--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2019-7d65c50fd6
2019-10-29 01:27:04.179111
--------------------------------------------------------------------------------

Name        : selinux-policy
Product     : Fedora 31
Version     : 3.14.4
Release     : 39.fc31
URL         : https://github.com/fedora-selinux/selinux-policy
Summary     : SELinux policy configuration
Description :
SELinux Base package for SELinux Reference Policy - modular.
Based off of reference policy: Checked out revision  2.20091117

--------------------------------------------------------------------------------
Update Information:

More info: https://koji.fedoraproject.org/koji/buildinfo?buildID=1404708  ----
More info: https://koji.fedoraproject.org/koji/buildinfo?buildID=1403635
--------------------------------------------------------------------------------
ChangeLog:

* Fri Oct 25 2019 Lukas Vrabec <[email protected]> - 3.14.4-39
- Allow confined users to run newaliases
- Add interface mysql_dontaudit_rw_db()
- Label /var/lib/xfsdump/inventory as amanda_var_lib_t
- Allow tmpreaper_t domain to read all domains state
- Make httpd_var_lib_t label system mountdir attribute
- Update cockpit policy
- Allow nagios_script_t domain list files labled sysfs_t.
- Allow jetty_t domain search and read cgroup_t files.
- Donaudit ifconfig_t domain to read/write mysqld_db_t files
- Dontaudit domains read/write leaked pipes
* Tue Oct 22 2019 Lukas Vrabec <[email protected]> - 3.14.4-38
- Allow nagios_script_t domain list files labled sysfs_t.
- Allow jetty_t domain search and read cgroup_t files.
- Allow Gluster mount client to mount files_type
- Dontaudit and disallow sys_admin capability for keepalived_t domain
- Update numad policy to allow signull, kill, nice and trace processes
- Allow ipmievd_t to RW watchdog devices
- Update allow rules set for pads_t domain
- Allow networkmanager_t domain domain transition to chronyc_t domain 
BZ(1760226)
- Update apache and pkcs policies to make active opencryptoki rules
- Allow ldconfig_t domain to manage initrc_tmp_t link files Allow netutils_t 
domain to write to initrc_tmp_t fifo files
- Allow user domains to manage user session services
- Allow staff and user users to get status of user systemd session
- Update sudo_role_template() to allow caller domain to read syslog pid files
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1754219 - SELinux is preventing /usr/sbin/groupadd from read 
access on the fifo_file fifo_file
        https://bugzilla.redhat.com/show_bug.cgi?id=1754219
  [ 2 ] Bug #1753239 - SELinux is preventing timedatex from 'write' accesses on 
the directory /etc.
        https://bugzilla.redhat.com/show_bug.cgi?id=1753239
  [ 3 ] Bug #1761765 - Cannot lock down cockpit.service: avc:  denied  { 
mounton } / { nnp_transition }
        https://bugzilla.redhat.com/show_bug.cgi?id=1761765
  [ 4 ] Bug #1754397 - SELinux is preventing timedatex from using the 
'sys_time' capabilities.
        https://bugzilla.redhat.com/show_bug.cgi?id=1754397
  [ 5 ] Bug #1754800 - SELinux is preventing timedatex from 'execute' accesses 
on the file /usr/sbin/hwclock.
        https://bugzilla.redhat.com/show_bug.cgi?id=1754800
  [ 6 ] Bug #1755828 - SELinux prevents bitlbee from mmap()-ing the 
/usr/share/p11-kit/modules/p11-kit-trust.module file
        https://bugzilla.redhat.com/show_bug.cgi?id=1755828
  [ 7 ] Bug #1734188 - SELinux is preventing sssd_be from 'search' accesses on 
the directory /var/kerberos/krb5.
        https://bugzilla.redhat.com/show_bug.cgi?id=1734188
  [ 8 ] Bug #1715597 - Multiple denials for NetworkManager access to 'nsfs' in 
Fedora-Rawhide-20190529.n.0
        https://bugzilla.redhat.com/show_bug.cgi?id=1715597
  [ 9 ] Bug #1701750 - keepalived netlink_connector_socket bind create 
permission
        https://bugzilla.redhat.com/show_bug.cgi?id=1701750
  [ 10 ] Bug #1699911 - dbus-broker-20-2.fc31 (with 
systemd-241-4.gitcbf14c9.fc31) triggers some new AVCs making the system not 
ever finishing boot sequence
        https://bugzilla.redhat.com/show_bug.cgi?id=1699911
  [ 11 ] Bug #1714600 - Mislabeled /dev, causing systemd to cascade crash
        https://bugzilla.redhat.com/show_bug.cgi?id=1714600
  [ 12 ] Bug #1757950 - SELinux prevents opendkim from executing sendmail
        https://bugzilla.redhat.com/show_bug.cgi?id=1757950
  [ 13 ] Bug #1756463 - SELinux is preventing systemd-logind from 'read' 
accesses on the blk_file mmcblk0p1.
        https://bugzilla.redhat.com/show_bug.cgi?id=1756463
  [ 14 ] Bug #1757043 - SELinux prevents the pads service from starting
        https://bugzilla.redhat.com/show_bug.cgi?id=1757043
  [ 15 ] Bug #1622115 - SELinux is preventing sealert from 'read' accesses on 
the chr_file random.
        https://bugzilla.redhat.com/show_bug.cgi?id=1622115
  [ 16 ] Bug #1752826 - SELinux is preventing systemd-logind from 'read' 
accesses on the directory entries.
        https://bugzilla.redhat.com/show_bug.cgi?id=1752826
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2019-7d65c50fd6' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]

Reply via email to