rpms/selinux-policy/F-9 policy-20071130.patch,1.191,1.192

Daniel J Walsh (dwalsh) fedora-extras-commits at redhat.com
Mon Jul 14 20:38:43 UTC 2008


Author: dwalsh

Update of /cvs/extras/rpms/selinux-policy/F-9
In directory cvs-int.fedora.redhat.com:/tmp/cvs-serv7155

Modified Files:
	policy-20071130.patch 
Log Message:
* Tue Jul 8 2008 Dan Walsh <dwalsh at redhat.com> 3.3.1-78
- Allow unconfined_t to setfcap
- Allow spamassassin to read razor lib files


policy-20071130.patch:

Index: policy-20071130.patch
===================================================================
RCS file: /cvs/extras/rpms/selinux-policy/F-9/policy-20071130.patch,v
retrieving revision 1.191
retrieving revision 1.192
diff -u -r1.191 -r1.192
--- policy-20071130.patch	14 Jul 2008 20:10:21 -0000	1.191
+++ policy-20071130.patch	14 Jul 2008 20:37:57 -0000	1.192
@@ -17192,7 +17192,7 @@
  ')
 diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/kerberos.te serefpolicy-3.3.1/policy/modules/services/kerberos.te
 --- nsaserefpolicy/policy/modules/services/kerberos.te	2008-06-12 23:38:02.000000000 -0400
-+++ serefpolicy-3.3.1/policy/modules/services/kerberos.te	2008-07-11 14:36:19.000000000 -0400
++++ serefpolicy-3.3.1/policy/modules/services/kerberos.te	2008-07-14 16:33:45.000000000 -0400
 @@ -16,6 +16,7 @@
  type kadmind_t;
  type kadmind_exec_t;
@@ -17298,13 +17298,7 @@
  allow krb5kdc_t self:netlink_route_socket r_netlink_socket_perms;
  allow krb5kdc_t self:tcp_socket create_stream_socket_perms;
  allow krb5kdc_t self:udp_socket create_socket_perms;
-@@ -160,11 +182,13 @@
- allow krb5kdc_t krb5_conf_t:file read_file_perms;
- dontaudit krb5kdc_t krb5_conf_t:file write;
- 
--can_exec(krb5kdc_t, krb5kdc_exec_t)
-+qcan_exec(krb5kdc_t, krb5kdc_exec_t)
- 
+@@ -165,6 +187,8 @@
  read_files_pattern(krb5kdc_t,krb5kdc_conf_t,krb5kdc_conf_t)
  dontaudit krb5kdc_t krb5kdc_conf_t:file write;
  




More information about the fedora-extras-commits mailing list