From 89fc5f15afa2402db6a51358064c888cc5d8e72d Mon Sep 17 00:00:00 2001 From: Lukas Vrabec Date: Tue, 8 Nov 2016 12:47:22 +0100 Subject: [PATCH] * Tue Nov 08 2016 Lukas Vrabec - 3.13.1-224 - Allow watching netflix using Firefox --- container-selinux.tgz | Bin 4908 -> 4911 bytes policy-rawhide-contrib.patch | 20 ++++++++++++-------- selinux-policy.spec | 5 ++++- 3 files changed, 16 insertions(+), 9 deletions(-) diff --git a/container-selinux.tgz b/container-selinux.tgz index cafd41f5e1b7c5b88e952c16a9a5891d6beedd49..7a78fdfc9244b531df1ecd72c3ef0dfe0bfecec2 100644 GIT binary patch literal 4911 zcmV+~6VU7*iwFSYx*=Eq1MOYwkKDMC_t)vaLa-O`%)*|B$MFK=O@d%IAM)XlMY7*+ z?-aGf?$%nbh}1mJ@c({Qd`Of;QdGCvo;$PvySt^TAITzFtSS~Yaaph^El7QtZeASe zx`yk+hxhn-^TQvm^-s8NuWvrwzPN#p>)YEu+`hkkaeZ@p^TUT1!S%5!q+bnXQ5^&? zvimw(lh{f(_5Anew9@S5O`gKQwvLeM>S~hh|f~cypG>%wW7D22ANZqV8Hp&Eg#Zlq=DlHhPH&IN^|JBweteb+RISHXWj`RA> zzgA~kQiL`6cazpYyE;2#PnFh!mWRDD+$11@kbPX8y}nqj&f>Brah`;fM0LCi*J*M7 z-Oa`7OcfVa5rbOcT|1cR3Ao&q?aMLjH0WPDU7KJb5t#9?7`<`3TXX^O6@q^=unqOmHtnlF+nSp>)%1%6djC6 z>k25P*BwvD@{qD!5CLJsK*B7I1K#@1c>r~Xbdjb9t2({Ma**;XcIW_E)*{4O81T^* z=S?X$ToVhSpz@Bnl;#vAc*8i0D76&DpN-2}6Iom`r#$@sWl&Zq|0w(8OIA0wCL-ye z*fmLutyi(;DWY_ow|j1!ATDoPn*`szgMYX1@BOm&*)M~zOY5% z02G~J5OW~o&Bfh5O6vPX0#MG57=H@w28#85e)oQ35-WhL$Qw z^j3=GHOWde)}l>29t`lU;tXcS8ygCPjXiPoh;yMYR5e2eqD{zs#VAS^AEKb} z(;#0(co*;LP)v}A5NffEkns}kV&@==)mIZXej^2&BWk?HB{@XS8D@#STd1-8B$Tzp zUhwY*ZTYuQv_2$08%~g{-15m`L6!@l1$kHIWH7=wtx0j^2UlMg!Qbv~sZ#HV`-1%vIugEsxFgZs2Di+q+9a-8ns^*q%5 zvPRNWkGlP}u^9pjxcR}>cwekvo_4)-o`TO{b=M$`fTr6b%7pzHeEB%f!-B%NVmA}2 zin&9TE(9$eX`K^O{4&Ha;72KY0Eo^&Ze{GW{97+}*?fc7Kh3R;lWBKbInJmSMqaau z;DuG0rSTIV;mXUGZasM01yegJ7uxfQD8TEbqc>sHu$@f37=>{7!)KPF!s|OHi-1M`P8q|xoeHX_X(b!hU?k@UKff_HZulrN+q9Klc(a(=!x4{!Z^lXW}`s;mJO zyR6wd#PoeOf5I4ga~OH%L4$SK6ba=M2De9+(Pd(Xr-eTt(XOlFUO`2@g<~pMz797# zVHJ#uCj-1(GlVR_7Dy9APW(<6<%Z$WPbu}sZuDbgsI=W0hK_{Z} zT}h%hv}z@&QwE7@9hkb^=IV_(jX6MrO(^ZL1Id^qGN_9mk}+qZLmEDAk=#)2w!IMv zpE{~E-rKb7dvbj?+?=$Cy}!9<+xc_Us=p;=Gg{5OdgNSVRkvNGj@J%bEX0LkcD-G` z`Qa(2d|w0YALUn3#uFbl=zwb>i*LO~W81~l!}?9cB$O_N5h-o=JNXTdX|z~y$XINaRwR% zU1CsPE3RV_LSwo4TFGr!f}596Oz^NHpayGwqcP%kmI^rXuwa%2zy9<~P?a@ncV{c9 zzyvyKCDs(tT5m&Z{n6SB^G#GT;`agag(My6L~`o*c;kIho5$Qq&1H!KH$cq$~;QV(dYr{ zFci@T9|uOPWeiEjMQK6fekr|e2^IZqZ=M?w#_%e|rH|cZ$cStg_H;gG8H34<*fZ&0oaBTmL@^|sVI{GE6X zCffic?(9qy46Cl%BdkdV7E*?LgcD5NcG8xBXTj?JeiD>kXK9`?UJojhk*4d?ZZ}|l zl(zRE_A@4!O`D#);QmcdG!|D2pft${We$5cDBcBYuAyl|D^esb&fy5wn}Tj9A247B zI3u|htHXFqWWqvH$sObM&~#eiP_Xgolf4lqlUO{F4OuPwG+nLu=B?I!dd7_?pa_fo zTigMT^S1VBvM@?a8?*Z~*N!$Yi@e&Z&^}{ZdHz)JrOkEQud!RhjeVQy#F{-xYARmkTe&#u4t+WEAIOUCP#{3Rh_hF*t+uvzf zT*AXW`@U!1S|98;7G`449vi;+ecRq^qzs@fBj!MXqrLBVbgTGhk8e80 zaGWBvBM8SU01r*9UUf8Zg=5UyviiskSj>6iX*f~L(tDUFiKTo=pWw45 z;m7i2A>s*j31y|Sl=+_N+Pp=5(Wjz2l4TA!lo*DI`Ch^ne%5Im7G+|og3dxokw8iJ zEnB+TgK5vQ23s~3Hr^`Ug_wXaO&`m&gB@d)XAz1eF7v#~$YaPmc$$}Q5X_aJk!f0j zJvL8qAkWM}(XvbwA(bc}`f<0%ZJ`##-Heg@PGZtv&gE<_M`7rLi+XMAvZd zJkv517uf4b`Cx&T?-fx=hGr^GgwGpWi@JkWICOaNIo(>Qd&HpXF)RzzHs>Ivu{PNF z#%%gOkt4f?M?KoZJ+?j|4NK($k&sQ)WK4J|kG3JNbBG~tgMOkol@jUwgyO)qMYfWd zEBbWf#5EiUtE=4V;a`ZyqJ?V*g&p9vxzr5|;4-5VBDOH66~jcaJ-PAy*!N-*cx`&} zMB&w|AbX6(kyp%%o3oprL~)2=fI3YG+F;u>!H){}=i#%#pHEco=;OC_Su*|w3^nyt z9@_+4ZPwnrEJJ=^H}Rrn6}a^?Itn^f01P%%av`Y3c0)T5W*5KT+v1+w<5pZ^%J(ZtXEFfATw7jm7)Iu6Df~wEZB>b;pnzk~%uz6;=~gH7d8_Y-GW&fB*UK z!9Sou_ayigPaE=7EqmJFYH$RHrz-Md#JN0f&rb%c1cUmNLT#fz;Uk}y&K~H9x%0A! zf5YF_y=y=(WNWMQ!lO;-jI?e%9uzauwxkuy9~~r05do65(VS2=dzw&E^-oyVIbaMfv@nu;bUo&^F1JKVVK*L+KdqseICU-ptEtjww1gAz4rhk zC7EpKYpYPvK-tUtYg)6)=Fr+03+`DL7-zAb41(oAC+tqe&noIZt=V*tK#)0HcmCXG z;+rT#3Wn*rwCLQfY(?jqhk{yd^7zuLS=(dagV4hDD%g}Yy6F<2d%H_WMGNgsdea`3 zYLCHQ)- z>8wZGy&1q*>KPxY@_b%9P&>-FJEx~!plS+^PXvT@wtk#C60bU&c(ao9Ccki89(^*tBP5ZwnOTF9!YUSjuD#?5ksU3f{WbbMkJ%Z!xupAPH1U+Ed?E z2Ru9;m+4T&Z4n>T_YfzLrOt2GedQ?h)y0$wRWC8@l%`FesCo{SlVj6dtN4Cruf(g9 zCJtc9bFX_GJkmL5o;qsdY8E&xaNM5q>YdfGuIK8_MH9&+)30B0J)6ucSqR>l39?Wb zuB4Ddi*Vd0_~5wxq7T!j?$ePg6&Pj9`9yZ!P)s#+M@f*6&?- zE>|m=%gxc=ZQ*|Z$MuIBcsBa`zwb})|M(i$6>bq;{dOr1HS^c|@OaH5EWKiNZtmpY z5329FX(SIPQhYS4(qFgI={O7{^HMP-dM3ZkIN;|;m9F(5ZvkttQAeN zbHO@ClUJ?}23S|3wBPV#gEy%1eoc@q6-D&R?|;Mdn*Q|_CqJiw)nN&LWdBO@a}vt{ zV+?t2m$~rdITs1JAmY0NAcvTHj(g`&m6%5uu?pEda1S20X81*iuf2$6MzO+QcrYv2 z#mDpj`0$|(tI+}KSGbyOJrS%WNM_c}f+s5X8~#}bQB5D^cVnNWsmV(NcpA;9ca5Bj?yIG+UGf4r|Wc`uG4k8PS@!=U8n1Govzb$ hx=z>WI$fvhbe*o#b-GU1>H7bC{Vx2*6 literal 4908 zcmV+{6VvP;iwFSY_#jvS1MOYwkKDEq_t)FMLa+n)F0k)my9sbkS`n zccs`?0OEJ`N`oI~e|jKs!-$5S76IGoHn&dqAV-#NfNL!V0Bc`6dPp%z2d0weU%oB)SDJ8ylV$DJz*CsEZ_(o1(JQTy@c|Z(?fop5l025baujl^8Pz7QxkWVu7d=s zAG5Mf37sM7Gnb^JI3|>%oy`-m6be+!N5FScjijAydHKOtHzt}}XlEet;cHltI;X(6 zNi#xK!IGNy$igH0sfn5osLv^A%K&fr4wU%cNR$l3&AaxC3%Z7i@fPyx>?LmN7(L_Q z;;~tYw^*M+=5!a;ZJW>~kl~h3mrZkL#fQBS{5yQq-GAh> z9@l4DkvQF?&_SXjacw0dmB-6W#DGBl0~hxr>cPVXibb>SA##Jz{}L6^cDRr{jX9R{ zsvS+YN%%vwo5GlyFh|vr#vXi1rhwLusMLMNEc~(u&UELEC(q+V}}lqWi3Lig#jO3ao&`2 z!!@xG3M%iIOKDC~f;Wt_h*C>Y{MopyHIc<7bIQa2p9f`y@{h9bpR>BLH4#Y%#jZ(O zY`uy#PZ6c#yxnu-1aW!W+9deu4g7lx|K2TYpZ)abAD_s|!L67oP3El|;0s$64nWZv z1~CUR-dx=6qolrDBmm{?h*4-`uHXGg8OdXo&5As|A3tk~lyUKQ9VM_6X=tf}L~o@? zUX!duV;v-w!g%6O0(mKB*{z#WfLEYc?h~wuz%lrvT1{^8BWOoP>yb`y$qEH>0h2!! z_v);IAy$_-1117!i?~@)kp%a3YBI2MlEcdNUIikjET#`fNoMD#OyM-FdPeNHs>;?aB z(3XD-Me9T2v*85E$}OK97G${)T99{TPKE>=(|LUov{BGNn?R78XEwC@ao znodfabbCpPyCqR~C1rGJKyHsOh*=X_W_On;fkj|NFQI`U;Xs|%pi9Ci$mg>$KQ_hJ5MSrp3YYBgbrHewWj_3;o;26{5*lZUV`zNm}Zpc2Gd@4YeUYrgl3 z+slMMh6Sc|+TVZrp(}ts<({iz@7_aNRM_z0+f(8;x1mC)E7#(p<#b?^bMRY~kgAWM z3uLueIm_5E#-)|JUpG*zK(>$jMSQxaP%zjYJZRI;I=D;gvdCvyA;;-1Ue80_FKZ-C z^{Crl8=E1pfSVs|jrYa+DGg{T`;wya-lt+hyuJ^I(idE4cp1oi%|%NKYU^-D!jgPvWPfCPg`hB zJ}`esLmJ&aY$MX#QHLfE9Z9b%DR_6sLHR-&!VwHrA?K%S^YGTsH(AHCpvoFhvCEpR zLrmXi^Cyg>6IQ{f zcr?JvHABb(OiozP>c^^t<_b$SrBd3TZ^pp)y39x%RacXe@2b0RqNB_76Lcaf-<2eK zL#tMTI%SZk)`6+pZLZ#!)0hJ^*o4v^JCKY?B7?g4AsKTfI;7#_7Re3OZrdA?@TsFp zM1Hlx+dt4Gc?R(0D|>Uiz2#X?*tX4l*0n;)KX z%J((U{!xAvWjyg=gATYBviQ<#G`3w#J*?kEOhV~$izmowxZJ+=H!OuVZ6jWu++TGboDlmbL zT8TA9wAS0u+W27iy$Uu_MhUdXW{N^FX@sU8Ulu@{IW4C?wX&vojzkiXyevYYoX-s< zxz3CTu8=nC-$Gb<<6Ts2`O}=oVoY!?6Pk>k94lRIOLn|5w;{nkI5BpWrc8LWZ7neEaXx!xO!>Ns5 zwbO;4;$|%Nu+NA5V_X#|?IU+_T~SZ@n>XDUWHkno`O|g91NMgY(BY>YA8E~_iVwK)s4|aIb2NH@It)eh z!N-9SYZ*h*aZy^(xL-Is1paNE7HvWwzfni`fXOxh zi90(J1;eVV_6Tc|frXUe9^nL2x1F>l;90P`zn=u9*IAmUjMsz8WTff3wA&4sAEoU* zi2aNSX49r8FSvix6OF~y0w_%~LYc$f4T?9xnrmp<(25j^i*q=F^`@ZP$p;LW0nSLS z#p*B~6Pd7(RC337Jv5zGI23Gr`ebj!$s`s}WJ6ZVK229EzIm&4pPq3e3Mj&2{}y+E zjc9q~OPdy#@XXuKndU*Q<@wyZvK0~T|hcp6R=v-A!oN@6Kr(kJ+=N%*mR zS%`Q-T|!x@EM>lDx;Af7U-YTyj%1kw4kdeW%15TC(pDD z#Rc|yQr=sj<$Fa`lA)Q36XEm5)}rp96%HLK-wudJM|~waqz5X{-%4zA>Br zCvs%h@Tf<7xX0E9q+zLCAQG~Pnv4lA<-s=Obq+D)ZP1Str&1!lpHLjww#Zfzb48zS zoVbPqVRe;TJ^TytShR5Mps)kHG?%)80bFKuLc|v4v|^YjwkJ2fANx*B0?U5ctOB=wMn^%X3V^|eN-hM|*luVC!tCPrdt2O-d)$gkO!@w1xe?JT z41Cx_H zG3zxVfWr{J%>e*Pu2maQUl!4}G}#^3P^>N;<>E`5ut+CGR+g0))MSy;vQn*0DY(Lz zay4m-Nss&hhDjrF#4%x&nVH%c-7Ky)0_WlqD>ZEo=C}%wBNVB9=nD8pN!-+_*^4*f z_Sh=oz)GE0G|DZI#P;z8ysfwmu{x$YQJLsCZvyufP0sz&8joQ*8_`L93zHTWAe z=#B(G<7q>ls%1|bTn&!k@Ki-!j5wFa?fJ=Im0(bxQmAe8Cw$=Z(%AzYF?U`T@o)Is zx_1reg=}qgUU;+#osrg!$Ae-<+Lp9p`GbQ*DI!3!HkuR4W=|8Uan}^M49EB`(~w!~ zxx#e}Z2Qh8g>{g^O}l~5^K6An#HT@(ZE1y%>dI(0 zaJ3;Uyx|OBbsVBAx`G_7H!`VYlDRx~1z~a+wpBO2;5#0Noa1jK>xQb(D1H_1QnNTy z;_L(`+eJZ?=!D&=_*q5Wr8S!l5(qMf>&~D1Oneh% zNWm~&mlmDdm96Mp^H5N$O&(u*HEVked=Of=UId%6MmJpobZ>VFsc50SNw3<&Qtfg2 z9*^vElQVX^N$`Dl?^QG9x}jIwHdHtR=#>aV5t1JB@l$?|*W5~nvudcYA-!LuC!O_( zyEg+EOFiQwRi4jl2Wm$dcjxrf3sg>}`Q!{KcSO9ZQ+4fqixCPQhE(dQRRg_${XP5F~+WNqg$M>VSvG z<1!tpxGmy?`X1s0vefy_y009CzPgxFq3R`uozk@F6IIWla&l~%YZc$`?3H+R(!>EQ zdG2+OgGV~&%u`2gT+ITf1&-TOUcIwA*7aPyxo9GpWcu|>u4j{ZB@4kjGeH(A!<7_r zXc6xG5FhmE91*XigLYI5GA|6_&X&}*SJ)D1`)TTkkP*yp@2w@D-uP0aU;4cZPvvSQ zbGbR%yDi-B|G56<2A+-n{_pQj@BjE5*A;FNUj1?@4mI=F`|x$K?bmI6GM9J};_rOW3%n!7ExGw0OSyJ&vEY@suJ@EBUT}s2kyb+)(pSs@U<7Q%qUj)3lC-myZD$M z03SZIVKq8H{R&sJttW!D1j)?0S@1;Ve!;(LG;0-{fJ09h@aQsl^3NMBBtogaglR$N zf{r2qnjQn-tL!133n|}Jp#yFA!%>>#OZz;h>vWy2({;K|*XcT4r|Wc`uG4k8PS@!= eU8n1Govzb$x=z>WI$i(I*M9-IsZp2!pa1|3bD((u diff --git a/policy-rawhide-contrib.patch b/policy-rawhide-contrib.patch index b4f8d8fa..811c8b8c 100644 --- a/policy-rawhide-contrib.patch +++ b/policy-rawhide-contrib.patch @@ -52309,7 +52309,7 @@ index 6194b80..e27c53d 100644 ') + diff --git a/mozilla.te b/mozilla.te -index 11ac8e4..653ba10 100644 +index 11ac8e4..9336364 100644 --- a/mozilla.te +++ b/mozilla.te @@ -6,17 +6,56 @@ policy_module(mozilla, 2.8.0) @@ -52762,7 +52762,7 @@ index 11ac8e4..653ba10 100644 ') optional_policy(` -@@ -300,259 +339,254 @@ optional_policy(` +@@ -300,259 +339,257 @@ optional_policy(` ######################################## # @@ -52777,6 +52777,8 @@ index 11ac8e4..653ba10 100644 +dontaudit mozilla_plugin_t self:capability2 block_suspend; +dontaudit mozilla_plugin_t self:cap_userns {sys_ptrace }; + ++ ++allow mozilla_plugin_t self:cap_userns {sys_admin sys_chroot}; +allow mozilla_plugin_t self:process { getsession setcap setpgid getsched setsched signal_perms execmem execstack setrlimit transition }; +allow mozilla_plugin_t self:netlink_route_socket r_netlink_socket_perms; +allow mozilla_plugin_t self:netlink_socket create_socket_perms; @@ -52836,21 +52838,23 @@ index 11ac8e4..653ba10 100644 +can_exec(mozilla_plugin_t, mozilla_plugin_tmp_t) manage_files_pattern(mozilla_plugin_t, mozilla_plugin_tmpfs_t, mozilla_plugin_tmpfs_t) ++manage_dirs_pattern(mozilla_plugin_t, mozilla_plugin_tmpfs_t, mozilla_plugin_tmpfs_t) manage_lnk_files_pattern(mozilla_plugin_t, mozilla_plugin_tmpfs_t, mozilla_plugin_tmpfs_t) manage_fifo_files_pattern(mozilla_plugin_t, mozilla_plugin_tmpfs_t, mozilla_plugin_tmpfs_t) manage_sock_files_pattern(mozilla_plugin_t, mozilla_plugin_tmpfs_t, mozilla_plugin_tmpfs_t) - fs_tmpfs_filetrans(mozilla_plugin_t, mozilla_plugin_tmpfs_t, { file lnk_file sock_file fifo_file }) +-fs_tmpfs_filetrans(mozilla_plugin_t, mozilla_plugin_tmpfs_t, { file lnk_file sock_file fifo_file }) ++fs_tmpfs_filetrans(mozilla_plugin_t, mozilla_plugin_tmpfs_t, { file dir lnk_file sock_file fifo_file }) +userdom_manage_home_texlive(mozilla_plugin_t) allow mozilla_plugin_t mozilla_plugin_rw_t:dir list_dir_perms; -allow mozilla_plugin_t mozilla_plugin_rw_t:file read_file_perms; -allow mozilla_plugin_t mozilla_plugin_rw_t:lnk_file read_lnk_file_perms; +- +-dgram_send_pattern(mozilla_plugin_t, mozilla_plugin_tmpfs_t, mozilla_plugin_tmpfs_t, mozilla_t) +-stream_connect_pattern(mozilla_plugin_t, mozilla_plugin_tmpfs_t, mozilla_plugin_tmpfs_t, mozilla_t) +read_lnk_files_pattern(mozilla_plugin_t, mozilla_plugin_rw_t, mozilla_plugin_rw_t) +read_files_pattern(mozilla_plugin_t, mozilla_plugin_rw_t, mozilla_plugin_rw_t) --dgram_send_pattern(mozilla_plugin_t, mozilla_plugin_tmpfs_t, mozilla_plugin_tmpfs_t, mozilla_t) --stream_connect_pattern(mozilla_plugin_t, mozilla_plugin_tmpfs_t, mozilla_plugin_tmpfs_t, mozilla_t) -- -can_exec(mozilla_plugin_t, { mozilla_exec_t mozilla_plugin_home_t mozilla_plugin_tmp_t }) +can_exec(mozilla_plugin_t, mozilla_exec_t) @@ -53162,7 +53166,7 @@ index 11ac8e4..653ba10 100644 ') optional_policy(` -@@ -560,7 +594,11 @@ optional_policy(` +@@ -560,7 +597,11 @@ optional_policy(` ') optional_policy(` @@ -53175,7 +53179,7 @@ index 11ac8e4..653ba10 100644 ') optional_policy(` -@@ -568,108 +606,144 @@ optional_policy(` +@@ -568,108 +609,144 @@ optional_policy(` ') optional_policy(` diff --git a/selinux-policy.spec b/selinux-policy.spec index 09d7df10..872bf61a 100644 --- a/selinux-policy.spec +++ b/selinux-policy.spec @@ -19,7 +19,7 @@ Summary: SELinux policy configuration Name: selinux-policy Version: 3.13.1 -Release: 223%{?dist} +Release: 224%{?dist} License: GPLv2+ Group: System Environment/Base Source: serefpolicy-%{version}.tgz @@ -675,6 +675,9 @@ exit 0 %endif %changelog +* Tue Nov 08 2016 Lukas Vrabec - 3.13.1-224 +- Allow watching netflix using Firefox + * Mon Nov 07 2016 Lukas Vrabec - 3.13.1-223 - nmbd_t needs net_admin capability like smbd - Add interface chronyd_manage_pid() Allow logrotate to manage chrony pids