]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
16 years agotrunk: switch daemons from inheriting from all levels to initrc_t sharing to all...
Chris PeBenito [Wed, 22 Aug 2007 20:21:52 +0000 (20:21 +0000)] 
trunk: switch daemons from inheriting from all levels to initrc_t sharing to all levels.

16 years agotrunk: updates from dan on 9 modules
Chris PeBenito [Wed, 22 Aug 2007 20:02:41 +0000 (20:02 +0000)] 
trunk: updates from dan on 9 modules

16 years agotrunk: add some info to the readme about building from headers
Chris PeBenito [Wed, 22 Aug 2007 15:34:23 +0000 (15:34 +0000)] 
trunk: add some info to the readme about building from headers

16 years agotrunk: Files and radvd updates from Stefan Schulze Frielinghaus.
Chris PeBenito [Tue, 21 Aug 2007 19:03:34 +0000 (19:03 +0000)] 
trunk: Files and radvd updates from Stefan Schulze Frielinghaus.

16 years agotrunk: fix gdm xsession scripts on redhat machines.
Chris PeBenito [Mon, 20 Aug 2007 18:54:29 +0000 (18:54 +0000)] 
trunk: fix gdm xsession scripts on redhat machines.

16 years agotrunk: Deprecate mls_file_write_down() and mls_file_read_up(), replaced with mls_writ...
Chris PeBenito [Mon, 20 Aug 2007 18:26:08 +0000 (18:26 +0000)] 
trunk: Deprecate mls_file_write_down() and mls_file_read_up(), replaced with mls_write_all_levels() and mls_read_all_levels(), for consistency.

16 years agotrunk: several MLS enhancements.
Chris PeBenito [Mon, 20 Aug 2007 15:15:03 +0000 (15:15 +0000)] 
trunk: several MLS enhancements.

16 years agotrunk: Database userspace object manager classes from KaiGai Kohei.
Chris PeBenito [Thu, 9 Aug 2007 13:15:07 +0000 (13:15 +0000)] 
trunk: Database userspace object manager classes from KaiGai Kohei.

16 years agotrunk: filesystem patch from dan
Chris PeBenito [Wed, 8 Aug 2007 20:04:28 +0000 (20:04 +0000)] 
trunk: filesystem patch from dan

16 years agotrunk: 3 patches from dan
Chris PeBenito [Tue, 7 Aug 2007 17:06:32 +0000 (17:06 +0000)] 
trunk: 3 patches from dan

16 years agotrunk: several support macro fixes.
Chris PeBenito [Tue, 31 Jul 2007 15:11:22 +0000 (15:11 +0000)] 
trunk: several support macro fixes.

16 years agotrunk: add 3rd party interface for apache cgi.
Chris PeBenito [Thu, 26 Jul 2007 19:48:40 +0000 (19:48 +0000)] 
trunk: add 3rd party interface for apache cgi.

16 years agotrunk: fix pipe permission set in domtrans_pattern().
Chris PeBenito [Thu, 26 Jul 2007 19:41:15 +0000 (19:41 +0000)] 
trunk: fix pipe permission set in domtrans_pattern().

16 years agotrunk: add getserv and shmemserv nscd permissions.
Chris PeBenito [Tue, 24 Jul 2007 19:52:18 +0000 (19:52 +0000)] 
trunk: add getserv and shmemserv nscd permissions.

16 years agotrunk: fix targeted sshd. When the domain was unaliased from unconfined_t, a transit...
Chris PeBenito [Fri, 20 Jul 2007 18:25:26 +0000 (18:25 +0000)] 
trunk: fix targeted sshd.  When the domain was unaliased from unconfined_t, a transition to unconfined_t was not added.

16 years agotrunk: add application module
Chris PeBenito [Thu, 19 Jul 2007 18:57:48 +0000 (18:57 +0000)] 
trunk: add application module

16 years agotrunk: fix missed netlabel deprecation
Chris PeBenito [Thu, 19 Jul 2007 15:11:19 +0000 (15:11 +0000)] 
trunk: fix missed netlabel deprecation

16 years agotrunk: Add debian apcupsd binary location, from Stefan Schulze Frielinghaus.
Chris PeBenito [Mon, 2 Jul 2007 15:25:46 +0000 (15:25 +0000)] 
trunk: Add debian apcupsd binary location, from Stefan Schulze Frielinghaus.

16 years agotrunk: updated version and changelog for release
Chris PeBenito [Fri, 29 Jun 2007 15:30:58 +0000 (15:30 +0000)] 
trunk: updated version and changelog for release

16 years agotrunk: update module version numbers for release.
Chris PeBenito [Fri, 29 Jun 2007 14:48:13 +0000 (14:48 +0000)] 
trunk: update module version numbers for release.

16 years agoFix incorrectly named files_lib_filetrans_shared_lib() interface in the libraries...
Chris PeBenito [Thu, 28 Jun 2007 17:25:46 +0000 (17:25 +0000)] 
Fix incorrectly named files_lib_filetrans_shared_lib() interface in the libraries module.

16 years agotrunk: add templates to tags generation
Chris PeBenito [Thu, 28 Jun 2007 13:13:55 +0000 (13:13 +0000)] 
trunk: add templates to tags generation

16 years agotrunk, strict-targeted-merge: add mmap_zero to xserver domains.
Chris PeBenito [Thu, 28 Jun 2007 12:34:08 +0000 (12:34 +0000)] 
trunk, strict-targeted-merge: add mmap_zero to xserver domains.

16 years agotrunk: minor amanda update from dan
Chris PeBenito [Wed, 27 Jun 2007 19:19:20 +0000 (19:19 +0000)] 
trunk: minor amanda update from dan

16 years agotrunk: add rpcbind from dan
Chris PeBenito [Wed, 27 Jun 2007 16:31:55 +0000 (16:31 +0000)] 
trunk: add rpcbind from dan

16 years agotrunk: Unified labeled networking policy from Paul Moore.
Chris PeBenito [Wed, 27 Jun 2007 15:23:21 +0000 (15:23 +0000)] 
trunk: Unified labeled networking policy from Paul Moore.

The latest revision of the labeled policy patches which enable both labeled
and unlabeled policy support for NetLabel.  This revision takes into account
Chris' feedback from the first version and reduces the number of interface
calls in each domain down to two at present: one for unlabeled access, one for
NetLabel access.  The older, transport layer specific interfaces, are still
present for use by third-party modules but are not used in the default policy
modules.

trunk: Use netmsg initial SID for MLS-only Netlabel packets, from Paul Moore.

This patch changes the policy to use the netmsg initial SID as the "base"
SID/context for NetLabel packets which only have MLS security attributes.
Currently we use the unlabeled initial SID which makes it very difficult to
distinquish between actual unlabeled packets and those packets which have MLS
security attributes.

16 years agotrunk: pyzor and clamav updates from dan
Chris PeBenito [Tue, 26 Jun 2007 18:43:11 +0000 (18:43 +0000)] 
trunk: pyzor and clamav updates from dan

16 years agotrunk: fix typo in vmware.fc
Chris PeBenito [Tue, 26 Jun 2007 14:31:31 +0000 (14:31 +0000)] 
trunk: fix typo in vmware.fc

16 years agotrunk: nagios update from dan
Chris PeBenito [Thu, 21 Jun 2007 17:23:19 +0000 (17:23 +0000)] 
trunk: nagios update from dan

16 years agotrunk: procmail tweak from dan.
Chris PeBenito [Thu, 21 Jun 2007 14:54:34 +0000 (14:54 +0000)] 
trunk: procmail tweak from dan.

16 years agotrunk: xen updates from dan
Chris PeBenito [Thu, 21 Jun 2007 13:36:05 +0000 (13:36 +0000)] 
trunk: xen updates from dan

16 years agotrunk: trivial gentoo tweaks
Chris PeBenito [Wed, 20 Jun 2007 20:08:26 +0000 (20:08 +0000)] 
trunk: trivial gentoo tweaks

16 years agotrunk: 3 patches from dan
Chris PeBenito [Wed, 20 Jun 2007 19:47:10 +0000 (19:47 +0000)] 
trunk: 3 patches from dan

16 years agotrunk: radius one-liner from dan
Chris PeBenito [Wed, 20 Jun 2007 15:03:55 +0000 (15:03 +0000)] 
trunk: radius one-liner from dan

16 years agotrunk: big samba update from dan
Chris PeBenito [Tue, 19 Jun 2007 19:11:35 +0000 (19:11 +0000)] 
trunk: big samba update from dan

16 years agotrunk: drop snmpd_etc_t.
Chris PeBenito [Tue, 19 Jun 2007 17:39:35 +0000 (17:39 +0000)] 
trunk: drop snmpd_etc_t.

16 years agotrunk: confine sendmail and logrotate on targeted
Chris PeBenito [Tue, 19 Jun 2007 17:01:39 +0000 (17:01 +0000)] 
trunk: confine sendmail and logrotate on targeted

16 years agotrunk: Tunable connection to postgresql for users from KaiGai Kohei.
Chris PeBenito [Tue, 19 Jun 2007 14:30:06 +0000 (14:30 +0000)] 
trunk: Tunable connection to postgresql for users from KaiGai Kohei.

16 years agoMemprotect support patch from Stephen Smalley.
Chris PeBenito [Tue, 19 Jun 2007 13:02:26 +0000 (13:02 +0000)] 
Memprotect support patch from Stephen Smalley.

17 years agotrunk: 2 patches from dan
Chris PeBenito [Wed, 13 Jun 2007 13:54:56 +0000 (13:54 +0000)] 
trunk: 2 patches from dan

17 years agotrunk: add amtu from dan
Chris PeBenito [Tue, 12 Jun 2007 18:58:36 +0000 (18:58 +0000)] 
trunk: add amtu from dan

17 years agotrunk: Add logging_send_audit_msgs() interface and deprecate send_audit_msgs_pattern().
Chris PeBenito [Tue, 12 Jun 2007 18:46:14 +0000 (18:46 +0000)] 
trunk: Add logging_send_audit_msgs() interface and deprecate send_audit_msgs_pattern().

17 years agotrunk: version bumps for previous commit.
Chris PeBenito [Tue, 12 Jun 2007 13:08:19 +0000 (13:08 +0000)] 
trunk: version bumps for previous commit.

17 years agotrunk: 7 simple patches from dan.
Chris PeBenito [Tue, 12 Jun 2007 13:06:13 +0000 (13:06 +0000)] 
trunk: 7 simple patches from dan.

17 years agotrunk: 3 patches from dan
Chris PeBenito [Mon, 11 Jun 2007 15:43:37 +0000 (15:43 +0000)] 
trunk: 3 patches from dan

17 years agotrunk: 5 patches from dan
Chris PeBenito [Mon, 11 Jun 2007 15:01:10 +0000 (15:01 +0000)] 
trunk: 5 patches from dan

17 years agosix simple patches from dan
Chris PeBenito [Mon, 11 Jun 2007 14:09:09 +0000 (14:09 +0000)] 
six simple patches from dan

17 years agoadd fc entry for make_reiser4
Chris PeBenito [Fri, 8 Jun 2007 20:01:34 +0000 (20:01 +0000)] 
add fc entry for make_reiser4

17 years agotrunk: fix line in evolution to be strict-only; was being covered up by genhomedircon.
Chris PeBenito [Tue, 22 May 2007 17:01:38 +0000 (17:01 +0000)] 
trunk: fix line in evolution to be strict-only; was being covered up by genhomedircon.

17 years agotrunk: snmp tweak from dan
Chris PeBenito [Tue, 15 May 2007 18:06:31 +0000 (18:06 +0000)] 
trunk: snmp tweak from dan

17 years agotrunk: remaining pieces for apcupsd module
Chris PeBenito [Tue, 15 May 2007 15:43:00 +0000 (15:43 +0000)] 
trunk: remaining pieces for apcupsd module

17 years agotrunk: long overdue cleanup from when range_transitions were only in the base module
Chris PeBenito [Mon, 14 May 2007 15:35:47 +0000 (15:35 +0000)] 
trunk: long overdue cleanup from when range_transitions were only in the base module

17 years agomerge restorecon into setfiles
Chris PeBenito [Fri, 11 May 2007 17:10:43 +0000 (17:10 +0000)] 
merge restorecon into setfiles

17 years agoPatch to begin separating out hald helper programs from Dan Walsh.
Chris PeBenito [Mon, 7 May 2007 17:57:48 +0000 (17:57 +0000)] 
Patch to begin separating out hald helper programs from Dan Walsh.

17 years agoadd apcupsd from dan
Chris PeBenito [Mon, 7 May 2007 14:55:54 +0000 (14:55 +0000)] 
add apcupsd from dan

17 years agoFixes for squid, dovecot, and snmp from Dan Walsh.
Chris PeBenito [Mon, 7 May 2007 13:45:17 +0000 (13:45 +0000)] 
Fixes for squid, dovecot, and snmp from Dan Walsh.

17 years agoMiscellaneous consolekit fixes from Dan Walsh.
Chris PeBenito [Thu, 3 May 2007 14:15:38 +0000 (14:15 +0000)] 
Miscellaneous consolekit fixes from Dan Walsh.

17 years agotextrel lib update from dan
Chris PeBenito [Thu, 3 May 2007 13:43:44 +0000 (13:43 +0000)] 
textrel lib update from dan

17 years agoadd missing rename_dir_perms
Chris PeBenito [Thu, 3 May 2007 13:15:48 +0000 (13:15 +0000)] 
add missing rename_dir_perms

17 years agoPatch to have avahi use the nsswitch interface rather than individual permissions...
Chris PeBenito [Thu, 3 May 2007 12:45:28 +0000 (12:45 +0000)] 
Patch to have avahi use the nsswitch interface rather than individual permissions from Dan Walsh.

17 years agoPatch to dontaudit logrotate searching avahi pid directory from Dan Walsh.
Chris PeBenito [Wed, 2 May 2007 17:55:03 +0000 (17:55 +0000)] 
Patch to dontaudit logrotate searching avahi pid directory from Dan Walsh.

17 years ago- Patch to allow insmod to mount kvmfs and dontaudit rw unconfined_t pipes
Chris PeBenito [Wed, 2 May 2007 17:31:38 +0000 (17:31 +0000)] 
- Patch to allow insmod to mount kvmfs and dontaudit rw unconfined_t pipes
  to handle usage from userhelper.

17 years agoadd rwho from Nalin Dahyabhai
Chris PeBenito [Mon, 30 Apr 2007 17:39:01 +0000 (17:39 +0000)] 
add rwho from Nalin Dahyabhai

17 years agoPatch to allow amavis to read spamassassin libraries from Dan Walsh.
Chris PeBenito [Mon, 30 Apr 2007 15:19:47 +0000 (15:19 +0000)] 
Patch to allow amavis to read spamassassin libraries from Dan Walsh.

17 years agotrivial aide fix from dan
Chris PeBenito [Mon, 30 Apr 2007 15:09:15 +0000 (15:09 +0000)] 
trivial aide fix from dan

17 years agoPatch to allow slocate to getattr other filesystems and directories on those filesyst...
Chris PeBenito [Mon, 30 Apr 2007 15:01:19 +0000 (15:01 +0000)] 
Patch to allow slocate to getattr other filesystems and directories on those filesystems from Dan Walsh.

17 years agotrivial fix for netutils from dan
Chris PeBenito [Mon, 30 Apr 2007 14:44:04 +0000 (14:44 +0000)] 
trivial fix for netutils from dan

17 years agotrivial fix from dan for bluetooth
Chris PeBenito [Mon, 30 Apr 2007 14:33:12 +0000 (14:33 +0000)] 
trivial fix from dan for bluetooth

17 years agomissed piece of clip patch
Chris PeBenito [Mon, 30 Apr 2007 14:32:31 +0000 (14:32 +0000)] 
missed piece of clip patch

17 years agoFixes for RHEL4 from the CLIP project.
Chris PeBenito [Fri, 27 Apr 2007 15:08:15 +0000 (15:08 +0000)] 
Fixes for RHEL4 from the CLIP project.

17 years agoReplace the old lrrd fc entries with correct munin ones.
Chris PeBenito [Mon, 23 Apr 2007 17:36:35 +0000 (17:36 +0000)] 
Replace the old lrrd fc entries with correct munin ones.

17 years agoMove program admin template usage out of userdom_admin_user_template() to sysadm...
Chris PeBenito [Thu, 19 Apr 2007 14:30:57 +0000 (14:30 +0000)] 
Move program admin template usage out of userdom_admin_user_template() to sysadm policy in userdomain.te to fix usage of the template for third parties.

17 years agoFix clockspeed_run_cli() declaration, it was incorrectly defined as a template instea...
Chris PeBenito [Thu, 19 Apr 2007 14:24:02 +0000 (14:24 +0000)] 
Fix clockspeed_run_cli() declaration, it was incorrectly defined as a template instead of an interface.

17 years agofinal release entries for 20070417
Chris PeBenito [Tue, 17 Apr 2007 14:20:24 +0000 (14:20 +0000)] 
final release entries for 20070417

17 years agobump module versions for release
Chris PeBenito [Tue, 17 Apr 2007 13:28:09 +0000 (13:28 +0000)] 
bump module versions for release

17 years agolast piece of previous consolekit patch
Chris PeBenito [Wed, 11 Apr 2007 20:02:59 +0000 (20:02 +0000)] 
last piece of previous consolekit patch

17 years agoadd zabbix from dan
Chris PeBenito [Wed, 11 Apr 2007 18:55:44 +0000 (18:55 +0000)] 
add zabbix from dan

17 years ago5 patches from dan. confine insmod and udev on targeted, misc fc fixes, sasl kerbero...
Chris PeBenito [Wed, 11 Apr 2007 17:56:03 +0000 (17:56 +0000)] 
5 patches from dan.  confine insmod and udev on targeted, misc fc fixes, sasl kerberos use, and samba port fixes

17 years agomore consolekit updates from dan
Chris PeBenito [Wed, 11 Apr 2007 14:04:35 +0000 (14:04 +0000)] 
more consolekit updates from dan

17 years agolast piece of dan's previous patch
Chris PeBenito [Wed, 11 Apr 2007 13:31:10 +0000 (13:31 +0000)] 
last piece of dan's previous patch

17 years agoconfine ldconfig in targeted, from dan
Chris PeBenito [Tue, 10 Apr 2007 19:39:22 +0000 (19:39 +0000)] 
confine ldconfig in targeted, from dan

17 years agofrom dan:
Chris PeBenito [Tue, 10 Apr 2007 17:20:07 +0000 (17:20 +0000)] 
from dan:

kadmind trys to setattr on krb5kdc file.  Just a library checking access.

17 years agosix patches from dan
Chris PeBenito [Tue, 10 Apr 2007 13:10:58 +0000 (13:10 +0000)] 
six patches from dan

17 years agoman page updates from dan
Chris PeBenito [Mon, 2 Apr 2007 13:58:33 +0000 (13:58 +0000)] 
man page updates from dan

17 years agogentoo /lib can be a symlink on x86-64 systems
Chris PeBenito [Mon, 2 Apr 2007 13:33:18 +0000 (13:33 +0000)] 
gentoo /lib can be a symlink on x86-64 systems

17 years agofix http_script_domains, it was incorrectly applied to the content type rather than...
Chris PeBenito [Mon, 2 Apr 2007 13:20:55 +0000 (13:20 +0000)] 
fix http_script_domains, it was incorrectly applied to the content type rather than the script domain.  bug #24.

17 years agoemit "null" instead of NULL for userspace headers
Chris PeBenito [Fri, 30 Mar 2007 20:33:51 +0000 (20:33 +0000)] 
emit "null" instead of NULL for userspace headers

17 years agobools in modules fix to require the boolean in optionals that are part of the base...
Chris PeBenito [Fri, 30 Mar 2007 12:43:15 +0000 (12:43 +0000)] 
bools in modules fix to require the boolean in optionals that are part of the base module, and move bool declarations in the base module/monolithic

17 years agoadd refresh target to devel makefile which tries to reload all of the modules current...
Chris PeBenito [Thu, 29 Mar 2007 12:08:00 +0000 (12:08 +0000)] 
add refresh target to devel makefile which tries to reload all of the modules currently in the store.

17 years agoTwo patches from Paul Moore to for ipsec to remove redundant rules and have setkey...
Chris PeBenito [Wed, 28 Mar 2007 18:47:45 +0000 (18:47 +0000)] 
Two patches from Paul Moore to for ipsec to remove redundant rules and have setkey read the config file.

17 years agosix trivial patches from dan for iptables, netutils, ipsec, devices, filesystem and...
Chris PeBenito [Mon, 26 Mar 2007 20:47:29 +0000 (20:47 +0000)] 
six trivial patches from dan for iptables, netutils, ipsec, devices, filesystem and cpuspeed

17 years ago- Move booleans and tunables to modules when it is only used in a single
Chris PeBenito [Mon, 26 Mar 2007 18:41:45 +0000 (18:41 +0000)] 
- Move booleans and tunables to modules when it is only used in a single
  module.
- Add support for tunables and booleans local to a module.

17 years agoMerge sbin_t and ls_exec_t into bin_t.
Chris PeBenito [Fri, 23 Mar 2007 23:24:59 +0000 (23:24 +0000)] 
Merge sbin_t and ls_exec_t into bin_t.

17 years agoremove disable_trans booleans
Chris PeBenito [Fri, 23 Mar 2007 21:01:49 +0000 (21:01 +0000)] 
remove disable_trans booleans

17 years agoOutput different header sets for kernel and userland from flask headers.
Chris PeBenito [Fri, 23 Mar 2007 20:32:23 +0000 (20:32 +0000)] 
Output different header sets for kernel and userland from flask headers.

17 years agodeprecated pax class
Chris PeBenito [Fri, 23 Mar 2007 20:21:06 +0000 (20:21 +0000)] 
deprecated pax class

17 years agonetwork fix from dan
Chris PeBenito [Thu, 22 Mar 2007 14:33:00 +0000 (14:33 +0000)] 
network fix from dan

17 years agoone-liner from dan
Chris PeBenito [Thu, 22 Mar 2007 14:01:55 +0000 (14:01 +0000)] 
one-liner from dan

17 years agopatch from dan to have ricci modstorage transition to lvm
Chris PeBenito [Wed, 21 Mar 2007 20:02:50 +0000 (20:02 +0000)] 
patch from dan to have ricci modstorage transition to lvm

17 years agostop adding netfilter contexts, as decided at the developers summit
Chris PeBenito [Wed, 21 Mar 2007 19:40:55 +0000 (19:40 +0000)] 
stop adding netfilter contexts, as decided at the developers summit