diff --git a/policy-F12.patch b/policy-F12.patch index 3d71561..1af1cb3 100644 --- a/policy-F12.patch +++ b/policy-F12.patch @@ -17096,8 +17096,8 @@ diff -b -B --ignore-all-space --exclude-from=exclude -N -u -r nsaserefpolicy/pol +') diff -b -B --ignore-all-space --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/plymouth.te serefpolicy-3.6.32/policy/modules/services/plymouth.te --- nsaserefpolicy/policy/modules/services/plymouth.te 1969-12-31 19:00:00.000000000 -0500 -+++ serefpolicy-3.6.32/policy/modules/services/plymouth.te 2009-10-29 08:30:08.000000000 -0400 -@@ -0,0 +1,97 @@ ++++ serefpolicy-3.6.32/policy/modules/services/plymouth.te 2009-10-29 10:28:34.000000000 -0400 +@@ -0,0 +1,96 @@ +policy_module(plymouthd, 1.0.0) + +######################################## @@ -17149,7 +17149,6 @@ diff -b -B --ignore-all-space --exclude-from=exclude -N -u -r nsaserefpolicy/pol +dev_read_sysfs(plymouthd_t) +dev_read_framebuffer(plymouthd_t) +dev_write_framebuffer(plymouthd_t) -+dev_delete_null(plymouthd_t) + +domain_use_interactive_fds(plymouthd_t) + diff --git a/selinux-policy.spec b/selinux-policy.spec index 25d0725..76dc14c 100644 --- a/selinux-policy.spec +++ b/selinux-policy.spec @@ -20,7 +20,7 @@ Summary: SELinux policy configuration Name: selinux-policy Version: 3.6.32 -Release: 35%{?dist} +Release: 36%{?dist} License: GPLv2+ Group: System Environment/Base Source: serefpolicy-%{version}.tgz @@ -445,6 +445,22 @@ exit 0 %endif %changelog +* Thu Oct 29 2009 Dan Walsh 3.6.32-36 +- Change labeling of /usr/share/yumex/yumex-yum-backend +- Allow initrc_t to request loading kernel modules +- Allow initrc_t to manage net_conf_t files +- Allow prelink to manage tmp files for "delta rpm" +- Allow livecd tool to transition to chfn and passwd +- Allow cupsd to bind to howl port +- Allow plymouth to delete /dev/null +- dontaudit leaked userdomain sockets to xauth +- Allow lircd to use pseudo terminal device +- Allow sambagui to send syslog messages +- dontaudit chrome using nfs and samba file systems if they are used for the homedir +- Allow prelude-dispatch ipc_lock and setpcap +- Change lircd /var/run specification +- Define ports for dhcpcv6 + * Tue Oct 27 2009 Dan Walsh 3.6.32-35 - Allow bittlebee to connect to privoxy port - Allow iptables to work with shorewall