Группа :: Система/Основа
Пакет: policycoreutils
Главная Изменения Спек Патчи Sources Загрузить Gear Bugs and FR Repocop
23 июня 2022 Daniel Zagaynov <kotopesutility at altlinux.org> 1:3.2-alt6
- Added providing for policycoreutils-python-utils for more compatibility with RHEL.
- Fixed selinux-polgengui (Closes: #30183).
- Rebuilt with LTO.
- Updated dependencies.
- NMU: move gui module to python3-module-policycoreutils-gui (ALT bug 30125)
- Updated to upstream version 3.2.
- Updated to upstream version 3.1.
- Removed runtime dependency on selinux-policy-alt
- Updated to upstream version 3.0.
- NMU.
- policycoreutils-gui: removed requirement on selinux-policy (closes: #35687).
- Updated man pages translation by Olesya Gerasimenko.
- Updated to upstream version 2.9.
- Disabled support for python-2.
- Added man pages translation by Olesya Gerasimenko.
- Updated to upstream version 2.8.
- Obsoleted package python-module-sepolgen (Closes: #34981).
- Fixed build dependencies.
- Updated to upstream version 2.7.
- new version
- downgraded due regression (closes: #32254)
- move _libexecdir/selinux/hll to main package
- new version
- new version
- Add devel package, adjust spec according to Fedora spec
- Add BuildRequires to python-module-pygnome
- Go away from python gnome module dependency
- new version
- New version
- fix mcstrans.service
- Rebuild with new setools
- Add newrole capabilities
- New Version
- newrole: CAP_SETPCAP, capng_lock()
- Update gears tags
- newrole: patch from policycoreutils-2.1.14-37.fc20.src.rpm
- newrole: add CAP_AUDIT_WRITE to list fo drop_capabilities()
- mcstransd: convert sensitivity and categoryset separately
- newrole: add CAP_SETGID to list fo drop_capabilities() (ALT#28784)
- fix restorecond.service (by amike@) (ALT#28073)
- some fixes for mcstrans.service (thanx amike@)
- added restorecond.service for systemd (ALT#28074)
- added mcstrans.service for systemd (ALT#28073)
- 2.1.13
- fixed License
- newrole: Grant CAP_SETGID for pam_tcb.
- newrole: Fix drop_capabilities().
- Fix requires.
- Rebuild with Python-2.7
- Add policycoreutils-alt-autorelabel-fix-path.patch.
- Update gui and po patches from FC.
- spec cleanup.
- add mcstransd subpackage.
- Move /etc/pam.d/newrole into newrole subpackage.
- Move restorecond into its own subpackage.
- made gui subpackage noarch.
- to own /usr/share/sandbox.
- rewrite system-config-selinux.pam.
- enable build gui subpackage.
- move polgen.py back to gui subpackage.
- restorecond init script: add condstop.
- restorecond init script: fix status.
- Drop Russian man pages.
- Package sandbox-x subpackage as noarch.
- fixfiles: set context for root filesystem /dev/* files.
- update policycoreutils-po.patch from FC.
- update policycoreutils-gui.patch from FC.
- slightly spec cleanup.
- add sandbox and sandbox-x subpackages.
- Remove redundant information from description.
- Fix Url.
- Move sepolgen to separate package.
- fixfiles: /.autorelabel -> /etc/selinux/.autorelabel.
- slightly spec cleanup.
- rebuild with libaudit-2.0.4
- build without gui
- package sepolgen
- update policycoreutils-gui.patch from FC
- update translations from FC
- new version
- restorecond.init: use {start,stop}_daemon
- new version
- new version
- first build for Sisyphus, based on specfile from fedora
- Fix Japanese translations
- Change md5 to hashlib.md5 in sepolgen
- Rebuild for Python 2.6
- Fix error checking in restorecond, for inotify_add_watch
- Update to upstream
* semanage: use semanage_mls_enabled() from Stephen Smalley.
- Rebuild for Python 2.6
- Update to upstream
* fcontext add checked local records twice, fix from Dan Walsh.
- Update to upstream
* Allow local file context entries to override policy entries in
semanage from Dan Walsh.
* Newrole error message corrections from Dan Walsh.
* Add exception to audit2why call in audit2allow from Dan Walsh.
- add compression
- Move the usermode-gtk requires to the -gui subpackage.
- Fix traceback in audit2why
- Make GUI use translations
- Fix typo in man page
- Handle selinux disabled correctly
- Handle manipulation of fcontext file correctly
- Add usermode-gtk requires
- Allow addition of local modifications of fcontext policy.
- Fix system-config-selinux booleanspage throwing and exception
- Update po files
- Fix text in newrole
- Fix revertbutton on booleans page in system-config-selinux
- Change semodule calls for libsemanage
- Update to upstream
* Update po files from Dan Walsh.
- Fix semanage help display
- Update to upstream
* fixfiles will now remove all files in /tmp and will check for
unlabeled_t in /tmp and /var/tmp from Dan Walsh.
* add glob support to restorecond from Dan Walsh.
* allow semanage to handle multi-line commands in a single transaction
from Dan Walsh.
- Only call gen_requires once in sepolgen
- Change Requires line to gnome-python2-gnome
- Fix spelling mistakes
- Require libselinux-utils
- Add node support to semanage
- Fix fixfiles to correct unlabeled_t files and remove .? files
- Add glob support to restorecond so it can check every file in the homedir
- Update to upstream
* Merged semanage node support from Christian Kuester.
- Add require libsemanage-python
- Add missing html_util.py file
- Fixes for multiple transactions
- Allow multiple transactions in one semanage command
- Update to upstream
* Add support for boolean files and group support for seusers from Dan Walsh.
* Ensure that setfiles -p output is newline terminated from Russell Coker.
- Allow semanage user to add group lists %groupname
- Fix help
- Update to upstream
* Change setfiles to validate all file_contexts files when using -c from Stephen Smalley.
- Fix boolean handling
- Upgrade to latest sepolgen
- Update po patch
- Additial cleanup of boolean handling for semanage
- Handle ranges of ports in gui
- Fix indent problems in seobject
- Add lockdown wizard
- Allow semanage booleans to take an input file an process lots of booleans at once.
- Default prefix to "user"
- Remove semodule use within semanage
- Fix launching of polgengui from toolbar
- Update to upstream
* Fix audit2allow generation of role-type rules from Karl MacMillan.
- Fix spelling of enforcement
- Fix sepolgen/audit2allow handling of roles
- Fix sepolgen-ifgen processing
- Add deleteall to semanage permissive, cleanup error handling
- Complete removal of rhpl requirement
- Add semanage permissive *
- Fix fixfiles to cleanup /tmp and /var/tmp
- Fix listing of types in gui
- Update to upstream
* Remove security_check_context calls for prefix validation from semanage.
* Change setfiles and restorecon to not relabel if the file already has the correct context value even if -F/force is specified.
- Remove /usr/share/locale/sr@Latn/LC_MESSAGES/policycoreutils.mo
- Add rm -rf /tmp/gconfd-* /tmp/pulse-* /tmp/orbit-* to fixfiles restore
- So that mislabeled files will get removed on full relabel
- Make restorecond not start by default
- Fix polgengui to allow defining of confined roles.
- Add patches from Lubomir Rintel <lkundrak@v3.sk>
* Add necessary runtime dependencies on setools-console for -gui
* separate stderr when run seinfo commands - Update to upstream
* Update semanage man page for booleans from Dan Walsh.
* Add further error checking to seobject.py for setting booleans.
- Uninvasive (ie no string or widget changes) HIG approximations
in selinux-polgenui
- Move s-c-selinux to the right menu
- Fix boolean descriptions
- Fix semanage man page
- Don't use prefix in gui
- Update to upstream
* Update audit2allow to report dontaudit cases from Dan Walsh.
* Fix semanage port to use --proto from Caleb Case.
- Update to upstream
* Fix for segfault when conf file parse error occurs.
- Don't show tabs on polgengui
- Update to upstream
* Merged fix fixfiles option processing from Vaclav Ovsik. - Added existing users, staff and user_t users to polgengui
- Add messages for audit2allow DONTAUDIT
- Add ability to transition to roles via polgengui
- Update to upstream
* Make semodule_expand use sepol_set_expand_consume_base to reduce
peak memory usage.
- Update to upstream
* Merged audit2why fix and semanage boolean --on/--off/-1/-0 support from Dan Walsh.
* Merged a second fixfiles -C fix from Marshall Miller.
- Don't initialize audit2allow for audit2why call. Use default
- Update to upstream
* Merged fixfiles -C fix from Marshall Miller.
- Update to upstream
* Merged audit2allow cleanups and boolean descriptions from Dan Walsh.
* Merged setfiles -0 support by Benny Amorsen via Dan Walsh.
* Merged fixfiles fixes and support for ext4 and gfs2 from Dan Walsh.
- Update to upstream
* Merged replacement for audit2why from Dan Walsh.
- Cleanup fixfiles -f message in man page
- Update to upstream
* Merged update to chcat, fixfiles, and semanage scripts from Dan Walsh.
* Merged sepolgen fixes from Dan Walsh.
- handle files with spaces on upgrades
- Add support in fixfiles for ext4 ext4dev and gfs2
- Allow files with spaces to be used by setfiles
- Add descriptions of booleans to audit2allow
- Update to upstream
* Merged support for non-interactive newrole command invocation from Tim Reed.
- Change to use selinux bindings to audit2why
- Fix fixfiles to handle no args
- Fix roles output when creating a module
- Handle files with spaces in fixfiles
- Catch SELINUX_ERR with audit2allow and generate policy
- Make sepolgen set error exit code when partial failure
- audit2why now checks booleans for avc diagnosis
- Update to upstream
* Update Makefile to not build restorecond if
/usr/include/sys/inotify.h is not present
- Fix sepolgen to be able to parse Fedora 9 policy
Handle ifelse statements
Handle refpolicywarn inside of define
Add init.if and inetd.if into parse
Add parse_file to syntax error message
- Add scroll bar to fcontext gui page
- Add Russion Man pages
- Upgrade from NSA
* Drop verbose output on fixfiles -C from Dan Walsh.
* Fix argument handling in fixfiles from Dan Walsh.
* Enhance boolean support in semanage, including using the .xml description when available, from Dan Walsh. - Fix handling of final screen in polgengui
- Fix handling of disable selinux button in gui
- Upgrade from NSA
* load_policy initial load option from Chad Sellers.
- Don't show error on missing policy.xml
- GUI Enhancements
- Fix cgi generation
- Use more patterns
- Remove codec hacking, which seems to be fixed in python
- Fix typo
- Change to upstream minimal privledge interfaces
- Fix fixfiles argument parsing
- Fix File Labeling add
- Fix semanage to handle state where policy.xml is not installed
- Remove -v from restorecon in fixfiles
- Fix filter and search capabilities, add wait cursor
- Translate booleans via policy.xml
- Allow booleans to be set via semanage
- Require use of selinux-policy-devel
- Validate semanage fcontext input
- Fix template names for log files in gui
- Fix template to generate correct content
- Fix consolekit link to selinux-polgengui
- Fix the generation templates
- Fix enable/disable audit messages
- Add booleans page
- Lots of updates to gui
- Remove no.po
- Update to upstream
* Fix semodule option handling from Dan Walsh.
* Add deleteall support for ports and fcontexts in semanage from Dan Walsh.
- Fix semodule parameter checking
- Update to upstream
* Add genhomedircon script to invoke semodule -Bn from Dan Walsh. - Add deleteall for ports and fcontext
- Update to upstream
* Update semodule man page for -D from Dan Walsh.
* Add boolean, locallist, deleteall, and store support to semanage from Dan Walsh.
- Add genhomedircon script to rebuild file_context for shadow-utils
- Update translations
- Additional checkboxes for application policy
- Allow policy writer to select user types to transition to there users
- Fix bug in building policy with polgengui
- Creating ports correctly
- Update to upstream
* Improve semodule reporting of system errors from Stephen Smalley.
- Show local changes with semanage
- Fixed spelling mistakes in booleans defs
- Update po
- Update to upstream
* Fix setfiles selabel option flag setting for 64-bit from Stephen Smalley.
- Fix wording in policy generation tool
- Fix calls to _admin interfaces
- Upgrade version of sepolgen from NSA
* Expand the sepolgen parser to parse all current refpolicy modules from Karl MacMillan.
* Suppress generation of rules for non-denials from Karl MacMillan (take 3).
- Remove bogus import libxml2
- Lots of fixes for polgengui
- Change Requires /bin/rpm to rpm
- Bump libsemanage version for disable dontaudit
- New gui features for creating admin users
- Fix generated code for admin policy
- Lots of fixes for role templates
- Add more role_templates
- Update genpolgui to add creation of user domains
- Fix location of sepolgen-ifgen
- Add selinux-polgengui to desktop
- Cleanup spec
- Update semodule man page
* Fix genhomedircon searching for USER from Todd Miller
* Install run_init with mode 0755 from Dan Walsh.
* Fix chcat from Dan Walsh.
* Fix fixfiles pattern expansion and error reporting from Dan Walsh.
* Optimize genhomedircon to compile regexes once from Dan Walsh.
* Fix semanage gettext call from Dan Walsh.
- Update semodule man page
- Update to match NSA
* Disable dontaudits via semodule -D
- Speed up genhomedircon by an order of magnitude by compiling regex
- Allow semanage fcontext -a -t <<none>> /path to work
- Fixfiles update required to match new regex
- Update booleans translations
- rebuild for toolchain bug
- Add requires libselinux-python
- Fix fixfiles to report incorrect rpm
- Patch provided by Tony Nelson
- Clean up spec file
- Require newer libselinux version
- Fix checking for conflicting directory specification in genhomedircon
- Fix spelling mistakes in GUI
- Fix else path in chcat
- Update to match NSA
* Rebase setfiles to use new labeling interface.
- Add filter to all system-config-selinux lists
- Update to match NSA
* Fixed setsebool (falling through to error path on success).
- Update to match NSA
* Merged genhomedircon fixes from Dan Walsh.
* Merged setfiles -c usage fix from Dan Walsh.
* Merged restorecon fix from Yuichi Nakamura.
* Dropped -lsepol where no longer needed.
- Fix translations code, Add more filters to gui
- Fix setfiles -c to make it work
- Fix french translation to not crash system-config-selinux
- Fix genhomedircon to work in stage2 builds of anaconda
- Update to match NSA
- Fixes for polgentool templates file
- Updated version of policycoreutils
* Merged support for modifying the prefix via semanage from Dan Walsh. - Fixed genhomedircon to find homedirs correctly.
- Updated version of policycoreutils
* Merged po file updates from Dan Walsh. - Fix semanage to be able to modify prefix in user record
- Fix title on system-config-selinux
- Updated version of policycoreutils
* Build fix for setsebool.
- Updated version of policycoreutils
* Merged setsebool patch to only use libsemanage for persistent boolean changes from Stephen Smalley.
* Merged genhomedircon patch to use the __default__ setting from Dan Walsh.
* Dropped -b option from load_policy in preparation for always preserving booleans across reloads in the kernel.
- Fixes for polgengui
- Updated version of policycoreutils
* Merged chcat, fixfiles, genhomedircon, restorecond, and restorecon patches from Dan Walsh.
- Fix genhomedircon to handle non user_u for the default user
- More cleanups for gui
- Fix size and use_tmp problem on gui
- Fix restorecon crash
- Change polgengui to a druid
- Fully path script.py
- Add -l flag to restorecon to not traverse file systems
- Fixes for policygengui
- Add polgengui
- Updated version of sepolgen
* Merged seobject setransRecords patch to return the first alias from Xavier Toth.
- Updated version of sepolgen
* Merged updates to sepolgen-ifgen from Karl MacMillan.
* Merged updates to sepolgen parser and tools from Karl MacMillan.
This includes improved debugging support, handling of interface
calls with list parameters, support for role transition rules,
updated range transition rule support, and looser matching.
- Don't generate invalid context with genhomedircon
- Add filter to booleans page
- Fix polgen.py to not generate udp rules on tcp input
- system-config-selinux should be able to run on a disabled system,
- at least enough to get it enabled.
- Many fixes to polgengui
- Updated version of sepolgen
* Merged patch to discard self from types when generating requires from Karl MacMillan.
- Change location of audit2allow and sepol-ifgen to sbin
- Updated version of sepolgen
* Merged patch to move the sepolgen runtime data from /usr/share to /var/lib to facilitate a read-only /usr from Karl MacMillan.
- Add polgen gui
- Many fixes to system-config-selinux
- service restorecond status needs to set exit value correctly
- Fix gui
- Update to upstream
* Merged restorecond init script LSB compliance patch from Steve Grubb.
-sepolgen
* Merged better matching for refpolicy style from Karl MacMillan
* Merged support for extracting interface paramaters from interface calls from Karl MacMillan
* Merged support for parsing USER_AVC audit messages from Karl MacMillan.
- Update to upstream
-sepolgen
* Merged support for enabling parser debugging from Karl MacMillan. - Add sgrupp cleanup of restorcon init script
- Add Bill Nottinham patch to run restorcond condrestart in postun
- Update to upstream
- policycoreutils
* Merged newrole O_NONBLOCK fix from Linda Knippers.
* Merged sepolgen and audit2allow patches to leave generated files
in the current directory from Karl MacMillan.
* Merged restorecond memory leak fix from Steve Grubb.
-sepolgen
* Merged patch to leave generated files (e.g. local.te) in current directory from Karl MacMillan.
* Merged patch to make run-tests.py use unittest.main from Karl MacMillan.
* Merged patch to update PLY from Karl MacMillan.
* Merged patch to update the sepolgen parser to handle the latest reference policy from Karl MacMillan.
- Do not fail on sepolgen-ifgen
- Update to upstream
* Merged translations update from Dan Walsh.
* Merged chcat fixes from Dan Walsh.
* Merged man page fixes from Dan Walsh.
* Merged seobject prefix validity checking from Dan Walsh.
* Merged Makefile and refparser.py patch from Dan Walsh.
Fixes PYTHONLIBDIR definition and error handling on interface files.
- Updated newrole NONBlOCK patch
- Remove Requires: %{name}-plugins
- Update to upstream
* Merged seobject exception handler fix from Caleb Case.
* Merged setfiles memory leak patch from Todd Miller.
- Cleanup man pages syntax
- Add sepolgen
- Update to upstream
* Merged small fix to correct include of errcodes.h in semodule_deps from Dan Walsh.
- Update to upstream
* Merged new audit2allow from Karl MacMillan.
This audit2allow depends on the new sepolgen python module.
Note that you must run the sepolgen-ifgen tool to generate
the data needed by audit2allow to generate refpolicy.
* Fixed newrole non-pam build. - Fix Changelog and spelling error in man page
- Fix audit2allow on missing translations
- More chcat fixes
- Change chcat to exec semodule so file context is maintained
- Fix system-config-selinux ports view
- Update to upstream
* Fixed newrole non-pam build.
* Updated version for stable branch.
- Update to upstream
* Merged unicode-to-string fix for seobject audit from Dan Walsh.
* Merged man page updates to make "apropos selinux" work from Dan Walsh.
- * Merged newrole man page patch from Michael Thompson.
* Merged patch to fix python unicode problem from Dan Walsh.
- Fix handling of audit messages for useradd change
Resolves: #222159
- Update man pages by adding SELinux to header to fix apropos database
Resolves: #217881
- Want to update to match api
- Update to upstream
* Merged newrole securetty check from Dan Walsh.
* Merged semodule patch to generalize list support from Karl MacMillan.
Resolves: #200110
- Update to upstream
* Merged fixfiles and seobject fixes from Dan Walsh.
* Merged semodule support for list of modules after -i from Karl MacMillan.
- Update to upstream
* Merged patch to correctly handle a failure during semanage handle
creation from Karl MacMillan.
* Merged patch to fix seobject role modification from Dan Walsh.
- Stop newrole -l from working on non secure ttys
Resolves: #200110
- Update to upstream
* Merged patches from Dan Walsh to: - omit the optional name from audit2allow
- use the installed python version in the Makefiles
- re-open the tty with O_RDWR in newrole
- Update to upstream
* Patch from Dan Walsh to correctly suppress warnings in load_policy.
- Fix fixfiles script to use tty command correctly. If this command fails, it
should set the LOGFILE to /dev/null
Resolves: #220879
- Remove hard coding of python2.4 from Makefiles
- add exists switch to semanage to tell it not to check for existance of Linux user
Resolves: #219421
- Fix audit2allow generating reference policy
- Fix semanage to manage user roles properly
Resolves: #220071
- Update po files
- Fix newrole to open stdout and stderr rdrw so more will work on MLS machines
Resolves: #216920
- rebuild for python 2.5
- Update po files
Resolves: #216920
- Update po files
Resolves: #216920
- Update to upstream
* Patch from Dan Walsh to add an pam_acct_msg call to run_init
* Patch from Dan Walsh to fix error code returns in newrole
* Patch from Dan Walsh to remove verbose flag from semanage man page
* Patch from Dan Walsh to make audit2allow use refpolicy Makefile
in /usr/share/selinux/<SELINUXTYPE>
- Fixing the Makefile line again to build with LSPP support
Resolves: #208838
- Don't report errors on restorecond when file system does not support XATTRS
Resolves: #217694
- Fix -q qualifier on load_policy
Resolves: #214827
- Merge to upstream
- Fix makefile line
Resolves: #208838
- Additional po changes
- Added all booleans definitions
- Upstream accepted my patches
* Merged setsebool patch from Karl MacMillan.
This fixes a bug reported by Yuichi Nakamura with
always setting booleans persistently on an unmanaged system.
- Fixes for the gui
- Upstream accepted my patches
- Add Amy Grifis Patch to preserve newrole exit status
- Fix display of gui
- Add patch by Jose Plans to make run_init use pam_acct_mgmt
- More fixes to gui
- Fix audit2allow to generate referene policy
- Add group sort for portsPage.py
- Add enable/disableaudit to modules page
- Add glade file
- Fix Module handling in system-config-selinux
- Update to upstream
* Merged newrole patch set from Michael Thompson. - Add policycoreutils-gui
- No longer requires rhpl
- Fix genhomedircon man page
- Add newrole audit patch from sgrubb
- Update to upstream
* Merged audit2allow -l fix from Yuichi Nakamura.
* Merged restorecon -i and -o - support from Karl MacMillan.
* Merged semanage/seobject fix from Dan Walsh.
* Merged fixfiles -R and verify changes from Dan Walsh.
- Separate out newrole into its own package
- Update to upstream
* Merged newrole auditing of failures due to user actions from
Michael Thompson.
- Pass -i qualifier to restorecon for fixfiles -R
- Update translations
- Remove recursion from fixfiles -R calls
- Fix semanage to verify prefix
- More translations
- Compile with -pie
- Add translations
- Fix audit2allow -l
- Rebuild
- Update to upstream
- Change -o to take "-" for stdout
- Add -h support for genhomedircon
- Fix fixfiles handling of -o
- Make restorecon return the number of changes files if you use the -n flag
- Change setfiles and restorecon to use stderr except for -o flag
- Also -o flag will now output files
- Put back Erich's change
- Remove recursive switch when using rpm
- Fix fixfiles to handle multiple rpm and make -o work
- Apply patch
- Security fixes to run python in a more locked down manner
- More Translations
- Update to upstream
* Merged fix for restorecon // handling from Erich Schubert.
* Merged translations update and fixfiles fix from Dan Walsh.
- Change scripts to use /usr/sbin/python
- Add -i qualified to restorecon to tell it to ignore files that do not exist
- Fixfiles also modified for this change
- Ignore sigpipe
- Fix init script and add translations
- Update to upstream
* Merged fix for restorecon symlink handling from Erich Schubert.
- Update to upstream
* Merged semanage local file contexts patch from Chris PeBenito. - Fix fixfiles log creation
- More translations
- Update to upstream
* Merged patch from Dan Walsh with:
* audit2allow: process MAC_POLICY_LOAD events
* newrole: run shell with - prefix to start a login shell
* po: po file updates
* restorecond: bail if SELinux not enabled
* fixfiles: omit -q
* genhomedircon: fix exit code if non-root
* semodule_deps: install man page
* Merged secon Makefile fix from Joshua Brindle.
* Merged netfilter contexts support patch from Chris PeBenito.
- Fix audit2allow to handle reload of policy
- Stop restorecond init script when selinux is not enabled
- Update to upstream
* Merged restorecond size_t fix from Joshua Brindle.
* Merged secon keycreate patch from Michael LeMay.
* Merged restorecond fixes from Dan Walsh.
Merged updated po files from Dan Walsh.
* Merged python gettext patch from Stephen Bennett.
* Merged semodule_deps from Karl MacMillan.
- Change newrole to exec a login shell to prevent suspend.
- Report error when selinux not enabled in restorecond
- Fix handling of restorecond
- Fix creation of restorecond pidfile
- Update translations
- Update to new GCC
- Add verbose flag to restorecond and update translations
- Update to upstream
* Lindent.
* Merged patch from Dan Walsh with:
* -p option (progress) for setfiles and restorecon.
* disable context translation for setfiles and restorecon.
* on/off values for setsebool.
* Merged setfiles and semodule_link fixes from Joshua Brindle.
- Add progress indicator on fixfiles/setfiles/restorecon
- Don't use translations with matchpathcon
- Prompt for selinux-policy-devel package in audit2allow
- Allow setsebool to use on/off
- Update translations
- Update to upstream
* Merged fix for setsebool error path from Serge Hallyn.
* Merged patch from Dan Walsh with:
* Updated po files.
* Fixes for genhomedircon and seobject.
* Audit message for mass relabel by setfiles.
- Update audit mass relabel to only compile in when audit is installed.
- Update to required versions
- Update translation
- Fix shell selection
- Add BuildRequires for gettext
- * Updated fixfiles script for new setfiles location in /sbin.
- Update to upstream
* Merged more translations from Dan Walsh.
* Merged patch to relocate setfiles to /sbin for early relabel
when /usr might not be mounted from Dan Walsh.
* Merged semanage/seobject patch to preserve fcontext ordering in list.
* Merged secon patch from James Antill.
- Fix seobject.py to not sort the file_context file.
- move setfiles to /sbin
- secon man page and getopt fixes.
- Enable mass relabel audit, even though it doesn't work.
- secon fixes for --self-exec etc.
- secon change from level => sensitivity, add clearance.
- Add mass relabel AUDIT patch, but disable it until kernel problem solved.
- Update to upstream
* Merged patch with updates to audit2allow, secon, genhomedircon,
and semanage from Dan Walsh.
- Fix exception in genhomedircon
- Add rhpl dependancy
- Add secon man page and prompt options.
- Update to upstream
* Fixed audit2allow and po Makefiles for DESTDIR= builds.
* Merged .po file patch from Dan Walsh.
* Merged bug fix for genhomedircon.
- Fix exception on bad file_context
- Update to upstream
* Merged fix warnings patch from Karl MacMillan.
* Merged patch from Dan Walsh.
This includes audit2allow changes for analysis plugins,
internationalization support for several additional programs
and added po files, some fixes for semanage, and several cleanups.
It also adds a new secon utility.
- Fix genhomedircon to catch duplicate homedir problem
- Add secon program
- Add translations
- Fix check for "msg"
- Ship avc.py
- Add /etc/samba/secrets.tdb to restorecond.conf
- Update from upstream
* Merged semanage prefix support from Russell Coker.
* Added a test to setfiles to check that the spec file is
a regular file.
- added some missing buildrequires
- added Requires: initscripts for /sbin/service
- use absolute path /sbin/service
- Fix audit2allow to not require ausearch.
- Fix man page
- Add libflashplayer to restorecond.conf
- Update from upstream
* Merged audit2allow fixes for refpolicy from Dan Walsh.
* Merged fixfiles patch from Dan Walsh.
* Merged restorecond daemon from Dan Walsh.
* Merged semanage non-MLS fixes from Chris PeBenito.
* Merged semanage and semodule man page examples from Thomas Bleher.
- Clean up reference policy generation in audit2allow
- Add IN_MOVED_TO to catch renames
- make restorecond only ignore non directories with lnk > 1
- Make audit2allow translate dontaudit as well as allow rules
- Update from upstream
* Merged semanage labeling prefix patch from Ivan Gyurdiev.
- Fix audit2allow to retrieve dontaudit rules
- Open file descriptor to make sure file does not change from underneath.
- Fixes for restorecond attack via symlinks
- Fixes for fixfiles
- Restorecon has to handle suspend/resume
- Update to upstream
- Add restorecond
- Remove prereq
- Fix audit2allow to generate all rules
- Minor fixes to chcat and semanage
- Add missing setsebool man page
- Change audit2allow to use devel instead of refpolicy
- Update from upstream
* Merged semanage bug fix patch from Ivan Gyurdiev.
* Merged improve bindings patch from Ivan Gyurdiev.
* Merged semanage usage patch from Ivan Gyurdiev.
* Merged use PyList patch from Ivan Gyurdiev.
- Update from upstream
* Merged newrole -V/--version support from Glauber de Oliveira Costa.
* Merged genhomedircon prefix patch from Dan Walsh.
* Merged optionals in base patch from Joshua Brindle.
- bump again for double-long bug on ppc(64)
- rebuilt for new gcc4.1 snapshot and glibc changes
- Fix auditing to semanage
- Change genhomedircon to use new prefix interface in libselinux
- Update from upstream
* Merged seuser/user_extra support patch to semodule_package
from Joshua Brindle.
* Merged getopt type fix for semodule_link/expand and sestatus
from Chris PeBenito. - Fix genhomedircon output
- Add auditing to semanage
- Update from upstream
* Merged clone record on set_con patch from Ivan Gyurdiev.
- Update from upstream
* Merged genhomedircon fix from Dan Walsh.
* Merged seusers.system patch from Ivan Gyurdiev.
* Merged improve port/fcontext API patch from Ivan Gyurdiev.
* Merged genhomedircon patch from Dan Walsh.
- Update from upstream
* Merged newrole audit patch from Steve Grubb.
* Merged seuser -> seuser local rename patch from Ivan Gyurdiev.
* Merged semanage and semodule access check patches from Joshua Brindle.
- Add a default of /export/home
- Cleanup of the patch
- Correct handling of symbolic links in restorecon
- Added translation support to semanage
- Update from upstream
* Modified newrole and run_init to use the loginuid when
supported to obtain the Linux user identity to re-authenticate,
and to fall back to real uid. Dropped the use of the SELinux
user identity, as Linux users are now mapped to SELinux users
via seusers and the SELinux user identity space is separate.
* Merged semanage bug fixes from Ivan Gyurdiev.
* Merged semanage fixes from Russell Coker.
* Merged chcat.8 and genhomedircon patches from Dan Walsh.
- Fix genhomedircon to work on MLS policy
- Update to match NSA
* Merged chcat, semanage, and setsebool patches from Dan Walsh.
- Fixes for "add"-"modify" error messages
- Fixes for chcat
- Add management of translation file to semaange and seobject
- Fix chcat -l -L to work while not root
- Update to match NSA
* Merged semanage fixes from Ivan Gyurdiev.
* Merged semanage fixes from Russell Coker.
* Merged chcat, genhomedircon, and semanage diffs from Dan Walsh.
- Update chcat to manage user categories also
- Add check for root for semanage, genhomedircon
- Add ivans patch
- Update to match NSA
* Merged newrole cleanup patch from Steve Grubb.
* Merged setfiles/restorecon performance patch from Russell Coker.
* Merged genhomedircon and semanage patches from Dan Walsh.
* Merged remove add_local/set_local patch from Ivan Gyurdiev.
- Fixes for mls policy
- Update semanage and split out seobject
- Fix labeleing of home_root
- Update to match NSA
* Added filename to semodule error reporting.
- Update to match NSA
* Merged genhomedircon and semanage patch from Dan Walsh.
* Changed semodule error reporting to include argv[0].
- Update to match NSA
* Merged semanage getpwnam bug fix from Serge Hallyn (IBM).
* Merged patch series from Ivan Gyurdiev.
This includes patches to: - cleanup setsebool
- update setsebool to apply active booleans through libsemanage
- update semodule to use the new semanage_set_rebuild() interface
- fix various bugs in semanage
* Merged patch from Dan Walsh (Red Hat).
This includes fixes for restorecon, chcat, fixfiles, genhomedircon,
and semanage.
- Fix restorecon to not say it is changing user section when -vv is specified
- Fixes for semanage, patch from Ivan and added a test script
- Fix getpwnam call
- Anaconda fixes
- Turn off try catch block to debug anaconda failure
- More fixes for chcat
- Add try catch for files that may not exists
- Remove commands from genhomedircon for installer
- Fix genhomedircon to work in installer
- Update to match NSA
* Merged patch for chcat script from Dan Walsh.
- rebuilt
- More fixes to chcat
- Update to match NSA
* Merged fix for audit2allow long option list from Dan Walsh.
* Merged -r option for restorecon (alias for -R) from Dan Walsh.
* Merged chcat script and man page from Dan Walsh.
- Update to match NSA
- Add gfs support
- Update to match NSA
- Add chcat to policycoreutils, adding +/- syntax
`
- Require new version of libsemanage
- Update to match NSA
* Changed genhomedircon to warn on use of ROLE in homedir_template
if using managed policy, as libsemanage does not yet support it.
- Update to match NSA
* Merged genhomedircon bug fix from Dan Walsh.
* Revised semodule* man pages to refer to checkmodule and
to include example sections.
- Update to match NSA
* Merged audit2allow --tefile and --fcfile support from Dan Walsh.
* Merged genhomedircon fix from Dan Walsh.
* Merged semodule* man pages from Dan Walsh, and edited them.
* Changed setfiles to set the MATCHPATHCON_VALIDATE flag to
retain validation/canonicalization of contexts during init.
- Update to match NSA
* Changed genhomedircon to always use user_r for the role in the
managed case since user_get_defrole is broken. - Add te file capabilities to audit2allow
- Add man pages for semodule
- Update to match NSA
* Merged sestatus, audit2allow, and semanage patch from Dan Walsh.
* Fixed semodule -v option.
- Update to match NSA
* Merged audit2allow python script from Dan Walsh.
(old script moved to audit2allow.perl, will be removed later).
* Merged genhomedircon fixes from Dan Walsh.
* Merged semodule quieting patch from Dan Walsh
(inverts default, use -v to restore original behavior).
- Audit2allow
* Add more error checking
* Add gen policy package
* Add gen requires
- Update to match NSA
* Merged genhomedircon rewrite from Dan Walsh. - Rewrite audit2allow to python
- Fix genhomedircon to work with non libsemanage systems
- Patch genhomedircon to use libsemanage.py stuff
- Update to match NSA
* Merged setsebool cleanup patch from Ivan Gyurdiev.
- Fix genhomedircon to use seusers file, temporary fix until swigified semanage
- * Added -B (--build) option to semodule to force a rebuild.
* Reverted setsebool patch to call semanage_set_reload_bools().
* Changed setsebool to disable policy reload and to call
security_set_boolean_list to update the runtime booleans.
* Changed setfiles -c to use new flag to set_matchpathcon_flags()
to disable context translation by matchpathcon_init().
- Update to match NSA
* Changed setfiles for the context canonicalization support.
* Changed setsebool to call semanage_is_managed() interface
and fall back to security_set_boolean_list() if policy is
not managed.
* Merged setsebool memory leak fix from Ivan Gyurdiev.
* Merged setsebool patch to call semanage_set_reload_bools()
interface from Ivan Gyurdiev.
- Update to match NSA
* Merged setsebool patch from Ivan Gyurdiev.
This moves setsebool from libselinux/utils to policycoreutils,
and rewrites it to use libsemanage for permanent boolean changes.
- Rebuild to use latest libselinux, libsemanage, and libsepol
- Update to match NSA
* Merged semodule support for reload, noreload, and store options
from Joshua Brindle.
* Merged semodule_package rewrite from Joshua Brindle.
- Update to match NSA
* Cleaned up usage and error messages and releasing of memory by
semodule_* utilities.
* Corrected error reporting by semodule.
* Updated semodule_expand for change to sepol interface.
* Merged fixes for make DESTDIR= builds from Joshua Brindle.
- Update to match NSA
* Updated semodule_package for sepol interface changes.
- Update to match NSA
* Updated semodule_expand/link for sepol interface changes.
- Update to match NSA
* Merged non-PAM Makefile support for newrole and run_init from Timothy Wood.
- Update to match NSA
* Updated semodule_expand to use get interfaces for hidden sepol_module_package type.
* Merged newrole and run_init pam config patches from Dan Walsh (Red Hat).
* Merged fixfiles patch from Dan Walsh (Red Hat).
* Updated semodule for removal of semanage_strerror.
- Fix run_init.pamd and spec file
- Update to match NSA
* Updated semodule_link and semodule_expand to use shared libsepol.
Fixed audit2why to call policydb_init prior to policydb_read (still
uses the static libsepol).
- Update to match NSA
* Updated for changes to libsepol.
Changed semodule and semodule_package to use the shared libsepol.
Disabled build of semodule_link and semodule_expand for now.
Updated audit2why for relocated policydb internal headers,
still needs to be converted to a shared lib interface.
- Update newrole pam file to remove pam-stack
- Update run_init pam file to remove pam-stack
- Update to match NSA
* Fixed warnings in load_policy.
* Rewrote load_policy to use the new selinux_mkload_policy()
interface provided by libselinux.
- Rebuild with newer libararies
- Update to match NSA
* Merged patch to update semodule to the new libsemanage API
and improve the user interface from Karl MacMillan (Tresys).
* Modified semodule for the create/connect API split.
- More fixes to stop find from following nfs paths
- Update to match NSA
* Merged run_init open_init_pty bug fix from Manoj Srivastava
(unblock SIGCHLD). Bug reported by Erich Schubert.
- Update to match NSA
* Merged error shadowing bug fix for restorecon from Dan Walsh.
* Merged setfiles usage/man page update for -r option from Dan Walsh.
* Merged fixfiles -C patch to ignore :s0 addition on update
to a MCS/MLS policy from Dan Walsh.
- Add chcat script for use with chcon.
- Fix restorecon to exit with error code
- * Updated version for release.
- Add prereq for mount command
- Update to match NSA
* Changed setfiles -c to translate the context to raw format
prior to calling libsepol.
- Use new version of libsemange and require it for install
- Ignore s0 in file context
- Update to match NSA
* Merged patch for fixfiles -C from Dan Walsh.
- Update to match NSA
* Merged fixes for semodule_link and sestatus from Serge Hallyn (IBM).
Bugs found by Coverity.
- Fix fixfiles to call sort -u followed by sort -d.
- Change fixfiles to ignore /home directory on updates
- Update to match NSA
* Merged patch to move module read/write code from libsemanage
to libsepol from Jason Tang (Tresys).
- Update to match NSA
* Changed semodule* to link with libsemanage.
- Update to match NSA
* Merged restorecon patch from Ivan Gyurdiev.
- Update to match NSA
* Merged load_policy, newrole, and genhomedircon patches from Red Hat.
- Update to match NSA
* Merged loadable module support from Tresys Technology.
- Update to match NSA
* Updated version for release.
- Fix Ivan's patch for user role changes
- Add Ivan's patch for user role changes in genhomedircon
- Fix warning message on reload of booleans
- Update to match NSA
* Merged fixfiles and newrole patch from Dan Walsh.
* Merged audit2why man page from Dan Walsh.
- Add call to pam_acct_mgmt in newrole.
- Update to match NSA
* Extended audit2why to incorporate booleans and local user
settings when analyzing audit messages.
- Update to match NSA
* Updated audit2why for sepol_ prefixes on Flask types to
avoid namespace collision with libselinux, and to
include <selinux/selinux.h> now.
- Fix fixfiles to accept -f
- Update to match NSA
* Added audit2why utility.
- Change -f flag in fixfiles to remove stuff from /tmp
- Change -F flag to pass -F flag to restorecon/fixfiles. (IE Force relabel).
- Update to match NSA
* Fixed signed/unsigned pointer bug in load_policy.
* Reverted context validation patch for genhomedircon.
- Update to match NSA
* Reverted load_policy is_selinux_enabled patch from Dan Walsh.
Otherwise, an initial policy load cannot be performed using
load_policy, e.g. for anaconda.
- remove is_selinux_enabled check from load_policy (Bad idea)
- Update to version from NSA
* Merged load_policy is_selinux_enabled patch from Dan Walsh.
* Merged restorecon verbose output patch from Dan Walsh.
* Merged setfiles altroot patch from Chris PeBenito.
- Don't run load_policy on a non SELinux kernel.
- Update to version from NSA
* Merged context validation patch for genhomedircon from Eric Paris. - Fix verbose output of restorecon
- Update to version from NSA
* Changed setfiles -c to call set_matchpathcon_flags(3) to
turn off processing of .homedirs and .local.
- Update to released version from NSA
* Merged rewrite of genhomedircon by Eric Paris.
* Changed fixfiles to relabel jfs since it now supports security xattrs
(as of 2.6.11). Removed reiserfs until 2.6.12 is released with
fixed support for reiserfs and selinux.
- Update to released version from NSA
- Patch genhomedircon to handle passwd in different places.
- Fix genhomedircon to not put bad userad error in file_contexts.homedir
- Cleanup error reporting
- * Merged load_policy and genhomedircon patch from Dan Walsh.
- Fix genhomedircon to add extr "\n"
- Fix genhomedircon to handle blank users
- Update to latest from NSA
- Add call to libsepol
- Fix genhomedircon to handle root
- Fix fixfiles to better handle file system types
- Fix genhomedircon to handle spaces in SELINUXPOLICYTYPE
- Update to latest from NSA
* Merged several fixes from Ulrich Drepper.
- Apply Uli patch
* The Makefiles should use the -Wall option even if compiled in beehive
* Add -W, too
* use -Werror when used outside of beehive. This could also be used unconditionally
* setfiles/setfiles.c: fix resulting warning
* restorecon/restorecon.c: Likewise
* run_init/open_init_pty.c: argc hasn't been checked, the program would crash if
called without parameters. ignore the return value of nice properly.
* run_init: don't link with -ldl lutil
* load_policy: that's the bad bug. pointer to unsigned int is passed, size_t is
written to. fails on 64-bit archs
* sestatus: signed vs unsigned problem
* newrole: don't link with -ldl
- Update to latest from NSA
* Changed load_policy to fall back to the original policy upon
an error from sepol_genusers().
- Only restorecon on ext[23], reiser and xfs
- Update to latest from NSA
* Merged new genhomedircon script from Dan Walsh.
* Changed load_policy to call sepol_genusers().
- Remove Red Hat rhpl usage
- Add back in original syntax
- Update man page to match new syntax
- Fix genhomedircon regular expression
- Fix exclude in restorecon
- Trap failure on write
- Rewrite genhomedircon to generate file_context.homedirs
- several passes
- Update from NSA
* Changed relabel Makefile target to use restorecon.
- Update from NSA
* Merged restorecon patch from Dan Walsh.
- Update from NSA
* Merged further change to fixfiles -C from Dan Walsh.
* Merged updated fixfiles script from Dan Walsh. - Fix error handling of restorecon
- Fix sestatus for longer booleans
- More cleanup of fixfiles sed patch
* Merged further patches for restorecon/setfiles -e and fixfiles -C.
- More cleanup of fixfiles sed patch
- More cleanup of fixfiles sed patch
- Upgrade to latest from NSA
* Merged patch for open_init_pty from Manoj Srivastava.
- More cleanup of sed patch
- Upgrade to latest from NSA
* Merged updated fixfiles script from Dan Walsh.
* Merged updated man page for fixfiles from Dan Walsh and re-added unzipped.
* Reverted fixfiles patch for file_contexts.local;
obsoleted by setfiles rewrite.
* Merged error handling patch for restorecon from Dan Walsh.
* Merged semi raw mode for open_init_pty helper from Manoj Srivastava.
* Rewrote setfiles to use matchpathcon and the new interfaces
exported by libselinux (>= 1.21.5).
- Fix fixfiles patch
- Upgrade to latest from NSA
* Prevent overflow of spec array in setfiles. - Add diff comparason between file_contexts to fixfiles
- Allow restorecon to give an warning on file not found instead of exiting
- Upgrade to latest from NSA
* Merged newrole -l support from Darrel Goeddel (TCS). - Fix genhomedircon STARTING_UID
- Upgrade to latest from NSA
* Merged fixfiles patch for file_contexts.local from Dan Walsh.
- Temp file needs to be created in /etc/selinux/POLICYTYPE/contexts/files/ directory.
- Upgrade to latest from NSA
* Fixed restorecon to not treat errors from is_context_customizable()
as a customizable context.
* Merged setfiles/restorecon patch to not reset user field unless
-F option is specified from Dan Walsh.
* Merged open_init_pty helper for run_init from Manoj Srivastava.
* Merged audit2allow and genhomedircon man pages from Manoj Srivastava.
- Don't change user componant if it is all that changed unless forced.
- Change fixfiles to concatinate file_context.local for setfiles
- Update to latest from NSA
- Fix restorecon segfault
- Update to latest from NSA
* Merged fixfiles rewrite from Dan Walsh.
* Merged restorecon patch from Dan Walsh.
- Update to latest from NSA
* Merged fixfiles and restorecon patches from Dan Walsh.
* Don't display change if only user part changed.
- Fix fixfiles handling of rpm
- Fix restorecon to not warn on symlinks unless -v -v
- Fix output of verbose to show old context as well as new context
- Update to latest from NSA
* Changed restorecon to ignore ENOENT errors from matchpathcon.
* Merged nonls patch from Chris PeBenito.
- Update to latest from NSA
* Removed fixfiles.cron.
* Merged run_init.8 patch from Dan Walsh.
- Fix run_init.8 to refer to correct location of initrc_context
- Upgrade to latest from NSA
- Add code to sestatus to output the current policy from config file
- Patch audit2allow to return self and no brackets if only one rule
- Update to latest from NSA
- Eliminate fixfiles.cron
- Only run fixfiles.cron once a week, and eliminate null message
- Update with NSA
* Added -l option to setfiles to log changes via syslog.
* Merged -e option to setfiles to exclude directories.
* Merged -R option to restorecon for recursive descent.
- Add -e (exclude directory) switch to setfiles
- Add syslog to setfiles
- Add -R (recursive) switch to restorecon.
- Change to only display to terminal if tty is specified
- Only display to stdout if logfile not specified
- Add Steve Grubb patch to cleanup log files.
- Add optargs
- Update to match NSA
- Add fix to get cdrom info from /proc/media in fixfiles.
- Add Steve Grub patches for
* Fix fixfiles.cron MAILTO
* Several problems in sestatus
- Add -q (quiet) qualifier to load_policy to not report warnings
- Add requires for libsepol >= 1.1.1
- Update to latest from upstream
- Update to latest from upstream
- Includes Colin patch for verifying file_contexts
- Update to latest from upstream
- Update to latest from upstream
- Add Man page for load_policy
- new version from NSA uses libsepol
- Fix genhomedircon join command
- Latest from NSA
- Change fixfiles to not change when running a check
- Fix restorecon getopt call to stop hang on IBM Arches
- Only mail files less than 100 lines from fixfiles.cron
- Add Russell's fix for genhomedircon
- Latest from NSA
- Add ro warnings
- Latest from NSA
- Fix fixfiles.cron to delete outfile
- Fix fixfiles.cron to not run on non SELinux boxes
- Fix several problems in fixfiles and fixfiles.cron
- Update from NSA
- Add cron capability to fixfiles
- Update from NSA
- Fix fixfiles to handle no rpm file on relabel
- Update latest from NSA
- Add -o option to setfiles to save output of any files with incorrect context.
- Add rpm support to fixfiles
- Update restorecon to add file input support
- Update with NSA Latest
- rebuilt
- Fix run_init to use policy formats
- Update from NSA
- Change location of file_context file
- Change to use /etc/sysconfig/selinux to determine location of policy files
- Update to latest from NSA
- Change fixfiles to prompt before deleteing /tmp files
- have restorecon ingnore <<none>>
- Hand matchpathcon the file status
- Update to match NSA
- Move location of log file to /var/tmp
- Better grep command for bind
- Eliminate bind and context mounts
- update to match NSA
- Log fixfiles to the /tmp directory
- Add patch to fall back to authenticating via uid if
the current user's SELinux user identity is the default
identity - Add BuildRequires pam-devel
- Add man page, thanks to Richard Halley
- Upgrade to latest from NSA
- Update with latest from gentoo and NSA
- Check return codes in sestatus.c
- Fix sestatus to not double free
- Fix sestatus.conf to be unix format
- Warn on setfiles failure to relabel.
- Updated version of sestatus
- Fix fixfiles to checklabel properly
- add sestatus
- Change free call to freecon
- Cleanup
- Remove setfiles-assoc patch
- Fix restorecon to not crash on missing dir
- Change restorecon to not follow symlinks. It is too difficult and confusing
- to figure out the file context for the file pointed to by a symlink.
- Fix restorecon
- Read restorecon patch
- Change genhomedircon to take POLICYSOURCEDIR from command line
- Add checkselinux
- move fixfiles and restorecon to /sbin
- Restore patch of genhomedircon
- Eliminate trailing / in restorecon
- Add Verbosity check
- Add setfiles-assoc patch to try to freeup memory use
- Add fixlabels
- Update to latest from NSA
- Increase the size of buffer accepted by setfiles to BUFSIZ.
- genhomedircon should complete even if it can't read /etc/default/useradd
- fix restorecon to relabel unlabled files.
- Add genhomedircon from tresys
- Fixed patch for restorecon
- exit out when selinux is not enabled
- Fix minor bugs in restorecon
- Add restorecon c program
- Update to latest tarball from NSA
- Add sort patch
- rebuilt
- remove mods to run_init since init scripts don't require it anymore
- fix genhomedircon not to return and error
- add setfiles quiet patch
- add checkcon to verify context match file_context
- fix command parsing restorecon
- Add restorecon
- Update to latest NSA 1.4
- Change run_init.console to run as run_init_t
- Remove dietcc since load_policy is not in mkinitrd
- Change to use CONSOLEHELPER flag
- Don't authenticate run_init when used with consolehelper
- Add run_init consolehelper link
- Add russell spead up patch to deal with file path stems
- Build load_policy with diet gcc in order to save space on initrd
- Update with NSA latest
- remove i18n
- Temp remove gtk support
- Remove wnck requirement
- Add gtk support to run_init
- Add internationalization
- Initial version