Chapter 1. Package Updates
240
• Instances of
#!/usr/bin/env python
have been removed from SELinux policy source code, as
using this technique to call
python
in the top of an executable python file is being discontinued by
Red Hat developers. (
BZ#521284
1920
)
• Support for Red Hat Cluster Suite has been added to SELinux policy. Please note that SELinux
policy only provides coverage for the infrastructure components. Services directly managed
by Cluster Suite will require their own policies and are not covered by this enhancement.
(
BZ#522158
1921
)
• SELinux policy has been modified so that
cyrus-imapd
is now able to register its SNMP sub-agent
by connecting to a socket upon startup. (
BZ#523548
1922
)
• An SELinux denial was triggered when configuring the
SNMP
daemon to listen on TCP or UDP
ports for AgentX sub-agents. Policy has been modified so that this daemon can now bind TCP/UDP
sockets to AgentX ports. (
BZ#523773
1923
)
• SELinux denials were caused when implementing user quotas over
NFS
(Network File System)
shares. Policy has been modified to properly allow for the normal operation of quotas when using
NFS shares. (
BZ#525420
1924
)
• Upon updating the
udev
daemon to the latest version and restarting it, the SELinux context for udev
was changed from the default, causing errors. This update ensures that this context remains correct
when restarting udev. (
BZ#526640
1925
)
• SELinux policy has been modified to not trigger an error when the virDomainSave() API is called
from
qemu-kvm
. (
BZ#530552
1926
)
•
procmail
was causing an AVC denial when attempting to read files used by
spamassassin
.
Rules have been added to policy so that these applications can communicate normally via pipes.
(
BZ#530750
1927
)
• The ability to send and receive unlabeled packets was added to policy rules. (
BZ#530809
1928
)
• A bug prevented the installation of the
selinux-policy-strict
package because the requirements
of
aisexec
were not properly met. The strict policy can now be installed as expected.
(
BZ#531196
1929
)
• Real Time Kernel support was added to selinux-policy. (
BZ#531230
1930
)
• The
e4fsck
command was not properly labeled, causing execution to fail. Policy permissions have
been fixed so that e4fsck is now correctly labeled. (
BZ#532565
1931
)
• Permissions were modified to allow
pluto
to write logs properly. (
BZ#537106
1932
)
• This update includes updated policy rules for
IPsec
, fixing the AVC denials that prevented
pluto
from running properly. After applying this update, pluto runs as expected. Note that this is necessary
for FIPS-140 security compliance. (
BZ#537133
1933
)
•
vhostmd
is a daemon that provides a communication channel between a host and its hosted
virtual machines. Implementing a
vhostmd
daemon caused AVC denial errors when launching it
via
service vhostmd start
. SELinux policy rules have been added to protect the vhostmd
daemon. The daemon starts and operates normally after applying the update. (
BZ#543941
1934
)
Summary of Contents for ENTERPRISE LINUX 5.5 - S 2010
Page 10: ...x ...
Page 308: ...298 ...
Page 310: ...300 ...
Page 468: ...458 ...
Page 470: ...460 ...