refpolicy 2:2.20140421-3 source package in Ubuntu

Changelog

refpolicy (2:2.20140421-3) unstable; urgency=medium


  * Allow sysadm_t to read policy
  * Make systemd_login_list_pid_dirs() call init_search_pid_dirs() as it
    doesn't work without it
  * Added chromium/google-chrome policy
  * dev_getattr_sysfs(sysstat_t) for Debian cron job
  * Allow sysstat_t to manage it's log files
  * Allow dpkg_script_t to config all systemd services and get init status
  * Allow dpkg_script_t to dirmngr_admin
  * really added systemd_login_list_pid_dirs(system_dbusd_t) (somehow missed
    this last time)
  * Allow sshd to chat with systemd via dbus
  * Allow unconfined_t to restart services
  * systemd_write_inherited_logind_sessions_pipes(system_dbusd_t)
  * systemd_dbus_chat_logind(sshd_t)
  * Allow xend to read vm sysctls
  * Allow udev_t to manage xenfs_t files for xenstore-read
  * Allow system_dbusd_t systemd_login_read_pid_files access for
    /run/systemd/users/* files
  * Allow systemd_logind_t to stat tmpfs_t filesystems for /run/user
  * Remove the "genfscon selinuxfs" line from selinux.if in selinux-policy-dev
    to stop sepolgen-ifgen errors.
  * Make udev_relabelto_db() include lnk_file relabeling
  * Allow kernel_t to fs_search_tmpfs, selinux_compute_create_context, and
    kernel_read_unlabeled_state for booting without unconfined.pp
  * Allow system_cronjob_t to manage the apt cache
  * Allow modutils_read_module_config(init_t) and create cgroup_t links for
    strict config. Allow it to relabel from tmpfs_t symlinks
  * Allow init_run_all_scripts_domain (initrc_t) the service { status start
    stop } for all the daemon _initrc_exec_t scripts.
  * Allow sysadm_r to have domain system_mail_t for strict policy
  * Allow init_t to relabel device_t symlinks and pstore_t dirs, load kernel
    modules, manage init_var_run_t sock_files, read /usr, read /dev/urandom,
    systemd_manage_passwd_run, and domain_read_all_domains_state

 -- Russell Coker <email address hidden>  Sun, 29 Jun 2014 19:11:45 +1000

Upload details

Uploaded by:
Debian SELinux maintainers
Uploaded to:
Sid
Original maintainer:
Debian SELinux maintainers
Architectures:
all
Section:
admin
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Utopic: [FULLYBUILT] i386

Downloads

File Size SHA-256 Checksum
refpolicy_2.20140421-3.dsc 1.7 KiB 2b524f9a889bb3acf335296ff1fccf26b3210aa388a7a5a92fde41d1dd41dcfa
refpolicy_2.20140421.orig.tar.bz2 668.3 KiB 258ff813c84139175db63958ac8bff2bcce32982bb0d902e06aaaf17dd644367
refpolicy_2.20140421-3.debian.tar.xz 69.5 KiB 8abada0a0291e7ecb539e1b8b3197a43705e28e879898950c8f13ede403ff130

Available diffs

No changes file available.

Binary packages built by this source

selinux-policy-default: No summary available for selinux-policy-default in ubuntu utopic.

No description available for selinux-policy-default in ubuntu utopic.

selinux-policy-dev: No summary available for selinux-policy-dev in ubuntu utopic.

No description available for selinux-policy-dev in ubuntu utopic.

selinux-policy-doc: No summary available for selinux-policy-doc in ubuntu utopic.

No description available for selinux-policy-doc in ubuntu utopic.

selinux-policy-mls: No summary available for selinux-policy-mls in ubuntu utopic.

No description available for selinux-policy-mls in ubuntu utopic.

selinux-policy-src: No summary available for selinux-policy-src in ubuntu utopic.

No description available for selinux-policy-src in ubuntu utopic.