]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
17 years agoadd support for netfilter_contexts
Chris PeBenito [Mon, 7 Aug 2006 17:25:09 +0000 (17:25 +0000)] 
add support for netfilter_contexts

17 years agopatch from Stefan for mrtg daemon operation.
Chris PeBenito [Mon, 7 Aug 2006 17:14:00 +0000 (17:14 +0000)] 
patch from Stefan for mrtg daemon operation.

17 years agodisplay warning if using loadkeys_domtrans() in targeted
Chris PeBenito [Thu, 3 Aug 2006 18:02:28 +0000 (18:02 +0000)] 
display warning if using loadkeys_domtrans() in targeted

17 years agoadd missing entry for dan's last patch
Chris PeBenito [Wed, 2 Aug 2006 19:56:32 +0000 (19:56 +0000)] 
add missing entry for dan's last patch

17 years agofix up mtrr interfaces. missing the file class on a few interfaces, and read and...
Chris PeBenito [Tue, 1 Aug 2006 14:43:10 +0000 (14:43 +0000)] 
fix up mtrr interfaces.  missing the file class on a few interfaces, and read and write cannot be split.

17 years agoadd authlogin interface to abstract common login program perms
Chris PeBenito [Mon, 31 Jul 2006 22:26:59 +0000 (22:26 +0000)] 
add authlogin interface to abstract common login program perms

17 years agopatch from dan Wed, 26 Jul 2006 14:42:46 -0400
Chris PeBenito [Fri, 28 Jul 2006 15:13:58 +0000 (15:13 +0000)] 
patch from dan Wed, 26 Jul 2006 14:42:46 -0400

17 years agomore ssh agent fixes
Chris PeBenito [Wed, 26 Jul 2006 21:16:45 +0000 (21:16 +0000)] 
more ssh agent fixes

17 years agoclean up most of the remaining ssh TODO
Chris PeBenito [Wed, 26 Jul 2006 20:34:09 +0000 (20:34 +0000)] 
clean up most of the remaining ssh TODO

17 years agoadd gdm Xsession fc
Chris PeBenito [Wed, 26 Jul 2006 20:33:23 +0000 (20:33 +0000)] 
add gdm Xsession fc

17 years agoremove deprecated mount_send_nfs_client_request() from stunnel
Chris PeBenito [Tue, 25 Jul 2006 22:28:47 +0000 (22:28 +0000)] 
remove deprecated mount_send_nfs_client_request() from stunnel

17 years agoadd helpers for printing warning and error messages
Chris PeBenito [Tue, 25 Jul 2006 17:27:00 +0000 (17:27 +0000)] 
add helpers for printing warning and error messages

17 years agosome cleanup in the kernel layer
Chris PeBenito [Tue, 25 Jul 2006 15:23:13 +0000 (15:23 +0000)] 
some cleanup in the kernel layer

17 years agopatch to fix escaping of . in file contexts from james athey
Chris PeBenito [Mon, 24 Jul 2006 15:43:57 +0000 (15:43 +0000)] 
patch to fix escaping of . in file contexts from james athey

17 years agoadd access to keys for unconfined
Chris PeBenito [Fri, 14 Jul 2006 13:11:42 +0000 (13:11 +0000)] 
add access to keys for unconfined

17 years agofix up audit message perms now that audit_write denials are being audited by the...
Chris PeBenito [Thu, 13 Jul 2006 17:22:08 +0000 (17:22 +0000)] 
fix up audit message perms now that audit_write denials are being audited by the kernel.

17 years agoremove setbool auditallow, except for distro_rhel4.
Chris PeBenito [Thu, 13 Jul 2006 14:22:21 +0000 (14:22 +0000)] 
remove setbool auditallow, except for distro_rhel4.

17 years agoremove extra level of directory
Chris PeBenito [Wed, 12 Jul 2006 20:33:09 +0000 (20:33 +0000)] 
remove extra level of directory

17 years agoremove extra level of directory
Chris PeBenito [Wed, 12 Jul 2006 20:32:27 +0000 (20:32 +0000)] 
remove extra level of directory

17 years agomissing tcp connect for http cache
Chris PeBenito [Wed, 12 Jul 2006 13:17:24 +0000 (13:17 +0000)] 
missing tcp connect for http cache

17 years agoadd 3rd party interface for transition out of unconfined
Chris PeBenito [Mon, 10 Jul 2006 13:31:28 +0000 (13:31 +0000)] 
add 3rd party interface for transition out of unconfined

17 years agoadd audit_write and a little style cleanup.
Chris PeBenito [Fri, 7 Jul 2006 14:51:08 +0000 (14:51 +0000)] 
add audit_write and a little style cleanup.

17 years agomove non-policy dirs out of trunk
Chris PeBenito [Thu, 6 Jul 2006 17:35:17 +0000 (17:35 +0000)] 
move non-policy dirs out of trunk

17 years agochange to use validate target for module linking
Chris PeBenito [Thu, 6 Jul 2006 17:16:21 +0000 (17:16 +0000)] 
change to use validate target for module linking

17 years agomore TODO cleanup
Chris PeBenito [Thu, 6 Jul 2006 17:00:29 +0000 (17:00 +0000)] 
more TODO cleanup

17 years agoadd vgetty log fc
Chris PeBenito [Thu, 6 Jul 2006 14:52:04 +0000 (14:52 +0000)] 
add vgetty log fc

17 years agoa few TODO fixes, and deprecate mount_send_nfs_client_request().
Chris PeBenito [Wed, 5 Jul 2006 19:15:23 +0000 (19:15 +0000)] 
a few TODO fixes, and deprecate mount_send_nfs_client_request().

17 years agomake mta dep optional
Chris PeBenito [Mon, 3 Jul 2006 18:26:26 +0000 (18:26 +0000)] 
make mta dep optional

17 years agoadd support for toolchain testing
Chris PeBenito [Mon, 3 Jul 2006 18:03:16 +0000 (18:03 +0000)] 
add support for toolchain testing

17 years agofix initrc_context for targeted
Chris PeBenito [Mon, 3 Jul 2006 14:09:46 +0000 (14:09 +0000)] 
fix initrc_context for targeted

17 years agochange eventpollfs labeling to task sid
Chris PeBenito [Wed, 28 Jun 2006 20:28:09 +0000 (20:28 +0000)] 
change eventpollfs labeling to task sid

17 years agotemporarily add unlabeled packet perm to unlabeled association if
Chris PeBenito [Wed, 28 Jun 2006 14:54:04 +0000 (14:54 +0000)] 
temporarily add unlabeled packet perm to unlabeled association if

17 years agochange assignment of programs so they can be overridden on the cmdline
Chris PeBenito [Wed, 28 Jun 2006 14:42:36 +0000 (14:42 +0000)] 
change assignment of programs so they can be overridden on the cmdline

17 years agofix "no modules enabled" check
Chris PeBenito [Wed, 28 Jun 2006 13:55:52 +0000 (13:55 +0000)] 
fix "no modules enabled" check

17 years agobump mod versions for key
Chris PeBenito [Wed, 21 Jun 2006 21:04:14 +0000 (21:04 +0000)] 
bump mod versions for key

17 years agoadd key support
Chris PeBenito [Wed, 21 Jun 2006 21:02:49 +0000 (21:02 +0000)] 
add key support

17 years agolist dans patches
Chris PeBenito [Wed, 21 Jun 2006 19:07:32 +0000 (19:07 +0000)] 
list dans patches

17 years agopatch from Dan Tue, 20 Jun 2006 16:19:13 -0400
Chris PeBenito [Wed, 21 Jun 2006 18:25:06 +0000 (18:25 +0000)] 
patch from Dan Tue, 20 Jun 2006 16:19:13 -0400

17 years agoneed send_msg for merging dbus
Chris PeBenito [Tue, 20 Jun 2006 17:32:21 +0000 (17:32 +0000)] 
need send_msg for merging dbus

17 years agoremove raw network, make mta optional, and a little cleanup.
Chris PeBenito [Fri, 16 Jun 2006 19:54:21 +0000 (19:54 +0000)] 
remove raw network, make mta optional, and a little cleanup.

17 years agofix typo
Chris PeBenito [Fri, 16 Jun 2006 13:10:40 +0000 (13:10 +0000)] 
fix typo

17 years agoremove redundant conditional
Chris PeBenito [Thu, 15 Jun 2006 20:18:38 +0000 (20:18 +0000)] 
remove redundant conditional

17 years agofix typo
Chris PeBenito [Thu, 15 Jun 2006 17:37:47 +0000 (17:37 +0000)] 
fix typo

17 years agofix typo
Chris PeBenito [Thu, 15 Jun 2006 17:04:08 +0000 (17:04 +0000)] 
fix typo

17 years agoclean up usercanread
Chris PeBenito [Wed, 14 Jun 2006 20:52:45 +0000 (20:52 +0000)] 
clean up usercanread

17 years agofix typos
Chris PeBenito [Wed, 14 Jun 2006 14:10:24 +0000 (14:10 +0000)] 
fix typos

17 years agoadd ftpdctl from paul howarth
Chris PeBenito [Tue, 13 Jun 2006 18:17:34 +0000 (18:17 +0000)] 
add ftpdctl from paul howarth

17 years agoundo dans reversion
Chris PeBenito [Tue, 13 Jun 2006 13:05:35 +0000 (13:05 +0000)] 
undo dans reversion

17 years agopatch from dan Mon, 12 Jun 2006 15:32:00 -0400
Chris PeBenito [Mon, 12 Jun 2006 21:36:38 +0000 (21:36 +0000)] 
patch from dan Mon, 12 Jun 2006 15:32:00 -0400

17 years agoremove some extra endlines
Chris PeBenito [Mon, 12 Jun 2006 17:27:15 +0000 (17:27 +0000)] 
remove some extra endlines

17 years agoFix build system to not move type declarations out of optionals.
Chris PeBenito [Mon, 12 Jun 2006 16:59:21 +0000 (16:59 +0000)] 
Fix build system to not move type declarations out of optionals.

17 years agofix dbus_user_bus_client_template
Chris PeBenito [Mon, 12 Jun 2006 16:55:18 +0000 (16:55 +0000)] 
fix dbus_user_bus_client_template

17 years agofix to use ifndef convenience macro
Chris PeBenito [Mon, 12 Jun 2006 16:52:41 +0000 (16:52 +0000)] 
fix to use ifndef convenience macro

17 years agoadd ifndef convenience macro
Chris PeBenito [Mon, 12 Jun 2006 15:49:48 +0000 (15:49 +0000)] 
add ifndef convenience macro

17 years agofix typo
Chris PeBenito [Mon, 12 Jun 2006 15:42:13 +0000 (15:42 +0000)] 
fix typo

17 years agouse domtrans from initrc for insmod
Chris PeBenito [Mon, 12 Jun 2006 15:22:45 +0000 (15:22 +0000)] 
use domtrans from initrc for insmod

17 years agofix up bad ifdefs and remove foo.te definition for modules.
Chris PeBenito [Mon, 12 Jun 2006 14:17:40 +0000 (14:17 +0000)] 
fix up bad ifdefs and remove foo.te definition for modules.

17 years agoanother script in the apr build dir
Chris PeBenito [Fri, 9 Jun 2006 13:49:22 +0000 (13:49 +0000)] 
another script in the apr build dir

17 years agoshell scripts in the apr build dir
Chris PeBenito [Fri, 9 Jun 2006 13:47:58 +0000 (13:47 +0000)] 
shell scripts in the apr build dir

17 years agofix most bad rules in cups, bug 1771
Chris PeBenito [Thu, 8 Jun 2006 17:18:25 +0000 (17:18 +0000)] 
fix most bad rules in cups, bug 1771

17 years agopatch from dan Tue, 06 Jun 2006 22:50:46 -0400
Chris PeBenito [Wed, 7 Jun 2006 17:43:10 +0000 (17:43 +0000)] 
patch from dan Tue, 06 Jun 2006 22:50:46 -0400

17 years agofix execmod all files rule in wine
Chris PeBenito [Tue, 6 Jun 2006 17:51:24 +0000 (17:51 +0000)] 
fix execmod all files rule in wine

17 years agoimprove warning message, with file and line numbers
Chris PeBenito [Tue, 6 Jun 2006 17:25:23 +0000 (17:25 +0000)] 
improve warning message, with file and line numbers

17 years agofix bad use of templates
Chris PeBenito [Tue, 6 Jun 2006 17:24:34 +0000 (17:24 +0000)] 
fix bad use of templates

17 years agomissing net_bind_service cap for bind_all_ports interfaces
Chris PeBenito [Fri, 2 Jun 2006 17:44:44 +0000 (17:44 +0000)] 
missing net_bind_service cap for bind_all_ports interfaces

17 years agopackets
Chris PeBenito [Fri, 2 Jun 2006 15:06:45 +0000 (15:06 +0000)] 
packets

17 years agopackets for inetd
Chris PeBenito [Fri, 2 Jun 2006 13:48:34 +0000 (13:48 +0000)] 
packets for inetd

17 years agofill out networking perms
Chris PeBenito [Thu, 1 Jun 2006 18:17:53 +0000 (18:17 +0000)] 
fill out networking perms

17 years agopackets for ftp
Chris PeBenito [Wed, 31 May 2006 17:20:21 +0000 (17:20 +0000)] 
packets for ftp

17 years agopackets for services
Chris PeBenito [Tue, 30 May 2006 19:46:34 +0000 (19:46 +0000)] 
packets for services

17 years agopackets for admin modules
Chris PeBenito [Mon, 29 May 2006 19:53:43 +0000 (19:53 +0000)] 
packets for admin modules

17 years agoadd packets for apps
Chris PeBenito [Mon, 29 May 2006 18:25:58 +0000 (18:25 +0000)] 
add packets for apps

17 years agobreak packet_t into server_packet_t client_packet_t, and cover add packets to system...
Chris PeBenito [Mon, 29 May 2006 15:04:49 +0000 (15:04 +0000)] 
break packet_t into server_packet_t client_packet_t, and cover add packets to system modules where they make sense.

17 years agoadd gcc-config to portage
Chris PeBenito [Mon, 29 May 2006 14:16:22 +0000 (14:16 +0000)] 
add gcc-config to portage

17 years agoapache packets
Chris PeBenito [Fri, 26 May 2006 20:46:37 +0000 (20:46 +0000)] 
apache packets

17 years agoupdates for nfs, squid, and mta
Chris PeBenito [Fri, 26 May 2006 20:29:51 +0000 (20:29 +0000)] 
updates for nfs, squid, and mta

17 years agomore packets
Chris PeBenito [Fri, 26 May 2006 19:04:18 +0000 (19:04 +0000)] 
more packets

17 years agopacket updates for kernel, nscd, bind, ntp, spamassassin, and dhcpc
Chris PeBenito [Fri, 26 May 2006 18:04:46 +0000 (18:04 +0000)] 
packet updates for kernel, nscd, bind, ntp, spamassassin, and dhcpc

17 years agopackets for users
Chris PeBenito [Fri, 26 May 2006 14:40:12 +0000 (14:40 +0000)] 
packets for users

17 years agofix typos
Chris PeBenito [Fri, 26 May 2006 14:34:13 +0000 (14:34 +0000)] 
fix typos

17 years agocomment out .SECONDARY since its broken in make 3.81, and rawhide uses this make now
Chris PeBenito [Fri, 26 May 2006 14:33:44 +0000 (14:33 +0000)] 
comment out .SECONDARY since its broken in make 3.81, and rawhide uses this make now

17 years agoadd client and server packet attributes
Chris PeBenito [Fri, 26 May 2006 13:49:13 +0000 (13:49 +0000)] 
add client and server packet attributes

17 years agoupdate ssh for packets
Chris PeBenito [Thu, 25 May 2006 20:18:24 +0000 (20:18 +0000)] 
update ssh for packets

17 years agoreorganize the file
Chris PeBenito [Thu, 25 May 2006 18:42:32 +0000 (18:42 +0000)] 
reorganize the file

17 years agopackets from configuring cups from a web browser and printing a test page to a jetdirect
Chris PeBenito [Thu, 25 May 2006 18:41:14 +0000 (18:41 +0000)] 
packets from configuring cups from a web browser and printing a test page to a jetdirect

17 years agotypo
Chris PeBenito [Thu, 25 May 2006 17:59:50 +0000 (17:59 +0000)] 
typo

17 years agoinitial packet rules
Chris PeBenito [Thu, 25 May 2006 17:56:07 +0000 (17:56 +0000)] 
initial packet rules

17 years agoadd generic packet interfaces, and fix up unconfined handling
Chris PeBenito [Thu, 25 May 2006 17:01:36 +0000 (17:01 +0000)] 
add generic packet interfaces, and fix up unconfined handling

17 years agoremove debugging statemnet
Chris PeBenito [Thu, 25 May 2006 16:40:52 +0000 (16:40 +0000)] 
remove debugging statemnet

17 years agoadd makefile support for netfilter contexts
Chris PeBenito [Thu, 25 May 2006 15:14:19 +0000 (15:14 +0000)] 
add makefile support for netfilter contexts

17 years agofix copyright years
Chris PeBenito [Thu, 25 May 2006 15:09:06 +0000 (15:09 +0000)] 
fix copyright years

17 years agofix handling of comments at the end of the line, and add copyright
Chris PeBenito [Thu, 25 May 2006 15:04:39 +0000 (15:04 +0000)] 
fix handling of comments at the end of the line, and add copyright

17 years agofix chain declaration
Chris PeBenito [Thu, 25 May 2006 14:10:55 +0000 (14:10 +0000)] 
fix chain declaration

17 years agoadd command line arguments support, and mls/mcs support
Chris PeBenito [Thu, 25 May 2006 14:02:41 +0000 (14:02 +0000)] 
add command line arguments support, and mls/mcs support

17 years agoadd compute_av for doing rootok check
Chris PeBenito [Thu, 25 May 2006 13:14:08 +0000 (13:14 +0000)] 
add compute_av for doing rootok check

17 years agouse network_port()s to declare packets, since packets match up with these ports
Chris PeBenito [Wed, 24 May 2006 21:28:49 +0000 (21:28 +0000)] 
use network_port()s to declare packets, since packets match up with these ports

17 years agoinitial commit of netfilter config generator tool, still needs work on mls/mcs side.
Chris PeBenito [Wed, 24 May 2006 21:27:52 +0000 (21:27 +0000)] 
initial commit of netfilter config generator tool, still needs work on mls/mcs side.

17 years agoallow iptables to relabelto all packets
Chris PeBenito [Tue, 23 May 2006 19:07:22 +0000 (19:07 +0000)] 
allow iptables to relabelto all packets

17 years agoinitial support for packets
Chris PeBenito [Tue, 23 May 2006 18:31:02 +0000 (18:31 +0000)] 
initial support for packets

17 years agoinitial addition of packet policy, allow unconfined to send unlabeled packets.
Chris PeBenito [Mon, 22 May 2006 20:47:05 +0000 (20:47 +0000)] 
initial addition of packet policy, allow unconfined to send unlabeled packets.