From 28c37cd9e4d3e8c49e0cca333e03945359d5c9ca Mon Sep 17 00:00:00 2001 From: Lukas Vrabec Date: Jul 27 2016 09:29:39 +0000 Subject: * Wed Jul 27 2016 Lukas Vrabec 3.13.1-191.8 - Fix typo bug in ssh policy --- diff --git a/policy-f24-base.patch b/policy-f24-base.patch index f1ad4e1..3a23692 100644 --- a/policy-f24-base.patch +++ b/policy-f24-base.patch @@ -28595,7 +28595,7 @@ index fe0c682..60003bc 100644 + ps_process_pattern($1, sshd_t) +') diff --git a/policy/modules/services/ssh.te b/policy/modules/services/ssh.te -index cc877c7..80996f3 100644 +index cc877c7..4d56aea 100644 --- a/policy/modules/services/ssh.te +++ b/policy/modules/services/ssh.te @@ -6,43 +6,69 @@ policy_module(ssh, 2.4.2) @@ -28707,7 +28707,7 @@ index cc877c7..80996f3 100644 # -allow ssh_t self:capability { setuid setgid dac_override dac_read_search }; -+allow ssh_t self:capability { setcap setuid setgid dac_override dac_read_search }; ++allow ssh_t self:capability { setpcap setuid setgid dac_override dac_read_search }; allow ssh_t self:process ~{ ptrace setcurrent setexec setfscreate setrlimit execmem execstack execheap }; allow ssh_t self:fd use; allow ssh_t self:fifo_file rw_fifo_file_perms; diff --git a/selinux-policy.spec b/selinux-policy.spec index 2df8c88..464f016 100644 --- a/selinux-policy.spec +++ b/selinux-policy.spec @@ -19,7 +19,7 @@ Summary: SELinux policy configuration Name: selinux-policy Version: 3.13.1 -Release: 191.7%{?dist} +Release: 191.8%{?dist} License: GPLv2+ Group: System Environment/Base Source: serefpolicy-%{version}.tgz @@ -645,6 +645,9 @@ exit 0 %endif %changelog +* Wed Jul 27 2016 Lukas Vrabec 3.13.1-191.8 +- Fix typo bug in ssh policy + * Tue Jul 26 2016 Lukas Vrabec 3.13.1-191.7 - Allow lsmd_plugin_t to exec ldconfig. - Allow vnstatd domain to read /sys/class/net/ files