diff --git a/policy-20070703.patch b/policy-20070703.patch index 3162eee..b10ac8d 100644 --- a/policy-20070703.patch +++ b/policy-20070703.patch @@ -14343,7 +14343,7 @@ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/rpc. ## diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/rpc.te serefpolicy-3.0.8/policy/modules/services/rpc.te --- nsaserefpolicy/policy/modules/services/rpc.te 2007-10-22 13:21:39.000000000 -0400 -+++ serefpolicy-3.0.8/policy/modules/services/rpc.te 2008-01-30 09:24:12.000000000 -0500 ++++ serefpolicy-3.0.8/policy/modules/services/rpc.te 2008-03-04 17:02:21.000000000 -0500 @@ -59,10 +59,14 @@ manage_files_pattern(rpcd_t,rpcd_var_run_t,rpcd_var_run_t) files_pid_filetrans(rpcd_t,rpcd_var_run_t,file) @@ -14389,7 +14389,7 @@ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/rpc. +dev_dontaudit_getattr_all_blk_files(nfsd_t) +dev_dontaudit_getattr_all_chr_files(nfsd_t) -+dev_read_lvm_control(nfsd_t) ++dev_rw_lvm_control(nfsd_t) +storage_dontaudit_raw_read_fixed_disk(nfsd_t) + # for /proc/fs/nfs/exports - should we have a new type? diff --git a/selinux-policy.spec b/selinux-policy.spec index e142f05..69105b2 100644 --- a/selinux-policy.spec +++ b/selinux-policy.spec @@ -17,7 +17,7 @@ Summary: SELinux policy configuration Name: selinux-policy Version: 3.0.8 -Release: 90%{?dist} +Release: 91%{?dist} License: GPLv2+ Group: System Environment/Base Source: serefpolicy-%{version}.tgz @@ -381,6 +381,9 @@ exit 0 %endif %changelog +* Tue Mar 4 2008 Dan Walsh 3.0.8-91 +- Allow rpc.mountd to write to lvm_control_t chr_file + * Tue Mar 4 2008 Dan Walsh 3.0.8-90 - Allow mozilla to auth_use_nsswitch - Change location of mock