| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: selinux-policy-mls | Distribution: AlmaLinux |
| Version: 40.13.13 | Vendor: AlmaLinux |
| Release: 1.el10 | Build date: Sat Dec 7 17:59:19 2024 |
| Group: Unspecified | Build host: s390x-builder02.almalinux.org |
| Size: 11039618 | Source RPM: selinux-policy-40.13.13-1.el10.src.rpm |
| Packager: AlmaLinux Packaging Team <packager@almalinux.org> | |
| Url: https://github.com/fedora-selinux/selinux-policy | |
| Summary: SELinux MLS policy | |
SELinux MLS (Multi Level Security) policy package.
GPL-2.0-or-later
* Tue Nov 12 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.13-1
- Revert "Allow unconfined_t execute kmod in the kmod domain"
Resolves: RHEL-65190
- Add policy for /usr/libexec/samba/samba-bgqd
Resolves: RHEL-64908
- Label samba certificates with samba_cert_t
Resolves: RHEL-64908
- Label /usr/bin/samba-gpupdate with samba_gpupdate_exec_t
Resolves: RHEL-64908
- Allow rpcd read network sysctls
Resolves: RHEL-64737
- Label all semanage store files in /etc as semanage_store_t
Resolves: RHEL-65864
* Tue Oct 29 2024 Troy Dawson <tdawson@redhat.com> - 40.13.12-2
- Bump release for October 2024 mass rebuild:
Resolves: RHEL-64018
* Thu Oct 24 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.12-1
- Dontaudit subscription manager setfscreate and read file contexts
Resolves: RHEL-58009
- Allow the sysadm user use the secretmem API
Resolves: RHEL-40953
- Allow sudodomain list files in /var
Resolves: RHEL-58068
- Allow gnome-remote-desktop watch /etc directory
Resolves: RHEL-35877
- Allow journalctl connect to systemd-userdbd over a unix socket
Resolves: RHEL-58072
- systemd: allow sys_admin capability for systemd_notify_t
Resolves: RHEL-58072
- Allow some confined users send to lldpad over a unix dgram socket
Resolves: RHEL-61634
- Allow lldpad send to sysadm_t over a unix dgram socket
Resolves: RHEL-61634
- Allow lldpd connect to systemd-machined over a unix socket
Resolves: RHEL-61634
* Wed Oct 23 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.11-1
- Allow ping_t read network sysctls
Resolves: RHEL-54299
- Label /usr/lib/node_modules/npm/bin with bin_t
Resolves: RHEL-56350
- Label /run/sssd with sssd_var_run_t
Resolves: RHEL-57065
- Allow virtqemud read virtd_t files
Resolves: RHEL-57713
- Allow wdmd read hardware state information
Resolves: RHEL-57982
- Allow wdmd list the contents of the sysfs directories
Resolves: RHEL-57982
- Label /etc/sysctl.d and /run/sysctl.d with system_conf_t
Resolves: RHEL-58380
- Allow dirsrv read network sysctls
Resolves: RHEL-58381
- Allow lldpad create and use netlink_generic_socket
Resolves: RHEL-61634
- Allow unconfined_t execute kmod in the kmod domain
Resolves: RHEL-61755
- Confine the pcm service
Resolves: RHEL-52838
- Allow iio-sensor-proxy the bpf capability
Resolves: RHEL-62355
- Confine iio-sensor-proxy
Resolves: RHEL-62355
* Wed Oct 16 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.10-1
- Confine gnome-remote-desktop
Resolves: RHEL-35877
- Allow virtqemud get attributes of a tmpfs filesystem
Resolves: RHEL-40855
- Allow virtqemud get attributes of cifs files
Resolves: RHEL-40855
- Allow virtqemud get attributes of filesystems with extended attributes
Resolves: RHEL-39668
- Allow virtqemud get attributes of NFS filesystems
Resolves: RHEL-40855
- Add support for secretmem anon inode
Resolves: RHEL-40953
- Allow systemd-sleep read raw disk data
Resolves: RHEL-49600
- Allow systemd-hwdb send messages to kernel unix datagram sockets
Resolves: RHEL-50810
- Label /run/modprobe.d with modules_conf_t
Resolves: RHEL-54591
- Allow setsebool_t relabel selinux data files
Resolves: RHEL-55412
- Don't audit crontab_domain write attempts to user home
Resolves: RHEL-56349
- Differentiate between staff and sysadm when executing crontab with sudo
Resolves: RHEL-56349
- Add crontab_admin_domtrans interface
Resolves: RHEL-56349
- Add crontab_domtrans interface
Resolves: RHEL-56349
- Allow boothd connect to kernel over a unix socket
Resolves: RHEL-58060
- Fix label of pseudoterminals created from sudodomain
Resolves: RHEL-58068
- systemd: allow systemd_notify_t to send data to kernel_t datagram sockets
Resolves: RHEL-58072
- Allow rsyslog read systemd-logind session files
Resolves: RHEL-40961
- Label /dev/mmcblk0rpmb character device with removable_device_t
Resolves: RHEL-55265
- Label /dev/hfi1_[0-9]+ devices
Resolves: RHEL-62836
- Label /dev/papr-sysparm and /dev/papr-vpd
Resolves: RHEL-56908
- Support SGX devices
Resolves: RHEL-62354
- Suppress semodule's stderr
Resolves: RHEL-59192
* Mon Aug 26 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.9-1
- Allow virtqemud relabelfrom also for file and sock_file
Resolves: RHEL-49763
- Allow virtqemud relabel user tmp files and socket files
Resolves: RHEL-49763
- Update virtqemud policy for libguestfs usage
Resolves: RHEL-49763
- Label /run/libvirt/qemu/channel with virtqemud_var_run_t
Resolves: RHEL-47274
* Tue Aug 13 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.8-1
- Add virt_create_log() and virt_write_log() interfaces
Resolves: RHEL-47274
- Update libvirt policy
Resolves: RHEL-45464
Resolves: RHEL-49763
- Allow svirt_tcg_t map svirt_image_t files
Resolves: RHEL-47274
- Allow svirt_tcg_t read vm sysctls
Resolves: RHEL-47274
- Additional updates stalld policy for bpf usage
Resolves: RHEL-50356
* Thu Aug 08 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.7-1
- Add the swtpm.if interface file for interactions with other domains
Resolves: RHEL-47274
- Allow virtproxyd create and use its private tmp files
Resolves: RHEL-40499
- Allow virtproxyd read network state
Resolves: RHEL-40499
- Allow virtqemud domain transition on swtpm execution
Resolves: RHEL-47274
Resolves: RHEL-49763
- Allow virtqemud relabel virt_var_run_t directories
Resolves: RHEL-47274
Resolves: RHEL-45464
Resolves: RHEL-49763
- Allow virtqemud domain transition on passt execution
Resolves: RHEL-45464
- Allow virt_driver_domain create and use log files in /var/log
Resolves: RHEL-40239
- Allow virt_driver_domain connect to systemd-userdbd over a unix socket
Resolves: RHEL-44932
Resolves: RHEL-44898
- Update stalld policy for bpf usage
Resolves: RHEL-50356
- Allow boothd connect to systemd-userdbd over a unix socket
Resolves: RHEL-45907
- Allow linuxptp configure phc2sys and chronyd over a unix domain socket
Resolves: RHEL-46011
- Allow systemd-machined manage runtime sockets
Resolves: RHEL-49567
- Allow ip command write to ipsec's logs
Resolves: RHEL-41222
- Allow init_t nnp domain transition to firewalld_t
Resolves: RHEL-52481
- Update qatlib policy for v24.02 with new features
Resolves: RHEL-50377
- Allow postfix_domain map postfix_etc_t files
Resolves: RHEL-46327
* Thu Jul 25 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.6-1
- Allow virtnodedevd run udev with a domain transition
Resolves: RHEL-39890
- Allow virtnodedev_t create and use virtnodedev_lock_t
Resolves: RHEL-39890
- Allow svirt attach_queue to a virtqemud tun_socket
Resolves: RHEL-44312
- Label /run/systemd/machine with systemd_machined_var_run_t
Resolves: RHEL-49567
- Allow to create and delete socket files created by rhsm.service
* Tue Jul 16 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.5-1
- Allow to create and delete socket files created by rhsm.service
Resolves: RHEL-40857
- Allow svirt read virtqemud fifo files
Resolves: RHEL-40350
- Allow virt_dbus_t connect to virtqemud_t over a unix stream socket
Resolves: RHEL-37822
- Allow virtqemud read virt-dbus process state
Resolves: RHEL-37822
- Allow virtqemud run ssh client with a transition
Resolves: RHEL-43215
- Allow virtnetworkd exec shell when virt_hooks_unconfined is on
Resolves: RHEL-41168
- Allow NetworkManager the sys_ptrace capability in user namespace
Resolves: RHEL-46717
- Update keyutils policy
Resolves: RHEL-38920
- Allow ip the setexec permission
Resolves: RHEL-41182
* Fri Jun 28 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.4-1
- Confine libvirt-dbus
Resolves: RHEL-37822
- Allow sssd create and use io_uring
Resolves: RHEL-43448
- Allow virtqemud the kill capability in user namespace
Resolves: RHEL-44996
- Allow login_userdomain execute systemd-tmpfiles in the caller domain
Resolves: RHEL-44191
- Allow virtqemud read vm sysctls
Resolves: RHEL-40938
- Allow svirt_t read vm sysctls
Resolves: RHEL-40938
- Allow rshim get options of the netlink class for KOBJECT_UEVENT family
Resolves: RHEL-40859
- Allow systemd-hostnamed read the vsock device
Resolves: RHEL-45309
- Allow systemd (PID 1) manage systemd conf files
Resolves: RHEL-45304
- Allow journald read systemd config files and directories
Resolves: RHEL-45304
- Allow systemd_domain read systemd_conf_t dirs
Resolves: RHEL-45304
- Label systemd configuration files with systemd_conf_t
Resolves: RHEL-45304
- Allow dhcpcd the kill capability
Resolves: RHEL-43417
- Add support for libvirt hooks
Resolves: RHEL-41168
* Mon Jun 24 2024 Troy Dawson <tdawson@redhat.com> - 40.13.3-2
- Bump release for June 2024 mass rebuild
* Tue Jun 18 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.3-1
- Allow virtqemud manage nfs files when virt_use_nfs boolean is on
Resolves: RHEL-40205
- Allow virt_driver_domain read files labeled unconfined_t
Resolves: RHEL-40262
- Allow virt_driver_domain dbus chat with policykit
Resolves: RHEL-40346
- Escape "interface" as a file name in a virt filetrans pattern
Resolves: RHEL-34769
- Allow setroubleshootd get attributes of all sysctls
Resolves: RHEL-40923
- Allow qemu-ga read vm sysctls
Resolves: RHEL-40829
- Allow sbd to trace processes in user namespace
Resolves: RHEL-39989
- Allow request-key execute scripts
Resolves: RHEL-38920
- Update policy for haproxyd
Resolves: RHEL-40877
* Fri Jun 07 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.2-1
- Allow all domains read and write z90crypt device
Resolves: RHEL-28539
- Allow dhcpc read /run/netns files
Resolves: RHEL-39510
- Allow bootupd search efivarfs dirs
Resolves: RHEL-39514
* Fri May 17 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13.1-1
- Allow logwatch read logind sessions files
Resolves: RHEL-30441
- Allow sulogin relabel tty1
Resolves: RHEL-30440
- Dontaudit sulogin the checkpoint_restore capability
Resolves: RHEL-30440
- Allow postfix smtpd map aliases file
Resolves: RHEL-35544
- Ensure dbus communication is allowed bidirectionally
Resolves: RHEL-35783
- Allow various services read and write z90crypt device
Resolves: RHEL-28539
- Allow dhcpcd use unix_stream_socket
Resolves: RHEL-33081
- Allow xdm_t to watch and watch_reads mount_var_run_t
Resolves: RHEL-36073
- Allow plymouthd log during shutdown
Resolves: RHEL-30455
- Update rpm configuration for the /var/run equivalency change
Resolves: RHEL-36094
* Mon Feb 12 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13-1
- Only allow confined user domains to login locally without unconfined_login
- Add userdom_spec_domtrans_confined_admin_users interface
- Only allow admindomain to execute shell via ssh with ssh_sysadm_login
- Add userdom_spec_domtrans_admin_users interface
- Move ssh dyntrans to unconfined inside unconfined_login tunable policy
- Update ssh_role_template() for user ssh-agent type
- Allow init to inherit system DBus file descriptors
- Allow init to inherit fds from syslogd
- Allow any domain to inherit fds from rpm-ostree
- Update afterburn policy
- Allow init_t nnp domain transition to abrtd_t
* Tue Feb 06 2024 Zdenek Pytela <zpytela@redhat.com> - 40.12-1
- Rename all /var/lock file context entries to /run/lock
- Rename all /var/run file context entries to /run
- Invert the "/var/run = /run" equivalency
* Mon Feb 05 2024 Zdenek Pytela <zpytela@redhat.com> - 40.11-1
- Replace init domtrans rule for confined users to allow exec init
- Update dbus_role_template() to allow user service status
- Allow polkit status all systemd services
- Allow setroubleshootd create and use inherited io_uring
- Allow load_policy read and write generic ptys
- Allow gpg manage rpm cache
- Allow login_userdomain name_bind to howl and xmsg udp ports
- Allow rules for confined users logged in plasma
- Label /dev/iommu with iommu_device_t
- Remove duplicate file context entries in /run
- Dontaudit getty and plymouth the checkpoint_restore capability
- Allow su domains write login records
- Revert "Allow su domains write login records"
- Allow login_userdomain delete session dbusd tmp socket files
- Allow unix dgram sendto between exim processes
- Allow su domains write login records
- Allow smbd_t to watch user_home_dir_t if samba_enable_home_dirs is on
* Wed Jan 24 2024 Zdenek Pytela <zpytela@redhat.com> - 40.10-1
- Allow chronyd-restricted read chronyd key files
- Allow conntrackd_t to use bpf capability2
- Allow systemd-networkd manage its runtime socket files
- Allow init_t nnp domain transition to colord_t
- Allow polkit status systemd services
- nova: Fix duplicate declarations
- Allow httpd work with PrivateTmp
- Add interfaces for watching and reading ifconfig_var_run_t
- Allow collectd read raw fixed disk device
- Allow collectd read udev pid files
- Set correct label on /etc/pki/pki-tomcat/kra
- Allow systemd domains watch system dbus pid socket files
- Allow certmonger read network sysctls
- Allow mdadm list stratisd data directories
- Allow syslog to run unconfined scripts conditionally
- Allow syslogd_t nnp_transition to syslogd_unconfined_script_t
- Allow qatlib set attributes of vfio device files
* Tue Jan 09 2024 Zdenek Pytela <zpytela@redhat.com> - 40.9-1
- Allow systemd-sleep set attributes of efivarfs files
- Allow samba-dcerpcd read public files
- Allow spamd_update_t the sys_ptrace capability in user namespace
- Allow bluetooth devices work with alsa
- Allow alsa get attributes filesystems with extended attributes
* Tue Jan 02 2024 Yaakov Selkowitz <yselkowi@redhat.com> - 40.8-2
- Limit %selinux_requires to version, not release
* Thu Dec 21 2023 Zdenek Pytela <zpytela@redhat.com> - 40.8-1
- Allow hypervkvp_t write access to NetworkManager_etc_rw_t
- Add interface for write-only access to NetworkManager rw conf
- Allow systemd-sleep send a message to syslog over a unix dgram socket
- Allow init create and use netlink netfilter socket
- Allow qatlib load kernel modules
- Allow qatlib run lspci
- Allow qatlib manage its private runtime socket files
- Allow qatlib read/write vfio devices
- Label /etc/redis.conf with redis_conf_t
- Remove the lockdown-class rules from the policy
- Allow init read all non-security socket files
- Replace redundant dnsmasq pattern macros
- Remove unneeded symlink perms in dnsmasq.if
- Add additions to dnsmasq interface
- Allow nvme_stas_t create and use netlink kobject uevent socket
- Allow collectd connect to statsd port
- Allow keepalived_t to use sys_ptrace of cap_userns
- Allow dovecot_auth_t connect to postgresql using UNIX socket
* Wed Dec 13 2023 Zdenek Pytela <zpytela@redhat.com> - 40.7-1
- Make named_zone_t and named_var_run_t a part of the mountpoint attribute
- Allow sysadm execute traceroute in sysadm_t domain using sudo
- Allow sysadm execute tcpdump in sysadm_t domain using sudo
- Allow opafm search nfs directories
- Add support for syslogd unconfined scripts
- Allow gpsd use /dev/gnss devices
- Allow gpg read rpm cache
- Allow virtqemud additional permissions
- Allow virtqemud manage its private lock files
- Allow virtqemud use the io_uring api
- Allow ddclient send e-mail notifications
- Allow postfix_master_t map postfix data files
- Allow init create and use vsock sockets
- Allow thumb_t append to init unix domain stream sockets
- Label /dev/vas with vas_device_t
- Change domain_kernel_load_modules boolean to true
- Create interface selinux_watch_config and add it to SELinux users
* Tue Nov 28 2023 Zdenek Pytela <zpytela@redhat.com> - 40.6-1
- Add afterburn to modules-targeted-contrib.conf
- Update cifs interfaces to include fs_search_auto_mountpoints()
- Allow sudodomain read var auth files
- Allow spamd_update_t read hardware state information
- Allow virtnetworkd domain transition on tc command execution
- Allow sendmail MTA connect to sendmail LDA
- Allow auditd read all domains process state
- Allow rsync read network sysctls
- Add dhcpcd bpf capability to run bpf programs
- Dontaudit systemd-hwdb dac_override capability
- Allow systemd-sleep create efivarfs files
* Tue Nov 14 2023 Zdenek Pytela <zpytela@redhat.com> - 40.5-1
- Allow map xserver_tmpfs_t files when xserver_clients_write_xshm is on
- Allow graphical applications work in Wayland
- Allow kdump work with PrivateTmp
- Allow dovecot-auth work with PrivateTmp
- Allow nfsd get attributes of all filesystems
- Allow unconfined_domain_type use io_uring cmd on domain
- ci: Only run Rawhide revdeps tests on the rawhide branch
- Label /var/run/auditd.state as auditd_var_run_t
- Allow fido-device-onboard (FDO) read the crack database
- Allow ip an explicit domain transition to other domains
- Label /usr/libexec/selinux/selinux-autorelabel with semanage_exec_t
- Allow winbind_rpcd_t processes access when samba_export_all_* is on
- Enable NetworkManager and dhclient to use initramfs-configured DHCP connection
- Allow ntp to bind and connect to ntske port.
- Allow system_mail_t manage exim spool files and dirs
- Dontaudit keepalived setattr on keepalived_unconfined_script_exec_t
- Label /run/pcsd.socket with cluster_var_run_t
- ci: Run cockpit tests in PRs
* Thu Oct 19 2023 Zdenek Pytela <zpytela@redhat.com> - 40.4-1
- Add map_read map_write to kernel_prog_run_bpf
- Allow systemd-fstab-generator read all symlinks
- Allow systemd-fstab-generator the dac_override capability
- Allow rpcbind read network sysctls
- Support using systemd containers
- Allow sysadm_t to connect to iscsid using a unix domain stream socket
- Add policy for coreos installer
- Add coreos_installer to modules-targeted-contrib.conf
* Tue Oct 17 2023 Zdenek Pytela <zpytela@redhat.com> - 40.3-1
- Add policy for nvme-stas
- Confine systemd fstab,sysv,rc-local
- Label /etc/aliases.lmdb with etc_aliases_t
- Create policy for afterburn
- Add nvme_stas to modules-targeted-contrib.conf
- Add plans/tests.fmf
* Tue Oct 10 2023 Zdenek Pytela <zpytela@redhat.com> - 40.2-1
- Add the virt_supplementary module to modules-targeted-contrib.conf
- Make new virt drivers permissive
- Split virt policy, introduce virt_supplementary module
- Allow apcupsd cgi scripts read /sys
- Merge pull request #1893 from WOnder93/more-early-boot-overlay-fixes
- Allow kernel_t to manage and relabel all files
- Add missing optional_policy() to files_relabel_all_files()
* Tue Oct 03 2023 Zdenek Pytela <zpytela@redhat.com> - 40.1-1
- Allow named and ndc use the io_uring api
- Deprecate common_anon_inode_perms usage
- Improve default file context(None) of /var/lib/authselect/backups
- Allow udev_t to search all directories with a filesystem type
- Implement proper anon_inode support
- Allow targetd write to the syslog pid sock_file
- Add ipa_pki_retrieve_key_exec() interface
- Allow kdumpctl_t to list all directories with a filesystem type
- Allow udev additional permissions
- Allow udev load kernel module
- Allow sysadm_t to mmap modules_object_t files
- Add the unconfined_read_files() and unconfined_list_dirs() interfaces
- Set default file context of HOME_DIR/tmp/.* to <<none>>
- Allow kernel_generic_helper_t to execute mount(1)
* Fri Sep 29 2023 Zdenek Pytela <zpytela@redhat.com> - 38.29-1
- Allow sssd send SIGKILL to passkey_child running in ipa_otpd_t
- Allow systemd-localed create Xserver config dirs
- Allow sssd read symlinks in /etc/sssd
- Label /dev/gnss[0-9] with gnss_device_t
- Allow systemd-sleep read/write efivarfs variables
- ci: Fix version number of packit generated srpms
- Dontaudit rhsmcertd write memory device
- Allow ssh_agent_type create a sockfile in /run/user/USERID
- Set default file context of /var/lib/authselect/backups to <<none>>
- Allow prosody read network sysctls
- Allow cupsd_t to use bpf capability
* Fri Sep 15 2023 Zdenek Pytela <zpytela@redhat.com> - 38.28-1
- Allow sssd domain transition on passkey_child execution conditionally
- Allow login_userdomain watch lnk_files in /usr
- Allow login_userdomain watch video4linux devices
- Change systemd-network-generator transition to include class file
- Revert "Change file transition for systemd-network-generator"
- Allow nm-dispatcher winbind plugin read/write samba var files
- Allow systemd-networkd write to cgroup files
- Allow kdump create and use its memfd: objects
* Thu Aug 31 2023 Zdenek Pytela <zpytela@redhat.com> - 38.27-1
- Allow fedora-third-party get generic filesystem attributes
- Allow sssd use usb devices conditionally
- Update policy for qatlib
- Allow ssh_agent_type manage generic cache home files
* Thu Aug 24 2023 Zdenek Pytela <zpytela@redhat.com> - 38.26-1
- Change file transition for systemd-network-generator
- Additional support for gnome-initial-setup
- Update gnome-initial-setup policy for geoclue
- Allow openconnect vpn open vhost net device
- Allow cifs.upcall to connect to SSSD also through the /var/run socket
- Grant cifs.upcall more required capabilities
- Allow xenstored map xenfs files
- Update policy for fdo
- Allow keepalived watch var_run dirs
- Allow svirt to rw /dev/udmabuf
- Allow qatlib to modify hardware state information.
- Allow key.dns_resolve connect to avahi over a unix stream socket
- Allow key.dns_resolve create and use unix datagram socket
- Use quay.io as the container image source for CI
* Fri Aug 11 2023 Zdenek Pytela <zpytela@redhat.com> - 38.25-1
- ci: Move srpm/rpm build to packit
- .copr: Avoid subshell and changing directory
- Allow gpsd, oddjob and oddjob_mkhomedir_t write user_tty_device_t chr_file
- Label /usr/libexec/openssh/ssh-pkcs11-helper with ssh_agent_exec_t
- Make insights_client_t an unconfined domain
- Allow insights-client manage user temporary files
- Allow insights-client create all rpm logs with a correct label
- Allow insights-client manage generic logs
- Allow cloud_init create dhclient var files and init_t manage net_conf_t
- Allow insights-client read and write cluster tmpfs files
- Allow ipsec read nsfs files
- Make tuned work with mls policy
- Remove nsplugin_role from mozilla.if
- allow mon_procd_t self:cap_userns sys_ptrace
- Allow pdns name_bind and name_connect all ports
- Set the MLS range of fsdaemon_t to s0 - mls_systemhigh
- ci: Move to actions/checkout@v3 version
- .copr: Replace chown call with standard workflow safe.directory setting
- .copr: Enable `set -u` for robustness
- .copr: Simplify root directory variable
* Fri Aug 04 2023 Zdenek Pytela <zpytela@redhat.com> - 38.24-1
- Allow rhsmcertd dbus chat with policykit
- Allow polkitd execute pkla-check-authorization with nnp transition
- Allow user_u and staff_u get attributes of non-security dirs
- Allow unconfined user filetrans chrome_sandbox_home_t
- Allow svnserve execute postdrop with a transition
- Do not make postfix_postdrop_t type an MTA executable file
- Allow samba-dcerpc service manage samba tmp files
- Add use_nfs_home_dirs boolean for mozilla_plugin
- Fix labeling for no-stub-resolv.conf
* Wed Aug 02 2023 Zdenek Pytela <zpytela@redhat.com> - 38.23-1
- Revert "Allow winbind-rpcd use its private tmp files"
- Allow upsmon execute upsmon via a helper script
- Allow openconnect vpn read/write inherited vhost net device
- Allow winbind-rpcd use its private tmp files
- Update samba-dcerpc policy for printing
- Allow gpsd,oddjob,oddjob_mkhomedir rw user domain pty
- Allow nscd watch system db dirs
- Allow qatlib to read sssd public files
- Allow fedora-third-party read /sys and proc
- Allow systemd-gpt-generator mount a tmpfs filesystem
- Allow journald write to cgroup files
- Allow rpc.mountd read network sysctls
- Allow blueman read the contents of the sysfs filesystem
- Allow logrotate_t to map generic files in /etc
- Boolean: Allow virt_qemu_ga create ssh directory
* Tue Jul 25 2023 Zdenek Pytela <zpytela@redhat.com> - 38.22-1
- Allow systemd-network-generator send system log messages
- Dontaudit the execute permission on sock_file globally
- Allow fsadm_t the file mounton permission
- Allow named and ndc the io_uring sqpoll permission
- Allow sssd io_uring sqpoll permission
- Fix location for /run/nsd
- Allow qemu-ga get fixed disk devices attributes
- Update bitlbee policy
- Label /usr/sbin/sos with sosreport_exec_t
- Update policy for the sblim-sfcb service
- Add the files_getattr_non_auth_dirs() interface
- Fix the CI to work with DNF5
* Sat Jul 22 2023 Fedora Release Engineering <releng@fedoraproject.org> - 38.21-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jul 13 2023 Zdenek Pytela <zpytela@redhat.com> - 38.21-1
- Make systemd_tmpfiles_t MLS trusted for lowering the level of files
- Revert "Allow insights client map cache_home_t"
- Allow nfsidmapd connect to systemd-machined over a unix socket
- Allow snapperd connect to kernel over a unix domain stream socket
- Allow virt_qemu_ga_t create .ssh dir with correct label
- Allow targetd read network sysctls
- Set the abrt_handle_event boolean to on
- Permit kernel_t to change the user identity in object contexts
- Allow insights client map cache_home_t
- Label /usr/sbin/mariadbd with mysqld_exec_t
- Trim changelog so that it starts at F37 time
- Define equivalency for /run/systemd/generator.early
* Thu Jun 29 2023 Zdenek Pytela <zpytela@redhat.com> - 38.20-1
- Allow httpd tcp connect to redis port conditionally
- Label only /usr/sbin/ripd and ripngd with zebra_exec_t
- Dontaudit aide the execmem permission
- Remove permissive from fdo
- Allow sa-update manage spamc home files
- Allow sa-update connect to systemlog services
- Label /usr/lib/systemd/system/mimedefang.service with antivirus_unit_file_t
- Allow nsd_crond_t write nsd_var_run_t & connectto nsd_t
- Allow bootupd search EFI directory
* Tue Jun 27 2023 Zdenek Pytela <zpytela@redhat.com> - 38.19-1
- Change init_audit_control default value to true
- Allow nfsidmapd connect to systemd-userdbd with a unix socket
- Add the qatlib module
- Add the fdo module
- Add the bootupd module
- Set default ports for keylime policy
- Create policy for qatlib
- Add policy for FIDO Device Onboard
- Add policy for bootupd
- Add the qatlib module
- Add the fdo module
- Add the bootupd module
* Sun Jun 25 2023 Zdenek Pytela <zpytela@redhat.com> - 38.18-1
- Add support for kafs-dns requested by keyutils
- Allow insights-client execmem
- Add support for chronyd-restricted
- Add init_explicit_domain() interface
- Allow fsadm_t to get attributes of cgroup filesystems
- Add list_dir_perms to kerberos_read_keytab
- Label /var/run/tmpfiles.d/static-nodes.conf with kmod_var_run_t
- Allow sendmail manage its runtime files
- Allow keyutils_dns_resolver_exec_t be an entrypoint
- Allow collectd_t read network state symlinks
- Revert "Allow collectd_t read proc_net link files"
- Allow nfsd_t to list exports_t dirs
- Allow cupsd dbus chat with xdm
- Allow haproxy read hardware state information
- Add the kafs module
* Thu Jun 15 2023 Zdenek Pytela <zpytela@redhat.com> - 38.17-1
- Label /dev/userfaultfd with userfaultfd_t
- Allow blueman send general signals to unprivileged user domains
- Allow dkim-milter domain transition to sendmail
- Label /usr/sbin/cifs.idmap with cifs_helper_exec_t
- Allow cifs-helper read sssd kerberos configuration files
- Allow rpm_t sys_admin capability
- Allow dovecot_deliver_t create/map dovecot_spool_t dir/file
- Allow collectd_t read proc_net link files
- Allow insights-client getsession process permission
- Allow insights-client work with pipe and socket tmp files
- Allow insights-client map generic log files
- Update cyrus_stream_connect() to use sockets in /run
- Allow keyutils-dns-resolver read/view kernel key ring
- Label /var/log/kdump.log with kdump_log_t
* Fri Jun 09 2023 Zdenek Pytela <zpytela@redhat.com> - 38.16-1
- Add support for the systemd-pstore service
- Allow kdumpctl_t to execmem
- Update sendmail policy module for opensmtpd
- Allow nagios-mail-plugin exec postfix master
- Allow subscription-manager execute ip
- Allow ssh client connect with a user dbus instance
- Add support for ksshaskpass
- Allow rhsmcertd file transition in /run also for socket files
- Allow keyutils_dns_resolver_t execute keyutils_dns_resolver_exec_t
- Allow plymouthd read/write X server miscellaneous devices
- Allow systemd-sleep read udev pid files
- Allow exim read network sysctls
- Allow sendmail request load module
- Allow named map its conf files
- Allow squid map its cache files
- Allow NetworkManager_dispatcher_dhclient_t to execute shells without a domain transition
* Tue May 30 2023 Zdenek Pytela <zpytela@redhat.com> - 38.15-1
- Update policy for systemd-sleep
- Remove permissive domain for rshim_t
- Remove permissive domain for mptcpd_t
- Allow systemd-bootchartd the sys_ptrace userns capability
- Allow sysadm_t read nsfs files
- Allow sysadm_t run kernel bpf programs
- Update ssh_role_template for ssh-agent
- Update ssh_role_template to allow read/write unallocated ttys
- Add the booth module to modules.conf
- Allow firewalld rw ica_tmpfs_t files
* Fri May 26 2023 Zdenek Pytela <zpytela@redhat.com> - 38.14-1
- Remove permissive domain for cifs_helper_t
- Update the cifs-helper policy
- Replace cifsutils_helper_domtrans() with keyutils_request_domtrans_to()
- Update pkcsslotd policy for sandboxing
- Allow abrt_t read kernel persistent storage files
- Dontaudit targetd search httpd config dirs
- Allow init_t nnp domain transition to policykit_t
- Allow rpcd_lsad setcap and use generic ptys
- Allow samba-dcerpcd connect to systemd_machined over a unix socket
- Allow wireguard to rw network sysctls
- Add policy for boothd
- Allow kernel to manage its own BPF objects
- Label /usr/lib/systemd/system/proftpd.* & vsftpd.* with ftpd_unit_file_t
* Mon May 22 2023 Zdenek Pytela <zpytela@redhat.com> - 38.13-1
- Add initial policy for cifs-helper
- Label key.dns_resolver with keyutils_dns_resolver_exec_t
- Allow unconfined_service_t to create .gnupg labeled as gpg_secret_t
- Allow some systemd services write to cgroup files
- Allow NetworkManager_dispatcher_dhclient_t to read the DHCP configuration files
- Allow systemd resolved to bind to arbitrary nodes
- Allow plymouthd_t bpf capability to run bpf programs
- Allow cupsd to create samba_var_t files
- Allow rhsmcert request the kernel to load a module
- Allow virsh name_connect virt_port_t
- Allow certmonger manage cluster library files
- Allow plymouthd read init process state
- Add chromium_sandbox_t setcap capability
- Allow snmpd read raw disk data
- Allow samba-rpcd work with passwords
- Allow unconfined service inherit signal state from init
- Allow cloud-init manage gpg admin home content
- Allow cluster_t dbus chat with various services
- Allow nfsidmapd work with systemd-userdbd and sssd
- Allow unconfined_domain_type use IORING_OP_URING_CMD on all device nodes
- Allow plymouthd map dri and framebuffer devices
- Allow rpmdb_migrate execute rpmdb
- Allow logrotate dbus chat with systemd-hostnamed
- Allow icecast connect to kernel using a unix stream socket
- Allow lldpad connect to systemd-userdbd over a unix socket
- Allow journalctl open user domain ptys and ttys
- Allow keepalived to manage its tmp files
- Allow ftpd read network sysctls
- Label /run/bgpd with zebra_var_run_t
- Allow gssproxy read network sysctls
- Add the cifsutils module
* Tue Apr 25 2023 Zdenek Pytela <zpytela@redhat.com> - 38.12-1
- Allow telnetd read network sysctls
- Allow munin system plugin read generic SSL certificates
- Allow munin system plugin create and use netlink generic socket
- Allow login_userdomain create user namespaces
- Allow request-key to send syslog messages
- Allow request-key to read/view any key
- Add fs_delete_pstore_files() interface
- Allow insights-client work with teamdctl
- Allow insights-client read unconfined service semaphores
- Allow insights-client get quotas of all filesystems
- Add fs_read_pstore_files() interface
- Allow generic kernel helper to read inherited kernel pipes
* Fri Apr 14 2023 Zdenek Pytela <zpytela@redhat.com> - 38.11-1
- Allow dovecot-deliver write to the main process runtime fifo files
- Allow dmidecode write to cloud-init tmp files
- Allow chronyd send a message to cloud-init over a datagram socket
- Allow cloud-init domain transition to insights-client domain
- Allow mongodb read filesystem sysctls
- Allow mongodb read network sysctls
- Allow accounts-daemon read generic systemd unit lnk files
- Allow blueman watch generic device dirs
- Allow nm-dispatcher tlp plugin create tlp dirs
- Allow systemd-coredump mounton /usr
- Allow rabbitmq to read network sysctls
* Tue Apr 04 2023 Zdenek Pytela <zpytela@redhat.com> - 38.10-1
- Allow certmonger dbus chat with the cron system domain
- Allow geoclue read network sysctls
- Allow geoclue watch the /etc directory
- Allow logwatch_mail_t read network sysctls
- Allow insights-client read all sysctls
- Allow passt manage qemu pid sock files
* Fri Mar 24 2023 Zdenek Pytela <zpytela@redhat.com> - 38.9-1
- Allow sssd read accountsd fifo files
- Add support for the passt_t domain
- Allow virtd_t and svirt_t work with passt
- Add new interfaces in the virt module
- Add passt interfaces defined conditionally
- Allow tshark the setsched capability
- Allow poweroff create connections to system dbus
- Allow wg load kernel modules, search debugfs dir
- Boolean: allow qemu-ga manage ssh home directory
- Label smtpd with sendmail_exec_t
- Label msmtp and msmtpd with sendmail_exec_t
- Allow dovecot to map files in /var/spool/dovecot
* Fri Mar 03 2023 Zdenek Pytela <zpytela@redhat.com> - 38.8-1
- Confine gnome-initial-setup
- Allow qemu-guest-agent create and use vsock socket
- Allow login_pgm setcap permission
- Allow chronyc read network sysctls
- Enhancement of the /usr/sbin/request-key helper policy
- Fix opencryptoki file names in /dev/shm
- Allow system_cronjob_t transition to rpm_script_t
- Revert "Allow system_cronjob_t domtrans to rpm_script_t"
- Add tunable to allow squid bind snmp port
- Allow staff_t getattr init pid chr & blk files and read krb5
- Allow firewalld to rw z90crypt device
- Allow httpd work with tokens in /dev/shm
- Allow svirt to map svirt_image_t char files
- Allow sysadm_t run initrc_t script and sysadm_r role access
- Allow insights-client manage fsadm pid files
* Wed Feb 08 2023 Zdenek Pytela <zpytela@redhat.com> - 38.7-1
- Allowing snapper to create snapshots of /home/ subvolume/partition
- Add boolean qemu-ga to run unconfined script
- Label systemd-journald feature LogNamespace
- Add none file context for polyinstantiated tmp dirs
- Allow certmonger read the contents of the sysfs filesystem
- Add journalctl the sys_resource capability
- Allow nm-dispatcher plugins read generic files in /proc
- Add initial policy for the /usr/sbin/request-key helper
- Additional support for rpmdb_migrate
- Add the keyutils module
* Mon Jan 30 2023 Zdenek Pytela <zpytela@redhat.com> - 38.6-1
- Boolean: allow qemu-ga read ssh home directory
- Allow kernel_t to read/write all sockets
- Allow kernel_t to UNIX-stream connect to all domains
- Allow systemd-resolved send a datagram to journald
- Allow kernel_t to manage and have "execute" access to all files
- Fix the files_manage_all_files() interface
- Allow rshim bpf cap2 and read sssd public files
- Allow insights-client work with su and lpstat
- Allow insights-client tcp connect to all ports
- Allow nm-cloud-setup dispatcher plugin restart nm services
- Allow unconfined user filetransition for sudo log files
- Allow modemmanager create hardware state information files
- Allow ModemManager all permissions for netlink route socket
- Allow wg to send msg to kernel, write to syslog and dbus connections
- Allow hostname_t to read network sysctls.
- Dontaudit ftpd the execmem permission
- Allow svirt request the kernel to load a module
- Allow icecast rename its log files
- Allow upsd to send signal to itself
- Allow wireguard to create udp sockets and read net_conf
- Use '
%setup -q
' instead of '%setup'
- Pass -p 1 to '
%setup -q
'
* Sat Jan 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 38.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Fri Jan 13 2023 Zdenek Pytela <zpytela@redhat.com> - 38.5-1
- Allow insights client work with gluster and pcp
- Add insights additional capabilities
- Add interfaces in domain, files, and unconfined modules
- Label fwupdoffline and fwupd-detect-cet with fwupd_exec_t
- Allow sudodomain use sudo.log as a logfile
- Allow pdns server map its library files and bind to unreserved ports
- Allow sysadm_t read/write ipmi devices
- Allow prosody manage its runtime socket files
- Allow kernel threads manage kernel keys
- Allow systemd-userdbd the sys_resource capability
- Allow systemd-journal list cgroup directories
- Allow apcupsd dbus chat with systemd-logind
- Allow nut_domain manage also files and sock_files in /var/run
- Allow winbind-rpcd make a TCP connection to the ldap port
- Label /usr/lib/rpm/rpmdb_migrate with rpmdb_exec_t
- Allow tlp read generic SSL certificates
- Allow systemd-resolved watch tmpfs directories
- Revert "Allow systemd-resolved watch tmpfs directories"
* Mon Dec 19 2022 Zdenek Pytela <zpytela@redhat.com> - 38.4-1
- Allow NetworkManager and wpa_supplicant the bpf capability
- Allow systemd-rfkill the bpf capability
- Allow winbind-rpcd manage samba_share_t files and dirs
- Label /var/lib/httpd/md(/.*)? with httpd_sys_rw_content_t
- Allow gpsd the sys_ptrace userns capability
- Introduce gpsd_tmp_t for sockfiles managed by gpsd_t
- Allow load_policy_t write to unallocated ttys
- Allow ndc read hardware state information
- Allow system mail service read inherited certmonger runtime files
- Add lpr_roles to system_r roles
- Revert "Allow insights-client run lpr and allow the proper role"
- Allow stalld to read /sys/kernel/security/lockdown file
- Allow keepalived to set resource limits
- Add policy for mptcpd
- Add policy for rshim
- Allow admin users to create user namespaces
- Allow journalctl relabel with var_log_t and syslogd_var_run_t files
- Do not run restorecon /etc/NetworkManager/dispatcher.d in targeted
- Trim changelog so that it starts at F35 time
- Add mptcpd and rshim modules
* Wed Dec 14 2022 Zdenek Pytela <zpytela@redhat.com> - 38.3-1
- Allow insights-client dbus chat with various services
- Allow insights-client tcp connect to various ports
- Allow insights-client run lpr and allow the proper role
- Allow insights-client work with pcp and manage user config files
- Allow redis get user names
- Allow kernel threads to use fds from all domains
- Allow systemd-modules-load load kernel modules
- Allow login_userdomain watch systemd-passwd pid dirs
- Allow insights-client dbus chat with abrt
- Grant kernel_t certain permissions in the system class
- Allow systemd-resolved watch tmpfs directories
- Allow systemd-timedated watch init runtime dir
- Make `bootc` be `install_exec_t`
- Allow systemd-coredump create user_namespace
- Allow syslog the setpcap capability
- donaudit virtlogd and dnsmasq execmem
* Tue Dec 06 2022 Zdenek Pytela <zpytela@redhat.com> - 38.2-1
- Don't make kernel_t an unconfined domain
- Don't allow kernel_t to execute bin_t/usr_t binaries without a transition
- Allow kernel_t to execute systemctl to do a poweroff/reboot
- Grant basic permissions to the domain created by systemd_systemctl_domain()
- Allow kernel_t to request module loading
- Allow kernel_t to do compute_create
- Allow kernel_t to manage perf events
- Grant almost all capabilities to kernel_t
- Allow kernel_t to fully manage all devices
- Revert "In domain_transition_pattern there is no permission allowing caller domain to execu_no_trans on entrypoint, this patch fixing this issue"
- Allow pulseaudio to write to session_dbusd tmp socket files
- Allow systemd and unconfined_domain_type create user_namespace
- Add the user_namespace security class
- Reuse tmpfs_t also for the ramfs filesystem
- Label udf tools with fsadm_exec_t
- Allow networkmanager_dispatcher_plugin work with nscd
- Watch_sb all file type directories.
- Allow spamc read hardware state information files
- Allow sysadm read ipmi devices
- Allow insights client communicate with cupsd, mysqld, openvswitch, redis
- Allow insights client read raw memory devices
- Allow the spamd_update_t domain get generic filesystem attributes
- Dontaudit systemd-gpt-generator the sys_admin capability
- Allow ipsec_t only read tpm devices
- Allow cups-pdf connect to the system log service
- Allow postfix/smtpd read kerberos key table
- Allow syslogd read network sysctls
- Allow cdcc mmap dcc-client-map files
- Add watch and watch_sb dosfs interface
* Mon Nov 21 2022 Zdenek Pytela <zpytela@redhat.com> - 38.1-1
- Revert "Allow sysadm_t read raw memory devices"
- Allow systemd-socket-proxyd get attributes of cgroup filesystems
- Allow rpc.gssd read network sysctls
- Allow winbind-rpcd get attributes of device and pty filesystems
- Allow insights-client domain transition on semanage execution
- Allow insights-client create gluster log dir with a transition
- Allow insights-client manage generic locks
- Allow insights-client unix_read all domain semaphores
- Add domain_unix_read_all_semaphores() interface
- Allow winbind-rpcd use the terminal multiplexor
- Allow mrtg send mails
- Allow systemd-hostnamed dbus chat with init scripts
- Allow sssd dbus chat with system cronjobs
- Add interface to watch all filesystems
- Add watch_sb interfaces
- Add watch interfaces
- Allow dhcpd bpf capability to run bpf programs
- Allow netutils and traceroute bpf capability to run bpf programs
- Allow pkcs_slotd_t bpf capability to run bpf programs
- Allow xdm bpf capability to run bpf programs
- Allow pcscd bpf capability to run bpf programs
- Allow lldpad bpf capability to run bpf programs
- Allow keepalived bpf capability to run bpf programs
- Allow ipsec bpf capability to run bpf programs
- Allow fprintd bpf capability to run bpf programs
- Allow systemd-socket-proxyd get filesystems attributes
- Allow dirsrv_snmp_t to manage dirsrv_config_t & dirsrv_var_run_t files
/etc/selinux/mls /etc/selinux/mls/.policy.sha512 /etc/selinux/mls/booleans.subs_dist /etc/selinux/mls/contexts /etc/selinux/mls/contexts/customizable_types /etc/selinux/mls/contexts/dbus_contexts /etc/selinux/mls/contexts/default_contexts /etc/selinux/mls/contexts/default_type /etc/selinux/mls/contexts/failsafe_context /etc/selinux/mls/contexts/files /etc/selinux/mls/contexts/files/file_contexts /etc/selinux/mls/contexts/files/file_contexts.bin /etc/selinux/mls/contexts/files/file_contexts.homedirs /etc/selinux/mls/contexts/files/file_contexts.homedirs.bin /etc/selinux/mls/contexts/files/file_contexts.local /etc/selinux/mls/contexts/files/file_contexts.local.bin /etc/selinux/mls/contexts/files/file_contexts.subs /etc/selinux/mls/contexts/files/file_contexts.subs_dist /etc/selinux/mls/contexts/files/media /etc/selinux/mls/contexts/initrc_context /etc/selinux/mls/contexts/lxc_contexts /etc/selinux/mls/contexts/openssh_contexts /etc/selinux/mls/contexts/removable_context /etc/selinux/mls/contexts/securetty_types /etc/selinux/mls/contexts/sepgsql_contexts /etc/selinux/mls/contexts/snapperd_contexts /etc/selinux/mls/contexts/systemd_contexts /etc/selinux/mls/contexts/userhelper_context /etc/selinux/mls/contexts/users /etc/selinux/mls/contexts/users/guest_u /etc/selinux/mls/contexts/users/root /etc/selinux/mls/contexts/users/staff_u /etc/selinux/mls/contexts/users/unconfined_u /etc/selinux/mls/contexts/users/user_u /etc/selinux/mls/contexts/users/xguest_u /etc/selinux/mls/contexts/virtual_domain_context /etc/selinux/mls/contexts/virtual_image_context /etc/selinux/mls/contexts/x_contexts /etc/selinux/mls/logins /etc/selinux/mls/policy /etc/selinux/mls/policy/policy.33 /etc/selinux/mls/setrans.conf /etc/selinux/mls/seusers /usr/share/selinux/mls /usr/share/selinux/mls/base.lst /usr/share/selinux/mls/modules-base.lst /usr/share/selinux/mls/modules-contrib.lst /usr/share/selinux/mls/nonbasemodules.lst /var/lib/selinux/mls /var/lib/selinux/mls/active /var/lib/selinux/mls/active/commit_num /var/lib/selinux/mls/active/file_contexts /var/lib/selinux/mls/active/file_contexts.homedirs /var/lib/selinux/mls/active/homedir_template /var/lib/selinux/mls/active/modules /var/lib/selinux/mls/active/modules/100/accountsd /var/lib/selinux/mls/active/modules/100/accountsd/cil /var/lib/selinux/mls/active/modules/100/accountsd/hll /var/lib/selinux/mls/active/modules/100/accountsd/lang_ext /var/lib/selinux/mls/active/modules/100/acct /var/lib/selinux/mls/active/modules/100/acct/cil /var/lib/selinux/mls/active/modules/100/acct/hll /var/lib/selinux/mls/active/modules/100/acct/lang_ext /var/lib/selinux/mls/active/modules/100/afs /var/lib/selinux/mls/active/modules/100/afs/cil /var/lib/selinux/mls/active/modules/100/afs/hll /var/lib/selinux/mls/active/modules/100/afs/lang_ext /var/lib/selinux/mls/active/modules/100/aide /var/lib/selinux/mls/active/modules/100/aide/cil /var/lib/selinux/mls/active/modules/100/aide/hll /var/lib/selinux/mls/active/modules/100/aide/lang_ext /var/lib/selinux/mls/active/modules/100/alsa /var/lib/selinux/mls/active/modules/100/alsa/cil /var/lib/selinux/mls/active/modules/100/alsa/hll /var/lib/selinux/mls/active/modules/100/alsa/lang_ext /var/lib/selinux/mls/active/modules/100/amanda /var/lib/selinux/mls/active/modules/100/amanda/cil /var/lib/selinux/mls/active/modules/100/amanda/hll /var/lib/selinux/mls/active/modules/100/amanda/lang_ext /var/lib/selinux/mls/active/modules/100/amtu /var/lib/selinux/mls/active/modules/100/amtu/cil /var/lib/selinux/mls/active/modules/100/amtu/hll /var/lib/selinux/mls/active/modules/100/amtu/lang_ext /var/lib/selinux/mls/active/modules/100/anaconda /var/lib/selinux/mls/active/modules/100/anaconda/cil /var/lib/selinux/mls/active/modules/100/anaconda/hll /var/lib/selinux/mls/active/modules/100/anaconda/lang_ext /var/lib/selinux/mls/active/modules/100/antivirus /var/lib/selinux/mls/active/modules/100/antivirus/cil /var/lib/selinux/mls/active/modules/100/antivirus/hll /var/lib/selinux/mls/active/modules/100/antivirus/lang_ext /var/lib/selinux/mls/active/modules/100/apache /var/lib/selinux/mls/active/modules/100/apache/cil /var/lib/selinux/mls/active/modules/100/apache/hll /var/lib/selinux/mls/active/modules/100/apache/lang_ext /var/lib/selinux/mls/active/modules/100/apcupsd /var/lib/selinux/mls/active/modules/100/apcupsd/cil /var/lib/selinux/mls/active/modules/100/apcupsd/hll /var/lib/selinux/mls/active/modules/100/apcupsd/lang_ext /var/lib/selinux/mls/active/modules/100/apm /var/lib/selinux/mls/active/modules/100/apm/cil /var/lib/selinux/mls/active/modules/100/apm/hll /var/lib/selinux/mls/active/modules/100/apm/lang_ext /var/lib/selinux/mls/active/modules/100/application /var/lib/selinux/mls/active/modules/100/application/cil /var/lib/selinux/mls/active/modules/100/application/hll /var/lib/selinux/mls/active/modules/100/application/lang_ext /var/lib/selinux/mls/active/modules/100/arpwatch /var/lib/selinux/mls/active/modules/100/arpwatch/cil /var/lib/selinux/mls/active/modules/100/arpwatch/hll /var/lib/selinux/mls/active/modules/100/arpwatch/lang_ext /var/lib/selinux/mls/active/modules/100/auditadm /var/lib/selinux/mls/active/modules/100/auditadm/cil /var/lib/selinux/mls/active/modules/100/auditadm/hll /var/lib/selinux/mls/active/modules/100/auditadm/lang_ext /var/lib/selinux/mls/active/modules/100/authlogin /var/lib/selinux/mls/active/modules/100/authlogin/cil /var/lib/selinux/mls/active/modules/100/authlogin/hll /var/lib/selinux/mls/active/modules/100/authlogin/lang_ext /var/lib/selinux/mls/active/modules/100/automount /var/lib/selinux/mls/active/modules/100/automount/cil /var/lib/selinux/mls/active/modules/100/automount/hll /var/lib/selinux/mls/active/modules/100/automount/lang_ext /var/lib/selinux/mls/active/modules/100/avahi /var/lib/selinux/mls/active/modules/100/avahi/cil /var/lib/selinux/mls/active/modules/100/avahi/hll /var/lib/selinux/mls/active/modules/100/avahi/lang_ext /var/lib/selinux/mls/active/modules/100/awstats /var/lib/selinux/mls/active/modules/100/awstats/cil /var/lib/selinux/mls/active/modules/100/awstats/hll /var/lib/selinux/mls/active/modules/100/awstats/lang_ext /var/lib/selinux/mls/active/modules/100/base /var/lib/selinux/mls/active/modules/100/base/cil /var/lib/selinux/mls/active/modules/100/base/hll /var/lib/selinux/mls/active/modules/100/base/lang_ext /var/lib/selinux/mls/active/modules/100/bind /var/lib/selinux/mls/active/modules/100/bind/cil /var/lib/selinux/mls/active/modules/100/bind/hll /var/lib/selinux/mls/active/modules/100/bind/lang_ext /var/lib/selinux/mls/active/modules/100/bitlbee /var/lib/selinux/mls/active/modules/100/bitlbee/cil /var/lib/selinux/mls/active/modules/100/bitlbee/hll /var/lib/selinux/mls/active/modules/100/bitlbee/lang_ext /var/lib/selinux/mls/active/modules/100/bluetooth /var/lib/selinux/mls/active/modules/100/bluetooth/cil /var/lib/selinux/mls/active/modules/100/bluetooth/hll /var/lib/selinux/mls/active/modules/100/bluetooth/lang_ext /var/lib/selinux/mls/active/modules/100/boinc /var/lib/selinux/mls/active/modules/100/boinc/cil /var/lib/selinux/mls/active/modules/100/boinc/hll /var/lib/selinux/mls/active/modules/100/boinc/lang_ext /var/lib/selinux/mls/active/modules/100/bootloader /var/lib/selinux/mls/active/modules/100/bootloader/cil /var/lib/selinux/mls/active/modules/100/bootloader/hll /var/lib/selinux/mls/active/modules/100/bootloader/lang_ext /var/lib/selinux/mls/active/modules/100/brctl /var/lib/selinux/mls/active/modules/100/brctl/cil /var/lib/selinux/mls/active/modules/100/brctl/hll /var/lib/selinux/mls/active/modules/100/brctl/lang_ext /var/lib/selinux/mls/active/modules/100/bugzilla /var/lib/selinux/mls/active/modules/100/bugzilla/cil /var/lib/selinux/mls/active/modules/100/bugzilla/hll /var/lib/selinux/mls/active/modules/100/bugzilla/lang_ext /var/lib/selinux/mls/active/modules/100/cachefilesd /var/lib/selinux/mls/active/modules/100/cachefilesd/cil /var/lib/selinux/mls/active/modules/100/cachefilesd/hll /var/lib/selinux/mls/active/modules/100/cachefilesd/lang_ext /var/lib/selinux/mls/active/modules/100/calamaris /var/lib/selinux/mls/active/modules/100/calamaris/cil /var/lib/selinux/mls/active/modules/100/calamaris/hll /var/lib/selinux/mls/active/modules/100/calamaris/lang_ext /var/lib/selinux/mls/active/modules/100/canna /var/lib/selinux/mls/active/modules/100/canna/cil /var/lib/selinux/mls/active/modules/100/canna/hll /var/lib/selinux/mls/active/modules/100/canna/lang_ext /var/lib/selinux/mls/active/modules/100/ccs /var/lib/selinux/mls/active/modules/100/ccs/cil /var/lib/selinux/mls/active/modules/100/ccs/hll /var/lib/selinux/mls/active/modules/100/ccs/lang_ext /var/lib/selinux/mls/active/modules/100/cdrecord /var/lib/selinux/mls/active/modules/100/cdrecord/cil /var/lib/selinux/mls/active/modules/100/cdrecord/hll /var/lib/selinux/mls/active/modules/100/cdrecord/lang_ext /var/lib/selinux/mls/active/modules/100/certmaster /var/lib/selinux/mls/active/modules/100/certmaster/cil /var/lib/selinux/mls/active/modules/100/certmaster/hll /var/lib/selinux/mls/active/modules/100/certmaster/lang_ext /var/lib/selinux/mls/active/modules/100/certmonger /var/lib/selinux/mls/active/modules/100/certmonger/cil /var/lib/selinux/mls/active/modules/100/certmonger/hll /var/lib/selinux/mls/active/modules/100/certmonger/lang_ext /var/lib/selinux/mls/active/modules/100/certwatch /var/lib/selinux/mls/active/modules/100/certwatch/cil /var/lib/selinux/mls/active/modules/100/certwatch/hll /var/lib/selinux/mls/active/modules/100/certwatch/lang_ext /var/lib/selinux/mls/active/modules/100/cgroup /var/lib/selinux/mls/active/modules/100/cgroup/cil /var/lib/selinux/mls/active/modules/100/cgroup/hll /var/lib/selinux/mls/active/modules/100/cgroup/lang_ext /var/lib/selinux/mls/active/modules/100/chrome /var/lib/selinux/mls/active/modules/100/chrome/cil /var/lib/selinux/mls/active/modules/100/chrome/hll /var/lib/selinux/mls/active/modules/100/chrome/lang_ext /var/lib/selinux/mls/active/modules/100/chronyd /var/lib/selinux/mls/active/modules/100/chronyd/cil /var/lib/selinux/mls/active/modules/100/chronyd/hll /var/lib/selinux/mls/active/modules/100/chronyd/lang_ext /var/lib/selinux/mls/active/modules/100/cipe /var/lib/selinux/mls/active/modules/100/cipe/cil /var/lib/selinux/mls/active/modules/100/cipe/hll /var/lib/selinux/mls/active/modules/100/cipe/lang_ext /var/lib/selinux/mls/active/modules/100/clock /var/lib/selinux/mls/active/modules/100/clock/cil /var/lib/selinux/mls/active/modules/100/clock/hll /var/lib/selinux/mls/active/modules/100/clock/lang_ext /var/lib/selinux/mls/active/modules/100/clogd /var/lib/selinux/mls/active/modules/100/clogd/cil /var/lib/selinux/mls/active/modules/100/clogd/hll /var/lib/selinux/mls/active/modules/100/clogd/lang_ext /var/lib/selinux/mls/active/modules/100/cmirrord /var/lib/selinux/mls/active/modules/100/cmirrord/cil /var/lib/selinux/mls/active/modules/100/cmirrord/hll /var/lib/selinux/mls/active/modules/100/cmirrord/lang_ext /var/lib/selinux/mls/active/modules/100/colord /var/lib/selinux/mls/active/modules/100/colord/cil /var/lib/selinux/mls/active/modules/100/colord/hll /var/lib/selinux/mls/active/modules/100/colord/lang_ext /var/lib/selinux/mls/active/modules/100/comsat /var/lib/selinux/mls/active/modules/100/comsat/cil /var/lib/selinux/mls/active/modules/100/comsat/hll /var/lib/selinux/mls/active/modules/100/comsat/lang_ext /var/lib/selinux/mls/active/modules/100/courier /var/lib/selinux/mls/active/modules/100/courier/cil /var/lib/selinux/mls/active/modules/100/courier/hll /var/lib/selinux/mls/active/modules/100/courier/lang_ext /var/lib/selinux/mls/active/modules/100/cpucontrol /var/lib/selinux/mls/active/modules/100/cpucontrol/cil /var/lib/selinux/mls/active/modules/100/cpucontrol/hll /var/lib/selinux/mls/active/modules/100/cpucontrol/lang_ext /var/lib/selinux/mls/active/modules/100/cpufreqselector /var/lib/selinux/mls/active/modules/100/cpufreqselector/cil /var/lib/selinux/mls/active/modules/100/cpufreqselector/hll /var/lib/selinux/mls/active/modules/100/cpufreqselector/lang_ext /var/lib/selinux/mls/active/modules/100/cron /var/lib/selinux/mls/active/modules/100/cron/cil /var/lib/selinux/mls/active/modules/100/cron/hll /var/lib/selinux/mls/active/modules/100/cron/lang_ext /var/lib/selinux/mls/active/modules/100/cups /var/lib/selinux/mls/active/modules/100/cups/cil /var/lib/selinux/mls/active/modules/100/cups/hll /var/lib/selinux/mls/active/modules/100/cups/lang_ext /var/lib/selinux/mls/active/modules/100/cvs /var/lib/selinux/mls/active/modules/100/cvs/cil /var/lib/selinux/mls/active/modules/100/cvs/hll /var/lib/selinux/mls/active/modules/100/cvs/lang_ext /var/lib/selinux/mls/active/modules/100/cyphesis /var/lib/selinux/mls/active/modules/100/cyphesis/cil /var/lib/selinux/mls/active/modules/100/cyphesis/hll /var/lib/selinux/mls/active/modules/100/cyphesis/lang_ext /var/lib/selinux/mls/active/modules/100/cyrus /var/lib/selinux/mls/active/modules/100/cyrus/cil /var/lib/selinux/mls/active/modules/100/cyrus/hll /var/lib/selinux/mls/active/modules/100/cyrus/lang_ext /var/lib/selinux/mls/active/modules/100/daemontools /var/lib/selinux/mls/active/modules/100/daemontools/cil /var/lib/selinux/mls/active/modules/100/daemontools/hll /var/lib/selinux/mls/active/modules/100/daemontools/lang_ext /var/lib/selinux/mls/active/modules/100/dbadm /var/lib/selinux/mls/active/modules/100/dbadm/cil /var/lib/selinux/mls/active/modules/100/dbadm/hll /var/lib/selinux/mls/active/modules/100/dbadm/lang_ext /var/lib/selinux/mls/active/modules/100/dbskk /var/lib/selinux/mls/active/modules/100/dbskk/cil /var/lib/selinux/mls/active/modules/100/dbskk/hll /var/lib/selinux/mls/active/modules/100/dbskk/lang_ext /var/lib/selinux/mls/active/modules/100/dbus /var/lib/selinux/mls/active/modules/100/dbus/cil /var/lib/selinux/mls/active/modules/100/dbus/hll /var/lib/selinux/mls/active/modules/100/dbus/lang_ext /var/lib/selinux/mls/active/modules/100/dcc /var/lib/selinux/mls/active/modules/100/dcc/cil /var/lib/selinux/mls/active/modules/100/dcc/hll /var/lib/selinux/mls/active/modules/100/dcc/lang_ext /var/lib/selinux/mls/active/modules/100/devicekit /var/lib/selinux/mls/active/modules/100/devicekit/cil /var/lib/selinux/mls/active/modules/100/devicekit/hll /var/lib/selinux/mls/active/modules/100/devicekit/lang_ext /var/lib/selinux/mls/active/modules/100/dhcp /var/lib/selinux/mls/active/modules/100/dhcp/cil /var/lib/selinux/mls/active/modules/100/dhcp/hll /var/lib/selinux/mls/active/modules/100/dhcp/lang_ext /var/lib/selinux/mls/active/modules/100/dictd /var/lib/selinux/mls/active/modules/100/dictd/cil /var/lib/selinux/mls/active/modules/100/dictd/hll /var/lib/selinux/mls/active/modules/100/dictd/lang_ext /var/lib/selinux/mls/active/modules/100/dmesg /var/lib/selinux/mls/active/modules/100/dmesg/cil /var/lib/selinux/mls/active/modules/100/dmesg/hll /var/lib/selinux/mls/active/modules/100/dmesg/lang_ext /var/lib/selinux/mls/active/modules/100/dmidecode /var/lib/selinux/mls/active/modules/100/dmidecode/cil /var/lib/selinux/mls/active/modules/100/dmidecode/hll /var/lib/selinux/mls/active/modules/100/dmidecode/lang_ext /var/lib/selinux/mls/active/modules/100/dnsmasq /var/lib/selinux/mls/active/modules/100/dnsmasq/cil /var/lib/selinux/mls/active/modules/100/dnsmasq/hll /var/lib/selinux/mls/active/modules/100/dnsmasq/lang_ext /var/lib/selinux/mls/active/modules/100/dnssec /var/lib/selinux/mls/active/modules/100/dnssec/cil /var/lib/selinux/mls/active/modules/100/dnssec/hll /var/lib/selinux/mls/active/modules/100/dnssec/lang_ext /var/lib/selinux/mls/active/modules/100/dovecot /var/lib/selinux/mls/active/modules/100/dovecot/cil /var/lib/selinux/mls/active/modules/100/dovecot/hll /var/lib/selinux/mls/active/modules/100/dovecot/lang_ext /var/lib/selinux/mls/active/modules/100/entropyd /var/lib/selinux/mls/active/modules/100/entropyd/cil /var/lib/selinux/mls/active/modules/100/entropyd/hll /var/lib/selinux/mls/active/modules/100/entropyd/lang_ext /var/lib/selinux/mls/active/modules/100/exim /var/lib/selinux/mls/active/modules/100/exim/cil /var/lib/selinux/mls/active/modules/100/exim/hll /var/lib/selinux/mls/active/modules/100/exim/lang_ext /var/lib/selinux/mls/active/modules/100/fail2ban /var/lib/selinux/mls/active/modules/100/fail2ban/cil /var/lib/selinux/mls/active/modules/100/fail2ban/hll /var/lib/selinux/mls/active/modules/100/fail2ban/lang_ext /var/lib/selinux/mls/active/modules/100/fetchmail /var/lib/selinux/mls/active/modules/100/fetchmail/cil /var/lib/selinux/mls/active/modules/100/fetchmail/hll /var/lib/selinux/mls/active/modules/100/fetchmail/lang_ext /var/lib/selinux/mls/active/modules/100/finger /var/lib/selinux/mls/active/modules/100/finger/cil /var/lib/selinux/mls/active/modules/100/finger/hll /var/lib/selinux/mls/active/modules/100/finger/lang_ext /var/lib/selinux/mls/active/modules/100/firewalld /var/lib/selinux/mls/active/modules/100/firewalld/cil /var/lib/selinux/mls/active/modules/100/firewalld/hll /var/lib/selinux/mls/active/modules/100/firewalld/lang_ext /var/lib/selinux/mls/active/modules/100/firewallgui /var/lib/selinux/mls/active/modules/100/firewallgui/cil /var/lib/selinux/mls/active/modules/100/firewallgui/hll /var/lib/selinux/mls/active/modules/100/firewallgui/lang_ext /var/lib/selinux/mls/active/modules/100/firstboot /var/lib/selinux/mls/active/modules/100/firstboot/cil /var/lib/selinux/mls/active/modules/100/firstboot/hll /var/lib/selinux/mls/active/modules/100/firstboot/lang_ext /var/lib/selinux/mls/active/modules/100/fprintd /var/lib/selinux/mls/active/modules/100/fprintd/cil /var/lib/selinux/mls/active/modules/100/fprintd/hll /var/lib/selinux/mls/active/modules/100/fprintd/lang_ext /var/lib/selinux/mls/active/modules/100/fstools /var/lib/selinux/mls/active/modules/100/fstools/cil /var/lib/selinux/mls/active/modules/100/fstools/hll /var/lib/selinux/mls/active/modules/100/fstools/lang_ext /var/lib/selinux/mls/active/modules/100/ftp /var/lib/selinux/mls/active/modules/100/ftp/cil /var/lib/selinux/mls/active/modules/100/ftp/hll /var/lib/selinux/mls/active/modules/100/ftp/lang_ext /var/lib/selinux/mls/active/modules/100/games /var/lib/selinux/mls/active/modules/100/games/cil /var/lib/selinux/mls/active/modules/100/games/hll /var/lib/selinux/mls/active/modules/100/games/lang_ext /var/lib/selinux/mls/active/modules/100/getty /var/lib/selinux/mls/active/modules/100/getty/cil /var/lib/selinux/mls/active/modules/100/getty/hll /var/lib/selinux/mls/active/modules/100/getty/lang_ext /var/lib/selinux/mls/active/modules/100/git /var/lib/selinux/mls/active/modules/100/git/cil /var/lib/selinux/mls/active/modules/100/git/hll /var/lib/selinux/mls/active/modules/100/git/lang_ext /var/lib/selinux/mls/active/modules/100/gitosis /var/lib/selinux/mls/active/modules/100/gitosis/cil /var/lib/selinux/mls/active/modules/100/gitosis/hll /var/lib/selinux/mls/active/modules/100/gitosis/lang_ext /var/lib/selinux/mls/active/modules/100/glance /var/lib/selinux/mls/active/modules/100/glance/cil /var/lib/selinux/mls/active/modules/100/glance/hll /var/lib/selinux/mls/active/modules/100/glance/lang_ext /var/lib/selinux/mls/active/modules/100/gnome /var/lib/selinux/mls/active/modules/100/gnome/cil /var/lib/selinux/mls/active/modules/100/gnome/hll /var/lib/selinux/mls/active/modules/100/gnome/lang_ext /var/lib/selinux/mls/active/modules/100/gpg /var/lib/selinux/mls/active/modules/100/gpg/cil /var/lib/selinux/mls/active/modules/100/gpg/hll /var/lib/selinux/mls/active/modules/100/gpg/lang_ext /var/lib/selinux/mls/active/modules/100/gpm /var/lib/selinux/mls/active/modules/100/gpm/cil /var/lib/selinux/mls/active/modules/100/gpm/hll /var/lib/selinux/mls/active/modules/100/gpm/lang_ext /var/lib/selinux/mls/active/modules/100/gpsd /var/lib/selinux/mls/active/modules/100/gpsd/cil /var/lib/selinux/mls/active/modules/100/gpsd/hll /var/lib/selinux/mls/active/modules/100/gpsd/lang_ext /var/lib/selinux/mls/active/modules/100/gssproxy /var/lib/selinux/mls/active/modules/100/gssproxy/cil /var/lib/selinux/mls/active/modules/100/gssproxy/hll /var/lib/selinux/mls/active/modules/100/gssproxy/lang_ext /var/lib/selinux/mls/active/modules/100/guest /var/lib/selinux/mls/active/modules/100/guest/cil /var/lib/selinux/mls/active/modules/100/guest/hll /var/lib/selinux/mls/active/modules/100/guest/lang_ext /var/lib/selinux/mls/active/modules/100/hostname /var/lib/selinux/mls/active/modules/100/hostname/cil /var/lib/selinux/mls/active/modules/100/hostname/hll /var/lib/selinux/mls/active/modules/100/hostname/lang_ext /var/lib/selinux/mls/active/modules/100/inetd /var/lib/selinux/mls/active/modules/100/inetd/cil /var/lib/selinux/mls/active/modules/100/inetd/hll /var/lib/selinux/mls/active/modules/100/inetd/lang_ext /var/lib/selinux/mls/active/modules/100/init /var/lib/selinux/mls/active/modules/100/init/cil /var/lib/selinux/mls/active/modules/100/init/hll /var/lib/selinux/mls/active/modules/100/init/lang_ext /var/lib/selinux/mls/active/modules/100/inn /var/lib/selinux/mls/active/modules/100/inn/cil /var/lib/selinux/mls/active/modules/100/inn/hll /var/lib/selinux/mls/active/modules/100/inn/lang_ext /var/lib/selinux/mls/active/modules/100/ipsec /var/lib/selinux/mls/active/modules/100/ipsec/cil /var/lib/selinux/mls/active/modules/100/ipsec/hll /var/lib/selinux/mls/active/modules/100/ipsec/lang_ext /var/lib/selinux/mls/active/modules/100/iptables /var/lib/selinux/mls/active/modules/100/iptables/cil /var/lib/selinux/mls/active/modules/100/iptables/hll /var/lib/selinux/mls/active/modules/100/iptables/lang_ext /var/lib/selinux/mls/active/modules/100/irc /var/lib/selinux/mls/active/modules/100/irc/cil /var/lib/selinux/mls/active/modules/100/irc/hll /var/lib/selinux/mls/active/modules/100/irc/lang_ext /var/lib/selinux/mls/active/modules/100/irqbalance /var/lib/selinux/mls/active/modules/100/irqbalance/cil /var/lib/selinux/mls/active/modules/100/irqbalance/hll /var/lib/selinux/mls/active/modules/100/irqbalance/lang_ext /var/lib/selinux/mls/active/modules/100/iscsi /var/lib/selinux/mls/active/modules/100/iscsi/cil /var/lib/selinux/mls/active/modules/100/iscsi/hll /var/lib/selinux/mls/active/modules/100/iscsi/lang_ext /var/lib/selinux/mls/active/modules/100/jabber /var/lib/selinux/mls/active/modules/100/jabber/cil /var/lib/selinux/mls/active/modules/100/jabber/hll /var/lib/selinux/mls/active/modules/100/jabber/lang_ext /var/lib/selinux/mls/active/modules/100/kdump /var/lib/selinux/mls/active/modules/100/kdump/cil /var/lib/selinux/mls/active/modules/100/kdump/hll /var/lib/selinux/mls/active/modules/100/kdump/lang_ext /var/lib/selinux/mls/active/modules/100/kdumpgui /var/lib/selinux/mls/active/modules/100/kdumpgui/cil /var/lib/selinux/mls/active/modules/100/kdumpgui/hll /var/lib/selinux/mls/active/modules/100/kdumpgui/lang_ext /var/lib/selinux/mls/active/modules/100/kerberos /var/lib/selinux/mls/active/modules/100/kerberos/cil /var/lib/selinux/mls/active/modules/100/kerberos/hll /var/lib/selinux/mls/active/modules/100/kerberos/lang_ext /var/lib/selinux/mls/active/modules/100/kismet /var/lib/selinux/mls/active/modules/100/kismet/cil /var/lib/selinux/mls/active/modules/100/kismet/hll /var/lib/selinux/mls/active/modules/100/kismet/lang_ext /var/lib/selinux/mls/active/modules/100/ksmtuned /var/lib/selinux/mls/active/modules/100/ksmtuned/cil /var/lib/selinux/mls/active/modules/100/ksmtuned/hll /var/lib/selinux/mls/active/modules/100/ksmtuned/lang_ext /var/lib/selinux/mls/active/modules/100/ktalk /var/lib/selinux/mls/active/modules/100/ktalk/cil /var/lib/selinux/mls/active/modules/100/ktalk/hll /var/lib/selinux/mls/active/modules/100/ktalk/lang_ext /var/lib/selinux/mls/active/modules/100/ldap /var/lib/selinux/mls/active/modules/100/ldap/cil /var/lib/selinux/mls/active/modules/100/ldap/hll /var/lib/selinux/mls/active/modules/100/ldap/lang_ext /var/lib/selinux/mls/active/modules/100/libraries /var/lib/selinux/mls/active/modules/100/libraries/cil /var/lib/selinux/mls/active/modules/100/libraries/hll /var/lib/selinux/mls/active/modules/100/libraries/lang_ext /var/lib/selinux/mls/active/modules/100/lircd /var/lib/selinux/mls/active/modules/100/lircd/cil /var/lib/selinux/mls/active/modules/100/lircd/hll /var/lib/selinux/mls/active/modules/100/lircd/lang_ext /var/lib/selinux/mls/active/modules/100/loadkeys /var/lib/selinux/mls/active/modules/100/loadkeys/cil /var/lib/selinux/mls/active/modules/100/loadkeys/hll /var/lib/selinux/mls/active/modules/100/loadkeys/lang_ext /var/lib/selinux/mls/active/modules/100/locallogin /var/lib/selinux/mls/active/modules/100/locallogin/cil /var/lib/selinux/mls/active/modules/100/locallogin/hll /var/lib/selinux/mls/active/modules/100/locallogin/lang_ext /var/lib/selinux/mls/active/modules/100/lockdev /var/lib/selinux/mls/active/modules/100/lockdev/cil /var/lib/selinux/mls/active/modules/100/lockdev/hll /var/lib/selinux/mls/active/modules/100/lockdev/lang_ext /var/lib/selinux/mls/active/modules/100/logadm /var/lib/selinux/mls/active/modules/100/logadm/cil /var/lib/selinux/mls/active/modules/100/logadm/hll /var/lib/selinux/mls/active/modules/100/logadm/lang_ext /var/lib/selinux/mls/active/modules/100/logging /var/lib/selinux/mls/active/modules/100/logging/cil /var/lib/selinux/mls/active/modules/100/logging/hll /var/lib/selinux/mls/active/modules/100/logging/lang_ext /var/lib/selinux/mls/active/modules/100/logrotate /var/lib/selinux/mls/active/modules/100/logrotate/cil /var/lib/selinux/mls/active/modules/100/logrotate/hll /var/lib/selinux/mls/active/modules/100/logrotate/lang_ext /var/lib/selinux/mls/active/modules/100/logwatch /var/lib/selinux/mls/active/modules/100/logwatch/cil /var/lib/selinux/mls/active/modules/100/logwatch/hll /var/lib/selinux/mls/active/modules/100/logwatch/lang_ext /var/lib/selinux/mls/active/modules/100/lpd /var/lib/selinux/mls/active/modules/100/lpd/cil /var/lib/selinux/mls/active/modules/100/lpd/hll /var/lib/selinux/mls/active/modules/100/lpd/lang_ext /var/lib/selinux/mls/active/modules/100/lsm /var/lib/selinux/mls/active/modules/100/lsm/cil /var/lib/selinux/mls/active/modules/100/lsm/hll /var/lib/selinux/mls/active/modules/100/lsm/lang_ext /var/lib/selinux/mls/active/modules/100/lvm /var/lib/selinux/mls/active/modules/100/lvm/cil /var/lib/selinux/mls/active/modules/100/lvm/hll /var/lib/selinux/mls/active/modules/100/lvm/lang_ext /var/lib/selinux/mls/active/modules/100/mailman /var/lib/selinux/mls/active/modules/100/mailman/cil /var/lib/selinux/mls/active/modules/100/mailman/hll /var/lib/selinux/mls/active/modules/100/mailman/lang_ext /var/lib/selinux/mls/active/modules/100/mandb /var/lib/selinux/mls/active/modules/100/mandb/cil /var/lib/selinux/mls/active/modules/100/mandb/hll /var/lib/selinux/mls/active/modules/100/mandb/lang_ext /var/lib/selinux/mls/active/modules/100/mcelog /var/lib/selinux/mls/active/modules/100/mcelog/cil /var/lib/selinux/mls/active/modules/100/mcelog/hll /var/lib/selinux/mls/active/modules/100/mcelog/lang_ext /var/lib/selinux/mls/active/modules/100/memcached /var/lib/selinux/mls/active/modules/100/memcached/cil /var/lib/selinux/mls/active/modules/100/memcached/hll /var/lib/selinux/mls/active/modules/100/memcached/lang_ext /var/lib/selinux/mls/active/modules/100/milter /var/lib/selinux/mls/active/modules/100/milter/cil /var/lib/selinux/mls/active/modules/100/milter/hll /var/lib/selinux/mls/active/modules/100/milter/lang_ext /var/lib/selinux/mls/active/modules/100/miscfiles /var/lib/selinux/mls/active/modules/100/miscfiles/cil /var/lib/selinux/mls/active/modules/100/miscfiles/hll /var/lib/selinux/mls/active/modules/100/miscfiles/lang_ext /var/lib/selinux/mls/active/modules/100/modemmanager /var/lib/selinux/mls/active/modules/100/modemmanager/cil /var/lib/selinux/mls/active/modules/100/modemmanager/hll /var/lib/selinux/mls/active/modules/100/modemmanager/lang_ext /var/lib/selinux/mls/active/modules/100/modutils /var/lib/selinux/mls/active/modules/100/modutils/cil /var/lib/selinux/mls/active/modules/100/modutils/hll /var/lib/selinux/mls/active/modules/100/modutils/lang_ext /var/lib/selinux/mls/active/modules/100/mojomojo /var/lib/selinux/mls/active/modules/100/mojomojo/cil /var/lib/selinux/mls/active/modules/100/mojomojo/hll /var/lib/selinux/mls/active/modules/100/mojomojo/lang_ext /var/lib/selinux/mls/active/modules/100/mount /var/lib/selinux/mls/active/modules/100/mount/cil /var/lib/selinux/mls/active/modules/100/mount/hll /var/lib/selinux/mls/active/modules/100/mount/lang_ext /var/lib/selinux/mls/active/modules/100/mozilla /var/lib/selinux/mls/active/modules/100/mozilla/cil /var/lib/selinux/mls/active/modules/100/mozilla/hll /var/lib/selinux/mls/active/modules/100/mozilla/lang_ext /var/lib/selinux/mls/active/modules/100/mplayer /var/lib/selinux/mls/active/modules/100/mplayer/cil /var/lib/selinux/mls/active/modules/100/mplayer/hll /var/lib/selinux/mls/active/modules/100/mplayer/lang_ext /var/lib/selinux/mls/active/modules/100/mrtg /var/lib/selinux/mls/active/modules/100/mrtg/cil /var/lib/selinux/mls/active/modules/100/mrtg/hll /var/lib/selinux/mls/active/modules/100/mrtg/lang_ext /var/lib/selinux/mls/active/modules/100/mta /var/lib/selinux/mls/active/modules/100/mta/cil /var/lib/selinux/mls/active/modules/100/mta/hll /var/lib/selinux/mls/active/modules/100/mta/lang_ext /var/lib/selinux/mls/active/modules/100/munin /var/lib/selinux/mls/active/modules/100/munin/cil /var/lib/selinux/mls/active/modules/100/munin/hll /var/lib/selinux/mls/active/modules/100/munin/lang_ext /var/lib/selinux/mls/active/modules/100/mysql /var/lib/selinux/mls/active/modules/100/mysql/cil /var/lib/selinux/mls/active/modules/100/mysql/hll /var/lib/selinux/mls/active/modules/100/mysql/lang_ext /var/lib/selinux/mls/active/modules/100/nagios /var/lib/selinux/mls/active/modules/100/nagios/cil /var/lib/selinux/mls/active/modules/100/nagios/hll /var/lib/selinux/mls/active/modules/100/nagios/lang_ext /var/lib/selinux/mls/active/modules/100/namespace /var/lib/selinux/mls/active/modules/100/namespace/cil /var/lib/selinux/mls/active/modules/100/namespace/hll /var/lib/selinux/mls/active/modules/100/namespace/lang_ext /var/lib/selinux/mls/active/modules/100/ncftool /var/lib/selinux/mls/active/modules/100/ncftool/cil /var/lib/selinux/mls/active/modules/100/ncftool/hll /var/lib/selinux/mls/active/modules/100/ncftool/lang_ext /var/lib/selinux/mls/active/modules/100/netlabel /var/lib/selinux/mls/active/modules/100/netlabel/cil /var/lib/selinux/mls/active/modules/100/netlabel/hll /var/lib/selinux/mls/active/modules/100/netlabel/lang_ext /var/lib/selinux/mls/active/modules/100/netutils /var/lib/selinux/mls/active/modules/100/netutils/cil /var/lib/selinux/mls/active/modules/100/netutils/hll /var/lib/selinux/mls/active/modules/100/netutils/lang_ext /var/lib/selinux/mls/active/modules/100/networkmanager /var/lib/selinux/mls/active/modules/100/networkmanager/cil /var/lib/selinux/mls/active/modules/100/networkmanager/hll /var/lib/selinux/mls/active/modules/100/networkmanager/lang_ext /var/lib/selinux/mls/active/modules/100/nis /var/lib/selinux/mls/active/modules/100/nis/cil /var/lib/selinux/mls/active/modules/100/nis/hll /var/lib/selinux/mls/active/modules/100/nis/lang_ext /var/lib/selinux/mls/active/modules/100/nscd /var/lib/selinux/mls/active/modules/100/nscd/cil /var/lib/selinux/mls/active/modules/100/nscd/hll /var/lib/selinux/mls/active/modules/100/nscd/lang_ext /var/lib/selinux/mls/active/modules/100/nslcd /var/lib/selinux/mls/active/modules/100/nslcd/cil /var/lib/selinux/mls/active/modules/100/nslcd/hll /var/lib/selinux/mls/active/modules/100/nslcd/lang_ext /var/lib/selinux/mls/active/modules/100/ntop /var/lib/selinux/mls/active/modules/100/ntop/cil /var/lib/selinux/mls/active/modules/100/ntop/hll /var/lib/selinux/mls/active/modules/100/ntop/lang_ext /var/lib/selinux/mls/active/modules/100/ntp /var/lib/selinux/mls/active/modules/100/ntp/cil /var/lib/selinux/mls/active/modules/100/ntp/hll /var/lib/selinux/mls/active/modules/100/ntp/lang_ext /var/lib/selinux/mls/active/modules/100/nx /var/lib/selinux/mls/active/modules/100/nx/cil /var/lib/selinux/mls/active/modules/100/nx/hll /var/lib/selinux/mls/active/modules/100/nx/lang_ext /var/lib/selinux/mls/active/modules/100/oddjob /var/lib/selinux/mls/active/modules/100/oddjob/cil /var/lib/selinux/mls/active/modules/100/oddjob/hll /var/lib/selinux/mls/active/modules/100/oddjob/lang_ext /var/lib/selinux/mls/active/modules/100/openct /var/lib/selinux/mls/active/modules/100/openct/cil /var/lib/selinux/mls/active/modules/100/openct/hll /var/lib/selinux/mls/active/modules/100/openct/lang_ext /var/lib/selinux/mls/active/modules/100/openvpn /var/lib/selinux/mls/active/modules/100/openvpn/cil /var/lib/selinux/mls/active/modules/100/openvpn/hll /var/lib/selinux/mls/active/modules/100/openvpn/lang_ext /var/lib/selinux/mls/active/modules/100/openvswitch /var/lib/selinux/mls/active/modules/100/openvswitch/cil /var/lib/selinux/mls/active/modules/100/openvswitch/hll /var/lib/selinux/mls/active/modules/100/openvswitch/lang_ext /var/lib/selinux/mls/active/modules/100/pads /var/lib/selinux/mls/active/modules/100/pads/cil /var/lib/selinux/mls/active/modules/100/pads/hll /var/lib/selinux/mls/active/modules/100/pads/lang_ext /var/lib/selinux/mls/active/modules/100/pcmcia /var/lib/selinux/mls/active/modules/100/pcmcia/cil /var/lib/selinux/mls/active/modules/100/pcmcia/hll /var/lib/selinux/mls/active/modules/100/pcmcia/lang_ext /var/lib/selinux/mls/active/modules/100/pcscd /var/lib/selinux/mls/active/modules/100/pcscd/cil /var/lib/selinux/mls/active/modules/100/pcscd/hll /var/lib/selinux/mls/active/modules/100/pcscd/lang_ext /var/lib/selinux/mls/active/modules/100/pegasus /var/lib/selinux/mls/active/modules/100/pegasus/cil /var/lib/selinux/mls/active/modules/100/pegasus/hll /var/lib/selinux/mls/active/modules/100/pegasus/lang_ext /var/lib/selinux/mls/active/modules/100/pingd /var/lib/selinux/mls/active/modules/100/pingd/cil /var/lib/selinux/mls/active/modules/100/pingd/hll /var/lib/selinux/mls/active/modules/100/pingd/lang_ext /var/lib/selinux/mls/active/modules/100/piranha /var/lib/selinux/mls/active/modules/100/piranha/cil /var/lib/selinux/mls/active/modules/100/piranha/hll /var/lib/selinux/mls/active/modules/100/piranha/lang_ext /var/lib/selinux/mls/active/modules/100/plymouthd /var/lib/selinux/mls/active/modules/100/plymouthd/cil /var/lib/selinux/mls/active/modules/100/plymouthd/hll /var/lib/selinux/mls/active/modules/100/plymouthd/lang_ext /var/lib/selinux/mls/active/modules/100/podsleuth /var/lib/selinux/mls/active/modules/100/podsleuth/cil /var/lib/selinux/mls/active/modules/100/podsleuth/hll /var/lib/selinux/mls/active/modules/100/podsleuth/lang_ext /var/lib/selinux/mls/active/modules/100/policykit /var/lib/selinux/mls/active/modules/100/policykit/cil /var/lib/selinux/mls/active/modules/100/policykit/hll /var/lib/selinux/mls/active/modules/100/policykit/lang_ext /var/lib/selinux/mls/active/modules/100/polipo /var/lib/selinux/mls/active/modules/100/polipo/cil /var/lib/selinux/mls/active/modules/100/polipo/hll /var/lib/selinux/mls/active/modules/100/polipo/lang_ext /var/lib/selinux/mls/active/modules/100/portmap /var/lib/selinux/mls/active/modules/100/portmap/cil /var/lib/selinux/mls/active/modules/100/portmap/hll /var/lib/selinux/mls/active/modules/100/portmap/lang_ext /var/lib/selinux/mls/active/modules/100/portreserve /var/lib/selinux/mls/active/modules/100/portreserve/cil /var/lib/selinux/mls/active/modules/100/portreserve/hll /var/lib/selinux/mls/active/modules/100/portreserve/lang_ext /var/lib/selinux/mls/active/modules/100/postfix /var/lib/selinux/mls/active/modules/100/postfix/cil /var/lib/selinux/mls/active/modules/100/postfix/hll /var/lib/selinux/mls/active/modules/100/postfix/lang_ext /var/lib/selinux/mls/active/modules/100/postgresql /var/lib/selinux/mls/active/modules/100/postgresql/cil /var/lib/selinux/mls/active/modules/100/postgresql/hll /var/lib/selinux/mls/active/modules/100/postgresql/lang_ext /var/lib/selinux/mls/active/modules/100/postgrey /var/lib/selinux/mls/active/modules/100/postgrey/cil /var/lib/selinux/mls/active/modules/100/postgrey/hll /var/lib/selinux/mls/active/modules/100/postgrey/lang_ext /var/lib/selinux/mls/active/modules/100/ppp /var/lib/selinux/mls/active/modules/100/ppp/cil /var/lib/selinux/mls/active/modules/100/ppp/hll /var/lib/selinux/mls/active/modules/100/ppp/lang_ext /var/lib/selinux/mls/active/modules/100/prelink /var/lib/selinux/mls/active/modules/100/prelink/cil /var/lib/selinux/mls/active/modules/100/prelink/hll /var/lib/selinux/mls/active/modules/100/prelink/lang_ext /var/lib/selinux/mls/active/modules/100/prelude /var/lib/selinux/mls/active/modules/100/prelude/cil /var/lib/selinux/mls/active/modules/100/prelude/hll /var/lib/selinux/mls/active/modules/100/prelude/lang_ext /var/lib/selinux/mls/active/modules/100/privoxy /var/lib/selinux/mls/active/modules/100/privoxy/cil /var/lib/selinux/mls/active/modules/100/privoxy/hll /var/lib/selinux/mls/active/modules/100/privoxy/lang_ext /var/lib/selinux/mls/active/modules/100/procmail /var/lib/selinux/mls/active/modules/100/procmail/cil /var/lib/selinux/mls/active/modules/100/procmail/hll /var/lib/selinux/mls/active/modules/100/procmail/lang_ext /var/lib/selinux/mls/active/modules/100/prosody /var/lib/selinux/mls/active/modules/100/prosody/cil /var/lib/selinux/mls/active/modules/100/prosody/hll /var/lib/selinux/mls/active/modules/100/prosody/lang_ext /var/lib/selinux/mls/active/modules/100/psad /var/lib/selinux/mls/active/modules/100/psad/cil /var/lib/selinux/mls/active/modules/100/psad/hll /var/lib/selinux/mls/active/modules/100/psad/lang_ext /var/lib/selinux/mls/active/modules/100/ptchown /var/lib/selinux/mls/active/modules/100/ptchown/cil /var/lib/selinux/mls/active/modules/100/ptchown/hll /var/lib/selinux/mls/active/modules/100/ptchown/lang_ext /var/lib/selinux/mls/active/modules/100/publicfile /var/lib/selinux/mls/active/modules/100/publicfile/cil /var/lib/selinux/mls/active/modules/100/publicfile/hll /var/lib/selinux/mls/active/modules/100/publicfile/lang_ext /var/lib/selinux/mls/active/modules/100/pulseaudio /var/lib/selinux/mls/active/modules/100/pulseaudio/cil /var/lib/selinux/mls/active/modules/100/pulseaudio/hll /var/lib/selinux/mls/active/modules/100/pulseaudio/lang_ext /var/lib/selinux/mls/active/modules/100/qmail /var/lib/selinux/mls/active/modules/100/qmail/cil /var/lib/selinux/mls/active/modules/100/qmail/hll /var/lib/selinux/mls/active/modules/100/qmail/lang_ext /var/lib/selinux/mls/active/modules/100/qpid /var/lib/selinux/mls/active/modules/100/qpid/cil /var/lib/selinux/mls/active/modules/100/qpid/hll /var/lib/selinux/mls/active/modules/100/qpid/lang_ext /var/lib/selinux/mls/active/modules/100/quota /var/lib/selinux/mls/active/modules/100/quota/cil /var/lib/selinux/mls/active/modules/100/quota/hll /var/lib/selinux/mls/active/modules/100/quota/lang_ext /var/lib/selinux/mls/active/modules/100/radius /var/lib/selinux/mls/active/modules/100/radius/cil /var/lib/selinux/mls/active/modules/100/radius/hll /var/lib/selinux/mls/active/modules/100/radius/lang_ext /var/lib/selinux/mls/active/modules/100/radvd /var/lib/selinux/mls/active/modules/100/radvd/cil /var/lib/selinux/mls/active/modules/100/radvd/hll /var/lib/selinux/mls/active/modules/100/radvd/lang_ext /var/lib/selinux/mls/active/modules/100/raid /var/lib/selinux/mls/active/modules/100/raid/cil /var/lib/selinux/mls/active/modules/100/raid/hll /var/lib/selinux/mls/active/modules/100/raid/lang_ext /var/lib/selinux/mls/active/modules/100/rdisc /var/lib/selinux/mls/active/modules/100/rdisc/cil /var/lib/selinux/mls/active/modules/100/rdisc/hll /var/lib/selinux/mls/active/modules/100/rdisc/lang_ext /var/lib/selinux/mls/active/modules/100/readahead /var/lib/selinux/mls/active/modules/100/readahead/cil /var/lib/selinux/mls/active/modules/100/readahead/hll /var/lib/selinux/mls/active/modules/100/readahead/lang_ext /var/lib/selinux/mls/active/modules/100/remotelogin /var/lib/selinux/mls/active/modules/100/remotelogin/cil /var/lib/selinux/mls/active/modules/100/remotelogin/hll /var/lib/selinux/mls/active/modules/100/remotelogin/lang_ext /var/lib/selinux/mls/active/modules/100/rhcs /var/lib/selinux/mls/active/modules/100/rhcs/cil /var/lib/selinux/mls/active/modules/100/rhcs/hll /var/lib/selinux/mls/active/modules/100/rhcs/lang_ext /var/lib/selinux/mls/active/modules/100/rhgb /var/lib/selinux/mls/active/modules/100/rhgb/cil /var/lib/selinux/mls/active/modules/100/rhgb/hll /var/lib/selinux/mls/active/modules/100/rhgb/lang_ext /var/lib/selinux/mls/active/modules/100/ricci /var/lib/selinux/mls/active/modules/100/ricci/cil /var/lib/selinux/mls/active/modules/100/ricci/hll /var/lib/selinux/mls/active/modules/100/ricci/lang_ext /var/lib/selinux/mls/active/modules/100/rlogin /var/lib/selinux/mls/active/modules/100/rlogin/cil /var/lib/selinux/mls/active/modules/100/rlogin/hll /var/lib/selinux/mls/active/modules/100/rlogin/lang_ext /var/lib/selinux/mls/active/modules/100/roundup /var/lib/selinux/mls/active/modules/100/roundup/cil /var/lib/selinux/mls/active/modules/100/roundup/hll /var/lib/selinux/mls/active/modules/100/roundup/lang_ext /var/lib/selinux/mls/active/modules/100/rpc /var/lib/selinux/mls/active/modules/100/rpc/cil /var/lib/selinux/mls/active/modules/100/rpc/hll /var/lib/selinux/mls/active/modules/100/rpc/lang_ext /var/lib/selinux/mls/active/modules/100/rpcbind /var/lib/selinux/mls/active/modules/100/rpcbind/cil /var/lib/selinux/mls/active/modules/100/rpcbind/hll /var/lib/selinux/mls/active/modules/100/rpcbind/lang_ext /var/lib/selinux/mls/active/modules/100/rpm /var/lib/selinux/mls/active/modules/100/rpm/cil /var/lib/selinux/mls/active/modules/100/rpm/hll /var/lib/selinux/mls/active/modules/100/rpm/lang_ext /var/lib/selinux/mls/active/modules/100/rshd /var/lib/selinux/mls/active/modules/100/rshd/cil /var/lib/selinux/mls/active/modules/100/rshd/hll /var/lib/selinux/mls/active/modules/100/rshd/lang_ext /var/lib/selinux/mls/active/modules/100/rsync /var/lib/selinux/mls/active/modules/100/rsync/cil /var/lib/selinux/mls/active/modules/100/rsync/hll /var/lib/selinux/mls/active/modules/100/rsync/lang_ext /var/lib/selinux/mls/active/modules/100/rtkit /var/lib/selinux/mls/active/modules/100/rtkit/cil /var/lib/selinux/mls/active/modules/100/rtkit/hll /var/lib/selinux/mls/active/modules/100/rtkit/lang_ext /var/lib/selinux/mls/active/modules/100/rwho /var/lib/selinux/mls/active/modules/100/rwho/cil /var/lib/selinux/mls/active/modules/100/rwho/hll /var/lib/selinux/mls/active/modules/100/rwho/lang_ext /var/lib/selinux/mls/active/modules/100/samba /var/lib/selinux/mls/active/modules/100/samba/cil /var/lib/selinux/mls/active/modules/100/samba/hll /var/lib/selinux/mls/active/modules/100/samba/lang_ext /var/lib/selinux/mls/active/modules/100/sambagui /var/lib/selinux/mls/active/modules/100/sambagui/cil /var/lib/selinux/mls/active/modules/100/sambagui/hll /var/lib/selinux/mls/active/modules/100/sambagui/lang_ext /var/lib/selinux/mls/active/modules/100/sasl /var/lib/selinux/mls/active/modules/100/sasl/cil /var/lib/selinux/mls/active/modules/100/sasl/hll /var/lib/selinux/mls/active/modules/100/sasl/lang_ext /var/lib/selinux/mls/active/modules/100/screen /var/lib/selinux/mls/active/modules/100/screen/cil /var/lib/selinux/mls/active/modules/100/screen/hll /var/lib/selinux/mls/active/modules/100/screen/lang_ext /var/lib/selinux/mls/active/modules/100/secadm /var/lib/selinux/mls/active/modules/100/secadm/cil /var/lib/selinux/mls/active/modules/100/secadm/hll /var/lib/selinux/mls/active/modules/100/secadm/lang_ext /var/lib/selinux/mls/active/modules/100/selinuxutil /var/lib/selinux/mls/active/modules/100/selinuxutil/cil /var/lib/selinux/mls/active/modules/100/selinuxutil/hll /var/lib/selinux/mls/active/modules/100/selinuxutil/lang_ext /var/lib/selinux/mls/active/modules/100/sendmail /var/lib/selinux/mls/active/modules/100/sendmail/cil /var/lib/selinux/mls/active/modules/100/sendmail/hll /var/lib/selinux/mls/active/modules/100/sendmail/lang_ext /var/lib/selinux/mls/active/modules/100/setrans /var/lib/selinux/mls/active/modules/100/setrans/cil /var/lib/selinux/mls/active/modules/100/setrans/hll /var/lib/selinux/mls/active/modules/100/setrans/lang_ext /var/lib/selinux/mls/active/modules/100/setroubleshoot /var/lib/selinux/mls/active/modules/100/setroubleshoot/cil /var/lib/selinux/mls/active/modules/100/setroubleshoot/hll /var/lib/selinux/mls/active/modules/100/setroubleshoot/lang_ext /var/lib/selinux/mls/active/modules/100/seunshare /var/lib/selinux/mls/active/modules/100/seunshare/cil /var/lib/selinux/mls/active/modules/100/seunshare/hll /var/lib/selinux/mls/active/modules/100/seunshare/lang_ext /var/lib/selinux/mls/active/modules/100/shorewall /var/lib/selinux/mls/active/modules/100/shorewall/cil /var/lib/selinux/mls/active/modules/100/shorewall/hll /var/lib/selinux/mls/active/modules/100/shorewall/lang_ext /var/lib/selinux/mls/active/modules/100/slocate /var/lib/selinux/mls/active/modules/100/slocate/cil /var/lib/selinux/mls/active/modules/100/slocate/hll /var/lib/selinux/mls/active/modules/100/slocate/lang_ext /var/lib/selinux/mls/active/modules/100/smartmon /var/lib/selinux/mls/active/modules/100/smartmon/cil /var/lib/selinux/mls/active/modules/100/smartmon/hll /var/lib/selinux/mls/active/modules/100/smartmon/lang_ext /var/lib/selinux/mls/active/modules/100/snmp /var/lib/selinux/mls/active/modules/100/snmp/cil /var/lib/selinux/mls/active/modules/100/snmp/hll /var/lib/selinux/mls/active/modules/100/snmp/lang_ext /var/lib/selinux/mls/active/modules/100/snort /var/lib/selinux/mls/active/modules/100/snort/cil /var/lib/selinux/mls/active/modules/100/snort/hll /var/lib/selinux/mls/active/modules/100/snort/lang_ext /var/lib/selinux/mls/active/modules/100/sosreport /var/lib/selinux/mls/active/modules/100/sosreport/cil /var/lib/selinux/mls/active/modules/100/sosreport/hll /var/lib/selinux/mls/active/modules/100/sosreport/lang_ext /var/lib/selinux/mls/active/modules/100/soundserver /var/lib/selinux/mls/active/modules/100/soundserver/cil /var/lib/selinux/mls/active/modules/100/soundserver/hll /var/lib/selinux/mls/active/modules/100/soundserver/lang_ext /var/lib/selinux/mls/active/modules/100/spamassassin /var/lib/selinux/mls/active/modules/100/spamassassin/cil /var/lib/selinux/mls/active/modules/100/spamassassin/hll /var/lib/selinux/mls/active/modules/100/spamassassin/lang_ext /var/lib/selinux/mls/active/modules/100/squid /var/lib/selinux/mls/active/modules/100/squid/cil /var/lib/selinux/mls/active/modules/100/squid/hll /var/lib/selinux/mls/active/modules/100/squid/lang_ext /var/lib/selinux/mls/active/modules/100/ssh /var/lib/selinux/mls/active/modules/100/ssh/cil /var/lib/selinux/mls/active/modules/100/ssh/hll /var/lib/selinux/mls/active/modules/100/ssh/lang_ext /var/lib/selinux/mls/active/modules/100/sssd /var/lib/selinux/mls/active/modules/100/sssd/cil /var/lib/selinux/mls/active/modules/100/sssd/hll /var/lib/selinux/mls/active/modules/100/sssd/lang_ext /var/lib/selinux/mls/active/modules/100/staff /var/lib/selinux/mls/active/modules/100/staff/cil /var/lib/selinux/mls/active/modules/100/staff/hll /var/lib/selinux/mls/active/modules/100/staff/lang_ext /var/lib/selinux/mls/active/modules/100/stunnel /var/lib/selinux/mls/active/modules/100/stunnel/cil /var/lib/selinux/mls/active/modules/100/stunnel/hll /var/lib/selinux/mls/active/modules/100/stunnel/lang_ext /var/lib/selinux/mls/active/modules/100/su /var/lib/selinux/mls/active/modules/100/su/cil /var/lib/selinux/mls/active/modules/100/su/hll /var/lib/selinux/mls/active/modules/100/su/lang_ext /var/lib/selinux/mls/active/modules/100/sudo /var/lib/selinux/mls/active/modules/100/sudo/cil /var/lib/selinux/mls/active/modules/100/sudo/hll /var/lib/selinux/mls/active/modules/100/sudo/lang_ext /var/lib/selinux/mls/active/modules/100/sysadm /var/lib/selinux/mls/active/modules/100/sysadm/cil /var/lib/selinux/mls/active/modules/100/sysadm/hll /var/lib/selinux/mls/active/modules/100/sysadm/lang_ext /var/lib/selinux/mls/active/modules/100/sysadm_secadm /var/lib/selinux/mls/active/modules/100/sysadm_secadm/cil /var/lib/selinux/mls/active/modules/100/sysadm_secadm/hll /var/lib/selinux/mls/active/modules/100/sysadm_secadm/lang_ext /var/lib/selinux/mls/active/modules/100/sysnetwork /var/lib/selinux/mls/active/modules/100/sysnetwork/cil /var/lib/selinux/mls/active/modules/100/sysnetwork/hll /var/lib/selinux/mls/active/modules/100/sysnetwork/lang_ext /var/lib/selinux/mls/active/modules/100/sysstat /var/lib/selinux/mls/active/modules/100/sysstat/cil /var/lib/selinux/mls/active/modules/100/sysstat/hll /var/lib/selinux/mls/active/modules/100/sysstat/lang_ext /var/lib/selinux/mls/active/modules/100/systemd /var/lib/selinux/mls/active/modules/100/systemd/cil /var/lib/selinux/mls/active/modules/100/systemd/hll /var/lib/selinux/mls/active/modules/100/systemd/lang_ext /var/lib/selinux/mls/active/modules/100/tcpd /var/lib/selinux/mls/active/modules/100/tcpd/cil /var/lib/selinux/mls/active/modules/100/tcpd/hll /var/lib/selinux/mls/active/modules/100/tcpd/lang_ext /var/lib/selinux/mls/active/modules/100/tcsd /var/lib/selinux/mls/active/modules/100/tcsd/cil /var/lib/selinux/mls/active/modules/100/tcsd/hll /var/lib/selinux/mls/active/modules/100/tcsd/lang_ext /var/lib/selinux/mls/active/modules/100/telepathy /var/lib/selinux/mls/active/modules/100/telepathy/cil /var/lib/selinux/mls/active/modules/100/telepathy/hll /var/lib/selinux/mls/active/modules/100/telepathy/lang_ext /var/lib/selinux/mls/active/modules/100/telnet /var/lib/selinux/mls/active/modules/100/telnet/cil /var/lib/selinux/mls/active/modules/100/telnet/hll /var/lib/selinux/mls/active/modules/100/telnet/lang_ext /var/lib/selinux/mls/active/modules/100/tftp /var/lib/selinux/mls/active/modules/100/tftp/cil /var/lib/selinux/mls/active/modules/100/tftp/hll /var/lib/selinux/mls/active/modules/100/tftp/lang_ext /var/lib/selinux/mls/active/modules/100/tgtd /var/lib/selinux/mls/active/modules/100/tgtd/cil /var/lib/selinux/mls/active/modules/100/tgtd/hll /var/lib/selinux/mls/active/modules/100/tgtd/lang_ext /var/lib/selinux/mls/active/modules/100/thumb /var/lib/selinux/mls/active/modules/100/thumb/cil /var/lib/selinux/mls/active/modules/100/thumb/hll /var/lib/selinux/mls/active/modules/100/thumb/lang_ext /var/lib/selinux/mls/active/modules/100/tmpreaper /var/lib/selinux/mls/active/modules/100/tmpreaper/cil /var/lib/selinux/mls/active/modules/100/tmpreaper/hll /var/lib/selinux/mls/active/modules/100/tmpreaper/lang_ext /var/lib/selinux/mls/active/modules/100/tor /var/lib/selinux/mls/active/modules/100/tor/cil /var/lib/selinux/mls/active/modules/100/tor/hll /var/lib/selinux/mls/active/modules/100/tor/lang_ext /var/lib/selinux/mls/active/modules/100/tuned /var/lib/selinux/mls/active/modules/100/tuned/cil /var/lib/selinux/mls/active/modules/100/tuned/hll /var/lib/selinux/mls/active/modules/100/tuned/lang_ext /var/lib/selinux/mls/active/modules/100/tvtime /var/lib/selinux/mls/active/modules/100/tvtime/cil /var/lib/selinux/mls/active/modules/100/tvtime/hll /var/lib/selinux/mls/active/modules/100/tvtime/lang_ext /var/lib/selinux/mls/active/modules/100/udev /var/lib/selinux/mls/active/modules/100/udev/cil /var/lib/selinux/mls/active/modules/100/udev/hll /var/lib/selinux/mls/active/modules/100/udev/lang_ext /var/lib/selinux/mls/active/modules/100/ulogd /var/lib/selinux/mls/active/modules/100/ulogd/cil /var/lib/selinux/mls/active/modules/100/ulogd/hll /var/lib/selinux/mls/active/modules/100/ulogd/lang_ext /var/lib/selinux/mls/active/modules/100/uml /var/lib/selinux/mls/active/modules/100/uml/cil /var/lib/selinux/mls/active/modules/100/uml/hll /var/lib/selinux/mls/active/modules/100/uml/lang_ext /var/lib/selinux/mls/active/modules/100/unlabelednet /var/lib/selinux/mls/active/modules/100/unlabelednet/cil /var/lib/selinux/mls/active/modules/100/unlabelednet/hll /var/lib/selinux/mls/active/modules/100/unlabelednet/lang_ext /var/lib/selinux/mls/active/modules/100/unprivuser /var/lib/selinux/mls/active/modules/100/unprivuser/cil /var/lib/selinux/mls/active/modules/100/unprivuser/hll /var/lib/selinux/mls/active/modules/100/unprivuser/lang_ext /var/lib/selinux/mls/active/modules/100/updfstab /var/lib/selinux/mls/active/modules/100/updfstab/cil /var/lib/selinux/mls/active/modules/100/updfstab/hll /var/lib/selinux/mls/active/modules/100/updfstab/lang_ext /var/lib/selinux/mls/active/modules/100/usbmodules /var/lib/selinux/mls/active/modules/100/usbmodules/cil /var/lib/selinux/mls/active/modules/100/usbmodules/hll /var/lib/selinux/mls/active/modules/100/usbmodules/lang_ext /var/lib/selinux/mls/active/modules/100/userdomain /var/lib/selinux/mls/active/modules/100/userdomain/cil /var/lib/selinux/mls/active/modules/100/userdomain/hll /var/lib/selinux/mls/active/modules/100/userdomain/lang_ext /var/lib/selinux/mls/active/modules/100/userhelper /var/lib/selinux/mls/active/modules/100/userhelper/cil /var/lib/selinux/mls/active/modules/100/userhelper/hll /var/lib/selinux/mls/active/modules/100/userhelper/lang_ext /var/lib/selinux/mls/active/modules/100/usermanage /var/lib/selinux/mls/active/modules/100/usermanage/cil /var/lib/selinux/mls/active/modules/100/usermanage/hll /var/lib/selinux/mls/active/modules/100/usermanage/lang_ext /var/lib/selinux/mls/active/modules/100/usernetctl /var/lib/selinux/mls/active/modules/100/usernetctl/cil /var/lib/selinux/mls/active/modules/100/usernetctl/hll /var/lib/selinux/mls/active/modules/100/usernetctl/lang_ext /var/lib/selinux/mls/active/modules/100/uucp /var/lib/selinux/mls/active/modules/100/uucp/cil /var/lib/selinux/mls/active/modules/100/uucp/hll /var/lib/selinux/mls/active/modules/100/uucp/lang_ext /var/lib/selinux/mls/active/modules/100/virt /var/lib/selinux/mls/active/modules/100/virt/cil /var/lib/selinux/mls/active/modules/100/virt/hll /var/lib/selinux/mls/active/modules/100/virt/lang_ext /var/lib/selinux/mls/active/modules/100/vmware /var/lib/selinux/mls/active/modules/100/vmware/cil /var/lib/selinux/mls/active/modules/100/vmware/hll /var/lib/selinux/mls/active/modules/100/vmware/lang_ext /var/lib/selinux/mls/active/modules/100/vpn /var/lib/selinux/mls/active/modules/100/vpn/cil /var/lib/selinux/mls/active/modules/100/vpn/hll /var/lib/selinux/mls/active/modules/100/vpn/lang_ext /var/lib/selinux/mls/active/modules/100/w3c /var/lib/selinux/mls/active/modules/100/w3c/cil /var/lib/selinux/mls/active/modules/100/w3c/hll /var/lib/selinux/mls/active/modules/100/w3c/lang_ext /var/lib/selinux/mls/active/modules/100/webadm /var/lib/selinux/mls/active/modules/100/webadm/cil /var/lib/selinux/mls/active/modules/100/webadm/hll /var/lib/selinux/mls/active/modules/100/webadm/lang_ext /var/lib/selinux/mls/active/modules/100/webalizer /var/lib/selinux/mls/active/modules/100/webalizer/cil /var/lib/selinux/mls/active/modules/100/webalizer/hll /var/lib/selinux/mls/active/modules/100/webalizer/lang_ext /var/lib/selinux/mls/active/modules/100/wine /var/lib/selinux/mls/active/modules/100/wine/cil /var/lib/selinux/mls/active/modules/100/wine/hll /var/lib/selinux/mls/active/modules/100/wine/lang_ext /var/lib/selinux/mls/active/modules/100/wireshark /var/lib/selinux/mls/active/modules/100/wireshark/cil /var/lib/selinux/mls/active/modules/100/wireshark/hll /var/lib/selinux/mls/active/modules/100/wireshark/lang_ext /var/lib/selinux/mls/active/modules/100/wm /var/lib/selinux/mls/active/modules/100/wm/cil /var/lib/selinux/mls/active/modules/100/wm/hll /var/lib/selinux/mls/active/modules/100/wm/lang_ext /var/lib/selinux/mls/active/modules/100/xen /var/lib/selinux/mls/active/modules/100/xen/cil /var/lib/selinux/mls/active/modules/100/xen/hll /var/lib/selinux/mls/active/modules/100/xen/lang_ext /var/lib/selinux/mls/active/modules/100/xguest /var/lib/selinux/mls/active/modules/100/xguest/cil /var/lib/selinux/mls/active/modules/100/xguest/hll /var/lib/selinux/mls/active/modules/100/xguest/lang_ext /var/lib/selinux/mls/active/modules/100/xserver /var/lib/selinux/mls/active/modules/100/xserver/cil /var/lib/selinux/mls/active/modules/100/xserver/hll /var/lib/selinux/mls/active/modules/100/xserver/lang_ext /var/lib/selinux/mls/active/modules/100/zabbix /var/lib/selinux/mls/active/modules/100/zabbix/cil /var/lib/selinux/mls/active/modules/100/zabbix/hll /var/lib/selinux/mls/active/modules/100/zabbix/lang_ext /var/lib/selinux/mls/active/modules/100/zebra /var/lib/selinux/mls/active/modules/100/zebra/cil /var/lib/selinux/mls/active/modules/100/zebra/hll /var/lib/selinux/mls/active/modules/100/zebra/lang_ext /var/lib/selinux/mls/active/modules/100/zosremote /var/lib/selinux/mls/active/modules/100/zosremote/cil /var/lib/selinux/mls/active/modules/100/zosremote/hll /var/lib/selinux/mls/active/modules/100/zosremote/lang_ext /var/lib/selinux/mls/active/modules/400/extra_varrun /var/lib/selinux/mls/active/modules_checksum /var/lib/selinux/mls/active/policy.kern /var/lib/selinux/mls/active/policy.linked /var/lib/selinux/mls/active/seusers /var/lib/selinux/mls/active/seusers.linked /var/lib/selinux/mls/active/users_extra /var/lib/selinux/mls/active/users_extra.linked /var/lib/selinux/mls/semanage.read.LOCK /var/lib/selinux/mls/semanage.trans.LOCK
Generated by rpm2html 1.8.1
Fabrice Bellet, Tue Oct 21 07:22:22 2025