rpms/selinux-policy/F-9 policy-20071130.patch,1.191,1.192
Daniel J Walsh (dwalsh)
fedora-extras-commits at redhat.com
Mon Jul 14 20:38:43 UTC 2008
Author: dwalsh
Update of /cvs/extras/rpms/selinux-policy/F-9
In directory cvs-int.fedora.redhat.com:/tmp/cvs-serv7155
Modified Files:
policy-20071130.patch
Log Message:
* Tue Jul 8 2008 Dan Walsh <dwalsh at redhat.com> 3.3.1-78
- Allow unconfined_t to setfcap
- Allow spamassassin to read razor lib files
policy-20071130.patch:
Index: policy-20071130.patch
===================================================================
RCS file: /cvs/extras/rpms/selinux-policy/F-9/policy-20071130.patch,v
retrieving revision 1.191
retrieving revision 1.192
diff -u -r1.191 -r1.192
--- policy-20071130.patch 14 Jul 2008 20:10:21 -0000 1.191
+++ policy-20071130.patch 14 Jul 2008 20:37:57 -0000 1.192
@@ -17192,7 +17192,7 @@
')
diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/kerberos.te serefpolicy-3.3.1/policy/modules/services/kerberos.te
--- nsaserefpolicy/policy/modules/services/kerberos.te 2008-06-12 23:38:02.000000000 -0400
-+++ serefpolicy-3.3.1/policy/modules/services/kerberos.te 2008-07-11 14:36:19.000000000 -0400
++++ serefpolicy-3.3.1/policy/modules/services/kerberos.te 2008-07-14 16:33:45.000000000 -0400
@@ -16,6 +16,7 @@
type kadmind_t;
type kadmind_exec_t;
@@ -17298,13 +17298,7 @@
allow krb5kdc_t self:netlink_route_socket r_netlink_socket_perms;
allow krb5kdc_t self:tcp_socket create_stream_socket_perms;
allow krb5kdc_t self:udp_socket create_socket_perms;
-@@ -160,11 +182,13 @@
- allow krb5kdc_t krb5_conf_t:file read_file_perms;
- dontaudit krb5kdc_t krb5_conf_t:file write;
-
--can_exec(krb5kdc_t, krb5kdc_exec_t)
-+qcan_exec(krb5kdc_t, krb5kdc_exec_t)
-
+@@ -165,6 +187,8 @@
read_files_pattern(krb5kdc_t,krb5kdc_conf_t,krb5kdc_conf_t)
dontaudit krb5kdc_t krb5kdc_conf_t:file write;
More information about the fedora-extras-commits
mailing list