* [gentoo-commits] proj/hardened-dev:master commit in: sec-policy/selinux-postfix/files/, sec-policy/selinux-courier/, ...
@ 2011-03-14 19:12 Sven Vermeulen
0 siblings, 0 replies; only message in thread
From: Sven Vermeulen @ 2011-03-14 19:12 UTC (permalink / raw
To: gentoo-commits
commit: 8178138f95c0bcb72c8239e8a54eb8d77ff04c9d
Author: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
AuthorDate: Mon Mar 14 19:11:50 2011 +0000
Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
CommitDate: Mon Mar 14 19:11:50 2011 +0000
URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-dev.git;a=commit;h=8178138f
Various updates on policy ebuilds
---
sec-policy/selinux-base-policy/ChangeLog | 472 ++++++++++++++++++++
sec-policy/selinux-base-policy/files/config | 12 +
.../files/modules.conf.strict.20090730 | 49 ++
.../files/modules.conf.targeted.20090730 | 50 ++
...ndle-selinux-base-policy-2.20101213-r11.tar.bz2 | Bin 0 -> 12037 bytes
.../files/selinux-base-policy-20070329.diff | 96 ++++
sec-policy/selinux-base-policy/metadata.xml | 13 +
.../selinux-base-policy-2.20101213-r11.ebuild | 117 +++++
sec-policy/selinux-courier/ChangeLog | 184 ++++++++
.../files/fix-services-courier-r2.patch | 84 ++++
sec-policy/selinux-courier/metadata.xml | 6 +
.../selinux-courier-2.20101213-r2.ebuild | 17 +
sec-policy/selinux-ldap/ChangeLog | 104 +++++
.../selinux-ldap/files/fix-services-ldap-r1.patch | 43 ++
sec-policy/selinux-ldap/metadata.xml | 6 +
.../selinux-ldap/selinux-ldap-2.20101213-r1.ebuild | 17 +
sec-policy/selinux-openldap/ChangeLog | 104 +++++
sec-policy/selinux-openldap/metadata.xml | 6 +
.../selinux-openldap-2.20101213-r1.ebuild | 17 +
sec-policy/selinux-postfix/ChangeLog | 180 ++++++++
.../files/fix-services-postfix-r2.patch | 76 ++++
sec-policy/selinux-postfix/metadata.xml | 6 +
.../selinux-postfix-2.20101213-r2.ebuild | 14 +
23 files changed, 1673 insertions(+), 0 deletions(-)
diff --git a/sec-policy/selinux-base-policy/ChangeLog b/sec-policy/selinux-base-policy/ChangeLog
new file mode 100644
index 0000000..c961b47
--- /dev/null
+++ b/sec-policy/selinux-base-policy/ChangeLog
@@ -0,0 +1,472 @@
+# ChangeLog for sec-policy/selinux-base-policy
+# Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-base-policy/ChangeLog,v 1.71 2011/03/07 02:13:36 blueness Exp $
+
+*selinux-base-policy-2.20101213-r11 (14 Mar 2011)
+
+ 14 Mar 2011; <swift@gentoo.org>
+ +selinux-base-policy-2.20101213-r11.ebuild,
+ +files/patchbundle-selinux-base-policy-2.20101213-r11.tar.bz2,
+ +files/selinux-base-policy-20070329.diff, +files/config,
+ +files/modules.conf.strict.20090730,
+ +files/modules.conf.targeted.20090730, +metadata.xml:
+ Fixes for courier, enable ldap administration, enable postfix
+ administration
+
+*selinux-base-policy-2.20101213-r10 (07 Mar 2011)
+*selinux-base-policy-2.20101213-r9 (07 Mar 2011)
+
+ 07 Mar 2011; Anthony G. Basile <blueness@gentoo.org>
+ +selinux-base-policy-2.20101213-r9.ebuild,
+ +selinux-base-policy-2.20101213-r10.ebuild,
+ +files/patchbundle-selinux-base-policy-2.20101213-r10.tar.bz2,
+ +files/patchbundle-selinux-base-policy-2.20101213-r9.tar.bz2:
+ Added new patchbundles for rev bumps to base policy 2.20101213
+
+ 05 Feb 2011; Anthony G. Basile <blueness@gentoo.org>
+ +files/patchbundle-selinux-base-policy-2.20101213-r5.tar.bz2,
+ +files/patchbundle-selinux-base-policy-2.20101213-r6.tar.bz2,
+ +files/patchbundle-selinux-base-policy-2.20101213-r7.tar.bz2:
+ Added patchbundle for base policy 2.20101213.
+
+*selinux-base-policy-2.20101213-r7 (05 Feb 2011)
+*selinux-base-policy-2.20101213-r6 (05 Feb 2011)
+*selinux-base-policy-2.20101213-r5 (05 Feb 2011)
+
+ 05 Feb 2011; Anthony G. Basile <blueness@gentoo.org>
+ +selinux-base-policy-2.20101213-r5.ebuild,
+ +selinux-base-policy-2.20101213-r6.ebuild,
+ +selinux-base-policy-2.20101213-r7.ebuild:
+ New upstream policy.
+
+*selinux-base-policy-2.20091215 (16 Dec 2009)
+
+ 16 Dec 2009; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-2.20091215.ebuild:
+ New upstream release.
+
+*selinux-base-policy-20080525-r1 (14 Sep 2009)
+
+ 14 Sep 2009; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20080525-r1.ebuild:
+ Update old base policy to support ext4.
+
+ 14 Aug 2009; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-base-policy-20070329.ebuild,
+ -selinux-base-policy-20070928.ebuild, selinux-base-policy-20080525.ebuild:
+ Mark 20080525 stable, clear old ebuilds.
+
+*selinux-base-policy-2.20090814 (14 Aug 2009)
+
+ 14 Aug 2009; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-2.20090814.ebuild:
+ Git version of refpolicy for misc fixes including some cron problems.
+
+*selinux-base-policy-2.20090730 (03 Aug 2009)
+
+ 03 Aug 2009; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-2.20090730.ebuild:
+ New upstream release.
+
+ 18 Jul 2009; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20070329.ebuild, selinux-base-policy-20070928.ebuild,
+ selinux-base-policy-20080525.ebuild:
+ Drop alpha, mips, ppc, sparc selinux support.
+
+*selinux-base-policy-20080525 (25 May 2008)
+
+ 25 May 2008; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20080525.ebuild:
+ New SVN snapshot.
+
+ 16 Mar 2008; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-base-policy-20051022-r1.ebuild,
+ -selinux-base-policy-20061114.ebuild:
+ Remove old ebuilds.
+
+ 03 Feb 2008; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20070928.ebuild:
+ Mark stable.
+
+*selinux-base-policy-20070928 (26 Nov 2007)
+
+ 26 Nov 2007; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20070928.ebuild:
+ New SVN snapshot.
+
+ 04 Jun 2007; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20070329.ebuild:
+ Mark stable.
+
+ 30 Mar 2007; Chris PeBenito <pebenito@gentoo.org>
+ +files/selinux-base-policy-20070329.diff,
+ selinux-base-policy-20070329.ebuild:
+ Compile fix.
+
+*selinux-base-policy-20070329 (29 Mar 2007)
+
+ 29 Mar 2007; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20070329.ebuild:
+ New SVN snapshot.
+
+ 22 Feb 2007; Markus Ullmann <jokey@gentoo.org> ChangeLog:
+ Redigest for Manifest2
+
+*selinux-base-policy-20061114 (15 Nov 2006)
+
+ 15 Nov 2006; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20061114.ebuild:
+ New SVN snapshot.
+
+ 25 Oct 2006; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20061015.ebuild:
+ Fix to have default POLICY_TYPES if it is empty.
+
+ 21 Oct 2006; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20061015.ebuild:
+ Fix xml generation failure to die.
+
+*selinux-base-policy-20061015 (15 Oct 2006)
+
+ 15 Oct 2006; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-base-policy-20061008.ebuild,
+ +selinux-base-policy-20061015.ebuild:
+ Update for testing fixes.
+
+*selinux-base-policy-20061008 (08 Oct 2006)
+
+ 08 Oct 2006; Chris PeBenito <pebenito@gentoo.org> -files/semanage.conf,
+ +selinux-base-policy-20061008.ebuild,
+ -selinux-base-policy-99999999.ebuild:
+ First mainstream reference policy testing release.
+
+ 29 Sep 2006; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-99999999.ebuild:
+ Fix for new SVN location. Fixes 147781.
+
+ 22 Feb 2006; Stephen Bennett <spb@gentoo.org>
+ selinux-base-policy-20051022-r1.ebuild:
+ Alpha stable
+
+*selinux-base-policy-99999999 (02 Feb 2006)
+
+ 02 Feb 2006; Chris PeBenito <pebenito@gentoo.org> +files/config,
+ +files/modules.conf.strict, +files/modules.conf.targeted,
+ +files/semanage.conf, +selinux-base-policy-99999999.ebuild:
+ Add experimental policy for testing reference policy. Requires portage fix
+ from bug #110857.
+
+ 02 Feb 2006; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-base-policy-20050322.ebuild,
+ -selinux-base-policy-20050618.ebuild,
+ -selinux-base-policy-20050821.ebuild,
+ -selinux-base-policy-20051022.ebuild:
+ Clean out old ebuilds.
+
+ 14 Jan 2006; Stephen Bennett <spb@gentoo.org>
+ selinux-base-policy-20051022-r1.ebuild:
+ Added ~alpha
+
+*selinux-base-policy-20051022-r1 (08 Dec 2005)
+
+ 08 Dec 2005; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20051022-r1.ebuild:
+ Change to use compatability genhomedircon. Newer policycoreutils (1.28)
+ breaks the backwards compatability this policy uses.
+
+*selinux-base-policy-20051022 (22 Oct 2005)
+
+ 22 Oct 2005; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20051022.ebuild:
+ Very trivial fixes.
+
+ 08 Sep 2005; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20050821.ebuild:
+ Mark stable.
+
+*selinux-base-policy-20050821 (21 Aug 2005)
+
+ 21 Aug 2005; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20050821.ebuild:
+ Minor updates for 2.6.12.
+
+ 21 Jun 2005; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20050618.ebuild:
+ Mark stable.
+
+*selinux-base-policy-20050618 (18 Jun 2005)
+
+ 18 Jun 2005; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-base-policy-20041123.ebuild,
+ -selinux-base-policy-20050306.ebuild,
+ +selinux-base-policy-20050618.ebuild:
+ New release to support 2.6.12 features.
+
+ 10 May 2005; Stephen Bennett <spb@gentoo.org>
+ selinux-base-policy-20050322.ebuild:
+ mips stable
+
+ 01 May 2005; Stephen Bennett <spb@gentoo.org>
+ selinux-base-policy-20050322.ebuild:
+ Added ~mips.
+
+*selinux-base-policy-20050322 (23 Mar 2005)
+
+ 23 Mar 2005; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20050322.ebuild:
+ New release.
+
+*selinux-base-policy-20050306 (06 Mar 2005)
+
+ 06 Mar 2005; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20050306.ebuild:
+ Fix bad samba_domain dummy macro. Add policies needed for udev support.
+
+*selinux-base-policy-20050224 (24 Feb 2005)
+
+ 24 Feb 2005; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20050224.ebuild:
+ New release.
+
+ 19 Jan 2005; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20041123.ebuild:
+ Mark stable.
+
+*selinux-base-policy-20041123 (23 Nov 2004)
+
+ 23 Nov 2004; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20041123.ebuild:
+ New release with 1.18 merge.
+
+*selinux-base-policy-20041023 (23 Oct 2004)
+
+ 23 Oct 2004; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20041023.ebuild:
+ New release with 1.16 merge. Tcpd and inetd have been deprecated since they
+ are not in the base system anymore, and probably no one uses them anyway.
+
+*selinux-base-policy-20040906 (06 Sep 2004)
+
+ 06 Sep 2004; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20040906.ebuild:
+ New release with 1.14 merge, which has policy 18 (fine-grained netlink)
+ features.
+
+ 05 Sep 2004; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20040225.ebuild, -selinux-base-policy-20040509.ebuild,
+ -selinux-base-policy-20040604.ebuild, selinux-base-policy-20040629.ebuild,
+ selinux-base-policy-20040702.ebuild:
+ Remove old builds, switch to epause and ebeep in remaining builds.
+
+*selinux-base-policy-20040702 (02 Jul 2004)
+
+ 02 Jul 2004; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20040702.ebuild:
+ Same as 20040629, except with updated flask headers, which will come out in
+ 2.6.8.
+
+*selinux-base-policy-20040629 (29 Jun 2004)
+
+ 29 Jun 2004; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20040629.ebuild:
+ Large sysadmfile cleanup: disable admin_separation to give sysadm_r back its
+ ablility to modify all files. Minor fixes: portage_r works again, syslog-ng
+ breakage fixed, put back manual PaX policy for pageexec/segmexec.
+
+ 16 Jun 2004; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20040604.ebuild:
+ Mark stable.
+
+ 10 Jun 2004; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20040225.ebuild, selinux-base-policy-20040509.ebuild,
+ selinux-base-policy-20040604.ebuild:
+ Add src_compile() stub
+
+*selinux-base-policy-20040604 (04 Jun 2004)
+
+ 04 Jun 2004; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20040604.ebuild:
+ New release including 1.12 NSA policy, and experimental sesandbox.
+
+ 15 May 2004; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20040509.ebuild:
+ Mark stable.
+
+*selinux-base-policy-20040509 (09 May 2004)
+
+ 09 May 2004; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20040509.ebuild:
+ A few small cleanups. Make PaX non exec pages macro based on arch. Large
+ portage update, get rid of portage_exec_fetch_t, portage will setexec. Add
+ global_ssp tunable.
+
+*selinux-base-policy-20040418 (18 Apr 2004)
+
+ 18 Apr 2004; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20040418.ebuild:
+ New release for checkpolicy 1.10
+
+*selinux-base-policy-20040414 (14 Apr 2004)
+
+ 14 Apr 2004; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-base-policy-20040408.ebuild, +selinux-base-policy-20040414.ebuild:
+ Minor updates
+
+*selinux-base-policy-20040408 (08 Apr 2004)
+
+ 08 Apr 2004; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20040408.ebuild:
+ New update. Users.fc is now deprecated, as the contexts for user directories
+ is now automatically generated. Portage fetching of distfiles now has a
+ subdomain, for dropping priviledges.
+
+ 28 Feb 2004; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20040225.ebuild:
+ Mark stable.
+
+*selinux-base-policy-20040225 (25 Feb 2004)
+
+ 25 Feb 2004; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20040225.ebuild:
+ New support for PaX ACL hooks. Addition of tunable.te for configurable policy
+ options. Rewrite of portage.te. Now auto-transition for sysadm is default, can
+ reenable portage_r by tunable.te. Makefile update from NSA CVS.
+
+*selinux-base-policy-20040209 (09 Feb 2004)
+
+ 09 Feb 2004; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20040209.ebuild:
+ Minor revision to add XFS labeling and policy for integrated
+ runscript-run_init.
+
+ 07 Feb 2004; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20040202.ebuild:
+ Mark x86 stable.
+
+*selinux-base-policy-20040202 (02 Feb 2004)
+
+ 02 Feb 2004; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20040202.ebuild:
+ A few misc fixes. Allow portage to update bootloader code, such as in lilo or
+ grub postinst. This requires checkpolicy 1.4-r1.
+
+*selinux-base-policy-20031225 (25 Dec 2003)
+
+ 25 Dec 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20031225.ebuild:
+ New release, with merged NSA 1.4 policy. One critical note, this policy
+ requires pam 0.77. Much work has been done to minimize access to /etc/shadow,
+ and one requirement is in the patch for pam 0.77. If you do not use this pam
+ version or newer, you will be unable to authenticate in enforcing. Since
+ devfs no longer is usable in SELinux, it's policy has been removed. You
+ should merge the changes, remove the devfsd policy (devfsd.te and devfsd.fc),
+ load the policy, and relabel.
+
+ 27 Nov 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20031010-r1.ebuild:
+ Mark stable. Add build USE flag for stage building.
+
+*selinux-base-policy-20031010-r1 (12 Nov 2003)
+
+ 12 Nov 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20031010-r1.ebuild,
+ files/selinux-base-policy-20031010-cvs.diff:
+ Add fixes from policy cvs for compilers, so non x86 and ppc compilers can
+ work. Also portage update as a side effect of updated setfiles code in
+ portage, from bug 31748.
+
+ 28 Oct 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20031010.ebuild:
+ Mark stable
+
+*selinux-base-policy-20031010 (10 Oct 2003)
+
+ 10 Oct 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20031010.ebuild:
+ New release for new API. Massive cleanups all over the place.
+
+*selinux-base-policy-20030817 (17 Aug 2003)
+
+ 17 Aug 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20030817.ebuild:
+ Initial commit of new API policy
+
+ 10 Aug 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20030729-r1.ebuild:
+ Mark stable
+
+*selinux-base-policy-20030729-r1 (31 Jul 2003)
+
+ 31 Jul 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20030729-r1.ebuild:
+ New rev that handles an empty POLICYDIR sanely.
+
+*selinux-base-policy-20030729 (29 Jul 2003)
+
+ 29 Jul 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20030729.ebuild:
+ Make the ebuild use POLICYDIR. Important fix so portage can load policy so
+ selinux-policy.eclass works. update_modules_t cleanup. Fix for an access when
+ merging baselayout.
+
+*selinux-base-policy-20030720 (20 Jul 2003)
+
+ 20 Jul 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20030720.ebuild:
+ Many fixes, including the syslog fix. File contexts have changed, so a relabel
+ is needed. You may encounter problems relabeling /usr/portage, as its file
+ context has changed, as files should not have the same type as a domain.
+ Relabelling in permissive will fix this, or temporarily give portage_t a
+ file_type attribute. Tightened the can_exec_any() macro. Moved staff.fc to
+ users.fc, since all users with SELinux identities should have their home
+ directories have the correct identity, not the generic identity.
+
+ 06 Jun 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20030604.ebuild:
+ Mark stable
+
+*selinux-base-policy-20030604 (04 Jun 2003)
+
+ 04 Jun 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20030604.ebuild:
+ Fix broken 20030603
+
+ 04 Jun 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20030603.ebuild:
+ Pulling 20030603, as there are problems, 20030604 later today
+
+*selinux-base-policy-20030603 (03 Jun 2003)
+
+ 03 Jun 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20030603.ebuild:
+ Numerous various fixes. Added staff role. Removed ipsec, gpm and gpg policies
+ as they are not appropriate for the base policy, and untested.
+
+*selinux-base-policy-20030522 (22 May 2003)
+
+ 22 May 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20030522.ebuild:
+ The policy is in pretty good shape now. I've been able to run in enforcing mode
+ with little problem. I've also been able to successfully merge and unmerge
+ packages in enforcing mode, with few exceptions (why does mysql need to run ps
+ during configure?).
+
+*selinux-base-policy-20030514 (14 May 2003)
+
+ 14 May 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20030514.ebuild:
+ Many improvements in many areas. Of note, rlogind policies were removed. Klogd
+ is being merged into syslogd. The portage policy is much more complete, but
+ still needs work. Its suggested that all changes be merged in, policy
+ reloaded, then relabel.
+
+*selinux-base-policy-20030419 (19 Apr 2003)
+
+ 23 Apr 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-base-policy-20030419.ebuild:
+ Marking stable for selinux-small stable usage
+
+ 19 Apr 2003; Chris PeBenito <pebenito@gentoo.org> Manifest,
+ selinux-base-policy-20030419.ebuild:
+ Initial commit. Base policies for SELinux, with Gentoo-specifics
+
diff --git a/sec-policy/selinux-base-policy/files/config b/sec-policy/selinux-base-policy/files/config
new file mode 100644
index 0000000..41e6993
--- /dev/null
+++ b/sec-policy/selinux-base-policy/files/config
@@ -0,0 +1,12 @@
+# This file controls the state of SELinux on the system on boot.
+
+# SELINUX can take one of these three values:
+# enforcing - SELinux security policy is enforced.
+# permissive - SELinux prints warnings instead of enforcing.
+# disabled - No SELinux policy is loaded.
+SELINUX=permissive
+
+# SELINUXTYPE can take one of these two values:
+# targeted - Only targeted network daemons are protected.
+# strict - Full SELinux protection.
+SELINUXTYPE=strict
diff --git a/sec-policy/selinux-base-policy/files/modules.conf.strict.20090730 b/sec-policy/selinux-base-policy/files/modules.conf.strict.20090730
new file mode 100644
index 0000000..fcb3fd8
--- /dev/null
+++ b/sec-policy/selinux-base-policy/files/modules.conf.strict.20090730
@@ -0,0 +1,49 @@
+application = base
+authlogin = base
+bootloader = base
+clock = base
+consoletype = base
+corecommands = base
+corenetwork = base
+cron = base
+devices = base
+dmesg = base
+domain = base
+files = base
+filesystem = base
+fstools = base
+getty = base
+hostname = base
+hotplug = base
+init = base
+iptables = base
+kernel = base
+libraries = base
+locallogin = base
+logging = base
+lvm = base
+miscfiles = base
+mcs = base
+mls = base
+modutils = base
+mount = base
+mta = base
+netutils = base
+nscd = base
+portage = base
+raid = base
+rsync = base
+selinux = base
+selinuxutil = base
+ssh = base
+staff = base
+storage = base
+su = base
+sysadm = base
+sysnetwork = base
+terminal = base
+ubac = base
+udev = base
+userdomain = base
+usermanage = base
+unprivuser = base
diff --git a/sec-policy/selinux-base-policy/files/modules.conf.targeted.20090730 b/sec-policy/selinux-base-policy/files/modules.conf.targeted.20090730
new file mode 100644
index 0000000..ee8a14c
--- /dev/null
+++ b/sec-policy/selinux-base-policy/files/modules.conf.targeted.20090730
@@ -0,0 +1,50 @@
+application = base
+authlogin = base
+bootloader = base
+clock = base
+consoletype = base
+corecommands = base
+corenetwork = base
+cron = base
+devices = base
+dmesg = base
+domain = base
+files = base
+filesystem = base
+fstools = base
+getty = base
+hostname = base
+hotplug = base
+init = base
+iptables = base
+kernel = base
+libraries = base
+locallogin = base
+logging = base
+lvm = base
+miscfiles = base
+mcs = base
+mls = base
+modutils = base
+mount = base
+mta = base
+netutils = base
+nscd = base
+portage = base
+raid = base
+rsync = base
+selinux = base
+selinuxutil = base
+ssh = base
+staff = base
+storage = base
+su = base
+sysadm = base
+sysnetwork = base
+terminal = base
+ubac = base
+udev = base
+unconfined = base
+userdomain = base
+usermanage = base
+unprivuser = base
diff --git a/sec-policy/selinux-base-policy/files/patchbundle-selinux-base-policy-2.20101213-r11.tar.bz2 b/sec-policy/selinux-base-policy/files/patchbundle-selinux-base-policy-2.20101213-r11.tar.bz2
new file mode 100644
index 0000000..986142d
Binary files /dev/null and b/sec-policy/selinux-base-policy/files/patchbundle-selinux-base-policy-2.20101213-r11.tar.bz2 differ
diff --git a/sec-policy/selinux-base-policy/files/selinux-base-policy-20070329.diff b/sec-policy/selinux-base-policy/files/selinux-base-policy-20070329.diff
new file mode 100644
index 0000000..4a6f55c
--- /dev/null
+++ b/sec-policy/selinux-base-policy/files/selinux-base-policy-20070329.diff
@@ -0,0 +1,96 @@
+Index: policy/support/loadable_module.spt
+===================================================================
+--- policy/support/loadable_module.spt (revision 2248)
++++ policy/support/loadable_module.spt (revision 2249)
+@@ -128,10 +128,10 @@
+ # This needs to be reworked so expressions
+ # with parentheses can work.
+
+-define(`delcare_required_symbols',`
++define(`declare_required_symbols',`
+ ifelse(regexp($1, `\w'), -1, `', `dnl
+ bool regexp($1, `\(\w+\)', `\1');
+-delcare_required_symbols(regexp($1, `\w+\(.*\)', `\1'))dnl
++declare_required_symbols(regexp($1, `\w+\(.*\)', `\1'))dnl
+ ') dnl
+ ')
+
+@@ -140,16 +140,7 @@
+ # Tunable declaration
+ #
+ define(`gen_tunable',`
+- ifdef(`self_contained_policy',`
+- bool $1 dflt_or_overr(`$1'_conf,$2);
+- ',`
+- # loadable module tunable
+- # declaration will go here
+- # instead of bool when
+- # loadable modules support
+- # tunables
+- bool $1 dflt_or_overr(`$1'_conf,$2);
+- ')
++ bool $1 dflt_or_overr(`$1'_conf,$2);
+ ')
+
+ ##############################
+@@ -157,24 +148,12 @@
+ # Tunable policy handling
+ #
+ define(`tunable_policy',`
+- ifdef(`self_contained_policy',`
+- if (`$1') {
+- $2
+- ifelse(`$3',`',`',`} else {
+- $3
+- ')}
+- ',`
+- # structure for tunables
+- # will go here instead of a
+- # conditional when loadable
+- # modules support tunables
+- gen_require(`
+- delcare_required_symbols(`$1')
+- ')
+- if (`$1') {
+- $2
+- ifelse(`$3',`',`',`} else {
+- $3
+- ')}
++ gen_require(`
++ declare_required_symbols(`$1')
+ ')
++ if (`$1') {
++ $2
++ ifelse(`$3',`',`',`} else {
++ $3
++ ')}
+ ')
+Index: support/comment_move_decl.sed
+===================================================================
+--- support/comment_move_decl.sed (revision 2248)
++++ support/comment_move_decl.sed (revision 2249)
+@@ -5,9 +5,10 @@
+ /require \{/,/} # end require/b nextline
+ /optional \{/,/} # end optional/b nextline
+
+-/^[[:blank:]]*(attribute|type(alias)?) / s/^/# this line was moved by the build process: &/
++/^[[:blank:]]*(attribute|type(alias)?) /s/^/# this line was moved by the build process: &/
+ /^[[:blank:]]*(port|node|netif|genfs)con /s/^/# this line was moved by the build process: &/
+ /^[[:blank:]]*fs_use_(xattr|task|trans) /s/^/# this line was moved by the build process: &/
+ /^[[:blank:]]*sid /s/^/# this line was moved by the build process: &/
++/^[[:blank:]]*bool /s/^/# this line was moved by the build process: &/
+
+ :nextline
+Index: support/get_type_attr_decl.sed
+===================================================================
+--- support/get_type_attr_decl.sed (revision 2248)
++++ support/get_type_attr_decl.sed (revision 2249)
+@@ -5,7 +5,7 @@
+ /require \{/,/} # end require/b nextline
+ /optional \{/,/} # end optional/b nextline
+
+-/^[[:blank:]]*(attribute|type(alias)?) /{
++/^[[:blank:]]*(attribute|type(alias)?|bool) /{
+ s/^[[:blank:]]+//
+ p
+ }
diff --git a/sec-policy/selinux-base-policy/metadata.xml b/sec-policy/selinux-base-policy/metadata.xml
new file mode 100644
index 0000000..4e26a86
--- /dev/null
+++ b/sec-policy/selinux-base-policy/metadata.xml
@@ -0,0 +1,13 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!DOCTYPE pkgmetadata SYSTEM "http://www.gentoo.org/dtd/metadata.dtd">
+<pkgmetadata>
+ <herd>selinux</herd>
+ <longdescription>
+ Gentoo SELinux base policy. This contains policy for a system at the end of system installation.
+ There is no extra policy in this package.
+ </longdescription>
+ <use>
+ <flag name='peer_perms'>Enable the labeled networking peer permissions (SELinux policy capability).</flag>
+ <flag name='open_perms'>Enable the open permissions for file object classes (SELinux policy capability).</flag>
+ </use>
+</pkgmetadata>
diff --git a/sec-policy/selinux-base-policy/selinux-base-policy-2.20101213-r11.ebuild b/sec-policy/selinux-base-policy/selinux-base-policy-2.20101213-r11.ebuild
new file mode 100644
index 0000000..75a3548
--- /dev/null
+++ b/sec-policy/selinux-base-policy/selinux-base-policy-2.20101213-r11.ebuild
@@ -0,0 +1,117 @@
+# Copyright 1999-2011 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-base-policy/selinux-base-policy-2.20101213-r10.ebuild,v 1.1 2011/03/07 02:13:36 blueness Exp $
+
+EAPI="1"
+IUSE="+peer_perms open_perms"
+
+inherit eutils
+
+PATCHBUNDLE="${FILESDIR}/patchbundle-${PF}.tar.bz2"
+DESCRIPTION="Gentoo base policy for SELinux"
+HOMEPAGE="http://www.gentoo.org/proj/en/hardened/selinux/"
+SRC_URI="http://oss.tresys.com/files/refpolicy/refpolicy-${PV}.tar.bz2"
+LICENSE="GPL-2"
+SLOT="0"
+
+KEYWORDS="~amd64 ~x86"
+
+RDEPEND=">=sys-apps/policycoreutils-1.30.30
+ >=sys-fs/udev-151"
+DEPEND="${RDEPEND}
+ sys-devel/m4
+ >=sys-apps/checkpolicy-1.30.12"
+
+S=${WORKDIR}/
+
+src_unpack() {
+ [ -z "${POLICY_TYPES}" ] && local POLICY_TYPES="strict targeted"
+ MOD_CONF_VER="20090730"
+
+ unpack ${A}
+
+ cd "${S}"
+ epatch "${PATCHBUNDLE}"
+ cd "${S}/refpolicy"
+ # Fix bug 257111
+ sed -i -e 's:system_crond_t:system_cronjob_t:g' \
+ "${S}/refpolicy/config/appconfig-standard/default_contexts"
+
+ if ! use peer_perms; then
+ sed -i -e '/network_peer_controls/d' \
+ "${S}/refpolicy/policy/policy_capabilities"
+ fi
+
+ if ! use open_perms; then
+ sed -i -e '/open_perms/d' \
+ "${S}/refpolicy/policy/policy_capabilities"
+ fi
+
+ for i in ${POLICY_TYPES}; do
+ cp -a "${S}/refpolicy" "${S}/${i}"
+
+ cd "${S}/${i}";
+ make conf || die "${i} reconfiguration failed"
+
+ cp "${FILESDIR}/modules.conf.${i}.${MOD_CONF_VER}" \
+ "${S}/${i}/policy/modules.conf" \
+ || die "failed to set up modules.conf"
+ sed -i -e '/^QUIET/s/n/y/' -e '/^MONOLITHIC/s/y/n/' \
+ -e "/^NAME/s/refpolicy/$i/" "${S}/${i}/build.conf" \
+ || die "build.conf setup failed."
+
+ echo "DISTRO = gentoo" >> "${S}/${i}/build.conf"
+
+ if [ "${i}" == "targeted" ]; then
+ sed -i -e '/root/d' -e 's/user_u/unconfined_u/' \
+ "${S}/${i}/config/appconfig-standard/seusers" \
+ || die "targeted seusers setup failed."
+ fi
+ done
+}
+
+src_compile() {
+ [ -z "${POLICY_TYPES}" ] && local POLICY_TYPES="strict targeted"
+
+ for i in ${POLICY_TYPES}; do
+ cd "${S}/${i}"
+ make base || die "${i} compile failed"
+ done
+}
+
+src_install() {
+ [ -z "${POLICY_TYPES}" ] && local POLICY_TYPES="strict targeted"
+
+ for i in ${POLICY_TYPES}; do
+ cd "${S}/${i}"
+
+ make DESTDIR="${D}" install \
+ || die "${i} install failed."
+
+ make DESTDIR="${D}" install-headers \
+ || die "${i} headers install failed."
+
+ echo "run_init_t" > "${D}/etc/selinux/${i}/contexts/run_init_type"
+
+ echo "textrel_shlib_t" >> "${D}/etc/selinux/${i}/contexts/customizable_types"
+
+ # libsemanage won't make this on its own
+ keepdir "/etc/selinux/${i}/policy"
+ done
+
+ dodoc doc/Makefile.example doc/example.{te,fc,if}
+
+ insinto /etc/selinux
+ doins "${FILESDIR}/config"
+}
+
+pkg_postinst() {
+ [ -z "${POLICY_TYPES}" ] && local POLICY_TYPES="strict targeted"
+
+ for i in ${POLICY_TYPES}; do
+ einfo "Inserting base module into ${i} module store."
+
+ cd "/usr/share/selinux/${i}"
+ semodule -s "${i}" -b base.pp
+ done
+}
diff --git a/sec-policy/selinux-courier/ChangeLog b/sec-policy/selinux-courier/ChangeLog
new file mode 100644
index 0000000..8a9c5ef
--- /dev/null
+++ b/sec-policy/selinux-courier/ChangeLog
@@ -0,0 +1,184 @@
+# ChangeLog for sec-policy/selinux-courier
+# Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-courier/ChangeLog,v 1.1 2011/03/07 02:32:30 blueness Exp $
+
+*selinux-courier-2.20101213-r2 (14 Mar 2011)
+
+ 14 Mar 2011; <swift@gentoo.org> +files/fix-services-courier-r2.patch,
+ +selinux-courier-2.20101213-r2.ebuild, +metadata.xml:
+ Fix courier file contexts
+
+ 07 Mar 2011; Anthony G. Basile <blueness@gentoo.org>
+ +files/fix-services-courier-r1.patch,
+ +selinux-courier-2.20101213-r1.ebuild, +metadata.xml:
+ Renaming policy from courier-imap to match upstream naming standards.
+
+*selinux-courier-2.20101213-r1 (04 Mar 2011)
+
+ 04 Mar 2011; <swift@gentoo.org> +files/fix-services-courier-r1.patch,
+ +selinux-courier-2.20101213-r1.ebuild, +metadata.xml:
+ Fix file contexts
+
+*selinux-courier-imap-2.20101213 (05 Feb 2011)
+
+ 05 Feb 2011; Anthony G. Basile <blueness@gentoo.org>
+ +selinux-courier-imap-2.20101213.ebuild:
+ New upstream policy.
+
+*selinux-courier-imap-2.20091215 (16 Dec 2009)
+
+ 16 Dec 2009; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-courier-imap-2.20091215.ebuild:
+ New upstream release.
+
+ 14 Aug 2009; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-courier-imap-20070329.ebuild,
+ -selinux-courier-imap-20070928.ebuild,
+ selinux-courier-imap-20080525.ebuild:
+ Mark 20080525 stable, clear old ebuilds.
+
+*selinux-courier-imap-2.20090730 (03 Aug 2009)
+
+ 03 Aug 2009; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-courier-imap-2.20090730.ebuild:
+ New upstream release.
+
+ 18 Jul 2009; Chris PeBenito <pebenito@gentoo.org>
+ selinux-courier-imap-20070329.ebuild,
+ selinux-courier-imap-20070928.ebuild,
+ selinux-courier-imap-20080525.ebuild:
+ Drop alpha, mips, ppc, sparc selinux support.
+
+*selinux-courier-imap-20080525 (25 May 2008)
+
+ 25 May 2008; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-courier-imap-20080525.ebuild:
+ New SVN snapshot.
+
+ 16 Mar 2008; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-courier-imap-20050417.ebuild,
+ -selinux-courier-imap-20050607.ebuild,
+ -selinux-courier-imap-20050628.ebuild,
+ -selinux-courier-imap-20061114.ebuild:
+ Remove old ebuilds.
+
+ 03 Feb 2008; Chris PeBenito <pebenito@gentoo.org>
+ selinux-courier-imap-20070928.ebuild:
+ Mark stable.
+
+*selinux-courier-imap-20070928 (26 Nov 2007)
+
+ 26 Nov 2007; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-courier-imap-20070928.ebuild:
+ New SVN snapshot.
+
+ 29 Aug 2007; Christian Heim <phreak@gentoo.org> metadata.xml:
+ Removing kaiowas from metadata due to his retirement (see #61930 for
+ reference).
+
+ 04 Jun 2007; Chris PeBenito <pebenito@gentoo.org>
+ selinux-courier-imap-20070329.ebuild:
+ Mark stable.
+
+*selinux-courier-imap-20070329 (29 Mar 2007)
+
+ 29 Mar 2007; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-courier-imap-20070329.ebuild:
+ New SVN snapshot.
+
+ 22 Feb 2007; Markus Ullmann <jokey@gentoo.org> ChangeLog:
+ Redigest for Manifest2
+
+*selinux-courier-imap-20061114 (15 Nov 2006)
+
+ 15 Nov 2006; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-courier-imap-20061114.ebuild:
+ New SVN snapshot.
+
+*selinux-courier-imap-20061008 (10 Oct 2006)
+
+ 10 Oct 2006; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-courier-imap-20061008.ebuild:
+ First mainstream reference policy testing release.
+
+ 29 Jun 2005; petre rodan <kaiowas@gentoo.org>
+ selinux-courier-imap-20050628.ebuild:
+ mark stable
+
+*selinux-courier-imap-20050628 (28 Jun 2005)
+
+ 28 Jun 2005; petre rodan <kaiowas@gentoo.org>
+ +selinux-courier-imap-20050628.ebuild:
+ fc change needed by policycoreutils-1.24
+
+ 27 Jun 2005; petre rodan <kaiowas@gentoo.org>
+ selinux-courier-imap-20050607.ebuild:
+ mark stable
+
+*selinux-courier-imap-20050607 (26 Jun 2005)
+
+ 26 Jun 2005; petre rodan <kaiowas@gentoo.org>
+ -selinux-courier-imap-20050219.ebuild,
+ +selinux-courier-imap-20050607.ebuild:
+ policy cleanup with no semantic diff
+
+ 23 Apr 2005; petre rodan <kaiowas@gentoo.org> :
+ mark stable
+
+*selinux-courier-imap-20050417 (17 Apr 2005)
+
+ 17 Apr 2005; petre rodan <kaiowas@gentoo.org>
+ +selinux-courier-imap-20050417.ebuild:
+ merge with upstream and fix for bug #89321
+
+ 23 Mar 2005; petre rodan <kaiowas@gentoo.org>
+ selinux-courier-imap-20050219.ebuild:
+ mark stable
+
+*selinux-courier-imap-20050219 (25 Feb 2005)
+
+ 25 Feb 2005; petre rodan <kaiowas@gentoo.org>
+ -selinux-courier-imap-20040928.ebuild,
+ +selinux-courier-imap-20050219.ebuild:
+ removed 3 port defs not present upstream
+
+ 20 Jan 2005; petre rodan <kaiowas@gentoo.org>
+ selinux-courier-imap-20050105.ebuild:
+ mark stable
+
+*selinux-courier-imap-20050105 (06 Jan 2005)
+
+ 06 Jan 2005; petre rodan <kaiowas@gentoo.org>
+ -selinux-courier-imap-20041122.ebuild,
+ +selinux-courier-imap-20050105.ebuild:
+ policy that supports courier-authlib and >=courier-imap-4.0
+
+*selinux-courier-imap-20041122 (12 Dec 2004)
+
+ 12 Dec 2004; petre rodan <kaiowas@gentoo.org>
+ -selinux-courier-imap-20040406.ebuild,
+ +selinux-courier-imap-20041122.ebuild:
+ policy tweaks needed by latest versions of c-i
+
+ 28 Oct 2004; petre rodan <kaiowas@gentoo.org>
+ selinux-courier-imap-20040928.ebuild:
+ mark stable
+
+*selinux-courier-imap-20040928 (23 Oct 2004)
+
+ 23 Oct 2004; petre rodan <kaiowas@gentoo.org> metadata.xml,
+ +selinux-courier-imap-20040928.ebuild:
+ Fix for courier-imap 3.0.5
+
+*selinux-courier-imap-20040406 (06 Apr 2004)
+
+ 06 Apr 2004; Chris PeBenito <pebenito@gentoo.org>
+ selinux-courier-imap-20040406.ebuild:
+ Fixes for courier-imap 3.0.2, from bug #45917.
+
+*selinux-courier-imap-20040203 (03 Feb 2004)
+
+ 03 Feb 2004; Chris PeBenito <pebenito@gentoo.org> metadata.xml,
+ selinux-courier-imap-20040203.ebuild:
+ Initial commit. Submitted by Petre Rodan.
+
diff --git a/sec-policy/selinux-courier/files/fix-services-courier-r2.patch b/sec-policy/selinux-courier/files/fix-services-courier-r2.patch
new file mode 100644
index 0000000..b43e90b
--- /dev/null
+++ b/sec-policy/selinux-courier/files/fix-services-courier-r2.patch
@@ -0,0 +1,84 @@
+--- services/courier.te 2010-12-13 15:11:02.000000000 +0100
++++ services/courier.te 2011-03-13 15:02:29.525999999 +0100
+@@ -37,7 +37,7 @@
+ #
+
+ allow courier_authdaemon_t self:capability { setuid setgid sys_tty_config };
+-allow courier_authdaemon_t self:unix_stream_socket connectto;
++allow courier_authdaemon_t self:unix_stream_socket { create_stream_socket_perms connectto };
+
+ can_exec(courier_authdaemon_t, courier_exec_t)
+
+@@ -52,7 +52,11 @@
+ allow courier_authdaemon_t courier_tcpd_t:tcp_socket rw_stream_socket_perms;
+ allow courier_authdaemon_t courier_tcpd_t:fifo_file rw_file_perms;
+
++read_lnk_files_pattern(courier_authdaemon_t, courier_var_lib_t, courier_var_lib_t)
++
++manage_dirs_pattern(courier_authdaemon_t, courier_var_run_t, courier_var_run_t)
+ manage_sock_files_pattern(courier_authdaemon_t, courier_spool_t, courier_spool_t)
++manage_sock_files_pattern(courier_authdaemon_t, courier_var_run_t, courier_var_run_t)
+ files_search_spool(courier_authdaemon_t)
+
+ corecmd_search_bin(courier_authdaemon_t)
+@@ -95,8 +99,12 @@
+ # inherits file handle - should it?
+ allow courier_pop_t courier_var_lib_t:file { read write };
+
++search_dirs_pattern(courier_pop_t, var_lib_t, courier_var_lib_t)
++read_lnk_files_pattern(courier_pop_t, var_lib_t, courier_var_lib_t)
++
+ miscfiles_read_localization(courier_pop_t)
+
++courier_authdaemon_rw_inherited_stream_sockets(courier_pop_t)
+ courier_domtrans_authdaemon(courier_pop_t)
+
+ # do the actual work (read the Maildir)
+@@ -133,6 +141,8 @@
+ miscfiles_read_localization(courier_tcpd_t)
+
+ courier_domtrans_pop(courier_tcpd_t)
++courier_authdaemon_stream_connect(courier_tcpd_t)
++courier_domtrans_authdaemon(courier_tcpd_t)
+
+ ########################################
+ #
+@@ -144,3 +154,7 @@
+ optional_policy(`
+ cron_system_entry(courier_sqwebmail_t, courier_sqwebmail_exec_t)
+ ')
++
++optional_policy(`
++ mysql_stream_connect(courier_authdaemon_t)
++')
+--- services/courier.fc 2010-08-03 15:11:05.000000000 +0200
++++ services/courier.fc 2011-03-13 14:55:55.737999999 +0100
+@@ -5,20 +5,24 @@
+ /usr/sbin/courierlogger -- gen_context(system_u:object_r:courier_exec_t,s0)
+ /usr/sbin/courierldapaliasd -- gen_context(system_u:object_r:courier_exec_t,s0)
+ /usr/sbin/couriertcpd -- gen_context(system_u:object_r:courier_tcpd_exec_t,s0)
+-
+-/usr/lib(64)?/courier/authlib/.* -- gen_context(system_u:object_r:courier_authdaemon_exec_t,s0)
++ifdef(`distro_gentoo',`
++/usr/lib(64)?/courier-imap/couriertcpd -- gen_context(system_u:object_r:courier_tcpd_exec_t,s0)
++')
++/usr/lib(64)?/courier/(courier-)?authlib/.* -- gen_context(system_u:object_r:courier_authdaemon_exec_t,s0)
+ /usr/lib(64)?/courier/courier/.* -- gen_context(system_u:object_r:courier_exec_t,s0)
+ /usr/lib(64)?/courier/courier/courierpop.* -- gen_context(system_u:object_r:courier_pop_exec_t,s0)
+ /usr/lib(64)?/courier/courier/imaplogin -- gen_context(system_u:object_r:courier_pop_exec_t,s0)
++/usr/sbin/imaplogin -- gen_context(system_u:object_r:courier_authdaemon_exec_t,s0)
+ /usr/lib(64)?/courier/courier/pcpd -- gen_context(system_u:object_r:courier_pcp_exec_t,s0)
+ /usr/lib(64)?/courier/imapd -- gen_context(system_u:object_r:courier_pop_exec_t,s0)
++/usr/sbin/courier-imapd -- gen_context(system_u:object_r:courier_pop_exec_t,s0)
+ /usr/lib(64)?/courier/pop3d -- gen_context(system_u:object_r:courier_pop_exec_t,s0)
+ /usr/lib(64)?/courier/rootcerts(/.*)? gen_context(system_u:object_r:courier_etc_t,s0)
+ /usr/lib(64)?/courier/sqwebmail/cleancache\.pl -- gen_context(system_u:object_r:sqwebmail_cron_exec_t,s0)
+
+-/var/lib/courier(/.*)? -- gen_context(system_u:object_r:courier_var_lib_t,s0)
++/var/lib/courier(/.*)? gen_context(system_u:object_r:courier_var_lib_t,s0)
+
+-/var/run/courier(/.*)? -- gen_context(system_u:object_r:courier_var_run_t,s0)
++/var/run/courier(/.*)? gen_context(system_u:object_r:courier_var_run_t,s0)
+
+ /var/spool/authdaemon(/.*)? gen_context(system_u:object_r:courier_spool_t,s0)
+ /var/spool/courier(/.*)? gen_context(system_u:object_r:courier_spool_t,s0)
diff --git a/sec-policy/selinux-courier/metadata.xml b/sec-policy/selinux-courier/metadata.xml
new file mode 100644
index 0000000..97a61d6
--- /dev/null
+++ b/sec-policy/selinux-courier/metadata.xml
@@ -0,0 +1,6 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!DOCTYPE pkgmetadata SYSTEM "http://www.gentoo.org/dtd/metadata.dtd">
+<pkgmetadata>
+ <herd>selinux</herd>
+ <longdescription>Gentoo SELinux policy for courier</longdescription>
+</pkgmetadata>
diff --git a/sec-policy/selinux-courier/selinux-courier-2.20101213-r2.ebuild b/sec-policy/selinux-courier/selinux-courier-2.20101213-r2.ebuild
new file mode 100644
index 0000000..6e050fd
--- /dev/null
+++ b/sec-policy/selinux-courier/selinux-courier-2.20101213-r2.ebuild
@@ -0,0 +1,17 @@
+# Copyright 1999-2011 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-courier/selinux-courier-2.20101213-r1.ebuild,v 1.1 2011/03/07 02:32:30 blueness Exp $
+
+MODS="courier"
+IUSE=""
+
+inherit selinux-policy-2
+
+DESCRIPTION="SELinux policy for courier-imap"
+
+KEYWORDS="~amd64 ~x86"
+RDEPEND="!<=sec-policy/selinux-courier-imap-2.20101213
+ >=sys-apps/policycoreutils-1.30.30
+ >=sec-policy/selinux-base-policy-${PV}"
+
+POLICY_PATCH="${FILESDIR}/fix-services-courier-r2.patch"
diff --git a/sec-policy/selinux-ldap/ChangeLog b/sec-policy/selinux-ldap/ChangeLog
new file mode 100644
index 0000000..d49ab69
--- /dev/null
+++ b/sec-policy/selinux-ldap/ChangeLog
@@ -0,0 +1,104 @@
+# ChangeLog for sec-policy/selinux-ldap
+# Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-openldap/ChangeLog,v 1.18 2011/02/05 12:07:07 blueness Exp $
+
+*selinux-ldap-2.20101213-r1 (14 Mar 2011)
+
+ 14 Mar 2011; <swift@gentoo.org> +files/fix-services-ldap-r1.patch,
+ +selinux-ldap-2.20101213-r1.ebuild, +metadata.xml:
+ Fix file contexts, enable ldap administration
+
+*selinux-openldap-2.20101213 (05 Feb 2011)
+
+ 05 Feb 2011; Anthony G. Basile <blueness@gentoo.org>
+ +selinux-openldap-2.20101213.ebuild:
+ New upstream policy.
+
+*selinux-openldap-2.20091215 (16 Dec 2009)
+
+ 16 Dec 2009; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-2.20091215.ebuild:
+ New upstream release.
+
+ 14 Aug 2009; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-openldap-20070329.ebuild, -selinux-openldap-20070928.ebuild,
+ selinux-openldap-20080525.ebuild:
+ Mark 20080525 stable, clear old ebuilds.
+
+*selinux-openldap-2.20090730 (03 Aug 2009)
+
+ 03 Aug 2009; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-2.20090730.ebuild:
+ New upstream release.
+
+ 18 Jul 2009; Chris PeBenito <pebenito@gentoo.org>
+ selinux-openldap-20070329.ebuild, selinux-openldap-20070928.ebuild,
+ selinux-openldap-20080525.ebuild:
+ Drop alpha, mips, ppc, sparc selinux support.
+
+*selinux-openldap-20080525 (25 May 2008)
+
+ 25 May 2008; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-20080525.ebuild:
+ New SVN snapshot.
+
+ 16 Mar 2008; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-openldap-20050626.ebuild, -selinux-openldap-20051122.ebuild,
+ -selinux-openldap-20061114.ebuild:
+ Remove old ebuilds.
+
+ 03 Feb 2008; Chris PeBenito <pebenito@gentoo.org>
+ selinux-openldap-20070928.ebuild:
+ Mark stable.
+
+*selinux-openldap-20070928 (26 Nov 2007)
+
+ 26 Nov 2007; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-20070928.ebuild:
+ New SVN snapshot.
+
+ 29 Aug 2007; Christian Heim <phreak@gentoo.org> metadata.xml:
+ Removing kaiowas from metadata due to his retirement (see #61930 for
+ reference).
+
+ 04 Jun 2007; Chris PeBenito <pebenito@gentoo.org>
+ selinux-openldap-20070329.ebuild:
+ Mark stable.
+
+*selinux-openldap-20070329 (29 Mar 2007)
+
+ 29 Mar 2007; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-20070329.ebuild:
+ New SVN snapshot.
+
+ 22 Feb 2007; Markus Ullmann <jokey@gentoo.org> ChangeLog:
+ Redigest for Manifest2
+
+*selinux-openldap-20061114 (15 Nov 2006)
+
+ 15 Nov 2006; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-20061114.ebuild:
+ New SVN snapshot.
+
+*selinux-openldap-20061008 (10 Oct 2006)
+
+ 10 Oct 2006; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-20061008.ebuild:
+ First mainstream reference policy testing release.
+
+ 02 Dec 2005; petre rodan <kaiowas@gentoo.org>
+ selinux-openldap-20051122.ebuild:
+ mark stable on amd64 mips ppc sparc x86
+
+*selinux-openldap-20051122 (28 Nov 2005)
+
+ 28 Nov 2005; petre rodan <kaiowas@gentoo.org>
+ selinux-openldap-20050626.ebuild, +selinux-openldap-20051122.ebuild:
+ marked stable on amd64 mips ppc sparc x86, merge with upstream
+
+*selinux-openldap-20050626 (26 Jun 2005)
+
+ 26 Jun 2005; petre rodan <kaiowas@gentoo.org> +metadata.xml,
+ +selinux-openldap-20050626.ebuild:
+ initial commit
+
diff --git a/sec-policy/selinux-ldap/files/fix-services-ldap-r1.patch b/sec-policy/selinux-ldap/files/fix-services-ldap-r1.patch
new file mode 100644
index 0000000..f459b06
--- /dev/null
+++ b/sec-policy/selinux-ldap/files/fix-services-ldap-r1.patch
@@ -0,0 +1,43 @@
+--- services/ldap.te 2010-09-10 17:05:45.000000000 +0200
++++ services/ldap.te 2011-03-12 22:10:48.814999997 +0100
+@@ -42,11 +42,12 @@
+ # cjp: why net_raw?
+ allow slapd_t self:capability { kill setgid setuid net_raw dac_override dac_read_search };
+ dontaudit slapd_t self:capability sys_tty_config;
+-allow slapd_t self:process setsched;
++allow slapd_t self:process { setsched signal };
+ allow slapd_t self:fifo_file rw_fifo_file_perms;
+ allow slapd_t self:udp_socket create_socket_perms;
+ #slapd needs to listen and accept needed by ldapsearch (slapd needs to accept from ldapseach)
+ allow slapd_t self:tcp_socket create_stream_socket_perms;
++allow slapd_t self:unix_stream_socket listen;
+
+ allow slapd_t slapd_cert_t:dir list_dir_perms;
+ read_files_pattern(slapd_t, slapd_cert_t, slapd_cert_t)
+@@ -114,6 +115,7 @@
+
+ userdom_dontaudit_use_unpriv_user_fds(slapd_t)
+ userdom_dontaudit_search_user_home_dirs(slapd_t)
++userdom_use_user_terminals(slapd_t)
+
+ optional_policy(`
+ kerberos_keytab_template(slapd, slapd_t)
+--- services/ldap.fc 2010-08-03 15:11:06.000000000 +0200
++++ services/ldap.fc 2011-03-12 18:57:10.880999997 +0100
+@@ -8,7 +8,16 @@
+ /usr/lib/slapd -- gen_context(system_u:object_r:slapd_exec_t,s0)
+ ')
+
++ifdef(`distro_gentoo',`
++/usr/lib(64)?/openldap/slapd -- gen_context(system_u:object_r:slapd_exec_t,s0)
++')
++
+ /var/lib/ldap(/.*)? gen_context(system_u:object_r:slapd_db_t,s0)
++ifdef(`distro_gentoo',`
++/var/lib/openldap-data(/.*)? gen_context(system_u:object_r:slapd_db_t,s0)
++/var/lib/openldap-ldbm(/.*)? gen_context(system_u:object_r:slapd_db_t,s0)
++/var/lib/openldap-slurpd(/.*)? gen_context(system_u:object_r:slapd_db_t,s0)
++')
+ /var/lib/ldap/replog(/.*)? gen_context(system_u:object_r:slapd_replog_t,s0)
+
+ /var/run/ldapi -s gen_context(system_u:object_r:slapd_var_run_t,s0)
diff --git a/sec-policy/selinux-ldap/metadata.xml b/sec-policy/selinux-ldap/metadata.xml
new file mode 100644
index 0000000..d873bf1
--- /dev/null
+++ b/sec-policy/selinux-ldap/metadata.xml
@@ -0,0 +1,6 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!DOCTYPE pkgmetadata SYSTEM "http://www.gentoo.org/dtd/metadata.dtd">
+<pkgmetadata>
+ <herd>selinux</herd>
+ <longdescription>Gentoo SELinux policy for openldap</longdescription>
+</pkgmetadata>
diff --git a/sec-policy/selinux-ldap/selinux-ldap-2.20101213-r1.ebuild b/sec-policy/selinux-ldap/selinux-ldap-2.20101213-r1.ebuild
new file mode 100644
index 0000000..344be61
--- /dev/null
+++ b/sec-policy/selinux-ldap/selinux-ldap-2.20101213-r1.ebuild
@@ -0,0 +1,17 @@
+# Copyright 1999-2011 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-openldap/selinux-openldap-2.20101213.ebuild,v 1.1 2011/02/05 12:07:07 blueness Exp $
+
+MODS="ldap"
+IUSE=""
+
+inherit selinux-policy-2
+
+DESCRIPTION="SELinux policy for OpenLDAP server"
+RDEPEND="!<=sec-policy/selinux-openldap-2.20101213
+ >=sys-apps/policycoreutils-1.30.30
+ >=sec-policy/selinux-base-policy-${PV}"
+
+KEYWORDS="~amd64 ~x86"
+
+POLICY_PATCH="${FILESDIR}/fix-services-ldap-r1.patch"
diff --git a/sec-policy/selinux-openldap/ChangeLog b/sec-policy/selinux-openldap/ChangeLog
new file mode 100644
index 0000000..409c099
--- /dev/null
+++ b/sec-policy/selinux-openldap/ChangeLog
@@ -0,0 +1,104 @@
+# ChangeLog for sec-policy/selinux-openldap
+# Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-openldap/ChangeLog,v 1.18 2011/02/05 12:07:07 blueness Exp $
+
+*selinux-openldap-2.20101213-r1 (14 Mar 2011)
+
+ 14 Mar 2011; <swift@gentoo.org> +selinux-openldap-2.20101213-r1.ebuild,
+ +metadata.xml:
+ Phase-out of openldap (use selinux-ldap)
+
+*selinux-openldap-2.20101213 (05 Feb 2011)
+
+ 05 Feb 2011; Anthony G. Basile <blueness@gentoo.org>
+ +selinux-openldap-2.20101213.ebuild:
+ New upstream policy.
+
+*selinux-openldap-2.20091215 (16 Dec 2009)
+
+ 16 Dec 2009; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-2.20091215.ebuild:
+ New upstream release.
+
+ 14 Aug 2009; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-openldap-20070329.ebuild, -selinux-openldap-20070928.ebuild,
+ selinux-openldap-20080525.ebuild:
+ Mark 20080525 stable, clear old ebuilds.
+
+*selinux-openldap-2.20090730 (03 Aug 2009)
+
+ 03 Aug 2009; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-2.20090730.ebuild:
+ New upstream release.
+
+ 18 Jul 2009; Chris PeBenito <pebenito@gentoo.org>
+ selinux-openldap-20070329.ebuild, selinux-openldap-20070928.ebuild,
+ selinux-openldap-20080525.ebuild:
+ Drop alpha, mips, ppc, sparc selinux support.
+
+*selinux-openldap-20080525 (25 May 2008)
+
+ 25 May 2008; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-20080525.ebuild:
+ New SVN snapshot.
+
+ 16 Mar 2008; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-openldap-20050626.ebuild, -selinux-openldap-20051122.ebuild,
+ -selinux-openldap-20061114.ebuild:
+ Remove old ebuilds.
+
+ 03 Feb 2008; Chris PeBenito <pebenito@gentoo.org>
+ selinux-openldap-20070928.ebuild:
+ Mark stable.
+
+*selinux-openldap-20070928 (26 Nov 2007)
+
+ 26 Nov 2007; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-20070928.ebuild:
+ New SVN snapshot.
+
+ 29 Aug 2007; Christian Heim <phreak@gentoo.org> metadata.xml:
+ Removing kaiowas from metadata due to his retirement (see #61930 for
+ reference).
+
+ 04 Jun 2007; Chris PeBenito <pebenito@gentoo.org>
+ selinux-openldap-20070329.ebuild:
+ Mark stable.
+
+*selinux-openldap-20070329 (29 Mar 2007)
+
+ 29 Mar 2007; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-20070329.ebuild:
+ New SVN snapshot.
+
+ 22 Feb 2007; Markus Ullmann <jokey@gentoo.org> ChangeLog:
+ Redigest for Manifest2
+
+*selinux-openldap-20061114 (15 Nov 2006)
+
+ 15 Nov 2006; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-20061114.ebuild:
+ New SVN snapshot.
+
+*selinux-openldap-20061008 (10 Oct 2006)
+
+ 10 Oct 2006; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-openldap-20061008.ebuild:
+ First mainstream reference policy testing release.
+
+ 02 Dec 2005; petre rodan <kaiowas@gentoo.org>
+ selinux-openldap-20051122.ebuild:
+ mark stable on amd64 mips ppc sparc x86
+
+*selinux-openldap-20051122 (28 Nov 2005)
+
+ 28 Nov 2005; petre rodan <kaiowas@gentoo.org>
+ selinux-openldap-20050626.ebuild, +selinux-openldap-20051122.ebuild:
+ marked stable on amd64 mips ppc sparc x86, merge with upstream
+
+*selinux-openldap-20050626 (26 Jun 2005)
+
+ 26 Jun 2005; petre rodan <kaiowas@gentoo.org> +metadata.xml,
+ +selinux-openldap-20050626.ebuild:
+ initial commit
+
diff --git a/sec-policy/selinux-openldap/metadata.xml b/sec-policy/selinux-openldap/metadata.xml
new file mode 100644
index 0000000..d873bf1
--- /dev/null
+++ b/sec-policy/selinux-openldap/metadata.xml
@@ -0,0 +1,6 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!DOCTYPE pkgmetadata SYSTEM "http://www.gentoo.org/dtd/metadata.dtd">
+<pkgmetadata>
+ <herd>selinux</herd>
+ <longdescription>Gentoo SELinux policy for openldap</longdescription>
+</pkgmetadata>
diff --git a/sec-policy/selinux-openldap/selinux-openldap-2.20101213-r1.ebuild b/sec-policy/selinux-openldap/selinux-openldap-2.20101213-r1.ebuild
new file mode 100644
index 0000000..844e6df
--- /dev/null
+++ b/sec-policy/selinux-openldap/selinux-openldap-2.20101213-r1.ebuild
@@ -0,0 +1,17 @@
+# Copyright 1999-2011 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-openldap/selinux-openldap-2.20101213.ebuild,v 1.1 2011/02/05 12:07:07 blueness Exp $
+
+EAPI=3
+
+DESCRIPTION="SELinux policy for openldap (meta package for selinux-ldap)"
+HOMEPAGE="http://hardened.gentoo.org"
+SRC_URI=""
+
+LICENSE="as-is"
+SLOT="0"
+KEYWORDS="~amd64 ~x86"
+IUSE=""
+
+RDEPEND=">=sec-policy/selinux-ldap-2.20101213-r1"
+
diff --git a/sec-policy/selinux-postfix/ChangeLog b/sec-policy/selinux-postfix/ChangeLog
new file mode 100644
index 0000000..a394f4c
--- /dev/null
+++ b/sec-policy/selinux-postfix/ChangeLog
@@ -0,0 +1,180 @@
+# ChangeLog for sec-policy/selinux-postfix
+# Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-postfix/ChangeLog,v 1.32 2011/03/07 02:50:05 blueness Exp $
+
+*selinux-postfix-2.20101213-r2 (14 Mar 2011)
+
+ 14 Mar 2011; <swift@gentoo.org> +files/fix-services-postfix-r2.patch,
+ +selinux-postfix-2.20101213-r2.ebuild, +metadata.xml:
+ Allow postfix administration through sysadm
+
+*selinux-postfix-2.20101213-r1 (07 Mar 2011)
+
+ 07 Mar 2011; Anthony G. Basile <blueness@gentoo.org>
+ +files/fix-services-postfix-r1.patch,
+ +selinux-postfix-2.20101213-r1.ebuild:
+ Fix filecontexts
+
+*selinux-postfix-2.20101213 (05 Feb 2011)
+
+ 05 Feb 2011; Anthony G. Basile <blueness@gentoo.org>
+ +selinux-postfix-2.20101213.ebuild:
+ New upstream policy.
+
+*selinux-postfix-2.20091215 (16 Dec 2009)
+
+ 16 Dec 2009; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-postfix-2.20091215.ebuild:
+ New upstream release.
+
+ 14 Aug 2009; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-postfix-20070329.ebuild, -selinux-postfix-20070928.ebuild,
+ selinux-postfix-20080525.ebuild:
+ Mark 20080525 stable, clear old ebuilds.
+
+*selinux-postfix-2.20090730 (03 Aug 2009)
+
+ 03 Aug 2009; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-postfix-2.20090730.ebuild:
+ New upstream release.
+
+ 18 Jul 2009; Chris PeBenito <pebenito@gentoo.org>
+ selinux-postfix-20070329.ebuild, selinux-postfix-20070928.ebuild,
+ selinux-postfix-20080525.ebuild:
+ Drop alpha, mips, ppc, sparc selinux support.
+
+*selinux-postfix-20080525 (25 May 2008)
+
+ 25 May 2008; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-postfix-20080525.ebuild:
+ New SVN snapshot.
+
+ 16 Mar 2008; Chris PeBenito <pebenito@gentoo.org>
+ -selinux-postfix-20050626.ebuild, -selinux-postfix-20050918.ebuild,
+ -selinux-postfix-20051023.ebuild, -selinux-postfix-20051122.ebuild,
+ -selinux-postfix-20061114.ebuild:
+ Remove old ebuilds.
+
+ 03 Feb 2008; Chris PeBenito <pebenito@gentoo.org>
+ selinux-postfix-20070928.ebuild:
+ Mark stable.
+
+*selinux-postfix-20070928 (26 Nov 2007)
+
+ 26 Nov 2007; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-postfix-20070928.ebuild:
+ New SVN snapshot.
+
+ 04 Jun 2007; Chris PeBenito <pebenito@gentoo.org>
+ selinux-postfix-20070329.ebuild:
+ Mark stable.
+
+*selinux-postfix-20070329 (29 Mar 2007)
+
+ 29 Mar 2007; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-postfix-20070329.ebuild:
+ New SVN snapshot.
+
+ 22 Feb 2007; Markus Ullmann <jokey@gentoo.org> ChangeLog:
+ Redigest for Manifest2
+
+*selinux-postfix-20061114 (15 Nov 2006)
+
+ 15 Nov 2006; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-postfix-20061114.ebuild:
+ New SVN snapshot.
+
+*selinux-postfix-20061008 (10 Oct 2006)
+
+ 10 Oct 2006; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-postfix-20061008.ebuild:
+ First mainstream reference policy testing release.
+
+*selinux-postfix-20051122 (28 Nov 2005)
+
+ 28 Nov 2005; petre rodan <kaiowas@gentoo.org>
+ selinux-postfix-20051023.ebuild, +selinux-postfix-20051122.ebuild:
+ marked stable on amd64 mips ppc sparc x86, merge with upstream
+
+*selinux-postfix-20051023 (24 Oct 2005)
+
+ 24 Oct 2005; petre rodan <kaiowas@gentoo.org>
+ +selinux-postfix-20051023.ebuild:
+ merge with upstream
+
+ 18 Oct 2005; petre rodan <kaiowas@gentoo.org>
+ selinux-postfix-20050918.ebuild:
+ mark stable
+
+*selinux-postfix-20050918 (18 Sep 2005)
+
+ 18 Sep 2005; petre rodan <kaiowas@gentoo.org>
+ -selinux-postfix-20050417.ebuild, +selinux-postfix-20050918.ebuild:
+ merge with upstream, added mips arch
+
+ 26 Jun 2005; petre rodan <kaiowas@gentoo.org>
+ selinux-postfix-20050626.ebuild:
+ mark stable
+
+*selinux-postfix-20050626 (26 Jun 2005)
+
+ 26 Jun 2005; petre rodan <kaiowas@gentoo.org>
+ -selinux-postfix-20050219.ebuild, +selinux-postfix-20050626.ebuild:
+ added name_connect rules
+
+ 23 Apr 2005; petre rodan <kaiowas@gentoo.org>
+ -selinux-postfix-20041211.ebuild, selinux-postfix-20050417.ebuild:
+ mark stable
+
+*selinux-postfix-20050417 (16 Apr 2005)
+
+ 16 Apr 2005; petre rodan <kaiowas@gentoo.org>
+ +selinux-postfix-20050417.ebuild:
+ fix for bug #89321
+
+ 23 Mar 2005; petre rodan <kaiowas@gentoo.org>
+ selinux-postfix-20050219.ebuild:
+ mark stable
+
+*selinux-postfix-20050219 (25 Feb 2005)
+
+ 25 Feb 2005; petre rodan <kaiowas@gentoo.org>
+ +selinux-postfix-20050219.ebuild:
+ merge with upstream policy
+
+*selinux-postfix-20041211 (12 Dec 2004)
+
+ 12 Dec 2004; petre rodan <kaiowas@gentoo.org>
+ -selinux-postfix-20040427.ebuild, -selinux-postfix-20041021.ebuild,
+ -selinux-postfix-20041109.ebuild, -selinux-postfix-20041120.ebuild,
+ +selinux-postfix-20041211.ebuild:
+ removed old builds, small merge with upstream policy
+
+ 23 Nov 2004; petre rodan <kaiowas@gentoo.org>
+ selinux-postfix-20041120.ebuild:
+ mark stable
+
+*selinux-postfix-20041120 (22 Nov 2004)
+
+ 22 Nov 2004; petre rodan <kaiowas@gentoo.org>
+ +selinux-postfix-20041120.ebuild:
+ merge with nsa policy
+
+*selinux-postfix-20041109 (13 Nov 2004)
+
+ 13 Nov 2004; petre rodan <kaiowas@gentoo.org>
+ +selinux-postfix-20041109.ebuild:
+ merge with nsa policy
+
+*selinux-postfix-20041021 (27 Oct 2004)
+
+ 27 Oct 2004; petre rodan <kaiowas@gentoo.org>
+ +selinux-postfix-20041021.ebuild:
+ merge with nsa policy
+
+*selinux-postfix-20040427 (27 Apr 2004)
+
+ 27 Apr 2004; Chris PeBenito <pebenito@gentoo.org> +metadata.xml,
+ +selinux-postfix-20040427.ebuild:
+ Initial commit.
+
diff --git a/sec-policy/selinux-postfix/files/fix-services-postfix-r2.patch b/sec-policy/selinux-postfix/files/fix-services-postfix-r2.patch
new file mode 100644
index 0000000..df3af68
--- /dev/null
+++ b/sec-policy/selinux-postfix/files/fix-services-postfix-r2.patch
@@ -0,0 +1,76 @@
+--- services/postfix.te 2010-08-03 15:11:07.000000000 +0200
++++ services/postfix.te 2011-03-13 16:04:36.436999999 +0100
+@@ -93,7 +93,7 @@
+ #
+
+ # chown is to set the correct ownership of queue dirs
+-allow postfix_master_t self:capability { chown dac_override kill setgid setuid net_bind_service sys_tty_config };
++allow postfix_master_t self:capability { chown dac_override kill setgid setuid net_bind_service sys_tty_config dac_read_search };
+ allow postfix_master_t self:fifo_file rw_fifo_file_perms;
+ allow postfix_master_t self:tcp_socket create_stream_socket_perms;
+ allow postfix_master_t self:udp_socket create_socket_perms;
+@@ -201,6 +201,9 @@
+
+ optional_policy(`
+ mysql_stream_connect(postfix_master_t)
++ mysql_stream_connect(postfix_cleanup_t)
++ mysql_stream_connect(postfix_local_t)
++ mysql_stream_connect(postfix_virtual_t)
+ ')
+
+ optional_policy(`
+@@ -589,6 +592,7 @@
+ # for OpenSSL certificates
+ files_read_usr_files(postfix_smtpd_t)
+ mta_read_aliases(postfix_smtpd_t)
++mta_read_config(postfix_smtpd_t)
+
+ optional_policy(`
+ dovecot_stream_connect_auth(postfix_smtpd_t)
+--- services/postfix.fc 2010-08-03 15:11:07.000000000 +0200
++++ services/postfix.fc 2011-03-13 15:54:11.765000000 +0100
+@@ -16,20 +16,21 @@
+ /usr/libexec/postfix/pipe -- gen_context(system_u:object_r:postfix_pipe_exec_t,s0)
+ /usr/libexec/postfix/virtual -- gen_context(system_u:object_r:postfix_virtual_exec_t,s0)
+ ', `
+-/usr/lib/postfix/.* -- gen_context(system_u:object_r:postfix_exec_t,s0)
+-/usr/lib/postfix/cleanup -- gen_context(system_u:object_r:postfix_cleanup_exec_t,s0)
+-/usr/lib/postfix/local -- gen_context(system_u:object_r:postfix_local_exec_t,s0)
+-/usr/lib/postfix/master -- gen_context(system_u:object_r:postfix_master_exec_t,s0)
+-/usr/lib/postfix/pickup -- gen_context(system_u:object_r:postfix_pickup_exec_t,s0)
+-/usr/lib/postfix/(n)?qmgr -- gen_context(system_u:object_r:postfix_qmgr_exec_t,s0)
+-/usr/lib/postfix/showq -- gen_context(system_u:object_r:postfix_showq_exec_t,s0)
+-/usr/lib/postfix/smtp -- gen_context(system_u:object_r:postfix_smtp_exec_t,s0)
+-/usr/lib/postfix/lmtp -- gen_context(system_u:object_r:postfix_smtp_exec_t,s0)
+-/usr/lib/postfix/scache -- gen_context(system_u:object_r:postfix_smtp_exec_t,s0)
+-/usr/lib/postfix/smtpd -- gen_context(system_u:object_r:postfix_smtpd_exec_t,s0)
+-/usr/lib/postfix/bounce -- gen_context(system_u:object_r:postfix_bounce_exec_t,s0)
+-/usr/lib/postfix/pipe -- gen_context(system_u:object_r:postfix_pipe_exec_t,s0)
+-/usr/lib/postfix/virtual -- gen_context(system_u:object_r:postfix_virtual_exec_t,s0)
++/usr/lib(64)?/postfix/.* -- gen_context(system_u:object_r:postfix_exec_t,s0)
++/usr/lib(64)?/postfix/cleanup -- gen_context(system_u:object_r:postfix_cleanup_exec_t,s0)
++/usr/lib(64)?/postfix/local -- gen_context(system_u:object_r:postfix_local_exec_t,s0)
++/usr/lib(64)?/postfix/master -- gen_context(system_u:object_r:postfix_master_exec_t,s0)
++/usr/lib(64)?/postfix/pickup -- gen_context(system_u:object_r:postfix_pickup_exec_t,s0)
++/usr/lib(64)?/postfix/(n)?qmgr -- gen_context(system_u:object_r:postfix_qmgr_exec_t,s0)
++/usr/lib(64)?/postfix/showq -- gen_context(system_u:object_r:postfix_showq_exec_t,s0)
++/usr/lib(64)?/postfix/smtp -- gen_context(system_u:object_r:postfix_smtp_exec_t,s0)
++/usr/lib(64)?/postfix/lmtp -- gen_context(system_u:object_r:postfix_smtp_exec_t,s0)
++/usr/lib(64)?/postfix/scache -- gen_context(system_u:object_r:postfix_smtp_exec_t,s0)
++/usr/lib(64)?/postfix/smtpd -- gen_context(system_u:object_r:postfix_smtpd_exec_t,s0)
++/usr/lib(64)?/postfix/bounce -- gen_context(system_u:object_r:postfix_bounce_exec_t,s0)
++/usr/lib(64)?/postfix/pipe -- gen_context(system_u:object_r:postfix_pipe_exec_t,s0)
++/usr/lib(64)?/postfix/virtual -- gen_context(system_u:object_r:postfix_virtual_exec_t,s0)
++/usr/lib(64)?/postfix/postfix-script.* -- gen_context(system_u:object_r:postfix_exec_t,s0)
+ ')
+ /etc/postfix/postfix-script.* -- gen_context(system_u:object_r:postfix_exec_t,s0)
+ /etc/postfix/prng_exch -- gen_context(system_u:object_r:postfix_prng_t,s0)
+@@ -48,7 +49,7 @@
+
+ /var/spool/postfix(/.*)? gen_context(system_u:object_r:postfix_spool_t,s0)
+ /var/spool/postfix/maildrop(/.*)? gen_context(system_u:object_r:postfix_spool_maildrop_t,s0)
+-/var/spool/postfix/pid/.* gen_context(system_u:object_r:postfix_var_run_t,s0)
++/var/spool/postfix/pid(/.*)? gen_context(system_u:object_r:postfix_var_run_t,s0)
+ /var/spool/postfix/private(/.*)? gen_context(system_u:object_r:postfix_private_t,s0)
+ /var/spool/postfix/public(/.*)? gen_context(system_u:object_r:postfix_public_t,s0)
+ /var/spool/postfix/bounce(/.*)? gen_context(system_u:object_r:postfix_spool_bounce_t,s0)
diff --git a/sec-policy/selinux-postfix/metadata.xml b/sec-policy/selinux-postfix/metadata.xml
new file mode 100644
index 0000000..6cad3d5
--- /dev/null
+++ b/sec-policy/selinux-postfix/metadata.xml
@@ -0,0 +1,6 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!DOCTYPE pkgmetadata SYSTEM "http://www.gentoo.org/dtd/metadata.dtd">
+<pkgmetadata>
+ <herd>selinux</herd>
+ <longdescription>Gentoo SELinux policy for postfix</longdescription>
+</pkgmetadata>
diff --git a/sec-policy/selinux-postfix/selinux-postfix-2.20101213-r2.ebuild b/sec-policy/selinux-postfix/selinux-postfix-2.20101213-r2.ebuild
new file mode 100644
index 0000000..e93eab8
--- /dev/null
+++ b/sec-policy/selinux-postfix/selinux-postfix-2.20101213-r2.ebuild
@@ -0,0 +1,14 @@
+# Copyright 1999-2011 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-postfix/selinux-postfix-2.20101213-r1.ebuild,v 1.1 2011/03/07 02:50:05 blueness Exp $
+
+MODS="postfix"
+IUSE=""
+
+inherit selinux-policy-2
+
+DESCRIPTION="SELinux policy for postfix"
+
+KEYWORDS="~amd64 ~x86"
+
+POLICY_PATCH="${FILESDIR}/fix-services-postfix-r2.patch"
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2011-03-14 19:12 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-03-14 19:12 [gentoo-commits] proj/hardened-dev:master commit in: sec-policy/selinux-postfix/files/, sec-policy/selinux-courier/, Sven Vermeulen
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox