Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] SELinux base policy rev 6 in hardened-dev
Date: Sat, 12 Nov 2011 21:26:06
Hi all,

I have pushed out an update on the SELinux policies in hardened-dev. The
changes include:

- #389579 (Mismatch on amavisd.conf context)
- #389917 (Allow resource management from within inetd -> pam_limits
- #388875 (bootmisc init script test-writes directories in /var/log)
- #389569 (nagios updates, such as raid checking & mounted dir attributes)
- <no bug> (Added selinux-uwimap build as requested on mailinglist)
- <no bug> (gcc-config needs to manage etc_runtime_t files)
- <no bug> (gcc-config needs access to nfs_t if Portage tree is on NFS)
- <upstream> (Updated VDE patch to match upstream style)

I have also cleaned out our previous policies in the main portage tree
(those before 2.20110627) which was quite some work (removal itself doesn't
take that much time, but verifying that one isn't going to break systems is)
but I'm glad that is now done. 

	Sven Vermeulen