|
3
by Caleb Case
Basic refpolicy packaging. |
1 |
refpolicy (0.0.20071214-1ubuntu1) hardy; urgency=low |
2 |
||
3 |
* New upstream SVN HEAD. |
|
4 |
- Labeled networking peer object class updates. |
|
5 |
- Patch for debian logrotate to handle syslogd-listfiles, from Vaclav Ovsik. |
|
6 |
- Improve several tunables descriptions from Dan Walsh. |
|
7 |
- Patch to clean up ns switch usage in the policy from Dan Walsh. |
|
8 |
- More complete labeled networking infrastructure from KaiGai Kohei. |
|
9 |
- Add interface for libselinux constructor, for libselinux-linked |
|
10 |
SELinux-enabled programs. |
|
11 |
- Patch to restructure user role templates to create restricted user roles |
|
12 |
from Dan Walsh. |
|
13 |
- Russian man page translations from Andrey Markelov. |
|
14 |
- Remove unused types from dbus. |
|
15 |
- Add infrastructure for managing all user web content. |
|
16 |
- Deprecate some old file and dir permission set macros in favor of the |
|
17 |
newer, more consistently-named macros. |
|
18 |
- Patch to clean up unescaped periods in several file context entries from |
|
19 |
Jan-Frode Myklebust. |
|
20 |
- Merge shlib_t into lib_t. |
|
21 |
- Merge strict and targeted policies. The policy will now behave like the |
|
22 |
strict policy if the unconfined module is not present. If it is, it will |
|
23 |
behave like the targeted policy. Added an unconfined role to have a mix |
|
24 |
of confined and unconfined users. |
|
25 |
- Added modules: |
|
26 |
exim (Dan Walsh) |
|
27 |
postfixpolicyd (Jan-Frode Myklebust) |
|
28 |
- Add support for setting the unknown permissions handling. |
|
29 |
- Fix XML building for external reference builds and headers builds. |
|
30 |
- Patch to add missing requirements in userdomain interfaces from Shintaro |
|
31 |
Fujiwara. |
|
32 |
- Add tcpd_wrapped_domain() for services that use tcp wrappers. |
|
33 |
- Update MLS constraints from LSPP evaluated policy. |
|
34 |
- Allow initrc_t file descriptors to be inherited regardless of MLS level. |
|
35 |
Accordingly drop MLS permissions from daemons that inherit from any level. |
|
36 |
- Files and radvd updates from Stefan Schulze Frielinghaus. |
|
37 |
- Deprecate mls_file_write_down() and mls_file_read_up(), replaced with |
|
38 |
mls_write_all_levels() and mls_read_all_levels(), for consistency. |
|
39 |
- Add make kernel and init ranged interfaces pass the range transition MLS |
|
40 |
constraints. Also remove calls to mls_rangetrans_target() in modules that |
|
41 |
use the kernel and init interfaces, since its redundant. |
|
42 |
- Add interfaces for all MLS attributes except X object classes. |
|
43 |
- Require all sensitivities and categories for MLS and MCS policies, not just |
|
44 |
the low and high sensitivity and category. |
|
45 |
- Database userspace object manager classes from KaiGai Kohei. |
|
46 |
- Add third-party interface for Apache CGI. |
|
47 |
- Add getserv and shmemserv nscd permissions. |
|
48 |
- Add debian apcupsd binary location, from Stefan Schulze Frielinghaus. |
|
49 |
- Added modules: |
|
50 |
application
|
|
51 |
awstats (Stefan Schulze Frielinghaus) |
|
52 |
bitlbee (Devin Carraway) |
|
53 |
brctl (Dan Walsh) |
|
54 |
- Fix incorrectly named files_lib_filetrans_shared_lib() interface in the |
|
55 |
libraries module. |
|
56 |
- Unified labeled networking policy from Paul Moore. |
|
57 |
- Use netmsg initial SID for MLS-only Netlabel packets, from Paul Moore. |
|
58 |
- Xen updates from Dan Walsh. |
|
59 |
- Filesystem updates from Dan Walsh. |
|
60 |
- Large samba update from Dan Walsh. |
|
61 |
- Drop snmpd_etc_t. |
|
62 |
- Confine sendmail and logrotate on targeted. |
|
63 |
- Tunable connection to postgresql for users from KaiGai Kohei. |
|
64 |
- Memprotect support patch from Stephen Smalley. |
|
65 |
- Add logging_send_audit_msgs() interface and deprecate |
|
66 |
send_audit_msgs_pattern(). |
|
67 |
- Openct updates patch from Dan Walsh. |
|
68 |
- Merge restorecon into setfiles. |
|
69 |
- Patch to begin separating out hald helper programs from Dan Walsh. |
|
70 |
- Fixes for squid, dovecot, and snmp from Dan Walsh. |
|
71 |
- Miscellaneous consolekit fixes from Dan Walsh. |
|
72 |
- Patch to have avahi use the nsswitch interface rather than individual |
|
73 |
permissions from Dan Walsh. |
|
74 |
- Patch to dontaudit logrotate searching avahi pid directory from Dan Walsh. |
|
75 |
- Patch to allow insmod to mount kvmfs and dontaudit rw unconfined_t pipes |
|
76 |
to handle usage from userhelper from Dan Walsh. |
|
77 |
- Patch to allow amavis to read spamassassin libraries from Dan Walsh. |
|
78 |
- Patch to allow slocate to getattr other filesystems and directories on those |
|
79 |
filesystems from Dan Walsh. |
|
80 |
- Fixes for RHEL4 from the CLIP project. |
|
81 |
- Replace the old lrrd fc entries with munin ones. |
|
82 |
- Move program admin template usage out of userdom_admin_user_template() to |
|
83 |
sysadm policy in userdomain.te to fix usage of the template for third |
|
84 |
parties. |
|
85 |
- Fix clockspeed_run_cli() declaration, it was incorrectly defined as a |
|
86 |
template instead of an interface. |
|
87 |
- Added modules: |
|
88 |
amtu (Dan Walsh) |
|
89 |
apcupsd (Dan Walsh) |
|
90 |
rpcbind (Dan Walsh) |
|
91 |
rwho (Nalin Dahyabhai) |
|
92 |
||
93 |
-- Caleb Case <calebcase@gmail.com> Tue, 15 Jan 2008 21:55:52 -0500 |
|
94 |
||
95 |
refpolicy (0.0.20070507-5) unstable; urgency=low |
|
96 |
||
97 |
* Allow users to read the dpkg database. With this change, every user |
|
98 |
of the strict policy now has access to dpkg-checkbuildeps, grep-dctrl, |
|
99 |
etc, which was not the case previously. |
|
100 |
* Change the example localStrict.te policy file to silently ignore apt |
|
101 |
searching for something in /var/lib. With this example policy loaded |
|
102 |
in my strict policy UML virtual machine, I can compile packages in |
|
103 |
enforcing mode. Based on advice on the mailing list, allow more things |
|
104 |
to access /selinux |
|
105 |
* Merge in changes from Russell Coker. These include a better fix for |
|
106 |
/lib.init/rw. |
|
107 |
||
108 |
-- Manoj Srivastava <srivasta@debian.org> Fri, 18 May 2007 00:34:07 -0500 |
|
109 |
||
110 |
refpolicy (0.0.20070507-4) unstable; urgency=low |
|
111 |
||
112 |
* Allow apt to run update by giving r_netlink_socket_perms to |
|
113 |
self:netlink_route_socket. |
|
114 |
* Allow apt/aptitude to update, and install files |
|
115 |
- Added an interface to apt.if allow silently ignoring processes that |
|
116 |
attempt to use file descriptors from apt. |
|
117 |
- Bump the apt policy module version number, since we have added to |
|
118 |
the interface. |
|
119 |
- Added some stuff to dpkg.te to allow debconf .config file |
|
120 |
interactions back to the user |
|
121 |
- Add an optional dontaudit rule to libraries.te to allow |
|
122 |
apt-get/aptitude to install packages silently. |
|
123 |
* Very early in boot, /lib/init/rw is created as a mandatory tmpfs for |
|
124 |
state information. Label that directory as initrc_tmp_t to allow |
|
125 |
mount.te to be permitted to mount a tmpfs there. |
|
126 |
* In init.te, allow /etc/network/if-up.d/mountnfs to create |
|
127 |
/var/run/network/mountnfs as a poor mans lock. |
|
128 |
||
129 |
-- Manoj Srivastava <srivasta@debian.org> Fri, 11 May 2007 00:55:07 -0500 |
|
130 |
||
131 |
refpolicy (0.0.20070507-3) unstable; urgency=low |
|
132 |
||
133 |
* Add hostfs as a recognized remote file-system. This should allow a |
|
134 |
UML virtual machine to function in a fully enforcing mode. |
|
135 |
||
136 |
-- Manoj Srivastava <srivasta@debian.org> Wed, 9 May 2007 15:48:26 -0500 |
|
137 |
||
138 |
refpolicy (0.0.20070507-2) unstable; urgency=medium |
|
139 |
||
140 |
* Keep track of modules that are really built into the base policy in |
|
141 |
Debian. We then use this list to remove the modules .pp files from |
|
142 |
the policy shipped, since they can not be installed along with the |
|
143 |
base policy anyway. Make sure we don't add such modules hen |
|
144 |
considering module dependencies either. |
|
145 |
* Added Module ricci to modules.conf for both strict and targeted. |
|
146 |
||
147 |
-- Manoj Srivastava <srivasta@debian.org> Mon, 7 May 2007 09:07:36 -0500 |
|
148 |
||
149 |
refpolicy (0.0.20070507-1) unstable; urgency=low |
|
150 |
||
151 |
* New upstream SVN HEAD. |
|
152 |
- Miscellaneous consolekit fixes from Dan Walsh. |
|
153 |
- Patch to have avahi use the nsswitch interface rather than individual |
|
154 |
permissions from Dan Walsh. |
|
155 |
- Patch to dontaudit logrotate searching avahi pid directory from Dan |
|
156 |
Walsh. |
|
157 |
- Patch to allow insmod to mount kvmfs and dontaudit rw unconfined_t |
|
158 |
pipes to handle usage from userhelper from Dan Walsh. |
|
159 |
- Patch to allow amavis to read spamassassin libraries from Dan Walsh. |
|
160 |
- Patch to allow slocate to getattr other filesystems and directories |
|
161 |
on those filesystems from Dan Walsh. |
|
162 |
- Fixes for RHEL4 from the CLIP project. |
|
163 |
- Replace the old lrrd fc entries with munin ones. |
|
164 |
- Move program admin template usage out of |
|
165 |
userdom_admin_user_template() to sysadm policy in userdomain.te to |
|
166 |
fix usage of the template for third parties. |
|
167 |
- Fix clockspeed_run_cli() declaration, it was incorrectly defined as a |
|
168 |
template instead of an interface. |
|
169 |
- Added modules: rwho (Nalin Dahyabhai) |
|
170 |
* Updated dependencies, since this refpolicy needs newer toolchain, |
|
171 |
||
172 |
-- Manoj Srivastava <srivasta@debian.org> Mon, 7 May 2007 01:47:44 -0500 |
|
173 |
||
174 |
refpolicy (0.0.20070417-1) unstable; urgency=low |
|
175 |
||
176 |
* New upstream release. |
|
177 |
* Added XS-VCS-Arch and XS-VCS-Browse to debian/control, and updated |
|
178 |
build dependencies. |
|
179 |
* Bug fix: "selinux-policy-refpolicy-targeted: need file_contexts for |
|
180 |
gcj-dbtool-4.1 and /var/log/account", thanks to Russell Coker |
|
181 |
(Closes: #416910). |
|
182 |
||
183 |
-- Manoj Srivastava <srivasta@debian.org> Thu, 19 Apr 2007 02:28:29 -0500 |
|
184 |
||
185 |
refpolicy (0.0.20061018-5) unstable; urgency=high |
|
186 |
||
187 |
* Add policy for log and lock files for aptitude. This is needed for |
|
188 |
proper function; so one does not need to go into permissive mode to |
|
189 |
run aptitude. Stolen from Erich. This is a low risk change. |
|
190 |
* Debian puts grub in /usr/sbin/grub. Reflect that in the initial file |
|
191 |
context. |
|
192 |
* Debian creates /dev/xconsole independently of whether or not a xserver |
|
193 |
has been installed or not. So move the policy related to /dev/sconsole |
|
194 |
out of the xserver policy, and into places where relevant (init.te, |
|
195 |
logging.fc), to reflect the status that /dev/console is present |
|
196 |
anyway. |
|
197 |
* Add support for /etc/network/run and /dev/shm/network, which seem to |
|
198 |
be Debian specific as well. |
|
199 |
* Allow udev to manage configuration files. |
|
200 |
||
201 |
-- Manoj Srivastava <srivasta@debian.org> Fri, 9 Mar 2007 00:22:19 -0600 |
|
202 |
||
203 |
refpolicy (0.0.20061018-4) unstable; urgency=low |
|
204 |
||
205 |
* Bug fix: "selinux-policy-refpolicy-targeted: does not suggest a way to |
|
206 |
fix the 'maybe failing' attempt in postinst", thanks to Eddy Petrisor. |
|
207 |
While this does not belong in the postinst, I have addedthis to the |
|
208 |
README.Debian file. This should be a low risk change. (Closes: #407691). |
|
209 |
* Bug fix: "Default build.conf doesn't match default strict/targeted |
|
210 |
policy", thanks to Stefan.The build.conf included in the reference |
|
211 |
source policy describe to build a policy of the type "strict". The |
|
212 |
default binary policies coming with Debian are build with the policy |
|
213 |
type "strict-mcs" or "targeted-mcs". Change the build.conf shipped in |
|
214 |
source to conform to what we really use. (changes TYPE=strict to |
|
215 |
TYPE=strict-mcs, very low risk change. (Closes: #411256). |
|
216 |
* Bug fix: "selinux-policy-refpolicy-targeted: openvpn policy do not |
|
217 |
allow tcp connection mode", thanks to Rafal Kupka. This bug really |
|
218 |
should be at least important, and we should fully support a class of |
|
219 |
security product like OpenVPN on machines which are running SELinux, |
|
220 |
and this is a very low risk change. (Closes: #409041). |
|
221 |
* Install header files required for policy building for both strict and |
|
222 |
targeted policies in a new -dev package, so it becomes really useful |
|
223 |
to work with the source package. Moved the examples from the -src |
|
224 |
package to this new -dev package, since the example is only useful in |
|
225 |
with the headers provided. This is a new package, but it contains only |
|
226 |
files already in the sources (No upstream changes at all), and is the |
|
227 |
result of make install-headers. This new package has no rdepends, and |
|
228 |
should be a very low risk addition to Debian. |
|
229 |
* This release should be a whole lot better for building local policies, |
|
230 |
including the policygentool for creating a new policy from scratch, |
|
231 |
and ability to build local policy modular packages. The build.conf |
|
232 |
files have been cleaned up, and the source policy defaults to targeted |
|
233 |
policy, which is standard in Debian, as opposed to the strict policy, |
|
234 |
which has priority optional. |
|
235 |
||
236 |
-- Manoj Srivastava <srivasta@debian.org> Mon, 26 Feb 2007 22:37:17 -0600 |
|
237 |
||
238 |
refpolicy (0.0.20061018-3) unstable; urgency=high |
|
239 |
||
240 |
* Bug fix: "refpolicy: FTBFS: /bin/sh: debian/stamp/config-strict: No |
|
241 |
such file or directory", thanks to Lucas Nussbaum. This was fixed by |
|
242 |
moving all the stamps into ./debian instead. I'll re-visit the |
|
243 |
./debian/stamp/ directory in lenny. This is a pretty minor packaging |
|
244 |
change. (Closes: #405613). |
|
245 |
* Bug fix: "selinux-policy-refpolicy-targeted: Policy for dcc misses |
|
246 |
Debian's FHS paths", thanks to Devin Carraway. From the bug report: |
|
247 |
Many of the files in these packages are overlooked when labelling |
|
248 |
files, because refpolicy's dcc module stipulates paths not consistent |
|
249 |
with the Debian FHS layout. The files go unlabelled and dcc-client |
|
250 |
(at least) stops working. The two major problems are the references |
|
251 |
to /usr/libexec/dcc (damons, placed in /usr/sbin by the Debian |
|
252 |
packages) and to /var/dcc (all sorts of things, placed under |
|
253 |
/var/lib/dcc). A side effect of the latter is that dccifd_t and |
|
254 |
probably others need search on var_lib_t, through which it must pass |
|
255 |
to get to /var/lib/dcc. Fixed the policy; will send upstream. |
|
256 |
(Closes: #404309). |
|
257 |
* Bug fix: "selinux-policy-refpolicy-targeted: clamav policy forbids |
|
258 |
clamd_t search on /var/lib", thanks to Devin Carraway. This is a |
|
259 |
simple one line change, and obviously an oversight; I think getting |
|
260 |
clamd to work is fairly important. (Closes: #404895). |
|
261 |
* Bug fix: "selinux-policy-refpolicy-targeted: Multiple problems with |
|
262 |
courier policy", thanks to Devin Carraway. There is detailed |
|
263 |
information of the changes made in the bug report, and in the commit |
|
264 |
logs. Again, fixing courier daemons seems pretty important; SELinux |
|
265 |
tends to get used a lot on remote mail servers, and this fixes issues |
|
266 |
with the policy. (Closes: #405103). |
|
267 |
||
268 |
-- Manoj Srivastava <srivasta@debian.org> Mon, 15 Jan 2007 13:20:30 -0600 |
|
269 |
||
270 |
refpolicy (0.0.20061018-2) unstable; urgency=high |
|
271 |
||
272 |
* The This update enables MCS for targeted and strict, uses 1024 |
|
273 |
categories (as Fedora uses - necessary for compatability). Please note |
|
274 |
that enabling MCS categories is required for compatibility with |
|
275 |
filesystems created on Fedora Core 5 and above, RHEL 5 and above, and |
|
276 |
CentOS 5 and above. MCS categories is also a feature that we plan for |
|
277 |
all future releases of SE Linux and does not have a nice upgrade path |
|
278 |
- releasing etch without MCS will make things painful for SE Linux |
|
279 |
users on the upgrade to lenny. This feature has been extensively |
|
280 |
tested by Russel Coker and myself, and does not otherwise impact the |
|
281 |
install. |
|
282 |
* Allow semanage to use the initrd file descriptor in targeted policy. |
|
283 |
* Fix a bug with restorecon. |
|
284 |
* Bug fix: "refpolicy: qemu should have execmem permissions", thanks to |
|
285 |
David Härdeman (Closes: #402293). |
|
286 |
||
287 |
-- Manoj Srivastava <srivasta@debian.org> Fri, 22 Dec 2006 10:33:22 -0600 |
|
288 |
||
289 |
refpolicy (0.0.20061018-1) unstable; urgency=low |
|
290 |
||
291 |
* New upstream release |
|
292 |
* Updated copyright file with the new location of the sources, and added |
|
293 |
a watch file. |
|
294 |
* Bug fix: "selinux-policy-refpolicy-targeted: postinst package list |
|
295 |
retrieval suggestion", thanks to Alexander Buerger. Thanks to the |
|
296 |
provided suggestion, the selection of policy modules to install is not |
|
297 |
only faster, it is actually correct :) (Closes: #388744). |
|
298 |
* Bug fix: "Makefile for building policy modules?", thanks to Uwe |
|
299 |
Hermann. Provided an intial version, may have bugs. (Closes: #389116). |
|
300 |
||
301 |
-- Manoj Srivastava <srivasta@debian.org> Tue, 24 Oct 2006 14:31:22 -0500 |
|
302 |
||
303 |
refpolicy (0.0.20060911-2) unstable; urgency=low |
|
304 |
||
305 |
* Fixed a typo in policy postinst that made all the policies reload at |
|
306 |
every update. |
|
307 |
||
308 |
-- Manoj Srivastava <srivasta@debian.org> Tue, 12 Sep 2006 10:28:11 -0500 |
|
309 |
||
310 |
refpolicy (0.0.20060911-1) unstable; urgency=low |
|
311 |
||
312 |
* New upstream SCM HEAD. |
|
313 |
* Synched with Erich Schubert <erich@debian.org> |
|
314 |
+ Added first draft of python-support. You'll want to relabel these files. |
|
315 |
+ Build python-support and setroubleshoot modules |
|
316 |
+ Removed modules from guessing hintfile that are included in base. |
|
317 |
||
318 |
* Bug fix: "Defaults should match the strict/targeted policy", thanks to |
|
319 |
Uwe Hermann. Makde them match strict. (Closes: #386931). |
|
320 |
* Bug fix: "selinux-policy-refpolicy-src: Duplicate entries in policy |
|
321 |
files", thanks to Simon Richard Grint (Closes: #386909). |
|
322 |
* Bug fix: "modules.conf vs. modules.conf.dist", thanks to Uwe Hermann |
|
323 |
(Closes: #386887). |
|
324 |
* Bug fix: "OUTPUT_POLICY and policy-version comments", thanks to Uwe |
|
325 |
Hermann (Closes: #386930). |
|
326 |
* Bug fix: "s/bzip2/gzip/?", thanks to Uwe Hermann (Closes: #386885). |
|
327 |
* Bug fix: "selinux-refpolicy-src: include modules.conf files of strict |
|
328 |
and targeted for -src package", thanks to Erich Schubert |
|
329 |
(Closes: #386573). |
|
330 |
||
331 |
-- Manoj Srivastava <srivasta@debian.org> Mon, 11 Sep 2006 17:46:10 -0500 |
|
332 |
||
333 |
refpolicy (0.0.20060907-3) unstable; urgency=low |
|
334 |
||
335 |
* Updated a few more policy modules to latest versions for Debian. |
|
336 |
||
337 |
-- Manoj Srivastava <srivasta@debian.org> Fri, 8 Sep 2006 12:42:22 -0500 |
|
338 |
||
339 |
refpolicy (0.0.20060907-2) unstable; urgency=low |
|
340 |
||
341 |
* Update the module/package mapping. |
|
342 |
* In the selinux-policy-refpolicy-src package, now ship the |
|
343 |
modules.conf.strict and the modules.conf.targeted files which are used |
|
344 |
to build the corresponding policy packages, snce the raw modules.conf |
|
345 |
package has issues on Debian. |
|
346 |
* With this version, we no longer ship the selinux-policy-refpolicy-src |
|
347 |
unpacked into /etc with a gazillion conffiles; instead, we now ship a |
|
348 |
compressed tarball in /usr/src, which the user may unpack where they |
|
349 |
wish, and install policies as they wish. |
|
350 |
||
351 |
-- Manoj Srivastava <srivasta@debian.org> Fri, 8 Sep 2006 10:49:40 -0500 |
|
352 |
||
353 |
refpolicy (0.0.20060907-1) unstable; urgency=low |
|
354 |
||
355 |
* New upstream SCM HEAD. |
|
356 |
* Bug fix: "selinux-policy-refpolicy-src: Compile failure of modular |
|
357 |
targeted policy", thanks to Simon Richard Grint. Put a wrapper around |
|
358 |
the offending lines to only take effect when running a strict policy. |
|
359 |
(Closes: #384502). |
|
360 |
* Bug fix: "make: /usr/sbin/setfiles: Command not found", thanks to Uwe |
|
361 |
Hermann. Fixed upstream. (Closes: #384850). |
|
362 |
||
363 |
-- Manoj Srivastava <srivasta@debian.org> Fri, 8 Sep 2006 00:27:39 -0500 |
|
364 |
||
365 |
refpolicy (0.0.20060813-2) unstable; urgency=low |
|
366 |
||
367 |
* Bug fix: "Needs gawk", thanks to Simon Richard Grint |
|
368 |
(Closes: #382821). |
|
369 |
* Bug fix: "Move /etc/selinux/refpolicy/src/policy/man/man8/* |
|
370 |
manpages?", thanks to Uwe Hermann (Closes: #372789). |
|
371 |
* Fix errors in post installation initial policy creation process in the |
|
372 |
postinst. |
|
373 |
* Add directories required during policy build during postinst. This bug |
|
374 |
prevented any policies being built when the package was initially |
|
375 |
installed. Also, create an empty file_contexts.local file if it does |
|
376 |
not already exist. |
|
377 |
* Make selinux-policy-refpolicy-targeted provide and replace the |
|
378 |
obsolete package selinux-policy-default; which should in the future be |
|
379 |
just a virtual package. |
|
380 |
* Added postrm packages to strict and targeted policy packages, in order |
|
381 |
to clean out the directories in which files are created during policy |
|
382 |
build. |
|
383 |
* Rewrote the postinst in perl to allow us to do module dependency |
|
384 |
checks, and to map policy modules to debian packages, in order to |
|
385 |
better detect the modules that would be necessary for the target |
|
386 |
machine. |
|
387 |
* Also, compiling with either MCS or MLS produced errors while |
|
388 |
installing policy, since we lack setrans daemon. So we are now |
|
389 |
building with out them, created an easy to modify option to re-enable |
|
390 |
it later. |
|
391 |
* Updated modules.conf to use the latest offerings from Erich. |
|
392 |
||
393 |
-- Manoj Srivastava <srivasta@debian.org> Mon, 21 Aug 2006 14:59:52 -0500 |
|
394 |
||
395 |
refpolicy (0.0.20060813-1) unstable; urgency=low |
|
396 |
||
397 |
* New upstream SCM HEAD. |
|
398 |
* Bug fix: "refpolicy: FTBFS: tmp/generated_definitions.conf:597:ERROR |
|
399 |
'syntax error' at token '' on line 3416:", thanks to Andreas Jochens |
|
400 |
(Closes: #379559). |
|
401 |
* Bug fix: "FTBFS while generating selinux-policy-refpolicy-strict", |
|
402 |
thanks to Devin Carraway (Closes: #379376). |
|
403 |
* Python transition (#2): you are building a private python module. |
|
404 |
(Closes: #380930). |
|
405 |
||
406 |
-- Manoj Srivastava <srivasta@debian.org> Tue, 15 Aug 2006 09:53:06 -0500 |
|
407 |
||
408 |
refpolicy (0.0.20060509-2) unstable; urgency=low |
|
409 |
||
410 |
* Modified some paths to be more in line with upstream standards. |
|
411 |
||
412 |
-- Manoj Srivastava <srivasta@debian.org> Fri, 12 May 2006 08:30:08 -0500 |
|
413 |
||
414 |
refpolicy (0.0.20060509-1) unstable; urgency=low |
|
415 |
||
416 |
* New upstream release. First packaging for Sid. |
|
417 |
||
418 |
-- Manoj Srivastava <srivasta@debian.org> Tue, 9 May 2006 13:56:10 -0500 |
|
419 |
||
420 |
refpolicy (20060506-1) sesarge; urgency=low |
|
421 |
||
422 |
* New upstream checkout from CVS. |
|
423 |
* Even more new modules. |
|
424 |
||
425 |
-- Erich Schubert <erich@debian.org> Sat, 6 May 2006 21:44:07 +0200 |
|
426 |
||
427 |
refpolicy (20060418-2) sesarge; urgency=low |
|
428 |
||
429 |
* New upstream checkout from CVS. |
|
430 |
||
431 |
-- Erich Schubert <erich@debian.org> Fri, 21 Apr 2006 19:17:05 +0200 |
|
432 |
||
433 |
refpolicy (20060417-1) sesarge; urgency=low |
|
434 |
||
435 |
* New upstream checkout from CVS. |
|
436 |
* Until module linking is fixed, build everything into base. |
|
437 |
(Sorry, this will result in a much larger policy than necessary. |
|
438 |
Feel free to use the -src package to build your own!) |
|
439 |
||
440 |
-- Erich Schubert <erich@debian.org> Mon, 17 Apr 2006 21:04:49 +0200 |
|
441 |
||
442 |
refpolicy (20060414-1) sesarge; urgency=low |
|
443 |
||
444 |
* New upstream version with tons of new policy files |
|
445 |
||
446 |
-- Erich Schubert <erich@debian.org> Mon, 17 Apr 2006 20:48:50 +0200 |
|
447 |
||
448 |
refpolicy (20060329-2) sesarge; urgency=low |
|
449 |
||
450 |
* Merge upstream 20060329-2 |
|
451 |
||
452 |
-- Erich Schubert <erich@debian.org> Mon, 3 Apr 2006 00:44:06 +0200 |
|
453 |
||
454 |
refpolicy (20060324-2) sesarge; urgency=low |
|
455 |
||
456 |
* Merge upstream 20060324-4 |
|
457 |
||
458 |
-- Erich Schubert <erich@debian.org> Sat, 25 Mar 2006 03:34:36 +0100 |
|
459 |
||
460 |
refpolicy (20060324-1) sesarge; urgency=low |
|
461 |
||
462 |
* Merge upstream 20060323-2 |
|
463 |
* Merge changes by Thomas Bleher |
|
464 |
* Build with checkpolicy 1.30.1 |
|
465 |
* Sorry, still doesn't work with make > 3.80 |
|
466 |
||
467 |
-- Erich Schubert <erich@debian.org> Sat, 25 Mar 2006 02:21:00 +0100 |
|
468 |
||
469 |
refpolicy (20060315-2) sesarge; urgency=low |
|
470 |
||
471 |
* Make modular policy actually work. Hopefully. |
|
472 |
(Up to now, optional_policy(`module') in base was not working upstream!) |
|
473 |
* Revamp build process, don't use CDBS anymore since I didn't figure out |
|
474 |
how to do two clean runs of the same source tree, and there is little |
|
475 |
benefit here without any autotools or library magic needed |
|
476 |
||
477 |
-- Erich Schubert <erich@debian.org> Fri, 17 Mar 2006 20:51:55 +0100 |
|
478 |
||
479 |
refpolicy (20060315-1.1) sesarge; urgency=low |
|
480 |
||
481 |
* Small tweaks and bugfixes to policy |
|
482 |
||
483 |
-- Erich Schubert <erich@debian.org> Thu, 16 Mar 2006 23:13:40 +0100 |
|
484 |
||
485 |
refpolicy (20060315-1) sesarge; urgency=low |
|
486 |
||
487 |
* Merge with upstream and debian changes as of 20060309, rev 50 |
|
488 |
* Merge with upstream and debian changes as of 20060315, rev 55 |
|
489 |
* Added "netuser" role, similar to user_tcp_server boolean, but |
|
490 |
you can enable it for single users only. |
|
491 |
||
492 |
-- Erich Schubert <erich@debian.org> Thu, 16 Mar 2006 00:23:54 +0100 |
|
493 |
||
494 |
refpolicy (20060306-1) sesarge; urgency=low |
|
495 |
||
496 |
* Merge with upstream and debian policy changes as of 20060306, Rev 31 |
|
497 |
* Try to auto-build a policy after a fresh install in postinst |
|
498 |
* Add inetd module to base for now |
|
499 |
* Increase policycoreutils build-dep to hopefully solve the users_extra |
|
500 |
issues by using a newer policycoreutils for building... |
|
501 |
||
502 |
-- Erich Schubert <erich@debian.org> Mon, 6 Mar 2006 17:10:43 +0100 |
|
503 |
||
504 |
refpolicy (20060227-1) sesarge; urgency=low |
|
505 |
||
506 |
* Merge with upstream and debian policy changes as of 20060227, Rev 20 |
|
507 |
||
508 |
-- Erich Schubert <erich@debian.org> Tue, 28 Feb 2006 03:48:48 +0100 |
|
509 |
||
510 |
refpolicy (20060224-2) sesarge; urgency=low |
|
511 |
||
512 |
* Update build process to not require a tarball, include previous |
|
513 |
patches into our "branch" of the reference policy instead. |
|
514 |
||
515 |
-- Erich Schubert <erich@debian.org> Tue, 28 Feb 2006 03:13:51 +0100 |
|
516 |
||
517 |
refpolicy (20060224-1) sesarge; urgency=low |
|
518 |
||
519 |
* New upstream CVS checkout. |
|
520 |
* Move policy src from /etc to /usr/share/selinux/refpolicy |
|
521 |
This avoids an apt-get size limitation and follows Fedora. |
|
522 |
* Ship edited build.conf with policy source. |
|
523 |
* Use debhelper for installing documentation. |
|
524 |
* Add dependency for source onto gawk. |
|
525 |
||
526 |
-- Erich Schubert <erich@debian.org> Sat, 25 Feb 2006 01:01:44 +0100 |
|
527 |
||
528 |
refpolicy (20060222-1) sesarge; urgency=low |
|
529 |
||
530 |
* New upstream CVS checkout. |
|
531 |
* Thomas also provided a workaround for the make issues in his version. |
|
532 |
* Update dpkg/apt policy to interface renamings |
|
533 |
* Remove dpkg_script_exec_t, as supporting this would require bad hacks |
|
534 |
to dpkg and/or tar. Use dpkg_var_lib_t instead. |
|
535 |
||
536 |
-- Erich Schubert <erich@debian.org> Thu, 23 Feb 2006 02:01:35 +0100 |
|
537 |
||
538 |
refpolicy (20060217-3) sesarge; urgency=low |
|
539 |
||
540 |
* Create selinux-policy-refpolicy-doc package |
|
541 |
* DIRECT_INITRC=y |
|
542 |
||
543 |
-- Thomas Bleher <ThomasBleher@gmx.de> Mon, 20 Feb 2006 23:43:53 +0000 |
|
544 |
||
545 |
refpolicy (20060217-2) sesarge; urgency=low |
|
546 |
||
547 |
* Added first drafts of dpkg, apt policy |
|
548 |
||
549 |
-- Erich Schubert <erich@debian.org> Sat, 18 Feb 2006 03:20:59 +0100 |
|
550 |
||
551 |
refpolicy (20060217-1) sesarge; urgency=low |
|
552 |
||
553 |
* New upstream CVS checkout |
|
554 |
* Document make incompaibility via build-dep |
|
555 |
* Don't build some redhat specific policy modules, minor tweaks |
|
556 |
||
557 |
-- Erich Schubert <erich@debian.org> Tue, 14 Feb 2006 02:35:04 +0100 |
|
558 |
||
559 |
refpolicy (20060213-1) sesarge; urgency=low |
|
560 |
||
561 |
* New upstream CVS checkout. |
|
562 |
* Still not really useable |
|
563 |
||
564 |
-- Erich Schubert <erich@debian.org> Tue, 14 Feb 2006 02:35:04 +0100 |
|
565 |
||
566 |
refpolicy (20060117-1) sesarge; urgency=low |
|
567 |
||
568 |
* Experimental release |
|
569 |
||
570 |
-- Erich Schubert <erich@debian.org> Mon, 13 Feb 2006 22:50:03 +0100 |
|
|
1
by Caleb Case
Initial import |
571 |