Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] SELinux base policy rev 4 in hardened-dev
Date: Thu, 01 Mar 2012 20:35:06
Message-Id: 20120301203413.GA26788@gentoo.org
1 I've pushed revision 4 of the SELinux policies to the hardened-dev overlay.
2 This one contains the following changes since before:
3
4 <no bug> Update patch for DHCP LDAP support to use a tunable (dhcp_use_ldap)
5 <no bug> Correct clamav_var_log_t usage (instead of clamav_log_t, which doesn't exist)
6 <no bug> Allow gorg to signal itself
7 <no bug> Make sure mozilla_plugin_t is allowed for mozilla_roles (role attribute) as well
8
9 Users that have an LDAP backend for DHCP might want to enable the
10 dhcp_use_ldap boolean after upgrade as the support for LDAP backends has
11 been made optional.
12
13 Other than that, I have yet to confirm that the RDEPEND in
14 selinux-base-policy on selinux-base is incorrect or not (probably is). What
15 I need to make sure is that, if it changes to DEPEND, that the file
16 collisions that are otherwise introduced (earlier selinux-base-policy files
17 are now in selinux-base) do not interfere with a regular update.
18
19 This should be easy to check, I just need to upgrade my VMs currently and
20 will not be able to do the checks until tomorrow.
21
22 Wkr,
23 Sven Vermeulen