From: "Christopher J. PeBenito" <cpebenito@tresys.com>
To: "refpolicy@oss.tresys.com" <refpolicy@oss1.tresys.com>,
"selinux@tycho.nsa.gov" <selinux@tycho.nsa.gov>
Subject: ANN: Reference Policy Release
Date: Wed, 15 Feb 2012 15:19:20 -0500 [thread overview]
Message-ID: <4F3C1348.4090003@tresys.com> (raw)
A new release of the SELinux Reference Policy is now available on the Tresys OSS site, http://oss.tresys.com. This release reflects the git repository restructuring for core/contrib modules[1].
The complete change log for this release follows at the end of the email.
For people interested in helping Reference Policy development, the X desktop and role separation needs testing, in addition to general testing.
[1] http://oss.tresys.com/pipermail/refpolicy/2011-September/004619.html
* Wed Feb 15 2012 Chris PeBenito <selinux@tresys.com> - 2.20120215
- Sshd usage of mkhomedir_helper via oddjob, from Sven Vermeulen.
- Add slim and lxdm file contexts to xserver, from Sven Vermeulen.
- Add userdom interfaces for user application domains, user tmp files,
and user tmpfs files.
- Asterisk administration fixes from Sven Vermeulen.
- Fix makefiles to install files with the correct DAC permissions if the
umask is not 022.
- Remove deprecated support macros.
- Remove rolemap and per-role template support.
- Change corenetwork port declaration to apply the reserved port type
attribute only, when the type has ports above and below 1024.
- Change secure_mode_policyload to disable only toggling of this Boolean
rather than disabling all Boolean toggling permissions.
- Use role attributes to assist with domain transitions in interactive
programs.
- Milter ports patch from Paul Howarth.
- Separate portage fetch rules out of portage_run() and portage_domtrans()
from Sven Vermeulen.
- Enhance corenetwork network_port() macro to support ports that do not have
a well defined port number, such as stunnel.
- Opendkim support in dkim module from Paul Howarth.
- Wireshark updates from Sven Vermeulen.
- Change secure_mode_insmod to control sys_module capability rather than
controlling domain transitions to insmod.
- Openrc and portage updates from Sven Vermeulen.
- Allow user and role changes on dynamic transitions with the same
constraints as regular transitions.
- New git service features from Dominick Grift.
- Corenetwork policy size optimization from Dan Walsh.
- Silence spurious udp_socket listen denials.
- Fix unexpanded MLS/MCS fields in monolithic seusers file.
- Type transition fix in Postgresql database objects from KaiGai Kohei.
- Support for file context path substitutions (file_contexts.subs).
- Added contrib modules:
glance (Dan Walsh)
rhsmcertd (Dan Walsh)
sanlock (Dan Walsh)
sblim (Dan Walsh)
uuidd (Dan Walsh)
vdagent (Dan Walsh)
--
Chris PeBenito
Tresys Technology, LLC
www.tresys.com | oss.tresys.com
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
WARNING: multiple messages have this Message-ID (diff)
From: cpebenito@tresys.com (Christopher J. PeBenito)
To: refpolicy@oss.tresys.com
Subject: [refpolicy] ANN: Reference Policy Release
Date: Wed, 15 Feb 2012 15:19:20 -0500 [thread overview]
Message-ID: <4F3C1348.4090003@tresys.com> (raw)
A new release of the SELinux Reference Policy is now available on the Tresys OSS site, http://oss.tresys.com. This release reflects the git repository restructuring for core/contrib modules[1].
The complete change log for this release follows at the end of the email.
For people interested in helping Reference Policy development, the X desktop and role separation needs testing, in addition to general testing.
[1] http://oss.tresys.com/pipermail/refpolicy/2011-September/004619.html
* Wed Feb 15 2012 Chris PeBenito <selinux@tresys.com> - 2.20120215
- Sshd usage of mkhomedir_helper via oddjob, from Sven Vermeulen.
- Add slim and lxdm file contexts to xserver, from Sven Vermeulen.
- Add userdom interfaces for user application domains, user tmp files,
and user tmpfs files.
- Asterisk administration fixes from Sven Vermeulen.
- Fix makefiles to install files with the correct DAC permissions if the
umask is not 022.
- Remove deprecated support macros.
- Remove rolemap and per-role template support.
- Change corenetwork port declaration to apply the reserved port type
attribute only, when the type has ports above and below 1024.
- Change secure_mode_policyload to disable only toggling of this Boolean
rather than disabling all Boolean toggling permissions.
- Use role attributes to assist with domain transitions in interactive
programs.
- Milter ports patch from Paul Howarth.
- Separate portage fetch rules out of portage_run() and portage_domtrans()
from Sven Vermeulen.
- Enhance corenetwork network_port() macro to support ports that do not have
a well defined port number, such as stunnel.
- Opendkim support in dkim module from Paul Howarth.
- Wireshark updates from Sven Vermeulen.
- Change secure_mode_insmod to control sys_module capability rather than
controlling domain transitions to insmod.
- Openrc and portage updates from Sven Vermeulen.
- Allow user and role changes on dynamic transitions with the same
constraints as regular transitions.
- New git service features from Dominick Grift.
- Corenetwork policy size optimization from Dan Walsh.
- Silence spurious udp_socket listen denials.
- Fix unexpanded MLS/MCS fields in monolithic seusers file.
- Type transition fix in Postgresql database objects from KaiGai Kohei.
- Support for file context path substitutions (file_contexts.subs).
- Added contrib modules:
glance (Dan Walsh)
rhsmcertd (Dan Walsh)
sanlock (Dan Walsh)
sblim (Dan Walsh)
uuidd (Dan Walsh)
vdagent (Dan Walsh)
--
Chris PeBenito
Tresys Technology, LLC
www.tresys.com | oss.tresys.com
next reply other threads:[~2012-02-15 20:19 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-02-15 20:19 Christopher J. PeBenito [this message]
2012-02-15 20:19 ` [refpolicy] ANN: Reference Policy Release Christopher J. PeBenito
-- strict thread matches above, loose matches on Subject: below --
2019-02-01 20:22 ANN: Reference Policy release Chris PeBenito
2018-07-01 17:40 Chris PeBenito
2017-02-04 19:02 ANN: Reference Policy Release Chris PeBenito
2016-10-23 21:29 Chris PeBenito
2016-11-02 4:13 ` Russell Coker
2016-11-02 22:19 ` Chris PeBenito
2015-12-08 15:49 Christopher J. PeBenito
2014-12-03 19:31 Christopher J. PeBenito
2014-03-11 13:33 Christopher J. PeBenito
2013-04-24 20:56 Christopher J. PeBenito
2012-07-26 16:41 Christopher J. PeBenito
2011-07-26 18:44 Christopher J. PeBenito
2010-12-14 16:39 Christopher J. PeBenito
2010-05-25 20:02 Christopher J. PeBenito
2009-11-17 15:28 Christopher J. PeBenito
2009-07-30 18:45 Christopher J. PeBenito
2008-12-10 20:24 Christopher J. PeBenito
2008-10-14 18:34 Christopher J. PeBenito
2008-07-02 15:37 Christopher J. PeBenito
2008-04-02 18:14 Christopher J. PeBenito
2007-12-14 18:56 Christopher J. PeBenito
2007-09-28 15:19 Christopher J. PeBenito
2007-10-02 15:29 ` Shintaro Fujiwara
2007-06-29 17:30 Christopher J. PeBenito
2007-04-17 15:07 Christopher J. PeBenito
2007-04-19 20:45 ` Manoj Srivastava
2007-04-19 20:56 ` Karl MacMillan
2007-04-19 23:10 ` Manoj Srivastava
2006-12-12 22:35 Christopher J. PeBenito
2006-10-19 12:57 Christopher J. PeBenito
2006-03-07 15:28 Christopher J. PeBenito
2006-01-17 21:31 Christopher J. PeBenito
2005-12-07 16:40 Christopher J. PeBenito
2005-12-15 22:28 ` Serge E. Hallyn
2005-12-16 17:59 ` Daniel J Walsh
2005-12-18 23:20 ` Serge E. Hallyn
2006-01-03 15:48 ` Christopher J. PeBenito
2005-10-19 21:50 Christopher J. PeBenito
2005-09-22 20:56 Christopher J. PeBenito
2005-09-07 17:22 Christopher J. PeBenito
2005-08-26 15:57 Christopher J. PeBenito
2005-08-02 15:49 Christopher J. PeBenito
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4F3C1348.4090003@tresys.com \
--to=cpebenito@tresys.com \
--cc=refpolicy@oss1.tresys.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.