Accepted libselinux 1.28-1 (source)

Ubuntu Archive Auto-Sync katie at jackass.ubuntu.com
Sat Dec 31 14:06:04 GMT 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Origin: Debian/unstable
Format: 1.7
Date: Sat,  31 Dec 2005 13:56:20 +0000
Source: libselinux
Binary: selinux-utils, libselinux1, libselinux1-dev
Architecture: source
Version: 1.28-1
Distribution: dapper
Urgency: low
Maintainer: Manoj Srivastava <srivasta at debian.org>
Changed-By: Ubuntu Archive Auto-Sync <katie at jackass.ubuntu.com>
Changes: 
 libselinux (1.28-1) unstable; urgency=low
 .
   * New upstream release
     * Added MATCHPATHCON_VALIDATE flag for set_matchpathcon_flags() and
       modified matchpathcon implementation to make context validation/
       canonicalization optional at matchpathcon_init time, deferring it
       to a successful matchpathcon by default unless the new flag is set
       by the caller.
     * Added matchpathcon_init_prefix() interface, and
       reworked matchpathcon implementation to support selective
       loading of file contexts entries based on prefix matching
       between the pathname regex stems and the specified path
       prefix (stem must be a prefix of the specified path prefix).
     * Merged getsebool patch from Dan Walsh.
     * Added -f file_contexts option to matchpathcon util.
       Fixed warning message in matchpathcon_init().
     * Merged Makefile python definitions patch from Dan Walsh.
     * Merged swigify patch from Dan Walsh.
     * Merged make failure in rpm_execcon non-fatal in permissive mode
       patch from Ivan Gyurdiev.
     * Added MATCHPATHCON_NOTRANS flag for set_matchpathcon_flags()
       and modified matchpathcon_init() to skip context translation
       if it is set by the caller.
     * Added security_canonicalize_context() interface and
       set_matchpathcon_canoncon() interface for obtaining
       canonical contexts.  Changed matchpathcon internals
       to obtain canonical contexts by default.  Provided
       fallback for kernels that lack extended selinuxfs context
       interface.
     * Merged seusers parser changes from Ivan Gyurdiev.
     * Merged setsebool to libsemanage patch from Ivan Gyurdiev.
     * Changed seusers parser to reject empty fields.
     * Merged seusers empty level handling patch from Jonathan Kim (TCS).
     * Changed default entry for seusers to use __default__ to avoid
       ambiguity with users named "default".
     * Fixed init_selinux_config() handling of missing /etc/selinux/config
       or missing SELINUXTYPE= definition.
     * Merged selinux_translations_path() patch from Dan Walsh.
     * Added hidden_proto/def for get_default_context_with_role.
     * Merged selinux_path() and selinux_homedir_context_path()
       functions from Joshua Brindle.
     * Merged fixes for make DESTDIR= builds from Joshua Brindle.
     * Merged get_default_context_with_rolelevel and man pages from
       Dan Walsh (Red Hat).
     * Updated call to sepol_policydb_to_image for sepol changes.
     * Changed getseuserbyname to ignore empty lines and to handle
     no matching entry in the same manner as no seusers file.
     * Changed selinux_mkload_policy to try downgrading the
     latest policy version available to the kernel-supported version.
     * Changed selinux_mkload_policy to fall back to the maximum
     policy version supported by libsepol if the kernel policy version
     falls outside of the supported range.
     * Changed getseuserbyname to fall back to the Linux username and
     NULL level if seusers config file doesn't exist unless 
     REQUIRESEUSERS=1 is set in /etc/selinux/config.
     * Moved seusers.conf under $SELINUXTYPE and renamed to seusers.
     * Added selinux_init_load_policy() function as an even higher level
     interface for the initial policy load by /sbin/init.  This obsoletes
     the load_policy() function in the sysvinit-selinux.patch. 
     * Added selinux_mkload_policy() function as a higher level interface
     for loading policy than the security_load_policy() interface.
     * Merged fix for matchpathcon (regcomp error checking) from Johan
     Fischer.  Also added use of regerror to obtain the error string
     for inclusion in the error message.
     * Changed getseuserbyname to not require (and ignore if present)
     the MLS level in seusers.conf if MLS is disabled, setting *level
     to NULL in this case.
     * Merged getseuserbyname patch from Dan Walsh.
     * Merged STRIP_LEVEL patch for matchpathcon from Dan Walsh.  
       This allows file_contexts with MLS fields to be processed on 
       non-MLS-enabled systems with policies that are otherwise 
       identical (e.g. same type definitions).
     * Merged get_ordered_context_list_with_level() function from
       Dan Walsh, and added get_default_context_with_level().
       This allows MLS level selection for users other than the
       default level.
Files: 
 dc12916106df729c7dda9f6d30815137 635 libs optional libselinux_1.28-1.dsc
 88d2db4c3d7cb28019e4d1d7cccc0c0a 43915 libs optional libselinux_1.28-1.diff.gz
 7e121e125b52913237df458ff610e983 109236 libs optional libselinux_1.28.orig.tar.gz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iQEVAwUBQ7aOBAF4adwMEr3XAQJkqQf/UYanCiju3CmZCsit7bUf2WMNt4H/arK4
hq1YOV65TJNF7WC8002I6xm+O34D/Nr9Ru1CXijMdAOh14miK4KEdy0b28xmJ8kS
2itTyu7IzKvJyxO6Cp7Y4W+fNzJYBPGwJBQ9sAojyrm/zpCF1pA2rqrde23Avdu4
sVDkZ5vAxFiC3HEyw7sE4p5I277ynJQ/upOxuO3wY4e0GxMo4j9rM7iHKVQ5yewQ
h9nq4a6ghDy/e18x4hQu/i6+9xtaO17vsqB+0A8ZqBcetlqQ9mr5ALWSBsLEn3UK
jMJw/0osaph34WqiMxF5129hrZnZCL3UQ2tAXcQDFI/2RXTBDJW5Nw==
=02ou
-----END PGP SIGNATURE-----


Accepted:
libselinux_1.28-1.diff.gz
  to pool/main/libs/libselinux/libselinux_1.28-1.diff.gz
libselinux_1.28-1.dsc
  to pool/main/libs/libselinux/libselinux_1.28-1.dsc
libselinux_1.28.orig.tar.gz
  to pool/main/libs/libselinux/libselinux_1.28.orig.tar.gz




More information about the ubuntu-changes-auto mailing list