[DSE-Dev] refpolicy_2.20110726-9_amd64.changes ACCEPTED into unstable
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Sat Jun 30 10:53:39 UTC 2012
Accepted:
refpolicy_2.20110726-9.debian.tar.gz
to main/r/refpolicy/refpolicy_2.20110726-9.debian.tar.gz
refpolicy_2.20110726-9.dsc
to main/r/refpolicy/refpolicy_2.20110726-9.dsc
selinux-policy-default_2.20110726-9_all.deb
to main/r/refpolicy/selinux-policy-default_2.20110726-9_all.deb
selinux-policy-dev_2.20110726-9_all.deb
to main/r/refpolicy/selinux-policy-dev_2.20110726-9_all.deb
selinux-policy-doc_2.20110726-9_all.deb
to main/r/refpolicy/selinux-policy-doc_2.20110726-9_all.deb
selinux-policy-mls_2.20110726-9_all.deb
to main/r/refpolicy/selinux-policy-mls_2.20110726-9_all.deb
selinux-policy-src_2.20110726-9_all.deb
to main/r/refpolicy/selinux-policy-src_2.20110726-9_all.deb
Changes:
refpolicy (2:2.20110726-9) unstable; urgency=high
.
* Enable UBAC as roles aren't useful. I recommend using only roles user_r
and unconfined_r and using UBAC (constraining users from sharing files
between identities) where you would previously have used roles.
* Made cron jobs run in regular user domains such as unconfined_t and user_t
Closes: #679277
* Had the wrong timestamp on the last upload, corrected it for the record.
* Allow ftpd to create sock_file objects under /var/run for proftpd
* Change readahead policy to support memlockd.
* Allow devicekit_power_t, devicekit_disk_t, kerneloops_t, and policykit_t
to send dbus messages to users.
* Grant systemd utilities access to selinuxfs so they can correctly label directories
Closes: #678392
* Assigned type consolekit_var_run_t to /var/run/console(/.*)? because it's
created and managed by consolekit nowadays.
* Created tunable allow_ssh_connect_reserved_ports to allow ssh client to
connect to reserved ports.
* Correctly label all perdition binaries, give perdition_t dac_override, and
allow perdition_t to create it's own pid directories.
* Label /etc/dansguardian as squid_etc_t
* Allow devicekit_power_t to access acpi device and read udev tables and
allow devicekit_disk_t to read udev tables.
* Allow sshd_t to write to fifos inherited from systemd
* High urgency because we really need to have working cron jobs!!!
* Removed the postinst code to upgrade from pre-squeeze packages.
Override entries for your package:
refpolicy_2.20110726-9.dsc - source admin
selinux-policy-default_2.20110726-9_all.deb - optional admin
selinux-policy-dev_2.20110726-9_all.deb - optional admin
selinux-policy-doc_2.20110726-9_all.deb - optional doc
selinux-policy-mls_2.20110726-9_all.deb - extra admin
selinux-policy-src_2.20110726-9_all.deb - optional admin
Announcing to debian-devel-changes at lists.debian.org
Closing bugs: 678392 679277
Thank you for your contribution to Debian.
More information about the SELinux-devel
mailing list