Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] SELinux base policy 2.20120725 rev 4 in hardened-dev overlay
Date: Fri, 24 Aug 2012 18:02:28
Message-Id: 20120824173259.GA15784@gentoo.org
1 Hi folks,
2
3 Another policy iteration. Still contains a few /run updates (see how such a
4 "small" change in a distribution can make a large set of changes for
5 SELinux...) but other than that small fixes all over the place.
6
7 <no bug> Mark /etc/env.d in its entirety as etc_runtime_t
8 <no bug> Backport device driver context fixes
9 <no bug> Backport mei device driver support
10 #430990 Update skype policy for skype version 4
11 <no bug> Remove named_var_lib_t reference
12 #431654 Allow sysadm to manage asterisk service
13 #431654 Support postgresql (named init for sysadmin, /run/postgresql)
14 <no bug> Remove duplicate file context in java module
15 <no bug> Remove ~/.config/chromium context within mozilla
16 <no bug> Allow initrc_t to also setattr on the /run dirs he creates
17
18 Give it a go, all feedback appreciated. And if I don't reply on IRC quickly,
19 open a bugreport for it. It's also a better way to track changes and allows
20 me to properly bring fixes upstream as well.
21
22 Wkr,
23 Sven Vermeulen