]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
14 years agoadd pulseaudio from dan.
Chris PeBenito [Tue, 21 Jul 2009 14:05:38 +0000 (10:05 -0400)] 
add pulseaudio from dan.

14 years agoppp patch from dan
Chris PeBenito [Mon, 20 Jul 2009 19:41:19 +0000 (15:41 -0400)] 
ppp patch from dan

14 years agokerberos patch from dan
Chris PeBenito [Mon, 20 Jul 2009 19:41:08 +0000 (15:41 -0400)] 
kerberos patch from dan

14 years agodnsmasq patch from dan.
Chris PeBenito [Mon, 20 Jul 2009 19:40:57 +0000 (15:40 -0400)] 
dnsmasq patch from dan.

14 years agodhcp patch from dan
Chris PeBenito [Mon, 20 Jul 2009 19:40:41 +0000 (15:40 -0400)] 
dhcp patch from dan

14 years agopolicykit.if whitespace fix
Chris PeBenito [Mon, 20 Jul 2009 15:37:22 +0000 (11:37 -0400)] 
policykit.if whitespace fix

14 years ago4 patches from dan.
Chris PeBenito [Mon, 20 Jul 2009 15:34:46 +0000 (11:34 -0400)] 
4 patches from dan.

14 years agoadd kismet and pulseaudio ports. fix sorting of ports.
Chris PeBenito [Mon, 20 Jul 2009 15:17:31 +0000 (11:17 -0400)] 
add kismet and pulseaudio ports.  fix sorting of ports.

14 years agochangelog for previous commit
Chris PeBenito [Mon, 20 Jul 2009 15:16:22 +0000 (11:16 -0400)] 
changelog for previous commit

14 years agoadd policykit from dan.
Chris PeBenito [Mon, 20 Jul 2009 15:15:09 +0000 (11:15 -0400)] 
add policykit from dan.

14 years agofix bad varnishd interface names
Chris PeBenito [Mon, 20 Jul 2009 13:44:25 +0000 (09:44 -0400)] 
fix bad varnishd interface names

14 years agomodule version bump for f2583aa83b4f5c0081ac4caebffcc0a29401cf96
Chris PeBenito [Wed, 15 Jul 2009 13:30:08 +0000 (09:30 -0400)] 
module version bump for f2583aa83b4f5c0081ac4caebffcc0a29401cf96

14 years agoRemove duplicate distro_redhat context
Manoj Srivastava [Tue, 14 Jul 2009 17:17:44 +0000 (12:17 -0500)] 
Remove duplicate distro_redhat context

A recent update added an generic context for the lock files, so the
entry in distro_redhat can be removed.

Signed-off-by: Manoj Srivastava <srivasta@debian.org>
Signed-off-by: Chris PeBenito <cpebenito@tresys.com>
14 years ago5 patches from dan
Chris PeBenito [Tue, 14 Jul 2009 14:30:22 +0000 (10:30 -0400)] 
5 patches from dan

14 years agothree debian patches from manoj
Chris PeBenito [Tue, 14 Jul 2009 13:05:59 +0000 (09:05 -0400)] 
three debian patches from manoj

14 years agotrunk: fix typo in guest role decl.
Chris PeBenito [Wed, 8 Jul 2009 15:23:29 +0000 (15:23 +0000)] 
trunk: fix typo in guest role decl.

14 years agotrunk: update policycaps comments for sock_file open perm.
Chris PeBenito [Wed, 1 Jul 2009 13:34:54 +0000 (13:34 +0000)] 
trunk: update policycaps comments for sock_file open perm.

14 years agotrunk: 3 patches from dan.
Chris PeBenito [Tue, 30 Jun 2009 19:27:21 +0000 (19:27 +0000)] 
trunk: 3 patches from dan.

14 years agotrunk: add missing varnish port.
Chris PeBenito [Tue, 30 Jun 2009 17:48:15 +0000 (17:48 +0000)] 
trunk: add missing varnish port.

14 years agotrunk: pads from dan.
Chris PeBenito [Tue, 30 Jun 2009 15:03:20 +0000 (15:03 +0000)] 
trunk: pads from dan.

14 years agotrunk: prelude patch from dan.
Chris PeBenito [Tue, 30 Jun 2009 14:44:50 +0000 (14:44 +0000)] 
trunk: prelude patch from dan.

14 years agotrunk: varnishd from dan.
Chris PeBenito [Tue, 30 Jun 2009 13:49:53 +0000 (13:49 +0000)] 
trunk: varnishd from dan.

14 years agotrunk: whitespace fixes
Chris PeBenito [Fri, 26 Jun 2009 14:40:13 +0000 (14:40 +0000)] 
trunk: whitespace fixes

14 years agotrunk: 7 patches from dan.
Chris PeBenito [Fri, 26 Jun 2009 13:22:39 +0000 (13:22 +0000)] 
trunk: 7 patches from dan.

14 years agotrunk: nis patch from dan.
Chris PeBenito [Thu, 25 Jun 2009 15:16:29 +0000 (15:16 +0000)] 
trunk: nis patch from dan.

14 years agotrunk: add sssd from dan.
Chris PeBenito [Mon, 22 Jun 2009 15:33:21 +0000 (15:33 +0000)] 
trunk: add sssd from dan.

14 years agotrunk: remove unnecessary semicolons after interface/template calls.
Chris PeBenito [Fri, 19 Jun 2009 13:52:33 +0000 (13:52 +0000)] 
trunk: remove unnecessary semicolons after interface/template calls.

14 years agotrunk: Greylist milter from Paul Howarth.
Chris PeBenito [Thu, 18 Jun 2009 14:36:35 +0000 (14:36 +0000)] 
trunk: Greylist milter from Paul Howarth.

14 years agotrunk: Allow unix_update to change the security attributes associate with files so
Chris PeBenito [Thu, 18 Jun 2009 13:57:26 +0000 (13:57 +0000)] 
trunk: Allow unix_update to change the security attributes associate with files so
that it can properly create the shadow file. Also allow it to read from
urandom so that it can add salt to the password hash.

14 years agotrunk: Misc fixes for unix_update from Brandon Whalen.
Chris PeBenito [Thu, 18 Jun 2009 13:36:40 +0000 (13:36 +0000)] 
trunk: Misc fixes for unix_update from Brandon Whalen.

14 years agotrunk: Add x_device permissions for XI2 functions, from Eamon Walsh.
Chris PeBenito [Thu, 18 Jun 2009 13:07:23 +0000 (13:07 +0000)] 
trunk: Add x_device permissions for XI2 functions, from Eamon Walsh.

14 years agotrunk: 10 patches from dan.
Chris PeBenito [Fri, 12 Jun 2009 19:44:10 +0000 (19:44 +0000)] 
trunk: 10 patches from dan.

14 years agotrunk: 1 patch from dan.
Chris PeBenito [Fri, 12 Jun 2009 15:30:15 +0000 (15:30 +0000)] 
trunk: 1 patch from dan.

14 years agotrunk: 6 patches from dan.
Chris PeBenito [Thu, 11 Jun 2009 15:00:48 +0000 (15:00 +0000)] 
trunk: 6 patches from dan.

14 years agotrunk: 2 patches from dan.
Chris PeBenito [Mon, 8 Jun 2009 17:18:26 +0000 (17:18 +0000)] 
trunk: 2 patches from dan.

15 years agotrunk: MLS constraints for the x_selection class, from Eamon Walsh.
Chris PeBenito [Fri, 5 Jun 2009 13:36:19 +0000 (13:36 +0000)] 
trunk: MLS constraints for the x_selection class, from Eamon Walsh.

15 years agotrunk: add gpsd from miroslav grepl
Chris PeBenito [Tue, 2 Jun 2009 14:28:40 +0000 (14:28 +0000)] 
trunk: add gpsd from miroslav grepl

15 years agotrunk: missed UBAC change: update securetty_types for merged user tty type.
Chris PeBenito [Mon, 1 Jun 2009 17:41:34 +0000 (17:41 +0000)] 
trunk: missed UBAC change: update securetty_types for merged user tty type.

15 years agotrunk: 9 patches from dan.
Chris PeBenito [Mon, 1 Jun 2009 16:03:42 +0000 (16:03 +0000)] 
trunk: 9 patches from dan.

15 years agotrunk: add libjackserver.so textrel fc.
Chris PeBenito [Mon, 1 Jun 2009 13:04:40 +0000 (13:04 +0000)] 
trunk: add libjackserver.so textrel fc.

15 years agotrunk:
Chris PeBenito [Fri, 22 May 2009 13:37:32 +0000 (13:37 +0000)] 
trunk:
The attached patch allows unprivileged clients to export from or import
to the largeobject owned by themselves.

The current security policy does not allow them to import/export any
largeobjects without any clear reason.

NOTE: Export of the largeobject means that it dumps whole of the
largeobject into a local file, so SE-PostgreSQL checks both of
db_blob:{read export} on the largeobject and file:{write} on the
local file. Import is a reversal behavior.

KaiGai Kohei

15 years agotrunk:
Chris PeBenito [Thu, 21 May 2009 11:49:33 +0000 (11:49 +0000)] 
trunk:
The attached patch fixes incorrect behavior in sepgsql_enable_users_ddl.

The current policy allows users/unprivs to run ALTER TABLE statement
unconditionally, because db_table/db_column:{setattr} is allowed outside
of the boolean. It should be moved to conditional section.

In addition, they are also allowed to db_procedure:{create drop setattr}
for xxxx_sepgsql_proc_exec_t, but it means we allows them to create, drop
or alter definition of the functions unconditionally. So, it also should
be moved to conditional section.

The postgresql.te allows sepgsql_client_type to modify sepgsql_table_t
and sepgsql_sysobj_t when sepgsql_enable_users_ddl is enabled, but
it should not be allowed.

KaiGai Kohei

15 years agotrunk:
Chris PeBenito [Thu, 21 May 2009 11:28:14 +0000 (11:28 +0000)] 
trunk:
OK, the attached patch adds the following types for unprivileged clients.
 - unpriv_sepgsql_table_t
 - unpriv_sepgsql_sysobj_t
 - unpriv_sepgsql_proc_exec_t
 - unpriv_sepgsql_blob_t

These types are the default for unprivileged and unprefixed domains,
such as httpd_t and others.

In addition, TYPE_TRANSITION rules are moved to outside of tunable
of the sepgsql_enable_users_ddl. IIRC, it was enclosed within the
tunable because UBAC domains (user_t and so on) were allowed to
create sepgsql_table_t, and its default was pointed to this type
when sepgsql_enable_users_ddl is disabled.
However, it has different meanings now, so the TYPE_TRANSITION rules
should be unconditional.

KaiGai Kohei

15 years agotrunk: 4 patches from dan.
Chris PeBenito [Thu, 14 May 2009 14:41:50 +0000 (14:41 +0000)] 
trunk: 4 patches from dan.

15 years agotrunk: whitespace fix for squid.fc.
Chris PeBenito [Mon, 11 May 2009 12:07:07 +0000 (12:07 +0000)] 
trunk: whitespace fix for squid.fc.

15 years agose-postgresql update from kaigai
Chris PeBenito [Thu, 7 May 2009 12:35:32 +0000 (12:35 +0000)] 
se-postgresql update from kaigai
- rework: Add a comment of "deprecated" for deprecated permissions.
- bugfix: MCS policy did not constrain the following permissions.
    db_database:{getattr}
    db_table:{getattr lock}
    db_column:{getattr}
    db_procedure:{drop getattr setattr}
    db_blob:{getattr import export}
- rework: db_table:{lock} is moved to reader side, because it makes
  impossible to refer read-only table with foreign-key constraint.
  (FK checks internally acquire explicit locks.)
- bugfix: some of permissions in db_procedure class are allowed
  on sepgsql_trusted_proc_t, but it is a domain, not a procedure.
  It should allow them on sepgsql_trusted_proc_exec_t.
  I also aliased sepgsql_proc_t as sepgsql_proc_exec_t to avoid
  such kind of confusion, as Chris suggested before.
- rework: we should not allow db_procedure:{install} on the
  sepgsql_trusted_proc_exec_t, because of a risk to invoke trusted
  procedure implicitly.
- bugfix: MLS policy dealt db_blob:{export} as writer-side permission,
  but it is required whrn the largeobject is refered.
- bugfix: MLS policy didn't constrain the db_procedure class.

15 years agotrunk: lircd from miroslav grepl
Chris PeBenito [Wed, 6 May 2009 15:09:46 +0000 (15:09 +0000)] 
trunk: lircd from miroslav grepl

15 years agotrunk: whitespace fixes.
Chris PeBenito [Wed, 6 May 2009 14:44:57 +0000 (14:44 +0000)] 
trunk: whitespace fixes.

15 years agotrunk: 5 patches from dan.
Chris PeBenito [Wed, 6 May 2009 14:26:20 +0000 (14:26 +0000)] 
trunk: 5 patches from dan.

15 years agotrunk: Milter state directory patch from Paul Howarth.
Chris PeBenito [Tue, 21 Apr 2009 20:40:45 +0000 (20:40 +0000)] 
trunk: Milter state directory patch from Paul Howarth.

15 years agotrunk: 5 modules from dan.
Chris PeBenito [Mon, 20 Apr 2009 19:03:15 +0000 (19:03 +0000)] 
trunk: 5 modules from dan.

15 years agotrunk: 5 patches from dan.
Chris PeBenito [Tue, 7 Apr 2009 14:09:43 +0000 (14:09 +0000)] 
trunk: 5 patches from dan.

15 years agotrunk: module version bump for previous commit.
Chris PeBenito [Fri, 3 Apr 2009 14:15:53 +0000 (14:15 +0000)] 
trunk: module version bump for previous commit.

15 years agotrunk: 3 patches from dan.
Chris PeBenito [Fri, 3 Apr 2009 14:14:43 +0000 (14:14 +0000)] 
trunk: 3 patches from dan.

15 years agotrunk: 6 patches from dan.
Chris PeBenito [Tue, 31 Mar 2009 13:40:59 +0000 (13:40 +0000)] 
trunk: 6 patches from dan.

15 years agotrunk: 14 patches from dan.
Chris PeBenito [Mon, 23 Mar 2009 14:56:43 +0000 (14:56 +0000)] 
trunk: 14 patches from dan.

15 years agotrunk: 3 patches from dan.
Chris PeBenito [Fri, 20 Mar 2009 13:58:15 +0000 (13:58 +0000)] 
trunk: 3 patches from dan.

15 years agotrunk: 6 patches from dan.
Chris PeBenito [Thu, 19 Mar 2009 17:56:10 +0000 (17:56 +0000)] 
trunk: 6 patches from dan.

15 years agotrunk: add open perm to sock_file.
Chris PeBenito [Wed, 11 Mar 2009 14:58:03 +0000 (14:58 +0000)] 
trunk: add open perm to sock_file.

15 years agotrunk: 2 patches from dan.
Chris PeBenito [Wed, 11 Mar 2009 14:19:50 +0000 (14:19 +0000)] 
trunk: 2 patches from dan.

15 years agotrunk: 4 patches from dan.
Chris PeBenito [Wed, 11 Mar 2009 13:32:23 +0000 (13:32 +0000)] 
trunk: 4 patches from dan.

15 years agotrunk: add mysql db lnk_file transition.
Chris PeBenito [Wed, 11 Mar 2009 11:59:04 +0000 (11:59 +0000)] 
trunk: add mysql db lnk_file transition.

15 years agotrunk: 5 patches from dan.
Chris PeBenito [Tue, 10 Mar 2009 19:32:04 +0000 (19:32 +0000)] 
trunk: 5 patches from dan.

15 years agotrunk: fix typo in devices file contexts.
Chris PeBenito [Thu, 5 Mar 2009 17:46:22 +0000 (17:46 +0000)] 
trunk: fix typo in devices file contexts.

15 years agotrunk: storage patch from dan.
Chris PeBenito [Thu, 5 Mar 2009 15:49:41 +0000 (15:49 +0000)] 
trunk: storage patch from dan.

15 years agotrunk: devices patch from dan.
Chris PeBenito [Thu, 5 Mar 2009 15:36:41 +0000 (15:36 +0000)] 
trunk: devices patch from dan.

15 years agotrunk: corecommands patch from dan.
Chris PeBenito [Thu, 5 Mar 2009 14:43:03 +0000 (14:43 +0000)] 
trunk: corecommands patch from dan.

15 years agotrunk: add nlmsg_tty_audit permission.
Chris PeBenito [Thu, 5 Mar 2009 14:11:24 +0000 (14:11 +0000)] 
trunk: add nlmsg_tty_audit permission.

15 years agotrunk: man page fixes from dan.
Chris PeBenito [Thu, 5 Mar 2009 13:58:31 +0000 (13:58 +0000)] 
trunk: man page fixes from dan.

15 years agotrunk: filesystem patch from dan.
Chris PeBenito [Wed, 4 Mar 2009 15:53:07 +0000 (15:53 +0000)] 
trunk: filesystem patch from dan.

15 years agotrunk: add MLS constrains for ingress/egress permissions from Paul Moore.
Chris PeBenito [Mon, 2 Mar 2009 15:16:49 +0000 (15:16 +0000)] 
trunk: add MLS constrains for ingress/egress permissions from Paul Moore.

Add MLS constraints for several network related access controls including
the new ingress/egress controls and the older Secmark controls.  Based on
the following post to the SELinux Reference Policy mailing list:

 * http://oss.tresys.com/pipermail/refpolicy/2009-February/000579.html

15 years agotrunk: Drop write permission from fs_read_rpc_sockets().
Chris PeBenito [Tue, 24 Feb 2009 20:00:15 +0000 (20:00 +0000)] 
trunk: Drop write permission from fs_read_rpc_sockets().

15 years agotrunk: remove unused udev_runtime_t type.
Chris PeBenito [Tue, 24 Feb 2009 19:31:08 +0000 (19:31 +0000)] 
trunk: remove unused udev_runtime_t type.

15 years agotrunk: Patch for RadSec port from Glen Turner.
Chris PeBenito [Mon, 23 Feb 2009 13:41:28 +0000 (13:41 +0000)] 
trunk: Patch for RadSec port from Glen Turner.

15 years agotrunk: 6 patches from dan.
Chris PeBenito [Wed, 11 Feb 2009 19:28:30 +0000 (19:28 +0000)] 
trunk: 6 patches from dan.

15 years agotrunk: add context contains to setrans.
Chris PeBenito [Mon, 9 Feb 2009 13:58:22 +0000 (13:58 +0000)] 
trunk: add context contains to setrans.

15 years agotrunk: Enable network_peer_controls policy capability from Paul Moore.
Chris PeBenito [Tue, 3 Feb 2009 15:45:30 +0000 (15:45 +0000)] 
trunk: Enable network_peer_controls policy capability from Paul Moore.

15 years agotrunk: btrfs from Paul Moore.
Chris PeBenito [Fri, 30 Jan 2009 13:44:14 +0000 (13:44 +0000)] 
trunk: btrfs from Paul Moore.

15 years agotrunk: Add db_procedure install permission from KaiGai Kohei.
Chris PeBenito [Fri, 23 Jan 2009 19:49:36 +0000 (19:49 +0000)] 
trunk: Add db_procedure install permission from KaiGai Kohei.

15 years agotrunk: Add support for network interfaces with access controlled by a Boolean from...
Chris PeBenito [Thu, 15 Jan 2009 20:31:06 +0000 (20:31 +0000)] 
trunk: Add support for network interfaces with access controlled by a Boolean from the CLIP project.

15 years agotrunk: add sysadm_entry_spec_domtrans_to() interface from clip.
Chris PeBenito [Thu, 15 Jan 2009 15:07:37 +0000 (15:07 +0000)] 
trunk: add sysadm_entry_spec_domtrans_to() interface from clip.

15 years agotrunk: su fixes from clip.
Chris PeBenito [Tue, 13 Jan 2009 19:44:23 +0000 (19:44 +0000)] 
trunk: su fixes from clip.

15 years agotrunk: add support for labeled booleans.
Chris PeBenito [Tue, 13 Jan 2009 13:01:48 +0000 (13:01 +0000)] 
trunk: add support for labeled booleans.

15 years agotrunk: Remove node definitions and change node usage to generic nodes.
Chris PeBenito [Fri, 9 Jan 2009 19:48:02 +0000 (19:48 +0000)] 
trunk: Remove node definitions and change node usage to generic nodes.

15 years agotrunk: change network interface access from all to generic network interfaces.
Chris PeBenito [Tue, 6 Jan 2009 20:24:10 +0000 (20:24 +0000)] 
trunk: change network interface access from all to generic network interfaces.

15 years agotrunk: fix certwatch version number.
Chris PeBenito [Tue, 6 Jan 2009 19:33:24 +0000 (19:33 +0000)] 
trunk: fix certwatch version number.

15 years agotrunk: Add kernel_service access vectors, from Stephen Smalley.
Chris PeBenito [Mon, 5 Jan 2009 21:44:33 +0000 (21:44 +0000)] 
trunk: Add kernel_service access vectors, from Stephen Smalley.

15 years agotrunk: check in version and changelog for release.
Chris PeBenito [Wed, 10 Dec 2008 19:49:42 +0000 (19:49 +0000)] 
trunk: check in version and changelog for release.

15 years agotrunk: bump module versions for release.
Chris PeBenito [Wed, 10 Dec 2008 19:38:10 +0000 (19:38 +0000)] 
trunk: bump module versions for release.

15 years agotrunk: Fix consistency of audioentropy and iscsi module naming.
Chris PeBenito [Tue, 9 Dec 2008 16:47:33 +0000 (16:47 +0000)] 
trunk: Fix consistency of audioentropy and iscsi module naming.

15 years agotrunk: 2 patches from dan.
Chris PeBenito [Thu, 4 Dec 2008 15:01:12 +0000 (15:01 +0000)] 
trunk: 2 patches from dan.

15 years agotrunk: fix role change constraint.
Chris PeBenito [Wed, 3 Dec 2008 20:16:08 +0000 (20:16 +0000)] 
trunk: fix role change constraint.

15 years agotrunk: whitespace fixes in xml blocks.
Chris PeBenito [Wed, 3 Dec 2008 19:16:20 +0000 (19:16 +0000)] 
trunk: whitespace fixes in xml blocks.

15 years agotrunk: whitespace fix changing multiple spaces into tabs.
Chris PeBenito [Wed, 3 Dec 2008 18:33:19 +0000 (18:33 +0000)] 
trunk: whitespace fix changing multiple spaces into tabs.

15 years agotrunk: fix missing xml parameter.
Chris PeBenito [Wed, 3 Dec 2008 15:51:53 +0000 (15:51 +0000)] 
trunk: fix missing xml parameter.

15 years agotrunk: 3 patches from dan.
Chris PeBenito [Wed, 3 Dec 2008 15:21:33 +0000 (15:21 +0000)] 
trunk: 3 patches from dan.

15 years agotrunk: 2 patches from dan.
Chris PeBenito [Tue, 2 Dec 2008 22:40:49 +0000 (22:40 +0000)] 
trunk: 2 patches from dan.

15 years agotrunk: Debian file context fix for xen from Russell Coker.
Chris PeBenito [Mon, 24 Nov 2008 15:34:54 +0000 (15:34 +0000)] 
trunk: Debian file context fix for xen from Russell Coker.

15 years agotrunk: add milter module from Paul Howarth.
Chris PeBenito [Mon, 24 Nov 2008 15:06:58 +0000 (15:06 +0000)] 
trunk: add milter module from Paul Howarth.

15 years agotrunk: a fix on the previous commit.
Chris PeBenito [Wed, 19 Nov 2008 16:02:13 +0000 (16:02 +0000)] 
trunk: a fix on the previous commit.