diff options
author | Philip Tricca <flihp@twobit.us> | 2016-03-07 05:12:48 +0000 |
---|---|---|
committer | Philip Tricca <flihp@twobit.us> | 2016-03-21 03:21:32 +0000 |
commit | a0b7bd26bb9962f84d68ea8a21d921961bdfd735 (patch) | |
tree | bf8800169780d90052b4dff99d7e20210472d3aa | |
parent | 39b93f85885876e1e9056c332c240cd15fc80473 (diff) | |
download | meta-selinux-a0b7bd26bb9962f84d68ea8a21d921961bdfd735.tar.gz |
refpolicy: Replace 2.2014120 with release 2.20151208.
This was mostly straight forward. Had to refresh a single patch:
poky-policy-fix-new-SELINUXMNT-in-sys.patch
Signed-off-by: Philip Tricca <flihp@twobit.us>
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/ftp-add-ftpd_t-to-mlsfilewrite.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/ftp-add-ftpd_t-to-mlsfilewrite.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-clock.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-clock.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-corecommands.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-corecommands.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-dmesg.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-dmesg.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-bind.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-bind.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-real-path_login.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-real-path_login.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-real-path_resolv.conf.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-real-path_resolv.conf.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-real-path_shadow.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-real-path_shadow.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-real-path_su.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-real-path_su.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fstools.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fstools.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-ftpwho-dir.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-ftpwho-dir.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-iptables.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-iptables.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-mta.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-mta.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-netutils.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-netutils.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-nscd.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-nscd.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-rpm.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-rpm.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-screen.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-screen.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-ssh.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-ssh.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-su.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-su.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-subs_dist.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-subs_dist.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-sysnetwork.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-sysnetwork.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-udevd.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-udevd.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-update-alternatives_hostname.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-update-alternatives_hostname.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-update-alternatives_sysklogd.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-update-alternatives_sysklogd.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-update-alternatives_sysvinit.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-update-alternatives_sysvinit.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-bsdpty_device_t.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-bsdpty_device_t.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-syslogd_t-symlink.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-syslogd_t-symlink.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-tmp-symlink.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-tmp-symlink.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-var-cache-symlink.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-var-cache-symlink.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-var-log-symlink-apache.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-var-log-symlink-apache.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-var-log-symlink-audisp_remote_t.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-var-log-symlink-audisp_remote_t.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-var-log-symlink.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-var-log-symlink.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-syslogd_t-to-trusted-object.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-syslogd_t-to-trusted-object.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-allow-nfsd-to-exec-shell-commands.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-allow-nfsd-to-exec-shell-commands.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-allow-setfiles_t-to-read-symlinks.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-allow-setfiles_t-to-read-symlinks.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-allow-sysadm-to-run-rpcinfo.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-allow-sysadm-to-run-rpcinfo.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-don-t-audit-tty_device_t.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-don-t-audit-tty_device_t.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-dmesg-to-use-dev-kmsg.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-dmesg-to-use-dev-kmsg.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-new-SELINUXMNT-in-sys.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-new-SELINUXMNT-in-sys.patch) | 100 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-nfsd_t-to-mount_nfsd_fs_t.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-nfsd_t-to-mount_nfsd_fs_t.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-setfiles-statvfs-get-file-count.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-setfiles-statvfs-get-file-count.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-seutils-manage-config-files.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-seutils-manage-config-files.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-2.20151208/refpolicy-update-for_systemd.patch (renamed from recipes-security/refpolicy/refpolicy-2.20141203/refpolicy-update-for_systemd.patch) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-mcs_2.20151208.bb (renamed from recipes-security/refpolicy/refpolicy-mcs_2.20141203.bb) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-minimum_2.20151208.bb (renamed from recipes-security/refpolicy/refpolicy-minimum_2.20141203.bb) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-mls_2.20151208.bb (renamed from recipes-security/refpolicy/refpolicy-mls_2.20141203.bb) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-standard_2.20151208.bb (renamed from recipes-security/refpolicy/refpolicy-standard_2.20141203.bb) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy-targeted_2.20151208.bb (renamed from recipes-security/refpolicy/refpolicy-targeted_2.20141203.bb) | 0 | ||||
-rw-r--r-- | recipes-security/refpolicy/refpolicy_2.20151208.inc (renamed from recipes-security/refpolicy/refpolicy_2.20141203.inc) | 6 |
49 files changed, 31 insertions, 75 deletions
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/ftp-add-ftpd_t-to-mlsfilewrite.patch b/recipes-security/refpolicy/refpolicy-2.20151208/ftp-add-ftpd_t-to-mlsfilewrite.patch index 49da4b6..49da4b6 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/ftp-add-ftpd_t-to-mlsfilewrite.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/ftp-add-ftpd_t-to-mlsfilewrite.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-clock.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-clock.patch index 3ff8f55..3ff8f55 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-clock.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-clock.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-corecommands.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-corecommands.patch index 24b67c3..24b67c3 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-corecommands.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-corecommands.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-dmesg.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-dmesg.patch index db4c4d4..db4c4d4 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-dmesg.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-dmesg.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-bind.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-bind.patch index 59ba5bc..59ba5bc 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-bind.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-bind.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-real-path_login.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-real-path_login.patch index 427181e..427181e 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-real-path_login.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-real-path_login.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-real-path_resolv.conf.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-real-path_resolv.conf.patch index 80cca67..80cca67 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-real-path_resolv.conf.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-real-path_resolv.conf.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-real-path_shadow.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-real-path_shadow.patch index 29ac2c3..29ac2c3 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-real-path_shadow.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-real-path_shadow.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-real-path_su.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-real-path_su.patch index b0392ce..b0392ce 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fix-real-path_su.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fix-real-path_su.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fstools.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fstools.patch index 9c45694..9c45694 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-fstools.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-fstools.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-ftpwho-dir.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-ftpwho-dir.patch index a7d434f..a7d434f 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-ftpwho-dir.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-ftpwho-dir.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-iptables.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-iptables.patch index 89b1547..89b1547 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-iptables.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-iptables.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-mta.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-mta.patch index bbd83ec..bbd83ec 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-mta.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-mta.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-netutils.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-netutils.patch index b45d03e..b45d03e 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-netutils.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-netutils.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-nscd.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-nscd.patch index 1db328c..1db328c 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-nscd.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-nscd.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-rpm.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-rpm.patch index 7ba3380..7ba3380 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-rpm.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-rpm.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-screen.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-screen.patch index 3218194..3218194 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-screen.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-screen.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-ssh.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-ssh.patch index 9aeb3a2..9aeb3a2 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-ssh.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-ssh.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-su.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-su.patch index 358e4ef..358e4ef 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-su.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-su.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-subs_dist.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-subs_dist.patch index cfec7d9..cfec7d9 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-subs_dist.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-subs_dist.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-sysnetwork.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-sysnetwork.patch index 64f497d..64f497d 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-sysnetwork.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-sysnetwork.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-udevd.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-udevd.patch index c6c19be..c6c19be 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-udevd.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-udevd.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-update-alternatives_hostname.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-update-alternatives_hostname.patch index cedb5b5..cedb5b5 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-update-alternatives_hostname.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-update-alternatives_hostname.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-update-alternatives_sysklogd.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-update-alternatives_sysklogd.patch index 868ee6b..868ee6b 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-update-alternatives_sysklogd.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-update-alternatives_sysklogd.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-update-alternatives_sysvinit.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-update-alternatives_sysvinit.patch index 3a617d8..3a617d8 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-fc-update-alternatives_sysvinit.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-fc-update-alternatives_sysvinit.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-bsdpty_device_t.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-bsdpty_device_t.patch index 9a3322f..9a3322f 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-bsdpty_device_t.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-bsdpty_device_t.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-syslogd_t-symlink.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-syslogd_t-symlink.patch index aa9734a..aa9734a 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-syslogd_t-symlink.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-syslogd_t-symlink.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-tmp-symlink.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-tmp-symlink.patch index 210c297..210c297 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-tmp-symlink.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-tmp-symlink.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-var-cache-symlink.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-var-cache-symlink.patch index 18a92dd..18a92dd 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-var-cache-symlink.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-var-cache-symlink.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-var-log-symlink-apache.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-var-log-symlink-apache.patch index 8bc40c4..8bc40c4 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-var-log-symlink-apache.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-var-log-symlink-apache.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-var-log-symlink-audisp_remote_t.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-var-log-symlink-audisp_remote_t.patch index cbf0f7d..cbf0f7d 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-var-log-symlink-audisp_remote_t.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-var-log-symlink-audisp_remote_t.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-var-log-symlink.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-var-log-symlink.patch index b06f3ef..b06f3ef 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-rules-for-var-log-symlink.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-rules-for-var-log-symlink.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-syslogd_t-to-trusted-object.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-syslogd_t-to-trusted-object.patch index 92b1592..92b1592 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-add-syslogd_t-to-trusted-object.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-add-syslogd_t-to-trusted-object.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-allow-nfsd-to-exec-shell-commands.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-allow-nfsd-to-exec-shell-commands.patch index e77a730..e77a730 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-allow-nfsd-to-exec-shell-commands.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-allow-nfsd-to-exec-shell-commands.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-allow-setfiles_t-to-read-symlinks.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-allow-setfiles_t-to-read-symlinks.patch index 9ef61b4..9ef61b4 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-allow-setfiles_t-to-read-symlinks.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-allow-setfiles_t-to-read-symlinks.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-allow-sysadm-to-run-rpcinfo.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-allow-sysadm-to-run-rpcinfo.patch index ec3dbf4..ec3dbf4 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-allow-sysadm-to-run-rpcinfo.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-allow-sysadm-to-run-rpcinfo.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-don-t-audit-tty_device_t.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-don-t-audit-tty_device_t.patch index 82370d8..82370d8 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-don-t-audit-tty_device_t.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-don-t-audit-tty_device_t.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-dmesg-to-use-dev-kmsg.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-dmesg-to-use-dev-kmsg.patch index d6c8dbf..d6c8dbf 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-dmesg-to-use-dev-kmsg.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-dmesg-to-use-dev-kmsg.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-new-SELINUXMNT-in-sys.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-new-SELINUXMNT-in-sys.patch index 302a38f..7e92b64 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-new-SELINUXMNT-in-sys.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-new-SELINUXMNT-in-sys.patch | |||
@@ -14,8 +14,10 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
14 | policy/modules/kernel/selinux.if | 34 ++++++++++++++++++++++++++++++++-- | 14 | policy/modules/kernel/selinux.if | 34 ++++++++++++++++++++++++++++++++-- |
15 | 1 file changed, 32 insertions(+), 2 deletions(-) | 15 | 1 file changed, 32 insertions(+), 2 deletions(-) |
16 | 16 | ||
17 | --- a/policy/modules/kernel/selinux.if | 17 | Index: refpolicy/policy/modules/kernel/selinux.if |
18 | +++ b/policy/modules/kernel/selinux.if | 18 | =================================================================== |
19 | --- refpolicy.orig/policy/modules/kernel/selinux.if | ||
20 | +++ refpolicy/policy/modules/kernel/selinux.if | ||
19 | @@ -58,6 +58,10 @@ interface(`selinux_get_fs_mount',` | 21 | @@ -58,6 +58,10 @@ interface(`selinux_get_fs_mount',` |
20 | type security_t; | 22 | type security_t; |
21 | ') | 23 | ') |
@@ -27,7 +29,7 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
27 | # starting in libselinux 2.0.5, init_selinuxmnt() will | 29 | # starting in libselinux 2.0.5, init_selinuxmnt() will |
28 | # attempt to short circuit by checking if SELINUXMNT | 30 | # attempt to short circuit by checking if SELINUXMNT |
29 | # (/selinux) is already a selinuxfs | 31 | # (/selinux) is already a selinuxfs |
30 | @@ -84,6 +88,7 @@ interface(`selinux_dontaudit_get_fs_moun | 32 | @@ -88,6 +92,7 @@ interface(`selinux_dontaudit_get_fs_moun |
31 | type security_t; | 33 | type security_t; |
32 | ') | 34 | ') |
33 | 35 | ||
@@ -35,7 +37,7 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
35 | # starting in libselinux 2.0.5, init_selinuxmnt() will | 37 | # starting in libselinux 2.0.5, init_selinuxmnt() will |
36 | # attempt to short circuit by checking if SELINUXMNT | 38 | # attempt to short circuit by checking if SELINUXMNT |
37 | # (/selinux) is already a selinuxfs | 39 | # (/selinux) is already a selinuxfs |
38 | @@ -109,6 +114,8 @@ interface(`selinux_mount_fs',` | 40 | @@ -117,6 +122,8 @@ interface(`selinux_mount_fs',` |
39 | type security_t; | 41 | type security_t; |
40 | ') | 42 | ') |
41 | 43 | ||
@@ -44,7 +46,7 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
44 | allow $1 security_t:filesystem mount; | 46 | allow $1 security_t:filesystem mount; |
45 | ') | 47 | ') |
46 | 48 | ||
47 | @@ -128,6 +135,8 @@ interface(`selinux_remount_fs',` | 49 | @@ -136,6 +143,8 @@ interface(`selinux_remount_fs',` |
48 | type security_t; | 50 | type security_t; |
49 | ') | 51 | ') |
50 | 52 | ||
@@ -53,7 +55,7 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
53 | allow $1 security_t:filesystem remount; | 55 | allow $1 security_t:filesystem remount; |
54 | ') | 56 | ') |
55 | 57 | ||
56 | @@ -146,6 +155,8 @@ interface(`selinux_unmount_fs',` | 58 | @@ -154,6 +163,8 @@ interface(`selinux_unmount_fs',` |
57 | type security_t; | 59 | type security_t; |
58 | ') | 60 | ') |
59 | 61 | ||
@@ -62,24 +64,24 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
62 | allow $1 security_t:filesystem unmount; | 64 | allow $1 security_t:filesystem unmount; |
63 | ') | 65 | ') |
64 | 66 | ||
65 | @@ -164,6 +175,8 @@ interface(`selinux_getattr_fs',` | 67 | @@ -172,6 +183,8 @@ interface(`selinux_getattr_fs',` |
66 | type security_t; | 68 | type security_t; |
67 | ') | 69 | ') |
68 | 70 | ||
69 | + dev_getattr_sysfs_dirs($1) | 71 | + dev_getattr_sysfs_dirs($1) |
70 | + dev_search_sysfs($1) | 72 | + dev_search_sysfs($1) |
71 | allow $1 security_t:filesystem getattr; | 73 | allow $1 security_t:filesystem getattr; |
72 | ') | ||
73 | 74 | ||
74 | @@ -183,6 +196,7 @@ interface(`selinux_dontaudit_getattr_fs' | 75 | dev_getattr_sysfs($1) |
76 | @@ -194,6 +207,7 @@ interface(`selinux_dontaudit_getattr_fs' | ||
75 | type security_t; | 77 | type security_t; |
76 | ') | 78 | ') |
77 | 79 | ||
78 | + dev_dontaudit_search_sysfs($1) | 80 | + dev_dontaudit_search_sysfs($1) |
79 | dontaudit $1 security_t:filesystem getattr; | 81 | dontaudit $1 security_t:filesystem getattr; |
80 | ') | ||
81 | 82 | ||
82 | @@ -202,6 +216,7 @@ interface(`selinux_dontaudit_getattr_dir | 83 | dev_dontaudit_getattr_sysfs($1) |
84 | @@ -216,6 +230,7 @@ interface(`selinux_dontaudit_getattr_dir | ||
83 | type security_t; | 85 | type security_t; |
84 | ') | 86 | ') |
85 | 87 | ||
@@ -87,7 +89,7 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
87 | dontaudit $1 security_t:dir getattr; | 89 | dontaudit $1 security_t:dir getattr; |
88 | ') | 90 | ') |
89 | 91 | ||
90 | @@ -220,6 +235,7 @@ interface(`selinux_search_fs',` | 92 | @@ -234,6 +249,7 @@ interface(`selinux_search_fs',` |
91 | type security_t; | 93 | type security_t; |
92 | ') | 94 | ') |
93 | 95 | ||
@@ -95,7 +97,7 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
95 | dev_search_sysfs($1) | 97 | dev_search_sysfs($1) |
96 | allow $1 security_t:dir search_dir_perms; | 98 | allow $1 security_t:dir search_dir_perms; |
97 | ') | 99 | ') |
98 | @@ -239,6 +255,7 @@ interface(`selinux_dontaudit_search_fs', | 100 | @@ -253,6 +269,7 @@ interface(`selinux_dontaudit_search_fs', |
99 | type security_t; | 101 | type security_t; |
100 | ') | 102 | ') |
101 | 103 | ||
@@ -103,7 +105,7 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
103 | dontaudit $1 security_t:dir search_dir_perms; | 105 | dontaudit $1 security_t:dir search_dir_perms; |
104 | ') | 106 | ') |
105 | 107 | ||
106 | @@ -258,6 +275,7 @@ interface(`selinux_dontaudit_read_fs',` | 108 | @@ -272,6 +289,7 @@ interface(`selinux_dontaudit_read_fs',` |
107 | type security_t; | 109 | type security_t; |
108 | ') | 110 | ') |
109 | 111 | ||
@@ -111,7 +113,7 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
111 | dontaudit $1 security_t:dir search_dir_perms; | 113 | dontaudit $1 security_t:dir search_dir_perms; |
112 | dontaudit $1 security_t:file read_file_perms; | 114 | dontaudit $1 security_t:file read_file_perms; |
113 | ') | 115 | ') |
114 | @@ -279,6 +297,7 @@ interface(`selinux_get_enforce_mode',` | 116 | @@ -293,6 +311,7 @@ interface(`selinux_get_enforce_mode',` |
115 | type security_t; | 117 | type security_t; |
116 | ') | 118 | ') |
117 | 119 | ||
@@ -119,23 +121,7 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
119 | dev_search_sysfs($1) | 121 | dev_search_sysfs($1) |
120 | allow $1 security_t:dir list_dir_perms; | 122 | allow $1 security_t:dir list_dir_perms; |
121 | allow $1 security_t:file read_file_perms; | 123 | allow $1 security_t:file read_file_perms; |
122 | @@ -313,6 +332,7 @@ interface(`selinux_set_enforce_mode',` | 124 | @@ -361,6 +380,7 @@ interface(`selinux_read_policy',` |
123 | bool secure_mode_policyload; | ||
124 | ') | ||
125 | |||
126 | + dev_getattr_sysfs_dirs($1) | ||
127 | dev_search_sysfs($1) | ||
128 | allow $1 security_t:dir list_dir_perms; | ||
129 | allow $1 security_t:file rw_file_perms; | ||
130 | @@ -345,6 +365,7 @@ interface(`selinux_load_policy',` | ||
131 | bool secure_mode_policyload; | ||
132 | ') | ||
133 | |||
134 | + dev_getattr_sysfs_dirs($1) | ||
135 | dev_search_sysfs($1) | ||
136 | allow $1 security_t:dir list_dir_perms; | ||
137 | allow $1 security_t:file rw_file_perms; | ||
138 | @@ -375,6 +396,7 @@ interface(`selinux_read_policy',` | ||
139 | type security_t; | 125 | type security_t; |
140 | ') | 126 | ') |
141 | 127 | ||
@@ -143,35 +129,23 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
143 | dev_search_sysfs($1) | 129 | dev_search_sysfs($1) |
144 | allow $1 security_t:dir list_dir_perms; | 130 | allow $1 security_t:dir list_dir_perms; |
145 | allow $1 security_t:file read_file_perms; | 131 | allow $1 security_t:file read_file_perms; |
146 | @@ -440,8 +462,8 @@ interface(`selinux_set_generic_booleans' | 132 | @@ -426,6 +446,7 @@ interface(`selinux_set_generic_booleans' |
147 | type security_t; | 133 | type security_t; |
148 | ') | 134 | ') |
149 | 135 | ||
150 | + dev_getattr_sysfs_dirs($1) | 136 | + dev_getattr_sysfs_dirs($1) |
151 | dev_search_sysfs($1) | 137 | dev_search_sysfs($1) |
152 | - | ||
153 | allow $1 security_t:dir list_dir_perms; | ||
154 | allow $1 security_t:file rw_file_perms; | ||
155 | 138 | ||
156 | @@ -482,8 +504,8 @@ interface(`selinux_set_all_booleans',` | 139 | allow $1 security_t:dir list_dir_perms; |
140 | @@ -463,6 +484,7 @@ interface(`selinux_set_all_booleans',` | ||
157 | bool secure_mode_policyload; | 141 | bool secure_mode_policyload; |
158 | ') | 142 | ') |
159 | 143 | ||
160 | + dev_getattr_sysfs_dirs($1) | 144 | + dev_getattr_sysfs_dirs($1) |
161 | dev_search_sysfs($1) | 145 | dev_search_sysfs($1) |
162 | - | ||
163 | allow $1 security_t:dir list_dir_perms; | ||
164 | allow $1 { boolean_type -secure_mode_policyload_t }:file rw_file_perms; | ||
165 | allow $1 secure_mode_policyload_t:file read_file_perms; | ||
166 | @@ -528,6 +550,7 @@ interface(`selinux_set_parameters',` | ||
167 | attribute can_setsecparam; | ||
168 | ') | ||
169 | 146 | ||
170 | + dev_getattr_sysfs_dirs($1) | ||
171 | dev_search_sysfs($1) | ||
172 | allow $1 security_t:dir list_dir_perms; | 147 | allow $1 security_t:dir list_dir_perms; |
173 | allow $1 security_t:file rw_file_perms; | 148 | @@ -522,6 +544,7 @@ interface(`selinux_validate_context',` |
174 | @@ -552,6 +575,7 @@ interface(`selinux_validate_context',` | ||
175 | type security_t; | 149 | type security_t; |
176 | ') | 150 | ') |
177 | 151 | ||
@@ -179,7 +153,7 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
179 | dev_search_sysfs($1) | 153 | dev_search_sysfs($1) |
180 | allow $1 security_t:dir list_dir_perms; | 154 | allow $1 security_t:dir list_dir_perms; |
181 | allow $1 security_t:file rw_file_perms; | 155 | allow $1 security_t:file rw_file_perms; |
182 | @@ -574,6 +598,7 @@ interface(`selinux_dontaudit_validate_co | 156 | @@ -544,6 +567,7 @@ interface(`selinux_dontaudit_validate_co |
183 | type security_t; | 157 | type security_t; |
184 | ') | 158 | ') |
185 | 159 | ||
@@ -187,7 +161,7 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
187 | dontaudit $1 security_t:dir list_dir_perms; | 161 | dontaudit $1 security_t:dir list_dir_perms; |
188 | dontaudit $1 security_t:file rw_file_perms; | 162 | dontaudit $1 security_t:file rw_file_perms; |
189 | dontaudit $1 security_t:security check_context; | 163 | dontaudit $1 security_t:security check_context; |
190 | @@ -595,6 +620,7 @@ interface(`selinux_compute_access_vector | 164 | @@ -565,6 +589,7 @@ interface(`selinux_compute_access_vector |
191 | type security_t; | 165 | type security_t; |
192 | ') | 166 | ') |
193 | 167 | ||
@@ -195,34 +169,16 @@ Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com> | |||
195 | dev_search_sysfs($1) | 169 | dev_search_sysfs($1) |
196 | allow $1 security_t:dir list_dir_perms; | 170 | allow $1 security_t:dir list_dir_perms; |
197 | allow $1 security_t:file rw_file_perms; | 171 | allow $1 security_t:file rw_file_perms; |
198 | @@ -617,6 +643,7 @@ interface(`selinux_compute_create_contex | 172 | @@ -660,6 +685,13 @@ interface(`selinux_compute_user_contexts |
199 | type security_t; | 173 | type security_t; |
200 | ') | 174 | ') |
201 | 175 | ||
202 | + dev_getattr_sysfs_dirs($1) | 176 | + dev_getattr_sysfs_dirs($1) |
203 | dev_search_sysfs($1) | ||
204 | allow $1 security_t:dir list_dir_perms; | ||
205 | allow $1 security_t:file rw_file_perms; | ||
206 | @@ -639,6 +666,7 @@ interface(`selinux_compute_member',` | ||
207 | type security_t; | ||
208 | ') | ||
209 | |||
210 | + dev_getattr_sysfs_dirs($1) | 177 | + dev_getattr_sysfs_dirs($1) |
211 | dev_search_sysfs($1) | ||
212 | allow $1 security_t:dir list_dir_perms; | ||
213 | allow $1 security_t:file rw_file_perms; | ||
214 | @@ -669,6 +697,7 @@ interface(`selinux_compute_relabel_conte | ||
215 | type security_t; | ||
216 | ') | ||
217 | |||
218 | + dev_getattr_sysfs_dirs($1) | 178 | + dev_getattr_sysfs_dirs($1) |
219 | dev_search_sysfs($1) | 179 | + dev_getattr_sysfs_dirs($1) |
220 | allow $1 security_t:dir list_dir_perms; | 180 | + dev_getattr_sysfs_dirs($1) |
221 | allow $1 security_t:file rw_file_perms; | 181 | + dev_getattr_sysfs_dirs($1) |
222 | @@ -690,6 +719,7 @@ interface(`selinux_compute_user_contexts | ||
223 | type security_t; | ||
224 | ') | ||
225 | |||
226 | + dev_getattr_sysfs_dirs($1) | 182 | + dev_getattr_sysfs_dirs($1) |
227 | dev_search_sysfs($1) | 183 | dev_search_sysfs($1) |
228 | allow $1 security_t:dir list_dir_perms; | 184 | allow $1 security_t:dir list_dir_perms; |
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-nfsd_t-to-mount_nfsd_fs_t.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-nfsd_t-to-mount_nfsd_fs_t.patch index f04ebec..f04ebec 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-nfsd_t-to-mount_nfsd_fs_t.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-nfsd_t-to-mount_nfsd_fs_t.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-setfiles-statvfs-get-file-count.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-setfiles-statvfs-get-file-count.patch index 0b8cc5d..0b8cc5d 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-setfiles-statvfs-get-file-count.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-setfiles-statvfs-get-file-count.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-seutils-manage-config-files.patch b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-seutils-manage-config-files.patch index be33bf1..be33bf1 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/poky-policy-fix-seutils-manage-config-files.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/poky-policy-fix-seutils-manage-config-files.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-2.20141203/refpolicy-update-for_systemd.patch b/recipes-security/refpolicy/refpolicy-2.20151208/refpolicy-update-for_systemd.patch index 2ae4185..2ae4185 100644 --- a/recipes-security/refpolicy/refpolicy-2.20141203/refpolicy-update-for_systemd.patch +++ b/recipes-security/refpolicy/refpolicy-2.20151208/refpolicy-update-for_systemd.patch | |||
diff --git a/recipes-security/refpolicy/refpolicy-mcs_2.20141203.bb b/recipes-security/refpolicy/refpolicy-mcs_2.20151208.bb index 062727b..062727b 100644 --- a/recipes-security/refpolicy/refpolicy-mcs_2.20141203.bb +++ b/recipes-security/refpolicy/refpolicy-mcs_2.20151208.bb | |||
diff --git a/recipes-security/refpolicy/refpolicy-minimum_2.20141203.bb b/recipes-security/refpolicy/refpolicy-minimum_2.20151208.bb index b275821..b275821 100644 --- a/recipes-security/refpolicy/refpolicy-minimum_2.20141203.bb +++ b/recipes-security/refpolicy/refpolicy-minimum_2.20151208.bb | |||
diff --git a/recipes-security/refpolicy/refpolicy-mls_2.20141203.bb b/recipes-security/refpolicy/refpolicy-mls_2.20151208.bb index 7388232..7388232 100644 --- a/recipes-security/refpolicy/refpolicy-mls_2.20141203.bb +++ b/recipes-security/refpolicy/refpolicy-mls_2.20151208.bb | |||
diff --git a/recipes-security/refpolicy/refpolicy-standard_2.20141203.bb b/recipes-security/refpolicy/refpolicy-standard_2.20151208.bb index 3674fdd..3674fdd 100644 --- a/recipes-security/refpolicy/refpolicy-standard_2.20141203.bb +++ b/recipes-security/refpolicy/refpolicy-standard_2.20151208.bb | |||
diff --git a/recipes-security/refpolicy/refpolicy-targeted_2.20141203.bb b/recipes-security/refpolicy/refpolicy-targeted_2.20151208.bb index b169604..b169604 100644 --- a/recipes-security/refpolicy/refpolicy-targeted_2.20141203.bb +++ b/recipes-security/refpolicy/refpolicy-targeted_2.20151208.bb | |||
diff --git a/recipes-security/refpolicy/refpolicy_2.20141203.inc b/recipes-security/refpolicy/refpolicy_2.20151208.inc index d58ddea..ce90b13 100644 --- a/recipes-security/refpolicy/refpolicy_2.20141203.inc +++ b/recipes-security/refpolicy/refpolicy_2.20151208.inc | |||
@@ -1,8 +1,8 @@ | |||
1 | SRC_URI = "https://raw.githubusercontent.com/wiki/TresysTechnology/refpolicy/files/refpolicy-${PV}.tar.bz2;" | 1 | SRC_URI = "https://raw.githubusercontent.com/wiki/TresysTechnology/refpolicy/files/refpolicy-${PV}.tar.bz2;" |
2 | SRC_URI[md5sum] = "69594ede341987904dc2a8b7f2129a93" | 2 | SRC_URI[md5sum] = "7b1ca12e9ea0254508391559cb8f2c41" |
3 | SRC_URI[sha256sum] = "f438209c430d8a2d4ddcbe4bdd3edb46f6af7dc4913637af0b73c635e40c1522" | 3 | SRC_URI[sha256sum] = "2dd2f45a7132137afe8302805c3b7839739759b9ab73dd1815c01afe34ac99de" |
4 | 4 | ||
5 | FILESEXTRAPATHS_prepend := "${THISDIR}/refpolicy-2.20141203:" | 5 | FILESEXTRAPATHS_prepend := "${THISDIR}/refpolicy-2.20151208:" |
6 | 6 | ||
7 | # Fix file contexts for Poky | 7 | # Fix file contexts for Poky |
8 | SRC_URI += "file://poky-fc-subs_dist.patch \ | 8 | SRC_URI += "file://poky-fc-subs_dist.patch \ |