Changelog for
selinux-policy-3.7.19-54.SEL6.noarch.rpm :
* Fri Dec 10 2010 Eddy Nigg
- Rebuild for StartCom Linux 6.0.x
* Thu Sep 02 2010 Miroslav Grepl 3.7.19-54- Allow clmvd to create tmpfs filesResolves: #629391Resolves: #594833
* Wed Sep 01 2010 Miroslav Grepl 3.7.19-53- Fixes for jabberd policy- Fixes for sandbox policy
* Mon Aug 30 2010 Miroslav Grepl 3.7.19-52- Fix label for /bin/mountpoint - Allow fsadm to read virt blk image files
* Wed Aug 25 2010 Miroslav Grepl 3.7.19-51- Allow seunshare fowner capability- Allow dovecot to manage postfix privet socket
* Tue Aug 24 2010 Miroslav Grepl 3.7.19-50- Fixes for boinc policy- Fixes for shorewall policy
* Fri Aug 20 2010 Miroslav Grepl 3.7.19-49- Add label for /var/cache/rpcbind directory- Add chrome_role for xguest- Fix amavis_read_spool_files interface
* Wed Aug 18 2010 Miroslav Grepl 3.7.19-48- Fixes for shorewall policy- Allow sssd chown capability- Fix label for /usr/bin/mutter- Label dead.letter as mail_home_t- Allow pcscd to read hardware state information - Fixes for ulogd policy
* Fri Aug 13 2010 Miroslav Grepl 3.7.19-47- Fixes for boinc-project policy- Allow swat to read nmbd pid file- Allow fail2ban to read BIND log files- Fix cert handling from Dan - Remove transition from unconfined to ncftool domain
* Wed Aug 11 2010 Miroslav Grepl 3.7.19-46- Allow ipsec-mgmt to dbus chat with unconfined- Fixes for boinc policy
* Tue Aug 10 2010 Miroslav Grepl 3.7.19-45- Fixes for cgroup policy- Fixes for ncftool policy- Add ncftool_read_user_content boolean- Fix label for boinc init script- Fix label for fence_tool- Allow vhostmd to write virt content- Allow ricci domtrans ot shutdown
* Thu Aug 05 2010 Miroslav Grepl 3.7.19-44- Add support for luci- Add label for /var/spool/up2date
* Wed Aug 04 2010 Miroslav Grepl 3.7.19-43- Allow ncftool to run brctl- Fixes for ricci-modclusterd policy- Allow uucpd to execute ssh client- Add label for dayplanner- Allow sandbox_xserver execstack
* Mon Aug 02 2010 Miroslav Grepl 3.7.19-42- Allow kdump to read information from the debugging filesystem- Update boinc policy- Fixes for logwatch-mail policy
* Tue Jul 27 2010 Miroslav Grepl 3.7.19-41- Allow logwatch_mail to read read the networking state information.- Add label for /usr/bin/dosbox- Allow systat sys_admin capability
* Fri Jul 23 2010 Miroslav Grepl 3.7.19-40- Fixes for puppetmaster- Fix label for kadmin init script- Fixes for logwatch-mail policy- Allow arpwatch to request the kernel to load modules- Allow cron jobs to run with context of user that started them
* Wed Jul 21 2010 Miroslav Grepl 3.7.19-39- Allow munin_system_plugin to read files in /usr- Do not audit insmod attempts to write virt daemon unnamed pipes- Allow corosync to read ricci lib files
* Mon Jul 19 2010 Miroslav Grepl 3.7.19-38- Allow xdm_t to manage gnome homedir content- Allow s-c-firewall to read and write virtual memory sysctls- Fixes for logwatch policy
* Wed Jul 14 2010 Miroslav Grepl 3.7.19-37- Redefine hi_reserved_port_t to include ports from 512 to 599 - Add label for /sbin/sushell- Fixes for munin plugin policy
* Tue Jul 13 2010 Miroslav Grepl 3.7.19-36- Allow netutils to read and write USB monitor devices- Fix label for /rhev- Add user_setrlimit boolean- Allow initrc to manage virt lib files- Add support for ebtables- Add label for /bin/mksh- Dontaudit aiccu sys_tty_config capability- Add httpd_setrlimit boolean
* Fri Jul 09 2010 Miroslav Grepl 3.7.19-35- Add label for /bin/yash- Fixes for rhcs and corosync policy- Fixes for piranha-web policy
* Thu Jul 01 2010 Miroslav Grepl 3.7.19-34- Fix ipsec-mgmt inteface
* Wed Jun 30 2010 Miroslav Grepl 3.7.19-33- Fix label for /var/lib/git- Fix labels for conflicted files- Fix cgroup_admin interface
* Mon Jun 28 2010 Miroslav Grepl 3.7.19-32- Allow sectool to connect to users over unix stream socket- Add label for /var/spool/abrt-upload- Add audio_home_t type for homedir/Music files- Allow aiccu to read network config files- Allow qpidd to setsched- Allow virt domains to manage svirt_image_t fifo files- Fixes for NM-openswan- Fixes for admin interfaces
* Mon Jun 21 2010 Miroslav Grepl 3.7.19-31- Remove daemons dontaudit to search all dirs - Add support for epylog- All all domains to read lib files- Allow denyhosts to send syslog messages- Allow mysql-safe setrlimit- Allow rpm to execute rpm_tmp_t- Allow dmesg to appen abrt_var_cache files- Fixed label for abrt.socket
* Wed Jun 16 2010 Miroslav Grepl 3.7.19-30- Allow sysadm to run ncftool- Fixes for cobbler policy- Allow Network Manager to transition to ipsec_mgmt domain- Add label for /usr/libexec/nm-openswan-service- Add label for /dev
* Tue Jun 15 2010 Miroslav Grepl 3.7.19-29- Allow abrt sigkill- Add ncftool policy- Add cluster fixes- Fixes for audisp-remote
* Mon Jun 14 2010 Miroslav Grepl 3.7.19-28- Fixes for netutils- Cleanup of aiccu policy- Add mpd policy
* Wed Jun 09 2010 Miroslav Grepl 3.7.19-27- Allow ftpd ipc_lock capability- Allow audisp-remote to getcap and setcap- Allow iscsid to read and write raw memory devices- Fixes for bitlbee policy
* Wed Jun 09 2010 Miroslav Grepl 3.7.19-26- Allow krb5kdc to write krb5kdc_principal_t file- Allow hald to send generic signal to dhcp client- Fix dev_rw_vhost interface- Add /var/run/abrt.socket label
* Tue Jun 08 2010 Miroslav Grepl 3.7.19-25- Fixes for cmirrord policy- Dontaudit xauth to list inotifyfs filesystem.- Allow xserver to translate contexts.- Allow kdumpgui domain sys_admin capability- Allow vpnc to relabelfrom tun_socket- Allow prelink_cron_system_t to signal- Fixes for gitolite- Allow virt domain to read symbolic links in device directories
* Thu Jun 03 2010 Miroslav Grepl 3.7.19-24- Add support for /dev/vhost-net- Allow psad to read files in /usr- Allow systat to use nscd socket- Fixes for boinc policy
* Tue Jun 01 2010 Miroslav Grepl 3.7.19-23- Add cmirrord policy- Fixes for accountsd policy- Fixes for boinc policy- Allow cups-pdf to set attributes on fonts cache directory- Allow radiusd to setrlimit- Allow nscd sys_ptrace capability
* Tue May 25 2010 Dan Walsh 3.7.19-22- Allow procmail to execute scripts in the users home dir that are labeled home_bin_t- Fix /var/run/abrtd.lock label
* Mon May 24 2010 Dan Walsh 3.7.19-21- Allow login programs to read krb5_home_tResolves: 594833- Add obsoletes for cachefilesfd-selinux packageResolves: #575084
* Thu May 20 2010 Dan Walsh 3.7.19-20- Allow mount to r/w abrt fifo file- Allow svirt_t to getattr on hugetlbfs- Allow abrt to create a directory under /var/spool
* Wed May 19 2010 Dan Walsh 3.7.19-19- Add labels for /sys- Allow sshd to getattr on shutdown- Fixes for munin- Allow sssd to use the kernel key ring- Allow tor to send syslog messages- Allow iptabels to read usr files- allow policykit to read all domains state
* Thu May 13 2010 Dan Walsh 3.7.19-17- Fix path for /var/spool/abrt- Allow nfs_t as an entrypoint for http_sys_script_t- Add policy for piranha- Lots of fixes for sosreport
* Wed May 12 2010 Dan Walsh 3.7.19-16- Allow xm_t to read network state and get and set capabilities- Allow policykit to getattr all processes- Allow denyhosts to connect to tcp port 9911- Allow pyranha to use raw ip sockets and ptrace itself- Allow unconfined_execmem_t and gconfsd mechanism to dbus- Allow staff to kill ping process- Add additional MLS rules
* Mon May 10 2010 Dan Walsh 3.7.19-15- Allow gdm to edit ~/.gconf dirResolves: #590677- Allow dovecot to create directories in /var/lib/dovecotPartially resolves 590224- Allow avahi to dbus chat with NetworkManager- Fix cobbler labels- Dontaudit iceauth_t leaks- fix /var/lib/lxdm file context- Allow aiccu to use tun tap devices- Dontaudit shutdown using xserver.log
* Thu May 06 2010 Dan Walsh 3.7.19-14- Fixes for sandbox_x_net_t to match access for sandbox_web_t ++- Add xdm_etc_t for /etc/gdm directory, allow accountsd to manage this directory- Add dontaudit interface for bluetooth dbus- Add chronyd_read_keys, append_keys for initrc_t- Add log support for ksmtunedResolves: #586663
* Thu May 06 2010 Dan Walsh 3.7.19-13- Allow boinc to send mail
* Wed May 05 2010 Dan Walsh 3.7.19-12- Allow initrc_t to remove dhcpc_state_t- Fix label on sa-update.cron- Allow dhcpc to restart chrony initrc- Don\'t allow sandbox to send signals to its parent processes- Fix transition from unconfined_t -> unconfined_mount_t -> rpcd_tResolves: #589136
* Mon May 03 2010 Dan Walsh 3.7.19-11- Fix location of oddjob_mkhomedirResolves: #587385- fix labeling on /root/.shosts and ~/.shosts- Allow ipsec_mgmt_t to manage net_conf_tResolves: #586760
* Fri Apr 30 2010 Dan Walsh 3.7.19-10- Dontaudit sandbox trying to connect to netlink socketsResolves: #587609- Add policy for piranha
* Thu Apr 29 2010 Dan Walsh 3.7.19-9- Fixups for xguest policy- Fixes for running sandbox firefox
* Wed Apr 28 2010 Dan Walsh 3.7.19-8- Allow ksmtuned to use terminalsResolves: #586663- Allow lircd to write to generic usb devices
* Tue Apr 27 2010 Dan Walsh 3.7.19-7- Allow sandbox_xserver to connectto unconfined streamResolves: #585171
* Mon Apr 26 2010 Dan Walsh 3.7.19-6- Allow initrc_t to read slapd_db_tResolves: #585476- Allow ipsec_mgmt to use unallocated devpts and to create /etc/resolv.confResolves: #585963
* Thu Apr 22 2010 Dan Walsh 3.7.19-5- Allow rlogind_t to search /root for .rhostsResolves: #582760- Fix path for cached_var_t- Fix prelink paths /var/lib/prelink - Allow confined users to direct_dri- Allow mls lvm/cryptosetup to work
* Wed Apr 21 2010 Dan Walsh 3.7.19-4- Allow virtd_t to manage firewall/iptables configResolves: #573585
* Tue Apr 20 2010 Dan Walsh 3.7.19-3- Fix label on /root/.rhostsResolves: #582760- Add labels for Picasa- Allow openvpn to read home certs- Allow plymouthd_t to use tty_device_t- Run ncftool as iptables_t- Allow mount to unmount unlabeled_t- Dontaudit hal leaks
* Wed Apr 14 2010 Dan Walsh 3.7.19-2- Allow livecd to transition to mount
* Tue Apr 13 2010 Dan Walsh 3.7.19-1- Update to upstream- Allow abrt to delete sosreportResolves: #579998- Allow snmp to setuid and gidResolves: #582155- Allow smartd to use generic scsi devicesResolves: #582145
* Tue Apr 13 2010 Dan Walsh 3.7.18-3- Allow ipsec_t to create /etc/resolv.conf with the correct label- Fix reserved port destination- Allow autofs to transition to showmount- Stop crashing tuned
* Mon Apr 12 2010 Dan Walsh 3.7.18-2- Add telepathysofiasip policy
* Mon Apr 05 2010 Dan Walsh 3.7.18-1- Update to upstream- Fix label for /opt/google/chrome/chrome-sandbox- Allow modemmanager to dbus with policykit
* Mon Apr 05 2010 Dan Walsh 3.7.17-6- Fix allow_httpd_mod_auth_pam to use auth_use_pam(httpd_t)- Allow accountsd to read shadow file- Allow apache to send audit messages when using pam- Allow asterisk to bind and connect to sip tcp ports- Fixes for dovecot 2.0- Allow initrc_t to setattr on milter directories- Add procmail_home_t for .procmailrc file
* Thu Apr 01 2010 Dan Walsh 3.7.17-5- Fixes for labels during install from livecd
* Thu Apr 01 2010 Dan Walsh 3.7.17-4- Fix /cgroup file context - Fix broken afs use of unlabled_t- Allow getty to use the console for s390
* Wed Mar 31 2010 Dan Walsh 3.7.17-3- Fix cgroup handling adding policy for /cgroup- Allow confined users to write to generic usb devices, if user_rw_noexattrfile boolean set
* Tue Mar 30 2010 Dan Walsh 3.7.17-2- Merge patches from dgrift
* Mon Mar 29 2010 Dan Walsh 3.7.17-1- Update upstream- Allow abrt to write to the /proc under any process
* Fri Mar 26 2010 Dan Walsh 3.7.16-2- Fix ~/.fontconfig label- Add /root/.cert label- Allow reading of the fixed_file_disk_t:lnk_file if you can read file- Allow qemu_exec_t as an entrypoint to svirt_t
* Tue Mar 23 2010 Dan Walsh 3.7.16-1- Update to upstream- Allow tmpreaper to delete sandbox sock files- Allow chrome-sandbox_t to use /dev/zero, and dontaudit getattr file systems- Fixes for gitosis- No transition on livecd to passwd or chfn- Fixes for denyhosts
* Tue Mar 23 2010 Dan Walsh 3.7.15-4- Add label for /var/lib/upower- Allow logrotate to run sssd- dontaudit readahead on tmpfs blk files- Allow tmpreaper to setattr on sandbox files- Allow confined users to execute dos files- Allow sysadm_t to kill processes running within its clearance- Add accountsd policy- Fixes for corosync policy- Fixes from crontab policy- Allow svirt to manage svirt_image_t chr files- Fixes for qdisk policy- Fixes for sssd policy- Fixes for newrole policy
* Thu Mar 18 2010 Dan Walsh 3.7.15-3- make libvirt work on an MLS platform
* Thu Mar 18 2010 Dan Walsh 3.7.15-2- Add qpidd policy
* Thu Mar 18 2010 Dan Walsh 3.7.15-1- Update to upstream
* Tue Mar 16 2010 Dan Walsh 3.7.14-5- Allow boinc to read kernel sysctl- Fix snmp port definitions- Allow apache to read anon_inodefs
* Sun Mar 14 2010 Dan Walsh 3.7.14-4- Allow shutdown dac_override
* Sat Mar 13 2010 Dan Walsh 3.7.14-3- Add device_t as a file system- Fix sysfs association
* Fri Mar 12 2010 Dan Walsh 3.7.14-2- Dontaudit ipsec_mgmt sys_ptrace- Allow at to mail its spool files- Allow nsplugin to search in .pulse directory
* Fri Mar 12 2010 Dan Walsh 3.7.14-1- Update to upstream
* Fri Mar 12 2010 Dan Walsh 3.7.13-4- Allow users to dbus chat with xdm- Allow users to r/w wireless_device_t- Dontaudit reading of process states by ipsec_mgmt
* Thu Mar 11 2010 Dan Walsh 3.7.13-3- Fix openoffice from unconfined_t
* Wed Mar 10 2010 Dan Walsh 3.7.13-2- Add shutdown policy so consolekit can shutdown system
* Tue Mar 09 2010 Dan Walsh 3.7.13-1- Update to upstream
* Thu Mar 04 2010 Dan Walsh 3.7.12-1- Update to upstream
* Thu Mar 04 2010 Dan Walsh 3.7.11-1- Update to upstream - These are merges of my patches- Remove 389 labeling conflicts- Add MLS fixes found in RHEL6 testing- Allow pulseaudio to run as a service- Add label for mssql and allow apache to connect to this database port if boolean set- Dontaudit searches of debugfs mount point- Allow policykit_auth to send signals to itself- Allow modcluster to call getpwnam- Allow swat to signal winbind- Allow usbmux to run as a system role- Allow svirt to create and use devpts
* Mon Mar 01 2010 Dan Walsh 3.7.10-5- Add MLS fixes found in RHEL6 testing- Allow domains to append to rpm_tmp_t- Add cachefilesfd policy- Dontaudit leaks when transitioning
* Tue Feb 23 2010 Dan Walsh 3.7.10-4- Change allow_execstack and allow_execmem booleans to on- dontaudit acct using console- Add label for fping- Allow tmpreaper to delete sandbox_file_t- Fix wine dontaudit mmap_zero- Allow abrt to read var_t symlinks
* Mon Feb 22 2010 Dan Walsh 3.7.10-3- Additional policy for rgmanager
* Mon Feb 22 2010 Dan Walsh 3.7.10-2- Allow sshd to setattr on pseudo terms
* Mon Feb 22 2010 Dan Walsh 3.7.10-1- Update to upstream
* Thu Feb 18 2010 Dan Walsh 3.7.9-4- Allow policykit to send itself signals
* Wed Feb 17 2010 Dan Walsh 3.7.9-3- Fix duplicate cobbler definition
* Wed Feb 17 2010 Dan Walsh 3.7.9-2- Fix file context of /var/lib/avahi-autoipd
* Fri Feb 12 2010 Dan Walsh 3.7.9-1- Merge with upstream
* Thu Feb 11 2010 Dan Walsh 3.7.8-11- Allow sandbox to work with MLS
* Tue Feb 09 2010 Dan Walsh 3.7.8-9- Make Chrome work with staff user
* Thu Feb 04 2010 Dan Walsh 3.7.8-8- Add icecast policy- Cleanup spec file
* Wed Feb 03 2010 Dan Walsh 3.7.8-7- Add mcelog policy
* Mon Feb 01 2010 Dan Walsh 3.7.8-6- Lots of fixes found in F12
* Wed Jan 27 2010 Dan Walsh 3.7.8-5- Fix rpm_dontaudit_leaks
* Wed Jan 27 2010 Dan Walsh 3.7.8-4- Add getsched to hald_t- Add file context for Fedora/Redhat Directory Server
* Mon Jan 25 2010 Dan Walsh 3.7.8-3- Allow abrt_helper to getattr on all filesystems- Add label for /opt/real/RealPlayer/plugins/oggfformat\\.so
* Thu Jan 21 2010 Dan Walsh 3.7.8-2- Add gstreamer_home_t for ~/.gstreamer
* Mon Jan 18 2010 Dan Walsh 3.7.8-1- Update to upstream
* Fri Jan 15 2010 Dan Walsh 3.7.7-3- Fix git
* Thu Jan 07 2010 Dan Walsh 3.7.7-2- Turn on puppet policy- Update to dgrift git policy
* Thu Jan 07 2010 Dan Walsh 3.7.7-1- Move users file to selection by spec file.- Allow vncserver to run as unconfined_u:unconfined_r:unconfined_t
* Thu Jan 07 2010 Dan Walsh 3.7.6-1- Update to upstream
* Wed Jan 06 2010 Dan Walsh 3.7.5-8- Remove most of the permissive domains from F12.
* Tue Jan 05 2010 Dan Walsh 3.7.5-7- Add cobbler policy from dgrift
* Mon Jan 04 2010 Dan Walsh 3.7.5-6- add usbmon device- Add allow rulse for devicekit_disk
* Wed Dec 30 2009 Dan Walsh 3.7.5-5- Lots of fixes found in F12, fixes from Tom London
* Wed Dec 23 2009 Dan Walsh 3.7.5-4- Cleanups from dgrift
* Tue Dec 22 2009 Dan Walsh 3.7.5-3- Add back xserver_manage_home_fonts
* Mon Dec 21 2009 Dan Walsh 3.7.5-2- Dontaudit sandbox trying to read nscd and sssd
* Fri Dec 18 2009 Dan Walsh 3.7.5-1- Update to upstream
* Thu Dec 17 2009 Dan Walsh 3.7.4-4- Rename udisks-daemon back to devicekit_disk_t policy
* Wed Dec 16 2009 Dan Walsh 3.7.4-3- Fixes for abrt calls
* Fri Dec 11 2009 Dan Walsh 3.7.4-2- Add tgtd policy
* Fri Dec 04 2009 Dan Walsh 3.7.4-1- Update to upstream release
* Mon Nov 16 2009 Dan Walsh 3.7.3-1- Add asterisk policy back in- Update to upstream release 2.20091117
* Mon Nov 16 2009 Dan Walsh 3.7.1-1- Update to upstream release 2.20091117
* Mon Nov 16 2009 Dan Walsh 3.6.33-2- Fixup nut policy
* Thu Nov 12 2009 Dan Walsh 3.6.33-1- Update to upstream
* Thu Oct 01 2009 Dan Walsh 3.6.32-17- Allow vpnc request the kernel to load modules
* Wed Sep 30 2009 Dan Walsh 3.6.32-16- Fix minimum policy installs- Allow udev and rpcbind to request the kernel to load modules
* Wed Sep 30 2009 Dan Walsh 3.6.32-15- Add plymouth policy- Allow local_login to sys_admin
* Tue Sep 29 2009 Dan Walsh 3.6.32-13- Allow cupsd_config to read user tmp- Allow snmpd_t to signal itself- Allow sysstat_t to makedir in sysstat_log_t
* Fri Sep 25 2009 Dan Walsh 3.6.32-12- Update rhcs policy
* Thu Sep 24 2009 Dan Walsh 3.6.32-11- Allow users to exec restorecond
* Mon Sep 21 2009 Dan Walsh 3.6.32-10- Allow sendmail to request kernel modules load
* Mon Sep 21 2009 Dan Walsh 3.6.32-9- Fix all kernel_request_load_module domains
* Mon Sep 21 2009 Dan Walsh 3.6.32-8- Fix all kernel_request_load_module domains
* Sun Sep 20 2009 Dan Walsh 3.6.32-7- Remove allow_exec
* booleans for confined users. Only available for unconfined_t
* Fri Sep 18 2009 Dan Walsh 3.6.32-6- More fixes for sandbox_web_t
* Fri Sep 18 2009 Dan Walsh 3.6.32-5- Allow sshd to create .ssh directory and content
* Fri Sep 18 2009 Dan Walsh 3.6.32-4- Fix request_module line to module_request
* Fri Sep 18 2009 Dan Walsh 3.6.32-3- Fix sandbox policy to allow it to run under firefox. - Dont audit leaks.
* Thu Sep 17 2009 Dan Walsh 3.6.32-2- Fixes for sandbox
* Thu Sep 17 2009 Dan Walsh 3.6.32-1- Update to upstream- Dontaudit nsplugin search /root- Dontaudit nsplugin sys_nice
* Tue Sep 15 2009 Dan Walsh 3.6.31-5- Fix label on /usr/bin/notepad, /usr/sbin/vboxadd-service- Remove policycoreutils-python requirement except for minimum
* Mon Sep 14 2009 Dan Walsh 3.6.31-4- Fix devicekit_disk_t to getattr on all domains sockets and fifo_files- Conflicts seedit (You can not use selinux-policy-targeted and seedit at the same time.)
* Thu Sep 10 2009 Dan Walsh 3.6.31-3- Add wordpress/wp-content/uploads label- Fixes for sandbox when run from staff_t
* Thu Sep 10 2009 Dan Walsh 3.6.31-2- Update to upstream- Fixes for devicekit_disk
* Tue Sep 08 2009 Dan Walsh 3.6.30-6- More fixes
* Tue Sep 08 2009 Dan Walsh 3.6.30-5- Lots of fixes for initrc and other unconfined domains
* Fri Sep 04 2009 Dan Walsh 3.6.30-4- Allow xserver to use netlink_kobject_uevent_socket
* Thu Sep 03 2009 Dan Walsh 3.6.30-3- Fixes for sandbox
* Mon Aug 31 2009 Dan Walsh 3.6.30-2- Dontaudit setroubleshootfix looking at /root directory
* Mon Aug 31 2009 Dan Walsh 3.6.30-1- Update to upsteam
* Mon Aug 31 2009 Dan Walsh 3.6.29-2- Allow gssd to send signals to users- Fix duplicate label for apache content
* Fri Aug 28 2009 Dan Walsh 3.6.29-1- Update to upstream
* Fri Aug 28 2009 Dan Walsh 3.6.28-9- Remove polkit_auth on upgrades
* Wed Aug 26 2009 Dan Walsh 3.6.28-8- Add back in unconfined.pp and unconfineduser.pp- Add Sandbox unshare
* Tue Aug 25 2009 Dan Walsh 3.6.28-7- Fixes for cdrecord, mdadm, and others
* Sat Aug 22 2009 Dan Walsh 3.6.28-6- Add capability setting to dhcpc and gpm
* Sat Aug 22 2009 Dan Walsh 3.6.28-5- Allow cronjobs to read exim_spool_t
* Fri Aug 21 2009 Dan Walsh 3.6.28-4- Add ABRT policy
* Thu Aug 20 2009 Dan Walsh 3.6.28-3- Fix system-config-services policy
* Wed Aug 19 2009 Dan Walsh 3.6.28-2- Allow libvirt to change user componant of virt_domain
* Tue Aug 18 2009 Dan Walsh 3.6.28-1- Allow cupsd_config_t to be started by dbus- Add smoltclient policy
* Fri Aug 14 2009 Dan Walsh 3.6.27-1- Add policycoreutils-python to pre install
* Thu Aug 13 2009 Dan Walsh 3.6.26-11- Make all unconfined_domains permissive so we can see what AVC\'s happen
* Mon Aug 10 2009 Dan Walsh 3.6.26-10- Add pt_chown policy
* Mon Aug 10 2009 Dan Walsh 3.6.26-9- Add kdump policy for Miroslav Grepl- Turn off execstack boolean
* Fri Aug 07 2009 Bill Nottingham 3.6.26-8- Turn on execstack on a temporary basis (#512845)
* Thu Aug 06 2009 Dan Walsh 3.6.26-7- Allow nsplugin to connecto the session bus- Allow samba_net to write to coolkey data
* Wed Aug 05 2009 Dan Walsh 3.6.26-6- Allow devicekit_disk to list inotify
* Wed Aug 05 2009 Dan Walsh 3.6.26-5- Allow svirt images to create sock_file in svirt_var_run_t
* Tue Aug 04 2009 Dan Walsh 3.6.26-4- Allow exim to getattr on mountpoints- Fixes for pulseaudio
* Fri Jul 31 2009 Dan Walsh 3.6.26-3- Allow svirt_t to stream_connect to virtd_t
* Fri Jul 31 2009 Dan Walsh 3.6.26-2- Allod hald_dccm_t to create sock_files in /tmp
* Thu Jul 30 2009 Dan Walsh 3.6.26-1- More fixes from upstream
* Tue Jul 28 2009 Dan Walsh 3.6.25-1- Fix polkit label- Remove hidebrokensymptoms for nss_ldap fix- Add modemmanager policy- Lots of merges from upstream- Begin removing textrel_shlib_t labels, from fixed libraries
* Tue Jul 28 2009 Dan Walsh 3.6.24-1- Update to upstream
* Mon Jul 27 2009 Dan Walsh 3.6.23-2- Allow certmaster to override dac permissions
* Wed Jul 22 2009 Dan Walsh 3.6.23-1- Update to upstream
* Mon Jul 20 2009 Dan Walsh 3.6.22-3- Fix context for VirtualBox
* Tue Jul 14 2009 Dan Walsh 3.6.22-1- Update to upstream
* Fri Jul 10 2009 Dan Walsh 3.6.21-4- Allow clamscan read amavis spool files
* Wed Jul 08 2009 Dan Walsh 3.6.21-3- Fixes for xguest
* Tue Jul 07 2009 Tom \"spot\" Callaway 3.6.21-2- fix multiple directory ownership of mandirs
* Wed Jul 01 2009 Dan Walsh 3.6.21-1- Update to upstream
* Tue Jun 30 2009 Dan Walsh 3.6.20-2- Add rules for rtkit-daemon
* Thu Jun 25 2009 Dan Walsh 3.6.20-1- Update to upstream- Fix nlscd_stream_connect
* Thu Jun 25 2009 Dan Walsh 3.6.19-5- Add rtkit policy
* Wed Jun 24 2009 Dan Walsh 3.6.19-4- Allow rpcd_t to stream connect to rpcbind
* Tue Jun 23 2009 Dan Walsh 3.6.19-3- Allow kpropd to create tmp files
* Tue Jun 23 2009 Dan Walsh 3.6.19-2- Fix last duplicate /var/log/rpmpkgs
* Mon Jun 22 2009 Dan Walsh 3.6.19-1- Update to upstream
* add sssd
* Sat Jun 20 2009 Dan Walsh 3.6.18-1- Update to upstream
* cleanup
* Fri Jun 19 2009 Dan Walsh 3.6.17-1- Update to upstream- Additional mail ports- Add virt_use_usb boolean for svirt
* Thu Jun 18 2009 Dan Walsh 3.6.16-4- Fix mcs rules to include chr_file and blk_file
* Tue Jun 16 2009 Dan Walsh 3.6.16-3- Add label for udev-acl
* Mon Jun 15 2009 Dan Walsh 3.6.16-2- Additional rules for consolekit/udev, privoxy and various other fixes
* Fri Jun 12 2009 Dan Walsh 3.6.16-1- New version for upstream
* Thu Jun 11 2009 Dan Walsh 3.6.14-3- Allow NetworkManager to read inotifyfs
* Wed Jun 10 2009 Dan Walsh 3.6.14-2- Allow setroubleshoot to run mlocate
* Mon Jun 08 2009 Dan Walsh 3.6.14-1- Update to upstream
* Tue Jun 02 2009 Dan Walsh 3.6.13-3- Add fish as a shell- Allow fprintd to list usbfs_t- Allow consolekit to search mountpoints- Add proper labeling for shorewall
* Tue May 26 2009 Dan Walsh 3.6.13-2- New log file for vmware- Allow xdm to setattr on user_tmp_t
* Thu May 21 2009 Dan Walsh 3.6.13-1- Upgrade to upstream
* Wed May 20 2009 Dan Walsh 3.6.12-39- Allow fprintd to access sys_ptrace- Add sandbox policy
* Mon May 18 2009 Dan Walsh 3.6.12-38- Add varnishd policy
* Thu May 14 2009 Dan Walsh 3.6.12-37- Fixes for kpropd
* Tue May 12 2009 Dan Walsh 3.6.12-36- Allow brctl to r/w tun_tap_device_t
* Mon May 11 2009 Dan Walsh 3.6.12-35- Add /usr/share/selinux/packages
* Mon May 11 2009 Dan Walsh 3.6.12-34- Allow rpcd_t to send signals to kernel threads
* Thu May 07 2009 Dan Walsh 3.6.12-33- Fix upgrade for F10 to F11
* Thu May 07 2009 Dan Walsh 3.6.12-31- Add policy for /var/lib/fprint
* Tue May 05 2009 Dan Walsh 3.6.12-30-Remove duplicate line
* Tue May 05 2009 Dan Walsh 3.6.12-29- Allow svirt to manage pci and other sysfs device data
* Mon May 04 2009 Dan Walsh 3.6.12-28- Fix package selection handling
* Fri May 01 2009 Dan Walsh 3.6.12-27- Fix /sbin/ip6tables-save context- Allod udev to transition to mount- Fix loading of mls policy file
* Thu Apr 30 2009 Dan Walsh 3.6.12-26- Add shorewall policy
* Wed Apr 29 2009 Dan Walsh 3.6.12-25- Additional rules for fprintd and sssd
* Tue Apr 28 2009 Dan Walsh 3.6.12-24- Allow nsplugin to unix_read unix_write sem for unconfined_java
* Tue Apr 28 2009 Dan Walsh 3.6.12-23- Fix uml files to be owned by users
* Tue Apr 28 2009 Dan Walsh 3.6.12-22- Fix Upgrade path to install unconfineduser.pp when unocnfined package is 3.0.0 or less
* Mon Apr 27 2009 Dan Walsh 3.6.12-21- Allow confined users to manage virt_content_t, since this is home dir content- Allow all domains to read rpm_script_tmp_t which is what shell creates on redirection
* Mon Apr 27 2009 Dan Walsh 3.6.12-20- Fix labeling on /var/lib/misc/prelink
*- Allow xserver to rw_shm_perms with all x_clients- Allow prelink to execute files in the users home directory
* Fri Apr 24 2009 Dan Walsh 3.6.12-19- Allow initrc_t to delete dev_null- Allow readahead to configure auditing- Fix milter policy- Add /var/lib/readahead
* Fri Apr 24 2009 Dan Walsh 3.6.12-16- Update to latest milter code from Paul Howarth
* Thu Apr 23 2009 Dan Walsh 3.6.12-15- Additional perms for readahead
* Thu Apr 23 2009 Dan Walsh 3.6.12-14- Allow pulseaudio to acquire_svc on session bus- Fix readahead labeling
* Thu Apr 23 2009 Dan Walsh 3.6.12-13- Allow sysadm_t to run rpm directly- libvirt needs fowner
* Wed Apr 22 2009 Dan Walsh 3.6.12-12- Allow sshd to read var_lib symlinks for freenx
* Tue Apr 21 2009 Dan Walsh 3.6.12-11- Allow nsplugin unix_read and write on users shm and sem- Allow sysadm_t to execute su
* Tue Apr 21 2009 Dan Walsh 3.6.12-10- Dontaudit attempts to getattr user_tmpfs_t by lvm- Allow nfs to share removable media
* Mon Apr 20 2009 Dan Walsh 3.6.12-9- Add ability to run postdrop from confined users
* Sat Apr 18 2009 Dan Walsh 3.6.12-8- Fixes for podsleuth
* Fri Apr 17 2009 Dan Walsh 3.6.12-7- Turn off nsplugin transition- Remove Konsole leaked file descriptors for release
* Fri Apr 17 2009 Dan Walsh 3.6.12-6- Allow cupsd_t to create link files in print_spool_t- Fix iscsi_stream_connect typo- Fix labeling on /etc/acpi/actions- Don\'t reinstall unconfine and unconfineuser on upgrade if they are not installed
* Tue Apr 14 2009 Dan Walsh 3.6.12-5- Allow audioentroy to read etc files
* Mon Apr 13 2009 Dan Walsh 3.6.12-4- Add fail2ban_var_lib_t- Fixes for devicekit_power_t
* Thu Apr 09 2009 Dan Walsh 3.6.12-3- Separate out the ucnonfined user from the unconfined.pp package
* Tue Apr 07 2009 Dan Walsh 3.6.12-2- Make sure unconfined_java_t and unconfined_mono_t create user_tmpfs_t.
* Tue Apr 07 2009 Dan Walsh 3.6.12-1- Upgrade to latest upstream- Allow devicekit_disk sys_rawio
* Mon Apr 06 2009 Dan Walsh 3.6.11-1- Dontaudit binds to ports < 1024 for named- Upgrade to latest upstream
* Fri Apr 03 2009 Dan Walsh 3.6.10-9- Allow podsleuth to use tmpfs files
* Fri Apr 03 2009 Dan Walsh 3.6.10-8- Add customizable_types for svirt
* Fri Apr 03 2009 Dan Walsh 3.6.10-7- Allow setroubelshoot exec
* privs to prevent crash from bad libraries- add cpufreqselector
* Thu Apr 02 2009 Dan Walsh 3.6.10-6- Dontaudit listing of /root directory for cron system jobs
* Mon Mar 30 2009 Dan Walsh 3.6.10-5- Fix missing ld.so.cache label
* Fri Mar 27 2009 Dan Walsh 3.6.10-4- Add label for ~/.forward and /root/.forward
* Thu Mar 26 2009 Dan Walsh 3.6.10-3- Fixes for svirt
* Thu Mar 19 2009 Dan Walsh 3.6.10-2- Fixes to allow svirt read iso files in homedir
* Thu Mar 19 2009 Dan Walsh 3.6.10-1- Add xenner and wine fixes from mgrepl
* Wed Mar 18 2009 Dan Walsh 3.6.9-4- Allow mdadm to read/write mls override
* Tue Mar 17 2009 Dan Walsh 3.6.9-3- Change to svirt to only access svirt_image_t