--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-9520
2012-06-15 23:09:10
--------------------------------------------------------------------------------

Name        : selinux-policy
Product     : Fedora 17
Version     : 3.10.0
Release     : 130.fc17
URL         : http://oss.tresys.com/repos/refpolicy/
Summary     : SELinux policy configuration
Description :
SELinux Reference Policy - modular.
Based off of reference policy: Checked out revision  2.20091117

--------------------------------------------------------------------------------
Update Information:

- Dontaudit logwatch to gettr on /dev/dm-2 - Allow policykit-auth to manage 
kerberos files - Allow systemd_logind_t to signal, signull, sigkill all 
processes - Add filetrans rules for etc_runtime files - Allow systemd_login to 
send signals to devicekit power - Allow systemd_logind to signal initrc scripts 
to handle third party packages running as initrc_t - Allow virsh to read 
/etc/passwd - Allow policykit to manage kerberos rcache files - Allow 
systemd-logind to send a signal to init_t - /usr/sbin/xl2tpd wants to read 
/etc/group - Allow ncftool to list of content /etc/modprobe.d - Allow 
dkim-milter to listen own tcp_socke
- Allow collectd to read virt config - Allow collectd setsched - Add support 
for /usr/sbin/mdm* - Fix java binaries labels when installed under 
/usr/lib/jvm/java - Add labeling for /var/run/mdm - Allow apps that can read 
net_conf_t files read symlinks - Allow all domains that can search or read 
tmp_t, able to read a tmp_t link - Dontaudit mozilla_plugin looking at 
xdm_tmp_t - Looks like collectd needs to change it scheduling priority - Allow 
uux_t to access nsswitch data - New labeling for samba, pid dirs moved to 
subdirs of samba - Allow nova_api to use nsswitch - Allow mozilla_plugin to 
execute files labeled as lib_t - Label content under HOME_DIR/zimbrauserdata as 
mozilla_home date - abrt is fooled into reading mozilla_plugin content, we want 
to dontaudit - Allow mozilla_plugin to connect to ircd ports since a plugin 
might be a irc chat window - Allow winbind to create content in smbd_var_run_t 
directories - Allow setroubleshoot_fixit to read the selinux policy store. No 
reason to deny it - Support libvirt plugin for collectd
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jun 11 2012 Miroslav Grepl <[email protected]> 3.10.0-130
- Dontaudit logwatch to gettr on /dev/dm-2
- Allow policykit-auth to manage kerberos files
- Allow systemd_logind_t to signal, signull, sigkill all processes
- Add filetrans rules for etc_runtime files
- Allow systemd_login to send signals to devicekit power
- Allow systemd_logind to signal initrc scripts to handle third party packages 
running as initrc_t
- Allow virsh to read /etc/passwd
- Allow policykit to manage kerberos rcache files
- Allow systemd-logind to send a signal to init_t
- /usr/sbin/xl2tpd wants to read /etc/group
- Allow ncftool to list of content /etc/modprobe.d
- Allow dkim-milter to listen own tcp_socke
* Fri Jun  8 2012 Miroslav Grepl <[email protected]> 3.10.0-129
- Allow collectd to read virt config
- Allow collectd setsched
- Add support for /usr/sbin/mdm*
- Fix java binaries labels when installed under /usr/lib/jvm/java
- Add labeling for /var/run/mdm
- Allow apps that can read net_conf_t files read symlinks
- Allow all domains that can search or read tmp_t, able to read a tmp_t link
- Dontaudit mozilla_plugin looking at xdm_tmp_t
- Looks like collectd needs to change it scheduling priority
- Allow uux_t to access nsswitch data
- New labeling for samba, pid dirs moved to subdirs of samba
- Allow nova_api to use nsswitch
- Allow mozilla_plugin to execute files labeled as lib_t
- Label content under HOME_DIR/zimbrauserdata as mozilla_home date
- abrt is fooled into reading mozilla_plugin content, we want to dontaudit
- Allow mozilla_plugin to connect to ircd ports since a plugin might be a irc 
chat window
- Allow winbind to create content in smbd_var_run_t directories
- Allow setroubleshoot_fixit to read the selinux policy store.  No reason to 
deny it
- Support libvirt plugin for collectd
* Wed May 30 2012 Miroslav Grepl <[email protected]> 3.10.0-128
- Fix description of authlogin_nsswitch_use_ldap
- Fix transition rule for rhsmcertd_t needed for RHEL7
- Allow useradd to list nfs state data
- Allow openvpn to manage its log file and directory
- We want vdsm to transition to mount_t when executing mount command to make 
sure /etc/mtab remains labeled correctly
- Allow thumb to use nvidia devices
-  Allow local_login to create user_tmp_t files for kerberos
- Pulseaudio needs to read systemd_login /var/run content
- virt should only transition named system_conf_t config files
- Allow  munin to execute its plugins
- Allow nagios system plugin to read /etc/passwd
- Allow plugin to connect to soundd port
- Fix httpd_passwd to be able to ask passwords
- Radius servers can use ldap for backing store
- Seems to need to mount on /var/lib for xguest polyinstatiation to work.
- Allow systemd_logind to list the contents of gnome keyring
- VirtualGL need xdm to be able to manage content in /etc/opt/VirtualGL
- Add policy for isns-utils
* Mon May 28 2012 Miroslav Grepl <[email protected]> 3.10.0-127
- Add policy for subversion daemon
- Allow boinc to read passwd
- Allow pads to read kernel network state
- Fix man2html interface for sepolgen-ifgen
- Remove extra /usr/lib/systemd/system/smb
- Remove all /lib/systemd and replace with /usr/lib/systemd
- Add policy for man2html
- Fix the label of kerberos_home_t to krb5_home_t
- Allow mozilla plugins to use Citrix
- Allow tuned to read /proc/sys/kernel/nmi_watchdog
- Allow tune /sys options via systemd's tmpfiles.d "w" type
* Wed May 23 2012 Miroslav Grepl <[email protected]> 3.10.0-126
- Dontaudit lpr_t to read/write leaked mozilla tmp files
- Add file name transition for .grl-podcasts directory
- Allow corosync to read user tmp files
- Allow fenced to create snmp lib dirs/files
- More fixes for sge policy
- Allow mozilla_plugin_t to execute any application
- Allow dbus to read/write any open file descriptors to any non security file 
on the system that it inherits to that it can pass them to another domain
- Allow mongod to read system state information
-  Fix wrong type, we should dontaudit sys_admin for xdm_t not xserver_t
- Allow polipo to manage polipo_cache dirs
- Add jabbar_client port to mozilla_plugin_t
- Cleanup procmail policy
- system bus will pass around open file descriptors on files that do not have 
labels on them
- Allow l2tpd_t to read system state
- Allow tuned to run ls /dev
- Allow sudo domains to read usr_t files
- Add label to machine-id 
- Fix corecmd_read_bin_symlinks cut and paste error
* Wed May 16 2012 Miroslav Grepl <[email protected]> 3.10.0-125
- Fix pulseaudio port definition
- Add labeling for condor_starter
- Allow chfn_t to creat user_tmp_files
- Allow chfn_t to execute bin_t
- Allow prelink_cron_system_t to getpw calls
- Allow sudo domains to manage kerberos rcache files
- Allow user_mail_domains to work with courie
- Port definitions necessary for running jboss apps within openshift
-  Add support for openstack-nova-metadata-api
- Add support for nova-console*
- Add support for openstack-nova-xvpvncproxy
- Fixes to make privsep+SELinux working if we try to use chage to change passwd
- Fix auth_role() interface
- Allow numad to read sysfs
- Allow matahari-rpcd to execute shell
- Add label for ~/.spicec
- xdm is executing lspci as root which is requesting a sys_admin priv but seems 
to succeed without it
- Devicekit_disk wants to read the logind sessions file when writing a cd
- Add fixes for condor to make condor jobs working correctly
- Change label of /var/log/rpmpkgs to cron_log_t
- Access requires to allow systemd-tmpfiles --create to work.
- Fix obex to be a user application started by the session bus.
- Add additional filename trans rules for kerberos
- Fix /var/run/heartbeat labeling
- Allow apps that are managing rcache to file trans correctly
- Allow openvpn to authenticate against ldap server
- Containers need to listen to network starting and stopping events
* Wed May  9 2012 Miroslav Grepl <[email protected]> 3.10.0-124
- Make systemd unit files less specific
* Mon May  7 2012 Miroslav Grepl <[email protected]> 3.10.0-123
- Fix zarafa labeling
- Allow guest_t to fix labeling
- corenet_tcp_bind_all_unreserved_ports(ssh_t) should be called with the 
user_tcp_server boolean
- add lxc_contexts
- Allow accountsd to read /proc
- Allow restorecond to getattr on all file sytems
- tmpwatch now calls getpw
- Allow apache daemon to transition to pwauth domain
- Label content under /var/run/user/NAME/keyring* as gkeyringd_tmp_t
- The obex socket seems to be a stream socket
- dd label for /var/run/nologin
* Mon May  7 2012 Miroslav Grepl <[email protected]> 3.10.0-122
- Allow jetty running as httpd_t to read hugetlbfs files
- Allow sys_nice and setsched for rhsmcertd
- Dontaudit attempts by mozilla_plugin_t to bind to ssdp ports
- Allow setfiles to append to xdm_tmp_t
- Add labeling for /export as a usr_t directory
- Add labels for .grl files created by gstreamer
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #824098 - SELinux is preventing /usr/bin/lpstat.cups from 'write' 
accesses on the sock_file pkcs11.
        https://bugzilla.redhat.com/show_bug.cgi?id=824098
  [ 2 ] Bug #826751 - SELinux is preventing /usr/sbin/sendmail.sendmail from 
'read' accesses on the file smb.conf.
        https://bugzilla.redhat.com/show_bug.cgi?id=826751
  [ 3 ] Bug #827155 - SELinux is preventing 
/usr/lib64/xulrunner-2/plugin-container from 'rename' accesses on the file 
/home/gabriel/.macromedia/Flash_Player/#SharedObjects/4XCE67AA/s.ytimg.com/videostats.sxx.
        https://bugzilla.redhat.com/show_bug.cgi?id=827155
  [ 4 ] Bug #827568 - selinux is preventing dovecot-imap from accessing Maildir
        https://bugzilla.redhat.com/show_bug.cgi?id=827568
  [ 5 ] Bug #827592 - SELinux is preventing /usr/bin/chsh from 'execute' 
accesses on the file tmux.
        https://bugzilla.redhat.com/show_bug.cgi?id=827592
  [ 6 ] Bug #827712 - SELinux is preventing /usr/bin/totem-video-thumbnailer 
from 'execute' accesses on the file /run/user/dario/.orc/orcexec.iMG9e3 
(deleted).
        https://bugzilla.redhat.com/show_bug.cgi?id=827712
  [ 7 ] Bug #827732 - SELinux is preventing 
/opt/google/talkplugin/GoogleTalkPlugin from 'getattr' accesses on the 
fifo_file /dev/initctl.
        https://bugzilla.redhat.com/show_bug.cgi?id=827732
  [ 8 ] Bug #827733 - SELinux is preventing 
/opt/google/talkplugin/GoogleTalkPlugin from 'getattr' accesses on the file 
/proc/kcore.
        https://bugzilla.redhat.com/show_bug.cgi?id=827733
  [ 9 ] Bug #827813 - SELinux policy breaks os.path for cobbler
        https://bugzilla.redhat.com/show_bug.cgi?id=827813
  [ 10 ] Bug #828062 - SELinux is preventing /usr/sbin/sysctl from 'write' 
accesses on the file nmi_watchdog.
        https://bugzilla.redhat.com/show_bug.cgi?id=828062
  [ 11 ] Bug #828085 - SELinux is preventing /usr/bin/esmtp from 'execute' 
accesses on the file /usr/bin/bash.
        https://bugzilla.redhat.com/show_bug.cgi?id=828085
  [ 12 ] Bug #828094 - SELinux is preventing /usr/bin/esmtp from 'read' 
accesses on the file /root/.esmtp_queue/v8Vg0Ha4/mail.
        https://bugzilla.redhat.com/show_bug.cgi?id=828094
  [ 13 ] Bug #828320 - SELinux is preventing /usr/bin/bash from 'read' accesses 
on the file /etc/passwd.
        https://bugzilla.redhat.com/show_bug.cgi?id=828320
  [ 14 ] Bug #828619 - SELinux is preventing /usr/sbin/winbindd from 'write' 
accesses on the directory samba.
        https://bugzilla.redhat.com/show_bug.cgi?id=828619
  [ 15 ] Bug #828695 - SELinux is preventing /usr/bin/totem-video-thumbnailer 
from 'execute' accesses on the file /home/vydral/.orc/orcexec.0Pjr6i (deleted).
        https://bugzilla.redhat.com/show_bug.cgi?id=828695
  [ 16 ] Bug #828862 - SELinux is preventing /usr/bin/totem-video-thumbnailer 
from 'execute' accesses on the file /home/zoli/.orc/orcexec.5VEYDB (deleted).
        https://bugzilla.redhat.com/show_bug.cgi?id=828862
  [ 17 ] Bug #828988 - SELinux is preventing 
/opt/google/talkplugin/GoogleTalkPlugin from 'read' accesses on the file 
.Xauth13DgPb.
        https://bugzilla.redhat.com/show_bug.cgi?id=828988
  [ 18 ] Bug #829006 - SELinux is preventing 
/usr/lib64/nspluginwrapper/npviewer.bin from 'write' accesses on the file 
/home/richard/.nv/GLCache/c4e629e7ad097b2afebf55a6b779ec93/32fd9331b92aa1d3/149e6d932a00536e.toc.
        https://bugzilla.redhat.com/show_bug.cgi?id=829006
  [ 19 ] Bug #829050 - SELinux is preventing /usr/bin/gdb from 'read' accesses 
on the file nswrapper_64_64.libflashplayer.so.
        https://bugzilla.redhat.com/show_bug.cgi?id=829050
  [ 20 ] Bug #829081 - SELinux is preventing /usr/bin/python2.7 from 'create' 
accesses on the netlink_route_socket .
        https://bugzilla.redhat.com/show_bug.cgi?id=829081
  [ 21 ] Bug #829093 - SELinux is preventing /usr/bin/python2.7 from 'bind' 
accesses on the netlink_route_socket .
        https://bugzilla.redhat.com/show_bug.cgi?id=829093
  [ 22 ] Bug #829094 - SELinux is preventing /usr/sbin/ldconfig from 'execute' 
accesses on the file /usr/sbin/ldconfig.
        https://bugzilla.redhat.com/show_bug.cgi?id=829094
  [ 23 ] Bug #829095 - SELinux is preventing /usr/bin/bash from 'getattr' 
accesses on the file /etc/passwd.
        https://bugzilla.redhat.com/show_bug.cgi?id=829095
  [ 24 ] Bug #829410 - Selinux reports problems from gnash when using Youtube 
or Gmail
        https://bugzilla.redhat.com/show_bug.cgi?id=829410
  [ 25 ] Bug #829465 - SELinux is preventing /usr/bin/python2.7 from 'getattr' 
accesses on the file /etc/selinux/targeted/policy/policy.27.
        https://bugzilla.redhat.com/show_bug.cgi?id=829465
  [ 26 ] Bug #829468 - SELinux is preventing /usr/bin/python2.7 from 'read' 
accesses on the file /etc/selinux/targeted/policy/policy.27.
        https://bugzilla.redhat.com/show_bug.cgi?id=829468
  [ 27 ] Bug #829477 - SELinux is preventing 
/usr/lib64/xulrunner-2/plugin-container from 'name_connect' accesses on the 
tcp_socket .
        https://bugzilla.redhat.com/show_bug.cgi?id=829477
  [ 28 ] Bug #829725 - collectd with libvirt plugin needs to access 
libvirtd.conf
        https://bugzilla.redhat.com/show_bug.cgi?id=829725
  [ 29 ] Bug #829954 - SELinux is preventing /usr/bin/uux from 'getattr' 
accesses on the file /etc/passwd.
        https://bugzilla.redhat.com/show_bug.cgi?id=829954
  [ 30 ] Bug #830016 - SELinux is preventing /usr/sbin/collectd from using the 
'sys_nice' capabilities.
        https://bugzilla.redhat.com/show_bug.cgi?id=830016
  [ 31 ] Bug #830366 - SELinux is preventing 
/usr/lib/nspluginwrapper/npviewer.bin from 'rename' accesses on the file 
/home/roger/.macromedia/Flash_Player/#SharedObjects/LJ6K3K6K/s.ytimg.com/videostats.sxx.
        https://bugzilla.redhat.com/show_bug.cgi?id=830366
  [ 32 ] Bug #830461 - SELinux is preventing /usr/sbin/xl2tpd from 'open' 
accesses on the file /etc/group.
        https://bugzilla.redhat.com/show_bug.cgi?id=830461
  [ 33 ] Bug #830476 - SELinux is preventing /usr/lib/systemd/systemd-logind 
from using the 'signal' accesses on a process.
        https://bugzilla.redhat.com/show_bug.cgi?id=830476
  [ 34 ] Bug #830522 - SELinux is preventing /usr/bin/ncftool from 'read' 
accesses on the directory /etc/modprobe.d.
        https://bugzilla.redhat.com/show_bug.cgi?id=830522
  [ 35 ] Bug #830611 - selinux policy prevents dovecot domains access to 
mail_home_rw_t (Maildir)
        https://bugzilla.redhat.com/show_bug.cgi?id=830611
  [ 36 ] Bug #830634 - SELinux is preventing /usr/libexec/totem-plugin-viewer 
from 'rmdir' accesses on the directory 
/home/ksugawar/.nv/GLCache/7627299e856060b7a1cf3345db62a833.
        https://bugzilla.redhat.com/show_bug.cgi?id=830634
  [ 37 ] Bug #830693 - SELinux is preventing /usr/bin/python2.7 from 'getattr' 
accesses on the file /usr/lib/systemd/system/nmb.service.
        https://bugzilla.redhat.com/show_bug.cgi?id=830693
  [ 38 ] Bug #830712 - SELinux is preventing 
/usr/libexec/polkit-1/polkit-agent-helper-1 from read, write access on the file 
host_0.
        https://bugzilla.redhat.com/show_bug.cgi?id=830712
  [ 39 ] Bug #830804 - SELinux is preventing /usr/lib/systemd/systemd-logind 
from using the 'signal' accesses on a process.
        https://bugzilla.redhat.com/show_bug.cgi?id=830804
  [ 40 ] Bug #830882 - SELinux is preventing 
/usr/libexec/gstreamer-0.10/gst-plugin-scanner from 'execute' accesses on the 
file /run/user/tneuber/.orc/orcexec.nqWUoY (deleted).
        https://bugzilla.redhat.com/show_bug.cgi?id=830882
  [ 41 ] Bug #826071 - Selinux denies check_sensors access to password file
        https://bugzilla.redhat.com/show_bug.cgi?id=826071
  [ 42 ] Bug #826674 - [abrt] openstack-glance-2012.1-4.fc17: 
client.py:549:_do_request:ServerError: The request returned 500 Internal Server 
Error
        https://bugzilla.redhat.com/show_bug.cgi?id=826674
  [ 43 ] Bug #826784 - SELinuxs prevents Nagios check_procs plugin from 
accessing password file
        https://bugzilla.redhat.com/show_bug.cgi?id=826784
  [ 44 ] Bug #827637 - SELinux prevents postgrey from starting
        https://bugzilla.redhat.com/show_bug.cgi?id=827637
  [ 45 ] Bug #828097 - security-policy-targeted rpm postinst script traverses 
mounted media
        https://bugzilla.redhat.com/show_bug.cgi?id=828097
  [ 46 ] Bug #829298 - avc in nfs4 setup
        https://bugzilla.redhat.com/show_bug.cgi?id=829298
  [ 47 ] Bug #829802 - sysnet_read_config does not allow reading symlinks
        https://bugzilla.redhat.com/show_bug.cgi?id=829802
  [ 48 ] Bug #830527 - milter.if is not prepared for communication over tcp 
sockets
        https://bugzilla.redhat.com/show_bug.cgi?id=830527
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update selinux-policy' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
[email protected]
https://admin.fedoraproject.org/mailman/listinfo/package-announce

Reply via email to