معرفی شرکت ها


selinux-policy-mls-39.3-1.fc39.noarch.rpm


Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر
Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر
Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر
Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر
Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر

توضیحات

SELinux MLS policy
ویژگی مقدار
سیستم عامل Linux
توزیع Fedora 39
مخزن Fedora Everything noarch
نام بسته selinux-policy-mls
نام فایل بسته selinux-policy-mls-39.3-1.fc39.noarch.rpm
نسخه بسته 39.3
انتشار بسته 1.fc39
معماری بسته noarch
نگهدارنده -
تاریخ ساخت Sat 16 Dec 2023 05
هاست سازنده buildvm-x86-08.iad2.fedoraproject.org
نوع بسته .rpm
آدرس صفحه اصلی https://github.com/fedora-selinux/selinux-policy
مجوز GPL-2.0-or-later
حجم دانلود 4.4M
حجم نصب 10.156M
SELinux MLS (Multi Level Security) policy package.


جایگزین ها

بسته نسخه معماری مخزن
selinux-policy-mls-38.28-1.fc39.noarch.rpm 38.28 noarch Fedora Server
selinux-policy-mls-39.2-1.fc39.noarch.rpm 39.2 noarch Fedora Everything
selinux-policy-mls-39.6-1.fc39.noarch.rpm 39.6 noarch Fedora Everything


نیازمندی

مقدار نام
- /bin/sh
- /bin/sh
- /bin/sh
- /bin/sh
- /bin/sh
= 39.3-1.fc39 config(selinux-policy-mls)
- coreutils
>= 3.4-1 policycoreutils
>= 3.4-1 policycoreutils-newrole
= 39.3-1.fc39 selinux-policy
= 39.3-1.fc39 selinux-policy
- setransd


ارائه دهنده

مقدار نام
= 39.3-1.fc39 config(selinux-policy-mls)
= 39.3-1.fc39 selinux-policy-any
= 39.3-1.fc39 selinux-policy-mls


نحوه نصب


نصب پکیج rpm selinux-policy-mls:

    dnf install selinux-policy-mls-39.3-1.fc39.noarch.rpm


فایل ها

مسیرها
/etc/selinux/mls
/etc/selinux/mls/.policy.sha512
/etc/selinux/mls/booleans.subs_dist
/etc/selinux/mls/contexts
/etc/selinux/mls/contexts/customizable_types
/etc/selinux/mls/contexts/dbus_contexts
/etc/selinux/mls/contexts/default_contexts
/etc/selinux/mls/contexts/default_type
/etc/selinux/mls/contexts/failsafe_context
/etc/selinux/mls/contexts/files
/etc/selinux/mls/contexts/files/file_contexts
/etc/selinux/mls/contexts/files/file_contexts.bin
/etc/selinux/mls/contexts/files/file_contexts.homedirs
/etc/selinux/mls/contexts/files/file_contexts.homedirs.bin
/etc/selinux/mls/contexts/files/file_contexts.local
/etc/selinux/mls/contexts/files/file_contexts.local.bin
/etc/selinux/mls/contexts/files/file_contexts.subs
/etc/selinux/mls/contexts/files/file_contexts.subs_dist
/etc/selinux/mls/contexts/files/media
/etc/selinux/mls/contexts/initrc_context
/etc/selinux/mls/contexts/lxc_contexts
/etc/selinux/mls/contexts/openssh_contexts
/etc/selinux/mls/contexts/removable_context
/etc/selinux/mls/contexts/securetty_types
/etc/selinux/mls/contexts/sepgsql_contexts
/etc/selinux/mls/contexts/snapperd_contexts
/etc/selinux/mls/contexts/systemd_contexts
/etc/selinux/mls/contexts/userhelper_context
/etc/selinux/mls/contexts/users
/etc/selinux/mls/contexts/users/guest_u
/etc/selinux/mls/contexts/users/root
/etc/selinux/mls/contexts/users/staff_u
/etc/selinux/mls/contexts/users/unconfined_u
/etc/selinux/mls/contexts/users/user_u
/etc/selinux/mls/contexts/users/xguest_u
/etc/selinux/mls/contexts/virtual_domain_context
/etc/selinux/mls/contexts/virtual_image_context
/etc/selinux/mls/contexts/x_contexts
/etc/selinux/mls/logins
/etc/selinux/mls/policy
/etc/selinux/mls/policy/policy.33
/etc/selinux/mls/setrans.conf
/etc/selinux/mls/seusers
/usr/share/selinux/mls
/usr/share/selinux/mls/base.lst
/usr/share/selinux/mls/modules-base.lst
/usr/share/selinux/mls/modules-contrib.lst
/usr/share/selinux/mls/nonbasemodules.lst
/var/lib/selinux/mls
/var/lib/selinux/mls/active
... and 1062 more


گزارش تغییرات

تاریخ آخرین تغییر جزئیات
2023-12-15

Allow init create and use vsock sockets
Allow ddclient send e-mail notifications
Allow postfix_master_t map postfix data files
Allow thumb_t append to init unix domain stream sockets
Allow spamd_update_t read hardware state information
Allow systemd-sleep create efivarfs files

2023-11-14

Allow graphical applications work in Wayland
Allow map xserver_tmpfs_t files when xserver_clients_write_xshm is on
Allow kdump work with PrivateTmp
Allow dovecot-auth work with PrivateTmp
Allow nfsd get attributes of all filesystems
Allow fido-device-onboard (FDO) read the crack database
Allow ntp to bind and connect to ntske port.
Allow apcupsd cgi scripts read /sys
Allow rpcbind read network sysctls

2023-11-02

Support using systemd containers
Allow kernel_t to manage and relabel all files
Add missing optional_policy() to files_relabel_all_files()
Improve default file context(None) of /var/lib/authselect/backups
Allow targetd write to the syslog pid sock_file
Add ipa_pki_retrieve_key_exec() interface
Allow kdumpctl_t to list all directories with a filesystem type
Allow udev additional permissions
Allow udev load kernel module
Allow sysadm_t to mmap modules_object_t files
Add the unconfined_read_files() and unconfined_list_dirs() interfaces
Allow kernel_generic_helper_t to execute mount(1)

2023-10-02

Allow sssd send SIGKILL to passkey_child running in ipa_otpd_t
Allow systemd-localed create Xserver config dirs
Allow sssd read symlinks in /etc/sssd
Label /dev/gnss[0-9] with gnss_device_t
Allow systemd-sleep read/write efivarfs variables
ci: Fix version number of packit generated srpms
Dontaudit rhsmcertd write memory device
Allow ssh_agent_type create a sockfile in /run/user/USERID
Set default file context of /var/lib/authselect/backups to <<none>>
Allow prosody read network sysctls
Allow cupsd_t to use bpf capability

2023-09-15

Allow sssd domain transition on passkey_child execution conditionally
Allow login_userdomain watch lnk_files in /usr
Allow login_userdomain watch video4linux devices
Change systemd-network-generator transition to include class file
Revert "Change file transition for systemd-network-generator"
Allow nm-dispatcher winbind plugin read/write samba var files
Allow systemd-networkd write to cgroup files
Allow kdump create and use its memfd: objects

2023-08-31

Allow fedora-third-party get generic filesystem attributes
Allow sssd use usb devices conditionally
Update policy for qatlib
Allow ssh_agent_type manage generic cache home files
Update make-rhat-patches.sh file to use the f39 dist-git branch in F39

2023-08-24

Change file transition for systemd-network-generator
Additional support for gnome-initial-setup
Update gnome-initial-setup policy for geoclue
Allow openconnect vpn open vhost net device
Allow cifs.upcall to connect to SSSD also through the /var/run socket
Grant cifs.upcall more required capabilities
Allow xenstored map xenfs files
Update policy for fdo
Allow keepalived watch var_run dirs
Allow svirt to rw /dev/udmabuf
Allow qatlib to modify hardware state information.
Allow key.dns_resolve connect to avahi over a unix stream socket
Allow key.dns_resolve create and use unix datagram socket
Use quay.io as the container image source for CI

2023-08-11

ci: Move srpm/rpm build to packit
.copr: Avoid subshell and changing directory
Allow gpsd, oddjob and oddjob_mkhomedir_t write user_tty_device_t chr_file
Label /usr/libexec/openssh/ssh-pkcs11-helper with ssh_agent_exec_t
Make insights_client_t an unconfined domain
Allow insights-client manage user temporary files
Allow insights-client create all rpm logs with a correct label
Allow insights-client manage generic logs
Allow cloud_init create dhclient var files and init_t manage net_conf_t
Allow insights-client read and write cluster tmpfs files
Allow ipsec read nsfs files
Make tuned work with mls policy
Remove nsplugin_role from mozilla.if
allow mon_procd_t self:cap_userns sys_ptrace
Allow pdns name_bind and name_connect all ports
Set the MLS range of fsdaemon_t to s0 - mls_systemhigh
ci: Move to actions/checkout@v3 version
.copr: Replace chown call with standard workflow safe.directory setting
.copr: Enable `set -u` for robustness
.copr: Simplify root directory variable

2023-08-04

Allow rhsmcertd dbus chat with policykit
Allow polkitd execute pkla-check-authorization with nnp transition
Allow user_u and staff_u get attributes of non-security dirs
Allow unconfined user filetrans chrome_sandbox_home_t
Allow svnserve execute postdrop with a transition
Do not make postfix_postdrop_t type an MTA executable file
Allow samba-dcerpc service manage samba tmp files
Add use_nfs_home_dirs boolean for mozilla_plugin
Fix labeling for no-stub-resolv.conf

2023-08-02

Revert "Allow winbind-rpcd use its private tmp files"
Allow upsmon execute upsmon via a helper script
Allow openconnect vpn read/write inherited vhost net device
Allow winbind-rpcd use its private tmp files
Update samba-dcerpc policy for printing
Allow gpsd,oddjob,oddjob_mkhomedir rw user domain pty
Allow nscd watch system db dirs
Allow qatlib to read sssd public files
Allow fedora-third-party read /sys and proc
Allow systemd-gpt-generator mount a tmpfs filesystem
Allow journald write to cgroup files
Allow rpc.mountd read network sysctls
Allow blueman read the contents of the sysfs filesystem
Allow logrotate_t to map generic files in /etc
Boolean: Allow virt_qemu_ga create ssh directory

2023-07-25

Allow systemd-network-generator send system log messages
Dontaudit the execute permission on sock_file globally
Allow fsadm_t the file mounton permission
Allow named and ndc the io_uring sqpoll permission
Allow sssd io_uring sqpoll permission
Fix location for /run/nsd
Allow qemu-ga get fixed disk devices attributes
Update bitlbee policy
Label /usr/sbin/sos with sosreport_exec_t
Update policy for the sblim-sfcb service
Add the files_getattr_non_auth_dirs() interface
Fix the CI to work with DNF5

2023-07-22

Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild

2023-07-13

Make systemd_tmpfiles_t MLS trusted for lowering the level of files
Revert "Allow insights client map cache_home_t"
Allow nfsidmapd connect to systemd-machined over a unix socket
Allow snapperd connect to kernel over a unix domain stream socket
Allow virt_qemu_ga_t create .ssh dir with correct label
Allow targetd read network sysctls
Set the abrt_handle_event boolean to on
Permit kernel_t to change the user identity in object contexts
Allow insights client map cache_home_t
Label /usr/sbin/mariadbd with mysqld_exec_t
Trim changelog so that it starts at F37 time
Define equivalency for /run/systemd/generator.early

2023-06-29

Allow httpd tcp connect to redis port conditionally
Label only /usr/sbin/ripd and ripngd with zebra_exec_t
Dontaudit aide the execmem permission
Remove permissive from fdo
Allow sa-update manage spamc home files
Allow sa-update connect to systemlog services
Label /usr/lib/systemd/system/mimedefang.service with antivirus_unit_file_t
Allow nsd_crond_t write nsd_var_run_t & connectto nsd_t
Allow bootupd search EFI directory

2023-06-27

Change init_audit_control default value to true
Allow nfsidmapd connect to systemd-userdbd with a unix socket
Add the qatlib module
Add the fdo module
Add the bootupd module
Set default ports for keylime policy
Create policy for qatlib
Add policy for FIDO Device Onboard
Add policy for bootupd
Add the qatlib module
Add the fdo module
Add the bootupd module

2023-06-25

Add support for kafs-dns requested by keyutils
Allow insights-client execmem
Add support for chronyd-restricted
Add init_explicit_domain() interface
Allow fsadm_t to get attributes of cgroup filesystems
Add list_dir_perms to kerberos_read_keytab
Label /var/run/tmpfiles.d/static-nodes.conf with kmod_var_run_t
Allow sendmail manage its runtime files
Allow keyutils_dns_resolver_exec_t be an entrypoint
Allow collectd_t read network state symlinks
Revert "Allow collectd_t read proc_net link files"
Allow nfsd_t to list exports_t dirs
Allow cupsd dbus chat with xdm
Allow haproxy read hardware state information
Add the kafs module