]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 18 Mar 2011 13:57:12 +0000 (09:57 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agochange staff_gkeyringd_t to gkeyrind_staff_t, make gkeyrind_staff_t a domain_user_ex...
Dan Walsh [Fri, 18 Mar 2011 13:55:42 +0000 (09:55 -0400)] 
change staff_gkeyringd_t to gkeyrind_staff_t, make gkeyrind_staff_t a  domain_user_exemption_target so that login programs can start the domain directly.
Devicekit-power is executing restorecon
qpidd needs to bind to the matahari port

14 years agoAdd support for KDE ksysguardprocesslist_helper
Miroslav Grepl [Fri, 18 Mar 2011 12:59:06 +0000 (12:59 +0000)] 
Add support for KDE ksysguardprocesslist_helper

14 years agoAdd support for a new cluster service - foghorn
Miroslav Grepl [Fri, 18 Mar 2011 12:00:40 +0000 (12:00 +0000)] 
Add support for a new cluster service - foghorn
 * the service is treated by rhcs policy module
 * note: needs to be backported to RHEL6

14 years agognome-control-center reads colord lib files when monitor is plugged
Miroslav Grepl [Fri, 18 Mar 2011 09:28:10 +0000 (09:28 +0000)] 
gnome-control-center reads colord lib files when monitor is plugged

14 years agoAdd interface for defining node_types
Dan Walsh [Thu, 17 Mar 2011 20:10:55 +0000 (16:10 -0400)] 
Add interface for defining node_types

14 years agoFix multiple specification for boot.log
Miroslav Grepl [Thu, 17 Mar 2011 15:57:29 +0000 (15:57 +0000)] 
Fix multiple specification for boot.log

14 years agoFix gnome_dbus_chat_gkeyringd interface
Miroslav Grepl [Thu, 17 Mar 2011 15:39:06 +0000 (15:39 +0000)] 
Fix gnome_dbus_chat_gkeyringd interface

14 years agoFix typo
Miroslav Grepl [Thu, 17 Mar 2011 15:35:37 +0000 (15:35 +0000)] 
Fix typo

14 years agodevicekit leaks file descriptors to setfiles_t
Dan Walsh [Thu, 17 Mar 2011 14:09:06 +0000 (10:09 -0400)] 
devicekit leaks file descriptors to setfiles_t

14 years agoChange all all_nodes to generic_node and all_if to generic_if
Dan Walsh [Wed, 16 Mar 2011 21:25:35 +0000 (17:25 -0400)] 
Change all all_nodes to generic_node and all_if to generic_if

14 years agoShould not use deprecated interface
Dan Walsh [Wed, 16 Mar 2011 21:10:32 +0000 (17:10 -0400)] 
Should not use deprecated interface

14 years agoSwitch from using all_nodes to generic_node and from all_if to generic_if
Dan Walsh [Wed, 16 Mar 2011 20:57:46 +0000 (16:57 -0400)] 
Switch from using all_nodes to generic_node and from all_if to generic_if

14 years agoSwitch from using all_nodes to generic_node and from all_if to generic_if
Dan Walsh [Wed, 16 Mar 2011 20:55:05 +0000 (16:55 -0400)] 
Switch from using all_nodes to generic_node and from all_if to generic_if

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 16 Mar 2011 19:12:34 +0000 (15:12 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 16 Mar 2011 20:02:21 +0000 (20:02 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAdd support for xfce4-notifyd
Miroslav Grepl [Wed, 16 Mar 2011 20:01:48 +0000 (20:01 +0000)] 
Add support for xfce4-notifyd

14 years agoFix file context to show several labels as SystemHig
Dan Walsh [Wed, 16 Mar 2011 19:12:11 +0000 (15:12 -0400)] 
Fix file context to show several labels as SystemHig

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 16 Mar 2011 14:49:37 +0000 (10:49 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoseunshare needs to be able to mounton nfs/cifs/fusefs homedirs
Dan Walsh [Wed, 16 Mar 2011 14:49:28 +0000 (10:49 -0400)] 
seunshare needs to be able to mounton nfs/cifs/fusefs homedirs

14 years agoinit does something with the lvm_control_t on shutdown
Dan Walsh [Wed, 16 Mar 2011 14:20:55 +0000 (10:20 -0400)] 
init does something with the lvm_control_t on shutdown

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 16 Mar 2011 14:15:04 +0000 (14:15 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAdd etc_runtime_t label for /etc/securetty
Miroslav Grepl [Wed, 16 Mar 2011 14:14:25 +0000 (14:14 +0000)] 
Add etc_runtime_t label for /etc/securetty
Allow iptables to write iptables.save

14 years agoDontaudit mozilla_plugin_t trying to set the attributes on the fonts cache dir
Dan Walsh [Wed, 16 Mar 2011 13:26:02 +0000 (09:26 -0400)] 
Dontaudit mozilla_plugin_t trying to set the attributes on the fonts cache dir

14 years agoFixes to allow xdm_t to start gkeyringd_USERTYPE_t directly
Dan Walsh [Wed, 16 Mar 2011 12:48:52 +0000 (08:48 -0400)] 
Fixes to allow xdm_t to start gkeyringd_USERTYPE_t directly

14 years agoModule version bump for xauth patch from Guido Trentalancia.
Chris PeBenito [Wed, 16 Mar 2011 12:48:08 +0000 (08:48 -0400)] 
Module version bump for xauth patch from Guido Trentalancia.

14 years agoRearrange lines for xauth change.
Chris PeBenito [Wed, 16 Mar 2011 12:47:40 +0000 (08:47 -0400)] 
Rearrange lines for xauth change.

14 years agoxauth label and module request
Guido Trentalancia [Mon, 28 Feb 2011 19:38:01 +0000 (20:38 +0100)] 
xauth label and module request

When starting the X server from the console (using the startx script
that is being shipped with package xinit from X.Org), a few more
permissions are needed from the reference policy.

The label is for a file created by the startx script (from X.Org) and
the module being requested is ipv6 (which can be disabled by other
means).

14 years agoModule version bump for audisp patch from Guido Trentalancia.
Chris PeBenito [Wed, 16 Mar 2011 12:37:04 +0000 (08:37 -0400)] 
Module version bump for audisp patch from Guido Trentalancia.

14 years agopatch to allow the audit dispatcher to read the system state
Guido Trentalancia [Wed, 16 Feb 2011 06:29:17 +0000 (07:29 +0100)] 
patch to allow the audit dispatcher to read the system state

This patch allows the audit dispatcher to read the system
state.

14 years agopcscd needs to create netlink_kobject and read udev files
Dan Walsh [Wed, 16 Mar 2011 12:26:45 +0000 (08:26 -0400)] 
pcscd needs to create netlink_kobject and read udev files

14 years agoRemove redundant system dbus permissions with cpufreqselector and incorrect xdm dbus...
Chris PeBenito [Wed, 16 Mar 2011 12:20:28 +0000 (08:20 -0400)] 
Remove redundant system dbus permissions with cpufreqselector and incorrect xdm dbus permission.

14 years agologin.krb needs to be able to write user_tmp_t
Dan Walsh [Tue, 15 Mar 2011 21:36:33 +0000 (17:36 -0400)] 
login.krb needs to be able to write user_tmp_t

14 years agodirsrv needs to bind to port 7390 for dogtag
Dan Walsh [Tue, 15 Mar 2011 21:33:34 +0000 (17:33 -0400)] 
dirsrv needs to bind to port 7390 for dogtag

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 15 Mar 2011 19:21:29 +0000 (15:21 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoFix a bug in gpg policy
Miroslav Grepl [Tue, 15 Mar 2011 19:52:10 +0000 (19:52 +0000)] 
Fix a bug in gpg policy

14 years agoFix duplicate declaration for matahari port
Miroslav Grepl [Tue, 15 Mar 2011 19:46:09 +0000 (19:46 +0000)] 
Fix duplicate declaration for matahari port

14 years agoRemove duplicate TE rules for gpg
Miroslav Grepl [Tue, 15 Mar 2011 19:35:56 +0000 (19:35 +0000)] 
Remove duplicate TE rules for gpg

14 years agoAllowd dirsrv to manage link files in config dir
Dan Walsh [Tue, 15 Mar 2011 19:21:13 +0000 (15:21 -0400)] 
Allowd dirsrv to manage link files in config dir

14 years agodontaudit gpg trying to open audit socket
Dan Walsh [Tue, 15 Mar 2011 15:41:25 +0000 (11:41 -0400)] 
dontaudit gpg trying to open audit socket

14 years agoAdd label for matahari.pid file
Dan Walsh [Tue, 15 Mar 2011 15:38:17 +0000 (11:38 -0400)] 
Add label for matahari.pid file

14 years agoAllow qpid to manage matahari files
Dan Walsh [Tue, 15 Mar 2011 15:35:14 +0000 (11:35 -0400)] 
Allow qpid to manage matahari files

14 years agogpg sends audit messages
Dan Walsh [Tue, 15 Mar 2011 15:15:56 +0000 (11:15 -0400)] 
gpg sends audit messages

14 years agoMistake
Dan Walsh [Tue, 15 Mar 2011 14:47:12 +0000 (10:47 -0400)] 
Mistake

14 years agoInitial policy for matahari
Dan Walsh [Tue, 15 Mar 2011 14:46:58 +0000 (10:46 -0400)] 
Initial policy for matahari

14 years agoAdd dev_read_watchdog
Dan Walsh [Tue, 15 Mar 2011 14:43:20 +0000 (10:43 -0400)] 
Add dev_read_watchdog
Need interfaces to kill svirt and signal it
Add port for matahari

14 years agoAllow clamd to connect clamd port
Miroslav Grepl [Tue, 15 Mar 2011 15:01:27 +0000 (15:01 +0000)] 
Allow clamd to connect clamd port

14 years agoAdd support for kcmdatetimehelper
Miroslav Grepl [Tue, 15 Mar 2011 12:21:42 +0000 (12:21 +0000)] 
Add support for kcmdatetimehelper
Add config_usr_t for KDE /usr/share/config files
Allow confined users to read these files which is needed by KDE apps

14 years agoAllow shutdown to setrlimit and sys_nice
Dan Walsh [Mon, 14 Mar 2011 20:41:57 +0000 (16:41 -0400)] 
Allow shutdown to setrlimit and sys_nice

14 years agoAllow systemd_passwd to talk to /dev/log before udev or syslog is running
Dan Walsh [Mon, 14 Mar 2011 19:18:56 +0000 (15:18 -0400)] 
Allow systemd_passwd to talk to /dev/log before udev or syslog is running

14 years agoAdd list_auto_mountpoints to all nfs blocks of apache
Dan Walsh [Mon, 14 Mar 2011 19:05:37 +0000 (15:05 -0400)] 
Add list_auto_mountpoints to all nfs blocks of apache

14 years agoPurge chr_file and blk files on /tmp
Dan Walsh [Mon, 14 Mar 2011 18:58:12 +0000 (14:58 -0400)] 
Purge chr_file and blk files on /tmp

14 years agoDontaudit attempts by mock_t to setattr on /proc
Dan Walsh [Mon, 14 Mar 2011 18:43:14 +0000 (14:43 -0400)] 
Dontaudit attempts by mock_t to setattr on /proc

14 years agoremove qemu_role, it does not work, change staff_t to use qemu_run
Dan Walsh [Mon, 14 Mar 2011 18:07:42 +0000 (14:07 -0400)] 
remove qemu_role, it does not work, change staff_t to use qemu_run

14 years agoAllow system dbus to send messages to it's clients.
Chris PeBenito [Mon, 14 Mar 2011 15:52:19 +0000 (11:52 -0400)] 
Allow system dbus to send messages to it's clients.

14 years agoFixes for pads
Miroslav Grepl [Mon, 14 Mar 2011 13:46:24 +0000 (13:46 +0000)] 
Fixes for pads

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 11 Mar 2011 15:13:23 +0000 (10:13 -0500)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoFixes for piranha-pulse
Miroslav Grepl [Fri, 11 Mar 2011 16:02:44 +0000 (16:02 +0000)] 
Fixes for piranha-pulse
 * for services to failover
Add interfaces for ftpd

14 years agogpg_t needs to be able to encyprt anything owned by the user
Dan Walsh [Fri, 11 Mar 2011 15:13:11 +0000 (10:13 -0500)] 
gpg_t needs to be able to encyprt anything owned by the user

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Fri, 11 Mar 2011 14:04:03 +0000 (14:04 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agohal reads /etc/mtab which is now link
Miroslav Grepl [Fri, 11 Mar 2011 14:03:33 +0000 (14:03 +0000)] 
hal reads /etc/mtab which is now link

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 10 Mar 2011 20:56:59 +0000 (20:56 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agomozilla_plugin_tmp_t needs to be treated as user tmp files
Dan Walsh [Thu, 10 Mar 2011 20:00:55 +0000 (15:00 -0500)] 
mozilla_plugin_tmp_t needs to be treated as user tmp files

14 years agoMore dontaudits of writes from readahead
Dan Walsh [Thu, 10 Mar 2011 19:55:45 +0000 (14:55 -0500)] 
More dontaudits of writes from readahead

14 years agoDontaudit readahead_t file_type:dir write, to cover up kernel bug
Dan Walsh [Thu, 10 Mar 2011 17:39:22 +0000 (12:39 -0500)] 
Dontaudit readahead_t file_type:dir write, to cover up kernel bug

14 years agosystemd_tmpfiles needs to relabel faillog directory as well as the file
Dan Walsh [Thu, 10 Mar 2011 15:33:09 +0000 (10:33 -0500)] 
systemd_tmpfiles needs to relabel faillog directory as well as the file

14 years agoAllow hostname and consoletype to r/w inherited initrc_tmp_t files handline hostname...
Dan Walsh [Thu, 10 Mar 2011 14:58:12 +0000 (09:58 -0500)] 
Allow hostname and consoletype to r/w inherited initrc_tmp_t files handline hostname >> /tmp/myhost

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 10 Mar 2011 13:59:18 +0000 (08:59 -0500)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoinitrc_t needs to be able to create content in directories created by admins
Dan Walsh [Thu, 10 Mar 2011 13:59:07 +0000 (08:59 -0500)] 
initrc_t needs to be able to create content in directories created by admins

14 years agomozilla_plugin should work with the allow_exec* booleans
Dan Walsh [Thu, 10 Mar 2011 13:56:46 +0000 (08:56 -0500)] 
mozilla_plugin should work with the allow_exec* booleans
sysadm needs getpcap in order to run pscap

14 years agoFix typo
Miroslav Grepl [Thu, 10 Mar 2011 12:26:13 +0000 (12:26 +0000)] 
Fix typo

14 years agoChange label for /var/run/faillock
Miroslav Grepl [Thu, 10 Mar 2011 01:36:01 +0000 (01:36 +0000)] 
Change label for /var/run/faillock
Other fixes which relate wit this change

14 years agoAdd new dontaudit rules for sysadm_dbusd_t
Dan Walsh [Wed, 9 Mar 2011 21:07:48 +0000 (16:07 -0500)] 
Add new dontaudit rules for sysadm_dbusd_t

14 years agodontaudit sandbox domains sandbox_file_t:dir mounton;
Dan Walsh [Wed, 9 Mar 2011 20:44:12 +0000 (15:44 -0500)] 
dontaudit sandbox domains sandbox_file_t:dir mounton;
This is caused by the fuse file system attempting to be mounted

We need to let tmpreaper apps read/write all MCS/MLS levels

14 years agoAdd policykit fixes from Tim Waugh
Dan Walsh [Wed, 9 Mar 2011 20:29:07 +0000 (15:29 -0500)] 
Add policykit fixes from Tim Waugh

14 years ago- Fix storage_create_fixed_disk_dev interface
Miroslav Grepl [Wed, 9 Mar 2011 16:47:37 +0000 (16:47 +0000)] 
- Fix storage_create_fixed_disk_dev interface
Resolves: #675065

14 years agoAdd label for /dev/hpilo/*
Miroslav Grepl [Wed, 9 Mar 2011 16:07:27 +0000 (16:07 +0000)] 
Add label for /dev/hpilo/*

14 years agoAdd label for /var/lib/color dir since colord reads files in this dir
Miroslav Grepl [Wed, 9 Mar 2011 11:50:53 +0000 (11:50 +0000)] 
Add label for /var/lib/color dir since colord reads files in this dir

14 years agocolord reads/writes generic scsi devices, and connects to ipp_port_t via tcp
Dan Walsh [Tue, 8 Mar 2011 16:42:54 +0000 (11:42 -0500)] 
colord reads/writes generic scsi devices, and connects to ipp_port_t via tcp
Fix system_dbusd_var_run_t to be and init_sock_file
allow systemd_tmpfiles_t to list /var/lib/rpm directory

14 years agossh_t needs to read cert content in homedir
Dan Walsh [Tue, 8 Mar 2011 16:35:40 +0000 (11:35 -0500)] 
ssh_t needs to read cert content in homedir

14 years agoCertwatch reads all certs, from Miroslav Grepl.
Chris PeBenito [Tue, 8 Mar 2011 15:35:04 +0000 (10:35 -0500)] 
Certwatch reads all certs, from Miroslav Grepl.

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 8 Mar 2011 13:50:36 +0000 (08:50 -0500)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAdd ssh_run_keygen() interface
Miroslav Grepl [Tue, 8 Mar 2011 14:16:46 +0000 (14:16 +0000)] 
Add ssh_run_keygen() interface

14 years agostaff_r should be allowed to transition to qemu_t
Dan Walsh [Tue, 8 Mar 2011 13:42:07 +0000 (08:42 -0500)] 
staff_r should be allowed to transition to qemu_t

14 years agosystemd_tmpfiles_t cleans up /var/lib/rpm
Dan Walsh [Tue, 8 Mar 2011 13:38:31 +0000 (08:38 -0500)] 
systemd_tmpfiles_t cleans up /var/lib/rpm

14 years agoRemove duplicate ssh_keygen policy in ssh.te
Miroslav Grepl [Tue, 8 Mar 2011 13:31:04 +0000 (13:31 +0000)] 
Remove duplicate ssh_keygen policy in ssh.te

14 years agoAllow xdm to stream connect to vdagent
Miroslav Grepl [Tue, 8 Mar 2011 13:27:36 +0000 (13:27 +0000)] 
Allow xdm to stream connect to vdagent

14 years agoFix duplicate declaration for /dev/mqueue
Miroslav Grepl [Tue, 8 Mar 2011 13:01:34 +0000 (13:01 +0000)] 
Fix duplicate declaration for /dev/mqueue

14 years agoAnother merge fix
Miroslav Grepl [Tue, 8 Mar 2011 12:46:53 +0000 (12:46 +0000)] 
Another merge fix

14 years agoMerge fix
Miroslav Grepl [Tue, 8 Mar 2011 12:42:11 +0000 (12:42 +0000)] 
Merge fix

14 years agoRemove duplicate declaration caused by merge
Miroslav Grepl [Tue, 8 Mar 2011 12:33:46 +0000 (12:33 +0000)] 
Remove duplicate declaration caused by merge

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy; branch 'maste...
Miroslav Grepl [Tue, 8 Mar 2011 12:03:39 +0000 (12:03 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy; branch 'master' of http://oss.tresys.com/git/refpolicy

Conflicts:
policy/modules/admin/alsa.te
policy/modules/apps/cpufreqselector.if
policy/modules/kernel/devices.fc
policy/modules/kernel/devices.if
policy/modules/services/dbus.te
policy/modules/services/xserver.if
policy/modules/services/xserver.te
policy/modules/system/init.fc

14 years agoFix declaration of init_sock_file_type attribute
Miroslav Grepl [Tue, 8 Mar 2011 01:18:35 +0000 (01:18 +0000)] 
Fix declaration of init_sock_file_type attribute

14 years agoFix gnome_stream_connect_gkeyringd interface which causes an issue during build
Miroslav Grepl [Tue, 8 Mar 2011 01:09:48 +0000 (01:09 +0000)] 
Fix gnome_stream_connect_gkeyringd interface which causes an issue during build

14 years agoFix typo
Miroslav Grepl [Tue, 8 Mar 2011 01:02:10 +0000 (01:02 +0000)] 
Fix typo

14 years agoAllow telepathy_idle_t to connect gatekeeper port
Miroslav Grepl [Tue, 8 Mar 2011 00:56:02 +0000 (00:56 +0000)] 
Allow telepathy_idle_t to connect gatekeeper port

14 years agoAdd port defition for ssdp port
Miroslav Grepl [Tue, 8 Mar 2011 00:52:07 +0000 (00:52 +0000)] 
Add port defition for ssdp port
Allow telepathy to connect to ssdp port
Fix a bug in plymouth

14 years agoadd policy for /bin/systemd-notify
Dan Walsh [Mon, 7 Mar 2011 21:46:05 +0000 (16:46 -0500)] 
add policy for /bin/systemd-notify

14 years agoMount command requires users read mount_var_run_t
Dan Walsh [Mon, 7 Mar 2011 21:08:04 +0000 (16:08 -0500)] 
Mount command requires users read mount_var_run_t
colord needs to read konject_uevent_socket
User domains connect to the gkeyring socket

14 years agosystem_dbusd_t needs setrlimit
Dan Walsh [Mon, 7 Mar 2011 20:47:16 +0000 (15:47 -0500)] 
system_dbusd_t needs setrlimit
mount tries to read the state of the process transitioning to it