diff --git a/policy-20070501.patch b/policy-20070501.patch index 1e2f8ab..19cdfb5 100644 --- a/policy-20070501.patch +++ b/policy-20070501.patch @@ -8626,7 +8626,7 @@ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/system/unconf ') diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/system/unconfined.if serefpolicy-2.6.4/policy/modules/system/unconfined.if --- nsaserefpolicy/policy/modules/system/unconfined.if 2007-05-07 14:51:02.000000000 -0400 -+++ serefpolicy-2.6.4/policy/modules/system/unconfined.if 2007-06-12 11:16:33.000000000 -0400 ++++ serefpolicy-2.6.4/policy/modules/system/unconfined.if 2007-06-14 10:40:13.000000000 -0400 @@ -18,7 +18,7 @@ ') @@ -8670,7 +8670,7 @@ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/system/unconf nscd_unconfined($1) ') -@@ -556,3 +559,22 @@ +@@ -556,3 +559,39 @@ allow $1 unconfined_t:dbus acquire_svc; ') @@ -8693,6 +8693,23 @@ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/system/unconf + allow $1 unconfined_t:process ptrace; +') + ++######################################## ++## ++## Write unconfined users temporary files. ++## ++## ++## ++## Domain allowed access. ++## ++## ++# ++interface(`unconfined_write_tmp_files',` ++ gen_require(` ++ type unconfined_tmp_t; ++ ') ++ ++ allow $1 unconfined_tmp_t:file { getattr write append }; ++') diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/system/unconfined.te serefpolicy-2.6.4/policy/modules/system/unconfined.te --- nsaserefpolicy/policy/modules/system/unconfined.te 2007-05-07 14:51:02.000000000 -0400 +++ serefpolicy-2.6.4/policy/modules/system/unconfined.te 2007-06-12 11:16:33.000000000 -0400 diff --git a/selinux-policy.spec b/selinux-policy.spec index 8f58592..fc31e77 100644 --- a/selinux-policy.spec +++ b/selinux-policy.spec @@ -17,7 +17,7 @@ Summary: SELinux policy configuration Name: selinux-policy Version: 2.6.4 -Release: 14%{?dist} +Release: 15%{?dist} License: GPL Group: System Environment/Base Source: serefpolicy-%{version}.tgz @@ -360,6 +360,9 @@ semodule -b base.pp -r bootloader -r clock -r dpkg -r fstools -r hotplug -r init %endif %changelog +* Wed Jun 6 2007 Dan Walsh 2.6.4-15 +- Allow udev to signal dhcpc + * Wed Jun 6 2007 Dan Walsh 2.6.4-14 - Allow locate to lookup uid/gid