]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
13 years agoAdd missing cluster suite modules that were missing from the Changelog.
Chris PeBenito [Wed, 26 May 2010 15:53:21 +0000 (11:53 -0400)] 
Add missing cluster suite modules that were missing from the Changelog.

13 years agoFix duplicate lines in kudzu.
Chris PeBenito [Wed, 26 May 2010 12:26:50 +0000 (08:26 -0400)] 
Fix duplicate lines in kudzu.

13 years agoChangelog and version update for release.
Chris PeBenito [Tue, 25 May 2010 20:01:49 +0000 (16:01 -0400)] 
Changelog and version update for release.

13 years agoBump module versions for release.
Chris PeBenito [Mon, 24 May 2010 19:32:01 +0000 (15:32 -0400)] 
Bump module versions for release.

13 years agoAdd missing changelog entries.
Chris PeBenito [Mon, 24 May 2010 19:24:40 +0000 (15:24 -0400)] 
Add missing changelog entries.

13 years agoFix deprecated interface usage in rhel4 block in su.if.
Chris PeBenito [Mon, 24 May 2010 19:09:18 +0000 (15:09 -0400)] 
Fix deprecated interface usage in rhel4 block in su.if.

13 years agoModule version bump for 904f3d8.
Chris PeBenito [Mon, 24 May 2010 17:07:51 +0000 (13:07 -0400)] 
Module version bump for 904f3d8.

13 years agoModule version bump for 1184392 and more.
Chris PeBenito [Mon, 24 May 2010 17:00:07 +0000 (13:00 -0400)] 
Module version bump for 1184392 and more.

* module version bump
* make apache and unconfined portions optiona
* rearrange lines

13 years agoModule version bump for 7942f7f.
Chris PeBenito [Mon, 24 May 2010 16:26:57 +0000 (12:26 -0400)] 
Module version bump for 7942f7f.

13 years agoModule version bump for 383bd32.
Chris PeBenito [Mon, 24 May 2010 15:50:50 +0000 (11:50 -0400)] 
Module version bump for 383bd32.

13 years agoModule version bump for 9e28f74.
Chris PeBenito [Mon, 24 May 2010 15:44:37 +0000 (11:44 -0400)] 
Module version bump for 9e28f74.

13 years agoModule version bump for f61ef24.
Chris PeBenito [Mon, 24 May 2010 15:29:27 +0000 (11:29 -0400)] 
Module version bump for f61ef24.

13 years agoModule version bump for d5170e5.
Chris PeBenito [Mon, 24 May 2010 15:18:04 +0000 (11:18 -0400)] 
Module version bump for d5170e5.

13 years agoModule version bump for cb1df6a.
Chris PeBenito [Mon, 24 May 2010 15:13:26 +0000 (11:13 -0400)] 
Module version bump for cb1df6a.

13 years agoreadahead patch from Dan Walsh
Jeremy Solt [Mon, 24 May 2010 14:57:14 +0000 (10:57 -0400)] 
readahead patch from Dan Walsh

Edits:
 - Removed files_dontaudit_read_security_files and fs_dontaudit_read_tmpfs_blk_dev interface calls

13 years agoFix deprecated interface usage that crept into lvm.if.
Chris PeBenito [Mon, 24 May 2010 15:06:48 +0000 (11:06 -0400)] 
Fix deprecated interface usage that crept into lvm.if.

13 years agoMove line in logrotate; module version bump.
Chris PeBenito [Mon, 24 May 2010 15:00:38 +0000 (11:00 -0400)] 
Move line in logrotate; module version bump.

13 years agoRemove redundant optional and libs_* calls in clogd.
Chris PeBenito [Mon, 24 May 2010 14:47:33 +0000 (10:47 -0400)] 
Remove redundant optional and libs_* calls in clogd.

13 years agoModule version bump for 51ad76f.
Chris PeBenito [Mon, 24 May 2010 14:29:41 +0000 (10:29 -0400)] 
Module version bump for 51ad76f.

13 years agowhitespace fix for clogd
Jeremy Solt [Fri, 21 May 2010 20:44:22 +0000 (16:44 -0400)] 
whitespace fix for clogd

13 years agoclogd policy from Dan Walsh
Jeremy Solt [Thu, 6 May 2010 19:39:25 +0000 (15:39 -0400)] 
clogd policy from Dan Walsh

edits:
 - style and whitespace fixes
 - removed read_lnk_files_pattern from shm interface
 - removed permissive line

13 years agowhitespace fixes for cluster suite patch
Jeremy Solt [Fri, 21 May 2010 20:40:12 +0000 (16:40 -0400)] 
whitespace fixes for cluster suite patch

13 years agoRemoved unnecessary comments
Jeremy Solt [Fri, 21 May 2010 19:59:16 +0000 (15:59 -0400)] 
Removed unnecessary comments
Removed 'SELinux policy for' from policy summaries
Removed rgmanager interface for semaphores (doesn't appear to be needed or used)
Removed redundant calls to libs_use_ld_so and libs_use_shared_libs
Fixed rhcs interface names to match naming rules
Merged tmpfs and semaphore/shm interfaces

13 years agoRedhat Cluster Suite Policy from Dan Walsh
Jeremy Solt [Thu, 6 May 2010 17:13:41 +0000 (13:13 -0400)] 
Redhat Cluster Suite Policy from Dan Walsh

Edits:
 - Style and whitespace fixes
 - Removed interfaces for default_t from ricci.te - this didn't seem right
 - Removed link files from rgmanager_manage_tmpfs_files
 - Removed rdisc.if patch. it was previously committed
 - Not including kernel_kill interface call for rgmanager
 - Not including ldap interfaces in rgmanager.te (currently not in refpolicy)
 - Not including files_create_var_run_dirs call for rgmanager (not in refpolicy)

13 years agologrotate patch from Dan Walsh
Jeremy Solt [Mon, 24 May 2010 14:26:31 +0000 (10:26 -0400)] 
logrotate patch from Dan Walsh

13 years agovpn patch from Dan Walsh
Jeremy Solt [Mon, 24 May 2010 14:12:43 +0000 (10:12 -0400)] 
vpn patch from Dan Walsh

Edits:
 - Removed userdom_read_home_certs

13 years agodnsmasq patch from Dan Walsh
Jeremy Solt [Fri, 21 May 2010 21:02:24 +0000 (17:02 -0400)] 
dnsmasq patch from Dan Walsh
- cron_manage_pid_files call removed until further explanation

13 years agoReplace apache_delete_cache with apache_delete_cache_files in tmpreaper.te
Jeremy Solt [Mon, 24 May 2010 15:28:52 +0000 (11:28 -0400)] 
Replace apache_delete_cache with apache_delete_cache_files in tmpreaper.te

13 years agotmpreaper patch from Dan Walsh
Jeremy Solt [Mon, 24 May 2010 14:51:54 +0000 (10:51 -0400)] 
tmpreaper patch from Dan Walsh

13 years agoRemove call to nagios_rw_inherited_tmp_files
Jeremy Solt [Mon, 24 May 2010 14:04:23 +0000 (10:04 -0400)] 
Remove call to nagios_rw_inherited_tmp_files

13 years agonetutils patch from Dan Walsh
Jeremy Solt [Mon, 24 May 2010 13:54:02 +0000 (09:54 -0400)] 
netutils patch from Dan Walsh

Edits:
 - Dropping term_use_all_terms and user_ping tunables for ping and traceroute
 - Whitespace fixes

13 years agoRemove nagios_rw_inherited_tmp_files interface
Jeremy Solt [Mon, 24 May 2010 14:02:01 +0000 (10:02 -0400)] 
Remove nagios_rw_inherited_tmp_files interface

13 years agoNagios patch from Dan Walsh
Jeremy Solt [Mon, 24 May 2010 13:42:59 +0000 (09:42 -0400)] 
Nagios patch from Dan Walsh

Edits:
- Removed permissive lines
- Removed tunable for broken symptoms
- Style and whitespace fixes

13 years agoCreate type and allow squid to manage its own tmpfs files
Jeremy Solt [Fri, 21 May 2010 16:19:32 +0000 (12:19 -0400)] 
Create type and allow squid to manage its own tmpfs files

13 years agosquid patch from Dan Walsh
Jeremy Solt [Fri, 7 May 2010 14:57:56 +0000 (10:57 -0400)] 
squid patch from Dan Walsh

Edits:
 - Added netport to corenetwork.te.in

13 years agoremove rules for nx_server_home_ssh_t since they are already provided by the ssh...
Jeremy Solt [Fri, 21 May 2010 16:39:52 +0000 (12:39 -0400)] 
remove rules for nx_server_home_ssh_t since they are already provided by the ssh template

13 years agonx patch from Dan Walsh
Jeremy Solt [Fri, 7 May 2010 13:50:48 +0000 (09:50 -0400)] 
nx patch from Dan Walsh

Edits:
 - Style and whitespace fixes
 - Removed read_lnk_files_pattern from nx_read_home_files
 - Delete declaration of nx_server_home_ssh_t and files_type since the template already does this

14 years agoPostfix patch from Dan Walsh.
Chris PeBenito [Fri, 21 May 2010 12:56:49 +0000 (08:56 -0400)] 
Postfix patch from Dan Walsh.

14 years agoPrelink patch from Dan Walsh.
Chris PeBenito [Thu, 20 May 2010 12:54:51 +0000 (08:54 -0400)] 
Prelink patch from Dan Walsh.

14 years agoSendmail patch from Dan Walsh.
Chris PeBenito [Thu, 20 May 2010 12:36:38 +0000 (08:36 -0400)] 
Sendmail patch from Dan Walsh.

14 years agoProcmail patch from Dan Walsh.
Chris PeBenito [Thu, 20 May 2010 12:17:06 +0000 (08:17 -0400)] 
Procmail patch from Dan Walsh.

14 years agoMTA patch from Dan Walsh.
Chris PeBenito [Wed, 19 May 2010 13:00:39 +0000 (09:00 -0400)] 
MTA patch from Dan Walsh.

14 years agoSSH patch from Dan Walsh.
Chris PeBenito [Wed, 19 May 2010 12:31:17 +0000 (08:31 -0400)] 
SSH patch from Dan Walsh.

14 years agoCups patch from Dan Walsh.
Chris PeBenito [Tue, 18 May 2010 14:59:37 +0000 (10:59 -0400)] 
Cups patch from Dan Walsh.

14 years agoRemove excessive permission in udev_manage_rules_files() and move the interface up...
Chris PeBenito [Tue, 18 May 2010 14:28:17 +0000 (10:28 -0400)] 
Remove excessive permission in udev_manage_rules_files() and move the interface up in the .if file.  Module version bump for d56b33a.

14 years agoCreate new interface and type for managing /etc/udev/rules.d
Chris Richards [Fri, 16 Apr 2010 06:27:36 +0000 (06:27 +0000)] 
Create new interface and type for managing /etc/udev/rules.d

udev_var_run_t is used for managing files in /etc/udev/rules.d as well as other files, including udev pid files.  This patch creates a type specifically for rules.d files, and an interface for managing them.  It also gives access to this type to initrc_t so that rules can be properly populated during startup.  This also fixes a problem on Gentoo where udev rules are NOT properly populated on startup.

Signed-off-by: Chris Richards <gizmo@giz-works.com>
Signed-off-by: Chris PeBenito <cpebenito@tresys.com>
14 years agoAbrt patch from Dan Walsh.
Chris PeBenito [Tue, 18 May 2010 14:18:12 +0000 (10:18 -0400)] 
Abrt patch from Dan Walsh.

14 years agoPlymouthd policy from Dan Walsh.
Chris PeBenito [Tue, 18 May 2010 13:54:18 +0000 (09:54 -0400)] 
Plymouthd policy from Dan Walsh.

14 years agoHal patch from Dan Walsh.
Chris PeBenito [Tue, 18 May 2010 13:06:36 +0000 (09:06 -0400)] 
Hal patch from Dan Walsh.

Lots of random access for hal.

14 years agoLoadkeys patch from Dan Walsh.
Chris PeBenito [Fri, 14 May 2010 15:40:26 +0000 (11:40 -0400)] 
Loadkeys patch from Dan Walsh.

14 years agoJava patch from Dan Walsh.
Chris PeBenito [Fri, 14 May 2010 14:40:59 +0000 (10:40 -0400)] 
Java patch from Dan Walsh.

Additional java context

unconfined_Java apps needs to execmod any file since we do not know where the jave content will be labeled

We want unconfined java apps to transition to rpm when they execute rpm_exec_t.  To maintain proper labeling.

14 years agoCVS patch from Dan Walsh.
Chris PeBenito [Fri, 14 May 2010 14:24:11 +0000 (10:24 -0400)] 
CVS patch from Dan Walsh.

cvs needs dac_override when it tries to read shadow

14 years agoSETroubleshoot patch from Dan Walsh.
Chris PeBenito [Thu, 13 May 2010 17:22:53 +0000 (13:22 -0400)] 
SETroubleshoot patch from Dan Walsh.

Policy to handle the fixit button in setroubleshoot.

14 years agoAsterisk patch from Dan Walsh.
Chris PeBenito [Thu, 13 May 2010 15:35:58 +0000 (11:35 -0400)] 
Asterisk patch from Dan Walsh.

    asterisk_manage_lib_files(logrotate_t)
    asterisk_exec(logrotate_t)

Needs net_admin

Drops capabilities
connects to unix_stream

execs itself

Requests kernel load modules

Execs shells

Connects to postgresql and snmp ports

Reads urand and generic usb devices

Has mysql and postgresql back ends
sends mail

14 years agoMunin patch from Dan Walsh.
Chris PeBenito [Thu, 13 May 2010 15:20:54 +0000 (11:20 -0400)] 
Munin patch from Dan Walsh.

14 years agoRPM patch from Dan Walsh.
Chris PeBenito [Tue, 11 May 2010 15:11:40 +0000 (11:11 -0400)] 
RPM patch from Dan Walsh.

14 years agoMinor fixes on a2524cf. Module version bump.
Chris PeBenito [Tue, 11 May 2010 12:33:04 +0000 (08:33 -0400)] 
Minor fixes on a2524cf. Module version bump.

14 years agoWhitespace fixes on cobbler.
Chris PeBenito [Tue, 11 May 2010 12:23:02 +0000 (08:23 -0400)] 
Whitespace fixes on cobbler.

14 years agocobbler patch from Dan Walsh
Jeremy Solt [Fri, 7 May 2010 14:09:07 +0000 (10:09 -0400)] 
cobbler patch from Dan Walsh

14 years agoCyrus patch from Dan Walsh.
Chris PeBenito [Mon, 3 May 2010 19:14:50 +0000 (15:14 -0400)] 
Cyrus patch from Dan Walsh.

14 years agoClamav patch from Dan Walsh.
Chris PeBenito [Mon, 3 May 2010 19:01:35 +0000 (15:01 -0400)] 
Clamav patch from Dan Walsh.

14 years agoDovecot patch from Dan Walsh.
Chris PeBenito [Mon, 3 May 2010 18:37:19 +0000 (14:37 -0400)] 
Dovecot patch from Dan Walsh.

14 years agoNetworkmanager patch from Dan Walsh.
Chris PeBenito [Mon, 3 May 2010 18:01:26 +0000 (14:01 -0400)] 
Networkmanager patch from Dan Walsh.

14 years agoFix a typo in support/genhomedircon.
Justin P. Mattock [Fri, 23 Apr 2010 07:17:57 +0000 (00:17 -0700)] 
Fix a typo in support/genhomedircon.

Fix a typo in support/genhomedircon.

Signed-off-by: Justin P. Mattock <justinmattock@gmail.com>
Signed-off-by: Chris PeBenito <cpebenito@tresys.com>
14 years agoAdd kernel access to devtmpfs. Also add workround while devtmpfs is tmpfs_t instead...
Chris PeBenito [Mon, 3 May 2010 15:17:16 +0000 (11:17 -0400)] 
Add kernel access to devtmpfs.  Also add workround while devtmpfs is tmpfs_t instead of device_t.

14 years agoConsolekit patch from Dan Walsh.
Chris PeBenito [Mon, 3 May 2010 14:21:48 +0000 (10:21 -0400)] 
Consolekit patch from Dan Walsh.

14 years agoArpwatch patch from Dan Walsh.
Chris PeBenito [Mon, 3 May 2010 13:49:33 +0000 (09:49 -0400)] 
Arpwatch patch from Dan Walsh.

14 years agoDbus patch from Dan Walsh.
Chris PeBenito [Mon, 3 May 2010 13:34:42 +0000 (09:34 -0400)] 
Dbus patch from Dan Walsh.

14 years agoDevicekit patch from Dan Walsh.
Chris PeBenito [Mon, 3 May 2010 13:01:46 +0000 (09:01 -0400)] 
Devicekit patch from Dan Walsh.

14 years agoGPG patch from Dan Walsh.
Chris PeBenito [Fri, 30 Apr 2010 19:24:19 +0000 (15:24 -0400)] 
GPG patch from Dan Walsh.

14 years agoAdd trusted object condition to unix socket connectto/sendto, to fix label translation.
Chris PeBenito [Thu, 29 Apr 2010 15:29:39 +0000 (11:29 -0400)] 
Add trusted object condition to unix socket connectto/sendto, to fix label translation.

14 years agoAdd networking rules for spamd to connect to mysql/postgresql over the network, from...
Chris PeBenito [Tue, 27 Apr 2010 14:31:47 +0000 (10:31 -0400)] 
Add networking rules for spamd to connect to mysql/postgresql over the network, from Chris St. Pierre.

14 years agoAdd missing secmark rules in ntop, from Dominick Grift.
Chris PeBenito [Tue, 27 Apr 2010 13:31:30 +0000 (09:31 -0400)] 
Add missing secmark rules in ntop, from Dominick Grift.

14 years agoFTP patch from Dan Walsh.
Chris PeBenito [Mon, 26 Apr 2010 19:15:23 +0000 (15:15 -0400)] 
FTP patch from Dan Walsh.

14 years agoModule version bump for 34838aa.
Chris PeBenito [Mon, 26 Apr 2010 17:40:21 +0000 (13:40 -0400)] 
Module version bump for 34838aa.

14 years agoSamba patch from Dan Walsh
Jeremy Solt [Thu, 22 Apr 2010 18:35:58 +0000 (14:35 -0400)] 
Samba patch from Dan Walsh
 - signal interfaces
 - fusefs support
 - bug 566984: getattrs on all blk and chr files

Did not include:
 - changes related to samba_unconfined_script_t and samba_unconfined_net_t
 - samba_helper_template (didn't appear to be used)
 - manage_lnk_files_pattern in samba_manage_var_files
 - signal allow rule in samba_domtrans_winbind_helper
 - samba_role_notrans
 - userdom_manage_user_home_content

Some style and spacing fixes

14 years agobootmisc init script, 2nd try
Chris Richards [Sat, 24 Apr 2010 16:03:16 +0000 (16:03 +0000)] 
bootmisc init script, 2nd try

Allow to create /var/lock/.keep.  This prevents Portage from destroying /var/lock under certain conditions.  This patch is Gentoo specific.

Signed-off-by: Chris Richards <gizmo@giz-works.com>
Signed-off-by: Chris PeBenito <cpebenito@tresys.com>
14 years agoLircd patch from Dan Walsh.
Chris PeBenito [Tue, 20 Apr 2010 14:33:27 +0000 (10:33 -0400)] 
Lircd patch from Dan Walsh.

14 years agoAdd DenyHosts from Dan Walsh.
Chris PeBenito [Tue, 20 Apr 2010 13:46:20 +0000 (09:46 -0400)] 
Add DenyHosts from Dan Walsh.

14 years agoDjbdns patch from Dan Walsh.
Chris PeBenito [Tue, 20 Apr 2010 13:32:25 +0000 (09:32 -0400)] 
Djbdns patch from Dan Walsh.

14 years agoModule version bump and extra comments for 194d61f.
Chris PeBenito [Sat, 24 Apr 2010 12:09:50 +0000 (08:09 -0400)] 
Module version bump and extra comments for 194d61f.

14 years agomodutils patch for update-modules
Chris Richards [Fri, 16 Apr 2010 06:29:26 +0000 (06:29 +0000)] 
modutils patch for update-modules

update-modules on Gentoo throws errors when run because it sources /etc/init.d/functions.sh, which always scans /var/lib/init.d to set SOFTLEVEL environment var.  This is never used by update-modules.

Signed-off-by: Chris Richards <gizmo@giz-works.com>
Signed-off-by: Chris PeBenito <pebenito@gentoo.org>
14 years agoModule version bump for 8c38fba.
Chris PeBenito [Sat, 24 Apr 2010 12:07:51 +0000 (08:07 -0400)] 
Module version bump for 8c38fba.

14 years agoallow syslog-ng to setrlimit
Chris Richards [Fri, 16 Apr 2010 06:29:10 +0000 (06:29 +0000)] 
allow syslog-ng to setrlimit

syslog-ng wants to increase the number of permissible open files from 256 to 4096 on unix/linux systems.

Signed-off-by: Chris Richards <gizmo@giz-works.com>
Signed-off-by: Chris PeBenito <pebenito@gentoo.org>
14 years agoModule version bump for 4b121a5.
Chris PeBenito [Mon, 19 Apr 2010 14:23:11 +0000 (10:23 -0400)] 
Module version bump for 4b121a5.

14 years agoAdditional whitespace fix in nis.
Chris PeBenito [Mon, 19 Apr 2010 14:20:19 +0000 (10:20 -0400)] 
Additional whitespace fix in nis.

14 years agoStyle changes
Jeremy Solt [Mon, 12 Apr 2010 20:02:45 +0000 (16:02 -0400)] 
Style changes

14 years agonis patch from Dan Walsh
Jeremy Solt [Fri, 9 Apr 2010 15:52:54 +0000 (11:52 -0400)] 
nis patch from Dan Walsh

Made a couple style changes.
Removed unnecessary require in nis_use_ypbind interface

14 years agoAdditional whitespace fixes in certmonger.
Chris PeBenito [Mon, 19 Apr 2010 14:17:24 +0000 (10:17 -0400)] 
Additional whitespace fixes in certmonger.

14 years agoFix some whitespace and style issues.
Jeremy Solt [Mon, 12 Apr 2010 19:54:18 +0000 (15:54 -0400)] 
Fix some whitespace and style issues.

14 years agocertmonger policy from Dan Walsh
Jeremy Solt [Fri, 9 Apr 2010 17:05:52 +0000 (13:05 -0400)] 
certmonger policy from Dan Walsh

Removed manage_var_run and manage_var_lib interfaces
Added missing requires to admin interface
Removed permissive line
Fixed some spacing / style issues

14 years agoModule version bump for 4f7b413.
Chris PeBenito [Mon, 19 Apr 2010 14:05:22 +0000 (10:05 -0400)] 
Module version bump for 4f7b413.

14 years agoRemove excess white space from ntop.te
Jeremy Solt [Mon, 12 Apr 2010 19:31:43 +0000 (15:31 -0400)] 
Remove excess white space from ntop.te
Move ntop ports declaration to correct location.

14 years agoNtop policy from Dan Walsh
Jeremy Solt [Thu, 8 Apr 2010 14:28:53 +0000 (10:28 -0400)] 
Ntop policy from Dan Walsh

Added alias for ntop_http_content_t in apache
Pulled in ntop port from corenetwork patch

14 years agoModule version bump for 46e16a2.
Chris PeBenito [Mon, 19 Apr 2010 13:54:13 +0000 (09:54 -0400)] 
Module version bump for 46e16a2.

14 years agoMove optional policy to correct location for style
Jeremy Solt [Mon, 12 Apr 2010 19:23:36 +0000 (15:23 -0400)] 
Move optional policy to correct location for style

14 years agokerberos patch from Dan Walsh
Jeremy Solt [Thu, 8 Apr 2010 20:02:18 +0000 (16:02 -0400)] 
kerberos patch from Dan Walsh

14 years agoUse port range notation in corenetwork where it makes sense.
Chris PeBenito [Tue, 13 Apr 2010 15:55:04 +0000 (11:55 -0400)] 
Use port range notation in corenetwork where it makes sense.

14 years agoClean up output of generated corenetwork.te.
Chris PeBenito [Tue, 13 Apr 2010 15:52:09 +0000 (11:52 -0400)] 
Clean up output of generated corenetwork.te.

14 years agoFix network_port() in corenetwork to correctly handle port ranges.
Chris PeBenito [Tue, 13 Apr 2010 15:06:02 +0000 (11:06 -0400)] 
Fix network_port() in corenetwork to correctly handle port ranges.