--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-743a9247de
2018-06-09 20:39:22.943815
--------------------------------------------------------------------------------

Name        : selinux-policy
Product     : Fedora 28
Version     : 3.14.1
Release     : 32.fc28
URL         : %{git0-base}
Summary     : SELinux policy configuration
Description :
SELinux Base package for SELinux Reference Policy - modular.
Based off of reference policy: Checked out revision  2.20091117

--------------------------------------------------------------------------------
Update Information:

More info: https://koji.fedoraproject.org/koji/taskinfo?taskID=27453962
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun  6 2018 Lukas Vrabec <[email protected]> - 3.14.1-32
- Add dac_override capability to sendmail_t domain
* Wed Jun  6 2018 Lukas Vrabec <[email protected]> - 3.14.1-31
- Fix typo in authconfig policy
- Update ctdb domain to support gNFS setup
- Allow authconfig_t dbus chat with policykit
- Allow lircd_t domain to read system state
- Revert "Allow fsdaemon_t do send emails BZ(1582701)"
- Typo in uuidd policy
- Allow tangd_t domain read certs
- Allow vpnc_t domain to read configfs_t files/dirs BZ(1583107)
- Allow vpnc_t domain to read generic certs BZ(1583100)
- Label /var/lib/phpMyAdmin directory as httpd_sys_rw_content_t BZ(1584811)
- Allow NetworkManager_ssh_t domain to be system dbud client
- Allow virt_qemu_ga_t read utmp
- Add capability dac_override to system_mail_t domain
- Update uuidd policy to reflect last changes from base branch
- Add cap dac_override to procmail_t domain
- Allow sendmail to mmap etc_aliases_t files BZ(1578569)
- Add new interface dbus_read_pid_sock_files()
- Allow mpd_t domain read config_home files if mpd_enable_homedirs boolean will 
be enabled
- Allow fsdaemon_t do send emails BZ(1582701)
- Allow firewalld_t domain to request kernel module BZ(1573501)
- Allow chronyd_t domain to send send msg via dgram socket BZ(1584757)
- Add sys_admin capability to fprint_t SELinux domain
- Allow cyrus_t domain to create own files under /var/run BZ(1582885)
- Allow cachefiles_kernel_t domain to have capability dac_override
- Update policy for ypserv_t domain
- Allow zebra_t domain to bind on tcp/udp ports labeled as qpasa_agent_port_t
- Allow cyrus to have dac_override capability
- Dontaudit action when abrt-hook-ccpp is writing to nscd sockets
- Fix homedir polyinstantion under mls
- Fixed typo in init.if file
- Allow systemd to remove generic tmpt files BZ(1583144)
- Update init_named_socket_activation() interface to also allow systemd create 
objects in /var/run with proper label during socket activation
- Allow systemd-networkd and systemd-resolved services read system-dbusd socket 
BZ(1579075)
- Fix typo in authlogin SELinux security module
- Allod nsswitch_domain attribute to be system dbusd client BZ(1584632)
- Allow audisp_t domain to mmap audisp_exec_t binary
- Update ssh_domtrans_keygen interface to allow mmap ssh_keygen_exec_t binary 
file
- Label tcp/udp ports 2612 as qpasa_agetn_port_t
* Sat May 26 2018 Lukas Vrabec <[email protected]> - 3.14.1-30
- Add dac_override to exim policy BZ(1574303)
- Fix typo in conntrackd.fc file
- Allow sssd_t to kill sssd_selinux_manager_t
- Allow httpd_sys_script_t to connect to mongodb_port_t if boolean 
httpd_can_network_connect_db  is turned on
- Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp
- Allow policykit_auth_t to read udev db files BZ(1574419)
- Allow varnishd_t do be dbus client BZ(1582251)
- Allow cyrus_t domain to mmap own pid files BZ(1582183)
- Allow user_mail_t domain to mmap etc_aliases_t files
- Allow gkeyringd domains to run ssh agents
- Allow gpg_pinentry_t domain read ssh state
- Allow gpg_agent_t to send msgs to syslog/journal
- Add dac_override capability to dovecot_t domain
- Allow nscd_t domain to mmap system_db_t files
- Allow tangd_t domain to create tcp sockets and add new interface 
tangd_read_db_files
- Allow sysadm_u use xdm
- Allow xdm_t domain to listen ofor unix dgram sockets BZ(1581495)
- Add interface ssh_read_state()
- Fix typo in sysnetwork.if file
- Update dev_map_xserver_misc interface to allo mmaping char devices instead of 
files
- Allow noatsecure permission for all domain transitions from systemd.
- Allow systemd to read tangd db files
- Fix typo in ssh.if file
- Allow xdm_t domain to mmap xserver_misc_device_t files
* Thu May 24 2018 Lukas Vrabec <[email protected]> - 3.14.1-29
- Fixed typos in devices.if file
* Thu May 24 2018 Lukas Vrabec <[email protected]> - 3.14.1-28
- Allow mailman_mail_t domain to search for apache configs
- Allow mailman_cgi_t domain to ioctl an httpd with a unix domain stream 
sockets.
- Improve procmail_domtrans() to allow mmaping procmail_exec_t
- Allow ptrace arbitrary processes
- Allow jabberd_router_t domain read kerberos keytabs BZ(1573945)
- Allow certmonger to geattr of filesystems BZ(1578755)
- Allow hypervvssd_t domain to read fixed disk devices
- Allow several domains to manage ecryptfs_t filesystem
- Allow userdom_use_user_ttys for loadkeys_t domain
- Add dac_override capability to cachefiles_kernel_t domain
- Allow blueman to execute ldconfig BZ(1577581)
- Allow gpg_pinentry_t domain to read state of gpg_t processes
- Allow xdm_t domain to mmap xserver_misc_device_t files
- Allow xdm_t domain to execute systemd-coredump binary
- Add bridge_socket, dccp_socket, ib_socket and mpls_socket to socket_class_set
- Improve modutils_domtrans_insmod() interface to mmap insmod_exec_t binaries
- Improve iptables_domtrans() interface to allow mmaping iptables_exec_t binary
- Improve auth_domtrans_login_programinterface to allow also mmap login_exec_t 
binaries
- Improve auth_domtrans_chk_passwd() interface to allow also mmaping 
chkpwd_exec_t binaries.
- Allow mmap dhcpc_exec_t binaries in sysnet_domtrans_dhcpc interface
- Improve running xorg with proper SELinux domain even if systemd security 
feature NoNewPrivileges is used
- Associate sysctl_vm_overcommit_t with fs_t
- Allow systemd creating bluetooth sockets
- Allow ssh client to read network sysctl BZ(1574170)
- Allow systemd_resolved_t and systemd_networkd_t to read dbus pid files
* Tue May 22 2018 Lukas Vrabec <[email protected]> - 3.14.1-27
- Increase dependency versions of policycoreutils and checkpolicy packages
* Mon May 21 2018 Lukas Vrabec <[email protected]> - 3.14.1-26
- Disable secure mode environment cleansing for dirsrv_t
- Allow udev execute /usr/libexec/gdm-disable-wayland in xdm_t domain which 
allows create /run/gdm/custom.conf with proper xdm_var_run_t label.
* Mon May 21 2018 Lukas Vrabec <[email protected]> - 3.14.1-25
- Add dac_override capability to remote_login_t domain
- Allow chrome_sandbox_t to mmap tmp files
- Update ulogd SELinux security policy
- Allow rhsmcertd_t domain send signull to apache processes
- Allow systemd socket activation for modemmanager
- Allow geoclue to dbus chat with systemd
- Fix file contexts on conntrackd policy
- Temporary fix for varnish and apache adding capability for DAC_OVERRIDE
- Allow lsmd_plugin_t domain to getattr lsm_t unix stream sockets
- Add label for  /usr/sbin/pacemaker-remoted to have cluster_exec_t
- Allow nscd_t domain to be system dbusd client
- Allow abrt_t domain to read sysctl
- Add dac_read_search capability for tangd
- Allow systemd socket activation for rshd domain
- Add label for /usr/libexec/cyrus-imapd/master as cyrus_exec_t to have proper 
SELinux domain transition from init_t to cyrus_t
- Allow kdump_t domain to map /boot files
- Allow conntrackd_t domain to send msgs to syslog
- Label /usr/sbin/nhrpd and /usr/sbin/pimd binaries as zebra_exec_t
- Allow swnserve_t domain to stream connect to sasl domain
- Allow smbcontrol_t to create dirs with samba_var_t label
- Remove execstack,execmem and execheap from domains setroubleshootd_t, 
locate_t and podsleuth_t to increase security. BZ(1579760)
- Allow tangd to read public sssd files BZ(1509054)
- Allow geoclue start with nnp systemd security feature with proper SELinux 
Domain transition BZ(1575212)
- Allow ctdb_t domain modify ctdb_exec_t files
- Allow firewalld_t domain to create netlink_netfilter sockets
- Allow radiusd_t domain to read network sysctls
- Allow pegasus_t domain to mount tracefs_t filesystem
- Allow psad_t domain to read all domains state
- Allow tomcat_t domain to connect to mongod_t tcp port
- Allow dovecot and postfix to connect to systemd stream sockets
- Make nmbd_t domain dbus system client BZ(1569856)
- Merge pull request #55 from SISheogorath/fix/tlp-policy
- Merge pull request #54 from tmzullinger/rawhide
- Allow also listing system_dbusd_var_run_t dirs in dbusd_read_pid_files macro 
BZ(1566168)
- Allow gssproxy_t domain to read gssd_t state BZ(1572945)
- Allow create systemd to mount pid files
- Add files_map_boot_files() interface
- Remove execstack,execmem and execheap from domain fsadm_t to increase 
security. BZ(1579760)
- Fix typo xserver SELinux module
- Allow systemd to mmap files with var_log_t label
- Allow x_userdomains read/write to xserver session
- Allow users staff and sysadm to run wireshark on own domain
- Fix typos s/xserver/xdm/ for allow creating xserver misc devices
- Allow systemd-bootchart to create own tmpfs files
- Merge pull request #213 from tmzullinger/rawhide
- Allow xdm_t domain to install Nouveau drivers BZ(1570996)
- Allow unconfined_domain_type to create libs filetrans named content 
BZ(1513806)
* Sat Apr 28 2018 Lukas Vrabec <[email protected]> - 3.14.1-24
- Allow unconfined_domain_type to create libs filetrans named content 
BZ(1513806)
* Fri Apr 27 2018 Lukas Vrabec <[email protected]> - 3.14.1-23
- Allow dnssec_trigger_t domain to read system network state BZ(1570205)
- Add dac_override capability to mailman_mail_t domain
- Add dac_override capability to radvd_t domain
- Update openvswitch policy
- Add dac_override capability to oddjob_homedir_t domain
- Allow slapd_t domain to mmap slapd_var_run_t files
- Rename tang policy to tangd
- Allow virtd_t domain to relabel virt_var_lib_t files
- Allow logrotate_t domain to stop services via systemd
- Add tang policy
- Allow mozilla_plugin_t to create mozilla.pdf file in user homedir with label 
mozilla_home_t
- Allow snapperd_t daemon to create unlabeled dirs.
- Make httpd_var_run_t mountpoint
- Allow hsqldb_t domain to mmap own temp files
- We have inconsistency in cgi templates with upstream, we use _content_t, but 
refpolicy use httpd__content_t. Created aliasses to make it consistence
- Allow Openvswitch adding netdev bridge ovs 2.7.2.10 FDP
- Add new Boolean tomcat_use_execmem
- Allow nfsd_t domain to read/write sysctl fs files
- Allow conman to read system state
- Allow brltty_t domain to be dbusd system client
- Allow zebra_t domain to bind on babel udp port
- Allow freeipmi domain to read sysfs_t files
- Allow targetd_t domain mmap lvm config files
- Allow abrt_t domain to manage kdump crash files
- gnome_data_filetrans macro should be in optional block
- Allow netutils_t domain to create bluetooth sockets
- Allow traceroute to bind on generic sctp node
- Allow traceroute to search network sysctls
- Allow systemd to use virtio console
- Label /dev/op_panel and /dev/opal-prd as opal_device_t
- Label /run/ebtables.lock as iptables_var_run_t
- Allow udev_t domain to manage udev_rules_t char files.
- Assign babel_port_t label to udp port 6696
- Add new interface lvm_map_config
- Merge pull request #212 from stlaz/patch-1
- Allow local_login_t reads of udev_var_run_t context
* Wed Apr 18 2018 Lukas Vrabec <[email protected]> - 3.14.1-22
- Allow networkmanager domain to write to ecryptfs_t files BZ(1566706)
- Allow l2tpd domain to stream connect to sssd BZ(1568160)
- Dontaudit abrt_t to write to lib_t dirs BZ(1566784)
- Allow NetworkManager_ssh_t domain transition to insmod_t BZ(1567630)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1584478 - cyrus-imapd fails with selinux dac_override denied
        https://bugzilla.redhat.com/show_bug.cgi?id=1584478
  [ 2 ] Bug #1549364 - SELinux is preventing fprintd from using the 'sys_admin' 
capabilities.
        https://bugzilla.redhat.com/show_bug.cgi?id=1549364
  [ 3 ] Bug #1585470 - SELinux is preventing sendmail(ssmtp) from using the 
'dac_override' capabilities.
        https://bugzilla.redhat.com/show_bug.cgi?id=1585470
  [ 4 ] Bug #1583107 - SELinux is preventing openconnect from 'search' accesses 
on the directory /sys/kernel/config.
        https://bugzilla.redhat.com/show_bug.cgi?id=1583107
  [ 5 ] Bug #1584811 - SELinux is preventing php-fpm from 'map' accesses on the 
file 
/var/lib/phpMyAdmin/temp/twig/80/809dbf34efabcf21fa6d57b8d6f95b7ad7ac7d190851f4ef36fa9f94bac71c36.php.
        https://bugzilla.redhat.com/show_bug.cgi?id=1584811
  [ 6 ] Bug #1579075 - AVC: systemd-networkd and resolved unable to communicate 
over dbus
        https://bugzilla.redhat.com/show_bug.cgi?id=1579075
  [ 7 ] Bug #1574156 - SELinux is preventing sh from 'execute_no_trans' 
accesses on the file /usr/bin/kmod.
        https://bugzilla.redhat.com/show_bug.cgi?id=1574156
  [ 8 ] Bug #1585359 - SELinux is preventing mpd from 'search' accesses on the 
directory .config.
        https://bugzilla.redhat.com/show_bug.cgi?id=1585359
  [ 9 ] Bug #1582701 - SELinux is preventing mkdir from 'getattr' accesses on 
the directory /root/.esmtp_queue.
        https://bugzilla.redhat.com/show_bug.cgi?id=1582701
  [ 10 ] Bug #1584757 - AVC denial appear when joining with freeipa-client
        https://bugzilla.redhat.com/show_bug.cgi?id=1584757
  [ 11 ] Bug #1578569 - SELinux is preventing sendmail from 'map' accesses on 
the file /etc/mail/userdb.db.
        https://bugzilla.redhat.com/show_bug.cgi?id=1578569
  [ 12 ] Bug #1482353 - SELinux is preventing dhclient from 'map' accesses on 
the file 
/var/lib/NetworkManager/dhclient-f7751877-018c-4740-9ab0-7fdd76d9e1f2-wlp1s0.lease.
        https://bugzilla.redhat.com/show_bug.cgi?id=1482353
  [ 13 ] Bug #1582883 - SELinux is preventing master from using the 
'dac_override' capabilities.
        https://bugzilla.redhat.com/show_bug.cgi?id=1582883
  [ 14 ] Bug #1483716 - SELinux is preventing systemd from 'create' accesses on 
the netlink_audit_socket Unknown.
        https://bugzilla.redhat.com/show_bug.cgi?id=1483716
  [ 15 ] Bug #1584632 - Add nss_systemd support to auth_use_nsswitch()
        https://bugzilla.redhat.com/show_bug.cgi?id=1584632
  [ 16 ] Bug #1579626 - SELinux is preventing procmail from using the 
'dac_override' capabilities.
        https://bugzilla.redhat.com/show_bug.cgi?id=1579626
  [ 17 ] Bug #1583100 - SELinux is preventing openconnect from 'map' accesses 
on the file /usr/share/pki/ca-trust-source/ca-bundle.trust.p11-kit.
        https://bugzilla.redhat.com/show_bug.cgi?id=1583100
  [ 18 ] Bug #1575237 - SELinux is preventing gssproxy from 'read' accesses on 
the lnk_file exe.
        https://bugzilla.redhat.com/show_bug.cgi?id=1575237
  [ 19 ] Bug #1583144 - SELinux is preventing systemd from 'unlink' accesses on 
the archivo adb.0.log.
        https://bugzilla.redhat.com/show_bug.cgi?id=1583144
  [ 20 ] Bug #1582885 - SELinux is preventing imapd from 'create' accesses on 
the directory n.
        https://bugzilla.redhat.com/show_bug.cgi?id=1582885
  [ 21 ] Bug #1576998 - SELinux is preventing kworker/u8:4 from using the 
'dac_override' capabilities.
        https://bugzilla.redhat.com/show_bug.cgi?id=1576998
  [ 22 ] Bug #1575582 - SELinux is preventing (geoclue) from using the 
'nnp_transition' accesses on a process.
        https://bugzilla.redhat.com/show_bug.cgi?id=1575582
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-743a9247de' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]/message/WJ3QXJHI27ENQ3LH2VRTEDTBNOXMYQG3/

Reply via email to