]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Dominick Grift [Tue, 31 May 2011 08:29:10 +0000 (10:29 +0200)]
Silently deny sys_tty_config capability for drbdadm. #709259
Dominick Grift [Mon, 30 May 2011 08:10:31 +0000 (10:10 +0200)]
Silently deny attempts by prelink to read inherited gconf etc files
#708867
Dominick Grift [Mon, 30 May 2011 07:58:57 +0000 (09:58 +0200)]
Merge branch 'puppetmaster'
Dominick Grift [Mon, 30 May 2011 07:57:00 +0000 (09:57 +0200)]
Looks like puppetmaster actually runs it #708897
Dominick Grift [Sun, 29 May 2011 18:32:00 +0000 (20:32 +0200)]
label /var/cache/PackageKit rpm_var_cache_t
Dominick Grift [Sat, 28 May 2011 17:42:02 +0000 (19:42 +0200)]
Merge branch 'tmpfiles'
Dominick Grift [Sat, 28 May 2011 17:38:39 +0000 (19:38 +0200)]
notify needs to stat() /sys/fs/cgroup/systemd #708672
systemd-notify --booted uses stat() on /sys/fs/cgroup/systemd to
figure out whether systemd is running. i.e. the systemd hierarchy is
mounted
Dominick Grift [Sat, 28 May 2011 17:20:18 +0000 (19:20 +0200)]
tmpfiles needs to be able to purge sandbox_file_t pipes. #708568
Dominick Grift [Sat, 28 May 2011 10:09:42 +0000 (12:09 +0200)]
Only nfs_t filesystem mounted to /media is confirmed so
fs_getattr_all_fs() is a bit too coarse.
Dominick Grift [Sat, 28 May 2011 09:27:56 +0000 (11:27 +0200)]
colord lists noxattr directories (iso9660) #708585
Dominick Grift [Sat, 28 May 2011 09:19:15 +0000 (11:19 +0200)]
colord reads /dev/sr0 #708584
Dominick Grift [Fri, 27 May 2011 19:46:07 +0000 (21:46 +0200)]
Colord: Support nfs/cifs (other than mounted on /home)
Colord: Allow colord to get attributes of any filesystem (who knows
what one may have mounted on /media) #708474
Miroslav Grepl [Fri, 27 May 2011 10:18:29 +0000 (10:18 +0000)]
Allow security admin to manage selinux config files
dwalsh [Thu, 26 May 2011 15:46:47 +0000 (11:46 -0400)]
Allow staff user to read /dev cpuid
dwalsh [Thu, 26 May 2011 14:25:42 +0000 (10:25 -0400)]
ccs sends signals to the init process
dwalsh [Thu, 26 May 2011 14:06:09 +0000 (10:06 -0400)]
Pulseaudio owns 4713
dwalsh [Thu, 26 May 2011 13:20:06 +0000 (09:20 -0400)]
Assign jboss_management ports
Dominick Grift [Thu, 26 May 2011 12:57:06 +0000 (14:57 +0200)]
Make logger a permissive domain
Miroslav Grepl [Thu, 26 May 2011 14:25:00 +0000 (14:25 +0000)]
Remove duplicate declaration
Miroslav Grepl [Thu, 26 May 2011 14:11:48 +0000 (14:11 +0000)]
Add rhev policy module which contains rhev-agentd policy
Miroslav Grepl [Thu, 26 May 2011 11:17:43 +0000 (11:17 +0000)]
Fix abrt_manage_spool_retrace() interface
Miroslav Grepl [Thu, 26 May 2011 10:57:45 +0000 (10:57 +0000)]
More fixes for ABRT retrace-worker
Dan Walsh [Wed, 25 May 2011 20:08:18 +0000 (16:08 -0400)]
Fix interface syntax error
Dan Walsh [Wed, 25 May 2011 19:44:41 +0000 (15:44 -0400)]
Add dontaudit fd use to dontaudit write pipes and allow for write pipes
Dan Walsh [Wed, 25 May 2011 19:40:19 +0000 (15:40 -0400)]
Add dontaudit fd use to dontaudit fifo_file for virt
Dan Walsh [Wed, 25 May 2011 19:31:07 +0000 (15:31 -0400)]
Modifications needed to make reboot or shutdown work from a confined staff_t user
Dan Walsh [Wed, 25 May 2011 13:59:07 +0000 (09:59 -0400)]
Make vhost_device_t a trusted device
Dan Walsh [Wed, 25 May 2011 13:58:49 +0000 (09:58 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 25 May 2011 13:57:58 +0000 (09:57 -0400)]
Only allow virt_domains to use inherted tun_tap devices or vhost_dev_t
Chris PeBenito [Wed, 25 May 2011 12:30:54 +0000 (08:30 -0400)]
Fix incorrect parameter in semanage call in likewise.
Dominick Grift [Tue, 24 May 2011 18:28:36 +0000 (20:28 +0200)]
Merge branch 'various' into HEAD
Dan Walsh [Tue, 24 May 2011 18:20:19 +0000 (14:20 -0400)]
Add patch from Dominic Grift for dccp_socket
Change access_check to audit_access
Dominick Grift [Tue, 24 May 2011 18:16:09 +0000 (20:16 +0200)]
Merge branch 'open_unall_ttys' into HEAD
Dominick Grift [Tue, 24 May 2011 18:15:56 +0000 (20:15 +0200)]
Merge branch 'tp_logger_and_udev_consoletype' into HEAD
Dominick Grift [Tue, 24 May 2011 18:09:28 +0000 (20:09 +0200)]
sysadm_t running shutdown (systemctl) wants to "open" tty1.
Dan Walsh [Tue, 24 May 2011 17:53:47 +0000 (13:53 -0400)]
Add puppetca policy from Dominick
Dominick Grift [Tue, 24 May 2011 17:48:48 +0000 (19:48 +0200)]
Merge branch 'udev_consoletype' into HEAD
Dominick Grift [Tue, 24 May 2011 17:46:23 +0000 (19:46 +0200)]
Let udev_t domain transition to consoletype instead of run it in
udev_t domain #707279
Dominick Grift [Tue, 24 May 2011 17:31:09 +0000 (19:31 +0200)]
add tp_logger domain
Dan Walsh [Tue, 24 May 2011 16:40:07 +0000 (12:40 -0400)]
Allow colord to read inherited files from userspace
Dan Walsh [Tue, 24 May 2011 16:35:04 +0000 (12:35 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 24 May 2011 16:34:37 +0000 (12:34 -0400)]
Allow mount to use inherited unix_stream_sockets
Dan Walsh [Tue, 24 May 2011 14:21:33 +0000 (10:21 -0400)]
Trying to tighten down the use of inherited FDs
nsplugin exchanges dbus messages with devicekit_power
Chris PeBenito [Tue, 24 May 2011 13:12:43 +0000 (09:12 -0400)]
Module version bump and changelog for Fedora modules.
Chris PeBenito [Tue, 24 May 2011 13:11:56 +0000 (09:11 -0400)]
Add zarafa from Fedora.
Dominick Grift [Tue, 24 May 2011 12:47:21 +0000 (14:47 +0200)]
This concludes the fix for bz #706577 for now. Leave fail2ban_client_t
a permissive domain throughout rawhide for testing
Dominick Grift [Tue, 24 May 2011 11:25:45 +0000 (13:25 +0200)]
new port type for boinc client control and allow boinc to bind tcp
sockets to it: #707190
Dominick Grift [Tue, 24 May 2011 11:08:17 +0000 (13:08 +0200)]
lirc signals itself: 707157
Dominick Grift [Tue, 24 May 2011 10:23:38 +0000 (12:23 +0200)]
fix fenced_can_ssh
Dominick Grift [Tue, 24 May 2011 10:16:03 +0000 (12:16 +0200)]
access_check is audit_access
Dominick Grift [Tue, 24 May 2011 10:10:48 +0000 (12:10 +0200)]
I know it should not create files in /tmp but i guess we will just
have to deal with it for now
Dominick Grift [Tue, 24 May 2011 09:25:37 +0000 (11:25 +0200)]
fail2ban executes ldconfig
create fail2ban_client_t init daemon domain and allow it to connect to
fail2ban with a unix stream socket
Miroslav Grepl [Tue, 24 May 2011 09:08:52 +0000 (09:08 +0000)]
cgred needs auth_use_nsswitch()
Miroslav Grepl [Tue, 24 May 2011 08:45:27 +0000 (08:45 +0000)]
Allow clamav to manage amavis spool files
Miroslav Grepl [Tue, 24 May 2011 08:33:41 +0000 (08:33 +0000)]
Use httpd_can_sendmail boolean also for httpd_suexec_t
Other fixes for httpd_suexec_t
Miroslav Grepl [Tue, 24 May 2011 08:25:17 +0000 (08:25 +0000)]
Add fenced_can_ssh boolean
Miroslav Grepl [Tue, 24 May 2011 08:56:39 +0000 (08:56 +0000)]
Add dev_dontaudit_read_generic_files() which is used in colord policy
Conflicts:
policy/modules/services/colord.te
Miroslav Grepl [Mon, 23 May 2011 14:05:31 +0000 (14:05 +0000)]
Allow secadm to read and write SELinux configuration files and default contexts
Miroslav Grepl [Mon, 23 May 2011 08:50:16 +0000 (08:50 +0000)]
Allow mount to read usr files
Dan Walsh [Mon, 23 May 2011 22:36:08 +0000 (18:36 -0400)]
add sanlock and wdmd policy files
Dan Walsh [Mon, 23 May 2011 22:26:02 +0000 (18:26 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 23 May 2011 22:25:39 +0000 (18:25 -0400)]
Change named filetrans to include quotes required for upstream policy
Dominick Grift [Mon, 23 May 2011 20:38:32 +0000 (22:38 +0200)]
Merge branch 'fix_automount'
Dominick Grift [Mon, 23 May 2011 20:38:18 +0000 (22:38 +0200)]
Merge branch 'fix_virt'
Dominick Grift [Mon, 23 May 2011 20:38:03 +0000 (22:38 +0200)]
Merge branch 'unconfined_run_load_policy'
Dominick Grift [Mon, 23 May 2011 20:37:47 +0000 (22:37 +0200)]
Merge branch 'unused_and_broken'
Dan Walsh [Mon, 23 May 2011 20:31:02 +0000 (16:31 -0400)]
Dontaudit leaked pm-utils.log file to dhcpc_t
systemd_sysctl apps need to be able to use init_fds
Dominick Grift [Mon, 23 May 2011 20:30:08 +0000 (22:30 +0200)]
I suspect this was meant to be mount_t.
Dominick Grift [Mon, 23 May 2011 20:25:11 +0000 (22:25 +0200)]
fix: Dontaudit one virtdomain looking at anothers tmpfs_t (pulseaudio)
Dan Walsh [Mon, 23 May 2011 19:51:11 +0000 (15:51 -0400)]
Allow xauthority to create shared memory
Dan Walsh [Mon, 23 May 2011 19:42:19 +0000 (15:42 -0400)]
Make postfix user domains application_domains
Dan Walsh [Mon, 23 May 2011 19:24:42 +0000 (15:24 -0400)]
Allow xend to sys_admin privs
Dan Walsh [Mon, 23 May 2011 19:14:51 +0000 (15:14 -0400)]
Add jboss_management port for 2712, and allow httpd_t to bind to it
Allow init to create a udev_t kobject socket
Trying to figure out how leaked fds is working
Dominick Grift [Mon, 23 May 2011 18:57:28 +0000 (20:57 +0200)]
This is probably not optimal.
Dominick Grift [Mon, 23 May 2011 17:58:55 +0000 (19:58 +0200)]
This interface is unused and generally broken
Dan Walsh [Mon, 23 May 2011 16:52:45 +0000 (12:52 -0400)]
Allow logrotate to exec callweaver
Dan Walsh [Mon, 23 May 2011 16:48:03 +0000 (12:48 -0400)]
Add seutil_manage* to userdom_security_admin_template, security admin needs to be able to manage /etc/selinux
Dominick Grift [Mon, 23 May 2011 16:03:21 +0000 (18:03 +0200)]
ftpd_t needs to read fail2ban_var_lib_files. (bz #706577)
Dominick Grift [Mon, 23 May 2011 15:46:29 +0000 (17:46 +0200)]
Cannot read fail2ban_var_lib_t files without traversing
fail2ban_var_lib_t dir (/var/lib/fail2ban)
Dominick Grift [Sat, 21 May 2011 17:45:59 +0000 (19:45 +0200)]
Make cron work
Dominick Grift [Fri, 20 May 2011 20:24:58 +0000 (22:24 +0200)]
apcupsd lock file was missing file context specification rhbz #706489
Chris PeBenito [Fri, 20 May 2011 14:29:20 +0000 (10:29 -0400)]
Move passenger to admin layer.
Chris PeBenito [Fri, 20 May 2011 14:27:47 +0000 (10:27 -0400)]
Add passenger from Fedora.
Chris PeBenito [Fri, 20 May 2011 14:20:28 +0000 (10:20 -0400)]
Move mediawiki to services layer.
Chris PeBenito [Fri, 20 May 2011 14:17:12 +0000 (10:17 -0400)]
Add mediawiki from Fedora.
Chris PeBenito [Fri, 20 May 2011 14:16:09 +0000 (10:16 -0400)]
Add telepathy from Fedora.
Chris PeBenito [Fri, 20 May 2011 13:32:13 +0000 (09:32 -0400)]
Rename qpidd to qpid.
Chris PeBenito [Fri, 20 May 2011 13:31:04 +0000 (09:31 -0400)]
Add qpidd from Fedora.
Chris PeBenito [Fri, 20 May 2011 13:15:25 +0000 (09:15 -0400)]
Add vnstatd from Fedora.
Chris PeBenito [Fri, 20 May 2011 13:11:07 +0000 (09:11 -0400)]
Add bugzilla policy from Fedora.
Dominick Grift [Fri, 20 May 2011 08:26:00 +0000 (10:26 +0200)]
Merge branch 'colord_module' into HEAD
Dominick Grift [Fri, 20 May 2011 08:25:45 +0000 (10:25 +0200)]
Merge branch 'mozilla_fixes' into HEAD
Dominick Grift [Fri, 20 May 2011 08:24:06 +0000 (10:24 +0200)]
Wants to request the kernel to load modules: char-major-6-{0.3}
Dominick Grift [Fri, 20 May 2011 08:18:56 +0000 (10:18 +0200)]
Caller needs to be able to trace plugin process (top). I would
probably allow caller all signal_perms to plugin process instead of
just the current signal sigkill.
Caller needs to use plugin file descriptors.
Dominick Grift [Fri, 20 May 2011 08:09:51 +0000 (10:09 +0200)]
Without this you will not be able to unlock your key ring.
Chris PeBenito [Thu, 19 May 2011 13:56:59 +0000 (09:56 -0400)]
Add mpd from Fedora.
Chris PeBenito [Thu, 19 May 2011 13:56:44 +0000 (09:56 -0400)]
Add colord from Fedora.
Chris PeBenito [Thu, 19 May 2011 13:14:25 +0000 (09:14 -0400)]
Add cmirrord from Fedora.
Chris PeBenito [Thu, 19 May 2011 13:09:09 +0000 (09:09 -0400)]
Add aiccu from Fedora.
Dominick Grift [Wed, 18 May 2011 16:24:40 +0000 (18:24 +0200)]
space to tabs.