]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
14 years agoAlso add MCS fixes for initrc
Miroslav Grepl [Fri, 4 Nov 2011 15:02:17 +0000 (15:02 +0000)] 
Also add MCS fixes for initrc

14 years agoinit_t needs mcs fixes
Miroslav Grepl [Fri, 4 Nov 2011 15:01:34 +0000 (15:01 +0000)] 
init_t needs mcs fixes

14 years agovirtd_t needs to able to relabel chr_file
Miroslav Grepl [Fri, 4 Nov 2011 14:33:12 +0000 (14:33 +0000)] 
virtd_t needs to able to relabel chr_file

14 years agoAllow virtd_t to execute qemu-kvm
Miroslav Grepl [Fri, 4 Nov 2011 14:31:49 +0000 (14:31 +0000)] 
Allow virtd_t to execute qemu-kvm

14 years agoChanges for policy/mcs
Miroslav Grepl [Fri, 4 Nov 2011 13:44:14 +0000 (13:44 +0000)] 
Changes for policy/mcs

14 years agoFix thumb_role() interface
Miroslav Grepl [Fri, 4 Nov 2011 12:24:21 +0000 (12:24 +0000)] 
Fix thumb_role() interface

14 years agoFix typo
Miroslav Grepl [Fri, 4 Nov 2011 12:19:39 +0000 (12:19 +0000)] 
Fix typo

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Fri, 4 Nov 2011 11:42:46 +0000 (11:42 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow systemd-tmpfile to delete /run/user/$USER/dconf
Miroslav Grepl [Fri, 4 Nov 2011 11:42:18 +0000 (11:42 +0000)] 
Allow systemd-tmpfile to delete /run/user/$USER/dconf

14 years agoAdd dirsrvadmin_lock_t type
Miroslav Grepl [Fri, 4 Nov 2011 11:27:53 +0000 (11:27 +0000)] 
Add dirsrvadmin_lock_t type

14 years agoAllow systemd_tmpfiles_t to delete all user content, if the user moves a file to...
Dan Walsh [Thu, 3 Nov 2011 18:29:32 +0000 (14:29 -0400)] 
Allow systemd_tmpfiles_t to delete all user content, if the user moves a file to /tmp, systemd_tmpfiles_t needs to be able to delete it.  Also will fix the abiltiy to delete /run/user/ content

14 years agoAllow plymouthd_t to talk to sssd
Dan Walsh [Thu, 3 Nov 2011 18:23:42 +0000 (14:23 -0400)] 
Allow plymouthd_t to talk to sssd

14 years agoFix context declaration in cloudform.fc
Miroslav Grepl [Thu, 3 Nov 2011 15:31:09 +0000 (15:31 +0000)] 
Fix context declaration in cloudform.fc

14 years agomegadev should be a fixed_disk, not a removable disk.
Dan Walsh [Thu, 3 Nov 2011 15:24:47 +0000 (11:24 -0400)] 
megadev should be a fixed_disk, not a removable disk.
megadev0 is the SCSI board where all the local hard drives are
connected.

14 years agouse the correct interface
Dan Walsh [Thu, 3 Nov 2011 15:16:06 +0000 (11:16 -0400)] 
use the correct interface

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 3 Nov 2011 15:10:30 +0000 (11:10 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoWe have seen mount execute the consolehelper executable
Dan Walsh [Thu, 3 Nov 2011 15:09:51 +0000 (11:09 -0400)] 
We have seen mount execute the consolehelper executable

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
dwalsh [Thu, 3 Nov 2011 14:16:58 +0000 (10:16 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoPackage-cleanup does uses the rpm libraries
Dan Walsh [Thu, 3 Nov 2011 14:15:34 +0000 (10:15 -0400)] 
Package-cleanup does uses the rpm libraries

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 3 Nov 2011 13:25:53 +0000 (09:25 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow quota to add quotadb files to mail_spool and mta_mquue
Dan Walsh [Thu, 3 Nov 2011 13:24:04 +0000 (09:24 -0400)] 
Allow quota to add quotadb files to mail_spool and mta_mquue

14 years agoAllow initrc_t to manage dirsrv pid files
Miroslav Grepl [Thu, 3 Nov 2011 12:19:32 +0000 (12:19 +0000)] 
Allow initrc_t  to manage dirsrv pid files

14 years agoUpdated cloudforms policy for latest AVC's
dwalsh [Wed, 2 Nov 2011 16:40:39 +0000 (12:40 -0400)] 
Updated cloudforms policy for latest AVC's

14 years agoMLS Overrides needed for a user running at a level to be able to use sudo and talk...
dwalsh [Wed, 2 Nov 2011 16:10:22 +0000 (12:10 -0400)] 
MLS Overrides needed for a user running at a level to be able to use sudo and talk to sssd

14 years agoMore AVCS from Tom London for thumb
dwalsh [Wed, 2 Nov 2011 16:09:30 +0000 (12:09 -0400)] 
More AVCS from Tom London for thumb

14 years agoTom London avc's show thumb domain connencting back to user unix_stream_sockets
dwalsh [Wed, 2 Nov 2011 14:33:32 +0000 (10:33 -0400)] 
Tom London avc's show thumb domain connencting back to user unix_stream_sockets

14 years agoTom London shows telepathy_msn_t trying to look at pid 1, no reason to not allow it
dwalsh [Wed, 2 Nov 2011 14:32:57 +0000 (10:32 -0400)] 
Tom London shows telepathy_msn_t trying to look at pid 1, no reason to not allow it

14 years agoAllow userdomains to talk to usbmuxd for handling ipods
dwalsh [Wed, 2 Nov 2011 14:32:08 +0000 (10:32 -0400)] 
Allow userdomains to talk to usbmuxd for handling ipods

14 years agoAllow devicekit_power_t to manage content in gnome directories of home dir, also...
dwalsh [Wed, 2 Nov 2011 14:20:37 +0000 (10:20 -0400)] 
Allow devicekit_power_t to manage content in gnome directories of home dir, also allow it to read /dev/urandom

14 years agoRemove duplicat TE rules
Miroslav Grepl [Wed, 2 Nov 2011 11:38:30 +0000 (11:38 +0000)] 
Remove duplicat TE rules

14 years agoFix dev_filetrans_xserver_named_dev() interface
Miroslav Grepl [Wed, 2 Nov 2011 09:43:46 +0000 (09:43 +0000)] 
Fix dev_filetrans_xserver_named_dev() interface

14 years agoAdd support for pam_tty_audit.so for sudo domains
Miroslav Grepl [Wed, 2 Nov 2011 09:23:11 +0000 (09:23 +0000)] 
Add support for pam_tty_audit.so for sudo domains

14 years agoMake cloudform working again with SELinux
Miroslav Grepl [Wed, 2 Nov 2011 09:03:36 +0000 (09:03 +0000)] 
Make cloudform working again with SELinux

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 2 Nov 2011 07:57:58 +0000 (07:57 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow fsetid to smbd_t policy
Dan Walsh [Tue, 1 Nov 2011 20:28:04 +0000 (16:28 -0400)] 
Allow fsetid to smbd_t policy

14 years agoAdd dev_filetrans_xserver_misc to xserver_t so that if it creates a device in /dev...
Dan Walsh [Tue, 1 Nov 2011 20:21:47 +0000 (16:21 -0400)] 
Add dev_filetrans_xserver_misc to xserver_t so that if it creates a device in /dev it will be labeled xserver_misc_dev_t:

14 years agoAllow xserver_t to create nvidia devices with the correct label
Dan Walsh [Tue, 1 Nov 2011 18:54:12 +0000 (14:54 -0400)] 
Allow xserver_t to create nvidia devices with the correct label

14 years agodevicekit_dontaudit_rw_log actually needs open
Dan Walsh [Tue, 1 Nov 2011 15:39:36 +0000 (11:39 -0400)] 
devicekit_dontaudit_rw_log actually needs open

14 years agomozilla_plugin_tmpfs_t not used in mozila_domtrans_plugin interface
Dan Walsh [Tue, 1 Nov 2011 15:38:52 +0000 (11:38 -0400)] 
mozilla_plugin_tmpfs_t not used in mozila_domtrans_plugin interface

14 years agoDuplicate policy removed
Dan Walsh [Tue, 1 Nov 2011 15:38:24 +0000 (11:38 -0400)] 
Duplicate policy removed

14 years agognomeclock on kde wants to create dgram_socket
Dan Walsh [Tue, 1 Nov 2011 15:15:25 +0000 (11:15 -0400)] 
gnomeclock on kde wants to create dgram_socket

14 years agoinitrc_t should not be setting up devices if unconfined.pp is disabled
Dan Walsh [Tue, 1 Nov 2011 13:40:39 +0000 (09:40 -0400)] 
initrc_t should not be setting up devices if unconfined.pp is disabled

14 years agoAllow virtd_t domains to manage svirt_image_t chr_file
Dan Walsh [Tue, 1 Nov 2011 13:40:03 +0000 (09:40 -0400)] 
Allow virtd_t domains to manage svirt_image_t chr_file

14 years agoAllow tor to read sysfs_t
Miroslav Grepl [Tue, 1 Nov 2011 11:59:07 +0000 (11:59 +0000)] 
Allow tor to read sysfs_t

14 years agoFix abrt_manage_cache() interface
Miroslav Grepl [Tue, 1 Nov 2011 11:17:28 +0000 (11:17 +0000)] 
Fix abrt_manage_cache() interface

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Tue, 1 Nov 2011 11:09:43 +0000 (11:09 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoRevert "remove temporary fixes"
Miroslav Grepl [Tue, 1 Nov 2011 06:39:55 +0000 (06:39 +0000)] 
Revert "remove temporary fixes"

This reverts commit d62a4335e120f3f385575c25d20e2198b69ac3c1.

14 years agoRevert "Temporary remove conflict filename transition for kernel_t"
Miroslav Grepl [Tue, 1 Nov 2011 06:31:38 +0000 (06:31 +0000)] 
Revert "Temporary remove conflict filename transition for kernel_t"

This reverts commit dac919641809cd23dbdeb7f8b288c985a3d6b7ef.

14 years agoremove temporary fixes
Miroslav Grepl [Tue, 1 Nov 2011 06:30:50 +0000 (06:30 +0000)] 
remove temporary fixes

14 years agoMake filetrans rules optional so base policy will build
Dan Walsh [Mon, 31 Oct 2011 20:39:56 +0000 (16:39 -0400)] 
Make filetrans rules optional so base policy will build

14 years agoDontaudit chkpwd_t access to inherited TTYS
Dan Walsh [Mon, 31 Oct 2011 18:50:49 +0000 (14:50 -0400)] 
Dontaudit chkpwd_t access to inherited TTYS

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 31 Oct 2011 18:46:20 +0000 (14:46 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoMake sure postfix content gets created with the correct label
Dan Walsh [Mon, 31 Oct 2011 18:46:07 +0000 (14:46 -0400)] 
Make sure postfix content gets created with the correct label

14 years agoTemporary remove conflict filename transition for kernel_t
Miroslav Grepl [Mon, 31 Oct 2011 14:49:40 +0000 (14:49 +0000)] 
Temporary remove conflict filename transition for kernel_t

14 years agoAllow gnomeclock to read cgroup
Miroslav Grepl [Mon, 31 Oct 2011 13:10:36 +0000 (13:10 +0000)] 
Allow gnomeclock to read cgroup

14 years agoMove libs* calling in kernel.te to optional blokc
Miroslav Grepl [Mon, 31 Oct 2011 11:26:12 +0000 (11:26 +0000)] 
Move libs* calling in kernel.te to optional blokc

14 years agoFixes for cloudform policy
Miroslav Grepl [Mon, 31 Oct 2011 11:11:01 +0000 (11:11 +0000)] 
Fixes for cloudform policy

14 years agoAllow pptp to read kernel network state
Miroslav Grepl [Mon, 31 Oct 2011 10:00:08 +0000 (10:00 +0000)] 
Allow pptp to read kernel network state

14 years agoAllow gpg to read spamd tmp file
Miroslav Grepl [Mon, 31 Oct 2011 08:37:58 +0000 (08:37 +0000)] 
Allow gpg to read spamd tmp file

14 years agoAllow kcmdatetimehelper to read hardware state information
Miroslav Grepl [Mon, 31 Oct 2011 08:56:20 +0000 (08:56 +0000)] 
Allow kcmdatetimehelper to read hardware state information

14 years agoNew name for imagfac.py
Dan Walsh [Fri, 28 Oct 2011 20:36:35 +0000 (16:36 -0400)] 
New name for imagfac.py

14 years agoMove named file trans rules from unconfined_t to all unconfined_domains
Dan Walsh [Fri, 28 Oct 2011 20:28:58 +0000 (16:28 -0400)] 
Move named file trans rules from unconfined_t to all unconfined_domains

14 years agomatahari-serviced reads /etc/machine-id
Dan Walsh [Fri, 28 Oct 2011 20:28:06 +0000 (16:28 -0400)] 
matahari-serviced reads /etc/machine-id

14 years agoAllow plymouthd to read the process info on gdm
Dan Walsh [Fri, 28 Oct 2011 20:02:50 +0000 (16:02 -0400)] 
Allow plymouthd to read the process info on gdm

14 years agoAdd policy for matahari-qmf-sysconfigd
Dan Walsh [Fri, 28 Oct 2011 16:38:09 +0000 (12:38 -0400)] 
Add policy for matahari-qmf-sysconfigd

14 years agoAdd policy for matahari-qmf-sysconfigd
Dan Walsh [Fri, 28 Oct 2011 16:36:29 +0000 (12:36 -0400)] 
Add policy for matahari-qmf-sysconfigd

14 years agouse LDAP (OpenLDAP) with TLS (NSS) requires slapd_t be able to write to /var/cache...
Dan Walsh [Fri, 28 Oct 2011 13:57:23 +0000 (09:57 -0400)] 
use LDAP (OpenLDAP) with TLS (NSS) requires slapd_t be able to write to /var/cache/coolkey

14 years agoHandle all drupal versions
Dan Walsh [Fri, 28 Oct 2011 13:41:31 +0000 (09:41 -0400)] 
Handle all drupal versions

14 years agoAllow dovecot_auth to changes the sched algorythm
Dan Walsh [Fri, 28 Oct 2011 13:31:01 +0000 (09:31 -0400)] 
Allow dovecot_auth to changes the sched algorythm

14 years agoadditional access required for matahari_serviced_t
Dan Walsh [Fri, 28 Oct 2011 13:24:02 +0000 (09:24 -0400)] 
additional access required for matahari_serviced_t

14 years agoNeed to allow matahari_serviced_t to transition scripts and config all services
Dan Walsh [Fri, 28 Oct 2011 13:21:14 +0000 (09:21 -0400)] 
Need to allow matahari_serviced_t to transition scripts and config all services

14 years agoAllow chrome_sandbox_t to search user homedirs
Dan Walsh [Thu, 27 Oct 2011 21:21:59 +0000 (17:21 -0400)] 
Allow chrome_sandbox_t to search user homedirs

14 years agoChome_sandbox needs to read chrome_sandbox_nacl_t /proc data
Dan Walsh [Thu, 27 Oct 2011 20:57:32 +0000 (16:57 -0400)] 
Chome_sandbox needs to read chrome_sandbox_nacl_t /proc data

14 years agoAllow chrome to interact with passed in stream sockets
Dan Walsh [Thu, 27 Oct 2011 20:15:29 +0000 (16:15 -0400)] 
Allow chrome to interact with passed in stream sockets

14 years agoCheck in fixed for Chrome nacl support
Dan Walsh [Thu, 27 Oct 2011 13:50:04 +0000 (09:50 -0400)] 
Check in fixed for Chrome nacl support

14 years agoBegin removing qemu_t domain, we really no longer need this domain. Want to
Dan Walsh [Wed, 26 Oct 2011 14:16:32 +0000 (10:16 -0400)] 
Begin removing qemu_t domain, we really no longer need this domain.  Want to
remove transition from staff_t domain, staff_t should be using libvirt to
launch virtual machines.

14 years agosystemd_passwd needs dac_overide to communicate with users TTY's
Dan Walsh [Wed, 26 Oct 2011 13:23:02 +0000 (09:23 -0400)] 
systemd_passwd needs dac_overide to communicate with users TTY's

14 years agoAllow svirt_lxc domains to send kill signals within their container
Dan Walsh [Wed, 26 Oct 2011 13:22:31 +0000 (09:22 -0400)] 
Allow svirt_lxc domains to send kill signals within their container

14 years agoAllow policykit to talk to the systemd via dbus
Dan Walsh [Tue, 25 Oct 2011 19:53:29 +0000 (15:53 -0400)] 
Allow policykit to talk to the systemd via dbus

14 years agoMove chrome_sandbox_nacl_t to permissive domains
Dan Walsh [Tue, 25 Oct 2011 19:49:55 +0000 (15:49 -0400)] 
Move chrome_sandbox_nacl_t to permissive domains

14 years agoAdditional rules for chrome_sandbox_nacl
Dan Walsh [Tue, 25 Oct 2011 19:48:41 +0000 (15:48 -0400)] 
Additional rules for chrome_sandbox_nacl

14 years agoChange bootstrap name to nacl
Dan Walsh [Tue, 25 Oct 2011 15:40:06 +0000 (11:40 -0400)] 
Change bootstrap name to nacl

14 years agoChrome still needs execmem
Dan Walsh [Tue, 25 Oct 2011 15:21:14 +0000 (11:21 -0400)] 
Chrome still needs execmem

14 years agoMissing role for chrome_sandbox_bootstrap
Dan Walsh [Tue, 25 Oct 2011 15:20:41 +0000 (11:20 -0400)] 
Missing role for chrome_sandbox_bootstrap

14 years agoAdd boolean to remove execmem and execstack from virtual machines
Dan Walsh [Tue, 25 Oct 2011 14:42:31 +0000 (10:42 -0400)] 
Add boolean to remove execmem and execstack from virtual machines

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 25 Oct 2011 13:47:44 +0000 (09:47 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoDontaudit xdm_t doing an access_check on etc_t directories
Dan Walsh [Tue, 25 Oct 2011 13:47:28 +0000 (09:47 -0400)] 
Dontaudit xdm_t doing an access_check on etc_t directories

14 years agoAllow named to connect to dirsrv
Miroslav Grepl [Mon, 24 Oct 2011 22:13:52 +0000 (22:13 +0000)] 
Allow named to connect to dirsrv

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Mon, 24 Oct 2011 22:01:22 +0000 (22:01 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoApparently chrome does not need execmem any longer
Dan Walsh [Mon, 24 Oct 2011 20:41:24 +0000 (16:41 -0400)] 
Apparently chrome does not need execmem any longer

14 years agoudev talks to its own sock_file in /var/run/udevl
Dan Walsh [Mon, 24 Oct 2011 20:27:32 +0000 (16:27 -0400)] 
udev talks to its own sock_file in /var/run/udevl

14 years agoadd ldapmap1_0 as a krb5_host_rcache_t file
Dan Walsh [Mon, 24 Oct 2011 15:54:22 +0000 (11:54 -0400)] 
add ldapmap1_0 as a krb5_host_rcache_t file

14 years agoGoogle chrome developers asked me to add bootstrap policy for nacl stuff
Dan Walsh [Mon, 24 Oct 2011 15:31:13 +0000 (11:31 -0400)] 
Google chrome developers asked me to add bootstrap policy for nacl stuff

14 years agoFix abrt_manage_cache() interface
Miroslav Grepl [Mon, 24 Oct 2011 13:11:13 +0000 (13:11 +0000)] 
Fix abrt_manage_cache() interface

14 years agoAllow rhev_agentd_t to getattr on mountpoints
Miroslav Grepl [Mon, 24 Oct 2011 12:54:44 +0000 (12:54 +0000)] 
Allow rhev_agentd_t to getattr on mountpoints

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 24 Oct 2011 12:30:41 +0000 (08:30 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoPostfix_smtpd_t needs access to milters and cleanup seems to read/write postfix_smtpd...
Dan Walsh [Mon, 24 Oct 2011 12:30:20 +0000 (08:30 -0400)] 
Postfix_smtpd_t needs access to milters and cleanup seems to read/write postfix_smtpd_t unix_stream_sockets

14 years agoFix typo
Miroslav Grepl [Mon, 24 Oct 2011 09:08:17 +0000 (09:08 +0000)] 
Fix typo

14 years agoFixes for cloudform policies which need to connect to random ports
Miroslav Grepl [Mon, 24 Oct 2011 08:28:36 +0000 (08:28 +0000)] 
Fixes for cloudform policies which need to connect to random ports

14 years agoI have no idea why these guys have this label but it is wrong.
Dan Walsh [Fri, 21 Oct 2011 20:09:10 +0000 (16:09 -0400)] 
I have no idea why these guys have this label but it is wrong.