fapolicyd-selinux-1.3.3-100.el9> M Mv ĉJ4!!%joLne)Ip-Bm5 ']g(releng@rockylinux.org p-Bm5 '] /H<:9"l]-z³7a&qG u̇|kmΣI_Od&sq\@.)"B ~g q"Ä5)RaW^}2^ͶW((HL .BJ6J^h46b#l% /O oM4L&sm_< |Q" %ߎxchV'vL!&-<ɩ6NJrpO{t'3@N Q4>7=sHQP4ΚfeŞA Y 9 5_Me9TOD2$`⻒Ց3c}^8d&~G$|]kK`VbfkUX#;9E\j#V7v|ڐ0h-f ^/)Rzq1?uh-KE;p(yЋxS?Fr㹁1bc018f935a799bcf9c2b87464c3715c2b5254206539ba71ad1f2b72a8db40efbdeb3a527cbb735cd530f62f34f48f2c9c2b8d79Rzqᯠ Yw?>B?d " 4 7Ku{!L        8 (( x8 9 : p =>@GHIXY\]^bdeflt8uDvPr#,06x|Cfapolicyd-selinux1.3.3100.el9Fapolicyd selinuxThe fapolicyd-selinux package contains selinux policy for the fapolicyd daemon.g(!pb-1ec27f3e-4ac6-49d5-9b79-c4c6db2f7940-b-x86-64>Rocky Linux 9.5Rocky Enterprise Software FoundationGPLv3+Rocky Linux Build System (Peridot) Applications/Systemhttp://people.redhat.com/sgrubb/fapolicydlinuxnoarch if /usr/sbin/selinuxenabled; then if [ -e /etc/selinux/config ]; then . /etc/selinux/config fi _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi fi if [ -e /etc/selinux/config ]; then . /etc/selinux/config fi _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i /usr/share/selinux/packages/targeted/fapolicyd.pp.bz2 || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi if [ -e /etc/selinux/config ]; then . /etc/selinux/config fi _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fiif [ $1 -eq 0 ]; then if [ -e /etc/selinux/config ]; then . /etc/selinux/config fi _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r fapolicyd &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi0e;g(,g(-67baf991d7bac297609aefae8e8206f32c1739ad476be520d01d1ac9d43480f0cca48ed111599d1a1169794df53c284229a1755fb51ecf3668fc0eb090eef9ed@rootrootrootrootrootrootfapolicyd-1.3.3-100.el9.src.rpmfapolicyd-selinux      /bin/sh/bin/sh/bin/sh/bin/shfapolicydlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsZstd)selinux-policyselinux-policy-base1.3.3-100.el93.0.4-14.6.0-14.0-15.4.18-138.1.45-3.el938.1.45-3.el94.16.1.3d@d@cױ@b@b@bI@b @a@a`Radovan Sroka - 1.3.3-100Radovan Sroka - 1.3.2-100Radovan Sroka - 1.1.3-104Radovan Sroka - 1.1.3-102Radovan Sroka - 1.1-104Radovan Sroka - 1.1-101Radovan Sroka - 1.1-100Zoltan Fridrich - 1.0.4-101Mohan Boddu - 1.0.3-4Radovan Sroka - 1.0.3-3RHEL 9.5.0 ERRATUM - rebase to fapolicyd-1.3.3 and fapolicyd-selinux-0.7 Resolves: RHEL-36285RHEL 9.3.0 ERRATUM - Rebase fapolicyd to the latest stable version Resolves: RHEL-430 - fapolicyd can leak FDs and never answer request, causing target process to hang forever Resolves: RHEL-621 - RFE: send rule number to fanotify so it gets audited Resolves: RHEL-624 - fapolicyd needs to make sure the FD limit is never reached Resolves: RHEL-623 - fapolicyd still allows execution of a program after "untrusting" it Resolves: RHEL-622 - Default q_size doesn't match manpage's one Resolves: RHEL-627 - fapolicyd-cli --update then mount/umount twice causes fapolicyd daemon to block (state 'D') Resolves: RHEL-817 - Fix broken backwards compatibility backend numbers Resolves: RHEL-730 - SELinux prevents the fapolicyd from reading symlink (cert_t) Resolves: RHEL-816RHEL 9.2.0 ERRATUM - statically linked app can execute untrusted app Resolves: rhbz#2097077 - fapolicyd ineffective with systemd DynamicUser=yes Resolves: rhbz#2136802 - Starting manually fapolicyd while the service is already running breaks the system Resolves: rhbz#2160517 - Cannot execute /usr/libexec/grepconf.sh when falcon-sensor is enabled Resolves: rhbz#2160518 - fapolicyd: Introduce filtering of rpmdb Resolves: RHEL-192RHEL 9.1.0 ERRATUM - rebase fapolicyd to the latest stable vesion Resolves: rhbz#2100041 - fapolicyd gets way too easily killed by OOM killer Resolves: rhbz#2097385 - fapolicyd does not correctly handle SIGHUP Resolves: rhbz#2070655 - Introduce ppid rule attribute Resolves: rhbz#2102558 - fapolicyd often breaks package updates Resolves: rhbz#2111244 - drop libgcrypt in favour of openssl Resolves: rhbz#2111938 - Remove dnf plugin Resolves: rhbz#2113959 - fapolicyd.rules doesn't advertise that using a username/groupname instead of uid/gid also works Resolves: rhbz#2115849RHEL 9.1.0 ERRATUM - CVE-2022-1117 fapolicyd: fapolicyd wrongly prepares ld.so path Resolves: rhbz#2069123 - Faulty handling of static applications Resolves: rhbz#2096457RHEL 9.1.0 ERRATUM - fapolicyd denies access to /usr/lib64/ld-2.28.so Resolves: rhbz#2067493RHEL 9.0.0 ERRATUM - rebase to 1.1 Resolves: rhbz#2032408 - introduce rules.d Resolves: rhbz#2054740 - remove pretrans scriptlet Resolve: rhbz#2051481RHEL 9.0.0 ERRATUM - rebase to 1.0.4 - added rpm_sha256_only option - added trust.d directory - allow file names with whitespaces in trust files - use full paths in trust files Resolves: rhbz#2032408 - fix libc.so getting identified as application/x-executable Resolves: rhbz#2015307 - fix selinux DSP module definition in spec file Resolves: rhbz#2014449- Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688RHEL 9 BETA - SELinux prevents fapolicyd from watch_mount/watch_with_perm on /dev/shm Resolves: rhbz#1932225 Resolves: rhbz#1977731/bin/sh/bin/sh/bin/sh1.3.3-100.el9ipp-fapolicyd.iffapolicyd.pp.bz2fapolicyd/usr/share/selinux/devel/include/contrib//usr/share/selinux/packages/targeted//var/lib/selinux/targeted/active/modules/200/-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64-v2 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpiozstd19x86_64-redhat-linux-gnuSE Linux policy interface source if [ -e /etc/selinux/config ]; then . /etc/selinux/config fi _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi/bin/shutf-825d222d72c608bf7e98fa7b92147ff1f9bc16ccd9764f9ac60d2e44a053eb2c6002a7d1fc1ade37044639d4c26d4f56bbd65db7ce268587dfbfdc8cb439e8d69?(/h͌071081a4165f1b23be020./usr/share/selinux/devel/include/contrib/ipp-fapolicyd.if## for D allowed to transitio/ interface(`',` gen_require( typt,; ') corecmd_search_bin($1) _patt) cer access.canSlib ditoriesvar $1: _permsfilesReadr ManagemPIDpidrunsAll ofru administeanenvironmentroleRcap/t:pro { signal }ps_t tunable_(`deny_ptr; logging opsystemdsswt)fo2728882c30177packs/targeted/pp.bz2BZh91AY&SY ԭAyf{8T@w(Esx ˘7Y c ;`fQ@[4$ Р"l@%(Lhh@ Oi@ѦH)#5OP=4hFUUB!jI)422 @43P ɠ&MS=Cj44fh4AUGM24 d !2h44&L $LzJziBai@ 2  4 bm(54 =A4h4\X :o-s Tl5sEKbŋ B%,X\uu.ρ!FxKbXG43b $ł,ZZ][9P8eD7b m{V1Y I!wQ}]ξ'<ئ]qoç'$Ǧ7@[e1c \[|- j  \Š7K)ntb\tQbvܲ7}P U:WqqF\G:۷n>kq/sOu~y^7} O`|o<+< b}GNgz޿hMmc|9N)IK>k7ݯC4X6QWY[W_Ǭ/N'Ϸ]}aE_߿T_t::\F+M34\r;*t:*KU*+j5յ7}9=oݟ迭?'i׺xɮUCY|CkYX{-XyaAy62USl4IA x~&3F2hq (Q E aS!4 4apIa" :-c9/?|P KJ@Pfn,-j0åecrIhB-HZHS_i(X+LٳJהtت0-ZAB)YIAI` 3{+Ց'0jcF sPC)IF}-n;fI;vφnk/jϪI!eš^.b SM~7sv}C)^$m;fi|&^8ڟxז=,hi;~>|I!VA8f{z_=3[p2aw)yo-vMߍ@1oÄ|Sm߁D&ߑm-S]8i2m61C`&]t\fsgn^4hXweiO3 o-Hnql0 HgQKDp*ˣ-e!eec/F[ee˻/qh.e_vz2 eٗC.g74g̾JIl 5v" 2` iЮ!bw?S[Kٶښ֦W-FLi U223lǨ4fFmyyq<6?X;?`m>^O d'\p1-EZQj-Ec1"c0aF1YyyW_qר|@ܣ-0|w>| gkיǮOA\M~ז|{o~=wϯ~s5= ze^r|9M8Nwa t|eɡAp.D6=g1 ykiӆ<?R٫8鿮Zz㷗sۿNOG_ovc|g#'<gI=M b85j2,^v@aEW@`ʂ-b"CL$T mWrbel[-`Ld̵bx,BIPZ""&EXbd dTqKd-Z[-AB9,Q6r.8KY+:T*("P}&e"_L1cfh5Ss7o8= p'+cmZ'b%ͯ]6򄷘VRuijlmdX\岶u-ͼкy@8C/rx!B14ЌdaI$d#@^>+ApZ" bS4CE5 mYVUVWJhHH P$I"Ȫz}|qy) l 5i6żxI$3 x]9sɷY^F0fWܵvD 9O#|SNmo2U@$mV՗dny2fn6MUUUX1b^.oI9 :T۩1˱m6dLݤ4xdn;OdMY H3vLc.FI*dZy qDž$&*mf7ѽN{3v@w*ؐ1`\Xrnn,n*)I˲X^$ɫ.xZ7M;mq8Uf6s1o1ݥH ]MIwW+k 7j/<qq0>"\}%P-iFHy$AM$R6BH"kLvF @Yaq98ŁJU@.#J^@@(A"B)*)DR}FGyw{ȣ,^i|_+"#6&L2dɓ&Lk6dR p fF\3N48| *:OЉ/ XD8ϔ _.]:t 3r80rpط0a鸍kPF~Z6/ݥ /6Kh'-}vMR%{gϏF~_1~ӿמ]uӮ;"v.w:D[m}2'>C˿S!~n5=}Xg%sF01`p*|׿MBNdxL^=3"yUd'+ë9sfI7xɧN=ibHGbf:[ǟYyP8Q-mE|]1<{@z W1 6 \j,xؚ 8xۯrOitt7ғ-{^ZddgG %IkZptdг11&^8z.<:rOxմضZP~{}E#"a4m&ʼnmKR֕"q#n&XWϰꄎuu[[amI(^6UʅV%0\٥eftc|j$xv省-}}5e-'K7Nl1ޯC A'7NqrAoYֆdgQNN(6;:YH# E0kA$~(R^x:5?Y"}ر<8o2#V h\#V euGtz#W&X"-"rLG֙Q&v Ƙ&{a8V*-LIi#Fc<:}s>'F5&~=ܐ$8:;l_Ij5&56IxUA}"oB]y*[]pb-B@νXG'| ,#j_*)zgͶm@= v ַϝ$`k>i:Q .&)Q^9b lI_hR7Bw=68b>A:~x0R -l-Nݜ$IGvjCӫb{lU&H zЭ UAj]*Ph_ l+-R/}VC{mۢo3Le&9{Ij}>c̮hjp=- F9BN4D=GIgjo^@ڏゎ}f$]pt$.ǨtK槎uN?%}* K|蛼l:Kˤ:.[Vӻ.bfmݲw%'`69u[=FG盌*גh"T1OuF9tI)D˚U[o{_Kס`6oa9 G#zX 6`qm&6`qY)*x0'( %rG~mGN{MgtT$ HF]'|[vVe\8{\wpYͨV 5ͺsU9]iOm"UPEr8ImGujyXwޣQޝ;ýFzwR]g{j:[;#Q}dޝm{dn5NF*j*q>J;#Q{>G߮ǬS=U}NWs'|).䝧C{B^9yw2SdqTEpܩpG%&Gk@}swcz{#{F {ނ:ujC`j5 6FFQ0m50 "5|VZC5GG7>ooo=/gmX7\[Tbo+N2Sg6\ԓyq^x>95Kw\9㙭K{K{Q9.7U%c#~XHiQhA5h$Dj/I &Fm0j aF@9mF煦YPX Qng/PK|̞.ZF'w9f#2)Ϫ;䲁WH(8g_rjFn5Xw\UN UR{7U_+D|θUqV6ld0R+0@B[/@;KB _ؠ"+yPdY{,]&@bZZ,NØ& Xbl,DP",l` KKKehZ[,XXF H*G.v.,K"cBS ;bG6 enj>vׁ#R. #&%&h*$hhIQZ5*H#Go V 5u3e~ jha~#gIݚϥPH y#e:d1#Fl<ule Z{feT ŽoL2Ijps̸ZOq6D~n.fΫ尧L2<+wn.cwf'70<6$1FUl~k)1^je}[6WtnI }C{ٿsNcY$UlX˾iﮮI~3]'O?w]֭*N <,w+IGP<t{ayN");2Ҁ LQ8K &.8maL"bHYMR f: Gl1wV8 I,4b!D1Ѝ 6%@lֹNW`= D-͸ '1Y xC~.nw{=,bg':IwYPMa-!@D ʐKr @!109q)8_!aU`E)2_ݛMonJ۴$ QdN$ Tcg*lm,%m F0Lw!&4$HYe u\ܰRVKKy5Җ7ml ċxe"-& -`Ÿmhmt(THY1y2w7nCSEiŹ+,2Vd!pN8 0slU1@* Eg6Qcu{tv:>JC>)v/ߓvƼս;PlPgN8:&1mr^Na] O/^Ua 3`6L9TZcGLcc8v>.&!=7az5 ~mN^ 9X6ϖ4Ǩ|+et/K48zk醛f|KL2m0E6K! <I F]@/ fBE[ZV$[`jP_NiQ%-̠9H0xM.mqj,ɓT,qI0MXC.7䘕Wڹ;;'Io To(@lZXFeyM0b0Ȟy2On^h~ D=R"w4yqJO/6z7TA:o' \ Q$eY=Q1P>ت\ӄ;,!Rk읝c}~iݩ)i2hN κyˌ1FLeezŠnmI W2^0o)i4c} {~Fc.rw[z+>^_yhdNxt7ë] sWqsgI1oD=6rmmq]P;P,l0Os7ʭǛ!1$e]3C_NV^0,',,FGHywN\o6&Ԃ#2dwRde@iug-'Nn|+?~k'g'>.y$dvut|Ye E&AyMO݈1mz<\֠\a@`'en:PL@d۴LJXX]LWv5%P#"1TW"PN uCM{8rjx+;V+#z_1fmxy8ʳWV>ٙ7׎MX<|t[%N3; ȱԈi2/Fv^U9bjn,vK46՛GFB!4%k22 @a$o/vf&/XxقH؎ NI)6IC+d@ԦBj^T&$.]- -əUuV؍"IP7g<㞚"L2ha|cmD#Tɐ, E9=;N D @BDsp!(F' I !U.״ye 5Rb%XZg%)޳#Mُu7:gojmɓ7 QDcO+v9MrKŠ6Zxq0$"ІaVJ2/5*`Z4"Vf]NQ@>ViCZF΁3B[ռ t%Flaߧ[=Hڊwac%e5Ǚb3G/+ePe76䎆k* (tU'Tѝjch6~ UpH_,Id?G3 ]]Q@Bɚ@&Hyh`kJOer~6gNjo"%Ά0uwZy 9&0JZ