selinux-policy-38.33-3.red80> K KtĉH2!c31^ WggŠmsupport@red-soft.ru  WgjBk=mUkY%ȀUh:yb7˜ԏLE?5d  < EKR       $   L   V   `       <\()* +,-8 9L : >D?L@TD\Gd H I XY\< ]d ^ bdOeTfYl\tx u vw x$ yLCselinux-policy38.333.red80SELinux policy configurationSELinux core policy package. Originally based off of reference policy, the policy has been adjusted to provide support for RED OS.gQstapel80.red-soft.rudredosredsoftGPL-2.0-or-laterRED SOFTUnspecifiedhttps://github.com/fedora-selinux/selinux-policylinuxnoarch if [ $1 -eq 1 ] && [ -x "/usr/lib/systemd/systemd-update-helper" ]; then # Initial installation /usr/lib/systemd/systemd-update-helper install-system-units selinux-check-proper-disable.service || : fi if [ ! -s /etc/selinux/config ]; then # # New install so we will default to targeted policy # echo " # This file controls the state of SELinux on the system. # SELINUX= can take one of these three values: # enforcing - SELinux security policy is enforced. # permissive - SELinux prints warnings instead of enforcing. # disabled - No SELinux policy is loaded. # See also: # https://docs.fedoraproject.org/en-US/quick-docs/getting-started-with-selinux/#getting-started-with-selinux-selinux-states-and-modes # # NOTE: In earlier RED OS kernel builds, SELINUX=disabled would also # fully disable SELinux during boot. If you need a system with SELinux # fully disabled instead of SELinux running with no policy loaded, you # need to pass selinux=0 to the kernel command line. You can use grubby # to persistently set the bootloader to boot with selinux=0: # # grubby --update-kernel ALL --args selinux=0 # # To revert back to SELinux enabled: # # grubby --update-kernel ALL --remove-args selinux # SELINUX=enforcing # SELINUXTYPE= can take one of these three values: # targeted - Targeted processes are protected, # minimum - Modification of targeted policy. Only selected processes are protected. # mls - Multi Level Security protection. SELINUXTYPE=targeted " > /etc/selinux/config ln -sf ../selinux/config /etc/sysconfig/selinux /usr/sbin/restorecon /etc/selinux/config 2> /dev/null || : else . /etc/selinux/config fi exit 0 if [ $1 -eq 0 ] && [ -x "/usr/lib/systemd/systemd-update-helper" ]; then # Package removal, not upgrade /usr/lib/systemd/systemd-update-helper remove-system-units selinux-check-proper-disable.service || : fi if [ $1 = 0 ]; then /usr/sbin/setenforce 0 2> /dev/null if [ ! -s /etc/selinux/config ]; then echo "SELINUX=disabled" > /etc/selinux/config else sed -i 's/^SELINUX=.*/SELINUX=disabled/g' /etc/selinux/config fi fi exit 0FYA큤A큤AAgRgQgQgRgRgQgRf(DgRgRG2df4e45f86204f4676e8456556c67bf9425dbff740dcbe7d423ad901f785bb3bb3240fd7982059a65867f81ebab303d478bd1c29b1559bdcb2ba70781916b1ae8a0beca7f576064bfe85859d53e85dfc31157974115cac99b4e52ae31b77b185204d8eff92f95aac4df6c8122bc1505f468f3a901e5a4cc08940e0ede1938994Q@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootselinux-policy-38.33-3.red80.src.rpmconfig(selinux-policy)rpm_macro(_file_context_file)rpm_macro(_file_context_file_pre)rpm_macro(_file_custom_defined_booleans)rpm_macro(_file_custom_defined_booleans_tmp)rpm_macro(_selinux_policy_version)rpm_macro(_selinux_store_path)rpm_macro(_selinux_store_policy_path)rpm_macro(selinux_modules_install)rpm_macro(selinux_modules_uninstall)rpm_macro(selinux_relabel_post)rpm_macro(selinux_relabel_pre)rpm_macro(selinux_requires)rpm_macro(selinux_set_booleans)rpm_macro(selinux_unset_booleans)selinux-policyselinux-policy-base      /bin/awk/bin/sh/bin/sh/bin/sh/bin/sh/usr/bin/sha512sumconfig(selinux-policy)policycoreutilsrpm-plugin-selinuxrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsZstd)selinux-policy-any38.33-3.red803.5-13.0.4-14.6.0-14.0-15.4.18-138.33-3.red804.18.2/usr/sbin/selinuxenabled && /usr/sbin/semodule -nB exit 0pcre2g|f@fU@f! @f e@e\e9@e ddgdd@Oleg Sviridov - 38.33-3Oleg Sviridov - 38.33-2Oleg Sviridov - 38.33-1Oleg Sviridov - 38.32-2Oleg Sviridov - 38.32-1Oleg Sviridov - 38.31-1Oleg Sviridov - 38.29-2Alexandr Subbotin - 0:38.29-1Vladislav Mitin - 0:3.14.5-54Anton Fadeev - 0:3.14.5-53Anton Fadeev - 0:3.14.5-52Anton Fadeev - 0:3.14.5-51- Update policy for haproxyd - Dontaudit firewalld dac_raed_search capability - Allow webadm_t use generic ptys - Dontaudit webadm_t read passwd - Allow xdm_t to watch and watch_reads mount_var_run_t- Allow qemu-ga read vm sysctls - Allow svirt_t read vm sysctls - Allow svirt_tcg_t read vm sysctls - Allow svirt_tcg_t map svirt_image_t files- Allow smbd_t to watch user_home_dir_t if samba_enable_home_dirs is on - Allow keyutils-dns-resolver connect to the system log service - dontaudit execmem for modemmanager - Allow alsa get attributes filesystems with extended attributes - Allow xdm_t read unconfined services state- Allow mongodb search nfs dir- update to 38.32 - Fix NM dispatcher script runing with dhcp-client - Dont audit winbind_rpcd_t write urandom - Dont audit winbind_t write urandom- update to 38.31- Allow cifs.upcall open accesses to user_tmp_t- Update to 38.29- add policy for ip-client- Fix RO_0004_allow_systemd_machined_userdbd_runtime_sock_files.patch - Enable daemons_enable_cluster_mode by default- Add watch, watch_sb, watch_mount to access_vector- Allow local_login_t and passwd_t getattr proc/bin/sh/bin/sh/bin/sh/bin/sh 38.33-3.red8038.33-3.red8038.33-3.red80 selinuxconfigselinuxmacros.selinux-policyselinux-check-proper-disable.serviceselinux-policy.confselinux-policyCOPYINGselinuxpackages/etc//etc/selinux//etc/sysconfig//usr/lib/rpm/macros.d//usr/lib/systemd/system//usr/lib/tmpfiles.d//usr/share/licenses//usr/share/licenses/selinux-policy//usr/share//usr/share/selinux/-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -U_FORTIFY_SOURCE -Wp,-U_FORTIFY_SOURCE -Wp,-D_FORTIFY_SOURCE=3 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redsoft/redsoft-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redsoft/redsoft-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpiozstd19noarch-redsoft-linux-gnudirectoryemptyUnicode text, UTF-8 textASCII textPPPPPPPPP P P P P Pselinux-policy-targetedutf-84604ffc04ae9bf3ab068def8f982a15beea7b4ade13e53413e9b98d7c0d644857592d6a92ba2f1bb5b664976b2d22ae82ef9e16e7ac414ea76f820c9a2aa8d45?@(/h H(?sCaN/exR ]?Ʒ֏PjN K/;Tb Xxl  R `ʮHxUD"i&H$8xʆ3Nd6e1D$4H4M0Ft852XPS0GHri k!CS 6~`}5$>eM% ^"bW<}OX!`21k ?>:Q2ȘT+djh*?!mtJȆ,CLP<& yDbxZ *(^F!I+cvެ pkﹿ1R;aZƾ DN.!a`tqVɴY`̯/ilࠡJ+ 0 ,- , +4}aJ~SgLI?=%nG&~whЖ1W}F@aaW fk*`$G:?@7vDu<ΦV;nvbkcb w]JL;Xk\EGAeg'Qe`pnr *e~-g'h/뾇 8o BɁ18=|ٚOuD@e([ ˆP -wRYPDdIJf(Tɡ4vMhb8&K!]`%0Hd4#@KC}\0+[e%x,"Fxh=A gjdQE *:co'$PAk#WzczJew4%KTt2C] C.Ldyk ˰!.ű' I>rTۢU[B7d'k&/>&ԭF>Ck$N몝79t)#c]JzȢXN(-a6;J0meъ=p$@Y.Z8 gPZcnz9[C;N,өO%h 9]wÌ%)}bҿ//tLoOli$'1Y]J 'KN(Ai[eS W"?81F>YB9}'cw]>v-GJȠ`&"Yך݄IIJAKJݟu7՗XCg8Ha$d:A^d-'ԧ#  ,TUy Qp; pҺHe% gV k,-wLhtMfgTBl}r=`;ѝ`4 ;sl% Dt #,A鳥;'YXPXPp^ 6iQ>>qO?LX Cih\2& cQ\p8.*Sq(OGdd0֥tVrR@mPAmC.Sa98 *p8˱MqlT`A'8u?jPԓz~y믞NNkK{ 5"Ohu½5HU-7v5 NP|MPY_ב*6!cZ!"l4scu%Mt>'MKs$tWX;Iz$>Y?;9?eN:6٤' M…$SiE3c@ &8OYT M! 9 0 0 muI rGg'xG+ƸwiAGĸ_x\릻ˆP6*h&P1\u׬x㪗C n8~}O"(XoC2CMT.>_5^dȫ㖯pIl˶q?eIGؓA:ӛ%`u:,)D!ʬ]8X1 WQeb+UW' N0w ,fAsK;`<=2'X3,s/SeN/en*FaR0yK-@qxӰSQTw{sj!JкE3^Joܡ1iЕWz`/#fɂ #V1,VୟK.3@Ih>ۂ.Ay-_G9ZqDz8M{OļczPZ+E0;RYr)U'6ɟ@03\ϪN `ltӿ9$hhX ;Iݽk-w[fzG>w$C`3Iɻ.H>;6]]=Ǥ:F%xXpkm9'Y㔈H,{x?gA1cy 4hGFrO )ahwGD ewwLծ-@BOeY+$DKUӠ#=xKoA^rC׃Np a۶I"XӕA QV#}J!Rr'~R 7B9])飤+Zu=A㔲tX;F#f9*wFD]Jޫ@3=.GC߄6pgQX7?k.Zx]1#9&صd+?nPUqDP*aaO<#C 3ծlq5(Jl_RSCE;iAByM9zTiZJ}99˛bf~4aL+Y܇fȺB#.j׀ A y %s/덺WmdѴbՂ+qĮ>2|pC<1P/m-O҂uCj۫H8$TՔ!w+%70=%0qVw'8i[BԪ'u RC}pQ-# 2$ո P:&'̱A1$$N-Z`™n/ pM 8CW9O/$(^o/pot2QP|w?VkM:g`#gp/]钦wr wO8wG.jt *I߁LX`e +} VcORAFLiwXs89ǣEU^J5&BMW' Qx=z`>Lk u&lpkNoYw0Tsz&RaoޏjdGdqbspE"([)hdwWcf$@{WAӋQ4j+`󝃐A&:qH:ݟ\؊yOT \ nɈB8}Wo@JKԬ//R{.62p˚eP5@G'T$.!+Pa1ТoZE]MކwDd|zAޑ"X~H 6n# fUB\ ij\Kc =Al@j2E0M\;'ϧ3bSHkd7b)3VH0SLO|w\RYP{+p ɿ&8.=pݡԭ\$Cb*DB~|a%{!&xT{~-Έ~jk<\-(n+j(Av'&РQ9ݺׂ` G~1!ha+P8=nX(bdz֐ǀN-\_1_>TPĴ7DkYSvOyv+0PZqdB8䍁hc6 a.07+dpWdT,g MUm%xw 9f8xSG!T52o0F!n*axa%͘rq> $)%`qIAiv$Z+3u!8͹@E0 oG G| ^SAE\2Ȫ_1 $k}W@1Wyk%:M *$-{bAaNAhH,A==@k2S <" 1Т5Y#F+8rIdfs;z͹HצճDXk4b? ir"Mg$u9y ȑHKI! R@h h5OCH-܍8 ʢUֵ>rشF gB,aL=Eôi#ӐĩgbI 9@4\HLH8YP!oôipSta5(jwL[%}5?|7 0b$tޞ6Sc<ВY{ K a#} ܖ4AyE9ToN=F.t[LmOJ>ĦQhA C/oNi2#O~S}0c(/Q+02燉 r+=14/=f7]qԵꅄ! i;%Z>@|::a,_)>թ|++\WhǧT@$wu(\MW_0?g>Pij 'Unx]V>XO`[q;wp`HiX?̊_J8y8=RR3GX+ttVWT&md 94|c/Vo'AG:}֝!@J x*Yq1~CQF&n>|_ PsnΑMHLK/8L])w.Ϗr6c7ANrtG=Q 8[zbDUBRIM_;Z0g8+?#dF ^|bDM&n ,dSQ{)x5`#A:yGw {N: L"X|T|JCd@ 7[+Aǡ@ЯBO%I&l*d[O.;[^3-?>+3@6T规[zYJ/R pZ,P1F6z;>:۟޾7yKuS{XSˁ٫C`wqWi+u o/tC\EՒfPl˅ZQuhGr~V5L7F"+? N@Y`:}pf4W=~v 0OyǙrV4,&툦)< >o΂A!uEJ4?ڄ֬#nc;8A{[* j?Uy/ؼ5@r"3{Z ج( xeh׷5O%UGE䖢lE-+o!ŜB<2x/+} .7`F0tԥO vwPgINӔ 8 $*"io2d