]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Chris PeBenito [Thu, 31 Mar 2011 12:28:01 +0000 (08:28 -0400)]
Pull in mcs constraint changes from Fedora.
Dan Walsh [Thu, 31 Mar 2011 12:22:44 +0000 (08:22 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 31 Mar 2011 13:39:18 +0000 (13:39 +0000)]
- Allow abrt fowner capability
Miroslav Grepl [Thu, 31 Mar 2011 13:13:18 +0000 (13:13 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 31 Mar 2011 12:22:01 +0000 (08:22 -0400)]
Allow ssh_t to search /root for /root/.ssh
Dan Walsh [Wed, 30 Mar 2011 21:34:32 +0000 (17:34 -0400)]
dontaudit read of user_tmp_t from load_policy, this happens when a user executes semanage -i << _EOF ... _EOF
Dan Walsh [Wed, 30 Mar 2011 19:30:24 +0000 (15:30 -0400)]
Since /var/lock is moving to /run/lock. We need to allow all interfaces for lock files to search var_run_t
Dan Walsh [Tue, 29 Mar 2011 20:35:22 +0000 (16:35 -0400)]
Dontaudit listing of /dev for run_init
Miroslav Grepl [Tue, 29 Mar 2011 20:34:19 +0000 (20:34 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 29 Mar 2011 18:13:31 +0000 (14:13 -0400)]
Add file labelfor MathKernel
Dontaudit sandbox listing any mountpoint
Dan Walsh [Tue, 29 Mar 2011 17:51:40 +0000 (13:51 -0400)]
Add label for /dev/dlm*
Allowe asterisk to connect to pktcable ports.
Miroslav Grepl [Tue, 29 Mar 2011 16:27:23 +0000 (16:27 +0000)]
Remove "Make Makefile/Rules.modular run sepolgen-ifgen during build to check if files for bugs for now" change for now
Dan Walsh [Tue, 29 Mar 2011 15:55:03 +0000 (11:55 -0400)]
Allow systemd_tmpfiles_t to manage sandbox data
Dan Walsh [Tue, 29 Mar 2011 15:50:23 +0000 (11:50 -0400)]
More /run directories labels
Dan Walsh [Tue, 29 Mar 2011 14:47:38 +0000 (10:47 -0400)]
rlogind sends kill signal to chkpwd_t
Chris PeBenito [Tue, 29 Mar 2011 14:33:43 +0000 (10:33 -0400)]
Start pulling in kernel layer pieces from Fedora.
Dan Walsh [Tue, 29 Mar 2011 13:53:37 +0000 (09:53 -0400)]
systemd is now mounting on /var/lock
Miroslav Grepl [Tue, 29 Mar 2011 08:28:25 +0000 (08:28 +0000)]
Remove permissive $1_gkeyringd_t declaration from gnome.if since it fails on install
Miroslav Grepl [Mon, 28 Mar 2011 16:39:26 +0000 (16:39 +0000)]
Fix typo in gnome_role_gkeyringd() interface
Miroslav Grepl [Mon, 28 Mar 2011 15:48:15 +0000 (15:48 +0000)]
Add named_bind_http_port
Chris PeBenito [Mon, 28 Mar 2011 15:45:46 +0000 (11:45 -0400)]
Update access vectors.
Miroslav Grepl [Fri, 25 Mar 2011 13:53:16 +0000 (13:53 +0000)]
Allow $1_sudo_t and $1_su_t open access to user terminals
Allow initrc_t to use generic terminals
Miroslav Grepl [Fri, 25 Mar 2011 13:42:11 +0000 (13:42 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 25 Mar 2011 11:51:24 +0000 (07:51 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 25 Mar 2011 11:49:26 +0000 (07:49 -0400)]
Make Makefile/Rules.modular run sepolgen-ifgen during build to check if files for bugs
systemd is going to be useing /run and /run/lock for early bootup files.
Fix some comments in rlogin.if
Miroslav Grepl [Fri, 25 Mar 2011 09:52:31 +0000 (09:52 +0000)]
Fix typo in audit_spool_t definition
Miroslav Grepl [Fri, 25 Mar 2011 08:30:02 +0000 (08:30 +0000)]
Fix kerberos_read_home_content interface
Miroslav Grepl [Fri, 25 Mar 2011 08:03:41 +0000 (08:03 +0000)]
Turn off kdebacklighthelper policy for now since therse is a bug
Miroslav Grepl [Fri, 25 Mar 2011 08:02:57 +0000 (08:02 +0000)]
Add policy for KDE backlighthelper
Dan Walsh [Thu, 24 Mar 2011 19:30:42 +0000 (15:30 -0400)]
sssd needs to read ~/.k5login in nfs, cifs or fusefs file systems
Dan Walsh [Thu, 24 Mar 2011 19:26:43 +0000 (15:26 -0400)]
sssd wants to read .k5login file in users homedir
Dan Walsh [Thu, 24 Mar 2011 17:55:15 +0000 (13:55 -0400)]
setroubleshoot reads executables to see if they have TEXTREL
Dan Walsh [Thu, 24 Mar 2011 17:25:40 +0000 (13:25 -0400)]
Add /var/spool/audit support for new version of audit
Miroslav Grepl [Thu, 24 Mar 2011 00:05:23 +0000 (00:05 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Conflicts:
policy/modules/roles/unprivuser.te
policy/modules/roles/xguest.te
Miroslav Grepl [Thu, 24 Mar 2011 00:01:48 +0000 (00:01 +0000)]
Add permissive $1_gkeyringd_t declaration
Miroslav Grepl [Wed, 23 Mar 2011 23:59:47 +0000 (23:59 +0000)]
It does not work
* Revert "Make keyring policy work with user_t and xguest_t"
This reverts commit
f397dd48162a42ccef7eec5705e5efbf1a69eafb .
Miroslav Grepl [Wed, 23 Mar 2011 23:50:58 +0000 (23:50 +0000)]
systemd read mtab which is now a link
Miroslav Grepl [Wed, 23 Mar 2011 23:15:46 +0000 (23:15 +0000)]
Remove gnome_role_gkeyringd for other confined users. It does not work.
Miroslav Grepl [Wed, 23 Mar 2011 22:41:10 +0000 (22:41 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 23 Mar 2011 22:39:29 +0000 (22:39 +0000)]
Remove kerberos_connect_524() interface calling
Miroslav Grepl [Wed, 23 Mar 2011 22:27:52 +0000 (22:27 +0000)]
Fix obj_perm_sets.spt relating to policy-termis.patch
Miroslav Grepl [Wed, 23 Mar 2011 22:09:53 +0000 (22:09 +0000)]
Fix duplicate declaration
Miroslav Grepl [Wed, 23 Mar 2011 21:48:58 +0000 (21:48 +0000)]
Remove some unconfined domains
Miroslav Grepl [Wed, 23 Mar 2011 21:39:17 +0000 (21:39 +0000)]
Remove permissive domains
Miroslav Grepl [Wed, 23 Mar 2011 21:35:36 +0000 (21:35 +0000)]
Add policy-term.patch from Dan
Dan Walsh [Wed, 23 Mar 2011 19:39:01 +0000 (15:39 -0400)]
Combine kerberos_master_port_t and kerberos_port_t
Dan Walsh [Wed, 23 Mar 2011 19:37:30 +0000 (15:37 -0400)]
Combind kerberos_master_port_t into kerberos_port_t
Chris PeBenito [Wed, 23 Mar 2011 17:58:28 +0000 (13:58 -0400)]
Module version bump for mplayer updates from Sven Vermeulen.
Chris PeBenito [Wed, 23 Mar 2011 15:56:22 +0000 (11:56 -0400)]
Move domain_use_interactive_fds() line in mplayer.
Sven Vermeulen [Wed, 9 Mar 2011 21:19:12 +0000 (22:19 +0100)]
Support mplayer as plugin for others
Allow mplayer to behave as a plugin for higher-level (interactive)
applications, such as browser plugins
Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
Sven Vermeulen [Wed, 9 Mar 2011 21:15:01 +0000 (22:15 +0100)]
mplayer support for webcams
In order to work with webcams, mplayer domain needs write access to the
v4l_device_t (updates and reconfiguration of the video device)
Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
Dan Walsh [Wed, 23 Mar 2011 15:50:50 +0000 (11:50 -0400)]
systemd has setup /dev/kmsg as stderr for apps it executes
Dan Walsh [Wed, 23 Mar 2011 15:19:15 +0000 (11:19 -0400)]
Make keyring policy work with user_t and xguest_t
Dan Walsh [Wed, 23 Mar 2011 14:06:47 +0000 (10:06 -0400)]
Need these access so that init can impersonate sockets on unix_dgram_socket
Dan Walsh [Wed, 23 Mar 2011 13:31:49 +0000 (09:31 -0400)]
Add reading of link files to gnome_read_gconf_home_files
Dan Walsh [Wed, 23 Mar 2011 13:09:56 +0000 (09:09 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 23 Mar 2011 13:09:10 +0000 (09:09 -0400)]
telepathy domains need to resolve dns
initrc should be able to handle mcs labels if unconfined
Chris PeBenito [Wed, 23 Mar 2011 12:56:14 +0000 (08:56 -0400)]
Module version bump for postfix fc updates from Sven Vermeulen.
Chris PeBenito [Wed, 23 Mar 2011 12:49:52 +0000 (08:49 -0400)]
Whitespace fix in postfix.fc.
Sven Vermeulen [Wed, 9 Mar 2011 21:22:03 +0000 (22:22 +0100)]
Update postfix file contexts to support amd64 setup
Updates on the file contexts, supporting AMD64 multilib environment
( Patch 10 has been revoked a-la-last-minute, needs further testing )
Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
Sven Vermeulen [Wed, 9 Mar 2011 21:24:15 +0000 (22:24 +0100)]
postalias command should stay bin_t
postalias should stay bin_t, is manually executed (no role executes
postfix_master_exec_t as it is only to be launched through init scripts).
The postalias command is used to regenerate the aliases.db file from the
mail aliases and as such is a system administrative activity. However, by
default, no role has execute rights on any postfix_master_exec_t domains as
the domain is apparently meant only to be started from the run_init_t
domain.
Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
Miroslav Grepl [Wed, 23 Mar 2011 10:36:37 +0000 (10:36 +0000)]
systemd and fsck.ext4 read mtab which is now a link
Miroslav Grepl [Tue, 22 Mar 2011 23:26:40 +0000 (23:26 +0000)]
Fix typo
Miroslav Grepl [Tue, 22 Mar 2011 22:30:10 +0000 (22:30 +0000)]
Allow syslogd setsched
Miroslav Grepl [Tue, 22 Mar 2011 21:52:05 +0000 (21:52 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Tue, 22 Mar 2011 21:51:33 +0000 (21:51 +0000)]
Add syslogd_exec_t label for systemd-kmsg-syslogd
Dan Walsh [Tue, 22 Mar 2011 20:40:02 +0000 (16:40 -0400)]
ipsec_mgmt_t wants to cause ipsec_t to dump core, needs to be allowed
Chris PeBenito [Tue, 22 Mar 2011 13:31:21 +0000 (09:31 -0400)]
Fix db_blob typo in sepgsql_contexts.
Chris PeBenito [Tue, 22 Mar 2011 13:08:19 +0000 (09:08 -0400)]
Module version bump for sasl fc from Sven Vermeulen.
Sven Vermeulen [Wed, 9 Mar 2011 21:27:52 +0000 (22:27 +0100)]
Cyrus sasl /var/lib/sasl2 location support
Cyrus sasl by default looks in /var/lib/sasl2 for its PID file, socket
creation and lock files.
Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
Chris PeBenito [Tue, 22 Mar 2011 12:50:43 +0000 (08:50 -0400)]
Module version bump and changelog for courier from Sven Vermeulen.
Chris PeBenito [Tue, 22 Mar 2011 12:47:47 +0000 (08:47 -0400)]
Move Gentoo-specific couriertcpd fc line.
Sven Vermeulen [Wed, 9 Mar 2011 21:09:01 +0000 (22:09 +0100)]
Fix file contexts, add Gentoo-specific (?) location
Update on the file contexts for courier-imap. Also fixes a few context
directives which didn't update the directory itself.
Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
Sven Vermeulen [Wed, 9 Mar 2011 21:06:21 +0000 (22:06 +0100)]
Allow authdaemon to create unix_stream_sockets
The authdaemon needs the create_stream_socket_perms privs in order to be able to start up.
Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
Chris PeBenito [Tue, 22 Mar 2011 12:33:47 +0000 (08:33 -0400)]
Module version bump for alsactl location patch from Sven Vermeulen.
Chris PeBenito [Tue, 22 Mar 2011 12:32:06 +0000 (08:32 -0400)]
Move /usr/sbin/alsactl fc line.
Sven Vermeulen [Wed, 9 Mar 2011 21:05:24 +0000 (22:05 +0100)]
Support /usr/sbin/alsactl location too (fex. Gentoo, Slackware, Arch)
The alsactl binary is often installed in /usr/sbin instead of /sbin (not a
necessity to start up the system). Used in distributions such as Gentoo,
Slackware and Arch.
Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
Dan Walsh [Tue, 22 Mar 2011 11:52:57 +0000 (07:52 -0400)]
Allow rythmbox and other apps to share music over daap port
Miroslav Grepl [Tue, 22 Mar 2011 10:59:08 +0000 (10:59 +0000)]
Fix permissive declaration for staff_gkeyringd_t
Miroslav Grepl [Tue, 22 Mar 2011 10:32:04 +0000 (10:32 +0000)]
Fix typo in gnome.if
Miroslav Grepl [Tue, 22 Mar 2011 10:29:20 +0000 (10:29 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 21 Mar 2011 22:41:44 +0000 (18:41 -0400)]
Allow qemu and pulseaudio to work together
Dan Walsh [Mon, 21 Mar 2011 22:34:24 +0000 (18:34 -0400)]
Allow qemu_t to manage virt_home_t, and connect to the xserver
Dan Walsh [Mon, 21 Mar 2011 22:18:40 +0000 (18:18 -0400)]
Allow httpd to create socket file in /tmp
Dan Walsh [Mon, 21 Mar 2011 22:04:26 +0000 (18:04 -0400)]
Allow tuned to write to sysfs
Dan Walsh [Mon, 21 Mar 2011 21:49:04 +0000 (17:49 -0400)]
Allow systemd_tmpfiles to send kernel messages
Dan Walsh [Mon, 21 Mar 2011 21:06:56 +0000 (17:06 -0400)]
Add a dev_filetrans to readahead_manage_pid_files so any callers can create directories and files in /dev with this label.
Dan Walsh [Mon, 21 Mar 2011 20:56:22 +0000 (16:56 -0400)]
mrtg needs to be able to create /var/lock/mrtg
Dan Walsh [Mon, 21 Mar 2011 20:55:05 +0000 (16:55 -0400)]
mrtg needs to be able to create /var/lock/mrtg
Chris PeBenito [Mon, 21 Mar 2011 15:23:26 +0000 (11:23 -0400)]
Aisexec patch from Miroslav Grepl.
* openais needs ipc_owner and read/write user SysV sempaphores/shared memory
Chris PeBenito [Mon, 21 Mar 2011 15:14:34 +0000 (11:14 -0400)]
Whitespace fixes in userdomain.
Chris PeBenito [Mon, 21 Mar 2011 14:22:10 +0000 (10:22 -0400)]
Amavis patch for connecting to nslcd from Miroslav Grepl.
* needs to talk to nslcd
* needs sigkill
* executes shell
Chris PeBenito [Mon, 21 Mar 2011 13:48:05 +0000 (09:48 -0400)]
Sysnetwork patch from Miroslav Grepl.
* adds support for "ip xfrm" command which allows assign a context
Chris PeBenito [Mon, 21 Mar 2011 13:42:12 +0000 (09:42 -0400)]
Shorewall patch from Miroslav Grepl.
Miroslav Grepl [Mon, 21 Mar 2011 09:05:44 +0000 (09:05 +0000)]
Fix typo
Miroslav Grepl [Mon, 21 Mar 2011 09:01:21 +0000 (09:01 +0000)]
Add label for /usr/share/shorewall/getparams
Miroslav Grepl [Sun, 20 Mar 2011 21:18:05 +0000 (21:18 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Sun, 20 Mar 2011 21:17:24 +0000 (21:17 +0000)]
xdm needs to read KDE config files
Dan Walsh [Fri, 18 Mar 2011 16:16:20 +0000 (12:16 -0400)]
Smolt needs to look at urand and read hwdata
Dan Walsh [Fri, 18 Mar 2011 14:20:45 +0000 (10:20 -0400)]
google talk plugin in nsplugin is listing the contents of /dev, adding dontaudit for tis