From 1014cb1eeea5fa003bf36eccdba1a7e88841b618 Mon Sep 17 00:00:00 2001 From: Lukas Vrabec Date: Sun, 22 Oct 2017 15:56:04 +0200 Subject: [PATCH] * Sun Oct 22 2017 Lukas Vrabec - 3.13.1-298 - Drop *.lst files from file list - Ship file_contexts.homedirs in store - Allow proper transition when systems starting pdns to pdns_t domain. BZ(1305522) - Allow haproxy daemon to reexec itself. BZ(1447800) - Allow conmand to use usb ttys. - Allow systemd_machined to read mock lib files. BZ(1504493) - Allow systemd_resolved_t to dbusd chat with NetworkManager_t BZ(1505081) --- container-selinux.tgz | Bin 7147 -> 7150 bytes policy-rawhide-base.patch | 12 ++++++++++-- policy-rawhide-contrib.patch | 21 +++++++++++++-------- selinux-policy.spec | 11 ++++++++++- 4 files changed, 33 insertions(+), 11 deletions(-) diff --git a/container-selinux.tgz b/container-selinux.tgz index 5d202570ea2c8da871b62361de046cbdb7930670..ecd2a47dffcd5431967e9ab4282c88489caacf4c 100644 GIT binary patch delta 6949 zcmb7`RacY^qd;ktMwISGI*0B?q`Rb>L8&1hnwJ)k2I+1XTDqheknS3~yU+I*&RY9w z-|w~d5$F^IP({B(7|cI5KtMh*If`EqNSvHM=#s8QhA`Id?K&Yr>V5U;(O3KhsTWK( z#Enmd9h6q9VoVeMT?zI*HJj;N&_vO)C|7;=lO#}FqSJX%Bs3easQZ{KM^-GSX;!>k zW6EqI^LW}0zPN)wNtjf0{agb8|ECi@&>6TB0NeoItJlZ&nriUcx@p(j=azsnq_Tr4 zs5u3SnKiCQixMsC>cZ1oiT%x^$GME#->cey*HMXEC3Rh;i)t2Jk6$R}I@b0do9qox z684#;G>!3&L3r_y^WCyXPJ*+4&91| z(#j;}_<7Y2bFhF8rRb}g|4G|?$)nFsdBDp3zu(yhs=jr-ScFc>ag}@rUw!)w$Ghw& z8Tn7rtLz)G4tZ3t&Vi7j527*oh4zE$_$(L|6|hs}t|XtY^N(A}cHp_kG;XMGwoC2% z&Q5+y>VB0N9lU8G5%s!0HT*{M_z4(c7^;S_!eRpQAy|nx$*-cVe}br68Fh=Z8R(;F zntFG+ze8v)qcN}j$DpGv*dTiLyVb3*ZXr-&qrH<_lt~?KA@6KZqQskb)fq$WEfHez z@a~ePG670Jzf0xkZ<+sqaDyc%{_JML;IW3VEij%aZ#7m{mc;po)XzS@nEO!()j6G) ze*MFYoY~4hDA1B?|D&5!^Se#tGO(mD`7WzNK#k(V5%1qWixD1|3`*G;JDgtfr!+Tg z&W6X!0(oxKeRMgDWP1})PmAwfvBm99yQWKr7+T8`nOBRaBr9n&Oq9^HD0fL3aDtu{ z4ple>aVh6D*m#$*639Ydsm$?Dufujmi7kaboeaPQaDcI6My^4$vFM4!5Ph zH|^P~-5ZLt$0d3RCLtQEuexMlu{9QK=^q1=4k6t<6h0P}b&O=~vaTLzrN~@z3eP;h zTS9b60CffZA%m)gDr-q{big6b+C1at;(*p=-&+^P z2*xgz4G=Iphi>#KL3`9Qsc>L|)#wTj|ERS&XkJj#cuwCM&(9z8ts~;C)5MeW@~Z3Y zI;^sxuujijR8^rIH_W;hvDBs)9v>KkO9cAPr}R?$7k^ON(~fMo_U^^9eD81bBAFs2L8c+`IAx4zy>y}aWYu{H3;W~Z^w zrML_<$6QqVSzhE-tK7ec&BTmW&Bk zN5zM;Q&wuTMyfOTTn1_z#W6yxTo?0`n|nsl7R$V%hSup>PZO#o8*87IB(u}crF6V1 z9s4lkXsYal`evh^0$_$gQ#VBX1Fd!^dde%q2&4SdnS7{#jc8gk_W`LqYkS$m<{s9E z(+~HiCS!wauGiW&!=Vt{1z-2esb($N{UQhYY~Rkf)$I9S*b!1 znIF}pW`dOyXC4#(7vAfba>yfEicb?!`u7mW3-SiQDgTKfy)mKbIOI9Ear&#j^%|Z- z7FB4n*ggf-#8f~w#o3v}+d^{QL!z(QC+|DSLb(pC0KXHSV{YfxIdxr4b^UQNXH2yX zDs}06(HM@60f$jKBlKH_USWNzTy4Y}s&oyz31u2f{r2I(WiK~>#iRPaOwNX;#jT}T zLxzq(Ww;kC-{oq;bsov5?O|ZzKC6uPw++JP2Cx6>qSqTnBX<`e{$&nvWL7X`n>5cDmno2TFmZxhkkdh6fl$@g?0hg&?pE-bnl z5)&_m_5dcy2BczIxJ2?&E~r@MDA3-;4QX#c!h+AQ0b1upLAfO6bxp4Ccd$zY$5YwO z-fH@a)v+jDcA0Rxk1@S*@m*XP9xgnm^AHC2pg}!@3yz2wND1C%&E`7s3IVOcxU&Im zOJd}xI-Y?nb4DbWn!z4l*1cxXWAgZKLO%0wxs1r*gZRFk^LeDV#!$Rdxu;usY^Mb# zghSLF1q*|Bk06Z%x;?cJf$l5*kYOb4uliGmd*z{rJgWT8DIG)&=d;PxEp9bBE!qm@Z4)?NX4{b89Mx8 z6z}IW3iDV)^Z9Wq3)?tDxO@LMjG1rORvft8NL8>{sS_J z|A_|flSgvw&_S`buTy8LT~@FcY# zGdC*e<{icrsIA1%we^KR;FMoC2tNp+4Q`W;ZmC0j`lK7`hO4+KUrGkVdq!?O$EFD% z71os`iY8O7h}xZ!Qb+nI-Zp{uvvsp|tSyNZKd-2_bD<9n(5fq*@URo(+wkU|lijDI z(WB^O0T>s^%*F)su-<9(sch!#(BoVSNsu2k1tHr~j`v#@AHG*zd5fD)Fo&{w*2edo zZejh3Q&}44_WC6vsntvOEqn0$A~PFX;D4T1HkT3cRd`HUXz*}vT7>!2p2p>7E57+V zPCxgjh3sffw|VEB$p|(XuG6}ip+wWtFYmnHtIES0uMi8QrfSP^`c)=Rbs;z!^z1MG z)eRel87|vazOR6zwBs6SlUGZG_c$130|}3+0jtOKO&CJ7QJtU!B6Ab^*Ip)-1+p0yS7^ab*&!t@D zREfT954PDAu44kP9q$uU1c(Wp{|K`yIt?Bmp6Rq)dg75v4#rf`$0wMP7D$!5;&%t3>k)>tHVSOin69WCvi|06d*{PplE0e4gn`%TYb|=j@?(#GJ;Iz#;8AOV z8M>x}x#E>E_#pWxrswepUnQ;5V9TEH9#I>*xW`#vS~BtzR6b6q)+ott@Cpu>CY5@O}$88 zNUM&Ag({_?fasM!NPJ826-SfE<&XHnbK@f2=5z_#auk@7c6S3GCq`kM4WoQEt1PI=DE+I0U*N9dNoH1<6}J z@7Xx9b@h3^n@BV|d}m@asFiPR2X@+fZEyZnRHNbYWT2jTwA2DVy3HB9x=Ify-7oK6 zsKRhf88I1t^o&{u_Mqw3h-7e-nD(dd{%Wg3hz8uyI+@@*N|OX$m;HN@A|?mdD8EH9 z<2E11LOT$y3B1yaTbN$uOx1%Zq8C8TcRuD{b!f$c_B?oTHw;$C!j|vi&QHHFPk9dbu@yNW%t8u-{U8AC`vi0Le(s~#xC3g*!E!3 z)om4sj+bt@1p@woc|=CUg8ngQINSsAJGM}9#9L=Xj{dTwN7@yhQ})_DvTy#q`EEkUM#>W(YgMf>lfv)d zyZ^uOyCd*nFCOm*`@Qnc6`wT&&h1>#ksddM3~R?dHs8L4A&tujMq_5!e5UQaLsy9v zlrm_2aGt^MAQJf+;G+_xF~vFr1EwlC1aNR5nGlg`UtX%jIr}^*``{dWXeT*z?z7YgdK{fn5ieET=x1Ii94kBvty)0QymY!2TXu zYFb*R&m3E6k@b|Tg=W}v6~R0nLz(^UDz+!xJQ=U0$*!)*KC17yY{Pf;1w^)17xVK} z1Kw!?LO9fdbW7Cb`OgJ%CSiwh)!#g_N5|Wbb?xgAlks)XQx4T|QN{rVrTA2NGxIsz z94fEkm_7LZrDvt3!}V_sP+|xFxT(9@NYpc*^JIzOh$)mhN_EVAZ*(#(i1#!l6$3KM zQAk57tg-AC=$1iO2IG#DI9G{KQSBxSGwp994hspd&1Qq4i+hxMY@89kAv6kFQp0+MC`VqFCoh6{dSib7UyOgo-S3_}&nv~NR#k&@OQQU%ZfCRm2J7f0O zE)B=ry&Ho)E@jE|??#R&b*b#~47c2NU$7$nU(3NgD`0eWj=V(5SKNsT2= zvAVvc_B7Edw%>V|bP5ouFbkpxc-+gZa;&(BO%CrIJ~81QQubR!YW^qb3gH0rx*;;~ zi?B7Nz-X0lDESrvL@6XB@vb%Y*GA(s03%0Ic!_5Hm;${Hf72+}t8NrO8i0&Q}8 zM#*%<@?QJMI5}eXfl8F?s#}Q>ZkD%bgS@{HbJ~9{MN|jA{Vn0-C%ac|d3jt~%Djp> z+142ib!^Xp{CrT(J&3?`^`_Ab1mz6tA&f@>=fJew-J<56p?&_XWfTy z8K%hg0N!m`HO*mZw)66}D35+7k52zYs8MB{O69Iok}bSG&9yHo4pbVH6;T_k3E69z zmr`+QFW0i(Sl2}k3Cm9LJ|&T5755LE&@?5yQ({Krpe_FHK4e;2rk}#Ur}ya@ibvp& zldp=I`4AJ9%eVVS^=JoQ{)?y~45XX4lUd?#CVUBEs+p7ICaReK zZ0=>^q^ZmIQC=;TIDLCRJeC=^3MR`EzNNqR<8K?GO+I1u&(3S<-6L*wCa7yiv0dw; zRzG4J*t*iUA$rk<4XMLKzeS<-&m6+=XR-1Y*M6%~?YX(0{}62o@NjDd#lkn0Sgb0o z0ZM2NGBHM_{LMjj>F=BW+A*U}13VTg^K>S%2PCJ7hsUTw9u;#?D8&-E%Ct;eG>CRJ zn6-F&`AePr-wLPlBo5Obd<0Z+n8G&y#0C}Wf7zyUxoX>@!4bc;AZHJ8vWht^dyYC1 zQgFR?jS5)FmNQf%!#3|94_V_>SX0BM1n#GdbO4*<)}`Lb2Cm=N%S09v)@IAe|LqH? zhW!=skhA#ADJ3b${u%5)Kjxv4csZX}KXgoBCT6P-`T=UV-s8*wIcv2TBlM%6Kv~wg zY9fCeCKdK^cMkFB%RM*D-S}}%b3k(F#zcBb@z)x`xXh;}7zaON6zI+f#^Zq@K%9#2 z14_JtVK%;(>TVXX^%oaIHrJ^3h#06>$>2?$gZb8x7#)%IpoG+p56H*Xh6b|7o*H)P zY61}wz`R=}qPo6#;!FWc#j<$~1&~MKfQpTKGZ+QCd-W!7s{HqFYM~N-^hZlju`?<__+3uFUhD( z9ylQV9|-Go##6-1qiGLU3X|6k^i-kuHOH)ED0csqueNs&%oEm(n!25qwA|`MBgTef zQ0PjpByzJ8i?aIneEV)V?iiE4E3hAtfOYyP^SKHDVX@SS-%Tj&Ys-oN`$?g6!n$W9 z*dJHfrVlCS<(V7;rc8ew6B}T%aJW-l5~XmnJt%oj2C^~7W~Yg~Zy42_Mk#zs6y=jf(3#UorE27l$`yk2X_j&_giYW5j z*7_Y^ko_~{Z^v4Chfw(`(T;y7mceFx5;?D)_j`HsF{sE?A+6m&m&!v5uB{0EjY;;6 z?6p@E3T_7KUA07Q4o3Fb3I4`~pHqC$Kkt7KYt4ks&1B}vYJI8>>=3~c@@jQTn3!ln z_|~-jznd$%D|+1fVe4+SA{N4MR>kBxu9q}z_^6PoQ#0a1l`*BQJ0VqYT<+duiLW-X z2|7O*{m9}1sS`8l9SJ?s_;L~li3k7=4`R0~V63^VtIEjFxa-1Nfn|&9dRry(bgpzR zG-I!>1AkgyZq-80B-Z=@-^bVOJw?6J3zL^0!=3xGL-Gp@i6tpOudDxkcgfqM42as> z{Q*uYe>t01R#WdDQnCH1ueI$Ne!MCI=BvAco9Rev6EHs+ppm+7;DA}WQI1)BB9e|s zNP$N6E6<-77C-G?N|uo2plQq`3z~L`hh49Ghh1If5fY~;eY3yq`zsOU_ z>L~b{mCo0_SxYZJjRmywyQVqB%bJ=nQ~^_z6Xr{u_o=+#N<}}S@Ti5&^MgZ(;PIV8 zUS&0nFL=r9z$X%QnjlFTbSoMN{`450ZFzT}#8v<+8LFi&+r$#B#34HU~ gR!BN>uizOLzN95w^#6x}{e{Z#SKJ!HIRe7}0pY5ys{jB1 delta 6933 zcmajiex^-#cN|Q2ekTvp%@Nbx-G=GzI2_$E-SIr{pBK+{ z-7i1?zq>}%4mnT%5~UN^6J2S4YEha zZcpY0k>Fq-!b>{&L;81dDOL-h7I{wa?2bmYO=7M|V!|6RV22k>11!sOS|M z3#J=O6azX&41Sg5-Q z$y2i^ z4Wxr4gXJMpcy5}i{({Yn!a+wdKEpq2 z6?R&2P{@}AkD!9*;Og~sFz7!~anEO53Lcc7nGCsNlPrcEz_hxm)`H`Em7w2XDaM(T{9CJW2|M4f&ErqIK10bFE zfpZM*FvG_4-31|=@xW*ccZz*7m)zIw-X2D)fLTG3l1b)yF2z&LJ$Bs3N;O9D#qEiq?;Q3Tg2#gP_N>8ws&o@ZYNKjtK7b^`6| zo0N(c%NzI8Y-AH?sVuxeuPK9p!^3D93JKSl?8NC9K-{VuU=7|l*1!KJ`h0g<=NoVQ z`m)buk;NF@DZgzaq~_1UPKf*87eamj#lo+pB_dz$2qG23O;YEo|3hICP|Vm-%}{Kd zKm3O)wUTh(9%i=0v#t>yrDInpYs9P@L8%_6f%OsrM-joaf>*#20=2noMFw;T!pv(r zSr{LFiUppK&ph(>_G1&Bqei`bY7xtiNCxak;Y@WDUmK+T#C!-?MPYA{U(L){^E*8gk`h*T# zqan}5KX+TU{7MGWcUR&R8%B8YA z^J?GLuJjASsCoxj&hmdpo(ZrQ9}}_}IoYIOtifQnD@7v;RD4KcSN9K#kUtG_VmzU( zJNNef3q$?b*EFWigZ^_%t*@*TcUy#GNiPJF-L%<9!WQVpVT`a6U-Y|?M^{H&A9i5Kj$nt#KF4Z*FX0$P^E+MGb77o_; zLVEj2K(K4-hRCI*PqQpk!-c=l^N3K0<@GWY_03fai@a||ksscbaV(*iDh0Bcb%E~X zxzN~E)=~g)smQi*;XXs`gTp;i;ceHV2`?yO$S6!^sbKL#bdH>-R9Y<}rC(cyRb1d0 z*qxW~S5T`mzX8U`MX0+%)P-wg!9c9qErLmO;Oe)G)MsHX4npQT~3Ze#NsIA1@A^1~R*1>GMFX6!S`TWcP+}#U&w>s@=a#5ISoF>7Z z?D-2O#B*(hT{t4smd_>|JUIApkVbi=qrFQwe*6s!KJJ|4Sr_DV^0i!i*~;bB#hs?? z#jVj-5UcD2LA|1xcc&2LIIZhn5gwU@-4VK`g~@6Xgw6r{XT#=**OgrOeag8^%Z;a0 zraOR^yWk{?I=Xma%Uls;dhz4uz8zX3YDs2I&ite%=Da1;c7@%S%WAWn&Cq$@sNAVE zAS#A>%l&KZg37P{CR$LJbJ$5UzYBsxslWRw|F>JSLG}W zulRekWvb?(vHuPE;Fi?5F;Hn7TDxDmzKa_ClG2}hejOHSWuB;SF7l`x=^vDQdYV?q zaUI*07@+ioxj3dpCOa+X@&M#sXXjIQtJdda2=}G zyE_AX8)uj(_Vz|A?8FUI?7hX@9}PR-1t=jD7yTi~ajgKOMI|zAacU8JR>@CEVg4c% zIV03Tx0}ymDL9Q6Wd2|mkb(-l9j4~69&0_CX!`kB9_Xass)SHBR=L>W!hpub9{w@t zjyxLy7d~wM!rbDf0NrJ>b^EP~6Hn7=csxPd&*hEbQY*?kM=zVoQuyo7N2Izs#v zXsoXzOIlhl+Id+xuReuOOI6}AuP%fjBbG*9zke|K2b5mnIrmR1(zXiQnChsZq zpn?2KP?6x7S$MjWTKin90yr4ylAd?%>PXGpCF-?hcHtp0A<|`C_KNoj6;9NbWme ze8k?8QUnuRHhN6~rl8GXr_^VrMwgU`EeL-H*(GWg0m=?cr^TUyZe>qj9q(a;*~zcw z?Zy4P1NIfreGA2sS+L0~M*Yu2^YdT!>k8OFq6G|3RVOrq?>lUN!~Ff}=pbE-vN+;O zZ})kaePV+R)y|z1IraKdpBso8WID*>1F5Em49yh`)oiSQ7_7A z>3+zt>tX%5pi7B&3i^2}cAzKZbmzB9+JTBhs_mfnGflJg5HYISSp_oX^e78N>MD)|H@Z zNxOVo#3TtohPiOZiL7VHn-$_H#(W^?|+bmOYj zhTSQA2|18!2o;a`^!iv$=XR?Yuw#NE*r(FebxSgUzNM1HgFtWGEu(-A3sQK&}t2YQ_}YnzV7vP7JSm^sWs^{p{d80c{vh|$BDT`f|9N@UhuoMeL^Di z{ZZcz>}KA&(etvX(7x=>A=;)U8jY3nenw8q{JgKR7*j+}*Kx!;1u`={WR*RaGdh53 zFK2D`tdt}Do3(EfdImCI+c)*GGZz4i3>_RybeB;Jg| zzr%a^MmX8=bvmj4ONZZP*&msFLnko!p3iNW)SLX7F(!T6mIlr&T3zQ)u!bIM=?~x} z`r~{-{E}FYV-I}#j9*Krls;$?9UxBw8ciCIgtpd!)>>n?3|bxMgM&-^Lgp3c_4hPo z2D%T%d_PO4vvnM-PHY8!ZFTiB;fxmWZfNKB*GnT*o~!Wltz{qKElYd2yqBwK&)6vr z={BTUCwkf7(`AXrR!T)gqtxj<0k>uP;9IAt9}OU}PXOfi*=dQ)qROkoguj{3+zMw2 zy)M}W!;U`_-XcvYuUbO4vhPW~#Zf)j&DK}p$Dv;}Bd$@h7so|@TDyNHbyyefZKrgS zRTqeJFUH-RjfT{YG;}?&?2`u!y?db)?YtiR-7<+HhJDzsM0Py$p#Gj7j@i@c8F}|@ z?CMGsLlhXk&qCc}m)0g7+hKK&ZvelYGZsJ1Oe)ScIewphXXPJq) zTbiajJZsL9$v-#u+ojTqvTceDGT9Fx%yPzxHUuc^+s8D2mn}2v?uqYP?+9(7)O$9u zEX|z0D@ymafvb`-e4| zrBp`o%{}-H8tidgV|mYc{}zg9|5_y=yzw$NY>=ORp{^-r7EmbK5N%#q2SIZ*-8=ZT zfeZ}yW_W4-Q;8dvuFr)*u`3l79(R=fRnQk(Fy+Pf`eNiCHiytJ4!Y~sfQLl*6IwYH z^%qJ`bHz{<*Od<%)A;X5d|c@NNL7HLgALKQRzfs*lK((8kmykvY(BhA_W!-H(r}D* zTJ|qnD3-f>&5APDMkj&~ha9NV;?-0#54JBCy~@1U7 z7~+FV(HrH8BcIzlL&6$Zpq&tvzDz{rE0b0(lH(@khmfC}X+jM%1c{`(uROT0DV`Wv zMbh92qo1igaVygc|DFYGyMF=JPk;c1RNEppulxVX z;dy^DAk!2amF^VG*XXX>x4j>`vw^&H^$`8gMI#hr;4Bugf@8;k6Q~*7aBTd({ojcM zIuG2>pT-m`t}6x+hJZ)S(kaUFyQ%Ta&o4=a>32>nI>Y{fm$qluwAF84gW3+NGaUE= zEwxdzID;8)3|~w?!*W)uqB(W;@SIB)9I&s%|7+Almb^4bB)RT-U4NN5M21>WA?!0%W-mL^!VSi+ zX0}sarl`DCnf*qRIVXH}w^6AkYtD10Bdac%&& z+C!4J_0ajjkuQ}%B?7KP2lQNFZEi$3-H1VjE@~E*y58asmJy-I$$1`7gpjcrrs(0% zKincGnptJIqt2$#sX)Hxh>0Ry8Gjk^_6JUIqO3)bL7pEQ@eC2);+2hU`Oh<)o^Bc& z1@_5dgXJlhiymSZAFh)Bo5dsDI8qZj4F7~ubP^_f*m6WCpm)sN1YBIxGtrOId64PV z-J+AlEDs}vd zBnC^$(!^CHFn=>eCu1bq-crdyA`hLzxUK&>_s66dZcmhZO5p`wubS<*w`$G9rT=FK zQ$VEtzE-tsyalsT0x>|#UoY2HQUX?9Ftvd$(Smb9+J%W zm6ttyooF*3fD?5?i8)naSks}mMGe1YS$Gy^vkrBt&ge4J?(ANGfa}#B{2t*RtD9RI}dO zd}Mm0lFT6CzaqyLw;A!ySQw^{O7m*StFHLgfBMXR47`b-UD=~k@DI@S(x)RS8&w9H zRcUc)_MWvZ6;yy(qOv)8cn7C(C{=0n@*~vV_1AXn#<_EhNpcu`^gj$8Sv1d40&n`r zO}o?=ha!dDoYy zHl#Bu0)WNPxrub5k7k8cI}h+ZNr~28j%suz$_<1f0}FT((#6nj;z5`qK6IvP#civ3 zoFn-vMOGnpD$9?ra=8+~+~=#CA5bbKtUhl_WVzb30h!f3_kIZ~zmtAJJ+$Q^vNiPw z;zie(je||1mlom3hHQR{-tY|cPUD!4-xMO}KyGu{>)4WOW9V;dQ<1}FuD_Y1T}^EG z)AmrTc+aC>e>IGPemd!Cz#ps9kMkIIt0gRBmzleKCTbjZ9IOr}jrkl`ikw;z!tqvY z)VoZL2zTe0*D!k+X+vEF@uWcbGMT z=uQ&{Ua~P#|?yV|2pO%v# zQ{WH_RfM!Kn(J|UX*~w@Y&Ad^$v%(TPvOy%uiij3^xhoE)Xe55t_p=Pk0*guYGDDU>>ZbL zOJIWsSK7knOP-?gLL`0VCN62Y%6gAC+1TuRB0X8NYZF9{ytUNOn`g*KbV0YPD)ypk z=!%=v_zwL@Gl>N?Ix1hAwZ|pEAn?G8>l#I@JTD9nEd1VFB3*_J=WbB+XxF;YD4*5= zk(r;itn0(>@;?i{HU>0H>X+xIO>;%Z@-9Y`xgei+8ZAB=x7ofR2Q?8Q1vU{@{YsY? z{alw+q(-%DH=ofKDr8w>)$D6M|v&Q8CjNkl)5E@RCaz zC(`D3MIwDUo?Gfz=N4SPjnmiK`ntC@PU*;3d$nh*`Avh6#U+Yz_JmN0Q;=nJ(E67p}X)NSRYT$&U?$`aj?ru|v*l0|*fY*;{_SthR*0-Rg znHs4F6)T8{_vb`$3PM0xeM~*6E^5Z>Q-?IFffdOimsR8)Gb3bI`Um>BJ;Adl9IMO^ zwcgkPhpK3WK3-cuj;#UmJ*}zwb+?z2jbJ@Am(D}buT6*s_vuBIr91-?hl%^bMxMZ> zvM(;Pd-!w9@~024F$#8$gU$`mpECu|>0O*c`BX|F+5Nhw{R~k30_7n9`}B>q!ut!O{~$c36f^3kUTE0cG&Wl*F{9&*ngj{dSF7;2 zHkV}Iblx|}xE!s+BPOCww^M(ugtnl`63HdJ9>sS#G-eXT% zB6(bVQbYy?SOLhV_JZ|_M~h?I$|=bR)+MYYCEg=xl?Fj36MW_ztJRB|6v{KgG8^aN zDCbbibND%1$oHl}92k?r85gpQs$~qSi4;#3xA3$8mS)bHNaicM49kUIlGuuhuhPET W{~PuH5e0>B$lhmFYY68E2>%0%sK5LG diff --git a/policy-rawhide-base.patch b/policy-rawhide-base.patch index 7560b462..c4bf466d 100644 --- a/policy-rawhide-base.patch +++ b/policy-rawhide-base.patch @@ -50166,10 +50166,10 @@ index 000000000..5871e072d +') diff --git a/policy/modules/system/systemd.te b/policy/modules/system/systemd.te new file mode 100644 -index 000000000..e944cee17 +index 000000000..9b84c582d --- /dev/null +++ b/policy/modules/system/systemd.te -@@ -0,0 +1,1029 @@ +@@ -0,0 +1,1037 @@ +policy_module(systemd, 1.0.0) + +####################################### @@ -50537,6 +50537,10 @@ index 000000000..e944cee17 +') + +optional_policy(` ++ mock_read_lib_files(systemd_machined_t) ++') ++ ++optional_policy(` + virt_dbus_chat(systemd_machined_t) + virt_sandbox_read_state(systemd_machined_t) + virt_signal_sandbox(systemd_machined_t) @@ -51115,6 +51119,10 @@ index 000000000..e944cee17 + dbus_connect_system_bus(systemd_resolved_t) +') + ++optional_policy(` ++ networkmanager_dbus_chat(systemd_resolved_t) ++') ++ +######################################## +# +# Common rules for systemd domains diff --git a/policy-rawhide-contrib.patch b/policy-rawhide-contrib.patch index d16ef44e..c022c348 100644 --- a/policy-rawhide-contrib.patch +++ b/policy-rawhide-contrib.patch @@ -17134,10 +17134,10 @@ index 000000000..1cc5fa464 +') diff --git a/conman.te b/conman.te new file mode 100644 -index 000000000..2357f3ba8 +index 000000000..25cbb9aff --- /dev/null +++ b/conman.te -@@ -0,0 +1,97 @@ +@@ -0,0 +1,99 @@ +policy_module(conman, 1.0.0) + +######################################## @@ -17215,6 +17215,8 @@ index 000000000..2357f3ba8 + +userdom_use_user_ptys(conman_t) + ++term_use_usb_ttys(conman_t) ++ +tunable_policy(`conman_can_network',` + corenet_sendrecv_all_client_packets(conman_t) + corenet_tcp_connect_all_ports(conman_t) @@ -71621,10 +71623,10 @@ index 000000000..02df03ad6 +') diff --git a/pdns.te b/pdns.te new file mode 100644 -index 000000000..509d89837 +index 000000000..63ddc577c --- /dev/null +++ b/pdns.te -@@ -0,0 +1,82 @@ +@@ -0,0 +1,83 @@ +policy_module(pdns, 1.0.2) + +######################################## @@ -71642,6 +71644,7 @@ index 000000000..509d89837 +type pdns_t; +type pdns_exec_t; +init_daemon_domain(pdns_t, pdns_exec_t) ++init_nnp_daemon_domain(pdns_t) + +type pdns_unit_file_t; +systemd_unit_file(pdns_unit_file_t) @@ -90156,7 +90159,7 @@ index c8bdea28d..beb2872e3 100644 + allow $1 haproxy_unit_file_t:service {status start}; ') diff --git a/rhcs.te b/rhcs.te -index 6cf79c449..14be26dce 100644 +index 6cf79c449..7b0fd415b 100644 --- a/rhcs.te +++ b/rhcs.te @@ -20,6 +20,35 @@ gen_tunable(fenced_can_network_connect, false) @@ -90682,7 +90685,7 @@ index 6cf79c449..14be26dce 100644 optional_policy(` lvm_exec(gfs_controld_t) dev_rw_lvm_control(gfs_controld_t) -@@ -275,10 +607,57 @@ domtrans_pattern(groupd_t, fenced_exec_t, fenced_t) +@@ -275,10 +607,59 @@ domtrans_pattern(groupd_t, fenced_exec_t, fenced_t) dev_list_sysfs(groupd_t) @@ -90714,6 +90717,8 @@ index 6cf79c449..14be26dce 100644 +manage_sock_files_pattern(haproxy_t, haproxy_var_lib_t, haproxy_var_lib_t) +files_var_lib_filetrans(haproxy_t, haproxy_var_lib_t, { dir file lnk_file }) + ++can_exec(haproxy_t, haproxy_exec_t) ++ +corenet_sendrecv_unlabeled_packets(haproxy_t) + +corenet_tcp_connect_commplex_link_port(haproxy_t) @@ -90742,7 +90747,7 @@ index 6cf79c449..14be26dce 100644 ###################################### # # qdiskd local policy -@@ -292,7 +671,6 @@ manage_dirs_pattern(qdiskd_t, qdiskd_var_lib_t, qdiskd_var_lib_t) +@@ -292,7 +673,6 @@ manage_dirs_pattern(qdiskd_t, qdiskd_var_lib_t, qdiskd_var_lib_t) manage_sock_files_pattern(qdiskd_t, qdiskd_var_lib_t, qdiskd_var_lib_t) files_var_lib_filetrans(qdiskd_t, qdiskd_var_lib_t, { file dir sock_file }) @@ -90750,7 +90755,7 @@ index 6cf79c449..14be26dce 100644 kernel_read_software_raid_state(qdiskd_t) kernel_getattr_core_if(qdiskd_t) -@@ -321,6 +699,8 @@ storage_raw_write_fixed_disk(qdiskd_t) +@@ -321,6 +701,8 @@ storage_raw_write_fixed_disk(qdiskd_t) auth_use_nsswitch(qdiskd_t) diff --git a/selinux-policy.spec b/selinux-policy.spec index 5e28ec9f..51582520 100644 --- a/selinux-policy.spec +++ b/selinux-policy.spec @@ -19,7 +19,7 @@ Summary: SELinux policy configuration Name: selinux-policy Version: 3.13.1 -Release: 297%{?dist} +Release: 298%{?dist} License: GPLv2+ Group: System Environment/Base Source: serefpolicy-%{version}.tgz @@ -718,6 +718,15 @@ exit 0 %endif %changelog +* Sun Oct 22 2017 Lukas Vrabec - 3.13.1-298 +- Drop *.lst files from file list +- Ship file_contexts.homedirs in store +- Allow proper transition when systems starting pdns to pdns_t domain. BZ(1305522) +- Allow haproxy daemon to reexec itself. BZ(1447800) +- Allow conmand to use usb ttys. +- Allow systemd_machined to read mock lib files. BZ(1504493) +- Allow systemd_resolved_t to dbusd chat with NetworkManager_t BZ(1505081) + * Fri Oct 20 2017 Lukas Vrabec - 3.13.1-297 - Fix typo in virt file contexts file - allow ipa_dnskey_t to read /proc/net/unix file