~calebcase/+junk/selinux-support

3 by Caleb Case
Basic refpolicy packaging.
1
refpolicy (0.0.20071214-1ubuntu1) hardy; urgency=low
2
3
  * New upstream SVN HEAD.
4
   - Labeled networking peer object class updates.
5
   - Patch for debian logrotate to handle syslogd-listfiles, from Vaclav Ovsik.
6
   - Improve several tunables descriptions from Dan Walsh.
7
   - Patch to clean up ns switch usage in the policy from Dan Walsh.
8
   - More complete labeled networking infrastructure from KaiGai Kohei.
9
   - Add interface for libselinux constructor, for libselinux-linked
10
     SELinux-enabled programs.
11
   - Patch to restructure user role templates to create restricted user roles
12
     from Dan Walsh.
13
   - Russian man page translations from Andrey Markelov.
14
   - Remove unused types from dbus.
15
   - Add infrastructure for managing all user web content.
16
   - Deprecate some old file and dir permission set macros in favor of the
17
     newer, more consistently-named macros.
18
   - Patch to clean up unescaped periods in several file context entries from
19
     Jan-Frode Myklebust.
20
   - Merge shlib_t into lib_t.
21
   - Merge strict and targeted policies.  The policy will now behave like the
22
     strict policy if the unconfined module is not present.  If it is, it will
23
     behave like the targeted policy.  Added an unconfined role to have a mix
24
     of confined and unconfined users.
25
   - Added modules:
26
   	exim (Dan Walsh)
27
   	postfixpolicyd (Jan-Frode Myklebust)
28
   - Add support for setting the unknown permissions handling.
29
   - Fix XML building for external reference builds and headers builds.
30
   - Patch to add missing requirements in userdomain interfaces from Shintaro
31
     Fujiwara.
32
   - Add tcpd_wrapped_domain() for services that use tcp wrappers.
33
   - Update MLS constraints from LSPP evaluated policy.
34
   - Allow initrc_t file descriptors to be inherited regardless of MLS level.
35
     Accordingly drop MLS permissions from daemons that inherit from any level.
36
   - Files and radvd updates from Stefan Schulze Frielinghaus.
37
   - Deprecate mls_file_write_down() and mls_file_read_up(), replaced with
38
     mls_write_all_levels() and mls_read_all_levels(), for consistency.
39
   - Add make kernel and init ranged interfaces pass the range transition MLS
40
     constraints.  Also remove calls to mls_rangetrans_target() in modules that 
41
     use the kernel and init interfaces, since its redundant.
42
   - Add interfaces for all MLS attributes except X object classes.
43
   - Require all sensitivities and categories for MLS and MCS policies, not just
44
     the low and high sensitivity and category.
45
   - Database userspace object manager classes from KaiGai Kohei.
46
   - Add third-party interface for Apache CGI.
47
   - Add getserv and shmemserv nscd permissions.
48
   - Add debian apcupsd binary location, from Stefan Schulze Frielinghaus.
49
   - Added modules:
50
   	application
51
   	awstats (Stefan Schulze Frielinghaus)
52
   	bitlbee (Devin Carraway)
53
   	brctl (Dan Walsh)
54
   - Fix incorrectly named files_lib_filetrans_shared_lib() interface in the
55
     libraries module.
56
   - Unified labeled networking policy from Paul Moore.
57
   - Use netmsg initial SID for MLS-only Netlabel packets, from Paul Moore.
58
   - Xen updates from Dan Walsh.
59
   - Filesystem updates from Dan Walsh.
60
   - Large samba update from Dan Walsh.
61
   - Drop snmpd_etc_t.
62
   - Confine sendmail and logrotate on targeted.
63
   - Tunable connection to postgresql for users from KaiGai Kohei.
64
   - Memprotect support patch from Stephen Smalley.
65
   - Add logging_send_audit_msgs() interface and deprecate
66
     send_audit_msgs_pattern().
67
   - Openct updates patch from Dan Walsh.
68
   - Merge restorecon into setfiles.
69
   - Patch to begin separating out hald helper programs from Dan Walsh.
70
   - Fixes for squid, dovecot, and snmp from Dan Walsh.
71
   - Miscellaneous consolekit fixes from Dan Walsh.
72
   - Patch to have avahi use the nsswitch interface rather than individual
73
     permissions from Dan Walsh.
74
   - Patch to dontaudit logrotate searching avahi pid directory from Dan Walsh.
75
   - Patch to allow insmod to mount kvmfs and dontaudit rw unconfined_t pipes
76
     to handle usage from userhelper from Dan Walsh.
77
   - Patch to allow amavis to read spamassassin libraries from Dan Walsh.
78
   - Patch to allow slocate to getattr other filesystems and directories on those
79
     filesystems from Dan Walsh.
80
   - Fixes for RHEL4 from the CLIP project.
81
   - Replace the old lrrd fc entries with munin ones.
82
   - Move program admin template usage out of userdom_admin_user_template() to
83
     sysadm policy in userdomain.te to fix usage of the template for third
84
     parties.
85
   - Fix clockspeed_run_cli() declaration, it was incorrectly defined as a
86
     template instead of an interface.
87
   - Added modules:
88
   	amtu (Dan Walsh)
89
   	apcupsd (Dan Walsh)
90
   	rpcbind (Dan Walsh)
91
   	rwho (Nalin Dahyabhai)
92
93
 -- Caleb Case <calebcase@gmail.com>  Tue, 15 Jan 2008 21:55:52 -0500
94
95
refpolicy (0.0.20070507-5) unstable; urgency=low
96
97
  * Allow users to read the dpkg database. With this change, every user
98
    of the strict policy now has access to dpkg-checkbuildeps, grep-dctrl,
99
    etc, which was not the case previously.
100
  * Change the example localStrict.te policy file to silently ignore apt
101
    searching for something in /var/lib. With this example policy loaded
102
    in my strict policy UML virtual machine, I can compile packages in
103
    enforcing mode. Based on advice on the mailing list, allow more things
104
    to access /selinux
105
  * Merge in changes from Russell Coker. These include a better fix for
106
    /lib.init/rw.
107
108
 -- Manoj Srivastava <srivasta@debian.org>  Fri, 18 May 2007 00:34:07 -0500
109
110
refpolicy (0.0.20070507-4) unstable; urgency=low
111
112
  * Allow apt to run update by giving r_netlink_socket_perms to
113
    self:netlink_route_socket.
114
  * Allow apt/aptitude to update, and install files
115
    - Added an interface to apt.if allow silently ignoring processes that
116
      attempt to use file descriptors from apt. 
117
    - Bump the apt policy module version number, since we have added to
118
      the interface. 
119
    - Added some stuff to dpkg.te to allow debconf .config file
120
      interactions back to the user 
121
    - Add an optional  dontaudit rule to libraries.te to allow
122
      apt-get/aptitude to install packages silently. 
123
  * Very early in boot, /lib/init/rw is created as a mandatory tmpfs for
124
    state information. Label that directory as initrc_tmp_t to allow
125
    mount.te to be permitted to mount a tmpfs there.
126
  * In init.te, allow /etc/network/if-up.d/mountnfs to create
127
    /var/run/network/mountnfs as a poor mans lock. 
128
129
 -- Manoj Srivastava <srivasta@debian.org>  Fri, 11 May 2007 00:55:07 -0500
130
131
refpolicy (0.0.20070507-3) unstable; urgency=low
132
133
  * Add hostfs as a recognized remote file-system. This should allow a
134
    UML virtual machine to function in a fully enforcing mode.
135
136
 -- Manoj Srivastava <srivasta@debian.org>  Wed,  9 May 2007 15:48:26 -0500
137
138
refpolicy (0.0.20070507-2) unstable; urgency=medium
139
140
  * Keep track of modules that are really  built into the base policy in
141
    Debian.  We then use this list to remove  the modules .pp files from
142
    the policy shipped, since they can not be installed along with the
143
    base policy anyway. Make sure we don't add such modules hen
144
    considering module dependencies either.
145
  * Added Module ricci to modules.conf for both strict and targeted.
146
147
 -- Manoj Srivastava <srivasta@debian.org>  Mon,  7 May 2007 09:07:36 -0500
148
149
refpolicy (0.0.20070507-1) unstable; urgency=low
150
151
  * New upstream SVN HEAD.
152
    - Miscellaneous consolekit fixes from Dan Walsh.
153
    - Patch to have avahi use the nsswitch interface rather than individual
154
      permissions from Dan Walsh.
155
    - Patch to dontaudit logrotate searching avahi pid directory from Dan
156
      Walsh. 
157
    - Patch to allow insmod to mount kvmfs and dontaudit rw unconfined_t
158
      pipes to handle usage from userhelper from Dan Walsh.
159
    - Patch to allow amavis to read spamassassin libraries from Dan Walsh.
160
    - Patch to allow slocate to getattr other filesystems and directories
161
      on those filesystems from Dan Walsh.
162
    - Fixes for RHEL4 from the CLIP project.
163
    - Replace the old lrrd fc entries with munin ones.
164
    - Move program admin template usage out of
165
      userdom_admin_user_template() to sysadm policy in userdomain.te to
166
      fix usage of the template for third parties.
167
    - Fix clockspeed_run_cli() declaration, it was incorrectly defined as a
168
      template instead of an interface.
169
    - Added modules: rwho (Nalin Dahyabhai)
170
  * Updated dependencies, since this refpolicy needs newer toolchain,
171
172
 -- Manoj Srivastava <srivasta@debian.org>  Mon,  7 May 2007 01:47:44 -0500
173
174
refpolicy (0.0.20070417-1) unstable; urgency=low
175
176
  * New upstream release.
177
  * Added XS-VCS-Arch and XS-VCS-Browse to debian/control, and updated
178
    build dependencies.
179
  * Bug fix: "selinux-policy-refpolicy-targeted: need file_contexts for
180
    gcj-dbtool-4.1 and /var/log/account", thanks to Russell Coker
181
                                                           (Closes: #416910).
182
183
 -- Manoj Srivastava <srivasta@debian.org>  Thu, 19 Apr 2007 02:28:29 -0500
184
185
refpolicy (0.0.20061018-5) unstable; urgency=high
186
187
  * Add policy for log and lock files for aptitude. This is needed for
188
    proper function; so one does not need to go into permissive mode to
189
    run aptitude.  Stolen from Erich. This is a low risk change.
190
  * Debian puts grub in /usr/sbin/grub. Reflect that in the initial file
191
    context. 
192
  * Debian creates /dev/xconsole independently of whether or not a xserver
193
    has been installed or not. So move the policy related to /dev/sconsole
194
    out of the xserver policy, and into places where relevant (init.te,
195
    logging.fc), to reflect the status that /dev/console is present
196
    anyway.
197
  * Add support for /etc/network/run  and /dev/shm/network, which seem to
198
    be Debian specific as well.
199
  * Allow udev to manage configuration files.
200
201
 -- Manoj Srivastava <srivasta@debian.org>  Fri,  9 Mar 2007 00:22:19 -0600
202
203
refpolicy (0.0.20061018-4) unstable; urgency=low
204
205
  * Bug fix: "selinux-policy-refpolicy-targeted: does not suggest a way to
206
    fix the 'maybe failing' attempt in postinst", thanks to Eddy Petrisor.
207
    While this does not belong in the postinst, I have addedthis to the 
208
    README.Debian file. This should be a low risk change. (Closes: #407691).
209
  * Bug fix: "Default build.conf doesn't match default strict/targeted
210
    policy", thanks to Stefan.The build.conf included in the reference
211
    source policy describe to build a policy of the type "strict". The
212
    default binary policies coming with Debian are build with the policy
213
    type "strict-mcs" or "targeted-mcs". Change the build.conf shipped in
214
    source to conform to what we really use. (changes TYPE=strict to 
215
    TYPE=strict-mcs, very low risk change.                (Closes: #411256).
216
  * Bug fix: "selinux-policy-refpolicy-targeted: openvpn policy do not
217
    allow tcp connection mode", thanks to Rafal Kupka. This bug really
218
    should be at least important, and we should fully support a class of
219
    security product like OpenVPN on machines which are running SELinux,
220
    and this is a very low risk change.                    (Closes: #409041).
221
  * Install header files required for policy building for both strict and
222
    targeted policies in a new -dev package, so it becomes really useful
223
    to work with the source package. Moved the examples from the -src
224
    package to this new -dev package, since the example is only useful in
225
    with the headers provided. This is a new package, but it contains only
226
    files already in the sources (No upstream changes at all), and is the
227
    result of make install-headers. This new package has no rdepends, and
228
    should be a very low risk addition to Debian.
229
  * This release should be a whole lot better for building local policies,
230
    including the policygentool for creating a new policy from scratch,
231
    and ability to build local policy modular packages. The build.conf
232
    files have been cleaned up, and the source policy defaults to targeted
233
    policy, which is standard in Debian, as opposed to the strict policy,
234
    which has priority optional.
235
236
 -- Manoj Srivastava <srivasta@debian.org>  Mon, 26 Feb 2007 22:37:17 -0600
237
238
refpolicy (0.0.20061018-3) unstable; urgency=high
239
240
  * Bug fix: "refpolicy: FTBFS: /bin/sh: debian/stamp/config-strict: No
241
    such file or directory", thanks to Lucas Nussbaum. This was fixed by
242
    moving all the stamps into ./debian instead. I'll re-visit the
243
    ./debian/stamp/ directory in lenny. This is a pretty minor packaging
244
    change.                                                 (Closes: #405613).
245
  * Bug fix: "selinux-policy-refpolicy-targeted: Policy for dcc misses
246
    Debian's FHS paths", thanks to Devin Carraway. From the bug report:
247
    Many of the files in these packages are overlooked when labelling
248
    files, because refpolicy's dcc module stipulates paths not consistent
249
    with the Debian FHS layout.  The files go unlabelled and dcc-client
250
    (at least) stops working. The two major problems  are the references
251
    to /usr/libexec/dcc (damons, placed in /usr/sbin by the Debian
252
    packages) and to /var/dcc (all sorts of things, placed under
253
    /var/lib/dcc).  A side effect of the latter is that dccifd_t and
254
    probably others need search on var_lib_t, through which it must pass
255
    to get to /var/lib/dcc.  Fixed the policy; will send upstream.
256
                                                             (Closes: #404309).
257
  * Bug fix: "selinux-policy-refpolicy-targeted: clamav policy forbids
258
    clamd_t search on /var/lib", thanks to Devin Carraway.  This is a
259
    simple one line change, and obviously an oversight; I think getting
260
    clamd to work is fairly important.                        (Closes: #404895).
261
  * Bug fix: "selinux-policy-refpolicy-targeted: Multiple problems with
262
    courier policy", thanks to Devin Carraway.  There is detailed
263
    information of the changes made in the bug report, and in the commit
264
    logs. Again, fixing courier daemons seems pretty important; SELinux
265
    tends to get used a lot on remote mail servers, and this fixes issues
266
    with the policy.                                          (Closes: #405103).
267
268
 -- Manoj Srivastava <srivasta@debian.org>  Mon, 15 Jan 2007 13:20:30 -0600
269
270
refpolicy (0.0.20061018-2) unstable; urgency=high
271
272
  * The This update enables MCS for targeted and strict, uses 1024
273
    categories (as Fedora uses - necessary for compatability). Please note
274
    that enabling MCS categories is required for compatibility with
275
    filesystems created on Fedora Core 5 and above, RHEL 5 and above, and
276
    CentOS 5 and above.  MCS categories is also a feature that we plan for
277
    all future releases of SE Linux and does not have a nice upgrade path
278
    - releasing etch without MCS will make things painful for SE Linux
279
    users on the upgrade to lenny. This feature has been extensively
280
    tested by Russel Coker and myself, and does not otherwise impact the
281
    install. 
282
  * Allow semanage to use the initrd file descriptor in targeted policy.
283
  * Fix a bug with restorecon.
284
  * Bug fix: "refpolicy: qemu should have execmem permissions", thanks to
285
    David Härdeman                                       (Closes: #402293).
286
287
 -- Manoj Srivastava <srivasta@debian.org>  Fri, 22 Dec 2006 10:33:22 -0600
288
289
refpolicy (0.0.20061018-1) unstable; urgency=low
290
291
  * New upstream release
292
  * Updated copyright file with the new location of the sources, and added
293
    a watch file.
294
  * Bug fix: "selinux-policy-refpolicy-targeted: postinst package list
295
    retrieval suggestion", thanks to Alexander Buerger. Thanks to the
296
    provided suggestion, the selection of policy modules to install is not
297
    only faster, it is actually correct :)                 (Closes: #388744).
298
  * Bug fix: "Makefile for building policy modules?", thanks to Uwe
299
    Hermann.  Provided an intial version, may have bugs.   (Closes: #389116).
300
301
 -- Manoj Srivastava <srivasta@debian.org>  Tue, 24 Oct 2006 14:31:22 -0500
302
303
refpolicy (0.0.20060911-2) unstable; urgency=low
304
305
  * Fixed a typo in policy postinst that made all the policies reload at
306
    every update.
307
308
 -- Manoj Srivastava <srivasta@debian.org>  Tue, 12 Sep 2006 10:28:11 -0500
309
310
refpolicy (0.0.20060911-1) unstable; urgency=low
311
312
  * New upstream SCM HEAD.
313
  * Synched with Erich Schubert <erich@debian.org>
314
    + Added first draft of python-support. You'll want to relabel these files.
315
    + Build python-support and setroubleshoot modules
316
    + Removed modules from guessing hintfile that are included in base.
317
318
  * Bug fix: "Defaults should match the strict/targeted policy", thanks to
319
    Uwe Hermann. Makde them match strict.                     (Closes: #386931).
320
  * Bug fix: "selinux-policy-refpolicy-src: Duplicate entries in policy
321
    files", thanks to Simon Richard Grint                     (Closes: #386909).
322
  * Bug fix: "modules.conf vs. modules.conf.dist", thanks to Uwe Hermann
323
                                                              (Closes: #386887).
324
  * Bug fix: "OUTPUT_POLICY and policy-version comments", thanks to Uwe
325
    Hermann                                                  (Closes: #386930).
326
  * Bug fix: "s/bzip2/gzip/?", thanks to Uwe Hermann         (Closes: #386885).
327
  * Bug fix: "selinux-refpolicy-src: include modules.conf files of strict
328
    and targeted for -src package", thanks to Erich Schubert
329
                                                              (Closes: #386573).
330
331
 -- Manoj Srivastava <srivasta@debian.org>  Mon, 11 Sep 2006 17:46:10 -0500
332
333
refpolicy (0.0.20060907-3) unstable; urgency=low
334
335
  * Updated a few more policy modules to latest versions for Debian.
336
337
 -- Manoj Srivastava <srivasta@debian.org>  Fri,  8 Sep 2006 12:42:22 -0500
338
339
refpolicy (0.0.20060907-2) unstable; urgency=low
340
341
  * Update the module/package mapping.
342
  * In the selinux-policy-refpolicy-src package, now ship the
343
    modules.conf.strict and the modules.conf.targeted files which are used
344
    to build the corresponding policy packages, snce the raw modules.conf
345
    package has issues on Debian.
346
  * With this version, we no longer ship the selinux-policy-refpolicy-src
347
    unpacked into /etc with a gazillion conffiles; instead, we now ship a
348
    compressed tarball in /usr/src, which the user may unpack where they
349
    wish, and install policies as they wish.
350
351
 -- Manoj Srivastava <srivasta@debian.org>  Fri,  8 Sep 2006 10:49:40 -0500
352
353
refpolicy (0.0.20060907-1) unstable; urgency=low
354
355
  * New upstream SCM HEAD.
356
  * Bug fix: "selinux-policy-refpolicy-src: Compile failure of modular
357
    targeted policy", thanks to Simon Richard Grint. Put a wrapper around
358
    the offending lines to only take effect when running a strict policy.
359
                                                            (Closes: #384502).
360
  * Bug fix: "make: /usr/sbin/setfiles: Command not found", thanks to Uwe
361
    Hermann. Fixed upstream.                                (Closes: #384850).
362
363
 -- Manoj Srivastava <srivasta@debian.org>  Fri,  8 Sep 2006 00:27:39 -0500
364
365
refpolicy (0.0.20060813-2) unstable; urgency=low
366
367
  * Bug fix: "Needs gawk", thanks to Simon Richard Grint
368
                                                         (Closes: #382821).
369
  * Bug fix: "Move /etc/selinux/refpolicy/src/policy/man/man8/*
370
    manpages?", thanks to Uwe Hermann                    (Closes: #372789).
371
  * Fix errors in post installation initial policy creation process in the
372
    postinst. 
373
  * Add directories required during policy build during postinst. This bug
374
    prevented any policies being built when the package was initially
375
    installed. Also, create an empty  file_contexts.local file if it does
376
    not already exist. 
377
  * Make selinux-policy-refpolicy-targeted provide and replace the
378
    obsolete package selinux-policy-default; which should in the future be
379
    just a virtual package. 
380
  * Added postrm packages to strict and targeted policy packages, in order
381
    to clean out the directories in which files are created during policy
382
    build. 
383
  * Rewrote the postinst in perl to allow us to do module dependency
384
    checks, and to map policy modules to debian packages, in order to
385
    better detect the modules that would be necessary for the target
386
    machine. 
387
  * Also, compiling with either MCS or MLS produced errors while
388
    installing policy, since we lack setrans daemon. So we are now
389
    building with out them, created an easy to modify option to re-enable
390
    it later.
391
  * Updated modules.conf to use the latest offerings from Erich.
392
393
 -- Manoj Srivastava <srivasta@debian.org>  Mon, 21 Aug 2006 14:59:52 -0500
394
395
refpolicy (0.0.20060813-1) unstable; urgency=low
396
397
  * New upstream SCM HEAD.
398
  * Bug fix: "refpolicy: FTBFS: tmp/generated_definitions.conf:597:ERROR
399
    'syntax error' at token '' on line 3416:", thanks to Andreas Jochens
400
                                                        (Closes: #379559).
401
  * Bug fix: "FTBFS while generating selinux-policy-refpolicy-strict",
402
    thanks to Devin Carraway                            (Closes: #379376).
403
  * Python transition (#2): you are building a private python module.
404
                                                        (Closes: #380930).
405
406
 -- Manoj Srivastava <srivasta@debian.org>  Tue, 15 Aug 2006 09:53:06 -0500
407
408
refpolicy (0.0.20060509-2) unstable; urgency=low
409
410
  * Modified some paths to be more in line with upstream standards.
411
412
 -- Manoj Srivastava <srivasta@debian.org>  Fri, 12 May 2006 08:30:08 -0500
413
414
refpolicy (0.0.20060509-1) unstable; urgency=low
415
416
  * New upstream release. First packaging for Sid. 
417
418
 -- Manoj Srivastava <srivasta@debian.org>  Tue,  9 May 2006 13:56:10 -0500
419
420
refpolicy (20060506-1) sesarge; urgency=low
421
422
  * New upstream checkout from CVS.
423
  * Even more new modules.
424
425
 -- Erich Schubert <erich@debian.org>  Sat,  6 May 2006 21:44:07 +0200
426
427
refpolicy (20060418-2) sesarge; urgency=low
428
429
  * New upstream checkout from CVS.
430
431
 -- Erich Schubert <erich@debian.org>  Fri, 21 Apr 2006 19:17:05 +0200
432
433
refpolicy (20060417-1) sesarge; urgency=low
434
435
  * New upstream checkout from CVS.
436
  * Until module linking is fixed, build everything into base.
437
    (Sorry, this will result in a much larger policy than necessary.
438
     Feel free to use the -src package to build your own!)
439
440
 -- Erich Schubert <erich@debian.org>  Mon, 17 Apr 2006 21:04:49 +0200
441
442
refpolicy (20060414-1) sesarge; urgency=low
443
444
  * New upstream version with tons of new policy files
445
446
 -- Erich Schubert <erich@debian.org>  Mon, 17 Apr 2006 20:48:50 +0200
447
448
refpolicy (20060329-2) sesarge; urgency=low
449
450
  * Merge upstream 20060329-2
451
452
 -- Erich Schubert <erich@debian.org>  Mon,  3 Apr 2006 00:44:06 +0200
453
454
refpolicy (20060324-2) sesarge; urgency=low
455
456
  * Merge upstream 20060324-4
457
458
 -- Erich Schubert <erich@debian.org>  Sat, 25 Mar 2006 03:34:36 +0100
459
460
refpolicy (20060324-1) sesarge; urgency=low
461
462
  * Merge upstream 20060323-2
463
  * Merge changes by Thomas Bleher
464
  * Build with checkpolicy 1.30.1
465
  * Sorry, still doesn't work with make > 3.80
466
467
 -- Erich Schubert <erich@debian.org>  Sat, 25 Mar 2006 02:21:00 +0100
468
469
refpolicy (20060315-2) sesarge; urgency=low
470
471
  * Make modular policy actually work. Hopefully.
472
    (Up to now, optional_policy(`module') in base was not working upstream!)
473
  * Revamp build process, don't use CDBS anymore since I didn't figure out
474
    how to do two clean runs of the same source tree, and there is little
475
    benefit here without any autotools or library magic needed
476
477
 -- Erich Schubert <erich@debian.org>  Fri, 17 Mar 2006 20:51:55 +0100
478
479
refpolicy (20060315-1.1) sesarge; urgency=low
480
481
  * Small tweaks and bugfixes to policy
482
483
 -- Erich Schubert <erich@debian.org>  Thu, 16 Mar 2006 23:13:40 +0100
484
485
refpolicy (20060315-1) sesarge; urgency=low
486
487
  * Merge with upstream and debian changes as of 20060309, rev 50
488
  * Merge with upstream and debian changes as of 20060315, rev 55
489
  * Added "netuser" role, similar to user_tcp_server boolean, but
490
    you can enable it for single users only.
491
492
 -- Erich Schubert <erich@debian.org>  Thu, 16 Mar 2006 00:23:54 +0100
493
494
refpolicy (20060306-1) sesarge; urgency=low
495
496
  * Merge with upstream and debian policy changes as of 20060306, Rev 31
497
  * Try to auto-build a policy after a fresh install in postinst
498
  * Add inetd module to base for now
499
  * Increase policycoreutils build-dep to hopefully solve the users_extra
500
    issues by using a newer policycoreutils for building...
501
502
 -- Erich Schubert <erich@debian.org>  Mon,  6 Mar 2006 17:10:43 +0100
503
504
refpolicy (20060227-1) sesarge; urgency=low
505
506
  * Merge with upstream and debian policy changes as of 20060227, Rev 20
507
508
 -- Erich Schubert <erich@debian.org>  Tue, 28 Feb 2006 03:48:48 +0100
509
510
refpolicy (20060224-2) sesarge; urgency=low
511
512
  * Update build process to not require a tarball, include previous
513
    patches into our "branch" of the reference policy instead.
514
515
 -- Erich Schubert <erich@debian.org>  Tue, 28 Feb 2006 03:13:51 +0100
516
517
refpolicy (20060224-1) sesarge; urgency=low
518
519
  * New upstream CVS checkout.
520
  * Move policy src from /etc to /usr/share/selinux/refpolicy
521
    This avoids an apt-get size limitation and follows Fedora.
522
  * Ship edited build.conf with policy source.
523
  * Use debhelper for installing documentation.
524
  * Add dependency for source onto gawk.
525
526
 -- Erich Schubert <erich@debian.org>  Sat, 25 Feb 2006 01:01:44 +0100
527
528
refpolicy (20060222-1) sesarge; urgency=low
529
530
  * New upstream CVS checkout.
531
  * Thomas also provided a workaround for the make issues in his version.
532
  * Update dpkg/apt policy to interface renamings
533
  * Remove dpkg_script_exec_t, as supporting this would require bad hacks
534
    to dpkg and/or tar. Use dpkg_var_lib_t instead.
535
536
 -- Erich Schubert <erich@debian.org>  Thu, 23 Feb 2006 02:01:35 +0100
537
538
refpolicy (20060217-3) sesarge; urgency=low
539
540
  * Create selinux-policy-refpolicy-doc package
541
  * DIRECT_INITRC=y
542
543
 -- Thomas Bleher <ThomasBleher@gmx.de>  Mon, 20 Feb 2006 23:43:53 +0000
544
545
refpolicy (20060217-2) sesarge; urgency=low
546
547
  * Added first drafts of dpkg, apt policy
548
549
 -- Erich Schubert <erich@debian.org>  Sat, 18 Feb 2006 03:20:59 +0100
550
551
refpolicy (20060217-1) sesarge; urgency=low
552
553
  * New upstream CVS checkout
554
  * Document make incompaibility via build-dep
555
  * Don't build some redhat specific policy modules, minor tweaks
556
557
 -- Erich Schubert <erich@debian.org>  Tue, 14 Feb 2006 02:35:04 +0100
558
559
refpolicy (20060213-1) sesarge; urgency=low
560
561
  * New upstream CVS checkout.
562
  * Still not really useable
563
564
 -- Erich Schubert <erich@debian.org>  Tue, 14 Feb 2006 02:35:04 +0100
565
566
refpolicy (20060117-1) sesarge; urgency=low
567
568
  * Experimental release
569
570
 -- Erich Schubert <erich@debian.org>  Mon, 13 Feb 2006 22:50:03 +0100
1 by Caleb Case
Initial import
571