|
|
|
|
Changelog for selinux-policy-targeted-3.7.19-155.el6_3.4.noarch.rpm :
Mon Sep 3 14:00:00 2012 Miroslav Grepl 3.7.19-155.4 - Make condor_startd_ssh domain as unconfined - Allow condor_startd_ssh to connect to kerberos_master port Resolves:#852456
Wed Aug 29 14:00:00 2012 Miroslav Grepl 3.7.19-155.3 - Allow condor_startd to start sshd services with range Resolves:#852456
Sun Aug 19 14:00:00 2012 Miroslav Grepl 3.7.19-155.2 - sshd_t needs to be mls trusted object Resolves:#840674
Sat Jun 30 14:00:00 2012 Miroslav Grepl 3.7.19-155.1 - Allow sshd_t with privsep to work in MLS with a user at a different level Resolves:#840674
Mon Jun 18 14:00:00 2012 Miroslav Grepl 3.7.19-155 - Allow setroubleshootd to execute rpm Resolves:#833053 - Add labeling for /usr/lib/flash-plugin/libflashplayer.so
Thu May 24 14:00:00 2012 Miroslav Grepl 3.7.19-154 - distcvs to distgit corruption fix Resolves:#823991
Wed May 23 14:00:00 2012 Miroslav Grepl 3.7.19-154 - Allow fenced to manage snmpd lib files - Allow certmonger to get attributes on init script files Resolves:#790967 - Fix labeling for Firefox plugins Resolves:#747993 - Add mta_signal_user_agent() interface
Wed May 16 14:00:00 2012 Miroslav Grepl 3.7.19-153 - user_tcp_server boolean should be also for sysadm_t Resolves:#798534
Wed May 16 14:00:00 2012 Miroslav Grepl 3.7.19-152 - Add label for condor_starter Resolves:#807682 - Dontaudit sys_module for brctl - Allow winbind to send signull to smbd - Add jacorb port definition
Tue May 15 14:00:00 2012 Miroslav Grepl 3.7.19-151 - Add openstack-nova, openstack-keystone, openstack-glance, openstack-quantum policies - Allow sysadm_t to create other crontabs - Allow nfsd_t to read defaul_t link files - Fix labeling for /var/run/heartbeat - Fixes for admin_template() interface to make sysadm_secadm.pp module working correctly - More fixes for condor policy - Allow chfn_t to creat user_tmp_files - Allow chfn_t to execute bin_t - Fix auth_role() interface - Fixes to make privsep+SELinux working if we try to use chage to change passwd
Wed May 9 14:00:00 2012 Miroslav Grepl 3.7.19-150 - Allow condor-startd to dbus chat with hal - Allow rpc.mountd to read all files/dirs
Tue May 8 14:00:00 2012 Miroslav Grepl 3.7.19-149 - Add labeling for /usr/sbin/matahari-dbus-sysconfigd - Add additional labeling for zarafa - Allow guest_t to fix labeling - Corenet_tcp_bind_all_unreserved_ports(ssh_t) should be called with the user_tcp_server boolean - squashfs does not support xattr in RHEL6 Resolves:#815898 - Remove pyzor labeling and move it to spamassassin.fc - Fix config.tgz
Wed May 2 14:00:00 2012 Miroslav Grepl 3.7.19-148 - Add mysql_list_db() interface - Allow sshd to read/write condor-startd tcp socket
Tue Apr 24 14:00:00 2012 Miroslav Grepl 3.7.19-147 - Fix man pages for SELinux users - Allow all user domains to setexec - Allow cobblerd to get SELinux status and booleans - Add labeling for /etc/zipl.conf Resolves:#813803 - Allow fenced to read SNMP lib files
Tue Apr 17 14:00:00 2012 Miroslav Grepl 3.7.19-146 - Add sysadm_secadm policy module to separate in secadm_r, sysadm_r Resolves:#787413 - Fixes for libvirt-qmf - Add label for package-cleanup - Add support for zfs - Make cfengine domains as unconfined Resolves:#753184 - Allow sshd_t to dyntransition to sysadm_t
Wed Apr 4 14:00:00 2012 Miroslav Grepl 3.7.19-145 - Fix labeling for /var/run/slapd. * sockets Resolves:#799102 - Add condor policy
Tue Apr 3 14:00:00 2012 Miroslav Grepl 3.7.19-144 - Fixes for cfengine policy * changed labeling for /var/cfengine/outputs from var_log to cfengine_var_log_t * re-arranged policy to use template and cfengine_domain - Allow dovecot to domtrans sendmail to handle sieve scripts - Bacport libvirt-qmf policy for Fedora - Remove labeling for postmaster.pid file - Fix for virtual network which looses network connection - Add man pages for SELinux users - cgconfig needs to use getpw calls - Allow lvm and fsadm to write sysfs_t - Allow rpc.mounted to list user tmp files - Fix permissivedomains declarations Resolves:#806220 - Fix spec file to instal minimum policy properly
Wed Mar 21 13:00:00 2012 Miroslav Grepl 3.7.19-143 - Add missing transition from certmonger to certmonger_unconfined_t Resolves:#790967
Tue Mar 20 13:00:00 2012 Miroslav Grepl 3.7.19-142 - Fixes for man pages - Allow rpcd to execute sm-notify Resolves:#802247 - Add support for matahari-qmf-rpcd - Add support matahari vios-proxy- * apps - Allow quota-check to create files on nonxattr filesystems - Add support for ~/Maildir - Allow unconfined dyntransition - Fixes for certmonger_unconfined and certmonger - Fixes for certmonger policy
Wed Mar 14 13:00:00 2012 Miroslav Grepl 3.7.19-141 - Add man pages for apps, services - Allow nagios to use user terminals Resolves:#782325 - Add support for unconfined certmonger scripts - Add support for matahari-qmf-rpcd service - Allow chsh to use PAM - Allow rpc.statd to execute sm-notify which has bin_t label - Make sure files which are created by /usr/bin/R get proper label in home directories
Wed Mar 7 13:00:00 2012 Miroslav Grepl 3.7.19-140 - Add additional fixes for nagios handlers Resolves:#749311 - Add 7600 and 4447 as jboss_management ports
Tue Mar 6 13:00:00 2012 Miroslav Grepl 3.7.19-139 - Allow nfsd_t to getattr on all fs Resolves:#738628 - Make mailx working together with cron without unconfined module - Allow sssd sys_resource capability
Wed Feb 29 13:00:00 2012 Miroslav Grepl 3.7.19-138 - Add new policy for cfengine - Add new policy for sge gridengine jobs - Add support for nagios eventhandlers - Make system cron jobs run in the proper domain - Add policy to support privsep ssh process running in user domain - Add fixes relates to nss/FIPS - Add new rsync_use_ * booleans - Allow qpidd to connect to matahari ports - Allow sysadm_u to read system_r in MLS - Remove razor labeling because we treat razor with spam policy - Add support for matahari-qmf-sysconfig-consoled, clean up matahari policy - Fixes for interfaces Resolves:#791294 Resolves:#796351
Thu Feb 16 13:00:00 2012 Miroslav Grepl 3.7.19-137 - Remove nfs_ * booleans because nfs runs in kernel_t domain Resolves:#760405 - Add httpd_manage_ipa boolean - Dontaudit sys_ptrace for matahari-netd - Allow vhostmd to getattr on virtd - Allow snmpd to connect to the ricci_modcluster - qpidd should be allowed to connect to the amqp port
Thu Jan 26 13:00:00 2012 Miroslav Grepl 3.7.19-136 - backport mozilla_plugin policy - backport sandbox policy to support nacl - Add support for selinux_avcstat munin plugin - Treat hearbeat with corosync policy - Allow system cronjobs to read kernel network state - Allow corosync to read and write to qpidd shared memory - More fixes for qpidd Resolves:#769352 - Add policy for quota-nld
Wed Jan 25 13:00:00 2012 Miroslav Grepl 3.7.19-135 - Add fixes for qpidd policy, support for tmpfs_t Resolves:#769352 - Add fixes for mcelog policy, for new location of pid,sock files - Make sendmail and postfix working together
Wed Jan 11 13:00:00 2012 Miroslav Grepl 3.7.19-134 - Backport ABRT policy - Backport matahari policy - Add interfaces for libra - Add jboss_dubeg port definition
Wed Jan 4 13:00:00 2012 Miroslav Grepl 3.7.19-133 - Allow mta_user_agents to send sigchld to transitioning domain
Tue Jan 3 13:00:00 2012 Miroslav Grepl 3.7.19-132 - Fixes for nagios policy - Add a new interface for libra - Fix spec file to be testing SELinux status correctly
Mon Dec 5 13:00:00 2011 Miroslav Grepl 3.7.19-131 - Fixes for rhev policy - Make ssh-keygen as unconfined domain - Add sanlock_use_nfs boolean - Add ssh_dontaudit_search_user_home_dir interface - namespace_init and MLS fix
Mon Nov 21 13:00:00 2011 Miroslav Grepl 3.7.19-130 - Fix cloudform_exec_mongod interface Resolves:#753184
Mon Nov 21 13:00:00 2011 Miroslav Grepl 3.7.19-129 - Cron and libra fixes
Mon Nov 21 13:00:00 2011 Miroslav Grepl 3.7.19-128 - Add cronjob_role for sysadm - Change label for /var/spool/cron - Add interface to allow exec of mongod
Tue Nov 15 13:00:00 2011 Miroslav Grepl 3.7.19-127 - Make cronjob working on MLS
Wed Nov 9 13:00:00 2011 Miroslav Grepl 3.7.19-126 - Fix dev_rw_generic_usb_dev
Wed Nov 9 13:00:00 2011 Miroslav Grepl 3.7.19-125 - Change the postinstall to load_policy separately from the semodule command - This will put the proper files in place even if the kernel rejects the policy. - Allow login programs to connect to the pki_ca_port - Allow vhostmd to read /dev/rand and signal
Mon Nov 7 13:00:00 2011 Miroslav Grepl 3.7.19-124 - Add MCS fixes to make sVirt working correctly - Fixes for httpd_dirsrvadmin_script_t policy
Thu Nov 3 13:00:00 2011 Miroslav Grepl 3.7.19-123 - MLS Overrides needed for a user running at a level to be able to use sudo and talk to sssd - Allow initrc_t to manage dirsrv pid files with disabled unconfined module - Fixed for deltacloudd policy
Wed Nov 2 13:00:00 2011 Miroslav Grepl 3.7.19-122 - Add label for imagefactory images directory - Allow dovecot sys_nice Resolves:#749690
Mon Oct 31 13:00:00 2011 Miroslav Grepl 3.7.19-121 - Add support for dbomatic Resolves: #745531
Wed Oct 26 14:00:00 2011 Miroslav Grepl 3.7.19-120 - dhcpd needs dac_override
Tue Oct 25 14:00:00 2011 Miroslav Grepl 3.7.19-119 - Add cloudform policy
Tue Oct 18 14:00:00 2011 Miroslav Grepl 3.7.19-118 - Fix label for /root/.hushlogin - Allow domain to send/recv unlabeled packet - Allow sshd to relabel tun socket - Allow puppetmasterd to relabel puppet config files - Add label for lvs.conf - Fix labeling for matahari-netd agents
Thu Oct 13 14:00:00 2011 Miroslav Grepl 3.7.19-117 - Fix device interfaces - Add label for /dev/bsr4096_ * devices
Wed Oct 12 14:00:00 2011 Miroslav Grepl 3.7.19-116 - Interfaces fixes - Allow dirsrv to use PAM - Fix matahari labeling
Wed Oct 5 14:00:00 2011 Miroslav Grepl 3.7.19-115 - Add unlabelednet policy module - Add chrome role for xguest - Fix for vdagent policy - Add fix to allow confined apps to execmod on chrome
Thu Sep 29 14:00:00 2011 Miroslav Grepl 3.7.19-114 - Fix httpd_selinux man page - Add corenet_packet() interface - Add support for Clustered Samba commands
Wed Sep 21 14:00:00 2011 Miroslav Grepl 3.7.19-113 - Fix execmem_execmod() interface Resolves:#739618
Tue Sep 20 14:00:00 2011 Miroslav Grepl 3.7.19-112 - Fix description of allow_ * booleans - Allow sanlock to manage libvirt lib files - Fix bug in lsassd policy - Add label for /var/run/luci - move port 18001 from http_port_t to jboss_management_port_t
Fri Sep 16 14:00:00 2011 Miroslav Grepl 3.7.19-111 - Add git_cgit_read_gitosis_content boolean - Add support for cma port - Add virt_use_sanlock boolean and make sanlock working together libvirt - Make passenger and puppet working together
Thu Sep 8 14:00:00 2011 Miroslav Grepl 3.7.19-110 - Add label for passwd.adjunct - Allow pulse to execute /usr/sbin/fos - Fix labeling for passenger - Add selinux policy support for IP-in-SSH tunnelling - Allow sulogin to write /dev/pts/0 in single user mode
Wed Aug 31 14:00:00 2011 Miroslav Grepl 3.7.19-109 - Add abrt man page - Make internal-sftpd working - Fixes for cluster
Wed Aug 24 14:00:00 2011 Miroslav Grepl 3.7.19-108 - Add squid man page - Add git man page - Make puppet working with passenger - Allow procmail to execute hostname command
Thu Aug 11 14:00:00 2011 Miroslav Grepl 3.7.19-107 - Make new domains as unconfined - Add abrt_handle_event_t domain for ABRT event script - Add selinux_mysql man page - Fix httpd selinux man page - Fix interfaces
Tue Aug 2 14:00:00 2011 Miroslav Grepl 3.7.19-106 - Add ctdbd, uuidd, sblim policies
Tue Jul 26 14:00:00 2011 Miroslav Grepl 3.7.19-105 - Add zarafa, drbd, fcoemon, lldpad policies
Wed Jul 20 14:00:00 2011 Miroslav Grepl 3.7.19-104 - Allow puppet to Check access to the passwd executable - Add label for /var/www/html/logs directory - Add label for /var/lib/squeezeboxserver directory - Allow rgmanager executes init script files in initrc_t domain which ensure proper transitions
Thu Jul 14 14:00:00 2011 Miroslav Grepl 3.7.19-103 - Fixes in postfix policy
Thu Jun 30 14:00:00 2011 Miroslav Grepl 3.7.19-102 - Add rhsmcertd policy
Wed Jun 29 14:00:00 2011 Miroslav Grepl 3.7.19-101 - Add sanlock and wdmd policy - Allow syslogd ipc_lock
Mon Jun 20 14:00:00 2011 Miroslav Grepl 3.7.19-100 - More fixes for rhev-agentd
Fri Jun 17 14:00:00 2011 Miroslav Grepl 3.7.19-99 - Add mta_user_agent attribute * Needed for libra
Fri Jun 10 14:00:00 2011 Miroslav Grepl 3.7.19-98 - Fix for OpenShift
Mon Jun 6 14:00:00 2011 Miroslav Grepl 3.7.19-97 - Allow postfix-pickup to write files and directories regardless of their MCS category set. - Make xinetd trusted to write outbound packets regardless of the network\'s or node\'s MLS range Resolves: #705772
Thu May 26 14:00:00 2011 Miroslav Grepl 3.7.19-96 - Add rhev policy - Make vhostd device MLS trusted
Tue May 24 14:00:00 2011 Miroslav Grepl 3.7.19-95 - Allow secadm to manage selinux config files - Allow apache to use jboss management port - Add fenced_can_ssh boolean
Thu May 12 14:00:00 2011 Miroslav Grepl 3.7.19-94 - Fixes for libra
Fri Apr 29 14:00:00 2011 Miroslav Grepl 3.7.19-93 - Make init_t MLS trusted for reading/writing from/to sockets at any level
Wed Apr 27 14:00:00 2011 Miroslav Grepl 3.7.19-92 - Fix virt_admin interface
Wed Apr 27 14:00:00 2011 Miroslav Grepl 3.7.19-91 - Allow netlabel_mgmt_t to use all terms
Wed Apr 27 14:00:00 2011 Miroslav Grepl 3.7.19-90 - Add label for /dev/hpilo directory - Fix label for /var/cache/libvirt
Tue Apr 26 14:00:00 2011 Miroslav Grepl 3.7.19-89 - More fixes for aide
Tue Apr 26 14:00:00 2011 Miroslav Grepl 3.7.19-88 - Aide policy does not handle MLS mode well - Make netlabelctl working in MLS
Wed Apr 20 14:00:00 2011 Miroslav Grepl 3.7.19-87 - Allow $1_sudo_t to read default SELinux context - Allow tgtd to create a sock file - Allow initrc_t to manage faillock
Tue Apr 19 14:00:00 2011 Miroslav Grepl 3.7.19-86 - Allow squid to manage krb5_host_rcache_t files
Wed Apr 13 14:00:00 2011 Miroslav Grepl 3.7.19-85 - Allow unconfined to run libvirt in virtd_t domain - Make foghorn unconfined domain
Mon Apr 11 14:00:00 2011 Miroslav Grepl 3.7.19-84 - Allow foghorn to read usr files
Fri Apr 8 14:00:00 2011 Miroslav Grepl 3.7.19-83 - Add label for matahari-broker.pid file - Allow foghor to read snmp lib files - Make sysadm security admin - Fix ssh_sysadm_login boolean Resolves: #694551
Wed Apr 6 14:00:00 2011 Miroslav Grepl 3.7.19-82 - Allow ssh_keygen_t read and write a user TTYs and PTYs
Tue Apr 5 14:00:00 2011 Miroslav Grepl 3.7.19-81 - Add allow_sysadm_manage_security boolean - Add label for /dev/dlm. * - Allow auditadm_screen_t and secadm_screen_t dac_override capability - SSH_USE_STRONG_RNG is 1 which requires /dev/random - Fix auth_rw_faillog definition - Fixes for nslcd policy Resolves: #693368 - Allow qpidd to manage pid and lib matahari files - Allow rgmanager to send the kill signal to all users
Fri Mar 25 13:00:00 2011 Miroslav Grepl 3.7.19-80 - Add support for a new cluster service - foghorn - sssd needs to read ~/.k5login in nfs, cifs or fusefs file systems - sssd wants to read .k5login file in users homedir - Add support for vdsm - Allow syslogd setrlimit, sys_nice Resolves: #689431 - ipsec_mgmt_t wants to cause ipsec_t to dump core, needs to be allowed
Thu Mar 17 13:00:00 2011 Miroslav Grepl 3.7.19-79 - Fixes for sandbox/seunshare policy Resolves:#684919 - Allow ssh_keygen_t dac_override - Add matahari policy - Add label for /etc/securetty - Fixes for pirahna-pulse policy - Fixes for radius, samba, dirsrv, kerberos policies - Allow console login on MLS - Fix file context to show several labels as SystemHigh - Add port definition for dogtag, matahari, movaz ports
Thu Mar 10 13:00:00 2011 Miroslav Grepl 3.7.19-78 - Change context for /var/run/faillock
Wed Mar 9 13:00:00 2011 Miroslav Grepl 3.7.19-77 - Add spice fixes - Add label for /dev/hpilo/ *
Tue Mar 8 13:00:00 2011 Miroslav Grepl 3.7.19-76 - Fixes for ssh_keygen policy - Allow sysadm_t to run ssh-keygen in ssh_keygen_t domain - Backport spice vdagent policy
Fri Mar 4 13:00:00 2011 Miroslav Grepl 3.7.19-75 - Allow svirt to manage sock_file in ~/.libvirt directory - Allow sysamd to run udev in udev_t domain - Remove capability from svirt - Add lvm_exec_t label for kpartx
Tue Mar 1 13:00:00 2011 Miroslav Grepl 3.7.19-74 - Add virt_home_ type files located in ~/.libvirt directory - virt creates monitor sockets in the users home dir - Allow lvm setfscreate Resolves: #680388 - Make lsusb and lsblk working on MLS Resolves: #680426
Thu Feb 24 13:00:00 2011 Miroslav Grepl 3.7.19-73 - Fix spec file - Fix for policykit Resolves: #678044
Tue Feb 22 13:00:00 2011 Miroslav Grepl 3.7.19-72 - Fix for cmirrord Resolves: #676664 - Add mcsnetwrite attribute
Thu Feb 17 13:00:00 2011 Miroslav Grepl 3.7.19-71 - Allow cmirrord to create physical disk devices in /dev - Allow cluster domains to use the system bus and send each other dbus messages - Add label for /dev/tgt
Tue Feb 8 13:00:00 2011 Miroslav Grepl 3.7.19-70 - Make screen working for sysadm_u Resolves: #669439
Mon Feb 7 13:00:00 2011 Miroslav Grepl 3.7.19-69 - Make Spacewalk to work with selinux-policy Resolves: #673112 - Fix /root/.ssh labeling Resolves: #637109 - Fix for the spec file
Mon Jan 24 13:00:00 2011 Miroslav Grepl 3.7.19-68 - Other fixes for namespace policy
Thu Jan 20 13:00:00 2011 Miroslav Grepl 3.7.19-67 - Treat irpinit, iprupdate, iprdump services with raid policy Resolves: #669402
Wed Jan 19 13:00:00 2011 Miroslav Grepl 3.7.19-66 - Fixes for newrole related with namespace.init
Tue Jan 18 13:00:00 2011 Miroslav Grepl 3.7.19-65 - Allow newrole to run namespace_init
Fri Jan 14 13:00:00 2011 Miroslav Grepl 3.7.19-64 - Add namespace policy - Allow udev to stream connect to init Resolves: #667370 - Update for screen policy to handle pipe in homedir - Fixes for polyinstatiated homedir
Mon Jan 10 13:00:00 2011 Miroslav Grepl 3.7.19-63 - Make kernel_t domain MLS trusted for lowering the level of files
Wed Dec 22 13:00:00 2010 Miroslav Grepl 3.7.19-62 - Allow apache to read cobbler lib files Resolves: #658410
Tue Dec 21 13:00:00 2010 Miroslav Grepl 3.7.19-61 - Fixes for passenger policy - Allow user_t to conditionally transition to ping_t and traceroute_t Resolves: #663054
Mon Dec 20 13:00:00 2010 Miroslav Grepl 3.7.19-60 - Fixes for certmonger - Backport passenger policy - Allow run_init to read console_device Resolves: #657568 - Add label for /var/lib/dkim-milter - Fixes for munin policy
Thu Dec 9 13:00:00 2010 Miroslav Grepl 3.7.19-59 - Allow cdrecord setrlimiit Resolves: #615731 - Define debugfs_t as mountpoint Resolves: #646856 - Fix fenced_can_network_connect boolean description Resolves: #650136 - Add label for /var/run/faillock - Add dirsrv and dirsrv-admin policy Resolves: #655206 - Fixes for cobbler policy - Allow certmonger to manage dirsrv config Resolves: #658591
Tue Oct 26 14:00:00 2010 Miroslav Grepl 3.7.19-58 - Fix httpd_setrlimit boolean to allow sys_resource capability - Fix label for ip6tables.save - Allow ssh_t to exec ssh_exec_t - Dontaudit init leaks Resolves: #639083
Wed Oct 13 14:00:00 2010 Miroslav Grepl 3.7.19-57 - Allow system_mail_t to append ~/dead.letter - Allow mount to communicate with gfs_controld Resolves: #636683 - Dontaudit hal leaks in setfiles - gpm needs to use the user terminal
Wed Oct 6 14:00:00 2010 Miroslav Grepl 3.7.19-56 - Allow smartd to read usr files - Allow devicekit-power transition to dhcpc - Add label for /etc/timezone - Remove transition from unconfined_t to iptables_t - Allow domains with different mcs levels to send each other signals as long as they are not identified as mcsconstrainproc Resolves: #634945 - Allow nrpe to send signal and sigkill to the plugins - Fix up xguest to allow it to read hwdata and gconf_etc_t
Thu Sep 16 14:00:00 2010 Miroslav Grepl 3.7.19-55 - Add cluster_var_lib_t type and label for /var/lib/cluster - Add labeling for /root/.debug - Remove permissive from cmirrord domain - Dontaudit cmirrord_t sys_tty_config capability - Allow virtd to read from processes up to its clearance - Allow dovecot-deliver to create tmp files - Allow tor to send signals to itself - Handle /var/db/sudo - Remove allow_corosync_rw_tmpfs boolean Resolves: #631564
Thu Sep 2 14:00:00 2010 Miroslav Grepl 3.7.19-54 - Allow clmvd to create tmpfs files Resolves: #629391 Resolves: #594833
Wed Sep 1 14:00:00 2010 Miroslav Grepl 3.7.19-53 - Fixes for jabberd policy - Fixes for sandbox policy
Mon Aug 30 14:00:00 2010 Miroslav Grepl 3.7.19-52 - Fix label for /bin/mountpoint - Allow fsadm to read virt blk image files
Wed Aug 25 14:00:00 2010 Miroslav Grepl 3.7.19-51 - Allow seunshare fowner capability - Allow dovecot to manage postfix privet socket
Tue Aug 24 14:00:00 2010 Miroslav Grepl 3.7.19-50 - Fixes for boinc policy - Fixes for shorewall policy
Fri Aug 20 14:00:00 2010 Miroslav Grepl 3.7.19-49 - Add label for /var/cache/rpcbind directory - Add chrome_role for xguest - Fix amavis_read_spool_files interface
Wed Aug 18 14:00:00 2010 Miroslav Grepl 3.7.19-48 - Fixes for shorewall policy - Allow sssd chown capability - Fix label for /usr/bin/mutter - Label dead.letter as mail_home_t - Allow pcscd to read hardware state information - Fixes for ulogd policy
Fri Aug 13 14:00:00 2010 Miroslav Grepl 3.7.19-47 - Fixes for boinc-project policy - Allow swat to read nmbd pid file - Allow fail2ban to read BIND log files - Fix cert handling from Dan - Remove transition from unconfined to ncftool domain
Wed Aug 11 14:00:00 2010 Miroslav Grepl 3.7.19-46 - Allow ipsec-mgmt to dbus chat with unconfined - Fixes for boinc policy
Tue Aug 10 14:00:00 2010 Miroslav Grepl 3.7.19-45 - Fixes for cgroup policy - Fixes for ncftool policy - Add ncftool_read_user_content boolean - Fix label for boinc init script - Fix label for fence_tool - Allow vhostmd to write virt content - Allow ricci domtrans ot shutdown
Thu Aug 5 14:00:00 2010 Miroslav Grepl 3.7.19-44 - Add support for luci - Add label for /var/spool/up2date
Wed Aug 4 14:00:00 2010 Miroslav Grepl 3.7.19-43 - Allow ncftool to run brctl - Fixes for ricci-modclusterd policy - Allow uucpd to execute ssh client - Add label for dayplanner - Allow sandbox_xserver execstack
Mon Aug 2 14:00:00 2010 Miroslav Grepl 3.7.19-42 - Allow kdump to read information from the debugging filesystem - Update boinc policy - Fixes for logwatch-mail policy
Tue Jul 27 14:00:00 2010 Miroslav Grepl 3.7.19-41 - Allow logwatch_mail to read read the networking state information. - Add label for /usr/bin/dosbox - Allow systat sys_admin capability
Fri Jul 23 14:00:00 2010 Miroslav Grepl 3.7.19-40 - Fixes for puppetmaster - Fix label for kadmin init script - Fixes for logwatch-mail policy - Allow arpwatch to request the kernel to load modules - Allow cron jobs to run with context of user that started them
Wed Jul 21 14:00:00 2010 Miroslav Grepl 3.7.19-39 - Allow munin_system_plugin to read files in /usr - Do not audit insmod attempts to write virt daemon unnamed pipes - Allow corosync to read ricci lib files
Mon Jul 19 14:00:00 2010 Miroslav Grepl 3.7.19-38 - Allow xdm_t to manage gnome homedir content - Allow s-c-firewall to read and write virtual memory sysctls - Fixes for logwatch policy
Wed Jul 14 14:00:00 2010 Miroslav Grepl 3.7.19-37 - Redefine hi_reserved_port_t to include ports from 512 to 599 - Add label for /sbin/sushell - Fixes for munin plugin policy
Tue Jul 13 14:00:00 2010 Miroslav Grepl 3.7.19-36 - Allow netutils to read and write USB monitor devices - Fix label for /rhev - Add user_setrlimit boolean - Allow initrc to manage virt lib files - Add support for ebtables - Add label for /bin/mksh - Dontaudit aiccu sys_tty_config capability - Add httpd_setrlimit boolean
Fri Jul 9 14:00:00 2010 Miroslav Grepl 3.7.19-35 - Add label for /bin/yash - Fixes for rhcs and corosync policy - Fixes for piranha-web policy
Thu Jul 1 14:00:00 2010 Miroslav Grepl 3.7.19-34 - Fix ipsec-mgmt inteface
Wed Jun 30 14:00:00 2010 Miroslav Grepl 3.7.19-33 - Fix label for /var/lib/git - Fix labels for conflicted files - Fix cgroup_admin interface
Mon Jun 28 14:00:00 2010 Miroslav Grepl 3.7.19-32 - Allow sectool to connect to users over unix stream socket - Add label for /var/spool/abrt-upload - Add audio_home_t type for homedir/Music files - Allow aiccu to read network config files - Allow qpidd to setsched - Allow virt domains to manage svirt_image_t fifo files - Fixes for NM-openswan - Fixes for admin interfaces
Mon Jun 21 14:00:00 2010 Miroslav Grepl 3.7.19-31 - Remove daemons dontaudit to search all dirs - Add support for epylog - All all domains to read lib files - Allow denyhosts to send syslog messages - Allow mysql-safe setrlimit - Allow rpm to execute rpm_tmp_t - Allow dmesg to appen abrt_var_cache files - Fixed label for abrt.socket
Wed Jun 16 14:00:00 2010 Miroslav Grepl 3.7.19-30 - Allow sysadm to run ncftool - Fixes for cobbler policy - Allow Network Manager to transition to ipsec_mgmt domain - Add label for /usr/libexec/nm-openswan-service - Add label for /dev
Tue Jun 15 14:00:00 2010 Miroslav Grepl 3.7.19-29 - Allow abrt sigkill - Add ncftool policy - Add cluster fixes - Fixes for audisp-remote
Mon Jun 14 14:00:00 2010 Miroslav Grepl 3.7.19-28 - Fixes for netutils - Cleanup of aiccu policy - Add mpd policy
Wed Jun 9 14:00:00 2010 Miroslav Grepl 3.7.19-27 - Allow ftpd ipc_lock capability - Allow audisp-remote to getcap and setcap - Allow iscsid to read and write raw memory devices - Fixes for bitlbee policy
Wed Jun 9 14:00:00 2010 Miroslav Grepl 3.7.19-26 - Allow krb5kdc to write krb5kdc_principal_t file - Allow hald to send generic signal to dhcp client - Fix dev_rw_vhost interface - Add /var/run/abrt.socket label
Tue Jun 8 14:00:00 2010 Miroslav Grepl 3.7.19-25 - Fixes for cmirrord policy - Dontaudit xauth to list inotifyfs filesystem. - Allow xserver to translate contexts. - Allow kdumpgui domain sys_admin capability - Allow vpnc to relabelfrom tun_socket - Allow prelink_cron_system_t to signal - Fixes for gitolite - Allow virt domain to read symbolic links in device directories
Thu Jun 3 14:00:00 2010 Miroslav Grepl 3.7.19-24 - Add support for /dev/vhost-net - Allow psad to read files in /usr - Allow systat to use nscd socket - Fixes for boinc policy
Tue Jun 1 14:00:00 2010 Miroslav Grepl 3.7.19-23 - Add cmirrord policy - Fixes for accountsd policy - Fixes for boinc policy - Allow cups-pdf to set attributes on fonts cache directory - Allow radiusd to setrlimit - Allow nscd sys_ptrace capability
Tue May 25 14:00:00 2010 Dan Walsh 3.7.19-22 - Allow procmail to execute scripts in the users home dir that are labeled home_bin_t - Fix /var/run/abrtd.lock label
Mon May 24 14:00:00 2010 Dan Walsh 3.7.19-21 - Allow login programs to read krb5_home_t Resolves: 594833 - Add obsoletes for cachefilesfd-selinux package Resolves: #575084
Thu May 20 14:00:00 2010 Dan Walsh 3.7.19-20 - Allow mount to r/w abrt fifo file - Allow svirt_t to getattr on hugetlbfs - Allow abrt to create a directory under /var/spool
Wed May 19 14:00:00 2010 Dan Walsh 3.7.19-19 - Add labels for /sys - Allow sshd to getattr on shutdown - Fixes for munin - Allow sssd to use the kernel key ring - Allow tor to send syslog messages - Allow iptabels to read usr files - allow policykit to read all domains state
Thu May 13 14:00:00 2010 Dan Walsh 3.7.19-17 - Fix path for /var/spool/abrt - Allow nfs_t as an entrypoint for http_sys_script_t - Add policy for piranha - Lots of fixes for sosreport
Wed May 12 14:00:00 2010 Dan Walsh 3.7.19-16 - Allow xm_t to read network state and get and set capabilities - Allow policykit to getattr all processes - Allow denyhosts to connect to tcp port 9911 - Allow pyranha to use raw ip sockets and ptrace itself - Allow unconfined_execmem_t and gconfsd mechanism to dbus - Allow staff to kill ping process - Add additional MLS rules
Mon May 10 14:00:00 2010 Dan Walsh 3.7.19-15 - Allow gdm to edit ~/.gconf dir Resolves: #590677 - Allow dovecot to create directories in /var/lib/dovecot Partially resolves 590224 - Allow avahi to dbus chat with NetworkManager - Fix cobbler labels - Dontaudit iceauth_t leaks - fix /var/lib/lxdm file context - Allow aiccu to use tun tap devices - Dontaudit shutdown using xserver.log
Thu May 6 14:00:00 2010 Dan Walsh 3.7.19-14 - Fixes for sandbox_x_net_t to match access for sandbox_web_t ++ - Add xdm_etc_t for /etc/gdm directory, allow accountsd to manage this directory - Add dontaudit interface for bluetooth dbus - Add chronyd_read_keys, append_keys for initrc_t - Add log support for ksmtuned Resolves: #586663
Thu May 6 14:00:00 2010 Dan Walsh 3.7.19-13 - Allow boinc to send mail
Wed May 5 14:00:00 2010 Dan Walsh 3.7.19-12 - Allow initrc_t to remove dhcpc_state_t - Fix label on sa-update.cron - Allow dhcpc to restart chrony initrc - Don\'t allow sandbox to send signals to its parent processes - Fix transition from unconfined_t -> unconfined_mount_t -> rpcd_t Resolves: #589136
Mon May 3 14:00:00 2010 Dan Walsh 3.7.19-11 - Fix location of oddjob_mkhomedir Resolves: #587385 - fix labeling on /root/.shosts and ~/.shosts - Allow ipsec_mgmt_t to manage net_conf_t Resolves: #586760
Fri Apr 30 14:00:00 2010 Dan Walsh 3.7.19-10 - Dontaudit sandbox trying to connect to netlink sockets Resolves: #587609 - Add policy for piranha
Thu Apr 29 14:00:00 2010 Dan Walsh 3.7.19-9 - Fixups for xguest policy - Fixes for running sandbox firefox
Wed Apr 28 14:00:00 2010 Dan Walsh 3.7.19-8 - Allow ksmtuned to use terminals Resolves: #586663 - Allow lircd to write to generic usb devices
Tue Apr 27 14:00:00 2010 Dan Walsh 3.7.19-7 - Allow sandbox_xserver to connectto unconfined stream Resolves: #585171
Mon Apr 26 14:00:00 2010 Dan Walsh 3.7.19-6 - Allow initrc_t to read slapd_db_t Resolves: #585476 - Allow ipsec_mgmt to use unallocated devpts and to create /etc/resolv.conf Resolves: #585963
Thu Apr 22 14:00:00 2010 Dan Walsh 3.7.19-5 - Allow rlogind_t to search /root for .rhosts Resolves: #582760 - Fix path for cached_var_t - Fix prelink paths /var/lib/prelink - Allow confined users to direct_dri - Allow mls lvm/cryptosetup to work
Wed Apr 21 14:00:00 2010 Dan Walsh 3.7.19-4 - Allow virtd_t to manage firewall/iptables config Resolves: #573585
Tue Apr 20 14:00:00 2010 Dan Walsh 3.7.19-3 - Fix label on /root/.rhosts Resolves: #582760 - Add labels for Picasa - Allow openvpn to read home certs - Allow plymouthd_t to use tty_device_t - Run ncftool as iptables_t - Allow mount to unmount unlabeled_t - Dontaudit hal leaks
Wed Apr 14 14:00:00 2010 Dan Walsh 3.7.19-2 - Allow livecd to transition to mount
Tue Apr 13 14:00:00 2010 Dan Walsh 3.7.19-1 - Update to upstream - Allow abrt to delete sosreport Resolves: #579998 - Allow snmp to setuid and gid Resolves: #582155 - Allow smartd to use generic scsi devices Resolves: #582145
Tue Apr 13 14:00:00 2010 Dan Walsh 3.7.18-3 - Allow ipsec_t to create /etc/resolv.conf with the correct label - Fix reserved port destination - Allow autofs to transition to showmount - Stop crashing tuned
Mon Apr 12 14:00:00 2010 Dan Walsh 3.7.18-2 - Add telepathysofiasip policy
Mon Apr 5 14:00:00 2010 Dan Walsh 3.7.18-1 - Update to upstream - Fix label for /opt/google/chrome/chrome-sandbox - Allow modemmanager to dbus with policykit
Mon Apr 5 14:00:00 2010 Dan Walsh 3.7.17-6 - Fix allow_httpd_mod_auth_pam to use auth_use_pam(httpd_t) - Allow accountsd to read shadow file - Allow apache to send audit messages when using pam - Allow asterisk to bind and connect to sip tcp ports - Fixes for dovecot 2.0 - Allow initrc_t to setattr on milter directories - Add procmail_home_t for .procmailrc file
Thu Apr 1 14:00:00 2010 Dan Walsh 3.7.17-5 - Fixes for labels during install from livecd
Thu Apr 1 14:00:00 2010 Dan Walsh 3.7.17-4 - Fix /cgroup file context - Fix broken afs use of unlabled_t - Allow getty to use the console for s390
Wed Mar 31 14:00:00 2010 Dan Walsh 3.7.17-3 - Fix cgroup handling adding policy for /cgroup - Allow confined users to write to generic usb devices, if user_rw_noexattrfile boolean set
Tue Mar 30 14:00:00 2010 Dan Walsh 3.7.17-2 - Merge patches from dgrift
Mon Mar 29 14:00:00 2010 Dan Walsh 3.7.17-1 - Update upstream - Allow abrt to write to the /proc under any process
Fri Mar 26 13:00:00 2010 Dan Walsh 3.7.16-2 - Fix ~/.fontconfig label - Add /root/.cert label - Allow reading of the fixed_file_disk_t:lnk_file if you can read file - Allow qemu_exec_t as an entrypoint to svirt_t
Tue Mar 23 13:00:00 2010 Dan Walsh 3.7.16-1 - Update to upstream - Allow tmpreaper to delete sandbox sock files - Allow chrome-sandbox_t to use /dev/zero, and dontaudit getattr file systems - Fixes for gitosis - No transition on livecd to passwd or chfn - Fixes for denyhosts
Tue Mar 23 13:00:00 2010 Dan Walsh 3.7.15-4 - Add label for /var/lib/upower - Allow logrotate to run sssd - dontaudit readahead on tmpfs blk files - Allow tmpreaper to setattr on sandbox files - Allow confined users to execute dos files - Allow sysadm_t to kill processes running within its clearance - Add accountsd policy - Fixes for corosync policy - Fixes from crontab policy - Allow svirt to manage svirt_image_t chr files - Fixes for qdisk policy - Fixes for sssd policy - Fixes for newrole policy
Thu Mar 18 13:00:00 2010 Dan Walsh 3.7.15-3 - make libvirt work on an MLS platform
Thu Mar 18 13:00:00 2010 Dan Walsh 3.7.15-2 - Add qpidd policy
Thu Mar 18 13:00:00 2010 Dan Walsh 3.7.15-1 - Update to upstream
Tue Mar 16 13:00:00 2010 Dan Walsh 3.7.14-5 - Allow boinc to read kernel sysctl - Fix snmp port definitions - Allow apache to read anon_inodefs
Sun Mar 14 13:00:00 2010 Dan Walsh 3.7.14-4 - Allow shutdown dac_override
Sat Mar 13 13:00:00 2010 Dan Walsh 3.7.14-3 - Add device_t as a file system - Fix sysfs association
Fri Mar 12 13:00:00 2010 Dan Walsh 3.7.14-2 - Dontaudit ipsec_mgmt sys_ptrace - Allow at to mail its spool files - Allow nsplugin to search in .pulse directory
Fri Mar 12 13:00:00 2010 Dan Walsh 3.7.14-1 - Update to upstream
Fri Mar 12 13:00:00 2010 Dan Walsh 3.7.13-4 - Allow users to dbus chat with xdm - Allow users to r/w wireless_device_t - Dontaudit reading of process states by ipsec_mgmt
Thu Mar 11 13:00:00 2010 Dan Walsh 3.7.13-3 - Fix openoffice from unconfined_t
Wed Mar 10 13:00:00 2010 Dan Walsh 3.7.13-2 - Add shutdown policy so consolekit can shutdown system
Tue Mar 9 13:00:00 2010 Dan Walsh 3.7.13-1 - Update to upstream
Thu Mar 4 13:00:00 2010 Dan Walsh 3.7.12-1 - Update to upstream
Thu Mar 4 13:00:00 2010 Dan Walsh 3.7.11-1 - Update to upstream - These are merges of my patches - Remove 389 labeling conflicts - Add MLS fixes found in RHEL6 testing - Allow pulseaudio to run as a service - Add label for mssql and allow apache to connect to this database port if boolean set - Dontaudit searches of debugfs mount point - Allow policykit_auth to send signals to itself - Allow modcluster to call getpwnam - Allow swat to signal winbind - Allow usbmux to run as a system role - Allow svirt to create and use devpts
Mon Mar 1 13:00:00 2010 Dan Walsh 3.7.10-5 - Add MLS fixes found in RHEL6 testing - Allow domains to append to rpm_tmp_t - Add cachefilesfd policy - Dontaudit leaks when transitioning
Tue Feb 23 13:00:00 2010 Dan Walsh 3.7.10-4 - Change allow_execstack and allow_execmem booleans to on - dontaudit acct using console - Add label for fping - Allow tmpreaper to delete sandbox_file_t - Fix wine dontaudit mmap_zero - Allow abrt to read var_t symlinks
Mon Feb 22 13:00:00 2010 Dan Walsh 3.7.10-3 - Additional policy for rgmanager
Mon Feb 22 13:00:00 2010 Dan Walsh 3.7.10-2 - Allow sshd to setattr on pseudo terms
Mon Feb 22 13:00:00 2010 Dan Walsh 3.7.10-1 - Update to upstream
Thu Feb 18 13:00:00 2010 Dan Walsh 3.7.9-4 - Allow policykit to send itself signals
Wed Feb 17 13:00:00 2010 Dan Walsh 3.7.9-3 - Fix duplicate cobbler definition
Wed Feb 17 13:00:00 2010 Dan Walsh 3.7.9-2 - Fix file context of /var/lib/avahi-autoipd
Fri Feb 12 13:00:00 2010 Dan Walsh 3.7.9-1 - Merge with upstream
Thu Feb 11 13:00:00 2010 Dan Walsh 3.7.8-11 - Allow sandbox to work with MLS
Tue Feb 9 13:00:00 2010 Dan Walsh 3.7.8-9 - Make Chrome work with staff user
Thu Feb 4 13:00:00 2010 Dan Walsh 3.7.8-8 - Add icecast policy - Cleanup spec file
Wed Feb 3 13:00:00 2010 Dan Walsh 3.7.8-7 - Add mcelog policy
Mon Feb 1 13:00:00 2010 Dan Walsh 3.7.8-6 - Lots of fixes found in F12
Wed Jan 27 13:00:00 2010 Dan Walsh 3.7.8-5 - Fix rpm_dontaudit_leaks
Wed Jan 27 13:00:00 2010 Dan Walsh 3.7.8-4 - Add getsched to hald_t - Add file context for Fedora/Redhat Directory Server
Mon Jan 25 13:00:00 2010 Dan Walsh 3.7.8-3 - Allow abrt_helper to getattr on all filesystems - Add label for /opt/real/RealPlayer/plugins/oggfformat\\.so
Thu Jan 21 13:00:00 2010 Dan Walsh 3.7.8-2 - Add gstreamer_home_t for ~/.gstreamer
Mon Jan 18 13:00:00 2010 Dan Walsh 3.7.8-1 - Update to upstream
Fri Jan 15 13:00:00 2010 Dan Walsh 3.7.7-3 - Fix git
Thu Jan 7 13:00:00 2010 Dan Walsh 3.7.7-2 - Turn on puppet policy - Update to dgrift git policy
Thu Jan 7 13:00:00 2010 Dan Walsh 3.7.7-1 - Move users file to selection by spec file. - Allow vncserver to run as unconfined_u:unconfined_r:unconfined_t
Thu Jan 7 13:00:00 2010 Dan Walsh 3.7.6-1 - Update to upstream
Wed Jan 6 13:00:00 2010 Dan Walsh 3.7.5-8 - Remove most of the permissive domains from F12.
Tue Jan 5 13:00:00 2010 Dan Walsh 3.7.5-7 - Add cobbler policy from dgrift
Mon Jan 4 13:00:00 2010 Dan Walsh 3.7.5-6 - add usbmon device - Add allow rulse for devicekit_disk
Wed Dec 30 13:00:00 2009 Dan Walsh 3.7.5-5 - Lots of fixes found in F12, fixes from Tom London
Wed Dec 23 13:00:00 2009 Dan Walsh 3.7.5-4 - Cleanups from dgrift
Tue Dec 22 13:00:00 2009 Dan Walsh 3.7.5-3 - Add back xserver_manage_home_fonts
Mon Dec 21 13:00:00 2009 Dan Walsh 3.7.5-2 - Dontaudit sandbox trying to read nscd and sssd
Fri Dec 18 13:00:00 2009 Dan Walsh 3.7.5-1 - Update to upstream
Thu Dec 17 13:00:00 2009 Dan Walsh 3.7.4-4 - Rename udisks-daemon back to devicekit_disk_t policy
Wed Dec 16 13:00:00 2009 Dan Walsh 3.7.4-3 - Fixes for abrt calls
Fri Dec 11 13:00:00 2009 Dan Walsh 3.7.4-2 - Add tgtd policy
Fri Dec 4 13:00:00 2009 Dan Walsh 3.7.4-1 - Update to upstream release
Mon Nov 16 13:00:00 2009 Dan Walsh 3.7.3-1 - Add asterisk policy back in - Update to upstream release 2.20091117
Mon Nov 16 13:00:00 2009 Dan Walsh 3.7.1-1 - Update to upstream release 2.20091117
Mon Nov 16 13:00:00 2009 Dan Walsh 3.6.33-2 - Fixup nut policy
Thu Nov 12 13:00:00 2009 Dan Walsh 3.6.33-1 - Update to upstream
Thu Oct 1 14:00:00 2009 Dan Walsh 3.6.32-17 - Allow vpnc request the kernel to load modules
Wed Sep 30 14:00:00 2009 Dan Walsh 3.6.32-16 - Fix minimum policy installs - Allow udev and rpcbind to request the kernel to load modules
Wed Sep 30 14:00:00 2009 Dan Walsh 3.6.32-15 - Add plymouth policy - Allow local_login to sys_admin
Tue Sep 29 14:00:00 2009 Dan Walsh 3.6.32-13 - Allow cupsd_config to read user tmp - Allow snmpd_t to signal itself - Allow sysstat_t to makedir in sysstat_log_t
Fri Sep 25 14:00:00 2009 Dan Walsh 3.6.32-12 - Update rhcs policy
Thu Sep 24 14:00:00 2009 Dan Walsh 3.6.32-11 - Allow users to exec restorecond
Mon Sep 21 14:00:00 2009 Dan Walsh 3.6.32-10 - Allow sendmail to request kernel modules load
Mon Sep 21 14:00:00 2009 Dan Walsh 3.6.32-9 - Fix all kernel_request_load_module domains
Mon Sep 21 14:00:00 2009 Dan Walsh 3.6.32-8 - Fix all kernel_request_load_module domains
Sun Sep 20 14:00:00 2009 Dan Walsh 3.6.32-7 - Remove allow_exec * booleans for confined users. Only available for unconfined_t
Fri Sep 18 14:00:00 2009 Dan Walsh 3.6.32-6 - More fixes for sandbox_web_t
Fri Sep 18 14:00:00 2009 Dan Walsh 3.6.32-5 - Allow sshd to create .ssh directory and content
Fri Sep 18 14:00:00 2009 Dan Walsh 3.6.32-4 - Fix request_module line to module_request
Fri Sep 18 14:00:00 2009 Dan Walsh 3.6.32-3 - Fix sandbox policy to allow it to run under firefox. - Dont audit leaks.
Thu Sep 17 14:00:00 2009 Dan Walsh 3.6.32-2 - Fixes for sandbox
Thu Sep 17 14:00:00 2009 Dan Walsh 3.6.32-1 - Update to upstream - Dontaudit nsplugin search /root - Dontaudit nsplugin sys_nice
Tue Sep 15 14:00:00 2009 Dan Walsh 3.6.31-5 - Fix label on /usr/bin/notepad, /usr/sbin/vboxadd-service - Remove policycoreutils-python requirement except for minimum
Mon Sep 14 14:00:00 2009 Dan Walsh 3.6.31-4 - Fix devicekit_disk_t to getattr on all domains sockets and fifo_files - Conflicts seedit (You can not use selinux-policy-targeted and seedit at the same time.)
Thu Sep 10 14:00:00 2009 Dan Walsh 3.6.31-3 - Add wordpress/wp-content/uploads label - Fixes for sandbox when run from staff_t
Thu Sep 10 14:00:00 2009 Dan Walsh 3.6.31-2 - Update to upstream - Fixes for devicekit_disk
Tue Sep 8 14:00:00 2009 Dan Walsh 3.6.30-6 | |