]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Dan Walsh [Fri, 10 Jun 2011 16:23:45 +0000 (12:23 -0400)]
Fix auth_manage_var_auth
Dan Walsh [Fri, 10 Jun 2011 16:21:18 +0000 (12:21 -0400)]
Mistake when adding append_inherited_perms
Dan Walsh [Fri, 10 Jun 2011 16:13:26 +0000 (12:13 -0400)]
Allow piranha domains to signal each other, fix type to allow piranha_pulse_t to transition to piranha_fos_t
Dan Walsh [Fri, 10 Jun 2011 15:54:39 +0000 (11:54 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 10 Jun 2011 15:54:14 +0000 (11:54 -0400)]
Allow lvm to read/write pipes inherited from login programs
Dan Walsh [Fri, 10 Jun 2011 15:40:28 +0000 (11:40 -0400)]
Make sure pulseaudio content is created with correct context
Dominick Grift [Fri, 10 Jun 2011 11:28:04 +0000 (13:28 +0200)]
Call irc role for confined users
Dominick Grift [Fri, 10 Jun 2011 10:27:09 +0000 (12:27 +0200)]
Merge branch 'httpd_user_content'
Dominick Grift [Fri, 10 Jun 2011 10:13:35 +0000 (12:13 +0200)]
fix jabber syntax error
Dominick Grift [Fri, 10 Jun 2011 10:03:27 +0000 (12:03 +0200)]
Add some more obvious named file transitions for apache home content
Miroslav Grepl [Fri, 10 Jun 2011 08:11:02 +0000 (08:11 +0000)]
setfiles needs to be able to read symlinks to make restorecon on symlink working
Dan Walsh [Fri, 10 Jun 2011 03:42:02 +0000 (23:42 -0400)]
Allow most postfix domains to ignore MCS constraints
Dan Walsh [Fri, 10 Jun 2011 03:22:12 +0000 (23:22 -0400)]
mcswriteall should allow a process to ignore mcs labels
Dan Walsh [Thu, 9 Jun 2011 18:33:35 +0000 (14:33 -0400)]
Allow nut_upsd_t to signal itself
Miroslav Grepl [Thu, 9 Jun 2011 15:22:12 +0000 (15:22 +0000)]
audisp needs to to read system state and need to get attributes of / fs.
Miroslav Grepl [Thu, 9 Jun 2011 14:59:44 +0000 (14:59 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 9 Jun 2011 14:57:07 +0000 (14:57 +0000)]
dhcpc needs to use userdom_use_user_terminals() to make "ifup" working
Miroslav Grepl [Thu, 9 Jun 2011 11:47:29 +0000 (11:47 +0000)]
Clean up and fixes for jabber policy
Dominick Grift [Thu, 9 Jun 2011 11:15:36 +0000 (13:15 +0200)]
Merge branch 'fixes'
Dominick Grift [Thu, 9 Jun 2011 10:53:39 +0000 (12:53 +0200)]
gnome keyringd needs to read system state
telepathy_domains need to get attributes of / fs.
Dominick Grift [Wed, 8 Jun 2011 19:47:45 +0000 (21:47 +0200)]
postfix pickup fifo file #711866
Dan Walsh [Wed, 8 Jun 2011 18:37:11 +0000 (14:37 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 8 Jun 2011 18:36:51 +0000 (14:36 -0400)]
Update all references to selinuxfs to allow ssearching sysfs_t
Dominick Grift [Wed, 8 Jun 2011 18:29:54 +0000 (20:29 +0200)]
puppetmaster use nsswitch: #711804
Dominick Grift [Wed, 8 Jun 2011 17:25:39 +0000 (19:25 +0200)]
fix a typo
Chris PeBenito [Wed, 8 Jun 2011 17:05:34 +0000 (13:05 -0400)]
Merge various apps layer changes from the Fedora policy.
Dominick Grift [Wed, 8 Jun 2011 16:57:58 +0000 (18:57 +0200)]
Really needs execute; audit_access wont do it.
Dominick Grift [Wed, 8 Jun 2011 16:54:43 +0000 (18:54 +0200)]
logwatch mail: just allow it to use system_cronjob_t fds for now.
Dominick Grift [Wed, 8 Jun 2011 16:52:56 +0000 (18:52 +0200)]
Implement userdom_user_tmpfs_content()
users are allowed to manage all user tmpfs type content now so we do not
have to specify rules to specific user tmp and user tmpfs types.
Dominick Grift [Wed, 8 Jun 2011 16:46:49 +0000 (18:46 +0200)]
Edit userdom_manage_tmp/tmpfs_role to use user_tmp_type and
user_tmpfs_type respectively: if a type is declared user type then the
user needs to be able to manage (and relabel) it.
Dominick Grift [Wed, 8 Jun 2011 14:27:36 +0000 (16:27 +0200)]
sandbox fds: this does need seem to be strictly needed
allow sandbox_xserver_t staff_seunshare_t:fd use;
Dominick Grift [Wed, 8 Jun 2011 14:12:21 +0000 (16:12 +0200)]
Various sandbox X related fixes:
allow sandbox_web_client_t fs_t:filesystem quotaget;
fs_get_xattr_fs_quota($1_client_t)
allow sandbox_web_t staff_seunshare_t:fd use;
allow sandbox_xserver_t staff_screen_t:fd use;
domain_use_interactive_fds(sandbox_xserver_t)
Chris PeBenito [Wed, 8 Jun 2011 12:51:55 +0000 (08:51 -0400)]
Cyrus file context update for Gentoo from Corentin Labbe.
Dominick Grift [Tue, 7 Jun 2011 21:28:18 +0000 (23:28 +0200)]
use usertype here because chrome is labeled execmem_exec_t so we want
$1_execmem_t (which is $1_usertype) to be able to transition to the
sandbox.
Dominick Grift [Tue, 7 Jun 2011 20:20:21 +0000 (22:20 +0200)]
Merge branch 'cron_fd'
Dominick Grift [Tue, 7 Jun 2011 20:07:21 +0000 (22:07 +0200)]
logwatch_mail_t wants to use system_cronjob_t fds #711498
Dan Walsh [Tue, 7 Jun 2011 19:42:29 +0000 (15:42 -0400)]
Allow zabbix to getpw* calls and use semaphores
Dan Walsh [Tue, 7 Jun 2011 18:19:37 +0000 (14:19 -0400)]
init script needs to be able to manage sanlock_var_run_t files
Dan Walsh [Tue, 7 Jun 2011 18:11:31 +0000 (14:11 -0400)]
Allow sandlock and wdmd to create /var/run directories with the proper label
Dan Walsh [Tue, 7 Jun 2011 16:15:46 +0000 (12:15 -0400)]
mixclip.so has been compiled correctly
Dan Walsh [Tue, 7 Jun 2011 16:11:15 +0000 (12:11 -0400)]
Fix passenger policy module name
Miroslav Grepl [Tue, 7 Jun 2011 18:00:01 +0000 (18:00 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Tue, 7 Jun 2011 17:59:02 +0000 (17:59 +0000)]
Add jabberd_domain_template()
* Note: will use for ejabberd
Dominick Grift [Tue, 7 Jun 2011 14:05:04 +0000 (16:05 +0200)]
Remove duplicate mozilla_plugin_t policy
Dominick Grift [Tue, 7 Jun 2011 13:59:17 +0000 (15:59 +0200)]
pulseaudio really needs to open mozilla_plugin_tmpfs files.
calling user needs to be able to delete and read
mozilla_plugin_tmpfs_files atleast (pulse-shm)
allow calling users to ptrace, signal and ps mozilla_plugin_t
Chris PeBenito [Tue, 7 Jun 2011 13:14:53 +0000 (09:14 -0400)]
Merge ncftool from Fedora.
Dominick Grift [Mon, 6 Jun 2011 19:42:17 +0000 (21:42 +0200)]
Merge branch 'openicc'
Dominick Grift [Mon, 6 Jun 2011 19:42:03 +0000 (21:42 +0200)]
Merge branch 'fixes'
Dominick Grift [Mon, 6 Jun 2011 19:40:04 +0000 (21:40 +0200)]
Merge branch 'chrome'
Dominick Grift [Mon, 6 Jun 2011 19:24:55 +0000 (21:24 +0200)]
remove chrome_role from execmem_role_template chrome is already
allowed execmem.
call chrome role for user_t and staff_t
Dan Walsh [Mon, 6 Jun 2011 19:08:38 +0000 (15:08 -0400)]
Zabbix needs these rules when starting the zabbix_server_mysql
Dominick Grift [Mon, 6 Jun 2011 19:05:31 +0000 (21:05 +0200)]
selinux_t does not exist
Dominick Grift [Mon, 6 Jun 2011 18:55:26 +0000 (20:55 +0200)]
fix build
Dan Walsh [Mon, 6 Jun 2011 18:23:48 +0000 (14:23 -0400)]
Allow chrome to optionally be transitioned to
Dan Walsh [Mon, 6 Jun 2011 18:23:28 +0000 (14:23 -0400)]
Allow chrome to optionally be transitioned to
Dominick Grift [Mon, 6 Jun 2011 17:56:46 +0000 (19:56 +0200)]
Fix fix labeling of /usr/lib/xfce4
Dominick Grift [Mon, 6 Jun 2011 17:41:25 +0000 (19:41 +0200)]
Implement a type for freedesktop openicc standard (~/.local/share/icc)
Allow system_dbusd_t to read inherited icc_data_home_t files.
Allow colord_t to read icc_data_home_t content. #706975
http://www.freedesktop.org/wiki/OpenIcc#OpenICCproject
Dan Walsh [Mon, 6 Jun 2011 17:10:46 +0000 (13:10 -0400)]
Label stuff under /usr/lib/debug as if it was labeled under /
Dan Walsh [Mon, 6 Jun 2011 16:52:43 +0000 (12:52 -0400)]
Make unconfined_t transitioning to chrome_sanbox_t optional by boolean
Dan Walsh [Mon, 6 Jun 2011 16:35:13 +0000 (12:35 -0400)]
Fix labeling under /usr/lib/xfce4
Dan Walsh [Mon, 6 Jun 2011 15:49:21 +0000 (11:49 -0400)]
Init is now loading policy and mount selinuxfs
Miroslav Grepl [Mon, 6 Jun 2011 10:46:38 +0000 (10:46 +0000)]
Allow puppetmaster to create dirs in /var/run/puppet
Miroslav Grepl [Mon, 6 Jun 2011 12:03:46 +0000 (12:03 +0000)]
Allow ssh to execute systemctl
Miroslav Grepl [Mon, 6 Jun 2011 15:23:20 +0000 (15:23 +0000)]
Fixes for rhev-agent policy
Miroslav Grepl [Mon, 6 Jun 2011 11:05:18 +0000 (11:05 +0000)]
Allow fail2ban to create fail2ban_tmp_t dirs
Dominick Grift [Sun, 5 Jun 2011 10:41:21 +0000 (12:41 +0200)]
Initial mailscanner policy
Dan Walsh [Fri, 3 Jun 2011 20:29:49 +0000 (16:29 -0400)]
Allow programs that can read/write etc_runtime_t read links with that label, already allowed for read_etc_runtime_files
Allow postfix_pickup to ignore MCS labels
Add append_inherited_file_perms
Dan Walsh [Fri, 3 Jun 2011 15:58:59 +0000 (11:58 -0400)]
Allow mailserver_delivery and uux_t to read/write postfix_master_pipes.
Dan Walsh [Fri, 3 Jun 2011 15:51:01 +0000 (11:51 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 3 Jun 2011 15:50:31 +0000 (11:50 -0400)]
dontaudit devicekit trying to list contents of mnt_t
Dominick Grift [Thu, 2 Jun 2011 13:52:25 +0000 (15:52 +0200)]
Merge branch 'refs/heads/master' of ssh://domg472@git.fedorahosted.org/git/selinux-policy.git
Dominick Grift [Thu, 2 Jun 2011 13:33:32 +0000 (15:33 +0200)]
Rwho needs to stat() user terminal character files #708378
Miroslav Grepl [Thu, 2 Jun 2011 15:03:14 +0000 (15:03 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 2 Jun 2011 14:49:31 +0000 (14:49 +0000)]
Allow sys_chroot for postfix domains
Dan Walsh [Thu, 2 Jun 2011 13:27:54 +0000 (09:27 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 2 Jun 2011 13:27:40 +0000 (09:27 -0400)]
rwho needs to be able to getattr on user timernals
Dan Walsh [Thu, 2 Jun 2011 12:54:31 +0000 (08:54 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 2 Jun 2011 12:54:19 +0000 (08:54 -0400)]
Allow virtd_t to stream conect to sanlock, dontaudit leaked file descriptor from virtd_t to svirt_t, this is intentional
Dominick Grift [Wed, 1 Jun 2011 17:36:48 +0000 (19:36 +0200)]
Merge branch 'refs/heads/master' of ssh://domg472@git.fedorahosted.org/git/selinux-policy.git
Dan Walsh [Wed, 1 Jun 2011 17:32:33 +0000 (13:32 -0400)]
Allow apache to read proc_net_t
Allow userdomains to use seunshare fds
Dominick Grift [Wed, 1 Jun 2011 17:29:30 +0000 (19:29 +0200)]
networkmanager_filetrans_named_content: it does not like paths
Dan Walsh [Wed, 1 Jun 2011 17:22:03 +0000 (13:22 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 1 Jun 2011 17:19:28 +0000 (13:19 -0400)]
Move dev_filetrans_all_named_dev out of tunable init_systemd
Dominick Grift [Wed, 1 Jun 2011 15:46:35 +0000 (17:46 +0200)]
Do not support nfs/cifs #708474
Dominick Grift [Wed, 1 Jun 2011 15:42:14 +0000 (17:42 +0200)]
colord get attribute removable devices as per mgrepl's suggestion
Dan Walsh [Wed, 1 Jun 2011 14:10:57 +0000 (10:10 -0400)]
Make sure init, udev, initrc creating devices creates them with the right label
Dan Walsh [Wed, 1 Jun 2011 14:04:45 +0000 (10:04 -0400)]
Unconfined_t running wpa by hand causes nm-dhclient-eth1.conf to be mislabeled
Miroslav Grepl [Wed, 1 Jun 2011 14:46:29 +0000 (14:46 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dominick Grift [Wed, 1 Jun 2011 10:25:29 +0000 (12:25 +0200)]
rpm_t only needs to relabel generic device nodes
Dominick Grift [Wed, 1 Jun 2011 09:55:57 +0000 (11:55 +0200)]
fix syntax error
Dominick Grift [Wed, 1 Jun 2011 09:44:17 +0000 (11:44 +0200)]
rpm creates and renames generic device_t blk and chr files.
rpm relabels generic device_t blk and chr files to any device_node.
rpm deletes and sets attributes of all chr and blk device nodes.
Dominick Grift [Wed, 1 Jun 2011 09:25:13 +0000 (11:25 +0200)]
pulseaudio wants to read inherited mozilla plugin tmpfs files:
avc: denied { read } for pid=1630 comm="pulseaudio"
name="pulse-shm-
4091746155 " dev=tmpfs ino=53954
scontext=staff_u:staff_r:pulseaudio_t:s0-s0:c0.c1023
tcontext=staff_u:object_r:mozill _plugin_tmpfs_t:s0 tclass=file
Dominick Grift [Wed, 1 Jun 2011 09:20:05 +0000 (11:20 +0200)]
ldconfig wants to list user home directories:
avc: denied { read } for pid=29900 comm="ldconfig"
path="/home/dgrift" dev=dm-3 ino=
5767169
scontext=staff_u:system_r:ldconfig_t:s0-s0:c0.c1023
tcontext=staff_u:object_r:user_home_dir_t:s0 tclass=dir
Miroslav Grepl [Wed, 1 Jun 2011 08:53:10 +0000 (08:53 +0000)]
Add label for /var/lock/ppp directory
Dan Walsh [Tue, 31 May 2011 18:16:21 +0000 (14:16 -0400)]
Add filetrans_home_content for quota
Dan Walsh [Tue, 31 May 2011 17:16:36 +0000 (13:16 -0400)]
Fix sanlock policy and allow inetd_t to mls_net all levels for outbound networks
Dan Walsh [Tue, 31 May 2011 14:25:24 +0000 (10:25 -0400)]
Allow init to read adjtime
Allow pulseaudio to send signull to keyring
Dominick Grift [Tue, 31 May 2011 10:54:26 +0000 (12:54 +0200)]
Label /var/log/roundcubemail type httpd_log_t so that the webapp
(httpd_t) can log to it. #709246
Dominick Grift [Tue, 31 May 2011 09:08:09 +0000 (11:08 +0200)]
dovecot_deliver wants to read dovecot sock files and wants to stream
connect to dovecot #709257 #709255
Dominick Grift [Tue, 31 May 2011 08:45:19 +0000 (10:45 +0200)]
Extend audit_access interfaces to allow get attributes.
puppetmaster may only need to check access to groupadd useradd and
passwd (chage) #708897