-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2011-3576 2011-03-18 02:39:20 --------------------------------------------------------------------------------
Name : selinux-policy Product : Fedora 15 Version : 3.9.16 Release : 5.fc15 URL : http://oss.tresys.com/repos/refpolicy/ Summary : SELinux policy configuration Description : SELinux Reference Policy - modular. Based off of reference policy: Checked out revision 2.20091117 -------------------------------------------------------------------------------- Update Information: - Fix multiple specification for boot.log - devicekit leaks file descriptors to setfiles_t - Change all all_nodes to generic_node and all_if to generic_if - Should not use deprecated interface - Switch from using all_nodes to generic_node and from all_if to generic_if - Add support for xfce4-notifyd - Fix file context to show several labels as SystemHigh - seunshare needs to be able to mounton nfs/cifs/fusefs homedirs - Add etc_runtime_t label for /etc/securetty - Fixes to allow xdm_t to start gkeyringd_USERTYPE_t directly - login.krb needs to be able to write user_tmp_t - dirsrv needs to bind to port 7390 for dogtag - Fix a bug in gpg policy - gpg sends audit messages - Allow qpid to manage matahari files -------------------------------------------------------------------------------- References: [ 1 ] Bug #683578 - Extra policy required for colord https://bugzilla.redhat.com/show_bug.cgi?id=683578 [ 2 ] Bug #683830 - Selinux avc for systemd-tty-ask during boot https://bugzilla.redhat.com/show_bug.cgi?id=683830 [ 3 ] Bug #683832 - Selinux AVC for systemd-tmpfile during boot https://bugzilla.redhat.com/show_bug.cgi?id=683832 [ 4 ] Bug #683963 - SELinux is preventing /usr/libexec/gsd-datetime-mechanism from 'getattr' accesses on the sistema de archivos /. https://bugzilla.redhat.com/show_bug.cgi?id=683963 [ 5 ] Bug #684067 - SELinux is preventing /usr/libexec/hald-addon-storage from 'read' accesses on the lnk_file /etc/mtab. https://bugzilla.redhat.com/show_bug.cgi?id=684067 [ 6 ] Bug #684396 - SELinux is preventing /usr/sbin/wpa_supplicant from 'write' accesses on the netlink_socket Unknown. https://bugzilla.redhat.com/show_bug.cgi?id=684396 [ 7 ] Bug #684420 - SELinux is preventing /bin/systemd-tmpfiles from 'getattr' accesses on the blk_file /tmp/initrd.yvQczh/dev/ram1. https://bugzilla.redhat.com/show_bug.cgi?id=684420 [ 8 ] Bug #684901 - SELinux is preventing /usr/bin/python from 'setattr' accesses on the directory /proc. https://bugzilla.redhat.com/show_bug.cgi?id=684901 [ 9 ] Bug #685120 - SELinux is preventing /bin/systemd-tmpfiles from 'getattr' accesses on the blk_file /tmp/initrd.xlJhLZ/dev/ram0. https://bugzilla.redhat.com/show_bug.cgi?id=685120 [ 10 ] Bug #685122 - SELinux is preventing /bin/systemd-tmpfiles from 'getattr' accesses on the chr_file /tmp/initrd.xlJhLZ/dev/tty0. https://bugzilla.redhat.com/show_bug.cgi?id=685122 [ 11 ] Bug #688042 - avc: denied { write } for pid=438 comm="systemd-readahe" https://bugzilla.redhat.com/show_bug.cgi?id=688042 [ 12 ] Bug #688043 - avc: denied { read } for pid=779 comm="systemd-tmpfile" https://bugzilla.redhat.com/show_bug.cgi?id=688043 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update selinux-policy' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list [email protected] https://admin.fedoraproject.org/mailman/listinfo/package-announce
