Linux @ CERN

CERN > IT > Linux

CentOS 7 - Updates for x86_64: system environment/base: selinux-policy-doc

selinux-policy-doc - SELinux policy documentation

Website: http://oss.tresys.com/repos/refpolicy/
License: GPLv2+
Vendor: CentOS
Description:
SELinux policy documentation package

Packages

selinux-policy-doc-3.13.1-102.el7_3.16.noarch [2.7 MiB] Changelog by Lukas Vrabec (2017-03-09):
- Allow openvswitch read script state.
- Allow openvswitch exec hostname and readinitrc_t files
Resolves: rhbz#1430751
selinux-policy-doc-3.13.1-102.el7_3.15.noarch [2.7 MiB] Changelog by Lukas Vrabec (2017-02-07):
- Allow sssd_t domain setpgid
Resolves:rhbz#1419836
selinux-policy-doc-3.13.1-102.el7_3.13.noarch [2.7 MiB] Changelog by Lukas Vrabec (2017-01-09):
- Allow systemd container to read/write usermodehelperstate
Resolves: rhbz#1408126
- Allow glusterd_t to bind on glusterd_port_t udp ports.
Resolves: rhbz#1408128
selinux-policy-doc-3.13.1-102.el7_3.7.noarch [2.7 MiB] Changelog by Lukas Vrabec (2016-11-14):
- Update systemd on RHEL-7.2 box to version from RHEL-7.3 and then as a separate yum command update the selinux policy systemd will start generating USER_AVC denials and will start returning "Access Denied" errors to DBus clients.
Resolves: rhbz#1394715
selinux-policy-doc-3.13.1-102.el7_3.4.noarch [2.7 MiB] Changelog by Miroslav Grepl (2016-10-19):
- Allow GlusterFS with RDMA transport to be started correctly. It requires ipc_lock capability together with rw permission on rdma_cm device.
Resolves:#1386620
- Allow glusterd to get attributes on /sys/kernel/config directory.
Resolves:#1386621
selinux-policy-doc-3.13.1-102.el7.noarch [2.7 MiB] Changelog by Dan Walsh (2016-09-27):
- Add virt_sandbox_use_nfs -> virt_use_nfs boolean substitution.
Resolves: rhbz#1355783
selinux-policy-doc-3.13.1-60.el7_2.9.noarch [924 KiB] Changelog by Lukas Vrabec (2016-09-01):
- Dontaudit ldconfig read gluster lib files.
Resolves: rhbz#1372182
- Add interface glusterd_dontaudit_read_lib_dirs()
Resolves: rhbz#1372182
- Dontaudit Occasionally observing AVC's while running geo-rep automation
Resolves: rhbz#1372182
- Allow glusterd to manage socket files labeled as glusterd_brick_t.
Resolves: rhbz#1372191
selinux-policy-doc-3.13.1-60.el7_2.7.noarch [924 KiB] Changelog by Lukas Vrabec (2016-06-10):
- Allow glusterd domain read krb5_keytab_t files.
Resolves: rhbz#1344630
selinux-policy-doc-3.13.1-60.el7_2.3.noarch [923 KiB] Changelog by Lukas Vrabec (2016-01-27):
- Allow openvswitch domain capability sys_rawio
Resolves: rhbz#1299405
selinux-policy-doc-3.13.1-60.el7.noarch [922 KiB] Changelog by Miroslav Grepl (2015-10-14):
Allow hypervvssd to list all mountpoints to have VSS live backup working correctly.
Resolves:#1247880
selinux-policy-doc-3.13.1-23.el7_1.21.noarch [902 KiB] Changelog by Lukas Vrabec (2015-10-13):
- Added labels for files provided by rh-nginx18 collection
Resolves: #1270839
selinux-policy-doc-3.13.1-23.el7_1.18.noarch [902 KiB] Changelog by Miroslav Grepl (2015-09-03):
- Allow qpidd access to /proc/<pid>/net/psched
Resolves: #1254318
selinux-policy-doc-3.13.1-23.el7_1.17.noarch [902 KiB] Changelog by Miroslav Grepl (2015-08-28):
- Dontaudit chrome to read passwd file.
Resolves:#1257816
selinux-policy-doc-3.13.1-23.el7_1.13.noarch [901 KiB] Changelog by Miroslav Grepl (2015-07-28):
- glusterd call pcs utility which calls find for cib.* files and runs pstree under glusterd. Dontaudit access to security files and update gluster boolean to reflect these changes.
-  Allow glusterd to communicate with cluster domains over stream socket.
Resolves:#1238963
selinux-policy-doc-3.13.1-23.el7_1.8.noarch [899 KiB] Changelog by Miroslav Grepl (2015-06-15):
- Back port passenger fixes from RHEL-7.2
- Back port httpd fixes related to gluster+nagios.
- Back port glusterd changs from RHEL-7.2 related to Gluster.
- Back port ctdbd changs from RHEL-7.2 related to Gluster.
- Back port nagios changs from RHEL-7.2 related to Gluster.
- Back port samba changs from RHEL-7.2 related to Gluster.
Resolves:#1230292
Resolves:#1230299
Resolves:#1231649
Resolves:#1231930
Resolves:#1231942
selinux-policy-doc-3.13.1-23.el7_1.7.noarch [898 KiB] Changelog by Miroslav Grepl (2015-04-29):
- Label /usr/libexec/postgresql-ctl as postgresql_exec_t
- Update virt_read_pid_files() interface to allow read also symlinks with virt_var_run_t type.
- Add labeling for /usr/libexec/mysqld_safe-scl-helper.
- Add support for /usr/libexec/mongodb-scl-helper RHSCL helper script.
Resolves:#1209942 
- Allow mysqld_t to use pam.It is needed by MariDB if auth_apm.so auth plugin is used
Resolves:#1214236
- Added label mysqld_etc_t for /etc/my.cnf.d/ dir.
Resolves:#1214235
- Add support for mongod/mongos systemd unit files.
Resolves:#1214194

Listing created by repoview