- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild * Wed Dec 21 2016 Kevin Fenzi - 2.5-20- Rebuild for python 3.6 * Thu Dec 01 2016 Petr Lautrbach - 2.5-19- seobject: Handle python error returns correctly- policycoreutils/sepolicy/gui: fix current selinux state radiobutton- policycoreutils: semodule_package: do not fail with an empty fc file * Tue Nov 22 2016 Petr Lautrbach - 2.5-18- Update translations- Fix fcontextPage editing features (#1344842) * Mon Oct 03 2016 Petr Lautrbach 2.5-17- sandbox: Use dbus-run-session instead of dbus-launch when available- hll/pp: Change warning for module name not matching filename to match new behavior- Remove LDFLAGS from CFLAGS- sandbox: create a new session for sandboxed processes- sandbox: do not try to setup directories without -X or -M- sandbox: do not run xmodmap in a new X session- sandbox: Use GObject introspection binding instead of pygtk2- sandbox: fix file labels on copied files- sandbox: tests - close stdout of p- sandbox: tests - use sandbox from cwd- audit2allow: tests should use local copy not system- audit2allow: fix audit2why import from seobject- audit2allow: remove audit2why so that it gets symlinked- semanage: fix man page and help message for import option- semanage: fix error message for fcontext -m- semanage: Fix semanage fcontext -D- semanage: Correct fcontext auditing- semanage: Default serange to \"s0\" for port modify- semanage: Use socket.getprotobyname for protocol- semanage: fix modify action in node and interface- fixfiles: Pass -n to restorecon for fixfiles check- sepolicy: Check get_rpm_nvr_list() return value- Don\'t use subprocess.getstatusoutput() in Python 2 code- semanage: Add auditing of changes in records- Remove unused \'q\' from semodule getopt string * Mon Aug 01 2016 Petr Lautrbach 2.5-16- Remove unused autoconf files from po/- Remove duplicate, empty translation files- Rebuilt with libsepol-2.5-9, libselinux-2.5-11, libsemanage-2.5-7 * Thu Jul 21 2016 Petr Lautrbach 2.5-15- Fix sandbox -X issue related to python3 (#1358138) * Wed Jul 20 2016 Richard W.M. Jones - 2.5-14- Use generator approach to fix autorelabel * Tue Jul 19 2016 Fedora Release Engineering - 2.5-13- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages * Thu Jul 14 2016 Petr Lautrbach - 2.5-12- open_init_pty: Do not error on EINTR- Fix [-s STORE] typos in semanage- Update sandbox types in sandbox manual- Update translations * Mon Jun 27 2016 Petr Lautrbach - 2.5-11- Convert sandbox to gtk-3 using pygi-convert.sh (#1343166) * Thu Jun 23 2016 Petr Lautrbach - 2.5-10- Fix typos in semanage manpages- Fix the documentation of -l,--list for semodule- Minor fix in a French translation- Fix the extract example in semodule.8- Update sandbox.8 man page- Remove typos from chcat --help- sepolgen: Remove additional files when cleaning * Wed May 11 2016 Petr Lautrbach - 2.5-9- Fix multiple spelling errors- Rebuild with libsepol-2.5-6 * Mon May 02 2016 Petr Lautrbach - 2.5-8- Rebuilt with libsepol-2.5-5 * Fri Apr 29 2016 Petr Lautrbach - 2.5-7- hll/pp: Warn if module name different than output filename * Mon Apr 25 2016 Petr Lautrbach - 2.5-6- Ship selinux-autorelabel utility and systemd unit files (#1328825) * Fri Apr 08 2016 Petr Lautrbach - 2.5-5- sepolgen: Add support for TYPEBOUNDS statement in INTERFACE policy files (#1319338) * Fri Mar 18 2016 Petr Lautrbach - 2.5-4- Add documentation for MCS separated domains- Move svirt man page out of libvirt into its own * Thu Mar 17 2016 Petr Lautrbach - 2.5-3- policycoreutils: use python3 in chcat(#1318408) * Sat Mar 05 2016 Petr Lautrbach 2.5-2- policycoreutils/sepolicy: selinux_server.py to use GLib instead of gobject- policycoreutils-gui requires python-slip-dbus (#1314685) * Tue Feb 23 2016 Petr Lautrbach 2.5-1- Update to upstream release 2016-02-23 * Thu Feb 04 2016 Fedora Release Engineering - 2.4-21- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild * Mon Dec 14 2015 Petr Lautrbach - 2.4-20- Fix \'semanage permissive -l\' subcommand (#1286325)- Several \'sepolicy gui\' fixes (#1281309,#1281309,#1282382) * Tue Nov 17 2015 Petr Lautrbach 2.4-19- Require at least one argument for \'semanage permissive -d\' (#1255676) * Mon Nov 16 2015 Petr Lautrbach 2.4-18- Improve sepolicy command line interface- Fix sandbox to propagate specified MCS/MLS Security Level. (#1279006)- Fix \'audit2allow -R\' (#1280418) * Thu Nov 12 2015 Fedora Release Engineering - 2.4-17- Rebuilt for https://fedoraproject.org/wiki/Changes/python3.5 * Mon Nov 09 2015 Petr Lautrbach 2.4-16- policycoreutils-gui needs policycoreutils-python (#1279046) * Wed Nov 04 2015 Robert Kuska - 2.4-15- Rebuilt for Python3.5 rebuild * Thu Oct 08 2015 Petr Lautrbach 2.4-14- Revert the attempt to port -gui to GTK 3 (#1269328, #1266059) * Fri Oct 02 2015 Petr Lautrbach 2.4-13- newrole: Set keepcaps around setresuid calls- newrole: Open stdin as read/write * Fri Sep 04 2015 Petr Lautrbach 2.4-12- Fix several semanage issue (#1247714)- Decode output from subprocess, if error occurred (#1247039) * Wed Sep 02 2015 Petr Lautrbach 2.4-11- audit2allow, audit2why - ignore setlocale errors (#1208529) * Fri Aug 21 2015 Petr Lautrbach 2.4-10- Port sandbox to GTK 3 and fix issue with Xephyr * Thu Aug 13 2015 Petr Lautrbach 2.4-9- Fix another python3 issues mainly in sepolicy (#1247039,#1247575,#1251713) * Thu Aug 06 2015 Petr Lautrbach 2.4-8- Fix multiple python3 issues in sepolgen (#1249388,#1247575,#1247564) * Mon Jul 27 2015 Petr Lautrbach 2.4-7- policycoreutils-python3 depends on python-IPy-python3 * Mon Jul 27 2015 Petr Lautrbach 2.4-6- policycoreutils-devel depends on policycoreutils-python-utils (#1246818) * Fri Jul 24 2015 Petr Lautrbach 2.4-5- Move python utilities from -python to -python-utilities- All scripts originally from policycoreutils-python use python 3 now * Fri Jul 24 2015 Petr Lautrbach 2.4-4- policycoreutils: semanage: fix moduleRecords deleteall method * Thu Jul 23 2015 Petr Lautrbach 2.4-3- Improve compatibility with python 3- Add sepolgen module to python3 package * Tue Jul 21 2015 Petr Lautrbach 2.4-2- Add Python3 support for sepolgen module (#1125208,#1125209) * Tue Jul 21 2015 Petr Lautrbach 2.4-1.1- Update to 2.4 release * Wed Jul 15 2015 Petr Lautrbach 2.4-0.7- Fix typo in semanage args for minimum policy store * Fri Jul 03 2015 Petr Lautrbach 2.4-0.6- policycoreutils: semanage: update to new source policy infrastructure- semanage: move permissive module creation to /tmp * Thu Jun 18 2015 Fedora Release Engineering - 2.3-18- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Wed May 06 2015 Petr Lautrbach 2.3-17- setfiles/restorecon: fix -r/-R option (#1211721) * Mon Apr 13 2015 Petr Lautrbach 2.4-0.4- Update to upstream 2.4 * Tue Feb 24 2015 Petr Lautrbach 2.3-16- Temporary removed Requires:audit-libs-python from policycoreutils-python3 subpackage (#1195139)- Simplication of sepolicy-manpage web functionality (#1193552) * Mon Feb 02 2015 Petr Lautrbach 2.3-15- We need to cover file_context.XXX.homedir to have fixfiles with exclude_dirs working correctly- Use dnf instead of yum (#1156547) * Tue Nov 18 2014 Dan Walsh - 2.3-14- Audit2allow will check for mislabeled files, and tells user to fix the label.- Also checks for basefiles and suggests creating a different label.- Patch from Ryan Hallisey * Wed Nov 05 2014 Miroslav Grepl - 2.3-13- Switch back to yum. Need additional fixes to make it working correctly. * Wed Nov 05 2014 Miroslav Grepl - 2.3-12- Switch over to dnf from yum * Tue Sep 23 2014 Miroslav Grepl - 2.3-11- Improvements to audit2allow from rhalliseAATTredhat.com * Check for mislabeled files. * Check for base file use and * Suggest writable files as alternatives * Sun Aug 17 2014 Fedora Release Engineering - 2.3-10- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Mon Aug 04 2014 Dan Walsh - 2.3-9- Remove build requires for openbox, not needed * Thu Jul 31 2014 Tom Callaway - 2.3-8- fix license handling * Wed Jul 23 2014 Miroslav Grepl - 2.3-7- Examples are no longer in the main semanage man page (#1084390)- Add support for Fedora22 man pages. We need to fix it to not using hardcoding.- Print usage for all mutually exclusive options.- Fix selinux man page to refer seinfo and sesearch tools. * Sat Jun 07 2014 Fedora Release Engineering - 2.3-6- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Wed May 28 2014 Kalev Lember - 2.3-5- Rebuilt for https://fedoraproject.org/wiki/Changes/Python_3.4 * Tue May 20 2014 Miroslav Grepl - 2.3-4- Fix setfiles to work correctly if -r option is defined * Fri May 16 2014 Dan Walsh - 2.3-3- Update Miroslav Grepl Patches * If there is no executable we don\'t want to print a part of STANDARD FILE CON * Add-manpages-for-typealiased-types * Make fixfiles_exclude_dirs working if there is a substituion for the given d * Mon May 12 2014 Miroslav Grepl - 2.3-2- If there is no executable we don\'t want to print a part of STANDARD FILE CONTEXT * Tue May 06 2014 Dan Walsh - 2.3-1- Update to upstream * Add -P semodule option to man page from Dan Walsh. * selinux_current_policy_path will return none on a disabled SELinux system from Dan Walsh. * Add new icons for sepolicy gui from Dan Walsh. * Only return writeable files that are enabled from Dan Walsh. * Add domain to short list of domains, when -t and -d from Dan Walsh. * Fix up desktop files to match current standards from Dan Walsh. * Add support to return sensitivities and categories for python from Dan Walsh. * Cleanup whitespace from Dan Walsh. * Add message to tell user to install sandbox policy from Dan Walsh. * Add systemd unit file for mcstrans from Laurent Bigonville. * Improve restorecond systemd unit file from Laurent Bigonville. * Minor man pages improvements from Laurent Bigonville. * Tue May 06 2014 Miroslav Grepl - 2.2.5-15- Apply patch to use setcon in seunshare from lutoAATTmit.edu * Wed Apr 30 2014 Dan Walsh - 2.2.5-14- Remove requirement for systemd-units * Fri Apr 25 2014 Miroslav Grepl - 2.2.5-13- Fix previous Fix-STANDARD_FILE_CONTEXT patch to exclude if non_exec does not exist * Thu Apr 24 2014 Miroslav Grepl - 2.2.5-12- Add policycoreutils-rhat-revert.patch to revert the last two commits to make build working- Add 0001-Fix-STANDARD_FILE_CONTEXT-section-in-man-pages patch * Tue Apr 01 2014 Dan Walsh - 2.2.5-11- Update Translations * Thu Mar 27 2014 Miroslav Grepl - 2.2.5-10- Add support for Fedora21 html manpage structure- Fix broken dependencies to require only usermode-gtk * Wed Mar 26 2014 Dan Walsh - 2.2.5-9- mgrepl [PATCH] Deleteall user customization fails if there is a user used- for the default login. We do not want to fail on it and continue to delete- customizations for users which are not used for default login. * Mon Mar 24 2014 Dan Walsh - 2.2.5-8- Update Translations- Make selinux-policy build working also on another architectures related to s- Miroslav grepl patch to fix the creation of man pages on different architectures.- Add ability to list the actual active modules- Fix spelling mistake on sesearch in generate man pages. * Fri Feb 14 2014 Dan Walsh - 2.2.5-7- Allow manpages to be built on aarch64 * Fri Feb 14 2014 Dan Walsh - 2.2.5-6- Don\'t be verbose in fixfiles if there is not tty * Thu Feb 13 2014 Dan Walsh - 2.2.5-5- Yum should only be required for policycoreutils-devel * Tue Jan 21 2014 Dan Walsh - 2.2.5-4- Update translations * Thu Jan 16 2014 Dan Walsh - 2.2.5-3- Add Miroslav patch to- Fix previously_modified_initialize() to show modified changes properly for all selections * Wed Jan 08 2014 Dan Walsh - 2.2.5-2- Do not require /usr/share/selinux/devel/Makefile to build permissive domains * Mon Jan 06 2014 Dan Walsh - 2.2.5-1- Update to upstream * Ignore selevel/serange if MLS is disabled from Sven Vermeulen. * Fri Jan 03 2014 Dan Walsh - 2.2.4-8- Update Tranlations- Patch from Yuri Chornoivan to fix typos * Fri Jan 03 2014 Dan Walsh - 2.2.4-7- Fixes Customized booleans causing a crash of the sepolicy gui * Fri Dec 20 2013 Dan Walsh - 2.2.4-6- Fix sepolicy gui selection for advanced screen- Update Translations- Move requires checkpolicy requirement into policycoreutils-python * Mon Dec 16 2013 Dan Walsh - 2.2.4-5- Fix semanage man page description of import command- Fix policy kit file to allow changing to permissive mode * Mon Dec 16 2013 Dan Walsh - 2.2.4-4- Fix broken dependencies. * Fri Dec 13 2013 Dan Walsh - 2.2.4-3- Break out python3 code into separate package * Fri Dec 06 2013 Dan Walsh - 2.2.4-2- Add mgrepl patch- ptrace should be a part of deny_ptrace boolean in TEMPLATETYPE_admin * Tue Dec 03 2013 Dan Walsh - 2.2.4-1- Update to upstream * Revert automatic setting of serange and seuser in seobject; was breaking non-MLS systems.- Add patches for sepolicy gui from mgrepl to Fix advanced_item_button_push() to allow to select an application in advanced search menu Fix previously_modified_initialize() to show modified changes properly for all selections * Fri Nov 22 2013 Dan Walsh - 2.2.3-1- Update to upstream * Apply polkit check on all dbus interfaces and restrict to active user from Dan Walsh. * Fix typo in sepolicy gui dbus.relabel_on_boot call from Dan Walsh.- Apply Miroslav Grepl patch to fix TEMPLATETYPE_domtrans description in sepolicy generate * Wed Nov 20 2013 Dan Walsh - 2.2.2-2- Fix selinux-polgengui, get_all_modules call * Fri Nov 15 2013 Dan Walsh - 2.2.2-1- Speed up startup time of sepolicy gui- Clean up ports screen to only show enabled ports.- Update to upstream * Remove import policycoreutils.default_encoding_utf8 from semanage from Dan Walsh. * Make yum/extract_rpms optional for sepolicy generate from Dan Walsh. * Add test suite for audit2allow and sepolgen-ifgen from Dan Walsh. * Thu Oct 31 2013 Dan Walsh - 2.2-2- Shift around some of the files to more appropriate packages. * semodule_ * packages are required for devel. * Thu Oct 31 2013 Dan Walsh - 2.2-1- Update to upstream * Properly build the swig exception file from Laurent Bigonville. * Fix man pages from Laurent Bigonville. * Support overriding PATH and INITDIR in Makefile from Laurent Bigonville. * Fix LDFLAGS usage from Laurent Bigonville. * Fix init_policy warning from Laurent Bigonville. * Fix semanage logging from Laurent Bigonville. * Open newrole stdin as read/write from Sven Vermeulen. * Fix sepolicy transition from Sven Vermeulen. * Support overriding CFLAGS from Simon Ruderich. * Create correct man directory for run_init from Russell Coker. * restorecon GLOB_BRACE change from Michal Trunecka. * Extend audit2why to report additional constraint information. * Catch IOError errors within audit2allow from Dan Walsh. * semanage export/import fixes from Dan Walsh. * Improve setfiles progress reporting from Dan Walsh. * Document setfiles -o option in usage from Dan Walsh. * Change setfiles to always return -1 on failure from Dan Walsh. * Improve setsebool error r eporting from Dan Walsh. * Major overhaul of gui from Dan Walsh. * Fix sepolicy handling of non-MLS policy from Dan Walsh. * Support returning type aliases from Dan Walsh. * Add sepolicy tests from Dan Walsh. * Add org.selinux.config.policy from Dan Walsh. * Improve range and user input checking by semanage from Dan Walsh. * Prevent source or target arguments that end with / for substitutions from Dan Walsh. * Allow use of <> for semanage fcontext from Dan Walsh. * Report customized user levels from Dan Walsh. * Support deleteall for restoring disabled modules from Dan Walsh. * Improve semanage error reporting from Dan Walsh. * Only list disabled modules for module locallist from Dan Walsh. * Fix logging from Dan Walsh. * Define new constants for file type character codes from Dan Walsh. * Improve bash completions from Dan Walsh. * Convert semanage to argparse from Dan Walsh (originally by Dave Quigley). * Add semanage tests from Dan Walsh. * Split semanage man pages from Dan Walsh. * Move bash completion scripts from Dan Walsh. * Replace genhomedircon script with a link to semodule from Dan Walsh. * Fix fixfiles from Dan Walsh. * Add support for systemd service for restorecon from Dan Walsh. * Spelling corrections from Dan Walsh. * Improve sandbox support for home dir symlinks and file caps from Dan Walsh. * Switch sandbox to openbox window manager from Dan Walsh. * Coalesce audit2why and audit2allow from Dan Walsh. * Change audit2allow to append to output file from Dan Walsh. * Update translations from Dan Walsh. * Change audit2why to use selinux_current_policy_path from Dan Walsh. * Fri Oct 25 2013 Dan Walsh - 2.1.14-89- Fix handling of man pages. * Wed Oct 16 2013 Dan Walsh - 2.1.14-88- Cleanup errors found by pychecker- Apply patch from Michal Trunecka to allow restorecon to handle {} in globs * Fri Oct 11 2013 Dan Walsh - 2.1.14-87- sepolicy gui - mgrepl fixes for users and login- Update Translations. * Fri Oct 11 2013 Dan Walsh - 2.1.14-86- sepolicy gui - mgrepl added delete screens for users and login - Fix lots of bugs.- Update Translations. * Fri Oct 04 2013 Dan Walsh - 2.1.14-85- Fixes for fixfiles * exclude_from_dirs should apply to all types of restorecon calls * fixfiles check now works * exit with the correct status- semanage no longer import selinux * Wed Oct 02 2013 Dan Walsh - 2.1.14-84- Fixes for sepolicy gui- Fix setsebool to return 0 on success- Update Po * Mon Sep 30 2013 Dan Walsh - 2.1.14-83- Fix sizes of help screens in sepolicy gui * Sat Sep 28 2013 Dan Walsh - 2.1.14-82- Improvements to sepolicy gui - Add more help information - Cleanup code - Add deny_ptrace on lockdown screen - Make unconfined/permissivedomains lockdown work - Add more support for file equivalency * Wed Sep 18 2013 Dan Walsh - 2.1.14-81- Add back in the help png files- Begin Adding support for file equivalency. * Wed Sep 04 2013 Dan Walsh - 2.1.14-80- Random fixes for sepolicy gui * Do not prompt for password until you make a change * Add user mappings and selinux users page * lots of code cleanup- Verify homedir is owned by user before mounting over it with seunshare- Fix fixfiles to handle Relabel properly- Fix semanage fcontext -e / command to allow \"/\" * Wed Sep 04 2013 Dan Walsh - 2.1.14-79- Add Miroslav Grepl setsebool patch to give better error message on bad boolean names- Additional help screens for sepolicy gui * Tue Sep 03 2013 Dan Walsh - 2.1.14-78- Random fixes for sepolicy gui- Update Translations * Fri Aug 30 2013 Dan Walsh - 2.1.14-77- Add help screens for each page- Fixes for system page * Mon Aug 26 2013 Dan Walsh - 2.1.14-76- Add Miroslav Grepl Patch to handle semanage -i and semanage -o better- Update Translations * Thu Aug 15 2013 Dan Walsh - 2.1.14-75- Update sepolicy gui code, cleanups and add file transition tab- Fix semanage fcontext -a --ftype code to work. * Wed Aug 07 2013 Dan Walsh - 2.1.14-74- If policy is not installed get_bools should not crash * Wed Aug 07 2013 Dan Walsh - 2.1.14-73- Fix doc versioning * Tue Aug 06 2013 Dan Walsh - 2.1.14-72- Update sepolicy gui code, cleanups and add file transition tab- Fix semanage argparse problems * Fri Aug 02 2013 Dan Walsh - 2.1.14-71- Update sepolicy gui code, adding dbus calls- Update Translations * Fri Jul 26 2013 Dan Walsh - 2.1.14-70- Fix semanage argparse bugs- Update Translations- Add test suite for semanage command lines * Wed Jul 24 2013 Dan Walsh - 2.1.14-69- Fix semanage argparse bugs * Tue Jul 23 2013 Dan Walsh - 2.1.14-68- Fix bugs introduced by previous patch. semanage port- Update Translations- Add test suite for sepolicy command lines * Fri Jul 19 2013 Dan Walsh - 2.1.14-67- Fix bugs introduced by previous patch. semanage port- Update Translations * Wed Jul 17 2013 Dan Walsh - 2.1.14-66- Rewrite argparse code in semanage and fix reload problem. * Tue Jul 16 2013 Dan Walsh - 2.1.14-65- Do not generate shell script or spec file for sepolicy generate --newtype- Update translations- Fix sepolicy generate --admin_user man page again- Fix setsebool to print less verbose error messages by default, add -V for ve * Mon Jul 15 2013 Dan Walsh - 2.1.14-64- Move audit2allow and audit2why back into -python package * Wed Jul 10 2013 Dan Walsh - 2.1.14-63- Update sepolicy gui.- Error out of you call sepolicy gui without policycoreutils-gui package installed- Fix semanage login -d command- Update Translations * Wed Jul 10 2013 Dan Walsh - 2.1.14-62- Update sepolicy gui. * Fri Jul 05 2013 Dan Walsh - 2.1.14-61- Add Ryan Hallisey sepolicy gui.- Update Translations * Mon Jun 24 2013 Dan Walsh - 2.1.14-60- Fix semanage module error handling * Sun Jun 23 2013 Dan Walsh - 2.1.14-59- Add back default exception handling for errors, which argparse rewrite removed. * Fri Jun 21 2013 Dan Walsh - 2.1.14-58- Fix generation of booleans in man pages * Fri Jun 21 2013 Dan Walsh - 2.1.14-57- Remove requires for systemd-sysv- Move systemd-units require to restorecond section- Update Tranlasions- More sepolicy interfaces for gui- Cleanup man pages for sepolicy generate * Wed Jun 19 2013 Dan Walsh - 2.1.14-56- Fix semanage export/import commands- Fix semange module command- Remove --version option from sandbox * Tue Jun 18 2013 Dan Walsh - 2.1.14-55- Add man page doc for --role and bash complestion support for sepolicy --role * Tue Jun 18 2013 Dan Walsh - 2.1.14-54- Make fcdict return a dictionary of dictionaries- Fix for sepolicy manpage * Mon Jun 17 2013 Dan Walsh - 2.1.14-53- Add new man pages for each semanage subsection * Mon Jun 17 2013 Dan Walsh - 2.1.14-52- Fix handling of sepolicy network sorting.- Additional interfaces needed for sepolicy gui * Thu Jun 06 2013 Dan Walsh - 2.1.14-51- Fix handling of semanage args * Thu Jun 06 2013 Dan Walsh - 2.1.14-50- Fix sepolicy generate --confined_admin to generate tunables- Add new interface to generate entrypoints for use with new gui * Wed Jun 05 2013 Dan Walsh - 2.1.14-49- Fix handing of semanage with no args * Tue Jun 04 2013 Dan Walsh - 2.1.14-48- Fix audit2allow -o to open file for append- Fix the name of the spec file generated in the build script * Fri May 31 2013 Dan Walsh - 2.1.14-47- Fix mgrepl patch to support all semanage command parsing * Sun May 26 2013 Dan Walsh - 2.1.14-46- Fix the name of the spec file generated in the build script- Add mgrepl patch to support argparse for semanage command parsing * Tue May 21 2013 Dan Walsh - 2.1.14-45- Fix sandbox to always use sandbox_file_t, so generated policy will work.- Update Translations * Thu May 16 2013 Dan Walsh - 2.1.14-44- Fix sepolicy-generate man page to clear up options/policy type- Add Miroslav Grepl to not generate man page when doing sepolicy generate --customize- Add support for executing semanage user within spec file- Fix generation of confined admin domains, to handle booleans properly. * Tue May 14 2013 Dan Walsh - 2.1.14-43- Need to handle gziped policy.xml as well as not compressed. * Tue May 14 2013 Dan Walsh - 2.1.14-42- Add support for Xephyr -resizable, so sandbox can now resize window- Add support for compressed policy.xml- Miroslav Grepl patch to allow sepolicy interface on individual interface fil- Also add capability to test interfaces for correctness. * Mon May 13 2013 Dan Walsh - 2.1.14-41- Apply patches from Sven Vermeulen for sepolgen to fix typos. * Mon May 13 2013 Dan Walsh - 2.1.14-40- Only require selinux-policy-devel for policycoreutils-devel, this will shrink the size of the livecd. * Sun May 12 2013 Dan Walsh - 2.1.14-39- Run sepolgen-ifgen in audit2allow and sepolicy generate, if needed, first time- Add Sven Vermeulen patches to cleanup man pages * Fri May 10 2013 Dan Walsh - 2.1.14-38- No longer run sepolgen-ifgen at install time.- Run sepolgen-ifgen in audit2allow and sepolicy generate, if needed.- Update Translations * Mon Apr 22 2013 Dan Walsh - 2.1.14-37- Fix exceptionion hanling in audit2allow -o- Generate Man pages for everydomain, not just ones with exec_t entrypoints- sepolicy comunicate should return ValueError not TypeError- Trim header line in sepolicy manpage to use less space- Add missing options to restorecon man page * Thu Apr 11 2013 Dan Walsh - 2.1.14-36- Raise proper Exception on sepolicy communicate with invalid value * Wed Apr 10 2013 Dan Walsh - 2.1.14-35- Update translations- Add patch by Miroslav Grepl to add compile test for sepolicy interface command. * Tue Apr 09 2013 Dan Walsh - 2.1.14-34- Update translations- Add patch inspired by Miroslav Grepl to add extended information for sepolicy interface command. * Mon Apr 08 2013 Dan Walsh - 2.1.14-33- Update translations- Add missing man pages and fixup existing man pages * Wed Apr 03 2013 Dan Walsh - 2.1.14-32- Move sepolicy to policycoreutils-devel pacage, since most of it is used for devel- Apply Miroslav Grepl Patches for sepolicy-- Fix generate mutually groups option handling-- EUSER is used for existing policy-- customize options can be used together with admin_domain option-- Fix manpage.py to generate correct man pages for SELinux users-- Fix policy *.te file generated by customize+writepaths options-- Fix install script for confined_admin option * Mon Apr 01 2013 Dan Walsh - 2.1.14-31- Add post install scripts for gui to make sure Icon Cache is refreshed.- Fix grammar issue in secon man page- Update Translations * Thu Mar 28 2013 Dan Walsh - 2.1.14-30- Add buildrequires for OpenBox to prevent me from accidently building into RHEL7- Add support for returning alias data to sepolicy.info python bindings * Wed Mar 27 2013 Dan Walsh - 2.1.14-28- Fix audit2allow output to better align analysys with the allow rules- Apply Miroslav Grepl patch to clean up sepolicy generate usage- Apply Miroslav Grepl patch to fixupt handing of admin_user generation- Update Tranlslations * Wed Mar 27 2013 Dan Walsh - 2.1.14-27- Allow semanage fcontext -a -t \"<>\" ... to work * Mon Mar 25 2013 Dan Walsh - 2.1.14-26- Can not unshare IPC in sandbox, since it blows up Xephyr- Remove bogus error message sandbox about reseting setfsuid * Thu Mar 21 2013 Dan Walsh - 2.1.14-25- Fix sepolicy generate --customize to generate policy with -w commands * Thu Mar 21 2013 Dan Walsh - 2.1.14-24- sepolgen-ifgen needs to handle filename transition rules containing \":\" * Tue Mar 19 2013 Dan Walsh - 2.1.14-23- sepolicy manpage:- use nroff instead of man2html- Remove checking for name of person who created the man page- audit2allow- Fix output to show the level that is different. * Thu Mar 14 2013 Dan Walsh - 2.1.14-22- Fix newrole to not drop capabilities from the bounding set.- Stop dropping capabilities from its children.- Add better error messages.- Change location of bash_completion files to /usr/share/bash-completion/compl * Mon Mar 11 2013 Dan Walsh - 2.1.14-21- sepolicy generate should look for booleans that effect equivalence names, and add them to the man page * Thu Mar 07 2013 Dan Walsh - 2.1.14-20- Mention creation of permissive domains in sepolicy generate man page- Change sepolicy manpage to use shortname with an \"_\" to stop accidently grabbing unrelated types for a domain.- Fix audit2allow to show better information on constraint violations. * Wed Mar 06 2013 Dan Walsh - 2.1.14-19- Have restorecon exit -1 on errors for consistancy. * Tue Mar 05 2013 Dan Walsh - 2.1.14-18- Need to provide a value to semanage boolean -m * Mon Mar 04 2013 Dan Walsh - 2.1.14-17- Fix cut and paste errors for sepolicy network command * Fri Mar 01 2013 Dan Walsh - 2.1.14-16- Fix sepoicy interface to work properly * Thu Feb 28 2013 Dan Walsh - 2.1.14-15- Fix fixfiles to use exclude_dirs on fixfiles restore * Thu Feb 28 2013 Dan Walsh - 2.1.14-14- Allow users with symlinked homedirs to work. call realpath on homedir- Fix sepolicy reorganization of helper functions. * Sun Feb 24 2013 Dan Walsh - 2.1.14-13- Update trans- Fix sepolicy reorganization of helper functions. * Sun Feb 24 2013 Rahul Sundaram - 2.1.14-13- remove vendor tag from desktop file. https://fedorahosted.org/fpc/ticket/247- clean up spec to follow current guidelines * Fri Feb 22 2013 Dan Walsh - 2.1.14-12- Do not load interface file by default when sepolicy is called, mov get_all_methods to the sepolicy package * Fri Feb 22 2013 Dan Walsh - 2.1.14-11- sepolgen-ifgen should use the current policy path if selinux is enabled * Fri Feb 22 2013 Dan Walsh - 2.1.14-10- Fix sepolicy to be able to work on an SELinux disabled system.- Needed to be able to build man pages in selinux-policy package * Thu Feb 21 2013 Dan Walsh - 2.1.14-9- Add yum to requires of policycoreutils-python since sepolicy requires it. * Thu Feb 21 2013 Dan Walsh - 2.1.14-8- Sepolixy should not throw an exception on an SELinux disabled machine- Switch from using console app to using pkexec, so we will work betterwith policykit.- Add missing import to fix system-config-selinux startup- Add comment to pamd files about pam_rootok.so- Fix sepolicy generate to not comment out the first line * Wed Feb 20 2013 Dan Walsh - 2.1.14-7- Add --root/-r flag to sepolicy manpage,- This allows us to generate man pages on the fly in the selinux-policy build * Mon Feb 18 2013 Dan Walsh - 2.1.14-6- Fix newrole to retain cap_audit_write when compiled with namespace, alsodo not drop capabilities when run as root. * Thu Feb 14 2013 Dan Walsh - 2.1.14-5- Fix man page generation and public_content description * Thu Feb 14 2013 Dan Walsh - 2.1.14-4- Revert some changes which are causing the wrong policy version file to be created- Switch sandbox to start using openbox rather then matchbox- Make sepolgen a symlink to sepolicy- update translations * Wed Feb 13 2013 Dan Walsh - 2.1.14-3- Fix empty system-config-selinux.png, again * Tue Feb 12 2013 Dan Walsh - 2.1.14-2- Fix empty system-config-selinux.png * Thu Feb 07 2013 Dan Walsh - 2.1.14-1- Update to upstream * setfiles: estimate percent progress * load_policy: make link at the destination directory * Rebuild polgen.glade with glade-3 * sepolicy: new command to unite small utilities * sepolicy: Update Makefiles and po files * sandbox: use sepolicy to look for sandbox_t * gui: switch to use sepolicy * gui: sepolgen: use sepolicy to generate * semanage: use sepolicy for boolean dictionary * add po file configuration information * po: stop running update-po on all * semanage: seobject verify policy types before allowing you to assign them. * gui: Start using Popen, instead of os.spawnl * sandbox: Copy /var/tmp to /tmp as they are the same inside * qualifier to shred content * semanage: Fix handling of boolean_sub names when using the -F flag * semanage: man: roles instead of role * gui: system-config-selinux: Catch no DISPLAY= error * setfiles: print error if no default label found * semanage: list logins file entries in semanage login -l * semanage: good error message is sepolgen python module missing * gui: system-config-selinux: do not use lokkit * secon: add support for setrans color information in prompt output * restorecond: remove /etc/mtab from default list * gui: If you are not able to read enforcemode set it to False * genhomedircon: regenerate genhomedircon more often * restorecond: Add /etc/udpatedb.conf to restorecond.conf * genhomedircon generation to allow spec file to pass in SEMODULE_PATH * fixfiles: relabel only after specific date * po: update translations * sandbox: seunshare: do not reassign realloc value * seunshare: do checking on setfsuid * sestatus: rewrite to shut up coverity * Thu Jan 31 2013 Dan Walsh - 2.1.12-58- Reorginize sepolicy so all get_all functions are in main module- Add -B capability to fixfiles onboot and fixfiles restore, basically searches for all files created since the last boot. * Fri Jan 25 2013 Dan Walsh - 2.1.12-57- Update to latest patches from eparis/Upstream- fixfiles onboot will write any flags handed to it to /.autorelabel.- * Patch sent to initscripts to have fedora-autorelabel pass flags back to fixfiles restore- * This should allow fixfiles -F onboot, to force a hard relabel.- Add -p to show progress on full relabel. * Tue Jan 15 2013 Dan Walsh - 2.1.12-56- Additional changes for bash completsion and generate man page to match the w- Add newtype as a new qualifier to sepolicy generate. This new mechanism wil- a policy write to generate types after the initial policy has been written a- will autogenerate all of the interfaces.- I also added a -w options to allow policy writers from the command line to s- the writable directories of files.-- Modify network.py to include interface definitions for newly created port type- Standardize of te_types just like all of the other templates.- Change permissive domains creation to raise exception if sepolgen is not ins- get_te_results no longer needs or uses the opts parameter.- The compliler was complaining so I just removed the option.- Start returning analysis data for audit2allow * Tue Jan 15 2013 Dan Walsh - 2.1.12-55- Update Translations- Fix handling of semanage generate --cgi -n MODULE PATHTO/CGI- This fixes the spec file and script file getting wrong names for modules and types. * Wed Jan 09 2013 Dan Walsh - 2.1.12-54- Additional patch from Miroslav to handle role attributes * Wed Jan 09 2013 Dan Walsh - 2.1.12-53- Update with Miroslav patch to handle role attributes- Update Translations- import sepolicy will only throw exception on missing policy iff selinux is enabled * Sat Jan 05 2013 Dan Walsh - 2.1.12-52- Update to latest patches from eparis/Upstream- secon: add support for setrans color information in prompt output- Update translations * Fri Jan 04 2013 Dan Walsh - 2.1.12-51- Update translations- Fix sepolicy booleans to handle autogenerated booleans descriptions- Cleanups of sepolicy manpage- Fix crash on git_shell man page generation * Thu Jan 03 2013 Dan Walsh - 2.1.12-50- Update translations- update sepolicy manpage to generate fcontext equivalence data and to listdefault file context paths.- Add ability to generate policy for confined admins and domains like puppet. * Thu Dec 20 2012 Dan Walsh - 2.1.12-49- Fix semanage permissive , this time with the patch.- Update translations * Wed Dec 19 2012 Dan Walsh - 2.1.12-48- Fix semanage permissive- Change to use correct gtk forward button- Update po * Mon Dec 17 2012 Dan Walsh - 2.1.12-47- Move audit2why to -devel package * Mon Dec 17 2012 Dan Walsh - 2.1.12-46- sepolicy transition was blowing up. Also cleanup output when only source is specified.- sepolicy generate should allow policy modules names that include - or _ * Mon Dec 10 2012 Dan Walsh - 2.1.12-45- Apply patch from Miroslav to display proper range description in man pages g- Should print warning on missing default label when run in recusive mode iff- Remove extra -R description, and fix recursive description * Thu Dec 06 2012 Dan Walsh - 2.1.12-44- Additional fixes for disabled SELinux Box- system-config-selinux no longer relies on lokkit for /etc/selinux/config * Thu Dec 06 2012 Dan Walsh - 2.1.12-43- sepolicy should failover to installed policy file on a disabled SELinux box, if it exists. * Wed Dec 05 2012 Dan Walsh - 2.1.12-42- Update Translations- sepolicy network -d needs to accept multiple domains * Fri Nov 30 2012 Dan Walsh - 2.1.12-41- Add --path as a parameter to sepolicy generate- Print warning message if program does not exists when generating policy, and do not attempt to run nm command- Fix sepolicy generate -T to not take an argument, and supress the help message- Since this is really just a testing tool * Fri Nov 30 2012 Dan Walsh - 2.1.12-40- Fix sepolicy communicate to handle invalid input * Thu Nov 29 2012 Dan Walsh - 2.1.12-39- Fix sepolicy network -p to handle high ports * Thu Nov 29 2012 Dan Walsh - 2.1.12-38- Fix handling of manpages without entrypoints, nsswitch domains- Update Translations * Wed Nov 28 2012 Dan Walsh - 2.1.12-37- Move sepogen python bindings back into policycoreutils-python out of -devel, since sepolicy is using the * Tue Nov 27 2012 Dan Walsh - 2.1.12-36- Fix sepolicy/__init__.py to handle _() * Wed Nov 21 2012 Dan Walsh - 2.1.12-35- Add Miroslav Grepl patch to create etc_rw_t sock files policy * Fri Nov 16 2012 Dan Walsh - 2.1.12-34- Fix semanage to work without policycoreutils-devel installed- Update translations * Tue Nov 13 2012 Dan Walsh - 2.1.12-33- Fix semanage login -l to list contents of /etc/selinux/POLICY/logins directory * Tue Nov 13 2012 Dan Walsh - 2.1.12-32- Fix booleansPage not showing booleans- Fix audit2allow -b * Tue Nov 13 2012 Dan Walsh - 2.1.12-31- Fix sepolicy booleans again- Fix man page * Mon Nov 12 2012 Dan Walsh - 2.1.12-30- Move policy generation tools into policycoreutils-devel * Mon Nov 12 2012 Dan Walsh - 2.1.12-29- Document and fix sepolicy booleans- Update Translations- Fix several spelling mistakes * Wed Nov 07 2012 Dan Walsh - 2.1.12-27- Only report restorecon warning for missing default label, if not runningrecusively- Update translations * Mon Nov 05 2012 Dan Walsh - 2.1.12-26- Fix semanage booleans -l, move more boolean_dict handling into sepolicy- Update translations- Fixup sepolicy generate to discover /var/log, /var/run and /var/lib directories if they match the name- Fix kill function call should indicate signal_perms not kill capability- Error out cleanly in system-config-selinux, if it can not contact XServer * Mon Nov 05 2012 Dan Walsh - 2.1.12-25- Remove run_init, no longer needed with systemd.- Fix sepolicy generate to not include subdirs in generated fcontext file. (mgrepl patch) * Sat Nov 03 2012 Dan Walsh - 2.1.12-24- Fix manpage to generate proper man pages for alternate policy,basically allow me to build RHEL6 man pages on a Fedora 18 box, as long asI pull the policy, policy.xml and file_contexts and file_contexts.homedir * Thu Nov 01 2012 Dan Walsh - 2.1.12-23- Fix some build problems in sepolicy manpage and sepolicy transition | |