Message ID | 20250328142811.4096141-2-dominick.grift@defensec.nl |
---|---|
State | New |
Headers | show
Return-Path: <openwrt-devel-bounces+incoming=patchwork.ozlabs.org@lists.openwrt.org> X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; secure) header.d=lists.infradead.org header.i=@lists.infradead.org header.a=rsa-sha256 header.s=bombadil.20210309 header.b=wJC4lYSs; dkim=fail reason="signature verification failed" (1024-bit key; unprotected) header.d=defensec.nl header.i=@defensec.nl header.a=rsa-sha256 header.s=default header.b=fNpvdLbJ; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=none (no SPF record) smtp.mailfrom=lists.openwrt.org (client-ip=2607:7c80:54:3::133; helo=bombadil.infradead.org; envelope-from=openwrt-devel-bounces+incoming=patchwork.ozlabs.org@lists.openwrt.org; receiver=patchwork.ozlabs.org) Received: from bombadil.infradead.org (bombadil.infradead.org [IPv6:2607:7c80:54:3::133]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (secp384r1) server-digest SHA384) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4ZPNvc07Gzz1yHN for <incoming@patchwork.ozlabs.org>; Sat, 29 Mar 2025 01:58:51 +1100 (AEDT) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:References:In-Reply-To: Message-ID:Date:Subject:Cc:To:From:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=oXFIrGRc9qfIcfpNviVHPXM8WGTLG7KqlVg8s+fITyM=; b=wJC4lYSsKz4c0n WGPnGqZengbMVRLWZZ4KxolUUxhGMxWfqaMHaZCi3gd4u1qpoCv4VuVrEfHvFsWEciesuRrw11c0H v5Ao9kVTHKeO5Y++LFjht5wxQMkEtXba7Q5H/ixX/0N3Ub4W5yge3VG0/omFbhW63zpqSsL+LcZu6 E7E/WpPtwCEwMSp24hOdaGRuIIdCf/Ay44q6oZS1aaEupvUsykmDoQg/JvqtUaNc8N4q5oab1CqtC ijTVcYiF3Dr9sJSJZT21aDQSScsTK48l1v7vIr/i6mEf+q9v7PCNFRyOsUJzBuA3GBZDckXoPdRHm VkTmk7g2f+0ydaNF2r+Q==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.98.1 #2 (Red Hat Linux)) id 1tyB9C-0000000Dfno-1tP5; Fri, 28 Mar 2025 14:57:26 +0000 Received: from markus.defensec.nl ([2a10:3781:2099::123]) by bombadil.infradead.org with esmtps (Exim 4.98.1 #2 (Red Hat Linux)) id 1tyAhD-0000000DbB1-3Whh for openwrt-devel@lists.openwrt.org; Fri, 28 Mar 2025 14:28:35 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=defensec.nl; s=default; t=1743172095; bh=GxrSxqJ/R5Qen2LUfEpcOiplOfNds/wTBHUha18rmkU=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=fNpvdLbJE6Wybhe70AZJWv6K8aexV8CEJbn8TPRC+trPB6koOn4+hxnDFTTZBYob0 tbM4oHrU6HmKfpElMzNu4xSQKzETRy8urA6x+bzLd5kOo87Wz9HYuqOMsAeHSO7vPb oho2edmzCHGXZsZHzyPlukbWn9b7t9SJybSUapU0= Received: from template-20250210123507.. (nimbus.lan [IPv6:2a10:3781:2099::514]) by markus.defensec.nl (Postfix) with ESMTPSA id 5E578160DA7; Fri, 28 Mar 2025 15:28:15 +0100 (CET) From: Dominick Grift <dominick.grift@defensec.nl> To: openwrt-devel@lists.openwrt.org Cc: Dominick Grift <dominick.grift@defensec.nl> Subject: [PATCH 2/6] libselinux: update to version 3.8.1 Date: Fri, 28 Mar 2025 15:28:07 +0100 Message-ID: <20250328142811.4096141-2-dominick.grift@defensec.nl> X-Mailer: git-send-email 2.47.2 In-Reply-To: <20250328142811.4096141-1-dominick.grift@defensec.nl> References: <20250328142811.4096141-1-dominick.grift@defensec.nl> MIME-Version: 1.0 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20250328_072832_563701_8109E8C7 X-CRM114-Status: GOOD ( 11.72 ) X-Spam-Score: -2.8 (--) X-Spam-Report: Spam detection software, running on the system "bombadil.infradead.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Changes since version 3.5 8e9157bb Update VERSIONs to 3.8.1 for release. 71aec30d Update VERSIONs to 3.8 for release. 45fdf23c libselinux: Close old selabel handle when setting a new one 9833f0d2 Update VERSIONs to 3.8-rc4 for [...] Content analysis details: (-2.8 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at https://www.dnswl.org/, low trust [2a10:3781:2099:0:0:0:0:123 listed in] [list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000] X-BeenThere: openwrt-devel@lists.openwrt.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: OpenWrt Development List <openwrt-devel.lists.openwrt.org> List-Unsubscribe: <https://lists.openwrt.org/mailman/options/openwrt-devel>, <mailto:openwrt-devel-request@lists.openwrt.org?subject=unsubscribe> List-Archive: <http://lists.openwrt.org/pipermail/openwrt-devel/> List-Post: <mailto:openwrt-devel@lists.openwrt.org> List-Help: <mailto:openwrt-devel-request@lists.openwrt.org?subject=help> List-Subscribe: <https://lists.openwrt.org/mailman/listinfo/openwrt-devel>, <mailto:openwrt-devel-request@lists.openwrt.org?subject=subscribe> Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "openwrt-devel" <openwrt-devel-bounces@lists.openwrt.org> Errors-To: openwrt-devel-bounces+incoming=patchwork.ozlabs.org@lists.openwrt.org |
Series | [1/6] libsepol: update to version 3.8.1 | expand |
diff --git a/package/libs/libselinux/Makefile b/package/libs/libselinux/Makefile index f90d4993c8..9f65f5bf65 100644 --- a/package/libs/libselinux/Makefile +++ b/package/libs/libselinux/Makefile @@ -6,12 +6,12 @@ include $(TOPDIR)/rules.mk PKG_NAME:=libselinux -PKG_VERSION:=3.5 +PKG_VERSION:=3.8.1 PKG_RELEASE:=1 PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz PKG_SOURCE_URL:=https://github.com/SELinuxProject/selinux/releases/download/$(PKG_VERSION) -PKG_HASH:=9a3a3705ac13a2ccca2de6d652b6356fead10f36fb33115c185c5ccdf29eec19 +PKG_HASH:=ec2d2789f931152d21c1db1eb4bc202ce4eccede34d9be9e360e3b45243cee2c PKG_LICENSE:=libselinux-1.0 PKG_LICENSE_FILES:=LICENSE
Changes since version 3.5 8e9157bb Update VERSIONs to 3.8.1 for release. 71aec30d Update VERSIONs to 3.8 for release. 45fdf23c libselinux: Close old selabel handle when setting a new one 9833f0d2 Update VERSIONs to 3.8-rc4 for release. 2cb24a20 libselinux: set errno in failure case c8a5aa74 libselinux/fuzz: handle inputs with trailing data d13d13ea libselinux/fuzz: readjust load_mmap() update e0f61d3b Update VERSIONs to 3.8-rc3 for release. 08e0a348 libselinux: restore previous regex spec ordering 6c8f6390 libselinux/fuzz: update for lookup_all() change 9395cc03 Always build for LFS mode on 32-bit archs. adf2e609 Update VERSIONs to 3.8-rc2 for release. f50abe2a libselinux/utils: drop reachable assert in sefcontext_compile 2db6d12a libselinux/utils: use correct error handling 3ff5f9ef libselinux: simplify string formatting 4d436e4b libselinux: use vector instead of linked list for substitutions 89dd0b23 libselinux: avoid memory allocation in common file label lookup 742a3543 libselinux: harden availability check against user CFLAGS 856895ca libselinux: move functions out of header file 8efed460 libselinux: avoid dynamic allocation in openattr() 39174cfd libselinux: make use of calloc(3) 2dec1581 Update VERSIONs to 3.8-rc1 for release. 20175564 libselinux: support parallel selabel_lookup(3) 8997f543 libselinux: add selabel_file(5) fuzzer daa3e6e9 libselinux: remove unused hashtab code 92306daf libselinux: rework selabel_file(5) database 90b1c237 libselinux: sidtab updates e5fd7b07 libselinux: add unique id to sidtab entries 162d8ed0 libselinux: use more appropriate types in sidtab 44f7af06 libselinux/utils: introduce selabel_compare f18f9e5e libselinux/matchpathcon: RESOURCE_LEAK: Variable "con" 33ac7c96 libselinux/setexecfilecon: Remove useless rc check cecbff93 selinux: set missing errno in failure branch 48f66b6a selinux: free memory in error branch 6376f90d libselinux: avoid errno modification by fclose(3) 8e0e718b libselinux: fix swig bindings for 4.3.0 9b83fe3d libselinux: formally deprecate security_compute_user() b4117420 libselinux: rename hashtab functions 463584cb libselinux: deprecate security_disable(3) 017d7d53 libselinux: Fix integer comparison issues when compiling for 32-bit 7974aea5 libselinux/restorecon: Include <selinux/label.h> f398662e libselinux: set free'd data to NULL 2eb286bc Release 3.7 e6c99f34 Update VERSIONs to 3.7-rc3 for release. f55f7648 libselinux: constify avc_open(3) parameter a02fccf8 tree-wide: fix misc typos 2b6f639a libselinux: avoid pointer dereference before check c8b1f592 libselinux: free empty scandir(3) result 9ef1a835 Update VERSIONs to 3.7-rc2 for release. 6a223cb1 Update VERSIONs to 3.7-rc1 for release. f1dadd19 libselinux: constify selinux_set_mapping(3) parameter d370cbfc libselinux/man: add format attribute for set_matchpathcon_printf(3) c476389b libselinux/man: use void in synopses 06b326d4 libselinux/man: sync const qualifiers 9f06e045 libselinux/man: correct file extension of man pages 6e2f7033 libselinux: avoid logs in get_ordered_context_list() without policy af543f1b libselinux, libsepol: Add CFLAGS and LDFLAGS to Makefile checks fb497895 libselinux/utils/selabel_digest: pass BASEONLY only for file backend 5876aca0 libselinux: free data on selabel open failure 994b9b20 libselinux/utils/selabel_digest: avoid buffer overflow 5f5edd48 libselinux/utils/selabel_digest: cleanup c774f15a libselinux/utils/selabel_digest: drop unsupported option -d 82195e77 libselinux: use reentrant strtok_r(3) dfe30d9d libselinux: Fix ordering of arguments to calloc b18fddef libselinux: reorder calloc(3) arguments 454a9f24 libselinux: enable usage with pedantic UB sanitizers ebf41685 libselinux: support huge passwd/group entries 846550d7 libselinux: use logging wrapper in getseuser(3) and get_default_context(3) family 65c8fd45 libselinux: fail selabel_open(3) on invalid option 7f925776 libselinux: align SELABEL_OPT_DIGEST usage with man page 1dd04338 libselinux/utils: improve compute_av output 1d5c3b72 libselinux/utils: free allocated resources abd18ec3 libselinux/man: sync selinux_check_securetty_context(3) 1daa91b2 libselinux/man: mention errno for regex compilation failure 97fa708d Update VERSIONs to 3.6 for release. 5939fb96 libselinux: state setexecfilecon(3) sets errno on failure 4c8bf60f libselinux: always set errno on context translation failure 00a1cf46 libselinux: update const qualifier of parameters in man pages 89dd980c Add CPPFLAGS to Makefiles 0f5a8dd3 Update VERSIONs to 3.6-rc2 for release. f1178a13 libselinux: use DJB2a string hash function d858afca libselinux: fix memory leak in customizable_init() 9fcf4cca libselinux: update Python binding 1aaf5943 Update VERSIONs to 3.6-rc1 for release. cb8289c2 libselinux: introduce reallocarray(3) 3dad44a1 libselinux: cast to unsigned char for character handling function 674470fd libselinux/utils: update getdefaultcon 6df403d5 libselinux: set errno on label lookup failure 168edd1c libselinux: free elements on read_spec_entries() failure dcb8e1bf libselinux/utils: drop include of internal header file c81c76cb libselinux: simplify internal selabel_validate prototype 9911f2ac libselinux: check for stream rewind failures 275daa4e libselinux: avoid unused function 25a18110 libselinux: fix logic for building android backend 0b93e30c libselinux: update string_to_mode() e28f6a8a libselinux/utils: use correct type for backend argument 0eb989f6 libselinux: parameter simplifications 4eea9948 libselinux: avoid regex serialization truncations f1a8afc2 libselinux/utils: use type safe union assignment 92b1e5b6 libselinux: simplify zeroing allocation b4007663 libselinux: constify selabel_cmp(3) parameters 9c668bfd libselinux: drop unnecessary warning overrides bfff3417 libselinux: drop obsolete optimization flag 6ec7a49c libselinux: misc label cleanup 3459dfd9 libselinux/utils: update selabel_partial_match 14f35fde Do not automatically install Russian translations 84c195e1 libselinux: Remove the Russian translations 8e6e0443 libselinux: Remove the Russian translations 8963492b checkpolicy,libselinux,libsepol,policycoreutils,semodule-utils: update my email f189e8af libselinux,policycoreutils,python,semodule-utils: de-brand SELinux ec35d1d8 libselinux/utils: introduce getpolicyload d8edd363 libselinux: add check for calloc in check_booleans d596efb4 libselinux: Add examples to man pages 2c7b71db libselinux: performance optimization for duplicate detection 4a420508 libselinux: adapting hashtab to libselinux d95bc8b7 libselinux: migrating hashtab from policycoreutils c9b3cbb6 libselinux: set CFLAGS for pip installation Signed-off-by: Dominick Grift <dominick.grift@defensec.nl> --- package/libs/libselinux/Makefile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-)