Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] SELinux base policy 2.20120725 rev 5 in hardened-dev overlay
Date: Sat, 08 Sep 2012 21:02:31
Message-Id: 20120908181457.GA8767@gentoo.org
1 Hi guys,
2
3 I've pushed out a new revision on the policies to the hardened-dev overlay.
4 I haven't heard of any more regressions towards the 20120215 policies since
5 so chances are that I'll be pushing out this one to the main tree soon (as
6 ~arch). This is too because we're moving forward a lot, and the 20120215
7 policies are more than likely not that useful anymore.
8
9 In any case, here is the set of changes since the previous revision:
10
11 <no bug> Various capability updates for sanlock (backport)
12 <no bug> Tor reads network sysctls (backport)
13 <no bug> Support minimal polkit (backport)
14 <no bug> Allow CUPS to read crypto sysctls (backport)
15 <no bug> Allow wicd to execute wpa_cli within its own domain (networkmanager_t) (backport)
16 <no bug> Add in milter greylist enhancements (backport)
17 <no bug> GPG agent reads /dev/random (backport)
18 <no bug> Support gitolite3 (backport)
19 <no bug> Support LDAP-based user authentication for dovecot (backport)
20 <no bug> Various block_suspend fixes (backport)
21 <no bug> Freshclam reads system/network state (backport)
22 <no bug> Introduce systemtap policy (backport)
23 <no bug> Fix ports usage for djbdns (backport)
24 <no bug> Allow quota to request loading kernel modules (backport)
25 <no bug> Allow sasl to talk with mysql over tcp (backport)
26 <no bug> Introduce sensord policy (backport)
27 <no bug> Turn all booleans off by default (backport)
28 <no bug> Support loop device file context (backport)
29 <no bug> Mark the syslog-ng.persist file as syslogd_var_lib_t so it survives relabeling
30 <no bug> ConsoleKit creates /var/run/console and tagfiles
31 <no bug> Backport lost+found changes from refpolicy
32 <no bug> Set resource limits for dbus system daemon
33 <no bug> Allow lvm_t (cryptsetup) to request loading a crypto-related kernel module
34 #432990 Introduce puppet_admin and puppet_admin_puppetmaster interfaces
35 #431654 Allow initrc_t to create /run/nscd
36 #431654 Allow initrc_t to create /run/ConsoleKit
37 #431654 Allow sysadmin to manage ntp
38 #431654 Allow sysadmin to manage bind (named)
39 #431654 Allow sysadmin to manage openvpn
40 #431654 Allow initrc_t to create /run/asterisk
41
42 @Paolo, this doesn't fix the denials you notice, but I don't think those are
43 regressions and you're able to boot in enforcing mode, so I'm hoping the
44 remainder of fixes that are needed can be put in quickly (i.e. when my time
45 allows it to look at them :-(
46
47 The majority of changes are backports as refpolicy has seen its share of
48 updates (mainly due to a few Fedora/RedHat developers or contributors
49 gaining commit rights to the reference policy). I'm expecting quite a lot of
50 other changes to come up in the next few weeks, but you'll have to excuse me
51 for not porting them immediately back - september's a quite busy month in
52 real life for me.
53
54 Have fun at it!
55
56 Sven Vermeulen

Replies

Subject Author
Re: [gentoo-hardened] SELinux base policy 2.20120725 rev 5 in hardened-dev overlay Paolo Barile <f.p.barile@×××××.com>