From 0ab5f5b469ffc3a9b3e60ab102f3361859abc221 Mon Sep 17 00:00:00 2001 From: Lukas Vrabec Date: Thu, 4 Aug 2016 11:15:29 +0200 Subject: [PATCH] * Thu Aug 04 2016 Lukas Vrabec 3.13.1-207 - Fix filesystem inteface file, we don't have nsfs_fs_t type, just nsfs_t --- docker-selinux.tgz | Bin 4316 -> 4316 bytes policy-rawhide-base.patch | 6 +++--- selinux-policy.spec | 5 ++++- 3 files changed, 7 insertions(+), 4 deletions(-) diff --git a/docker-selinux.tgz b/docker-selinux.tgz index ec8f1874897edfe399623e4255c7fdc11c71be89..3a576e957f71f19110075a64f360d2a31797f327 100644 GIT binary patch literal 4316 zcmV<25F_s&iwFSr2BTL11MOVvkJ~m9&sY1e5RwAfJtX_cwkfb_dpNZB;XWKtT>G(r zDoeDju3jfn>-7cs-*1L5Q531i+M8_eEFiHh&iqIYN5h%nXp=I&BlShPe(`kI6WuTwTBW=IZ7}aP@>^(pN)SR0qL}?7ogx zB=*vcwf{-4<*Qf0ceKg#sNVnZ>y`v%MT)nyZ0eW=4g19VLloq58NU?#> zi|;NK+Y&&gU7g~}Gg5IW(^uiyN>Tx>`Y z*5uz!S_8pyv0(d3jX7j*)HecC3)zR|;`RA*xrob}#CZ}@64miGT&2a?SJ&sug#r$% zh(V`#*Fw-g+4&Nojx6gKBV3pEYNi84{4WwErhNHAep$)ZFeE-VK9>3N_3Gk+Ba3E-nbkl~ zDrCBiYVvHv%ttd((1Lb?n6s2JRA8r+C5rufbah7fvf}O$ywg{;x2AvNPciPCv?6i3 zPDvs+Pu%rL*K+X=6S3;ZeBhq@ROajeZE)GBM~K-W=zm5-V)Hvb$tXfB64Ph__MxQTF{yRyV#WBB|BwiloJ6Qn!w0LfNlr zF|G57@J6kM)_?U5{@uX8uaD?R{rr!gp2JSSy^ktQX6yrXQ+TWj;LxeADo5$xIc~^B zNqv8KK4wtty&S=;Aa_q0$zzs{CuBZYH<}`4T*B>I2(&~xLke0fNQ&e&$x8H^K`JRI z3vUVJrI_W)txEx3fu-0bxHbaEj{b~c+~P-|S6;_|Lo9MAf!u=RPsO@iRG>d~iHhyg zqoV{iQIQ0@I_-J8Imuz$`NB`<4n&eqQVwTqjsngDfue*uLt?hTg20lP@l;i8KX;D} zEO4*Lf;oA&hJyaEJ-213*j>RXbvMPAko$^Jlp?mEeDKqjrJ}lxw{<8~eHTLK#}O=E zA|`92FtIBt0b}Nx6l{)o@#=RoAZE@mUDWLcik&B+93o17qUeo1+10G0G;HXod{%C_ z+PeVd2IT_WmN~H(T5eNv59IUlY*yI*CU_|tE`a0Z`Ah@~cfu|V-kOaAZm~vq8)qp< zU1ES>HsDfm0Xb2)*4KR1p-F@2EY_=%1&xXX@Ksm)6E4b?vI1FEh(eN zgW_K9QP65a%k2IF=X)TaSOnbJB@mdt8Vo=fC3#v1UB^VMb1}t}pg=D4QXUr2l|>u6Q|4`<-K>_(=|tJH(cGN`tg zQGjFILdeLfTnf#+8RwN#w&UCpK4Z;CVoen|;#1s<8dWkXtja8n_gpPid@BQ5h&BtR zQvT;g`$+uz`ltztFlyLV9_4ql6ujj*l{4^>POcx})a^rVO!JUR5(B1t@36Bl$C?~k zR`L`US51DJ@E>1UVz3`0zk*^^HkLA;?_cBgYIq}G+~p95$vC(XcSFh3vn6nvWBbrT zA)l$k#+7BJH*Fb*Dr;bSIihE61CBS$HzJOO>!g=?)?rmPMMAj|!BdXoSaWeuqv7Y; z@pfF((~8DiR1<8=hdaQqyGO-dVajb#%nv+X*r4luRl*d6qnuJH!Oy4g@VzcG5=Ygg zr|v+HaaO5c&$SVaB7@#yatVLw(%L`8C39(vJYgRr_21vVbJTxdzdzM~e~wEy`e9xs z5KEs4ZFm!0UtC>W&9YI;SHVvt&fxJ!9~m5zB{u>Ip|L!%sN`7%!PGx^FTrk0z{RO` znm*$8N#zN6G!LQvuRs1ARAtTdc}68ojethO!I~mk>Cx*A4lLxGU>#+Yz)URj?6NQX zq%Vm`UKXJ+g$mIw>ONnJ_K-HKKf*K#<84%I2)5=tg3^qd60PA7+0t~CBoE#?lb#Xs z%cI7y=9?H*)XTn$@S%Tie3t&u!yKOBZFIBlXPs6{G@;No+0#Okgy2bG=0PjOS8 zmz;G7E$%jfA$pX*`B3{g23M9u@MY@c;jGi#h;wA2*_{6-z^0F$i&60>Qp-oWyy^lD8q*q<^?uevDPWZi~9xW?*k zwhsEKvouc`?~%#_R8Oxu$%6;EM#e{Ekz5?EbTIFtdvgea#noe3o217&%G0jnyI{qi zc-qj46baZ{e*|Y5bZ0qdZ$r_iNnK0ksw|wz+ph$j3NU&a<_EIQ#HP(dnPErncbX6f z00bvt@zC%M{_gSYwDF4#p_l)iHg*rQwfA@iu9!dK!1-}#@JSy|PaXWm{xyB*e%1-v z=VW)E!uxoQd8-bCPv`anZSveIO%`>YU~n0rNaMM#%e*zDX#S?jkZ;!AUsGi`#5zHS zPWG-x;gO)^^hj{>ywTsVf6tivAp5lWkBmU>P6uG9vZVtcR@vic;#Owa%wHWdwD-eO zC#HQpfPR?1qhCG5a7@!OHW*#tm6uJy%3|vC<9$zOnjVd@PtYSTgnPoWd9E?>uZ`~S zmAv7p5OX*f!=fF02VuH`Pl1`BOnkXatA5}z*R zF$i6fcOcHh)$+o)ivNZXT(Z@3;Zk<5f4`2^TJ)WMlG>;WLoNIECmG4gV8jS$+wmHq zE&MD<6AMMrQHcHk^Ip@Y>#3A;P%+u*q2(jx^2LOxhe)MAw~SRoV2Um-^SsK) zL&&A?Vc;S3r1?83J@fC-4$TV*r!14EbAd@i!L`ar2AU*-qSZi|D-lWvHg_Va4T~O^ z=yp?=P1WyKHVZ$B?(-}y?koa%oEvrY818ra?Q}|6S)+Zeqg}`oH4orNBq_Z!iFgtN zpUZ;MUCQFE(I_id>=}Zul9W3WM7|@VN&$=}-hwxq&d}PzC|oO!p3{v<(xCuTguxq- zbo`%`#>SHJTyU%m(SY95`au>AN$hw$+0;(o;GkFm^SCh4%W z#?9~4Y=kd#pH}er7VFaG_WZjcl!g2q!OlslK_mwl=Ad3+l^uSSqHs7+4hpY())d?& z1zXSSAv&jsJ(AvotxK_%;DMT(i|MEtEiepBBv7lF8>$A76IVla&#eNhOB)v7xI@JL z?W`;-Ka(3#ZqjP3DTNpT#o^w|WjHdI%I!n+$XvU+n^K44%jOdy_!7S1f<9?<+kAp6-x&s~ohaRmrm{ z(B#JWM+HLG?R$x)4LqUN9RPbs;ilyd@$+5b^YPWwC%YY|s->%0sDG&!tPMnU8s+sS zG=cDty;TARsg5l1MnA4>$%M#SNP8MiN|kw^L})3f%ct5@?b^b3d>dfY4@*`JRoMdk zDqeLo9Y;|J!rQh{zeOyJD0|0>e_Ta#oP+NQXjnXSNjsZ>iztucZCZ3TUr|5l>SLYO zWCv@PxCj5*E0RX}St6*K$=-*4O_VtO7icwp`e4~q-^k}3-GCMN5 zcqORdp@=ZlkVIGzk@7-QV=%T4YYspzuA`Dd9H%Tg#BGIXi@)HjEo;#9V#{Wu7EQfY z@5;fr(iJ9cH%Su3{JlFjX(y-T!kt%p3{e`sa^S3d;hrJ}W|n_#9cl!h`sKMpNtmyT9-VwQt;On+wjjD;5lAk==si0Y#9Z0Hxzn7nYF}(G_HERg!zRQ159B9UzUoUE*yRK2tgv)ql)%FtqpN>G8+| zhf$-T;|EjY=O}ui@481qcD_Kz{JuGln57K^uUr=iH#krBlLd0UkCW!B{6t+0{PG0pd!H86Nd64;0TSojuS zx>NE~_H!ZA8Pmsa6v21L@5Hy~q5FGmcgssK@Dlv&^5QS&e_c!i(gm~v1@<&U>a&nq zx0cUeA>B0)T(M&yNlmz4Q;9YV)(sXrvO+}IxgR@AvFYovwMf6=AIO@nGb32&KmZs$ z0+{@JS;w2{rO;bC3$f=n89E0Pm)S!+3s2Tin<$${fcUik60>Quuv8r9Qrq^`e?YwC zf2!+AP|+_t0x+Nn)9@SqeX{v@UwU^uU8n1Govzb$x=z>WI$fvhbe*o#b-MmHuKxlX KwqXDOcmMzg#FT~r literal 4316 zcmV<25F_s&iwFRTS)f+{1MOVvkJ~m9&sY1e5RwAfJtX_ctH7r1;n3cP`*1*U?Z*PD zEYY^QdYwqE*B9h}zZt$nQKTMgZ?e6!fW)>q^CLMN4QGaSC2R*eKnLtbr3wu?&@eo zVlUlT`=9h$zIYLQN1Hs4>irMDZb?v9qEdG8^;)anR;c6J9MZmWDS5oHC;{|8BG`NEAs;G|gpontv{c}O} z{D&U)PrMZqV8PR9j$$x-3^GA$UX*HKK)eiuUtp%c#h^40Il#fB7N zP5#}aH4rQp3%0M+m_znTeIqcnkbPV(UY;+Pi@2;woF^eAQ5|o?Ra%^VbA7&CDB!S) z7<7tvEd>3Ooi7pU$g++>K2J;5IPFn6Pm^vO6`Zm!)dOYu3-3sYGD}xM0;7ysS*L`~ zkm6!UicuUB%Fz}x#3y9{V;U9WT~s4oD@WdQ@Xd9P;0C4_NM!gLR;11;aIMpfP}QZR z=Au8Qrame0a`pK#!gXn{W;#&B{~}Rh%9k(X*OhDyL*jGeW0@~suP!b)vS@agSq=24 zLZ;iOCQnApd^8gUEodi*IZG)+1$IhVqS(JjS7(GTD{ddaJAGAqYx+0-6ywfGD-x&c zlq7QV#9fbcEf?=F5vz{O2kyC#WzG)J2A7R`fS4VE{%2G~8}h_#RL%$WI95txKg>=k z?!o8b@hn|`v7XF^Z7dnurbk#YpUHbXasLRm53EeN`U7N4(Up&s?4gT}{P#$|OW8Jv zfU032QkKR6pKgY81P$S`VEo!((5Ncja<&_b4@2yqk+e2iH6RLV8CtU@AaiDNFJ zIb8|fFwP=MJzep(eqSphyG!QuhyOo^cpK#(W#2z%b>o{Nl3LxaNLp+rb?bO0l>M3( z(>k9BZ`5jN{Wovm-&^?i?ud@m&;R)8DeMH?`>4`n#y(Itg~zG@4xQ?%a+Lm^_TN z@RmScidnAQx)k6QSc+YOYa?*%=+79&4SocA<#qfw#3F|h$Sp|zRIJNI1^QE$sMsz& zI!a&@6-ltG)1J4RlN`34ul#iGKqUDj<#5L4DBwI0C`za^BxVaN2rP*iPgTYCbNAT5 z0{4n6n3H#FDCiH{b6bXr-4&ctcT;=`xvLmODPjxC2S06DDyo}!TZcl`cOi6s9Kqrx zVzM?06T6}kFlMev!RCk;uYNZJV&)9fMcrg zy$euoP%gl2nG<`V)0yv(Z&qSbbC+x!Dt=Tx>7Hfppah8JA zB?bs)11=R8kQ0SVP9bFXai?#!9^U>{AYk-w08H_w?4*X22I$T@-CU63?l^eck}`Tc zDDLGR1+6Bu%temysI}@-f6s{W> zRUqfbBMSZir_eF%|2&~lsOJgnV_KI*KFbq$goWZGoFBEgb4hCH1_B&w^M_s3ad*?d zDYlg%4_U?+!6$HGYnWm{(@ha&!mA5Df1D7604%q-j#kzGa0brHZe-fLN9GuC`0)>MHbKE=JLQ6;0os?5@O&(%`Jw=$rGXtQ7{ z<$rFpkHo((kD8zeqlRteQGPc|!CRhEIRhW*JIc6XO;T(TpQ6SGUzQPm+;pvt^HG6GMC24Bla;;|NZToe*O3Rt8Y*B-(TVqj((Vz z3B=N8LK|KM*B4h8SF>!?@9?e6j|Lc!G2US@!eV$QCQzM|!aImI`R(kY$g98isDp*GuB`_1qJiF`* zKj}*%l9xp&Orb)wi@ML3qCKR|>W?r@!gw1M8-lGlkDxT8rbKHvM7A_tCCP)g&ZK9A z{PL(VtobHJ74@?3B7E%M8=s{=^e~5KcpKfU`&p;e61j0)A-MS59I?9V%t2*m@l)KC z=Ot$yLW{diV2B>&Z$8w1j=_~B5qz0Cc{uAd_jq_$_94QV*=(y}UK#R$A0`8D>@%!s zhXsCGOi196y?ezR=?;^z?_aw4Z8{64laEr_0)6wWPi679r;OszknPW`7K=e2e)UyN zmnP0LZPG-+%12osOeWlq?q0BH{kI^t29g5KKK;G+j3U~w<(yhHGBhvH6<)f zg8a59lb|3>qyzak2rYGm0l!g4JHTXXfW&N?t2eNGD!p2h4ECoC)2lAZHd(hJ5U#Ph zo2`R>>MYGu#(Sjl0M*m0PV(SEu95K(StJ*SD;>>rW8SL6;PbitK$|=_N|QyMCm37?DAIVY>oRW*DVo1&GUS_e_t#Vz4zW&< zp_9GqQFtUMIXx1bJa6=X3J3*nxyY@TaO{A;88 zdm(RlD#RQP#;|Ay-$9tJ;8S2GDESnaBS1`8@Ie^&qIcfcoU!b_0))?qwHAG+pQJXb!cfb;{aHq`G8i!e+IGA~ zXbV3JlF6eskpbc-ZiX!|Ng#CGmG$i)4L|(f)0kz{L9s&&e>=>I##@pMU}Lmtnkt#l z!U|)46cEKMy#pmoOn6C@;OS3S;V98^qpdT9AbxqLAp>LF6;&n;us5SXHi%RH|# zavyT(dl+~KJ!$?0DsaP;jj>l7S|PplCHv=1PPTg3X;sYQv(( zCA!_zWmEOLmCeGBqWe5ci(8989_L0KJ%;<8emk8~R@P`=>u4A9M9n?;5lKpKO(LGe zz~{1{beFPtYc$Hr6?=x@t0d*l1d;E^s8RrqDRo-y_!cSDl9)f(IGtiI{6rgZI<8fq$Az=NJT0h zmTorF3FFVhCY!oV!+vt5L<4;4g!4KvoBL@XDce^5x&-8MuG{!=jJO|h`eQ8fm`OS; zt#R`^H5=gz-K7;gzQww9xjp}G2xTFEN3e5}Y7of*hB>GgSY?M_r6?Q@l!LC3v9b=3+W(MhgrB6A9F6=7y>Pe7bAH|`Lz ze>*G7%FpCRl$*2~Yf2$TKykSDav6@yrE>caJu=s>?xxh?_&BK!xqGByx1s9&2X1*jVgv5^C(zOq{1#1IQokn@R z2~8k8WN(##L8>E5ywQ&hh^JRlBzE9p45R^}~`?Lshl_ zzlv8KO~+9bg7CI&)Nc_BBg)>f;vZMh9OvM>0vZ+%UDD1b;3CSSc$*fT%~#Y`%lM%_E8tyQ!m6O8Fg|CW@B68IgWXk*31(}h&J2j=Qq8I?`jSy z?76G*-U+Q5d)g^TR9t> zhyg?8EZRSJo1y_DY`lx%+gLb5ySt3A^h_x@mOSbj;TyIb>Md4nHfAfflpB9bWT>=D z6h_XjeKOf*7C`B^)P-dvMRWyOTb1PAE!2A&LkCDBZ7^M)e;v9SrR~d3reV zz+u!V==j0Z_&JJR=-cj*kex5kblwE8rZ94>s*b7;Ga(tPX-86~itcNd#{XYjLgp9i z$9%D2`2CNow{PBl=>7fw52wHX|3$7#%#2_DCQCN?dsy-a?OQE-P7GlqDGIS0oF0=c17M`r3Hc>VY0P$)6C1%rRVW~LIrMB&>|A2VO z|5VqbprT)P1YkfDrr|gI`(*R+zV_~Tx=z>WI$fvhbe*o#b-GU1={jAf>va8ZT>k}X KMR=?LcmM$8iDLTz diff --git a/policy-rawhide-base.patch b/policy-rawhide-base.patch index fa761223..a462cc0c 100644 --- a/policy-rawhide-base.patch +++ b/policy-rawhide-base.patch @@ -18093,7 +18093,7 @@ index d7c11a0..6b3331d 100644 /var/run/shm/.* <> -') diff --git a/policy/modules/kernel/filesystem.if b/policy/modules/kernel/filesystem.if -index 8416beb..acf95e0 100644 +index 8416beb..440c63f 100644 --- a/policy/modules/kernel/filesystem.if +++ b/policy/modules/kernel/filesystem.if @@ -631,6 +631,27 @@ interface(`fs_getattr_cgroup',` @@ -20391,10 +20391,10 @@ index 8416beb..acf95e0 100644 +# +interface(`fs_rw_nsfs_files',` + gen_require(` -+ type nsfs_fs_t; ++ type nsfs_t; + ') + -+ rw_files_pattern($1, nsfs_fs_t, nsfs_fs_t) ++ rw_files_pattern($1, nsfs_t, nsfs_t) +') + +######################################## diff --git a/selinux-policy.spec b/selinux-policy.spec index ee1ea02f..313bdb55 100644 --- a/selinux-policy.spec +++ b/selinux-policy.spec @@ -19,7 +19,7 @@ Summary: SELinux policy configuration Name: selinux-policy Version: 3.13.1 -Release: 206%{?dist} +Release: 207%{?dist} License: GPLv2+ Group: System Environment/Base Source: serefpolicy-%{version}.tgz @@ -648,6 +648,9 @@ exit 0 %endif %changelog +* Thu Aug 04 2016 Lukas Vrabec 3.13.1-207 +- Fix filesystem inteface file, we don't have nsfs_fs_t type, just nsfs_t + * Tue Aug 02 2016 Lukas Vrabec 3.13.1-206 - collectd: update policy for 5.5 - Allow puppet_t transtition to shorewall_t