| Message ID | 20250328142811.4096141-6-dominick.grift@defensec.nl |
|---|---|
| State | New |
| Headers | show
Return-Path:
<openwrt-devel-bounces+incoming=patchwork.ozlabs.org@lists.openwrt.org>
X-Original-To: incoming@patchwork.ozlabs.org
Delivered-To: patchwork-incoming@legolas.ozlabs.org
Authentication-Results: legolas.ozlabs.org;
dkim=pass (2048-bit key;
secure) header.d=lists.infradead.org header.i=@lists.infradead.org
header.a=rsa-sha256 header.s=bombadil.20210309 header.b=ng0k2jSh;
dkim=fail reason="signature verification failed" (1024-bit key;
unprotected) header.d=defensec.nl header.i=@defensec.nl header.a=rsa-sha256
header.s=default header.b=CSwzHlQZ;
dkim-atps=neutral
Authentication-Results: legolas.ozlabs.org;
spf=none (no SPF record) smtp.mailfrom=lists.openwrt.org
(client-ip=2607:7c80:54:3::133; helo=bombadil.infradead.org;
envelope-from=openwrt-devel-bounces+incoming=patchwork.ozlabs.org@lists.openwrt.org;
receiver=patchwork.ozlabs.org)
Received: from bombadil.infradead.org (bombadil.infradead.org
[IPv6:2607:7c80:54:3::133])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange X25519 server-signature ECDSA (secp384r1) server-digest SHA384)
(No client certificate requested)
by legolas.ozlabs.org (Postfix) with ESMTPS id 4ZPNvc2zLsz1yHR
for <incoming@patchwork.ozlabs.org>; Sat, 29 Mar 2025 01:58:52 +1100 (AEDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.infradead.org; s=bombadil.20210309; h=Sender:
Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post:
List-Archive:List-Unsubscribe:List-Id:MIME-Version:References:In-Reply-To:
Message-ID:Date:Subject:Cc:To:From:Reply-To:Content-ID:Content-Description:
Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:
List-Owner; bh=2NmADUjRmDnj1zfEhJ4Y1zWdMv5BK4MtnXEtsRJ5YFQ=; b=ng0k2jSh/DwiIO
23aoxI/1nlEb8qwNchfLN3jB8VIorGB0SFl3CJ8NcYqIbKasNx+E2iBws3Fnr8jAyMjrlr5jAJacQ
WVCknMGjd7xuTe+XJxZ1rzgOcuIQDsN8OvKi7YCkSbax/WuaDbSFYgf9w1h0UoTsL9nR/9yNlT/EH
NdSJOmWuhvf41q361uiM6P5F6eg0pAFxG9PNdGbJ4sbIYRup6vSePvnEozZm6N6KsFYfdPwng9FWP
fbDpe+9sx7D6pTCEt/8B8hSdGpevQtCCVfE8eMvH2MpkGaGNlB/EXEJICo7xquuKshvnSp3IaMgbG
Bgja5ZiQsUf8BoEwbiJQ==;
Received: from localhost ([::1] helo=bombadil.infradead.org)
by bombadil.infradead.org with esmtp (Exim 4.98.1 #2 (Red Hat Linux))
id 1tyB9F-0000000Dfoz-16Ol;
Fri, 28 Mar 2025 14:57:29 +0000
Received: from markus.defensec.nl ([2a10:3781:2099::123])
by bombadil.infradead.org with esmtps (Exim 4.98.1 #2 (Red Hat Linux))
id 1tyAhH-0000000DbF9-0NzB
for openwrt-devel@lists.openwrt.org;
Fri, 28 Mar 2025 14:28:36 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=defensec.nl;
s=default; t=1743172095;
bh=2AUx2+xnUMdq2zdTVjUgfdBCuQzbCxE+tOr3IvkB0F0=;
h=From:To:Cc:Subject:Date:In-Reply-To:References:From;
b=CSwzHlQZQLjg+pPLGUDlX93QwQ9xnFVz8c6yIxG7Td2gGHc6AfImkZTjHxM8rmFKa
Rf3RW/B797yKvql+PLMyqy1G8y4XZOvw4kdhZfcR2iZbNkrLP3hmINA5YrDpviNJvL
oFE8naesw+0OfGILYKk+itz1h7UamomdUoRWnZMU=
Received: from template-20250210123507.. (nimbus.lan
[IPv6:2a10:3781:2099::514])
by markus.defensec.nl (Postfix) with ESMTPSA id AC120160DAB;
Fri, 28 Mar 2025 15:28:15 +0100 (CET)
From: Dominick Grift <dominick.grift@defensec.nl>
To: openwrt-devel@lists.openwrt.org
Cc: Dominick Grift <dominick.grift@defensec.nl>
Subject: [PATCH 6/6] checkpolicy: update to version 3.8.1
Date: Fri, 28 Mar 2025 15:28:11 +0100
Message-ID: <20250328142811.4096141-6-dominick.grift@defensec.nl>
X-Mailer: git-send-email 2.47.2
In-Reply-To: <20250328142811.4096141-1-dominick.grift@defensec.nl>
References: <20250328142811.4096141-1-dominick.grift@defensec.nl>
MIME-Version: 1.0
X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3
X-CRM114-CacheID: sfid-20250328_072835_430391_92A3DE31
X-CRM114-Status: GOOD ( 10.19 )
X-Spam-Score: -2.8 (--)
X-Spam-Report: Spam detection software,
running on the system "bombadil.infradead.org",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Changes since version 3.5 8e9157bb Update VERSIONs to 3.8.1
for release. 71aec30d Update VERSIONs to 3.8 for release. 9833f0d2 Update
VERSIONs to 3.8-rc4 for release. 4c246013 checkpolicy: clear queue between
parser passes fdb [...]
Content analysis details: (-2.8 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
-0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at https://www.dnswl.org/, low
trust
[2a10:3781:2099:0:0:0:0:123 listed in]
[list.dnswl.org]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
-0.1 DKIM_VALID Message has at least one valid DKIM or DK
signature
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from
author's
domain
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily valid
-1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1%
[score: 0.0000]
X-BeenThere: openwrt-devel@lists.openwrt.org
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: OpenWrt Development List <openwrt-devel.lists.openwrt.org>
List-Unsubscribe: <https://lists.openwrt.org/mailman/options/openwrt-devel>,
<mailto:openwrt-devel-request@lists.openwrt.org?subject=unsubscribe>
List-Archive: <http://lists.openwrt.org/pipermail/openwrt-devel/>
List-Post: <mailto:openwrt-devel@lists.openwrt.org>
List-Help: <mailto:openwrt-devel-request@lists.openwrt.org?subject=help>
List-Subscribe: <https://lists.openwrt.org/mailman/listinfo/openwrt-devel>,
<mailto:openwrt-devel-request@lists.openwrt.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: "openwrt-devel" <openwrt-devel-bounces@lists.openwrt.org>
Errors-To:
openwrt-devel-bounces+incoming=patchwork.ozlabs.org@lists.openwrt.org
|
| Series | [1/6] libsepol: update to version 3.8.1 | expand |
diff --git a/package/utils/checkpolicy/Makefile b/package/utils/checkpolicy/Makefile index 4ebf97bb3f..179127bf1a 100644 --- a/package/utils/checkpolicy/Makefile +++ b/package/utils/checkpolicy/Makefile @@ -6,12 +6,12 @@ include $(TOPDIR)/rules.mk PKG_NAME:=checkpolicy -PKG_VERSION:=3.5 +PKG_VERSION:=3.8.1 PKG_RELEASE:=1 PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz PKG_SOURCE_URL:=https://github.com/SELinuxProject/selinux/releases/download/$(PKG_VERSION) -PKG_HASH:=7aa48ab2222a0b9881111d6d7f70c3014d3d9338827d9e02df105a68c0df5dbc +PKG_HASH:=7b477c516e2693d8b6c511386323177f1d7db51c2e04eb6d0de8ca2b36120e5d PKG_INSTALL:=1 PKG_BUILD_DEPENDS:=libselinux HOST_BUILD_DEPENDS:=libselinux/host
Changes since version 3.5 8e9157bb Update VERSIONs to 3.8.1 for release. 71aec30d Update VERSIONs to 3.8 for release. 9833f0d2 Update VERSIONs to 3.8-rc4 for release. 4c246013 checkpolicy: clear queue between parser passes fdb70902 checkpolicy: do not consume unmatched identifiers 21cbacb6 checkpolicy: remove unneeded queue_head() 158fb95e checkpolicy: check identifier before copying e0f61d3b Update VERSIONs to 3.8-rc3 for release. adf2e609 Update VERSIONs to 3.8-rc2 for release. 42d653aa checkpolicy: drop host bits in IPv6 CIDR address 2dec1581 Update VERSIONs to 3.8-rc1 for release. 32c24c24 checkpolicy: add support for xperms in conditional policies 77747a36 checkpolicy: avoid leak of identifier on required attribute beca1ee1 checkpolicy: avoid memory leaks on redeclarations 6f2b689f checkpolicy: Fix MLS users in optional blocks e7bbd67b checkpolicy/fuzz: fix setjmp condition ba7945a2 libsepol: Support nlmsg extended permissions 5421320d libsepol: Rename ioctl xperms structures and functions 84a33fb9 checkpolicy: Check the right bits of an ibpkeycon rule subnet prefix 2eb286bc Release 3.7 e6c99f34 Update VERSIONs to 3.7-rc3 for release. 5f822d33 checkpolicy: reject duplicate nodecon statements 9ef1a835 Update VERSIONs to 3.7-rc2 for release. 804e52b7 checkpolicy: support CIDR notation for nodecon statements 44533801 checkpolicy: perform contiguous check in host byte order 6a223cb1 Update VERSIONs to 3.7-rc1 for release. 82d99136 checkpolicy: drop global policyvers variable 505d1b4c checkpolicy: declare file local variable static f4ffda66 checkpolicy/tests: add test for splitting xperm rule 652e2883 checkpolicy: free complete role_allow_rule on error 04303b5b checkpolicy: drop union stack_item_u 08e55dff checkpolicy: drop never read member f07fc2a7 checkpolicy/fuzz: override YY_FATAL_ERROR 0ffe9747 checkpolicy: include <ctype.h> for isprint(3) a39e474f checkpolicy: update error diagnostic 9f2f9e28 checkpolicy: free identifiers on invalid typebounds 39b3cc51 checkpolicy: handle unprintable token ca77c592 checkpolicy: use YYerror only when available f3b67a84 checkpolicy/fuzz: scan Xen policies f4330d57 checkpolicy: return YYerror on invalid character 0e1e30db checkpolicy: clone level only once b106fad2 checkpolicy/fuzz: drop redundant notdefined check 8c9d2d65 checkpolicy/fuzz: Update check_level() to use notdefined field fe16f586 checkpolicy, libsepol: Fix potential double free of mls_level_t 3dc11169 checkpolicy: misc policy_define.c cleanup 22f7bb8c checkpolicy: avoid assigning garbage values 63207ce8 checkpolicy: free temporary bounds type 4e407ba3 checkpolicy: provide more descriptive error messages 8ad3ce72 checkpolicy: bail out on invalid role 52f187cb checkpolicy: call YYABORT on parse errors 187e7584 checkpolicy: clean expression on error 770ad3ec checkpolicy: check allocation and free memory on error at type definition 8b115c45 checkpolicy: free ebitmap on error b75bf48b checkpolicy: cleanup identifiers on error c2fc48be checkpolicy: cleanup resources on parse error 595c4163 checkpolicy: add libfuzz based fuzzer 90db06c5 libsepol: Use a dynamic buffer in sepol_av_to_string() 97fa708d Update VERSIONs to 3.6 for release. 4d33c675 checkpolicy/dispol: misc updates 89dd980c Add CPPFLAGS to Makefiles 58a444fb checkpolicy/dismod: avoid duplicate initialization and fix module linking 0f5a8dd3 Update VERSIONs to 3.6-rc2 for release. fdb536f3 libsepol: avoid fixed sized format buffer for xperms 1aaf5943 Update VERSIONs to 3.6-rc1 for release. 2b9f21ef checkpolicy: add round-trip tests e6093911 checkpolicy: Remove support for role dominance rules 14f35fde Do not automatically install Russian translations b7e39e50 checkpolicy: Remove the Russian translations 8963492b checkpolicy,libselinux,libsepol,policycoreutils,semodule-utils: update my email 40674f48 Revert "checkpolicy,libsepol: move transition to separate structure in avtab" 6776946d Revert "checkpolicy,libsepol: move filename transitions to avtab" 6e6444a0 Revert "checkpolicy,libsepol: move filename transition rules to avrule" 748614b7 Revert "checkpolicy,libsepol: add prefix/suffix support to kernel policy" 311dc446 Revert "checkpolicy,libsepol: add prefix/suffix support to module policy" c39ebd07 checkpolicy,libsepol: add prefix/suffix support to module policy 1174483d checkpolicy,libsepol: add prefix/suffix support to kernel policy 565d8748 checkpolicy,libsepol: move filename transition rules to avrule e169fe26 checkpolicy,libsepol: move filename transitions to avtab de708edf checkpolicy,libsepol: move transition to separate structure in avtab b3788b9c dismod, dispol: reduce the messages in batch mode 6e077ba7 dismod: print the policy version only in interactive mode 4c069224 checkpolicy/dismod: misc improvements b87724cb checkpolicy: add option to skip checking neverallow rules 666a7dfd dispol: add --actions option for non-interactive use f8a076f1 dispol: handle EOF in user interaction eeb0a751 dispol: delete an unnecessary empty line f78eea5a dispol: add --help option 966de0c8 checkpolicy: Add examples to man pages df0b1929 dismod: add --actions option for non-interactive use d1a9cddf dismod: handle EOF in user interaction 5b1a2f1d dismod: delete an unnecessary empty line 5045368d dismod: add --help option 00728e12 checkpolicy: only set declared permission bits for wildcards c646f390 checkpolicy: reject condition with bool and tunable in expression 2d5f97b8 checkpolicy: drop unused token CLONE b7b32cf4 checkpolicy/dispol: add output functions d213d80f checkpolicy: rename bool identifiers 513fc157 checkpolicy: update cond_expr_t struct member name 6f7b0ee6 checkpolicy: add not-self neverallow support Signed-off-by: Dominick Grift <dominick.grift@defensec.nl> --- package/utils/checkpolicy/Makefile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-)