]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
14 years agoFix auth_manage_var_auth
Dan Walsh [Fri, 10 Jun 2011 16:23:45 +0000 (12:23 -0400)] 
Fix auth_manage_var_auth

14 years agoMistake when adding append_inherited_perms
Dan Walsh [Fri, 10 Jun 2011 16:21:18 +0000 (12:21 -0400)] 
Mistake when adding append_inherited_perms

14 years agoAllow piranha domains to signal each other, fix type to allow piranha_pulse_t to...
Dan Walsh [Fri, 10 Jun 2011 16:13:26 +0000 (12:13 -0400)] 
Allow piranha domains to signal each other, fix type to allow piranha_pulse_t to transition to piranha_fos_t

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 10 Jun 2011 15:54:39 +0000 (11:54 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow lvm to read/write pipes inherited from login programs
Dan Walsh [Fri, 10 Jun 2011 15:54:14 +0000 (11:54 -0400)] 
Allow lvm to read/write pipes inherited from login programs

14 years agoMake sure pulseaudio content is created with correct context
Dan Walsh [Fri, 10 Jun 2011 15:40:28 +0000 (11:40 -0400)] 
Make sure pulseaudio content is created with correct context

14 years agoCall irc role for confined users
Dominick Grift [Fri, 10 Jun 2011 11:28:04 +0000 (13:28 +0200)] 
Call irc role for confined users

14 years agoMerge branch 'httpd_user_content'
Dominick Grift [Fri, 10 Jun 2011 10:27:09 +0000 (12:27 +0200)] 
Merge branch 'httpd_user_content'

14 years agofix jabber syntax error
Dominick Grift [Fri, 10 Jun 2011 10:13:35 +0000 (12:13 +0200)] 
fix jabber syntax error

14 years agoAdd some more obvious named file transitions for apache home content
Dominick Grift [Fri, 10 Jun 2011 10:03:27 +0000 (12:03 +0200)] 
Add some more obvious named file transitions for apache home content

14 years agosetfiles needs to be able to read symlinks to make restorecon on symlink working
Miroslav Grepl [Fri, 10 Jun 2011 08:11:02 +0000 (08:11 +0000)] 
setfiles needs to be able to read symlinks to make restorecon on symlink working

14 years agoAllow most postfix domains to ignore MCS constraints
Dan Walsh [Fri, 10 Jun 2011 03:42:02 +0000 (23:42 -0400)] 
Allow most postfix domains to ignore MCS constraints

14 years agomcswriteall should allow a process to ignore mcs labels
Dan Walsh [Fri, 10 Jun 2011 03:22:12 +0000 (23:22 -0400)] 
mcswriteall should allow a process to ignore mcs labels

14 years agoAllow nut_upsd_t to signal itself
Dan Walsh [Thu, 9 Jun 2011 18:33:35 +0000 (14:33 -0400)] 
Allow nut_upsd_t to signal itself

14 years agoaudisp needs to to read system state and need to get attributes of / fs.
Miroslav Grepl [Thu, 9 Jun 2011 15:22:12 +0000 (15:22 +0000)] 
audisp needs to to read system state and  need to get attributes of / fs.

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 9 Jun 2011 14:59:44 +0000 (14:59 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agodhcpc needs to use userdom_use_user_terminals() to make "ifup" working
Miroslav Grepl [Thu, 9 Jun 2011 14:57:07 +0000 (14:57 +0000)] 
dhcpc needs to use userdom_use_user_terminals() to make "ifup" working

14 years agoClean up and fixes for jabber policy
Miroslav Grepl [Thu, 9 Jun 2011 11:47:29 +0000 (11:47 +0000)] 
Clean up and fixes for jabber policy

14 years agoMerge branch 'fixes'
Dominick Grift [Thu, 9 Jun 2011 11:15:36 +0000 (13:15 +0200)] 
Merge branch 'fixes'

14 years agognome keyringd needs to read system state
Dominick Grift [Thu, 9 Jun 2011 10:53:39 +0000 (12:53 +0200)] 
gnome keyringd needs to read system state
telepathy_domains need to get attributes of / fs.

14 years agopostfix pickup fifo file #711866
Dominick Grift [Wed, 8 Jun 2011 19:47:45 +0000 (21:47 +0200)] 
postfix pickup fifo file #711866

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 8 Jun 2011 18:37:11 +0000 (14:37 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoUpdate all references to selinuxfs to allow ssearching sysfs_t
Dan Walsh [Wed, 8 Jun 2011 18:36:51 +0000 (14:36 -0400)] 
Update all references to selinuxfs to allow ssearching sysfs_t

14 years agopuppetmaster use nsswitch: #711804
Dominick Grift [Wed, 8 Jun 2011 18:29:54 +0000 (20:29 +0200)] 
puppetmaster use nsswitch: #711804

14 years agofix a typo
Dominick Grift [Wed, 8 Jun 2011 17:25:39 +0000 (19:25 +0200)] 
fix a typo

14 years agoMerge various apps layer changes from the Fedora policy.
Chris PeBenito [Wed, 8 Jun 2011 17:05:34 +0000 (13:05 -0400)] 
Merge various apps layer changes from the Fedora policy.

14 years agoReally needs execute; audit_access wont do it.
Dominick Grift [Wed, 8 Jun 2011 16:57:58 +0000 (18:57 +0200)] 
Really needs execute; audit_access wont do it.

14 years agologwatch mail: just allow it to use system_cronjob_t fds for now.
Dominick Grift [Wed, 8 Jun 2011 16:54:43 +0000 (18:54 +0200)] 
logwatch mail: just allow it to use system_cronjob_t fds for now.

14 years agoImplement userdom_user_tmpfs_content()
Dominick Grift [Wed, 8 Jun 2011 16:52:56 +0000 (18:52 +0200)] 
Implement userdom_user_tmpfs_content()
users are allowed to manage all user tmpfs type content now so we do not
have to specify rules to specific user tmp and user tmpfs types.

14 years agoEdit userdom_manage_tmp/tmpfs_role to use user_tmp_type and
Dominick Grift [Wed, 8 Jun 2011 16:46:49 +0000 (18:46 +0200)] 
Edit userdom_manage_tmp/tmpfs_role to use user_tmp_type and
user_tmpfs_type respectively: if a type is declared user type then the
user needs to be able to manage (and relabel) it.

14 years agosandbox fds: this does need seem to be strictly needed
Dominick Grift [Wed, 8 Jun 2011 14:27:36 +0000 (16:27 +0200)] 
sandbox fds: this does need seem to be strictly needed
allow sandbox_xserver_t staff_seunshare_t:fd use;

14 years agoVarious sandbox X related fixes:
Dominick Grift [Wed, 8 Jun 2011 14:12:21 +0000 (16:12 +0200)] 
Various sandbox X related fixes:

allow sandbox_web_client_t fs_t:filesystem quotaget;
fs_get_xattr_fs_quota($1_client_t)
allow sandbox_web_t staff_seunshare_t:fd use;
allow sandbox_xserver_t staff_screen_t:fd use;
domain_use_interactive_fds(sandbox_xserver_t)

14 years agoCyrus file context update for Gentoo from Corentin Labbe.
Chris PeBenito [Wed, 8 Jun 2011 12:51:55 +0000 (08:51 -0400)] 
Cyrus file context update for Gentoo from Corentin Labbe.

14 years agouse usertype here because chrome is labeled execmem_exec_t so we want
Dominick Grift [Tue, 7 Jun 2011 21:28:18 +0000 (23:28 +0200)] 
use usertype here because chrome is labeled execmem_exec_t so we want
$1_execmem_t (which is $1_usertype) to be able to transition to the
sandbox.

14 years agoMerge branch 'cron_fd'
Dominick Grift [Tue, 7 Jun 2011 20:20:21 +0000 (22:20 +0200)] 
Merge branch 'cron_fd'

14 years agologwatch_mail_t wants to use system_cronjob_t fds #711498
Dominick Grift [Tue, 7 Jun 2011 20:07:21 +0000 (22:07 +0200)] 
logwatch_mail_t wants to use system_cronjob_t fds #711498

14 years agoAllow zabbix to getpw* calls and use semaphores
Dan Walsh [Tue, 7 Jun 2011 19:42:29 +0000 (15:42 -0400)] 
Allow zabbix to getpw* calls and use semaphores

14 years agoinit script needs to be able to manage sanlock_var_run_t files
Dan Walsh [Tue, 7 Jun 2011 18:19:37 +0000 (14:19 -0400)] 
init script needs to be able to manage sanlock_var_run_t files

14 years agoAllow sandlock and wdmd to create /var/run directories with the proper label
Dan Walsh [Tue, 7 Jun 2011 18:11:31 +0000 (14:11 -0400)] 
Allow sandlock and wdmd to create /var/run directories with the proper label

14 years agomixclip.so has been compiled correctly
Dan Walsh [Tue, 7 Jun 2011 16:15:46 +0000 (12:15 -0400)] 
mixclip.so has been compiled correctly

14 years agoFix passenger policy module name
Dan Walsh [Tue, 7 Jun 2011 16:11:15 +0000 (12:11 -0400)] 
Fix passenger policy module name

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Tue, 7 Jun 2011 18:00:01 +0000 (18:00 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAdd jabberd_domain_template()
Miroslav Grepl [Tue, 7 Jun 2011 17:59:02 +0000 (17:59 +0000)] 
Add jabberd_domain_template()
 * Note: will use for ejabberd

14 years agoRemove duplicate mozilla_plugin_t policy
Dominick Grift [Tue, 7 Jun 2011 14:05:04 +0000 (16:05 +0200)] 
Remove duplicate mozilla_plugin_t policy

14 years agopulseaudio really needs to open mozilla_plugin_tmpfs files.
Dominick Grift [Tue, 7 Jun 2011 13:59:17 +0000 (15:59 +0200)] 
pulseaudio really needs to open mozilla_plugin_tmpfs files.
calling user needs to be able to delete and read
mozilla_plugin_tmpfs_files atleast (pulse-shm)
allow calling users to ptrace, signal and ps mozilla_plugin_t

14 years agoMerge ncftool from Fedora.
Chris PeBenito [Tue, 7 Jun 2011 13:14:53 +0000 (09:14 -0400)] 
Merge ncftool from Fedora.

14 years agoMerge branch 'openicc'
Dominick Grift [Mon, 6 Jun 2011 19:42:17 +0000 (21:42 +0200)] 
Merge branch 'openicc'

14 years agoMerge branch 'fixes'
Dominick Grift [Mon, 6 Jun 2011 19:42:03 +0000 (21:42 +0200)] 
Merge branch 'fixes'

14 years agoMerge branch 'chrome'
Dominick Grift [Mon, 6 Jun 2011 19:40:04 +0000 (21:40 +0200)] 
Merge branch 'chrome'

14 years agoremove chrome_role from execmem_role_template chrome is already
Dominick Grift [Mon, 6 Jun 2011 19:24:55 +0000 (21:24 +0200)] 
remove chrome_role from execmem_role_template chrome is already
allowed execmem.
call chrome role for user_t and staff_t

14 years agoZabbix needs these rules when starting the zabbix_server_mysql
Dan Walsh [Mon, 6 Jun 2011 19:08:38 +0000 (15:08 -0400)] 
Zabbix needs these rules when starting the zabbix_server_mysql

14 years agoselinux_t does not exist
Dominick Grift [Mon, 6 Jun 2011 19:05:31 +0000 (21:05 +0200)] 
selinux_t does not exist

14 years agofix build
Dominick Grift [Mon, 6 Jun 2011 18:55:26 +0000 (20:55 +0200)] 
fix build

14 years agoAllow chrome to optionally be transitioned to
Dan Walsh [Mon, 6 Jun 2011 18:23:48 +0000 (14:23 -0400)] 
Allow chrome to optionally be transitioned to

14 years agoAllow chrome to optionally be transitioned to
Dan Walsh [Mon, 6 Jun 2011 18:23:28 +0000 (14:23 -0400)] 
Allow chrome to optionally be transitioned to

14 years agoFix fix labeling of /usr/lib/xfce4
Dominick Grift [Mon, 6 Jun 2011 17:56:46 +0000 (19:56 +0200)] 
Fix fix labeling of /usr/lib/xfce4

14 years agoImplement a type for freedesktop openicc standard (~/.local/share/icc)
Dominick Grift [Mon, 6 Jun 2011 17:41:25 +0000 (19:41 +0200)] 
Implement a type for freedesktop openicc standard (~/.local/share/icc)
Allow system_dbusd_t to read inherited icc_data_home_t files.
Allow colord_t to read icc_data_home_t content. #706975

http://www.freedesktop.org/wiki/OpenIcc#OpenICCproject

14 years agoLabel stuff under /usr/lib/debug as if it was labeled under /
Dan Walsh [Mon, 6 Jun 2011 17:10:46 +0000 (13:10 -0400)] 
Label stuff under /usr/lib/debug as if it was labeled under /

14 years agoMake unconfined_t transitioning to chrome_sanbox_t optional by boolean
Dan Walsh [Mon, 6 Jun 2011 16:52:43 +0000 (12:52 -0400)] 
Make unconfined_t transitioning to chrome_sanbox_t optional by boolean

14 years agoFix labeling under /usr/lib/xfce4
Dan Walsh [Mon, 6 Jun 2011 16:35:13 +0000 (12:35 -0400)] 
Fix labeling under /usr/lib/xfce4

14 years agoInit is now loading policy and mount selinuxfs
Dan Walsh [Mon, 6 Jun 2011 15:49:21 +0000 (11:49 -0400)] 
Init is now loading policy and mount selinuxfs

14 years agoAllow puppetmaster to create dirs in /var/run/puppet
Miroslav Grepl [Mon, 6 Jun 2011 10:46:38 +0000 (10:46 +0000)] 
Allow puppetmaster to create dirs in /var/run/puppet

14 years agoAllow ssh to execute systemctl
Miroslav Grepl [Mon, 6 Jun 2011 12:03:46 +0000 (12:03 +0000)] 
Allow ssh to execute systemctl

14 years agoFixes for rhev-agent policy
Miroslav Grepl [Mon, 6 Jun 2011 15:23:20 +0000 (15:23 +0000)] 
Fixes for rhev-agent policy

14 years agoAllow fail2ban to create fail2ban_tmp_t dirs
Miroslav Grepl [Mon, 6 Jun 2011 11:05:18 +0000 (11:05 +0000)] 
Allow fail2ban to create fail2ban_tmp_t dirs

14 years agoInitial mailscanner policy
Dominick Grift [Sun, 5 Jun 2011 10:41:21 +0000 (12:41 +0200)] 
Initial mailscanner policy

14 years agoAllow programs that can read/write etc_runtime_t read links with that label, already...
Dan Walsh [Fri, 3 Jun 2011 20:29:49 +0000 (16:29 -0400)] 
Allow programs that can read/write etc_runtime_t read links with that label, already allowed for read_etc_runtime_files
Allow postfix_pickup to ignore MCS labels
Add append_inherited_file_perms

14 years agoAllow mailserver_delivery and uux_t to read/write postfix_master_pipes.
Dan Walsh [Fri, 3 Jun 2011 15:58:59 +0000 (11:58 -0400)] 
Allow mailserver_delivery and uux_t to read/write postfix_master_pipes.

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 3 Jun 2011 15:51:01 +0000 (11:51 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agodontaudit devicekit trying to list contents of mnt_t
Dan Walsh [Fri, 3 Jun 2011 15:50:31 +0000 (11:50 -0400)] 
dontaudit devicekit trying to list contents of mnt_t

14 years agoMerge branch 'refs/heads/master' of ssh://domg472@git.fedorahosted.org/git/selinux...
Dominick Grift [Thu, 2 Jun 2011 13:52:25 +0000 (15:52 +0200)] 
Merge branch 'refs/heads/master' of ssh://domg472@git.fedorahosted.org/git/selinux-policy.git

14 years agoRwho needs to stat() user terminal character files #708378
Dominick Grift [Thu, 2 Jun 2011 13:33:32 +0000 (15:33 +0200)] 
Rwho needs to stat() user terminal character files #708378

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 2 Jun 2011 15:03:14 +0000 (15:03 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow sys_chroot for postfix domains
Miroslav Grepl [Thu, 2 Jun 2011 14:49:31 +0000 (14:49 +0000)] 
Allow sys_chroot for postfix domains

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 2 Jun 2011 13:27:54 +0000 (09:27 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agorwho needs to be able to getattr on user timernals
Dan Walsh [Thu, 2 Jun 2011 13:27:40 +0000 (09:27 -0400)] 
rwho needs to be able to getattr on user timernals

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 2 Jun 2011 12:54:31 +0000 (08:54 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow virtd_t to stream conect to sanlock, dontaudit leaked file descriptor from...
Dan Walsh [Thu, 2 Jun 2011 12:54:19 +0000 (08:54 -0400)] 
Allow virtd_t to stream conect to sanlock, dontaudit leaked file descriptor from virtd_t to svirt_t, this is intentional

14 years agoMerge branch 'refs/heads/master' of ssh://domg472@git.fedorahosted.org/git/selinux...
Dominick Grift [Wed, 1 Jun 2011 17:36:48 +0000 (19:36 +0200)] 
Merge branch 'refs/heads/master' of ssh://domg472@git.fedorahosted.org/git/selinux-policy.git

14 years agoAllow apache to read proc_net_t
Dan Walsh [Wed, 1 Jun 2011 17:32:33 +0000 (13:32 -0400)] 
Allow apache to read proc_net_t
Allow userdomains to use seunshare fds

14 years agonetworkmanager_filetrans_named_content: it does not like paths
Dominick Grift [Wed, 1 Jun 2011 17:29:30 +0000 (19:29 +0200)] 
networkmanager_filetrans_named_content: it does not like paths

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 1 Jun 2011 17:22:03 +0000 (13:22 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoMove dev_filetrans_all_named_dev out of tunable init_systemd
Dan Walsh [Wed, 1 Jun 2011 17:19:28 +0000 (13:19 -0400)] 
Move dev_filetrans_all_named_dev out of tunable init_systemd

14 years agoDo not support nfs/cifs #708474
Dominick Grift [Wed, 1 Jun 2011 15:46:35 +0000 (17:46 +0200)] 
Do not support nfs/cifs #708474

14 years agocolord get attribute removable devices as per mgrepl's suggestion
Dominick Grift [Wed, 1 Jun 2011 15:42:14 +0000 (17:42 +0200)] 
colord get attribute removable devices as per mgrepl's suggestion

14 years agoMake sure init, udev, initrc creating devices creates them with the right label
Dan Walsh [Wed, 1 Jun 2011 14:10:57 +0000 (10:10 -0400)] 
Make sure init, udev, initrc creating devices creates them with the right label

14 years agoUnconfined_t running wpa by hand causes nm-dhclient-eth1.conf to be mislabeled
Dan Walsh [Wed, 1 Jun 2011 14:04:45 +0000 (10:04 -0400)] 
Unconfined_t running wpa by hand causes nm-dhclient-eth1.conf to be mislabeled

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 1 Jun 2011 14:46:29 +0000 (14:46 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agorpm_t only needs to relabel generic device nodes
Dominick Grift [Wed, 1 Jun 2011 10:25:29 +0000 (12:25 +0200)] 
rpm_t only needs to relabel generic device nodes

14 years agofix syntax error
Dominick Grift [Wed, 1 Jun 2011 09:55:57 +0000 (11:55 +0200)] 
fix syntax error

14 years agorpm creates and renames generic device_t blk and chr files.
Dominick Grift [Wed, 1 Jun 2011 09:44:17 +0000 (11:44 +0200)] 
rpm creates and renames generic device_t blk and chr files.
rpm relabels generic device_t blk and chr files to any device_node.
rpm deletes and sets attributes of all chr and blk device nodes.

14 years agopulseaudio wants to read inherited mozilla plugin tmpfs files:
Dominick Grift [Wed, 1 Jun 2011 09:25:13 +0000 (11:25 +0200)] 
pulseaudio wants to read inherited mozilla plugin tmpfs files:

avc:  denied  { read } for  pid=1630 comm="pulseaudio"
name="pulse-shm-4091746155" dev=tmpfs ino=53954
scontext=staff_u:staff_r:pulseaudio_t:s0-s0:c0.c1023
tcontext=staff_u:object_r:mozill _plugin_tmpfs_t:s0 tclass=file

14 years agoldconfig wants to list user home directories:
Dominick Grift [Wed, 1 Jun 2011 09:20:05 +0000 (11:20 +0200)] 
ldconfig wants to list user home directories:

avc:  denied  { read } for  pid=29900 comm="ldconfig"
path="/home/dgrift" dev=dm-3 ino=5767169
scontext=staff_u:system_r:ldconfig_t:s0-s0:c0.c1023
tcontext=staff_u:object_r:user_home_dir_t:s0 tclass=dir

14 years agoAdd label for /var/lock/ppp directory
Miroslav Grepl [Wed, 1 Jun 2011 08:53:10 +0000 (08:53 +0000)] 
Add label for /var/lock/ppp directory

14 years agoAdd filetrans_home_content for quota
Dan Walsh [Tue, 31 May 2011 18:16:21 +0000 (14:16 -0400)] 
Add filetrans_home_content for quota

14 years agoFix sanlock policy and allow inetd_t to mls_net all levels for outbound networks
Dan Walsh [Tue, 31 May 2011 17:16:36 +0000 (13:16 -0400)] 
Fix sanlock policy and allow inetd_t to mls_net all levels for outbound networks

14 years agoAllow init to read adjtime
Dan Walsh [Tue, 31 May 2011 14:25:24 +0000 (10:25 -0400)] 
Allow init to read adjtime
Allow pulseaudio to send signull to keyring

14 years agoLabel /var/log/roundcubemail type httpd_log_t so that the webapp
Dominick Grift [Tue, 31 May 2011 10:54:26 +0000 (12:54 +0200)] 
Label /var/log/roundcubemail type httpd_log_t so that the webapp
(httpd_t) can log to it. #709246

14 years agodovecot_deliver wants to read dovecot sock files and wants to stream
Dominick Grift [Tue, 31 May 2011 09:08:09 +0000 (11:08 +0200)] 
dovecot_deliver wants to read dovecot sock files and wants to stream
connect to dovecot #709257 #709255

14 years agoExtend audit_access interfaces to allow get attributes.
Dominick Grift [Tue, 31 May 2011 08:45:19 +0000 (10:45 +0200)] 
Extend audit_access interfaces to allow get attributes.
puppetmaster may only need to check access to groupadd useradd and
passwd (chage) #708897