]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
14 years agoSilently deny sys_tty_config capability for drbdadm. #709259
Dominick Grift [Tue, 31 May 2011 08:29:10 +0000 (10:29 +0200)] 
Silently deny sys_tty_config capability for drbdadm. #709259

14 years agoSilently deny attempts by prelink to read inherited gconf etc files
Dominick Grift [Mon, 30 May 2011 08:10:31 +0000 (10:10 +0200)] 
Silently deny attempts by prelink to read inherited gconf etc files
#708867

14 years agoMerge branch 'puppetmaster'
Dominick Grift [Mon, 30 May 2011 07:58:57 +0000 (09:58 +0200)] 
Merge branch 'puppetmaster'

14 years agoLooks like puppetmaster actually runs it #708897
Dominick Grift [Mon, 30 May 2011 07:57:00 +0000 (09:57 +0200)] 
Looks like puppetmaster actually runs it #708897

14 years agolabel /var/cache/PackageKit rpm_var_cache_t
Dominick Grift [Sun, 29 May 2011 18:32:00 +0000 (20:32 +0200)] 
label /var/cache/PackageKit rpm_var_cache_t

14 years agoMerge branch 'tmpfiles'
Dominick Grift [Sat, 28 May 2011 17:42:02 +0000 (19:42 +0200)] 
Merge branch 'tmpfiles'

14 years agonotify needs to stat() /sys/fs/cgroup/systemd #708672
Dominick Grift [Sat, 28 May 2011 17:38:39 +0000 (19:38 +0200)] 
notify needs to stat() /sys/fs/cgroup/systemd #708672

systemd-notify --booted uses stat() on /sys/fs/cgroup/systemd to
figure out whether systemd is running. i.e. the systemd hierarchy is
mounted

14 years agotmpfiles needs to be able to purge sandbox_file_t pipes. #708568
Dominick Grift [Sat, 28 May 2011 17:20:18 +0000 (19:20 +0200)] 
tmpfiles needs to be able to purge sandbox_file_t pipes. #708568

14 years agoOnly nfs_t filesystem mounted to /media is confirmed so
Dominick Grift [Sat, 28 May 2011 10:09:42 +0000 (12:09 +0200)] 
Only nfs_t filesystem mounted to /media is confirmed so
fs_getattr_all_fs() is a bit too coarse.

14 years agocolord lists noxattr directories (iso9660) #708585
Dominick Grift [Sat, 28 May 2011 09:27:56 +0000 (11:27 +0200)] 
colord lists noxattr directories (iso9660) #708585

14 years agocolord reads /dev/sr0 #708584
Dominick Grift [Sat, 28 May 2011 09:19:15 +0000 (11:19 +0200)] 
colord reads /dev/sr0 #708584

14 years agoColord: Support nfs/cifs (other than mounted on /home)
Dominick Grift [Fri, 27 May 2011 19:46:07 +0000 (21:46 +0200)] 
Colord: Support nfs/cifs (other than mounted on /home)
Colord: Allow colord to get attributes of any filesystem (who knows
what one may have mounted on /media) #708474

14 years agoAllow security admin to manage selinux config files
Miroslav Grepl [Fri, 27 May 2011 10:18:29 +0000 (10:18 +0000)] 
Allow security admin to manage selinux config files

14 years agoAllow staff user to read /dev cpuid
dwalsh [Thu, 26 May 2011 15:46:47 +0000 (11:46 -0400)] 
Allow staff user to read /dev cpuid

14 years agoccs sends signals to the init process
dwalsh [Thu, 26 May 2011 14:25:42 +0000 (10:25 -0400)] 
ccs sends signals to the init process

14 years agoPulseaudio owns 4713
dwalsh [Thu, 26 May 2011 14:06:09 +0000 (10:06 -0400)] 
Pulseaudio owns 4713

14 years agoAssign jboss_management ports
dwalsh [Thu, 26 May 2011 13:20:06 +0000 (09:20 -0400)] 
Assign jboss_management ports

14 years agoMake logger a permissive domain
Dominick Grift [Thu, 26 May 2011 12:57:06 +0000 (14:57 +0200)] 
Make logger a permissive domain

14 years agoRemove duplicate declaration
Miroslav Grepl [Thu, 26 May 2011 14:25:00 +0000 (14:25 +0000)] 
Remove duplicate declaration

14 years agoAdd rhev policy module which contains rhev-agentd policy
Miroslav Grepl [Thu, 26 May 2011 14:11:48 +0000 (14:11 +0000)] 
Add rhev policy module which contains rhev-agentd policy

14 years agoFix abrt_manage_spool_retrace() interface
Miroslav Grepl [Thu, 26 May 2011 11:17:43 +0000 (11:17 +0000)] 
Fix abrt_manage_spool_retrace() interface

14 years agoMore fixes for ABRT retrace-worker
Miroslav Grepl [Thu, 26 May 2011 10:57:45 +0000 (10:57 +0000)] 
More fixes for ABRT retrace-worker

14 years agoFix interface syntax error
Dan Walsh [Wed, 25 May 2011 20:08:18 +0000 (16:08 -0400)] 
Fix interface syntax error

14 years agoAdd dontaudit fd use to dontaudit write pipes and allow for write pipes
Dan Walsh [Wed, 25 May 2011 19:44:41 +0000 (15:44 -0400)] 
Add dontaudit fd use to dontaudit write pipes and allow for write pipes

14 years agoAdd dontaudit fd use to dontaudit fifo_file for virt
Dan Walsh [Wed, 25 May 2011 19:40:19 +0000 (15:40 -0400)] 
Add dontaudit fd use to dontaudit fifo_file for virt

14 years agoModifications needed to make reboot or shutdown work from a confined staff_t user
Dan Walsh [Wed, 25 May 2011 19:31:07 +0000 (15:31 -0400)] 
Modifications needed to make reboot or shutdown work from a confined staff_t user

14 years agoMake vhost_device_t a trusted device
Dan Walsh [Wed, 25 May 2011 13:59:07 +0000 (09:59 -0400)] 
Make vhost_device_t a trusted device

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 25 May 2011 13:58:49 +0000 (09:58 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoOnly allow virt_domains to use inherted tun_tap devices or vhost_dev_t
Dan Walsh [Wed, 25 May 2011 13:57:58 +0000 (09:57 -0400)] 
Only allow virt_domains to use inherted tun_tap devices or vhost_dev_t

14 years agoFix incorrect parameter in semanage call in likewise.
Chris PeBenito [Wed, 25 May 2011 12:30:54 +0000 (08:30 -0400)] 
Fix incorrect parameter in semanage call in likewise.

14 years agoMerge branch 'various' into HEAD
Dominick Grift [Tue, 24 May 2011 18:28:36 +0000 (20:28 +0200)] 
Merge branch 'various' into HEAD

14 years agoAdd patch from Dominic Grift for dccp_socket
Dan Walsh [Tue, 24 May 2011 18:20:19 +0000 (14:20 -0400)] 
Add patch from Dominic Grift for dccp_socket
Change access_check to audit_access

14 years agoMerge branch 'open_unall_ttys' into HEAD
Dominick Grift [Tue, 24 May 2011 18:16:09 +0000 (20:16 +0200)] 
Merge branch 'open_unall_ttys' into HEAD

14 years agoMerge branch 'tp_logger_and_udev_consoletype' into HEAD
Dominick Grift [Tue, 24 May 2011 18:15:56 +0000 (20:15 +0200)] 
Merge branch 'tp_logger_and_udev_consoletype' into HEAD

14 years agosysadm_t running shutdown (systemctl) wants to "open" tty1.
Dominick Grift [Tue, 24 May 2011 18:09:28 +0000 (20:09 +0200)] 
sysadm_t running shutdown (systemctl) wants to "open" tty1.

14 years agoAdd puppetca policy from Dominick
Dan Walsh [Tue, 24 May 2011 17:53:47 +0000 (13:53 -0400)] 
Add puppetca policy from Dominick

14 years agoMerge branch 'udev_consoletype' into HEAD
Dominick Grift [Tue, 24 May 2011 17:48:48 +0000 (19:48 +0200)] 
Merge branch 'udev_consoletype' into HEAD

14 years agoLet udev_t domain transition to consoletype instead of run it in
Dominick Grift [Tue, 24 May 2011 17:46:23 +0000 (19:46 +0200)] 
Let udev_t domain transition to consoletype instead of run it in
udev_t domain #707279

14 years agoadd tp_logger domain
Dominick Grift [Tue, 24 May 2011 17:31:09 +0000 (19:31 +0200)] 
add tp_logger domain

14 years agoAllow colord to read inherited files from userspace
Dan Walsh [Tue, 24 May 2011 16:40:07 +0000 (12:40 -0400)] 
Allow colord to read inherited files from userspace

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 24 May 2011 16:35:04 +0000 (12:35 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow mount to use inherited unix_stream_sockets
Dan Walsh [Tue, 24 May 2011 16:34:37 +0000 (12:34 -0400)] 
Allow mount to use inherited unix_stream_sockets

14 years agoTrying to tighten down the use of inherited FDs
Dan Walsh [Tue, 24 May 2011 14:21:33 +0000 (10:21 -0400)] 
Trying to tighten down the use of inherited FDs
nsplugin exchanges dbus messages with devicekit_power

14 years agoModule version bump and changelog for Fedora modules.
Chris PeBenito [Tue, 24 May 2011 13:12:43 +0000 (09:12 -0400)] 
Module version bump and changelog for Fedora modules.

14 years agoAdd zarafa from Fedora.
Chris PeBenito [Tue, 24 May 2011 13:11:56 +0000 (09:11 -0400)] 
Add zarafa from Fedora.

14 years agoThis concludes the fix for bz #706577 for now. Leave fail2ban_client_t
Dominick Grift [Tue, 24 May 2011 12:47:21 +0000 (14:47 +0200)] 
This concludes the fix for bz #706577 for now. Leave fail2ban_client_t
a permissive domain throughout rawhide for testing

14 years agonew port type for boinc client control and allow boinc to bind tcp
Dominick Grift [Tue, 24 May 2011 11:25:45 +0000 (13:25 +0200)] 
new port type for boinc client control and allow boinc to bind tcp
sockets to it: #707190

14 years agolirc signals itself: 707157
Dominick Grift [Tue, 24 May 2011 11:08:17 +0000 (13:08 +0200)] 
lirc signals itself: 707157

14 years agofix fenced_can_ssh
Dominick Grift [Tue, 24 May 2011 10:23:38 +0000 (12:23 +0200)] 
fix fenced_can_ssh

14 years agoaccess_check is audit_access
Dominick Grift [Tue, 24 May 2011 10:16:03 +0000 (12:16 +0200)] 
access_check is audit_access

14 years agoI know it should not create files in /tmp but i guess we will just
Dominick Grift [Tue, 24 May 2011 10:10:48 +0000 (12:10 +0200)] 
I know it should not create files in /tmp but i guess we will just
have to deal with it for now

14 years agofail2ban executes ldconfig
Dominick Grift [Tue, 24 May 2011 09:25:37 +0000 (11:25 +0200)] 
fail2ban executes ldconfig
create fail2ban_client_t init daemon domain and allow it to connect to
fail2ban with a unix stream socket

14 years agocgred needs auth_use_nsswitch()
Miroslav Grepl [Tue, 24 May 2011 09:08:52 +0000 (09:08 +0000)] 
cgred needs auth_use_nsswitch()

14 years agoAllow clamav to manage amavis spool files
Miroslav Grepl [Tue, 24 May 2011 08:45:27 +0000 (08:45 +0000)] 
Allow clamav to manage amavis spool files

14 years agoUse httpd_can_sendmail boolean also for httpd_suexec_t
Miroslav Grepl [Tue, 24 May 2011 08:33:41 +0000 (08:33 +0000)] 
Use httpd_can_sendmail boolean also for httpd_suexec_t
Other fixes for httpd_suexec_t

14 years agoAdd fenced_can_ssh boolean
Miroslav Grepl [Tue, 24 May 2011 08:25:17 +0000 (08:25 +0000)] 
Add fenced_can_ssh boolean

14 years agoAdd dev_dontaudit_read_generic_files() which is used in colord policy
Miroslav Grepl [Tue, 24 May 2011 08:56:39 +0000 (08:56 +0000)] 
Add dev_dontaudit_read_generic_files() which is used in colord policy

Conflicts:

policy/modules/services/colord.te

14 years agoAllow secadm to read and write SELinux configuration files and default contexts
Miroslav Grepl [Mon, 23 May 2011 14:05:31 +0000 (14:05 +0000)] 
Allow secadm  to read and write SELinux configuration files and default contexts

14 years agoAllow mount to read usr files
Miroslav Grepl [Mon, 23 May 2011 08:50:16 +0000 (08:50 +0000)] 
Allow mount to read usr files

14 years agoadd sanlock and wdmd policy files
Dan Walsh [Mon, 23 May 2011 22:36:08 +0000 (18:36 -0400)] 
add sanlock and wdmd policy files

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 23 May 2011 22:26:02 +0000 (18:26 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoChange named filetrans to include quotes required for upstream policy
Dan Walsh [Mon, 23 May 2011 22:25:39 +0000 (18:25 -0400)] 
Change named filetrans to include quotes required for upstream policy

14 years agoMerge branch 'fix_automount'
Dominick Grift [Mon, 23 May 2011 20:38:32 +0000 (22:38 +0200)] 
Merge branch 'fix_automount'

14 years agoMerge branch 'fix_virt'
Dominick Grift [Mon, 23 May 2011 20:38:18 +0000 (22:38 +0200)] 
Merge branch 'fix_virt'

14 years agoMerge branch 'unconfined_run_load_policy'
Dominick Grift [Mon, 23 May 2011 20:38:03 +0000 (22:38 +0200)] 
Merge branch 'unconfined_run_load_policy'

14 years agoMerge branch 'unused_and_broken'
Dominick Grift [Mon, 23 May 2011 20:37:47 +0000 (22:37 +0200)] 
Merge branch 'unused_and_broken'

14 years agoDontaudit leaked pm-utils.log file to dhcpc_t
Dan Walsh [Mon, 23 May 2011 20:31:02 +0000 (16:31 -0400)] 
Dontaudit leaked pm-utils.log file to dhcpc_t
systemd_sysctl apps need to be able to use init_fds

14 years agoI suspect this was meant to be mount_t.
Dominick Grift [Mon, 23 May 2011 20:30:08 +0000 (22:30 +0200)] 
I suspect this was meant to be mount_t.

14 years agofix: Dontaudit one virtdomain looking at anothers tmpfs_t (pulseaudio)
Dominick Grift [Mon, 23 May 2011 20:25:11 +0000 (22:25 +0200)] 
fix: Dontaudit one virtdomain looking at anothers tmpfs_t (pulseaudio)

14 years agoAllow xauthority to create shared memory
Dan Walsh [Mon, 23 May 2011 19:51:11 +0000 (15:51 -0400)] 
Allow xauthority to create shared memory

14 years agoMake postfix user domains application_domains
Dan Walsh [Mon, 23 May 2011 19:42:19 +0000 (15:42 -0400)] 
Make postfix user domains application_domains

14 years agoAllow xend to sys_admin privs
Dan Walsh [Mon, 23 May 2011 19:24:42 +0000 (15:24 -0400)] 
Allow xend to sys_admin privs

14 years agoAdd jboss_management port for 2712, and allow httpd_t to bind to it
Dan Walsh [Mon, 23 May 2011 19:14:51 +0000 (15:14 -0400)] 
Add jboss_management port for 2712, and allow httpd_t to bind to it
Allow init to create a udev_t kobject socket
Trying to figure out how leaked fds is working

14 years agoThis is probably not optimal.
Dominick Grift [Mon, 23 May 2011 18:57:28 +0000 (20:57 +0200)] 
This is probably not optimal.

14 years agoThis interface is unused and generally broken
Dominick Grift [Mon, 23 May 2011 17:58:55 +0000 (19:58 +0200)] 
This interface is unused and generally broken

14 years agoAllow logrotate to exec callweaver
Dan Walsh [Mon, 23 May 2011 16:52:45 +0000 (12:52 -0400)] 
Allow logrotate to exec callweaver

14 years agoAdd seutil_manage* to userdom_security_admin_template, security admin needs to be...
Dan Walsh [Mon, 23 May 2011 16:48:03 +0000 (12:48 -0400)] 
Add seutil_manage* to userdom_security_admin_template, security admin needs to be able to manage /etc/selinux

14 years agoftpd_t needs to read fail2ban_var_lib_files. (bz #706577)
Dominick Grift [Mon, 23 May 2011 16:03:21 +0000 (18:03 +0200)] 
ftpd_t needs to read fail2ban_var_lib_files. (bz #706577)

14 years agoCannot read fail2ban_var_lib_t files without traversing
Dominick Grift [Mon, 23 May 2011 15:46:29 +0000 (17:46 +0200)] 
Cannot read fail2ban_var_lib_t files without traversing
fail2ban_var_lib_t dir (/var/lib/fail2ban)

14 years agoMake cron work
Dominick Grift [Sat, 21 May 2011 17:45:59 +0000 (19:45 +0200)] 
Make cron work

14 years agoapcupsd lock file was missing file context specification rhbz #706489
Dominick Grift [Fri, 20 May 2011 20:24:58 +0000 (22:24 +0200)] 
apcupsd lock file was missing file context specification rhbz #706489

14 years agoMove passenger to admin layer.
Chris PeBenito [Fri, 20 May 2011 14:29:20 +0000 (10:29 -0400)] 
Move passenger to admin layer.

14 years agoAdd passenger from Fedora.
Chris PeBenito [Fri, 20 May 2011 14:27:47 +0000 (10:27 -0400)] 
Add passenger from Fedora.

14 years agoMove mediawiki to services layer.
Chris PeBenito [Fri, 20 May 2011 14:20:28 +0000 (10:20 -0400)] 
Move mediawiki to services layer.

14 years agoAdd mediawiki from Fedora.
Chris PeBenito [Fri, 20 May 2011 14:17:12 +0000 (10:17 -0400)] 
Add mediawiki from Fedora.

14 years agoAdd telepathy from Fedora.
Chris PeBenito [Fri, 20 May 2011 14:16:09 +0000 (10:16 -0400)] 
Add telepathy from Fedora.

14 years agoRename qpidd to qpid.
Chris PeBenito [Fri, 20 May 2011 13:32:13 +0000 (09:32 -0400)] 
Rename qpidd to qpid.

14 years agoAdd qpidd from Fedora.
Chris PeBenito [Fri, 20 May 2011 13:31:04 +0000 (09:31 -0400)] 
Add qpidd from Fedora.

14 years agoAdd vnstatd from Fedora.
Chris PeBenito [Fri, 20 May 2011 13:15:25 +0000 (09:15 -0400)] 
Add vnstatd from Fedora.

14 years agoAdd bugzilla policy from Fedora.
Chris PeBenito [Fri, 20 May 2011 13:11:07 +0000 (09:11 -0400)] 
Add bugzilla policy from Fedora.

14 years agoMerge branch 'colord_module' into HEAD
Dominick Grift [Fri, 20 May 2011 08:26:00 +0000 (10:26 +0200)] 
Merge branch 'colord_module' into HEAD

14 years agoMerge branch 'mozilla_fixes' into HEAD
Dominick Grift [Fri, 20 May 2011 08:25:45 +0000 (10:25 +0200)] 
Merge branch 'mozilla_fixes' into HEAD

14 years agoWants to request the kernel to load modules: char-major-6-{0.3}
Dominick Grift [Fri, 20 May 2011 08:24:06 +0000 (10:24 +0200)] 
Wants to request the kernel to load modules: char-major-6-{0.3}

14 years agoCaller needs to be able to trace plugin process (top). I would
Dominick Grift [Fri, 20 May 2011 08:18:56 +0000 (10:18 +0200)] 
Caller needs to be able to trace plugin process (top). I would
probably allow caller all signal_perms to plugin process instead of
just the current signal sigkill.

Caller needs to use plugin file descriptors.

14 years agoWithout this you will not be able to unlock your key ring.
Dominick Grift [Fri, 20 May 2011 08:09:51 +0000 (10:09 +0200)] 
Without this you will not be able to unlock your key ring.

14 years agoAdd mpd from Fedora.
Chris PeBenito [Thu, 19 May 2011 13:56:59 +0000 (09:56 -0400)] 
Add mpd from Fedora.

14 years agoAdd colord from Fedora.
Chris PeBenito [Thu, 19 May 2011 13:56:44 +0000 (09:56 -0400)] 
Add colord from Fedora.

14 years agoAdd cmirrord from Fedora.
Chris PeBenito [Thu, 19 May 2011 13:14:25 +0000 (09:14 -0400)] 
Add cmirrord from Fedora.

14 years agoAdd aiccu from Fedora.
Chris PeBenito [Thu, 19 May 2011 13:09:09 +0000 (09:09 -0400)] 
Add aiccu from Fedora.

14 years agospace to tabs.
Dominick Grift [Wed, 18 May 2011 16:24:40 +0000 (18:24 +0200)] 
space to tabs.