]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
14 years agocolord tries to read files off noxattr file systems
Dan Walsh [Tue, 26 Apr 2011 15:02:42 +0000 (11:02 -0400)] 
colord tries to read files off noxattr file systems

14 years agoHave xdm_t create .Xauthority files with the correct label
Dan Walsh [Tue, 26 Apr 2011 15:02:21 +0000 (11:02 -0400)] 
Have xdm_t create .Xauthority files with the correct label

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 26 Apr 2011 14:00:45 +0000 (10:00 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoMozilla_plugin_t needs to be able to read nsplugin content, needs to use stream socke...
Dan Walsh [Tue, 26 Apr 2011 14:00:28 +0000 (10:00 -0400)] 
Mozilla_plugin_t needs to be able to read nsplugin content, needs to use stream sockets leaked from transition domains, Needs to be able to append to .xsession-errors

14 years agocolord seems to be searching homedirs
Dan Walsh [Tue, 26 Apr 2011 14:00:11 +0000 (10:00 -0400)] 
colord seems to be searching homedirs

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Tue, 26 Apr 2011 09:29:16 +0000 (09:29 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAdd gnome-shell as a window manager, and allow window manager to exec usr_tmp_t
Dan Walsh [Mon, 25 Apr 2011 20:05:12 +0000 (16:05 -0400)] 
Add gnome-shell as a window manager, and allow window manager to exec usr_tmp_t

14 years agonew xm_exec_t label for /usr/sbin/xl
Dan Walsh [Mon, 25 Apr 2011 14:52:14 +0000 (10:52 -0400)] 
new xm_exec_t label for /usr/sbin/xl

14 years agoallow udev to transition to gpsd_t if a gps mouse is plugged in
Dan Walsh [Mon, 25 Apr 2011 14:44:20 +0000 (10:44 -0400)] 
allow udev to transition to gpsd_t if a gps mouse is plugged in

14 years agoallow mailman to use inherited fifo_file from postfix
Dan Walsh [Mon, 25 Apr 2011 14:40:43 +0000 (10:40 -0400)] 
allow mailman to use inherited fifo_file from postfix

14 years agoAllow systemd_passwd_agent_t to stream connect to init and send signull to lvm_t
Dan Walsh [Mon, 25 Apr 2011 14:36:56 +0000 (10:36 -0400)] 
Allow systemd_passwd_agent_t to stream connect to init and send signull to lvm_t

14 years agoAdd nvidiactl named transition
Dan Walsh [Mon, 25 Apr 2011 13:43:23 +0000 (09:43 -0400)] 
Add nvidiactl named transition

14 years agoAdd support for firebird port
Dan Walsh [Mon, 25 Apr 2011 13:23:51 +0000 (09:23 -0400)] 
Add support for firebird port
Allow init scripts to create /etc content with the correct labels.

14 years agoAllow sshd_t to getcap
Dan Walsh [Mon, 25 Apr 2011 13:08:54 +0000 (09:08 -0400)] 
Allow sshd_t to getcap

14 years agoAllow sshd_t to getcap
Dan Walsh [Mon, 25 Apr 2011 13:07:49 +0000 (09:07 -0400)] 
Allow sshd_t to getcap

14 years agoAllow sshd_t to getcap
Dan Walsh [Mon, 25 Apr 2011 13:06:06 +0000 (09:06 -0400)] 
Allow sshd_t to getcap

14 years agoMore typo fixes for kerberos.if
Miroslav Grepl [Sat, 23 Apr 2011 00:28:53 +0000 (00:28 +0000)] 
More typo fixes for kerberos.if

14 years agoUse the proper interface in sasl policy
Miroslav Grepl [Sat, 23 Apr 2011 00:08:48 +0000 (00:08 +0000)] 
Use the proper interface in sasl policy

14 years agoFix typo in kerberos.if
Miroslav Grepl [Fri, 22 Apr 2011 23:53:10 +0000 (23:53 +0000)] 
Fix typo in kerberos.if

14 years agoFix typo
Miroslav Grepl [Fri, 22 Apr 2011 22:59:35 +0000 (22:59 +0000)] 
Fix typo

14 years agoFix xserver_user_x_domain_template() interface
Miroslav Grepl [Fri, 22 Apr 2011 16:32:43 +0000 (16:32 +0000)] 
Fix xserver_user_x_domain_template() interface

14 years agoFix duplicate declaration
Miroslav Grepl [Fri, 22 Apr 2011 16:27:00 +0000 (16:27 +0000)] 
Fix duplicate declaration

14 years agoAllow sshd_t getcap
Miroslav Grepl [Fri, 22 Apr 2011 15:39:11 +0000 (15:39 +0000)] 
Allow sshd_t getcap

14 years agokadmind wants to setsched
Dan Walsh [Fri, 22 Apr 2011 11:37:27 +0000 (07:37 -0400)] 
kadmind wants to setsched

14 years agoAdd filetrans in homedir for kerberos, ssh, virt, xserver
Dan Walsh [Thu, 21 Apr 2011 21:53:40 +0000 (17:53 -0400)] 
Add filetrans in homedir for kerberos, ssh, virt, xserver

14 years agoAdd named filetrans for mta content, remove unconfined_sendmail_t
Dan Walsh [Thu, 21 Apr 2011 21:07:35 +0000 (17:07 -0400)] 
Add named filetrans for mta content, remove unconfined_sendmail_t

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 21 Apr 2011 20:40:41 +0000 (16:40 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoseunshare needs to read /dev/urandom
Dan Walsh [Thu, 21 Apr 2011 20:39:33 +0000 (16:39 -0400)] 
seunshare needs to read /dev/urandom
sandbox openoffice throws an AVC about setatt on lib_t file, need a dontaudit
sysadmin needs to be able to create properly labeled apache files in homedir

14 years agoUdev does not actually read or write any devices. SELinux just thinks
Dominick Grift [Thu, 21 Apr 2011 18:48:08 +0000 (20:48 +0200)] 
Udev does not actually read or write any devices. SELinux just thinks
so, but udev does not actually need to open many of these. By removing
the permissions for udev to open many character and block device nodes
we may improve security.

Signed-off-by: Dominick Grift <domg472@gmail.com>
14 years agoFinal update for aide policy
Dan Walsh [Thu, 21 Apr 2011 13:59:37 +0000 (09:59 -0400)] 
Final update for aide policy

14 years agoNeeds to be able to write to its log file
Dan Walsh [Thu, 21 Apr 2011 13:20:32 +0000 (09:20 -0400)] 
Needs to be able to write to its log file

14 years agoAide policy does not handle mls mode well
Dan Walsh [Thu, 21 Apr 2011 12:49:08 +0000 (08:49 -0400)] 
Aide policy does not handle mls mode well
networkmanager needs to be able to write to /etc/NetworkManager/system-connections
staff.te needs sorting

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 21 Apr 2011 12:12:24 +0000 (08:12 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow user_t and staff_t access to generic scsi to handle locally plugged in scanners
Dan Walsh [Thu, 21 Apr 2011 12:12:10 +0000 (08:12 -0400)] 
Allow user_t and staff_t access to generic scsi to handle locally plugged in scanners

14 years agoFix abrt_domtrans_retrace_worker() interface
Miroslav Grepl [Thu, 21 Apr 2011 12:10:09 +0000 (12:10 +0000)] 
Fix abrt_domtrans_retrace_worker() interface

14 years agoFix typo
Miroslav Grepl [Thu, 21 Apr 2011 12:04:55 +0000 (12:04 +0000)] 
Fix typo

14 years agoAdd filename param in for files_etc_filetrans
Dan Walsh [Wed, 20 Apr 2011 20:47:24 +0000 (16:47 -0400)] 
Add filename param in for files_etc_filetrans

14 years agoAllow telepath_msn_t to read /proc/PARENT/cmdline
Dan Walsh [Wed, 20 Apr 2011 18:44:32 +0000 (14:44 -0400)] 
Allow telepath_msn_t to read /proc/PARENT/cmdline

14 years agoftpd needs kill capability
Dan Walsh [Wed, 20 Apr 2011 15:27:49 +0000 (11:27 -0400)] 
ftpd needs kill capability

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 20 Apr 2011 13:42:21 +0000 (09:42 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoFix typo in files_setattr_lock_dirs
Miroslav Grepl [Wed, 20 Apr 2011 15:38:25 +0000 (15:38 +0000)] 
Fix typo in files_setattr_lock_dirs

14 years agoAdd support for ABRT retrace server
Miroslav Grepl [Wed, 20 Apr 2011 15:37:17 +0000 (15:37 +0000)] 
Add support for ABRT retrace server

14 years agoForward porting some fixes from F15
Dan Walsh [Wed, 20 Apr 2011 13:42:07 +0000 (09:42 -0400)] 
Forward porting some fixes from F15

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 20 Apr 2011 13:14:10 +0000 (09:14 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow $1_sudo_t to read default SELinux context
Miroslav Grepl [Wed, 20 Apr 2011 14:11:17 +0000 (14:11 +0000)] 
Allow $1_sudo_t to read default SELinux context

14 years agoAdd label for tgtd sock file in /var/run/
Miroslav Grepl [Wed, 20 Apr 2011 13:33:55 +0000 (13:33 +0000)] 
Add label for tgtd sock file in /var/run/

14 years agoAdd apache_exec_rotatelogs interface
Miroslav Grepl [Wed, 20 Apr 2011 13:14:24 +0000 (13:14 +0000)] 
Add apache_exec_rotatelogs interface
Allow tgtd to create sock file in /var/run

14 years agogkeyring needs to be able to manage nfs homedirs
Dan Walsh [Wed, 20 Apr 2011 13:13:58 +0000 (09:13 -0400)] 
gkeyring needs to be able to manage nfs homedirs

14 years agotrying to transition to if running sudoedit
Dan Walsh [Tue, 19 Apr 2011 16:45:04 +0000 (12:45 -0400)] 
trying to transition to  if running sudoedit

14 years agoAllow power management to shutdown the system
Dan Walsh [Tue, 19 Apr 2011 16:35:37 +0000 (12:35 -0400)] 
Allow power management to shutdown the system

14 years agosudo uses tmp_t files for using sudoedit
Dan Walsh [Tue, 19 Apr 2011 15:52:32 +0000 (11:52 -0400)] 
sudo uses tmp_t files for using sudoedit

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 19 Apr 2011 15:38:54 +0000 (11:38 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAdd transition rules
Dan Walsh [Tue, 19 Apr 2011 15:38:46 +0000 (11:38 -0400)] 
Add transition rules

14 years agodirsrv needs to be able to setattr on var_lock_t
Dan Walsh [Tue, 19 Apr 2011 14:11:35 +0000 (10:11 -0400)] 
dirsrv needs to be able to setattr on var_lock_t

14 years agoAllow syslog to read the process state
Miroslav Grepl [Tue, 19 Apr 2011 12:38:46 +0000 (12:38 +0000)] 
Allow syslog to read  the process state

14 years agoFix ring buffer rules capability2 usage.
Chris PeBenito [Mon, 18 Apr 2011 17:06:21 +0000 (13:06 -0400)] 
Fix ring buffer rules capability2 usage.

14 years agoallow all zaraha domains to signal themselves, server writes to /tmp
Dan Walsh [Mon, 18 Apr 2011 15:58:23 +0000 (11:58 -0400)] 
allow all zaraha domains to signal themselves, server writes to /tmp

14 years agoallow all zaraha domains to signal themselves, server writes to /tmp
Dan Walsh [Mon, 18 Apr 2011 15:53:53 +0000 (11:53 -0400)] 
allow all zaraha domains to signal themselves, server writes to /tmp

14 years agoMerge branch 'master' of http://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 18 Apr 2011 13:40:22 +0000 (09:40 -0400)] 
Merge branch 'master' of http://git.fedorahosted.org/git/selinux-policy

14 years agoAdd label for /usr/lib/chromium-browser/chrome
Miroslav Grepl [Mon, 18 Apr 2011 10:27:16 +0000 (10:27 +0000)] 
Add label for /usr/lib/chromium-browser/chrome
Allow sandbox_web type to manage nsplugin rw files

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Fri, 15 Apr 2011 15:06:58 +0000 (15:06 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoChangelog and module version bump for postgresql selabel_lookup update from KaiGai...
Chris PeBenito [Fri, 15 Apr 2011 14:25:10 +0000 (10:25 -0400)] 
Changelog and module version bump for postgresql selabel_lookup update from KaiGai Kohei.

14 years agoallow postgresql_t to read selabel files
Kohei Kaigai [Fri, 15 Apr 2011 08:40:56 +0000 (09:40 +0100)] 
allow postgresql_t to read selabel files

The attached patch allows postgresql_t domain to read selabel definition files
(such as /etc/selinux/targeted/contexts/sepgsql_contexts).

The upcoming version (v9.1) uses selabel_lookup(3) to assign initial security context
of database objects, we need to allow this reference.

Thanks,
--
NEC Europe Ltd, SAP Global Competence Center
KaiGai Kohei <kohei.kaigai@eu.nec.com>

14 years agoMerge branch 'master' of http://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 15 Apr 2011 13:23:59 +0000 (09:23 -0400)] 
Merge branch 'master' of http://git.fedorahosted.org/git/selinux-policy

14 years agoDontaudit sandbox domains trying to mounton sandbox_file_t, this is caused by fuse...
Dan Walsh [Fri, 15 Apr 2011 12:58:02 +0000 (08:58 -0400)] 
Dontaudit sandbox domains trying to mounton sandbox_file_t, this is caused by fuse mounts

14 years agoAllow initrc_t domain to manage abrt pid files
Miroslav Grepl [Fri, 15 Apr 2011 13:29:45 +0000 (13:29 +0000)] 
Allow initrc_t domain to manage abrt pid files

14 years agoMerge branch 'master' of http://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 15 Apr 2011 12:41:32 +0000 (08:41 -0400)] 
Merge branch 'master' of http://git.fedorahosted.org/git/selinux-policy

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Fri, 15 Apr 2011 09:49:42 +0000 (09:49 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAdd support for AEOLUS project
Miroslav Grepl [Fri, 15 Apr 2011 09:48:59 +0000 (09:48 +0000)] 
Add support for AEOLUS project

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Fri, 15 Apr 2011 08:22:31 +0000 (08:22 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoVirt_admin should be allowed to manage images and processes
Dan Walsh [Thu, 14 Apr 2011 20:59:52 +0000 (16:59 -0400)] 
Virt_admin should be allowed to manage images and processes

14 years agoMerge branch 'master' of http://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 14 Apr 2011 15:45:09 +0000 (11:45 -0400)] 
Merge branch 'master' of http://git.fedorahosted.org/git/selinux-policy

14 years agoPull in some changes from Fedora policy system layer.
Chris PeBenito [Thu, 14 Apr 2011 15:36:56 +0000 (11:36 -0400)] 
Pull in some changes from Fedora policy system layer.

14 years agoRearrange and whitespace fix filesystem.fc.
Chris PeBenito [Thu, 14 Apr 2011 14:17:18 +0000 (10:17 -0400)] 
Rearrange and whitespace fix filesystem.fc.

14 years agoPull in additional kernel layer Fedora policy changes.
Chris PeBenito [Thu, 14 Apr 2011 14:05:56 +0000 (10:05 -0400)] 
Pull in additional kernel layer Fedora policy changes.

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 14 Apr 2011 13:46:33 +0000 (09:46 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow plymountd to send signals to init
Dan Walsh [Thu, 14 Apr 2011 13:45:53 +0000 (09:45 -0400)] 
Allow plymountd to send signals to init
Add label for /var/tmp/HTTP_23

14 years agoChange labeling of fping6
Dan Walsh [Thu, 14 Apr 2011 13:39:05 +0000 (09:39 -0400)] 
Change labeling of fping6

14 years agoFix kerberos_manage_host_rcache interface
Miroslav Grepl [Wed, 13 Apr 2011 21:10:26 +0000 (21:10 +0000)] 
Fix kerberos_manage_host_rcache interface

14 years agoAdd files_rw_generic_tmp_dir interface
Miroslav Grepl [Wed, 13 Apr 2011 21:09:47 +0000 (21:09 +0000)] 
Add files_rw_generic_tmp_dir interface

14 years agoMerge branch 'master' of http://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 13 Apr 2011 21:04:24 +0000 (17:04 -0400)] 
Merge branch 'master' of http://git.fedorahosted.org/git/selinux-policy

Conflicts:
policy/modules/services/kerberos.if

14 years agoEvery app that used to exec init is now execing systemdctl
Dan Walsh [Wed, 13 Apr 2011 18:35:56 +0000 (14:35 -0400)] 
Every app that used to exec init is now execing systemdctl

14 years agoxdm_t needs getsession for switch user
Dan Walsh [Wed, 13 Apr 2011 15:14:02 +0000 (11:14 -0400)] 
xdm_t needs getsession for switch user

14 years agoMerge branch 'master' of http://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 13 Apr 2011 15:13:26 +0000 (11:13 -0400)] 
Merge branch 'master' of http://git.fedorahosted.org/git/selinux-policy

14 years agoFixes for F15
Dan Walsh [Wed, 13 Apr 2011 15:13:08 +0000 (11:13 -0400)] 
Fixes for F15

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 13 Apr 2011 15:11:59 +0000 (11:11 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow squid to manage krb5_host_rcache_t files
Dan Walsh [Wed, 13 Apr 2011 15:00:16 +0000 (11:00 -0400)] 
Allow squid to manage krb5_host_rcache_t files

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 13 Apr 2011 10:18:06 +0000 (10:18 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow foghorn to connect to agentx port
Miroslav Grepl [Tue, 12 Apr 2011 18:47:22 +0000 (18:47 +0000)] 
Allow foghorn to connect to agentx port

14 years agoFixes for colord policy
Miroslav Grepl [Tue, 12 Apr 2011 18:22:41 +0000 (18:22 +0000)] 
Fixes for colord policy

14 years agoInstall leaves some files around that xdm generates avc's
Dan Walsh [Tue, 12 Apr 2011 17:30:14 +0000 (13:30 -0400)] 
Install leaves some files around that xdm generates avc's

14 years agoconsolekit executes systemctl
Dan Walsh [Tue, 12 Apr 2011 17:15:11 +0000 (13:15 -0400)] 
consolekit executes systemctl

14 years agofiletrans policy
Dan Walsh [Tue, 12 Apr 2011 15:00:36 +0000 (11:00 -0400)] 
filetrans policy

14 years agoUpdated with latest names
Dan Walsh [Mon, 11 Apr 2011 21:08:42 +0000 (17:08 -0400)] 
Updated with latest names

14 years agoMerge
Dan Walsh [Mon, 11 Apr 2011 20:17:14 +0000 (16:17 -0400)] 
Merge

14 years agoMerge branch 'master' of http://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 11 Apr 2011 20:16:28 +0000 (16:16 -0400)] 
Merge branch 'master' of http://git.fedorahosted.org/git/selinux-policy

Conflicts:
policy/modules/kernel/devices.if
policy/modules/kernel/files.if

14 years agoCreate file named transition rules
Dan Walsh [Mon, 11 Apr 2011 20:14:33 +0000 (16:14 -0400)] 
Create file named transition rules

14 years agoRemove F16 change
Dan Walsh [Mon, 11 Apr 2011 16:21:15 +0000 (12:21 -0400)] 
Remove F16 change

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 11 Apr 2011 16:20:10 +0000 (12:20 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoNeed to allow apps that use locks to read /var/lock if it is a symlink
Dan Walsh [Mon, 11 Apr 2011 16:19:56 +0000 (12:19 -0400)] 
Need to allow apps that use locks to read /var/lock if it is a symlink