]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
14 years agoAllow only spamc_t to connect to abrt over unix stream socket rather than all apps...
Miroslav Grepl [Mon, 11 Jul 2011 18:25:24 +0000 (18:25 +0000)] 
Allow only spamc_t to connect to abrt over unix stream socket rather than all apps domains for now

14 years agoAllow amavis to read sysfs
Miroslav Grepl [Mon, 11 Jul 2011 16:30:20 +0000 (16:30 +0000)] 
Allow amavis to read sysfs

14 years agoAllow asterisk to read /dev/random if it uses TLS
Miroslav Grepl [Mon, 11 Jul 2011 16:15:09 +0000 (16:15 +0000)] 
Allow asterisk to read /dev/random if it uses TLS

14 years agoAllow colord to read ini files which are labeled as bin_t
Miroslav Grepl [Mon, 11 Jul 2011 11:45:28 +0000 (11:45 +0000)] 
Allow colord to read ini files which are labeled as bin_t

14 years agoAllow dirsrvadmin sys_resource and setrlimit to use ulimit
Miroslav Grepl [Mon, 11 Jul 2011 11:02:40 +0000 (11:02 +0000)] 
Allow dirsrvadmin sys_resource and setrlimit to use ulimit

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 7 Jul 2011 17:41:17 +0000 (13:41 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoSystemd needs to be able to create sock_files for every label in /var/run directory...
Dan Walsh [Thu, 7 Jul 2011 17:37:01 +0000 (13:37 -0400)] 
Systemd needs to be able to create sock_files for every label in /var/run directory, cupsd being the first.  Also lists /var and /var/spool directories

14 years agoRevert: ea889ac720a4fddde6d8376cb5dc9336d14e867e
Dominick Grift [Wed, 6 Jul 2011 22:15:53 +0000 (00:15 +0200)] 
Revert: ea889ac720a4fddde6d8376cb5dc9336d14e867e
mozilla_plugin_tmp_t is userdom_user_tmp_content() and so callers have
full access to it.

14 years agocallers need to stream connect to mozilla plugin ( gecko media
Dominick Grift [Wed, 6 Jul 2011 21:37:06 +0000 (23:37 +0200)] 
callers need to stream connect to mozilla plugin ( gecko media
player plugin ) #711605

14 years agoRemove labels for libexec abrt helpers
Dan Walsh [Wed, 6 Jul 2011 21:00:12 +0000 (17:00 -0400)] 
Remove labels for libexec abrt helpers

14 years agoAllow apps that transition to mozilla_plugin_t to use the fd
Dan Walsh [Wed, 6 Jul 2011 20:44:16 +0000 (16:44 -0400)] 
Allow apps that transition to mozilla_plugin_t to use the fd

14 years agoAdd openl2tpd to l2tpd policy
Dan Walsh [Wed, 6 Jul 2011 20:43:46 +0000 (16:43 -0400)] 
Add openl2tpd to l2tpd policy

14 years agoqpidd is reading the sysfs file
Dan Walsh [Wed, 6 Jul 2011 20:04:37 +0000 (16:04 -0400)] 
qpidd is reading the sysfs file

14 years agoAbrt helper is reading the execuatbles that crash
Dan Walsh [Wed, 6 Jul 2011 20:04:08 +0000 (16:04 -0400)] 
Abrt helper is reading the execuatbles that crash

14 years agoxauth seems to be creating unix_dgram_sockets and reading network state
Dan Walsh [Wed, 6 Jul 2011 20:03:44 +0000 (16:03 -0400)] 
xauth seems to be creating unix_dgram_sockets and reading network state

14 years agoadd l2tpd daemon policy
Dan Walsh [Tue, 5 Jul 2011 20:21:21 +0000 (16:21 -0400)] 
add l2tpd daemon policy

14 years agoDomains that execute killall like gdm, need to getattributes of executables
Dan Walsh [Tue, 5 Jul 2011 17:41:54 +0000 (13:41 -0400)] 
Domains that execute killall like gdm, need to getattributes of executables

14 years agoAllow mail domains to read asterisk_tmp_t content
Dan Walsh [Tue, 5 Jul 2011 16:38:34 +0000 (12:38 -0400)] 
Allow mail domains to read asterisk_tmp_t content

14 years agoCleanup sandbox policy
Dan Walsh [Tue, 5 Jul 2011 16:38:07 +0000 (12:38 -0400)] 
Cleanup sandbox policy

14 years agochrome_sandbox_t needs to write to inherited files in the homedir, if it is using...
Dan Walsh [Tue, 5 Jul 2011 15:33:38 +0000 (11:33 -0400)] 
chrome_sandbox_t needs to write to inherited files in the homedir, if it is using nfs or cifs

14 years agoAllow sysadmin_t to transition to systemd_passwd to start and stop init scripts
Dan Walsh [Tue, 5 Jul 2011 15:19:33 +0000 (11:19 -0400)] 
Allow sysadmin_t to transition to systemd_passwd to start and stop init scripts

14 years ago#711804 reveals that puppetmaster needs to search through sysfs_t
Dan Walsh [Fri, 1 Jul 2011 11:40:11 +0000 (07:40 -0400)] 
#711804 reveals that puppetmaster needs to search through sysfs_t

14 years agoabrt-dump-oops runs from init and needs to write to abrt_var_cache, so I am making...
Dan Walsh [Fri, 1 Jul 2011 11:39:24 +0000 (07:39 -0400)] 
abrt-dump-oops runs from init and needs to write to abrt_var_cache, so I am making it a helper app

14 years agovpnc_t tries to access an init_t fd, but works without the access, so dontaudit it
Dan Walsh [Fri, 1 Jul 2011 11:38:38 +0000 (07:38 -0400)] 
vpnc_t tries to access an init_t fd, but works without the access, so dontaudit it

14 years agoFix virt_dontaudit_read_chr_dev() interface
Miroslav Grepl [Thu, 30 Jun 2011 17:18:51 +0000 (17:18 +0000)] 
Fix virt_dontaudit_read_chr_dev() interface

14 years agoAdd more interfaces for rhsmcertd policy
Miroslav Grepl [Thu, 30 Jun 2011 16:55:53 +0000 (16:55 +0000)] 
Add more interfaces for rhsmcertd policy
Dontaudit xguest dbus chat with rhsmcertd

14 years agoChange usbmuxd_t to dontaudit attempts to read chr_file (usb) devices owned by an...
Dan Walsh [Thu, 30 Jun 2011 11:24:13 +0000 (07:24 -0400)] 
Change usbmuxd_t to dontaudit attempts to read chr_file (usb) devices owned by an svirt guest

14 years agoAdd mysld_safe_exec_t for libra domains to be able to start private mysql domains
Dan Walsh [Thu, 30 Jun 2011 11:12:39 +0000 (07:12 -0400)] 
Add mysld_safe_exec_t for libra domains to be able to start private mysql domains

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 30 Jun 2011 11:08:42 +0000 (07:08 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoSandbox starts dbus within some apps and this attempts to communicate with netlink_se...
Dan Walsh [Thu, 30 Jun 2011 11:08:20 +0000 (07:08 -0400)] 
Sandbox starts dbus within some apps and this attempts to communicate with netlink_selinux_socket.  I think we need to allow this access, as it stops an ugly line from appearing in the log file

14 years agoRevert "Sandbox starts dbus within some apps and this attempts to communicate with...
Dan Walsh [Thu, 30 Jun 2011 11:07:24 +0000 (07:07 -0400)] 
Revert "Sandbox starts dbus within some apps and this attempts to communicate with netlink_selinux_socket.  I think we need to allow this access, as it stops an ugly line from appearing in the log file"

This reverts commit 5a709ffff74bb93b11744d0a3041120a4910f94c.

14 years agoSandbox starts dbus within some apps and this attempts to communicate with netlink_se...
Dan Walsh [Thu, 30 Jun 2011 11:06:28 +0000 (07:06 -0400)] 
Sandbox starts dbus within some apps and this attempts to communicate with netlink_selinux_socket.  I think we need to allow this access, as it stops an ugly line from appearing in the log file

14 years agoAllow pppd to search /var/lock dir
Miroslav Grepl [Tue, 28 Jun 2011 10:56:49 +0000 (10:56 +0000)] 
Allow pppd to search /var/lock dir

14 years agoAllow usbmuxd_t to read chr_files owned by svirt_t
Dan Walsh [Wed, 29 Jun 2011 17:04:06 +0000 (13:04 -0400)] 
Allow usbmuxd_t to read chr_files owned by svirt_t

14 years agoAdd rhsmcertd policy
Miroslav Grepl [Wed, 29 Jun 2011 16:02:10 +0000 (16:02 +0000)] 
Add rhsmcertd policy
 * Subscription Management Certificate Daemon policy

14 years agoAllow colord to read /proc/stat
Miroslav Grepl [Wed, 29 Jun 2011 15:16:10 +0000 (15:16 +0000)] 
Allow colord to read /proc/stat

14 years agoAdd support for corosync-notifyd
Miroslav Grepl [Wed, 29 Jun 2011 13:35:24 +0000 (13:35 +0000)] 
Add support for corosync-notifyd
  * add corosync_exec_t label

14 years agoAllow shutdown to send sigchld to rhev-agentd
Miroslav Grepl [Wed, 29 Jun 2011 13:22:42 +0000 (13:22 +0000)] 
Allow shutdown to send sigchld to rhev-agentd

14 years agoFix file context issue in postfix.fc
Miroslav Grepl [Wed, 29 Jun 2011 11:20:39 +0000 (11:20 +0000)] 
Fix file context issue in postfix.fc

14 years agoAllow confined users to dbus chat with telepathy domains
Miroslav Grepl [Wed, 29 Jun 2011 11:01:22 +0000 (11:01 +0000)] 
Allow confined users to dbus chat with telepathy domains

14 years agoAllow telepathy_gabble to read gnome home config
Miroslav Grepl [Wed, 29 Jun 2011 08:32:16 +0000 (08:32 +0000)] 
Allow telepathy_gabble to read gnome home config

14 years agoFix bud in bugzilla.if
Miroslav Grepl [Tue, 28 Jun 2011 16:21:56 +0000 (16:21 +0000)] 
Fix bud in bugzilla.if

14 years agoRemove duplicate context declaration for /usr/sbin/validate
Miroslav Grepl [Tue, 28 Jun 2011 15:46:38 +0000 (15:46 +0000)] 
Remove duplicate context declaration for /usr/sbin/validate

14 years agoRemove others duplicate declarations
Miroslav Grepl [Tue, 28 Jun 2011 15:37:52 +0000 (15:37 +0000)] 
Remove others duplicate declarations

14 years agoRemove duplicate declaration from iptables.fc
Miroslav Grepl [Tue, 28 Jun 2011 15:22:05 +0000 (15:22 +0000)] 
Remove duplicate declaration from iptables.fc

14 years agoAdd back upstream changes in userdomain.if
Miroslav Grepl [Tue, 28 Jun 2011 15:12:09 +0000 (15:12 +0000)] 
Add back upstream changes in userdomain.if

14 years agoRemove duplicate declaration from vnstat
Miroslav Grepl [Tue, 28 Jun 2011 15:01:19 +0000 (15:01 +0000)] 
Remove duplicate declaration from vnstat

14 years agoAdd back telepathy_dbus_chat() interface
Miroslav Grepl [Tue, 28 Jun 2011 14:55:27 +0000 (14:55 +0000)] 
Add back telepathy_dbus_chat() interface

14 years agoUse files_list_lost_found() interface
Miroslav Grepl [Tue, 28 Jun 2011 14:46:25 +0000 (14:46 +0000)] 
Use files_list_lost_found() interface

14 years agoAdd back application_getattr_socket() interface
Miroslav Grepl [Tue, 28 Jun 2011 14:41:14 +0000 (14:41 +0000)] 
Add back application_getattr_socket() interface

14 years agoRemove duplicate declaration in rssh policy
Miroslav Grepl [Tue, 28 Jun 2011 14:35:32 +0000 (14:35 +0000)] 
Remove duplicate declaration in rssh policy

14 years agoUse zarafa_domtrans_deliver interface instead of zarafa_deliver_domtrans
Miroslav Grepl [Tue, 28 Jun 2011 14:30:45 +0000 (14:30 +0000)] 
Use zarafa_domtrans_deliver interface instead of zarafa_deliver_domtrans

14 years agoFix typo
Miroslav Grepl [Tue, 28 Jun 2011 14:26:03 +0000 (14:26 +0000)] 
Fix typo

14 years agoUse mozilla_exec_user_home_files()
Miroslav Grepl [Tue, 28 Jun 2011 14:22:24 +0000 (14:22 +0000)] 
Use mozilla_exec_user_home_files()

14 years agoUse bugzilla_dontaudit_rw_stream_sockets(system_mail_t) which is correct
Miroslav Grepl [Tue, 28 Jun 2011 14:18:01 +0000 (14:18 +0000)] 
Use bugzilla_dontaudit_rw_stream_sockets(system_mail_t) which is correct

14 years agoUse the right interface
Miroslav Grepl [Tue, 28 Jun 2011 14:14:41 +0000 (14:14 +0000)] 
Use the right interface
 * bugzilla_search_content(system_mail_t)

14 years agoRemove duplication declaration in mozilla policy
Miroslav Grepl [Tue, 28 Jun 2011 14:10:33 +0000 (14:10 +0000)] 
Remove duplication declaration in mozilla policy

14 years agoRemove duplicate declaration from colord policy
Miroslav Grepl [Tue, 28 Jun 2011 14:05:35 +0000 (14:05 +0000)] 
Remove duplicate declaration from colord policy

14 years agoAdd back interface(`zarafa_manage_lib_files() interface
Miroslav Grepl [Tue, 28 Jun 2011 14:03:00 +0000 (14:03 +0000)] 
Add back interface(`zarafa_manage_lib_files() interface

14 years agoAdd back passenger_manage_pid_content() interface
Miroslav Grepl [Tue, 28 Jun 2011 13:59:45 +0000 (13:59 +0000)] 
Add back passenger_manage_pid_content() interface

14 years agoAdd back mediawiki interfaces
Miroslav Grepl [Tue, 28 Jun 2011 13:52:59 +0000 (13:52 +0000)] 
Add back mediawiki interfaces

14 years agoRemove duplicate declaration from userdomain.if
Miroslav Grepl [Tue, 28 Jun 2011 13:49:39 +0000 (13:49 +0000)] 
Remove duplicate declaration from userdomain.if

14 years agoAdd missing interfaces to userdomain.if
Miroslav Grepl [Tue, 28 Jun 2011 13:46:30 +0000 (13:46 +0000)] 
Add missing interfaces to userdomain.if

14 years agoAdd old userdomain.if file
Miroslav Grepl [Tue, 28 Jun 2011 13:36:42 +0000 (13:36 +0000)] 
Add old userdomain.if file

14 years agoJust for testing
Miroslav Grepl [Tue, 28 Jun 2011 13:28:57 +0000 (13:28 +0000)] 
Just for testing

14 years agoRemove duplicate declaration for rssh.if
Miroslav Grepl [Tue, 28 Jun 2011 13:03:17 +0000 (13:03 +0000)] 
Remove duplicate declaration for rssh.if

14 years agoRemove duplicate declarations for iscsi.if, libraries.if and logging.if
Miroslav Grepl [Tue, 28 Jun 2011 13:01:02 +0000 (13:01 +0000)] 
Remove duplicate declarations for iscsi.if, libraries.if and logging.if

14 years agoRemove duplicate declarations in ipsec.if
Miroslav Grepl [Tue, 28 Jun 2011 12:53:16 +0000 (12:53 +0000)] 
Remove duplicate declarations in ipsec.if

14 years agoFix duplicate declaration in daemontools.if
Miroslav Grepl [Tue, 28 Jun 2011 12:51:14 +0000 (12:51 +0000)] 
Fix duplicate declaration in daemontools.if

14 years agoFix duplicate declaration in authlogin.if
Miroslav Grepl [Tue, 28 Jun 2011 12:49:58 +0000 (12:49 +0000)] 
Fix duplicate declaration in authlogin.if

14 years agoFix duplicate declaration in kernel.if
Miroslav Grepl [Tue, 28 Jun 2011 12:48:43 +0000 (12:48 +0000)] 
Fix duplicate declaration in kernel.if

14 years agoFix duplicate declarations in filesystem.if (caused by merge with upstream)
Miroslav Grepl [Tue, 28 Jun 2011 12:45:52 +0000 (12:45 +0000)] 
Fix duplicate declarations in filesystem.if (caused by merge with upstream)

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Tue, 28 Jun 2011 12:37:58 +0000 (12:37 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoRemove all duplicate declaration from domain.if, corenetwork.if, files.if
Miroslav Grepl [Tue, 28 Jun 2011 12:36:18 +0000 (12:36 +0000)] 
Remove all duplicate declaration from domain.if, corenetwork.if, files.if

14 years agoFix shorewall.if
Miroslav Grepl [Tue, 28 Jun 2011 12:28:40 +0000 (12:28 +0000)] 
Fix shorewall.if

14 years agoFix for colord.if and others
Miroslav Grepl [Tue, 28 Jun 2011 12:07:40 +0000 (12:07 +0000)] 
Fix for colord.if and others

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 28 Jun 2011 10:30:24 +0000 (06:30 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow systemd_tmpfiles_t to list file_t directories
Dan Walsh [Tue, 28 Jun 2011 10:28:26 +0000 (06:28 -0400)] 
Allow systemd_tmpfiles_t to list file_t directories

14 years agoAllow systemd_tmpfiles_t to list file_t directories
Dan Walsh [Tue, 28 Jun 2011 10:26:41 +0000 (06:26 -0400)] 
Allow systemd_tmpfiles_t to list file_t directories

14 years agoFix more typos
Miroslav Grepl [Tue, 28 Jun 2011 09:41:36 +0000 (09:41 +0000)] 
Fix more typos

14 years agoFix in telepathy.if
Miroslav Grepl [Tue, 28 Jun 2011 08:50:51 +0000 (08:50 +0000)] 
Fix in telepathy.if

14 years agoFix ncftool.if
Miroslav Grepl [Mon, 27 Jun 2011 18:44:05 +0000 (18:44 +0000)] 
Fix ncftool.if

14 years agoqpidd policy was renamed to qpid by upstream
Miroslav Grepl [Mon, 27 Jun 2011 17:53:32 +0000 (17:53 +0000)] 
qpidd policy was renamed to qpid by upstream

14 years agoMove mediawiki policy from apps to services
Miroslav Grepl [Mon, 27 Jun 2011 17:47:23 +0000 (17:47 +0000)] 
Move mediawiki policy from apps to services

14 years agoMove passenger policy from services to admin layer
Miroslav Grepl [Mon, 27 Jun 2011 17:38:59 +0000 (17:38 +0000)] 
Move passenger policy from services to admin layer

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy; branch 'maste...
Miroslav Grepl [Mon, 27 Jun 2011 17:33:58 +0000 (17:33 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy; branch 'master' of http://oss.tresys.com/git/refpolicy

Conflicts:
policy/mcs
policy/modules/admin/ncftool.fc
policy/modules/admin/ncftool.if
policy/modules/admin/ncftool.te
policy/modules/admin/shorewall.if
policy/modules/apps/kdumpgui.te
policy/modules/apps/mozilla.if
policy/modules/apps/mozilla.te
policy/modules/apps/qemu.te
policy/modules/apps/rssh.te
policy/modules/apps/sambagui.te
policy/modules/apps/screen.if
policy/modules/apps/telepathy.fc
policy/modules/apps/telepathy.if
policy/modules/apps/telepathy.te
policy/modules/apps/vmware.te
policy/modules/apps/webalizer.te
policy/modules/apps/wm.fc
policy/modules/kernel/corecommands.fc
policy/modules/kernel/corenetwork.fc
policy/modules/kernel/corenetwork.if.in
policy/modules/kernel/corenetwork.te.in
policy/modules/kernel/devices.if
policy/modules/kernel/domain.if
policy/modules/kernel/files.fc
policy/modules/kernel/files.if
policy/modules/kernel/filesystem.fc
policy/modules/kernel/filesystem.if
policy/modules/kernel/filesystem.te
policy/modules/kernel/selinux.if
policy/modules/kernel/storage.if
policy/modules/kernel/terminal.fc
policy/modules/kernel/terminal.if
policy/modules/roles/sysadm.te
policy/modules/services/aiccu.if
policy/modules/services/aiccu.te
policy/modules/services/aisexec.te
policy/modules/services/amavis.te
policy/modules/services/bugzilla.fc
policy/modules/services/bugzilla.if
policy/modules/services/bugzilla.te
policy/modules/services/cgroup.te
policy/modules/services/cmirrord.fc
policy/modules/services/cmirrord.if
policy/modules/services/cobbler.if
policy/modules/services/colord.fc
policy/modules/services/colord.if
policy/modules/services/colord.te
policy/modules/services/courier.fc
policy/modules/services/cyrus.fc
policy/modules/services/dbus.if
policy/modules/services/dbus.te
policy/modules/services/dovecot.te
policy/modules/services/mpd.fc
policy/modules/services/mpd.if
policy/modules/services/mpd.te
policy/modules/services/postfix.fc
policy/modules/services/vnstatd.fc
policy/modules/services/vnstatd.if
policy/modules/services/vnstatd.te
policy/modules/services/xserver.te
policy/modules/services/zabbix.fc
policy/modules/services/zabbix.te
policy/modules/services/zarafa.fc
policy/modules/services/zarafa.if
policy/modules/services/zarafa.te
policy/modules/system/application.if
policy/modules/system/authlogin.if
policy/modules/system/daemontools.if
policy/modules/system/daemontools.te
policy/modules/system/fstools.te
policy/modules/system/init.te
policy/modules/system/ipsec.fc
policy/modules/system/ipsec.te
policy/modules/system/iptables.fc
policy/modules/system/iptables.if
policy/modules/system/iptables.te
policy/modules/system/iscsi.te
policy/modules/system/libraries.fc
policy/modules/system/logging.fc
policy/modules/system/logging.te
policy/modules/system/sysnetwork.te
policy/modules/system/userdomain.if

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Mon, 27 Jun 2011 14:00:08 +0000 (14:00 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

Conflicts:
policy/modules/kernel/terminal.if
policy/modules/system/logging.te

14 years agoAllow ifconfig to create appletalk_sockets
Dan Walsh [Mon, 27 Jun 2011 12:53:36 +0000 (08:53 -0400)] 
Allow ifconfig to create appletalk_sockets

14 years agoFix filetrans rule
Dan Walsh [Mon, 27 Jun 2011 11:25:34 +0000 (07:25 -0400)] 
Fix filetrans rule

14 years agoFix setcap and getcap for syslogd
Miroslav Grepl [Mon, 27 Jun 2011 07:57:56 +0000 (07:57 +0000)] 
Fix setcap and getcap for syslogd

14 years agoAdd files_delete_all_pid_sockets(init_t) instead of files_unlink_all_pid_sockets
Miroslav Grepl [Mon, 27 Jun 2011 07:48:47 +0000 (07:48 +0000)] 
Add  files_delete_all_pid_sockets(init_t) instead of files_unlink_all_pid_sockets

14 years agoFix name transition for ptmx_t
Miroslav Grepl [Mon, 27 Jun 2011 07:32:23 +0000 (07:32 +0000)] 
Fix name transition for ptmx_t

14 years agologging.te: setcap and getcap are not permissions for the capability
Dominick Grift [Sun, 26 Jun 2011 19:36:26 +0000 (21:36 +0200)] 
logging.te: setcap and getcap are not permissions for the capability
object class they are permissions for the process object class.

14 years agoinit.te: syntax error: files_unlink_all_pid_sockets is now
Dominick Grift [Sun, 26 Jun 2011 19:30:55 +0000 (21:30 +0200)] 
init.te: syntax error: files_unlink_all_pid_sockets is now
files_delete_all_pid_sockets.

14 years agoterminals: commented out for now because it breaks built and does not
Dominick Grift [Sun, 26 Jun 2011 19:22:10 +0000 (21:22 +0200)] 
terminals: commented out for now because it breaks built and does not
make sense.

/dev/pts directories has a (named) file transition rule in here as well
so if /dev/pts gets created with devpts_t then this chr_file in there
will automatically inherit this type from the parent.

If this rule was added as a fall back to ensure that /dev/pts/ptmx gets
created with a proper type even if /dev/pts is created with device_t
instead of devpts_t then we should not use filetrans_pattern here.

14 years agoirssi wants to read /proc/meminfo
Dominick Grift [Sun, 26 Jun 2011 19:09:47 +0000 (21:09 +0200)] 
irssi wants to read /proc/meminfo
irssi: remove duplicate policy (auth_use_nsswitch already provides for
this access)
irssi: remove irssi access to sendrecv from generic ports add access to
sendrecv from ircd and httpd_cache ports instead.

14 years agoRemove bogus $ from postfix.if
Dan Walsh [Sun, 26 Jun 2011 11:22:23 +0000 (07:22 -0400)] 
Remove bogus $ from postfix.if

14 years agoModule version bump for mozilla plugin bug fix from Harry Ciao.
Chris PeBenito [Fri, 24 Jun 2011 13:04:41 +0000 (09:04 -0400)] 
Module version bump for mozilla plugin bug fix from Harry Ciao.

14 years agoFix the call to mozilla_run_plugin.
Harry Ciao [Thu, 23 Jun 2011 02:53:44 +0000 (10:53 +0800)] 
Fix the call to mozilla_run_plugin.

When mozilla_role interface is called, 1st argument is the caller's
role and 2nd argument is the caller's domain, such as:

   mozilla_role(staff_r, staff_t)

When mozilla_role calls mozilla_run_plugin, the passed 2nd argument
should be the caller's role rather than its domain, so $1 not $2 should
be used.

Signed-off-by: Harry Ciao <qingtao.cao@windriver.com>
14 years agoFix label on abrt-hook-ccpp
Dan Walsh [Thu, 23 Jun 2011 20:11:16 +0000 (16:11 -0400)] 
Fix label on abrt-hook-ccpp