]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Dan Walsh [Fri, 18 Mar 2011 13:57:12 +0000 (09:57 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 18 Mar 2011 13:55:42 +0000 (09:55 -0400)]
change staff_gkeyringd_t to gkeyrind_staff_t, make gkeyrind_staff_t a domain_user_exemption_target so that login programs can start the domain directly.
Devicekit-power is executing restorecon
qpidd needs to bind to the matahari port
Miroslav Grepl [Fri, 18 Mar 2011 12:59:06 +0000 (12:59 +0000)]
Add support for KDE ksysguardprocesslist_helper
Miroslav Grepl [Fri, 18 Mar 2011 12:00:40 +0000 (12:00 +0000)]
Add support for a new cluster service - foghorn
* the service is treated by rhcs policy module
* note: needs to be backported to RHEL6
Miroslav Grepl [Fri, 18 Mar 2011 09:28:10 +0000 (09:28 +0000)]
gnome-control-center reads colord lib files when monitor is plugged
Dan Walsh [Thu, 17 Mar 2011 20:10:55 +0000 (16:10 -0400)]
Add interface for defining node_types
Miroslav Grepl [Thu, 17 Mar 2011 15:57:29 +0000 (15:57 +0000)]
Fix multiple specification for boot.log
Miroslav Grepl [Thu, 17 Mar 2011 15:39:06 +0000 (15:39 +0000)]
Fix gnome_dbus_chat_gkeyringd interface
Miroslav Grepl [Thu, 17 Mar 2011 15:35:37 +0000 (15:35 +0000)]
Fix typo
Dan Walsh [Thu, 17 Mar 2011 14:09:06 +0000 (10:09 -0400)]
devicekit leaks file descriptors to setfiles_t
Dan Walsh [Wed, 16 Mar 2011 21:25:35 +0000 (17:25 -0400)]
Change all all_nodes to generic_node and all_if to generic_if
Dan Walsh [Wed, 16 Mar 2011 21:10:32 +0000 (17:10 -0400)]
Should not use deprecated interface
Dan Walsh [Wed, 16 Mar 2011 20:57:46 +0000 (16:57 -0400)]
Switch from using all_nodes to generic_node and from all_if to generic_if
Dan Walsh [Wed, 16 Mar 2011 20:55:05 +0000 (16:55 -0400)]
Switch from using all_nodes to generic_node and from all_if to generic_if
Dan Walsh [Wed, 16 Mar 2011 19:12:34 +0000 (15:12 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 16 Mar 2011 20:02:21 +0000 (20:02 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 16 Mar 2011 20:01:48 +0000 (20:01 +0000)]
Add support for xfce4-notifyd
Dan Walsh [Wed, 16 Mar 2011 19:12:11 +0000 (15:12 -0400)]
Fix file context to show several labels as SystemHig
Dan Walsh [Wed, 16 Mar 2011 14:49:37 +0000 (10:49 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 16 Mar 2011 14:49:28 +0000 (10:49 -0400)]
seunshare needs to be able to mounton nfs/cifs/fusefs homedirs
Dan Walsh [Wed, 16 Mar 2011 14:20:55 +0000 (10:20 -0400)]
init does something with the lvm_control_t on shutdown
Miroslav Grepl [Wed, 16 Mar 2011 14:15:04 +0000 (14:15 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 16 Mar 2011 14:14:25 +0000 (14:14 +0000)]
Add etc_runtime_t label for /etc/securetty
Allow iptables to write iptables.save
Dan Walsh [Wed, 16 Mar 2011 13:26:02 +0000 (09:26 -0400)]
Dontaudit mozilla_plugin_t trying to set the attributes on the fonts cache dir
Dan Walsh [Wed, 16 Mar 2011 12:48:52 +0000 (08:48 -0400)]
Fixes to allow xdm_t to start gkeyringd_USERTYPE_t directly
Chris PeBenito [Wed, 16 Mar 2011 12:48:08 +0000 (08:48 -0400)]
Module version bump for xauth patch from Guido Trentalancia.
Chris PeBenito [Wed, 16 Mar 2011 12:47:40 +0000 (08:47 -0400)]
Rearrange lines for xauth change.
Guido Trentalancia [Mon, 28 Feb 2011 19:38:01 +0000 (20:38 +0100)]
xauth label and module request
When starting the X server from the console (using the startx script
that is being shipped with package xinit from X.Org), a few more
permissions are needed from the reference policy.
The label is for a file created by the startx script (from X.Org) and
the module being requested is ipv6 (which can be disabled by other
means).
Chris PeBenito [Wed, 16 Mar 2011 12:37:04 +0000 (08:37 -0400)]
Module version bump for audisp patch from Guido Trentalancia.
Guido Trentalancia [Wed, 16 Feb 2011 06:29:17 +0000 (07:29 +0100)]
patch to allow the audit dispatcher to read the system state
This patch allows the audit dispatcher to read the system
state.
Dan Walsh [Wed, 16 Mar 2011 12:26:45 +0000 (08:26 -0400)]
pcscd needs to create netlink_kobject and read udev files
Chris PeBenito [Wed, 16 Mar 2011 12:20:28 +0000 (08:20 -0400)]
Remove redundant system dbus permissions with cpufreqselector and incorrect xdm dbus permission.
Dan Walsh [Tue, 15 Mar 2011 21:36:33 +0000 (17:36 -0400)]
login.krb needs to be able to write user_tmp_t
Dan Walsh [Tue, 15 Mar 2011 21:33:34 +0000 (17:33 -0400)]
dirsrv needs to bind to port 7390 for dogtag
Dan Walsh [Tue, 15 Mar 2011 19:21:29 +0000 (15:21 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Tue, 15 Mar 2011 19:52:10 +0000 (19:52 +0000)]
Fix a bug in gpg policy
Miroslav Grepl [Tue, 15 Mar 2011 19:46:09 +0000 (19:46 +0000)]
Fix duplicate declaration for matahari port
Miroslav Grepl [Tue, 15 Mar 2011 19:35:56 +0000 (19:35 +0000)]
Remove duplicate TE rules for gpg
Dan Walsh [Tue, 15 Mar 2011 19:21:13 +0000 (15:21 -0400)]
Allowd dirsrv to manage link files in config dir
Dan Walsh [Tue, 15 Mar 2011 15:41:25 +0000 (11:41 -0400)]
dontaudit gpg trying to open audit socket
Dan Walsh [Tue, 15 Mar 2011 15:38:17 +0000 (11:38 -0400)]
Add label for matahari.pid file
Dan Walsh [Tue, 15 Mar 2011 15:35:14 +0000 (11:35 -0400)]
Allow qpid to manage matahari files
Dan Walsh [Tue, 15 Mar 2011 15:15:56 +0000 (11:15 -0400)]
gpg sends audit messages
Dan Walsh [Tue, 15 Mar 2011 14:47:12 +0000 (10:47 -0400)]
Mistake
Dan Walsh [Tue, 15 Mar 2011 14:46:58 +0000 (10:46 -0400)]
Initial policy for matahari
Dan Walsh [Tue, 15 Mar 2011 14:43:20 +0000 (10:43 -0400)]
Add dev_read_watchdog
Need interfaces to kill svirt and signal it
Add port for matahari
Miroslav Grepl [Tue, 15 Mar 2011 15:01:27 +0000 (15:01 +0000)]
Allow clamd to connect clamd port
Miroslav Grepl [Tue, 15 Mar 2011 12:21:42 +0000 (12:21 +0000)]
Add support for kcmdatetimehelper
Add config_usr_t for KDE /usr/share/config files
Allow confined users to read these files which is needed by KDE apps
Dan Walsh [Mon, 14 Mar 2011 20:41:57 +0000 (16:41 -0400)]
Allow shutdown to setrlimit and sys_nice
Dan Walsh [Mon, 14 Mar 2011 19:18:56 +0000 (15:18 -0400)]
Allow systemd_passwd to talk to /dev/log before udev or syslog is running
Dan Walsh [Mon, 14 Mar 2011 19:05:37 +0000 (15:05 -0400)]
Add list_auto_mountpoints to all nfs blocks of apache
Dan Walsh [Mon, 14 Mar 2011 18:58:12 +0000 (14:58 -0400)]
Purge chr_file and blk files on /tmp
Dan Walsh [Mon, 14 Mar 2011 18:43:14 +0000 (14:43 -0400)]
Dontaudit attempts by mock_t to setattr on /proc
Dan Walsh [Mon, 14 Mar 2011 18:07:42 +0000 (14:07 -0400)]
remove qemu_role, it does not work, change staff_t to use qemu_run
Chris PeBenito [Mon, 14 Mar 2011 15:52:19 +0000 (11:52 -0400)]
Allow system dbus to send messages to it's clients.
Miroslav Grepl [Mon, 14 Mar 2011 13:46:24 +0000 (13:46 +0000)]
Fixes for pads
Dan Walsh [Fri, 11 Mar 2011 15:13:23 +0000 (10:13 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Fri, 11 Mar 2011 16:02:44 +0000 (16:02 +0000)]
Fixes for piranha-pulse
* for services to failover
Add interfaces for ftpd
Dan Walsh [Fri, 11 Mar 2011 15:13:11 +0000 (10:13 -0500)]
gpg_t needs to be able to encyprt anything owned by the user
Miroslav Grepl [Fri, 11 Mar 2011 14:04:03 +0000 (14:04 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Fri, 11 Mar 2011 14:03:33 +0000 (14:03 +0000)]
hal reads /etc/mtab which is now link
Miroslav Grepl [Thu, 10 Mar 2011 20:56:59 +0000 (20:56 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 10 Mar 2011 20:00:55 +0000 (15:00 -0500)]
mozilla_plugin_tmp_t needs to be treated as user tmp files
Dan Walsh [Thu, 10 Mar 2011 19:55:45 +0000 (14:55 -0500)]
More dontaudits of writes from readahead
Dan Walsh [Thu, 10 Mar 2011 17:39:22 +0000 (12:39 -0500)]
Dontaudit readahead_t file_type:dir write, to cover up kernel bug
Dan Walsh [Thu, 10 Mar 2011 15:33:09 +0000 (10:33 -0500)]
systemd_tmpfiles needs to relabel faillog directory as well as the file
Dan Walsh [Thu, 10 Mar 2011 14:58:12 +0000 (09:58 -0500)]
Allow hostname and consoletype to r/w inherited initrc_tmp_t files handline hostname >> /tmp/myhost
Dan Walsh [Thu, 10 Mar 2011 13:59:18 +0000 (08:59 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 10 Mar 2011 13:59:07 +0000 (08:59 -0500)]
initrc_t needs to be able to create content in directories created by admins
Dan Walsh [Thu, 10 Mar 2011 13:56:46 +0000 (08:56 -0500)]
mozilla_plugin should work with the allow_exec* booleans
sysadm needs getpcap in order to run pscap
Miroslav Grepl [Thu, 10 Mar 2011 12:26:13 +0000 (12:26 +0000)]
Fix typo
Miroslav Grepl [Thu, 10 Mar 2011 01:36:01 +0000 (01:36 +0000)]
Change label for /var/run/faillock
Other fixes which relate wit this change
Dan Walsh [Wed, 9 Mar 2011 21:07:48 +0000 (16:07 -0500)]
Add new dontaudit rules for sysadm_dbusd_t
Dan Walsh [Wed, 9 Mar 2011 20:44:12 +0000 (15:44 -0500)]
dontaudit sandbox domains sandbox_file_t:dir mounton;
This is caused by the fuse file system attempting to be mounted
We need to let tmpreaper apps read/write all MCS/MLS levels
Dan Walsh [Wed, 9 Mar 2011 20:29:07 +0000 (15:29 -0500)]
Add policykit fixes from Tim Waugh
Miroslav Grepl [Wed, 9 Mar 2011 16:47:37 +0000 (16:47 +0000)]
- Fix storage_create_fixed_disk_dev interface
Resolves: #675065
Miroslav Grepl [Wed, 9 Mar 2011 16:07:27 +0000 (16:07 +0000)]
Add label for /dev/hpilo/*
Miroslav Grepl [Wed, 9 Mar 2011 11:50:53 +0000 (11:50 +0000)]
Add label for /var/lib/color dir since colord reads files in this dir
Dan Walsh [Tue, 8 Mar 2011 16:42:54 +0000 (11:42 -0500)]
colord reads/writes generic scsi devices, and connects to ipp_port_t via tcp
Fix system_dbusd_var_run_t to be and init_sock_file
allow systemd_tmpfiles_t to list /var/lib/rpm directory
Dan Walsh [Tue, 8 Mar 2011 16:35:40 +0000 (11:35 -0500)]
ssh_t needs to read cert content in homedir
Chris PeBenito [Tue, 8 Mar 2011 15:35:04 +0000 (10:35 -0500)]
Certwatch reads all certs, from Miroslav Grepl.
Dan Walsh [Tue, 8 Mar 2011 13:50:36 +0000 (08:50 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Tue, 8 Mar 2011 14:16:46 +0000 (14:16 +0000)]
Add ssh_run_keygen() interface
Dan Walsh [Tue, 8 Mar 2011 13:42:07 +0000 (08:42 -0500)]
staff_r should be allowed to transition to qemu_t
Dan Walsh [Tue, 8 Mar 2011 13:38:31 +0000 (08:38 -0500)]
systemd_tmpfiles_t cleans up /var/lib/rpm
Miroslav Grepl [Tue, 8 Mar 2011 13:31:04 +0000 (13:31 +0000)]
Remove duplicate ssh_keygen policy in ssh.te
Miroslav Grepl [Tue, 8 Mar 2011 13:27:36 +0000 (13:27 +0000)]
Allow xdm to stream connect to vdagent
Miroslav Grepl [Tue, 8 Mar 2011 13:01:34 +0000 (13:01 +0000)]
Fix duplicate declaration for /dev/mqueue
Miroslav Grepl [Tue, 8 Mar 2011 12:46:53 +0000 (12:46 +0000)]
Another merge fix
Miroslav Grepl [Tue, 8 Mar 2011 12:42:11 +0000 (12:42 +0000)]
Merge fix
Miroslav Grepl [Tue, 8 Mar 2011 12:33:46 +0000 (12:33 +0000)]
Remove duplicate declaration caused by merge
Miroslav Grepl [Tue, 8 Mar 2011 12:03:39 +0000 (12:03 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy; branch 'master' of http://oss.tresys.com/git/refpolicy
Conflicts:
policy/modules/admin/alsa.te
policy/modules/apps/cpufreqselector.if
policy/modules/kernel/devices.fc
policy/modules/kernel/devices.if
policy/modules/services/dbus.te
policy/modules/services/xserver.if
policy/modules/services/xserver.te
policy/modules/system/init.fc
Miroslav Grepl [Tue, 8 Mar 2011 01:18:35 +0000 (01:18 +0000)]
Fix declaration of init_sock_file_type attribute
Miroslav Grepl [Tue, 8 Mar 2011 01:09:48 +0000 (01:09 +0000)]
Fix gnome_stream_connect_gkeyringd interface which causes an issue during build
Miroslav Grepl [Tue, 8 Mar 2011 01:02:10 +0000 (01:02 +0000)]
Fix typo
Miroslav Grepl [Tue, 8 Mar 2011 00:56:02 +0000 (00:56 +0000)]
Allow telepathy_idle_t to connect gatekeeper port
Miroslav Grepl [Tue, 8 Mar 2011 00:52:07 +0000 (00:52 +0000)]
Add port defition for ssdp port
Allow telepathy to connect to ssdp port
Fix a bug in plymouth
Dan Walsh [Mon, 7 Mar 2011 21:46:05 +0000 (16:46 -0500)]
add policy for /bin/systemd-notify
Dan Walsh [Mon, 7 Mar 2011 21:08:04 +0000 (16:08 -0500)]
Mount command requires users read mount_var_run_t
colord needs to read konject_uevent_socket
User domains connect to the gkeyring socket
Dan Walsh [Mon, 7 Mar 2011 20:47:16 +0000 (15:47 -0500)]
system_dbusd_t needs setrlimit
mount tries to read the state of the process transitioning to it