Changelog
policycoreutils (1.28-1) unstable; urgency=low
* New upstream release
* Updated version for release.
* Clarified the genhomedircon warning message.
* Changed genhomedircon to warn on use of ROLE in homedir_template
if using managed policy, as libsemanage does not yet support it.
* Merged genhomedircon bug fix from Dan Walsh.
* Revised semodule* man pages to refer to checkmodule and
to include example sections.
* Merged audit2allow --tefile and --fcfile support from Dan Walsh.
* Merged genhomedircon fix from Dan Walsh.
* Merged semodule* man pages from Dan Walsh, and edited them.
* Changed setfiles to set the MATCHPATHCON_VALIDATE flag to
retain validation/canonicalization of contexts during init.
* Changed genhomedircon to always use user_r for the role in the
managed case since user_get_defrole is broken.
* Merged sestatus, audit2allow, and semanage patch from Dan Walsh.
* Fixed semodule -v option.
* Merged audit2allow python script from Dan Walsh.
(old script moved to audit2allow.perl, will be removed later).
* Merged genhomedircon fixes from Dan Walsh.
* Merged semodule quieting patch from Dan Walsh
(inverts default, use -v to restore original behavior).
* Merged genhomedircon rewrite from Dan Walsh.
* Merged setsebool cleanup patch from Ivan Gyurdiev.
* Added -B (--build) option to semodule to force a rebuild.
* Reverted setsebool patch to call semanage_set_reload_bools().
* Changed setsebool to disable policy reload and to call
security_set_boolean_list to update the runtime booleans.
* Changed setfiles -c to use new flag to set_matchpathcon_flags()
to disable context translation by matchpathcon_init().
* Changed setfiles for the context canonicalization support.
* Changed setsebool to call semanage_is_managed() interface
and fall back to security_set_boolean_list() if policy is
not managed.
* Merged setsebool memory leak fix from Ivan Gyurdiev.
* Merged setsebool patch to call semanage_set_reload_bools()
interface from Ivan Gyurdiev.
* Merged setsebool patch from Ivan Gyurdiev.
This moves setsebool from libselinux/utils to policycoreutils,
and rewrites it to use libsemanage for permanent boolean changes.
* Merged semodule support for reload, noreload, and store options
from Joshua Brindle.
* Merged semodule_package rewrite from Joshua Brindle.
* Cleaned up usage and error messages and releasing of memory by
semodule_* utilities.
* Corrected error reporting by semodule.
* Updated semodule_expand for change to sepol interface.
* Merged fixes for make DESTDIR= builds from Joshua Brindle.
* Updated semodule_package for sepol interface changes.
* Updated semodule_expand/link for sepol interface changes.
* Merged non-PAM Makefile support for newrole and run_init from Timothy Wood.
* Updated semodule_expand to use get interfaces for hidden sepol_module_package type.
* Merged newrole and run_init pam config patches from Dan Walsh (Red Hat).
* Merged fixfiles patch from Dan Walsh (Red Hat).
* Updated semodule for removal of semanage_strerror.
* Updated semodule_link and semodule_expand to use shared libsepol.
Fixed audit2why to call policydb_init prior to policydb_read (still
uses the static libsepol).
* Bug fix: "policycoreutils: doesn't remove /usr/sbin/setfiles.old on
purge", thanks to Lars Wirzenius (Closes: #341418).
-- Manoj Srivastava <email address hidden> Fri, 30 Dec 2005 00:56:01 -0600