]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Dan Walsh [Mon, 25 Jul 2011 14:32:46 +0000 (10:32 -0400)]
Allow gkeyring_t to interact with all user apps
Dan Walsh [Mon, 25 Jul 2011 12:49:29 +0000 (08:49 -0400)]
Add rules to allow firstboot to run on machines with the unconfined.pp module removed
Miroslav Grepl [Mon, 25 Jul 2011 08:56:36 +0000 (08:56 +0000)]
Try to treat /sbin/pppoe-server with pppd policy
* needs to be tested
Miroslav Grepl [Mon, 25 Jul 2011 08:32:22 +0000 (08:32 +0000)]
Allow lldpad to send to fcoemon unix dgram socket
Miroslav Grepl [Mon, 25 Jul 2011 08:30:08 +0000 (08:30 +0000)]
Add fcoemon policy
* Open-FCoE service daemon
Miroslav Grepl [Mon, 25 Jul 2011 08:25:13 +0000 (08:25 +0000)]
Allow systemd-login to use user domain tty which happens in runlevel 3
Miroslav Grepl [Sat, 23 Jul 2011 08:39:14 +0000 (08:39 +0000)]
Allow dhcpd setcap/getcap
Dan Walsh [Fri, 22 Jul 2011 20:39:20 +0000 (16:39 -0400)]
Allow systemd_logind to send dbus messages with users
Dan Walsh [Fri, 22 Jul 2011 20:28:55 +0000 (16:28 -0400)]
Allow dhcpd to get and set capabilities
Dan Walsh [Fri, 22 Jul 2011 20:25:43 +0000 (16:25 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 22 Jul 2011 20:25:19 +0000 (16:25 -0400)]
allow accountsd to read wtmp file
Miroslav Grepl [Fri, 22 Jul 2011 12:32:13 +0000 (12:32 +0000)]
Allow abrt-dump-oops to read system state information in /proc
Dan Walsh [Thu, 21 Jul 2011 20:34:18 +0000 (16:34 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 21 Jul 2011 21:03:18 +0000 (21:03 +0000)]
Rename oracledb_port_t to oracle_port_t
Miroslav Grepl [Thu, 21 Jul 2011 21:01:56 +0000 (21:01 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 21 Jul 2011 20:34:02 +0000 (16:34 -0400)]
Allow mount to mounton the selinux file system
Dan Walsh [Thu, 21 Jul 2011 20:31:39 +0000 (16:31 -0400)]
Allow users to list /var directories. per eparis
Miroslav Grepl [Thu, 21 Jul 2011 17:02:06 +0000 (17:02 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 21 Jul 2011 16:43:35 +0000 (12:43 -0400)]
add label for /selinux symbolic link
Dan Walsh [Thu, 21 Jul 2011 16:39:38 +0000 (12:39 -0400)]
init_t needs to be able to manage etc lnk_files
Dan Walsh [Thu, 21 Jul 2011 16:38:49 +0000 (12:38 -0400)]
Make firstboot always unconfined
Miroslav Grepl [Thu, 21 Jul 2011 16:22:07 +0000 (16:22 +0000)]
Allow postfix_pickup_t to delete postfix_spool links
Miroslav Grepl [Thu, 21 Jul 2011 16:19:04 +0000 (16:19 +0000)]
Fix typo
Miroslav Grepl [Thu, 21 Jul 2011 16:14:34 +0000 (16:14 +0000)]
More fixes for ctdbd policy
Dan Walsh [Thu, 21 Jul 2011 15:48:30 +0000 (11:48 -0400)]
New rules needed for virt_lxc_t to start a container
Dan Walsh [Thu, 21 Jul 2011 14:57:56 +0000 (10:57 -0400)]
fix unit name to standardize on httpd_unit_t name
Dan Walsh [Thu, 21 Jul 2011 13:39:46 +0000 (09:39 -0400)]
Allow crond to search and list the /root directory
Dan Walsh [Thu, 21 Jul 2011 13:31:56 +0000 (09:31 -0400)]
chrome_sandbox must be passing the open file descriptor back to chrome, so I think we need to allow this
Dan Walsh [Thu, 21 Jul 2011 13:18:34 +0000 (09:18 -0400)]
Fix interface to include httpd_sys_script_exec_t
Dan Walsh [Thu, 21 Jul 2011 13:16:37 +0000 (09:16 -0400)]
Allow psad_t to send its own processes all signals
Dan Walsh [Wed, 20 Jul 2011 21:42:47 +0000 (17:42 -0400)]
libffmpegsumo for chrome needs texrelocation
Dan Walsh [Wed, 20 Jul 2011 20:30:54 +0000 (16:30 -0400)]
Revert "Allow accountsd to read wtmp file"
This reverts commit
ff12712d14dca28bc28cc4e6a6b9f8be384fd767 .
Dan Walsh [Wed, 20 Jul 2011 20:28:46 +0000 (16:28 -0400)]
Fix rule to allow dump_oops_t to read /var/log/messages
Dan Walsh [Wed, 20 Jul 2011 20:28:35 +0000 (16:28 -0400)]
Fix rule to allow dump_oops_t to read /var/log/messages
Dan Walsh [Wed, 20 Jul 2011 16:38:29 +0000 (12:38 -0400)]
Allow accountsd to read wtmp file
Dan Walsh [Wed, 20 Jul 2011 16:38:09 +0000 (12:38 -0400)]
Allow systemd to create /var/run fifo_files
Dan Walsh [Wed, 20 Jul 2011 16:37:39 +0000 (12:37 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 20 Jul 2011 11:04:36 +0000 (11:04 +0000)]
Add fixes for postfix from RHEL
Miroslav Grepl [Wed, 20 Jul 2011 10:47:55 +0000 (10:47 +0000)]
More fixes for ctdbd policy
Miroslav Grepl [Wed, 20 Jul 2011 09:16:27 +0000 (09:16 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 20 Jul 2011 09:15:11 +0000 (09:15 +0000)]
Allow rgmanager executes init script files in initrc_t domain which ensure proper transitions
Dan Walsh [Tue, 19 Jul 2011 20:38:13 +0000 (16:38 -0400)]
Add systemd_unit file handling along with httpd just to try this out
Dan Walsh [Tue, 19 Jul 2011 19:51:02 +0000 (15:51 -0400)]
Looks like systemd_logind_t is reading user state /proc/PID/sessionid
Dan Walsh [Tue, 19 Jul 2011 17:38:01 +0000 (13:38 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 19 Jul 2011 17:26:15 +0000 (13:26 -0400)]
If you setup spice, xdm_t seems to be using the virtio device
Dan Walsh [Tue, 19 Jul 2011 17:25:48 +0000 (13:25 -0400)]
Revert mysql having kernel load modules, this was caused by a disable ipv6
Miroslav Grepl [Tue, 19 Jul 2011 17:23:30 +0000 (17:23 +0000)]
Correct systemd_login_read_pid_files interface
Miroslav Grepl [Tue, 19 Jul 2011 17:18:42 +0000 (17:18 +0000)]
abrt_dump_oops_t reads kernel sysctls
Miroslav Grepl [Tue, 19 Jul 2011 15:53:33 +0000 (15:53 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Tue, 19 Jul 2011 15:39:55 +0000 (15:39 +0000)]
Allow postfix_cleanup_t to searh maildrop
Dan Walsh [Tue, 19 Jul 2011 14:57:00 +0000 (10:57 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 19 Jul 2011 14:53:49 +0000 (10:53 -0400)]
logs directory under /var/www/html should be labeled content not as a httpd_log_t
Miroslav Grepl [Tue, 19 Jul 2011 14:11:20 +0000 (14:11 +0000)]
systemd-login needs fowner
Dan Walsh [Tue, 19 Jul 2011 12:29:00 +0000 (08:29 -0400)]
Allow mysqld to request the kernel to load modules
Dan Walsh [Tue, 19 Jul 2011 12:22:43 +0000 (08:22 -0400)]
Abrt_dump_oops_t reads kernel ring buffer
Miroslav Grepl [Tue, 19 Jul 2011 09:32:07 +0000 (09:32 +0000)]
xtables-multi wants to getattr of the proc fs
Miroslav Grepl [Tue, 19 Jul 2011 09:26:05 +0000 (09:26 +0000)]
Fixes for abrt_dump_oops_t policy
Dan Walsh [Tue, 19 Jul 2011 01:29:16 +0000 (21:29 -0400)]
Allow abrt_dump_oops to look at kernel sysctls
Dan Walsh [Mon, 18 Jul 2011 20:50:08 +0000 (16:50 -0400)]
abrt_dump_oops reads /var/log/messages
Dan Walsh [Mon, 18 Jul 2011 20:48:19 +0000 (16:48 -0400)]
Smoltclient is connecting to abrt
Dan Walsh [Mon, 18 Jul 2011 14:50:41 +0000 (10:50 -0400)]
Add initial policy for abrt_dump_oops_t
Dan Walsh [Mon, 18 Jul 2011 14:40:43 +0000 (10:40 -0400)]
Allow udev to read systemd_login var_run files
Dan Walsh [Mon, 18 Jul 2011 14:18:43 +0000 (10:18 -0400)]
Dontaudit leaked file descriptors to postdrop
Dan Walsh [Mon, 18 Jul 2011 14:13:57 +0000 (10:13 -0400)]
All spoolfile attribute so that systemd can create and delete sockets in spool file directories and with spoolfile types. Then change all files_type(.*spool_t) to files_spool_file)
Dominick Grift [Mon, 18 Jul 2011 08:32:32 +0000 (10:32 +0200)]
Merge branch 'logind_fix'
Dominick Grift [Mon, 18 Jul 2011 08:22:27 +0000 (10:22 +0200)]
systemd_logind: this is a bit cleaner
Miroslav Grepl [Mon, 18 Jul 2011 06:24:38 +0000 (06:24 +0000)]
Interface fixes
Dominick Grift [Sat, 16 Jul 2011 08:55:06 +0000 (10:55 +0200)]
systemd_logger: various stuff from dmesg
mozilla_plugin: allow caller to ptrace, ps and signal mozilla_plugin
Dominick Grift [Fri, 15 Jul 2011 18:23:35 +0000 (20:23 +0200)]
Merge branch 'master' of ssh://domg472@git.fedorahosted.org/git/selinux-policy.git
Dan Walsh [Fri, 15 Jul 2011 18:20:56 +0000 (14:20 -0400)]
Allow gssd to search though nfsd_fs_t file system, needed for new kerberos changes
Dominick Grift [Fri, 15 Jul 2011 18:09:13 +0000 (20:09 +0200)]
systemd_logind needs to dbus chat and read state files of all login
program domains.
Dominick Grift [Fri, 15 Jul 2011 17:57:06 +0000 (19:57 +0200)]
Try fix fc spec for /var/log/(l)?xdm.log again. #722571
Dan Walsh [Fri, 15 Jul 2011 17:51:36 +0000 (13:51 -0400)]
Remove bogus lines from systemd.te
Dominick Grift [Fri, 15 Jul 2011 17:42:58 +0000 (19:42 +0200)]
This does not belong here
Dominick Grift [Fri, 15 Jul 2011 17:36:42 +0000 (19:36 +0200)]
Merge branch 'master' of ssh://domg472@git.fedorahosted.org/git/selinux-policy.git
Dominick Grift [Fri, 15 Jul 2011 17:33:40 +0000 (19:33 +0200)]
Xserver: Removed rules that allowed xdm_t to use systemd_logind
/run/systemd/sessions/.* fifo_file descriptor, as that access is now
added to authlogin_pgm_domain (which xdm is)
The following calls in authlogin_pgm_domain are optional ( you may be
using upstart or sysvinit or whatever and my not have the systemd module
installed )
systemd_use_fds_logind($1)
systemd_write_inherited_logind_sessions_pipes($1)
Dan Walsh [Fri, 15 Jul 2011 17:32:15 +0000 (13:32 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 15 Jul 2011 17:31:00 +0000 (13:31 -0400)]
Inititial flask rules for systemd starting and stoping of services
Dominick Grift [Fri, 15 Jul 2011 17:19:20 +0000 (19:19 +0200)]
file context spec for /var/log/xdm.log #722571
Dan Walsh [Fri, 15 Jul 2011 16:52:22 +0000 (12:52 -0400)]
Add policy for systemd_logger and additional proivs for systemd_logind
Dan Walsh [Fri, 15 Jul 2011 16:51:43 +0000 (12:51 -0400)]
Allow login programs to communicate with systemd_logind
Dan Walsh [Fri, 15 Jul 2011 14:38:14 +0000 (10:38 -0400)]
Allow virtd_t to create dnsmasq pid dir
Dan Walsh [Fri, 15 Jul 2011 14:37:44 +0000 (10:37 -0400)]
Allow initrc_t to create pid files for wdmd
Dan Walsh [Fri, 15 Jul 2011 14:24:35 +0000 (10:24 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 15 Jul 2011 14:24:27 +0000 (10:24 -0400)]
Allow virt_lxc_t signal_perms
Dominick Grift [Fri, 15 Jul 2011 13:16:22 +0000 (15:16 +0200)]
systemd_logind links /run/user/$USER/X11/display to /tmp/.X11-unix/X*
sock_file
Dominick Grift [Fri, 15 Jul 2011 10:37:12 +0000 (12:37 +0200)]
Not sure if this is the right thing to do but systemd_logind_t needs
this and since init_systemd_domain has not had much use yet, it may be
applicable to all long running systemd domains.
By the way we should probably differentiate between long running systemd
domains and one shot systemd domains.
Dominick Grift [Fri, 15 Jul 2011 08:40:52 +0000 (10:40 +0200)]
virt: unconfined_t is optional
Dominick Grift [Fri, 15 Jul 2011 08:28:24 +0000 (10:28 +0200)]
Initial systemd_logind policy
logind creates seats, sessions and users dirs in /run/systemd. xdm and
systemd_dbusd_t use (read inherited) files in /run/systemd/sessions and
so i decided to give sessions a private type and leave seats and users
type systemd_logind_var_run_t since no other domains seem to want to
interact with this content so far. Later we could decide to create
private types or seats and or users as well or we could decide to label
all logind content in /run/user systemd_logind_var_run_t.
logind acquires service on system dbus, system dbus client and dbus
chats to xdm and init.
crond dbus chats to logind
systemd_logind needs to create dirs in /run/system/session,
systemd_logind needs to be able to read crond state files (probably does
this when it is not allowed to dbus chat to crond)
crond needs to be able to use systemd_logind fds and it needs to be able
to read inherited systemd_logind_sessions_t pipes.
Obviously systemd-logind is looking for something in /tmp/*/X11-unix but
i cannot determine what and since there is no
xserver_search_xdm_tmp_dirs interface available to call, i decided to
just allow logind to read xdm tmp files for now.
Only "allow systemd_logind_t xdm_tmp_t:dir search;" is actually
confirmed
Dan Walsh [Thu, 14 Jul 2011 21:11:03 +0000 (17:11 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 14 Jul 2011 21:09:35 +0000 (17:09 -0400)]
Add support for virt_lxc, default to unconfined domains for now
Dominick Grift [Thu, 14 Jul 2011 20:05:47 +0000 (22:05 +0200)]
colord and system_dbusd_t want to read inherited gdm color profile files
(xdm_var_lib_t)
colord wants to dbus chat to gdm
Dan Walsh [Thu, 14 Jul 2011 19:28:50 +0000 (15:28 -0400)]
dgrift did a more confined mechanism of allowing gkeyringd to talk to mission_control
Dan Walsh [Thu, 14 Jul 2011 17:40:18 +0000 (13:40 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 14 Jul 2011 18:32:49 +0000 (18:32 +0000)]
Allow setsched for virsh
Dan Walsh [Thu, 14 Jul 2011 17:37:04 +0000 (13:37 -0400)]
Latest useradd lists all devices in /dev and looks at kernel proc_core_t
Dan Walsh [Thu, 14 Jul 2011 17:36:23 +0000 (13:36 -0400)]
Add port definition for ctdb ports
Dan Walsh [Thu, 14 Jul 2011 17:35:14 +0000 (13:35 -0400)]
allow sftpd daemons to read locale file
Miroslav Grepl [Thu, 14 Jul 2011 16:30:57 +0000 (16:30 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 14 Jul 2011 14:21:56 +0000 (10:21 -0400)]
Tighten controls on append, to eliminate open. These interfaces are currently given to (domain)