Changelog for
selinux-policy-strict-2.4.6-300.SEL5_5.1.noarch.rpm :
* Thu Dec 15 2011 Eddy Nigg
- Rebuild for StartCom Linux 5.0.x
* Wed Jun 29 2011 Snir Ifrah - Rebuild for StartCom Linux 5.0.x
* Thu Apr 07 2011 Miroslav Grepl 2.4.6-300.el5_6.1- SSH_USE_STRONG_RNG is 1 which requires /dev/random
* Thu Dec 09 2010 Miroslav Grepl 2.4.6-300- Fixes for insmod policy to make ipc work in MLSResolves: #661368
* Wed Dec 08 2010 Miroslav Grepl 2.4.6-299- Fix label for ooo librariesResolves: #477103
* Tue Dec 07 2010 Miroslav Grepl 2.4.6-298- Dontaudit iscsid sys_ptrace capability- Allow iscsid set the priority of kernel threadsResolves: #649691- Allow svirt sys_rawio and sys_admin capability using virt_use_sysfs boolean- Allow insmod send null signal to all domains- Dontaudit vbetool attemps to read or write to console- Allow consoletype to read and write init script unnamed pipes
* Wed Dec 01 2010 Miroslav Grepl 2.4.6-297- Allow snmpd setuid and setgid capabilityResolves: bz658436
* Tue Nov 30 2010 Miroslav Grepl 2.4.6-296- Other fixes to make single mode work in MLS- Fixes for piranha-web policyResolves: #652074
* Wed Nov 24 2010 Miroslav Grepl 2.4.6-295- Fixes for MLS policy
* Tue Nov 23 2010 Miroslav Grepl 2.4.6-294- Allow svirt to manage files on hugetlbfs files file systemResolves: #652644
* Tue Nov 16 2010 Miroslav Grepl 2.4.6-293- Add port definition for epmap port- insmod needs to be able to create tmpfs_t files
* Wed Nov 10 2010 Miroslav Grepl 2.4.6-292- Allow winbind to read network state informationResolves: #649492
* Tue Nov 09 2010 Miroslav Grepl 2.4.6-291- Fixes for rhcs policy- Allow winbind to connect to epmap portResolves: #650141- Remove transition from unconfined to postfix-master
* Mon Nov 08 2010 Miroslav Grepl 2.4.6-290- Allow smbcontrol to ping samba services- Dontaudit iscsid to ptrace all domains
* Thu Oct 28 2010 Miroslav Grepl 2.4.6-289- Fixes for audisp-remote policy- Fix httpd_setrlimit boolean- Allow cups to manage printer spool lnk filesResolves: #646731
* Wed Oct 20 2010 Miroslav Grepl 2.4.6-288- Allow postfix-map to read the network state informationResolves:#643824
* Fri Oct 15 2010 Miroslav Grepl 2.4.6-287- Fixes for piranha-web policyResolves: #584447- Make selinux-policy-base to provide version- Remove duplicate declaration for /etc/NetworkManager/dispatcher.d
* Sat Oct 02 2010 Miroslav Grepl 2.4.6-286- Add httpd_setrlimit boolean- Do not audit spamc attemps to read and write sendmail unix_stream_socketsResolves: #637843
* Sat Sep 25 2010 Miroslav Grepl 2.4.6-285- Add home_bin_t type and allow procmail to execute it- Allow rpcd to set filesystem quotas of a filesystem with extended attributesResolves: #621057- Add rpm_dontaudit_leaks code - Make winbind_tmp_t as user tmp fileResolves: #598646- Fixes for rhcs policy
* Wed Sep 22 2010 Miroslav Grepl 2.4.6-284- Allow aisexec to read and write to unconfined shared memoryResolves: #633901
* Fri Sep 10 2010 Miroslav Grepl 2.4.6-283- Fix fptd_man pageResolves: #625498- Add support for newer HPLIP packageResolves: #626858- Allow pptp to read meminfoResolves: #551380
* Wed Jul 28 2010 Miroslav Grepl 2.4.6-282- Backport of svirt funtionalityResolves: #582613
* Fri Jul 23 2010 Miroslav Grepl 2.4.6-281- Add piranha policy- Fixes for rhcs policyResolves: #588902- Add support for MSSQLResolves: #570481- Fixes for BINDResolves: #578187- Allow xm to read virt config link filesResolves: #579497- Fixes for ipsec policyResolves: #591975- Allow postfix-smtpd sys_chroot capabilityResolves: #592752- Allow rsyslogd to read random deviceResolves: #593139- Fix label for /var/net-snmp directory- Fix label for oddjob- Allow apache to use mod_auth_pam via winbindResolves: #579105
* Fri Jul 16 2010 Dan Walsh 2.4.6-280- Allow aisexec ipc_ownerResolves: #614796
* Thu Mar 04 2010 Miroslav Grepl 2.4.6-279- Allow modclusterd to use nsswitchResolves: #522158
* Tue Mar 02 2010 Miroslav Grepl 2.4.6-278- Add label for iptables-saveResolves: #564376
* Tue Feb 23 2010 Miroslav Grepl 2.4.6-277- Fixes for rgmanagerResolves: #522158
* Tue Feb 23 2010 Miroslav Grepl 2.4.6-276- Allow cgi scripts run on nfs- Fix for ftp_home_dir booleanResolves: #566975
* Fri Feb 19 2010 Miroslav Grepl 2.4.6-275- Allow qdiskd sys_boot capability - Fixes for fenced and rgmanager policyResolves: #522158
* Mon Feb 15 2010 Miroslav Grepl 2.4.6-274- Fix label for cluster ocf-shellfuncs- Add slapd_initrc_exec_t type- Fix fenced policyResolves: #522158
* Fri Feb 12 2010 Miroslav Grepl 2.4.6-273- Allow samba domains to manage authentication cacheResolves: #507797- Add label for chrooted named log fileResolves: #562833
* Wed Feb 03 2010 Miroslav Grepl 2.4.6-272- Allow iscsid to create log fileResolves: #548599
* Thu Jan 28 2010 Miroslav Grepl 2.4.6-271- Allow qemu to read from random number generatorResolves: #552763- Add label for /sbin/mke4fsResolves: #532565- Add dhcpc ability to relabel net_conf_t filesResolves: #559355- Add iscsid fixesResolves: #548599- Add new type for cups interface scriptsResolves: #550015
* Tue Jan 12 2010 Miroslav Grepl 2.4.6-270- Allow prelink to load and execute functions from shared librariesResolves: #551664- Add label for /etc/xen directoryResolves: #554777
* Mon Jan 11 2010 Miroslav Grepl 2.4.6-269- Allow postfix_postdrop to read and write sendmail unix_stream_socketsResolves: #553492
* Tue Jan 05 2010 Miroslav Grepl 2.4.6-268- Fix labels for postgrestgres test suite Resolves: #551063- Fix multiple different specifications for /var/vdsm directoryResolves: #549492
* Mon Dec 21 2009 Miroslav Grepl 2.4.6-267- Add rgmanager fixes- Allow setkey to read sysadm tmp files Resolves: #515687- Allow fsdaemon to write to SCSI generic deviceResolves: #547387- Add attribute configfile and allow init script to read configfileResolves: #546604
* Thu Dec 10 2009 Miroslav Grepl 2.4.6-266- Add vhostmd policyResolves: #543941- Allow to sysadm to run racoonctl Resolves: #545369
* Wed Dec 02 2009 Miroslav Grepl 2.4.6-265- Add ipsec_log_t type to ipsec policyResolves: #537106
* Fri Nov 06 2009 Miroslav Grepl 2.4.6-264- Allow spamassassin to read /var/lib/spamassassin/ directoryResolves: #530750- Add rule to allow send/recv unlabeled packet to kernel.ifResolves: #530809- Add labeling for /sbin/e4fsckResolves: #532565
* Tue Oct 27 2009 Dan Walsh 2.4.6-263- Fix strict policy to build with rgmanager policy- Fix policy to set the UNKNOWN=allow flag on Real Time KernelResolves: #531230
* Tue Oct 27 2009 Dan Walsh 2.4.6-262- Allow apache to search any user home dirResolves: #522158
* Sun Oct 18 2009 Dan Walsh 2.4.6-261- Allow ccs to communicate with userdomains, and create tmpfs_tResolves: #503141Resolves: #522158
* Fri Oct 16 2009 Dan Walsh 2.4.6-260- Add clogd and other cluster patches from miroslav- Allow hplip_t to r/w cupsd_t socketResolves: #483395- Allow ssh_keygen_t to write to /root/.ssh directoryResolves: #492519- Add Red Hat Cluster PolicyResolves: #503141Resolves: #522158- Allow sysadm_t to transition to setkey_tResolves: #513447
* Sat Sep 26 2009 Dan Walsh 2.4.6-259- Fixes to make nfs quotas workResolves: #525420
* Wed Sep 09 2009 Dan Walsh 2.4.6-258- remove /usr/bin/env from poligygentool- Allow cyrus to communicate with snmp via stream socketResolves: #523548
* Sat Aug 29 2009 Dan Walsh 2.4.6-257- Complete addition of fast_cgiResolves: #519369
* Tue Aug 04 2009 Dan Walsh 2.4.6-256- Fix labeling on oracle librariesResolves: #516780Resolves: #515491Resolves: #515687Resolves: #500400
* Tue Jul 28 2009 Dan Walsh 2.4.6-255- Allow samba as domain controller to change passwordsResolves: #475562
* Wed Jul 22 2009 Dan Walsh 2.4.6-254- Add ipsec_match_default_spd back into userdomain- Allow sysadm_t to execute setkey and racoon executables- Dontaudit write of logwatch to etc_t- Allow samba as domain controller to change passwordsResolves: #475562
* Tue Jul 21 2009 Dan Walsh 2.4.6-253- Allow windbind to create directroies in samba_var_tResolves: #509174
* Wed Jul 08 2009 Dan Walsh 2.4.6-252- Change mmap_low boolean to effect unconfined_t- Allow ipsec_t to read its init scriptResolves: #511359
* Wed Jul 08 2009 Dan Walsh 2.4.6-251- Remove transition from initrc_t to qemu_t Resolves: #504805
* Tue Jul 07 2009 Dan Walsh 2.4.6-250- Need to transition from initrc_t to qemu_t Resolves: #504805
* Sat Jun 20 2009 Dan Walsh 2.4.6-249- Fix sbin==binResolves: #504805
* Sat Jun 20 2009 Dan Walsh 2.4.6-248- Allow cyrus to bind to port 3905Resolves: #504805
* Tue Jun 16 2009 Dan Walsh 2.4.6-247- Additional privs for privoxy, kpropd found in other dists- iscsi wants to look at the process state of all domainsResolves: #506057
* Sat Jun 13 2009 Dan Walsh 2.4.6-246- Allow semanage_t to transition to initrc_t in order to restart mcstransResolves: #460970- Additional rules for ipsecResolves: #443646
* Fri Jun 12 2009 Dan Walsh 2.4.6-245- Allow qemu to use full networkingResolves: #504238
* Wed Jun 10 2009 Dan Walsh 2.4.6-244- Allow qemu to append virt_log_tResolves: #504238
* Tue Jun 09 2009 Dan Walsh 2.4.6-243- Add policy for /dev/ksmResolves: #504238
* Fri Jun 05 2009 Dan Walsh 2.4.6-242- Allow all domains to search bin_t and sbin_t- Allow qemu to write to /var/run/svirt/qemuResolves: #499701
* Fri Jun 05 2009 Dan Walsh 2.4.6-241- Allow xm_ssh_t to search /rootResolves: #499888
* Fri Jun 05 2009 Dan Walsh 2.4.6-240- Don\'t execute semanage command in post installResolves: #499701
* Thu Jun 04 2009 Dan Walsh 2.4.6-239- Allow rsync_t to read nfs and samba sharesResolves: #499701
* Tue Jun 02 2009 Dan Walsh 2.4.6-238- Turn on qemu for OvirtResolves: #499701
* Fri May 22 2009 Dan Walsh 2.4.6-237- Fix iptables labelingResolves: #499888
* Fri May 15 2009 Dan Walsh 2.4.6-236- Allow xm to execute sshResolves: #499888
* Wed May 13 2009 Dan Walsh 2.4.6-234- Dontaudit sendmail leaked file descriptorResolves: #486187
* Tue May 12 2009 Dan Walsh 2.4.6-233- Add rsync_client for Fedora Infrastructure- Allow spamd to exec itself when it gets a hup signalResolves: #499701
* Sat May 09 2009 Dan Walsh 2.4.6-232- Allow spamd to exec itself when it gets a hup signal- Add Minimum policy for Ovirt to RHEL5Resolves: #499701
* Wed May 06 2009 Dan Walsh 2.4.6-231- Add postgrey policy- Allow xm_t in xen to list sysfsResolves: #499249
* Sat May 02 2009 Dan Walsh 2.4.6-230- Allow amanda to signal fsadm- Add context for /var/cache/cgit- Dontaudit apache leaked tcp_sockets- Fixes for cvs service-allow initrc_t and inetd_t siginh over their children- add privoxy_connect_any boolean- Allow smbd_t to signal nmbd_tResolves: #498596
* Sat Apr 25 2009 Dan Walsh 2.4.6-229- Fix sepolgen error regression- Fix milter implementaion - Additional rules required for update to automountResolves: #497273
* Fri Apr 24 2009 Dan Walsh 2.4.6-228- Additional rules required for update to automountResolves: #497273
* Thu Apr 23 2009 Dan Walsh 2.4.6-227- Allow nfs to share removable devices- Allow ipsec additional privs for FIPS complianceResolves: #497168
* Wed Apr 22 2009 Dan Walsh 2.4.6-226- Fix dnsmasq labeling for libvirt Resolves: #496867
* Fri Apr 17 2009 Dan Walsh 2.4.6-225- add context for rpc.quoatad- Allow spamassassin to append to user_home_t for log files Resolves: #481387Resolves: #486187
* Fri Apr 10 2009 Dan Walsh 2.4.6-224Allow ioctl to cron fifo pipesResolves: #481628
* Thu Apr 09 2009 Dan Walsh 2.4.6-222- Allow spamc to append to user_home_tResolves: #486187- Allow dbus to send message back to all servicesResolves: #481628
* Sat Apr 04 2009 Dan Walsh 2.4.6-221- Allow procmail to domtrans to spamassassinResolves: #486187
* Sat Apr 04 2009 Dan Walsh 2.4.6-220- Allow procmail to domtrans to spamassassinResolves: #492567
* Fri Mar 27 2009 Dan Walsh 2.4.6-219- Add labeling for /var/named/chroot/procResolves: #492567
* Fri Mar 13 2009 Dan Walsh 2.4.6-218- dnsmasq needs to read proc- Allow nscd to reexec itselfResolves: #429726
* Tue Mar 10 2009 Dan Walsh 2.4.6-217- Allow saslauthd access to kerberos host rcache- Allow dbus to read all domains statesResolves: #489899
* Thu Feb 26 2009 Dan Walsh 2.4.6-216- Dontaudit leaked descriptor to apache- Fixes for strict policyResolves: #486354
* Mon Feb 23 2009 Dan Walsh 2.4.6-215- Label all matlab libraries as textrel_shlib_tResolves: #486965
* Mon Feb 23 2009 Dan Walsh 2.4.6-214- Allow init_t to transition to rpm_script_tResolves: #480163
* Fri Feb 20 2009 Dan Walsh 2.4.6-213- Allow postfix_virtual_t to use private steam sock_file- Fix java shared library in IBM packageResolves: #486608
* Fri Feb 13 2009 Dan Walsh 2.4.6-212- More fixes for strict policy Resolves: #485111
* Wed Feb 11 2009 Dan Walsh 2.4.6-211- Allow samba to edit apache files in home dirResolves: #485111- Allow procmail to transition to spamassassin domainsResolves: #485107
* Wed Feb 11 2009 Dan Walsh 2.4.6-210- Fix labeling on sysstat packageResolves: #485078
* Mon Feb 09 2009 Dan Walsh 2.4.6-209- Fix duplicate /var/turboprint Resolves: #477123
* Fri Feb 06 2009 Dan Walsh 2.4.6-208- Allow samba to manage ALL files in home dir if boolean set- Fix typos in man pagesResolves: #477123
* Wed Jan 28 2009 Dan Walsh 2.4.6-207- Remove lusterfs fs_use_xattr lineResolves: #481628
* Mon Jan 26 2009 Dan Walsh 2.4.6-205- Allow dbus to send message back to all servicesResolves: #481628
* Fri Dec 19 2008 Dan Walsh 2.4.6-204- Allow ipsec_mgmt to exec sbin_t files (/sbin/lsmod)Resolves: #469943
* Wed Dec 17 2008 Dan Walsh 2.4.6-203- Allow samba to rw/shadowResolves: #474854
* Mon Dec 15 2008 Dan Walsh 2.4.6-202- Additional winbind and samba_net issues caused by coolkeyResolves: #474854
* Wed Dec 10 2008 Dan Walsh 2.4.6-200- Allow ldap to connect to sasl- avc denials during samba active directory joinResolves: #474852- samba - winbind - periodic avc denialsResolves: #474854- \"Syntax error on line 1 \' [type=SQUOTE]\" upgrading selinux-policy-develResolves: #474868- missing policyResolves: #475273
* Fri Dec 05 2008 Dan Walsh 2.4.6-199- Allow apps that check password to write to faillog audisp_remote needs to bind to audit portsResolves: #474481- Allow xm to stream connect to virtResolves: #472903
* Tue Dec 02 2008 Dan Walsh 2.4.6-197- Dontaudit search of /root for init daemons- Fixes for ricci- Allow xm to manage virt_image_tResolves: #472903
* Mon Dec 01 2008 Dan Walsh 2.4.6-195- Fixes for networkmanager- Allow xm to manage virt_image_tResolves: #472903
* Tue Nov 25 2008 Dan Walsh 2.4.6-194- Fix ipsec management label- Allow xm to manage virt_image_tResolves: #472903
* Thu Nov 20 2008 Dan Walsh 2.4.6-193- Fixes for networkmanager- Eliminte import polgenResolves: #440151
* Thu Nov 20 2008 Dan Walsh 2.4.6-192- Allow named to use kerberos keytabsResolves: #440151
* Wed Nov 19 2008 Dan Walsh 2.4.6-191- Fixes for Fedora Infrastructure- Stop transition to unconfined_t from init_tResolves: #440151
* Mon Nov 17 2008 Dan Walsh 2.4.6-189- Fixes for Fedora InfrastructureResolves: #440151
* Fri Nov 14 2008 Dan Walsh 2.4.6-188- Fixes for Fedora Infrastructure- Make pegasus an unconfined_domain - Add pki policyResolves: #440151
* Mon Nov 10 2008 Dan Walsh 2.4.6-185- Fixes for Fedora Infrastructure- Allow cups to signal hplip_tResolves: #470621
* Mon Nov 10 2008 Dan Walsh 2.4.6-183- Allow cups to signal hplip_tResolves: #470621- Allow dnsmasq to use libvirt files
* Thu Nov 06 2008 Dan Walsh 2.4.6-182- Change apache httpd_use_nfs to mean managing nfs shares- From Fedora InfrastructureResolves: #469943
* Thu Nov 06 2008 Dan Walsh 2.4.6-181- Change apache httpd_use_nfs to mean managing nfs shares- From Fedora InfrastructureResolves: #469943
* Wed Nov 05 2008 Dan Walsh 2.4.6-180- Fix label on /usr/sbin/ipsecResolves: #469943
* Mon Nov 03 2008 Dan Walsh 2.4.6-179- Allow restorecon to read locale_tResolves: #469402- Allow hal/pm-utils to look at /var/run/video.rom
* Sat Oct 25 2008 Dan Walsh 2.4.6-178- Allow dnsmasq reading of pid filesResolves: #442028
* Sat Oct 25 2008 Dan Walsh 2.4.6-177- More fixes for NetworkManagerResolves: #442028
* Wed Oct 22 2008 Dan Walsh 2.4.6-173- Allow samba to read crack_dbResolves: #467905
* Wed Oct 22 2008 Dan Walsh 2.4.6-171- Allow ssh_keygen_t to read fips_enabledResolves: #467720
* Tue Oct 21 2008 Dan Walsh 2.4.6-170- Allow confined domains to read fips_enabledResolves: #467720
* Tue Oct 21 2008 Dan Walsh 2.4.6-168- Add zosremote policy- Allow confined domains to read fips_enabledResolves: #467720
* Thu Oct 16 2008 Dan Walsh 2.4.6-167- Fix relabel to not output so many avcsResolves: #467229
* Thu Oct 16 2008 Dan Walsh 2.4.6-166- Allow snmp to getschedResolves: #466470
* Thu Oct 09 2008 Dan Walsh 2.4.6-165- New policy to allow fsdaemon to create correctly labeled devicesResolves: #456471
* Thu Oct 09 2008 Dan Walsh 2.4.6-164- Fix labeling on dhclient-lease files- Allow portmap_helper to bind to rpc portsResolves: #451805
* Fri Oct 03 2008 Dan Walsh 2.4.6-162- Allow domains to read etc_runtime for access to modified denyhosts- Allow dhcpc_t to list dbusd_etc_t directoryResolves: #459888
* Wed Sep 24 2008 Dan Walsh 2.4.6-161- More fixes for NetworkManagerResolves: #442028
* Wed Sep 24 2008 Dan Walsh 2.4.6-160- Upgrade dbus policy to match new packageResolves: #463267
* Wed Sep 17 2008 Dan Walsh 2.4.6-158- Proper labeling on wsgiResolves: #461323
* Fri Sep 12 2008 Dan Walsh 2.4.6-157- Allow postdrop rw sendmail unix_stream sockets- Additional snmp Resolves: #461323
* Fri Sep 12 2008 Dan Walsh 2.4.6-156- Add racoon/ipsec policyResolves: #247510
* Fri Sep 12 2008 Dan Walsh 2.4.6-155- Complete backport of logging/audit policy- Allow pegasus to look at kernel xen informationResolves: #461624
* Sat Sep 06 2008 Dan Walsh 2.4.6-154- Allow portmak to read kernel state - Allow ricci to figure out if cluster services are runningResolve: #461769
* Fri Sep 05 2008 Dan Walsh 2.4.6-153- Make stunnel work with psieved and other python scriptsResolve: #460733
* Thu Sep 04 2008 Dan Walsh 2.4.6-152- Allow freeradius to connect to snmp portResolve: #461040
* Wed Sep 03 2008 Dan Walsh 2.4.6-151- allow mailman_t signull- Fix location of sepolgen-ifgenResolves: #460398
* Sat Aug 30 2008 Dan Walsh 2.4.6-150- Allow iscsi net_rawResolves: #460398
* Wed Aug 27 2008 Dan Walsh 2.4.6-149- Fix file context to install on strict/mls policy- Allow hal to modify input deviceResolves: #442623
* Fri Aug 08 2008 Dan Walsh 2.4.6-145- Policy does not allow ifpolgen-if to work properlyResolves: #444133
* Fri Aug 08 2008 Dan Walsh 2.4.6-144- add mmap_low booleanResolves: #444133
* Wed Jul 30 2008 Dan Walsh 2.4.6-143- Allow smbd_t to chown filesResolves: #456674
* Thu Jul 17 2008 Dan Walsh 2.4.6-142- add mmap_low boolean- Upgrade to latest networkmanager policy- Add kpropd policy- update nscd policy- Update ntp policy- Update openvpn policy- Fix ppp_read_read interface- fix portmapper to allow it to connect to all <1024 ports- Fix ricci_modstorage to be able to start clvmdResolves: #442028Resolves: #447014Resolves: #455784
* Tue Jun 17 2008 Dan Walsh 2.4.6-141- Allow squid to listen to port 3401Resolves: #452787Resolves: #450390
* Tue Jun 17 2008 Dan Walsh 2.4.6-139- Add infiniband supportResolves: #447854
* Tue May 06 2008 Dan Walsh 2.4.6-138- Allow pam_console to setattr on cpu_device_tResolves: #447403- selinux-policy support for virtio block devicesResolves: #446229
* Wed Apr 30 2008 Dan Walsh 2.4.6-137.1- Allow named to bind to any udp portResolves: #451970
* Wed Apr 30 2008 Dan Walsh 2.4.6-137- Allow mdadm to read /dev/.udev directoryResolves: #248467
* Tue Apr 29 2008 Dan Walsh 2.4.6-136- Allow mdadm to read /dev/.udev directory- Allow Radiusd to access mysqlResolves: #248467
* Tue Apr 22 2008 Dan Walsh 2.4.6-135- Fixes for radiousd access in SELinuxResolves: #248467
* Sun Apr 20 2008 Dan Walsh 2.4.6-134- Allow kerberos daemons to create log files- Resolves: 442981- Fix label on /usr/libexec/hal_lpadminResolves: #442951
* Fri Apr 18 2008 Dan Walsh 2.4.6-133- Allow netutils to read kernel and net sysctlsResolves: #439018
* Tue Apr 15 2008 Dan Walsh 2.4.6-131- Allow rpc apps to manage coolkey directoryResolves: #440685
* Fri Apr 11 2008 Dan Walsh 2.4.6-130- Fix regression Resolves: #440260
* Thu Apr 10 2008 Dan Walsh 2.4.6-129- Fix regression Resolves: #440260
* Mon Apr 07 2008 Dan Walsh 2.4.6-128- Allow dhcpc to read dbus configResolves: #440260
* Sat Apr 05 2008 Dan Walsh 2.4.6-127- Allow deliver to manage homedir content, and Resolves: #414891
* Tue Mar 11 2008 Dan Walsh 2.4.6-126- Allow lvm to create fifo_file- Fix building of policy modules with MakefileResolves: #438234
* Wed Feb 27 2008 Dan Walsh 2.4.6-125- Dontaudit leaked httpd file descriptorResolves: #430702
* Tue Feb 26 2008 Dan Walsh 2.4.6-124- Fix deletion of dovecot files in strict/mls policy Resolves 434843- Allow hal to setsched on kernelResolves: #435197
* Fri Feb 22 2008 Dan Walsh 2.4.6-123- Fix labeling of exim log filesResolves: #429843
* Tue Feb 19 2008 Dan Walsh 2.4.6-122- Allow vpnc to bind to ipsecnat portResolves: #433363
* Thu Feb 07 2008 Dan Walsh 2.4.6-121- Fix transition rules on creation of nfs files in homedir.Resolves: #430577
* Wed Feb 06 2008 Dan Walsh 2.4.6-120- Fix transition rules on creation of nfs files in homedir.Resolves: #430577
* Mon Feb 04 2008 Dan Walsh 2.4.6-119- Revert previous version of policygentool- Remove snmpd_etc_tResolves: #247461
* Thu Jan 31 2008 Dan Walsh 2.4.6-118- Allow xdm_xserver_t to domain_mmap_lowResolves: #431023
* Tue Jan 29 2008 Dan Walsh 2.4.6-117- Allow mailman to signal itselfResolves: #430639- Allow iscsid to setrlimit Resolves: #430669- Additional fix to allow setroubleshoot to talk to dbusResolves: #224351
* Mon Jan 21 2008 Dan Walsh 2.4.6-116- Allow sysstat to read sysfsResolves: #429554
* Thu Jan 17 2008 Dan Walsh 2.4.6-115- Update selinux-policy to handle setroubleshootResolves: #224351
* Tue Jan 15 2008 Dan Walsh 2.4.6-114- Allow restorecond to read homedir sym links- Allow mailservers/postfix to use nfs file systemsResolves: #245605
* Thu Jan 10 2008 Dan Walsh 2.4.6-112- Turn off domain fd for MLSResolves: #427517
* Thu Jan 10 2008 Dan Walsh 2.4.6-111- Fix passing of fds, test regressionResolves: #427517
* Tue Jan 08 2008 Dan Walsh 2.4.6-110- Add access for oddjobResolves: #427517
* Tue Dec 18 2007 Dan Walsh 2.4.6-108- Allow kudzu to domtrans to unconfined_t- Allow audit to send mail- Allow mailman and postfix to interactResolves: #425806:
* Tue Dec 11 2007 Dan Walsh 2.4.6-107- Remove badly labeled pegasus directory- Allow postfix to work with NFS homedirs- Allow iptables to connect to ldap- Allow apache scripts to run nice- Allow ntpd to use /dev/ptmx for setting the time- Allow automount to read /dev/random- Allow samba to use kerberos- Allow squid to access to port 2048- Allow amanda to talk to ldap- Allow yppasswd to run pwupdate- Allow automount to mount squashfs- Add new nscd permissions- Resolves: #245605Resolves: #248838Resolves: #251841Resolves: #253999Resolves: #316011Resolves: #326631Resolves: #350511Resolves: #366461Resolves: #390771Resolves: #247814Resolves: #238347Resolves: #351051Resolves: #254199Resolves: #288771Resolves: #294671Resolves: #317281Resolves: #340311Resolves: #340321Resolves: #386481Resolves: #327121Resolves: #416541Resolves: #416561Resolves: #414891Resolves: 383231Resolves: 254197Resolves: 266341Resolves: 248835Resolves: 326721Resolves: 319791Resolves: 359701Resolves: 374431Resolves: 403241Resolves: 251712Resolves: 283971Resolves: 284361Resolves: 300391Resolves: 339651Resolves: 383191Resolves: 279261
* Wed Oct 24 2007 Dan Walsh 2.4.6-106.EL5_1.3- Allow NetworkManager and rpm_t to dbus chat- Rebuilding for errata toolResolves: 345991
* Wed Oct 03 2007 Dan Walsh 2.4.6-106.1- dontaudit consoletype talking to hotplug- allow hotplug to signal ifconfigResolves: 328211Resolves: 328251
* Wed Oct 03 2007 Dan Walsh 2.4.6-106- Remove additional avc\'s caused by pm-toolsResolves: #282421
* Wed Oct 03 2007 Dan Walsh 2.4.6-104- Fix salsa context to create alsa.sound correctlyResolves: #315341
* Tue Oct 02 2007 Dan Walsh 2.4.6-102- Allow multipathd to connect to itselfResolves: #245268
* Fri Sep 28 2007 Dan Walsh 2.4.6-101- Dontaudit postfix_smtpd_t getattr on /home- Fix ftpResolves: #245268
* Wed Sep 26 2007 Dan Walsh 2.4.6-99- Introduced a minor bug when fixing replay cache, blowing up strict policyResolves: #284831
* Tue Sep 25 2007 Dan Walsh 2.4.6-97- Fixup clmvd to allow creation of fixed devices- Fixes telnet/rlogin using replay cacheResolves: #284831
* Fri Sep 14 2007 Dan Walsh 2.4.6-93- Allow hal to write to pm-tools directoriesResolves: #282421
* Thu Sep 13 2007 Dan Walsh 2.4.6-92- Many fixes for Kerberos Replay Cache.Resolves: #282421
* Wed Sep 12 2007 Dan Walsh 2.4.6-91- Many fixes for Kerberos Replay Cache.- Allow xfs to listen on port 7100Resolves: #282421
* Sat Sep 08 2007 Dan Walsh 2.4.6-90- Additional perms for xenResolves: #249895
* Thu Sep 06 2007 Dan Walsh 2.4.6-89- Allow postfix to read master proc info- Allow unix_update to talk to nsswitch- Allow dmidecode to search sysfs_tResolves: #263141
* Wed Sep 05 2007 Dan Walsh 2.4.6-88- Fix relabel of /var/run dir- Allow snmp to read any directory- Allow cimserver to create pegasus_data directoriesResolves: #213809- Change to context on /var/run/libvirtResolves: #249069
* Wed Aug 22 2007 Dan Walsh 2.4.6-86- More fixes for snmpResolves: #246431
* Wed Aug 22 2007 Dan Walsh 2.4.6-85- Fix duplicate /etc/asound.state- Allow auditctl to getattr on all filesResolves: #249754
* Tue Aug 21 2007 Dan Walsh 2.4.6-84- Allow dovecot read of /tmp files for kerberos- Fix apache policy for virtual hosting- Allow Xen to run on nfsResolves: #253744
* Fri Aug 17 2007 Steve Grubb 2.4.6-83- Add set_loginuid permission to ftpd_tResolves:#220085
* Wed Aug 08 2007 Dan Walsh 2.4.6-82- Fix java specifications for IBM- Fix xen startup problemsResolves:#249895
* Sat Jul 28 2007 Dan Walsh 2.4.6-81- Allow auditctl dac_override and dac_read_searchResolves:#249754
* Thu Jul 12 2007 Dan Walsh 2.4.6-80- New devices- Allow fsadm to use xen images and log files
* Sun Jul 08 2007 Dan Walsh 2.4.6-79- Allow hal to write to pm-suspendResolves:#245926
* Mon Jul 02 2007 Dan Walsh 2.4.6-78- Added fixes for gfs init scriptResolves:#246194
* Tue Jun 12 2007 Dan Walsh 2.4.6-77- More fixes add mmap_zero for new kernelResolves:#244690
* Tue Jun 12 2007 Dan Walsh 2.4.6-76- Allow xenconsole to manage xen log files- add mmap_zero for new kernel- Fixes for RHEL5Resolves:#244690
* Tue Jun 12 2007 Dan Walsh 2.4.6-75- Allow lvm to connecto unix_stream_socketResolves: #241621
* Wed May 30 2007 Dan Walsh 2.4.6-74- Fix location of ypxfr on 64 bit platforms- Fixes for nagios, postfix, procmail, saslauthd, arpwatch, avahi, dovecotResolves: #241621
* Wed May 23 2007 Dan Walsh 2.4.6-72- Allow prelink sys_resource, Add transition rule to allow apps to run java in different context
* Wed May 16 2007 Dan Walsh 2.4.6-71- Allow netlable to read etc and work with init terminals- Change file context to have all of policy at SystemLowResolves: #239079
* Wed May 16 2007 Dan Walsh 2.4.6-70- Back out Useradd changeResolves: #239079
* Tue May 08 2007 Dan Walsh 2.4.6-69- Useradd causes files to lower sensitivityResolves: #239079
* Fri May 04 2007 Dan Walsh 2.4.6-68- Cleanup handling of audit messagesResolves: #238189
* Wed Apr 25 2007 Dan Walsh 2.4.6-67- Allow logging into the console on s390Resolves: #237703- Additional avc\'s caused by change in unix_updateResolves: #236316
* Wed Apr 25 2007 Dan Walsh 2.4.6-64- Fix crond avc when trying to read shadowResolves: #236316
* Wed Apr 25 2007 Dan Walsh 2.4.6-63- Handle password experationResolves: #236316
* Sat Apr 21 2007 Dan Walsh 2.4.6-62- Revert patch to stop secadm and sysadm from having audit_controlResolves: #236855
* Fri Apr 20 2007 Dan Walsh 2.4.6-61 - Fix admin_domain_template to allow custom user typesResolves: #237133-Allow lvm to create/delete generic device_t direcories/files under /dev Resolves: #237128
* Thu Apr 19 2007 Dan Walsh 2.4.6-60- Fixes for AIDE at SystemHigh- Stop secadm and sysadm from having audit_controlResolves: #236855
* Tue Apr 17 2007 Dan Walsh 2.4.6-59- Allow racoon to send audit messagesResolves: #232508
* Tue Apr 17 2007 Dan Walsh 2.4.6-58- Fix aide specification Resolves: #234885
* Sat Apr 14 2007 Dan Walsh 2.4.6-57- Allow ssh to read passwd crack databaseResolves: #236316
* Thu Apr 12 2007 Dan Walsh 2.4.6-56- Allow lvm mls_file_read_up to look at Fixed disksResolves: #236060
* Wed Apr 11 2007 Dan Walsh 2.4.6-55- kudzu Needs to ptrace initResolves: #225443
* Wed Apr 11 2007 Dan Walsh 2.4.6-54- syslog needs to be run as SystemHigh- Fix file context mappingResolves: #235725
* Fri Apr 06 2007 Dan Walsh 2.4.6-52- Allow netutils to read sysfsResolves: #235357- Allow samba to work as a PDCResolves: #235360- Allow ypserv to bind to ports 600-1024Resolves: #235363- Fix kudzu to be able to telinitResolves: #225443
* Wed Apr 04 2007 Dan Walsh 2.4.6-51- Allow nscd setcap privs
* Tue Apr 03 2007 Dan Walsh 2.4.6-50- More work to allow kudzu to setup init correctly so getty will workResolves: #225443- Allow pegasus to execute ifconfigResolves: #227485- Allow Aide to look at lnk_files and other fixesResolves: #234885- querying cups jobs with sysadm_r needs override mls restrictionsResolves: #234889
* Wed Mar 28 2007 Dan Walsh 2.4.6-49- Change init_daemon_domain(netlabel_mgmt_t,netlabel_mgmt_exec_t)- to init_system_domain(netlabel_mgmt_t,netlabel_mgmt_exec_t)Resolves: #233313
* Tue Mar 20 2007 Dan Walsh 2.4.6-47- Allow sysadm_r to transition to netlabel_mgmtResolves: #233313- Allow kudzu to setup init correctly so getty will workResolves: #225443
* Tue Mar 20 2007 Dan Walsh 2.4.6-46- Allow cyrus_t to user kerberos- Allow cyrus_t to send mail- Allow saslauthd_t to user kerberos
* Fri Mar 09 2007 Dan Walsh 2.4.6-45- Allow setkey to search racoon_conf- Allow ccs to create tmp filesResolves: #231021
* Fri Mar 09 2007 Dan Walsh 2.4.6-44- Fix use of hi_reserved_port_t
* Tue Mar 06 2007 Dan Walsh 2.4.6-43- Add amtu policy for MLSResolves: #231021-Additional paths for cups
* Thu Mar 01 2007 Dan Walsh 2.4.6-42- Dontaudit restorecon writing to cron pipes- Fix filespec for /dev/ub
*- Allow ftp and telnet to use kerberos key files- Allow syslog to use alternate ports- Allow radious to look at the routing table- Allow pyzor to getattr on autofs
* Thu Feb 22 2007 Dan Walsh 2.4.6-41- Allow samba to run as domain controller - execute useradd
* Fri Feb 16 2007 Dan Walsh 2.4.6-40- Fix bugzilla file context.
* Thu Feb 15 2007 Dan Walsh 2.4.6-39- Add bugzilla policy- Allow procmail to create tmp files so spamassisin will work- Some fixes for pyzor
* Wed Feb 14 2007 Dan Walsh 2.4.6-38- Removing dangling inlcud symlink if devel not installedResolves: #220085
* Mon Feb 12 2007 Dan Walsh 2.4.6-37- Allow kudzu to signal init to restartResolves: #225443
* Mon Feb 05 2007 Dan Walsh 2.4.6-36- Allow xen to work properly on ia64, needs to be able to read dosfs_tResolves: #217362- Allow mozilla, evolution and thunderbird to read dev_random.Resolves: FC6-227002- Allow spamd to connect to smtp portResolves: FC6-227184- Fixes to make ypxfr workResolves: FC6-227237- Allow audit fsetsid capabilityResolves: FC6-227423- Allow syslog (syslog-ng) to tcp_connect to other syslog serversResolves: FC6-218978
* Fri Jan 26 2007 Dan Walsh 2.4.6-35- Fixes to make setrans work properly on MLSResolves: #224441
* Fri Jan 26 2007 Dan Walsh 2.4.6-34- Fixes to make setrans work properly on MLSResolves: #224441
* Fri Jan 26 2007 Dan Walsh 2.4.6-33- Additional fixes for ricci_modstorage, lvm- Fixes for mls policy net labelResolves: #224441
* Wed Jan 24 2007 Dan Walsh 2.4.6-31- Fix clvmd policy- Fix squid cgi script to run with correct context.- Maintain proper context on /etc/lvm/.cache file- Lots of fixes for ricci and friends- mount.nfs needs sys_resource- Change gstreamer context for only i386- Fix libXcomp file_contextResolves: #224441
* Tue Jan 23 2007 Dan Walsh 2.4.6-30- Fixes for ricci_modserviceResolves: #217519
* Mon Jan 22 2007 Dan Walsh 2.4.6-29- remove swapfile avc- Fix rpcsvcgssdResolves: #217519
* Wed Jan 17 2007 Dan Walsh 2.4.6-28- Allow logwatch to use ypbind- Allow system_crond_t to create cron_var_run_t files (prelink files)- dontaudit postfix-smtp reading /boot, fix file context on lmtpResolves: #215722
* Mon Jan 15 2007 Dan Walsh 2.4.6-27- Fix senmail avc trying to read /root- More fixes for ssh transitions to userspaceResolves: #221608Resolves: #222548
* Fri Jan 12 2007 Dan Walsh 2.4.6-26- automounter needs setuid- prelink needs to be able to rw_dir_perms on usr_t- pcscd_t needs to be able to search sysfs_t- Lots of fixes to run sshd under xinetdResolves: #219999
* Wed Jan 10 2007 Dan Walsh 2.4.6-25- Allow pcscd to use dac_search_override capabilityResolves: #222064
* Mon Jan 08 2007 Dan Walsh 2.4.6-24- Allow prelink when run from rpm to create tmp filesResolves: #221865- Remove file_context for exportfsResolves: #221181- Allow spamassassin to create ~/.spamassissinResolves: #203290- Allow netlabel packets to flow.Resolves: #210426