]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
14 years agoAdd colord and allow user_t and staff_t to dbus chat with it
Dan Walsh [Mon, 7 Mar 2011 17:04:20 +0000 (12:04 -0500)] 
Add colord and allow user_t and staff_t to dbus chat with it

14 years agoPull in devices changes from Fedora.
Chris PeBenito [Mon, 7 Mar 2011 15:47:09 +0000 (10:47 -0500)] 
Pull in devices changes from Fedora.

14 years agoMove to allow systemd to create sock_files in random locations
Dan Walsh [Mon, 7 Mar 2011 15:45:46 +0000 (10:45 -0500)] 
Move to allow systemd to create sock_files in random locations

14 years agosystemd is creating sockets in avahi_var_run and system_dbusd_var_run
Dan Walsh [Mon, 7 Mar 2011 15:18:43 +0000 (10:18 -0500)] 
systemd is creating sockets in avahi_var_run and system_dbusd_var_run

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Fri, 4 Mar 2011 14:34:37 +0000 (14:34 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAdd list dir perms to consolekit_read_pids().
Chris PeBenito [Fri, 4 Mar 2011 14:33:56 +0000 (09:33 -0500)] 
Add list dir perms to consolekit_read_pids().

14 years agoAdd lvm_exec_t label for kpartx
Miroslav Grepl [Fri, 4 Mar 2011 14:33:54 +0000 (14:33 +0000)] 
Add lvm_exec_t label for kpartx
Allow mozilla_plugin_t to connect to mmcc port
Fix udev_run interface

14 years agoRemove unnecessary etc_runtime_t labeling.
Chris PeBenito [Fri, 4 Mar 2011 13:59:27 +0000 (08:59 -0500)] 
Remove unnecessary etc_runtime_t labeling.

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 3 Mar 2011 20:55:43 +0000 (15:55 -0500)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoDontaudit reading the mail_spool_t link from sandbox -X
Dan Walsh [Thu, 3 Mar 2011 20:55:17 +0000 (15:55 -0500)] 
Dontaudit reading the mail_spool_t link from sandbox -X

14 years agoAdditional fixes
Miroslav Grepl [Thu, 3 Mar 2011 19:40:17 +0000 (19:40 +0000)] 
Additional fixes

14 years agoTry to make rpm module independent
Miroslav Grepl [Thu, 3 Mar 2011 19:08:21 +0000 (19:08 +0000)] 
Try to make rpm module independent

14 years agoTry to make lvm module independent
Miroslav Grepl [Thu, 3 Mar 2011 18:55:35 +0000 (18:55 +0000)] 
Try to make lvm module independent

14 years agoMore fixes to make some modules independent
Miroslav Grepl [Thu, 3 Mar 2011 18:51:12 +0000 (18:51 +0000)] 
More fixes to make some modules independent

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 3 Mar 2011 18:30:36 +0000 (18:30 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoFix a typo
Miroslav Grepl [Thu, 3 Mar 2011 18:09:23 +0000 (18:09 +0000)] 
Fix a typo

14 years agoMake consoletype policy module independent
Miroslav Grepl [Thu, 3 Mar 2011 18:06:07 +0000 (18:06 +0000)] 
Make consoletype policy module independent

14 years agoFix a typo
Miroslav Grepl [Thu, 3 Mar 2011 17:34:22 +0000 (17:34 +0000)] 
Fix a typo

14 years agoTry to make cron module independent
Miroslav Grepl [Thu, 3 Mar 2011 17:27:59 +0000 (17:27 +0000)] 
Try to make cron module independent

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 3 Mar 2011 17:25:23 +0000 (12:25 -0500)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoUpdate to make new seunshare/sandbox work
Dan Walsh [Thu, 3 Mar 2011 17:25:06 +0000 (12:25 -0500)] 
Update to make new seunshare/sandbox work

14 years agoMake cron policy module independent
Miroslav Grepl [Thu, 3 Mar 2011 16:58:13 +0000 (16:58 +0000)] 
Make cron policy module independent

14 years agoFix related to fstools policy
Miroslav Grepl [Thu, 3 Mar 2011 16:41:30 +0000 (16:41 +0000)] 
Fix related to fstools policy
Fixes for dirsrv-admin policy

14 years agoFix for gkeyringd_domain
Miroslav Grepl [Thu, 3 Mar 2011 16:19:45 +0000 (16:19 +0000)] 
Fix for gkeyringd_domain

14 years agoFix which allows removing of squid policy module
Miroslav Grepl [Thu, 3 Mar 2011 15:25:26 +0000 (15:25 +0000)] 
Fix which allows removing of squid policy module

14 years agoFix for fpt policy to allow remove postgresql module
Miroslav Grepl [Thu, 3 Mar 2011 15:14:26 +0000 (15:14 +0000)] 
Fix for fpt policy to allow remove postgresql module

14 years agoAllow removing remotelogin policy module
Miroslav Grepl [Thu, 3 Mar 2011 15:02:41 +0000 (15:02 +0000)] 
Allow removing remotelogin policy module

14 years agoFix modemmanager policy to allow remove NM policy module
Miroslav Grepl [Thu, 3 Mar 2011 14:54:51 +0000 (14:54 +0000)] 
Fix modemmanager policy to allow remove NM policy module

14 years agoModule version bump for xserver patch from Sven Vermeulen.
Chris PeBenito [Thu, 3 Mar 2011 14:53:41 +0000 (09:53 -0500)] 
Module version bump for xserver patch from Sven Vermeulen.

14 years agoAllow removing of nscd policy module
Miroslav Grepl [Thu, 3 Mar 2011 14:33:06 +0000 (14:33 +0000)] 
Allow removing of nscd policy module

14 years agoWithout allow siginh, we get a huge timeout wait period (15 seconds)
Sven Vermeulen [Tue, 22 Feb 2011 20:30:39 +0000 (21:30 +0100)] 
Without allow siginh, we get a huge timeout wait period (15 seconds)

Allow xserver_restricted_role domains to call/start Xorg (using startx), fixes
15-second lag/timeout (needs siginh permission as provided by
xserver_domtrans).

Apparently, the 15-second lag (or some other behavior) was already detected
in the past, giving rise to the SIGINH permission in the xserver_domtrans()
interface.

However, domains that are given the xserver_(restricted_)role do not call
the xserver_domtrans but rather the "standard" domtrans_pattern.

The new patch suggests to use xserver_domtrans in the
xserver_restricted_role, which automatically includes the siginh permission
then.

Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
14 years agoFixes which allow removing of modutils policy module
Miroslav Grepl [Thu, 3 Mar 2011 14:06:10 +0000 (14:06 +0000)] 
Fixes which allow removing of modutils policy module

14 years agoFixes for kdumpgui and amavis policy
Miroslav Grepl [Thu, 3 Mar 2011 13:11:43 +0000 (13:11 +0000)] 
Fixes for kdumpgui and amavis policy

14 years agoFixes which allow removing of iptables policy module
Miroslav Grepl [Thu, 3 Mar 2011 13:04:50 +0000 (13:04 +0000)] 
Fixes which allow removing of iptables policy module

14 years agoFixes which allows removing of hostname policy module
Miroslav Grepl [Thu, 3 Mar 2011 12:59:15 +0000 (12:59 +0000)] 
Fixes which allows removing of hostname policy module

14 years agoFix allowing to remove consolekit policy module
Miroslav Grepl [Thu, 3 Mar 2011 12:52:28 +0000 (12:52 +0000)] 
Fix allowing to remove consolekit policy module

14 years agoFix allowing to remove clock policy module
Miroslav Grepl [Thu, 3 Mar 2011 11:47:15 +0000 (11:47 +0000)] 
Fix allowing to remove clock policy module

14 years agoFix allowing to remove bootloader policy module
Miroslav Grepl [Thu, 3 Mar 2011 11:31:07 +0000 (11:31 +0000)] 
Fix allowing to remove bootloader policy module

14 years agoallow virt_domains to use inherited noxattrs file systems
Dan Walsh [Wed, 2 Mar 2011 21:51:39 +0000 (16:51 -0500)] 
allow virt_domains to use inherited noxattrs file systems

14 years agofix interface
Dan Walsh [Wed, 2 Mar 2011 21:46:56 +0000 (16:46 -0500)] 
fix interface

14 years agoAllow svirt to use inherited file descriptors from libvirt
Dan Walsh [Wed, 2 Mar 2011 21:36:32 +0000 (16:36 -0500)] 
Allow svirt to use inherited file descriptors from libvirt

14 years agoDont allow svirt_t to send kill signals
Dan Walsh [Wed, 2 Mar 2011 20:18:25 +0000 (15:18 -0500)] 
Dont allow svirt_t to send kill signals

14 years agoCleanup policy to allow less modules in base
Dan Walsh [Wed, 2 Mar 2011 20:09:37 +0000 (15:09 -0500)] 
Cleanup policy to allow less modules in base

14 years agoCleanup to allow minimal files in base policy
Dan Walsh [Wed, 2 Mar 2011 18:37:31 +0000 (13:37 -0500)] 
Cleanup to allow minimal files in base policy

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 1 Mar 2011 20:52:34 +0000 (15:52 -0500)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoMake calls from domain optional so I cam move init and seutil to modules
Dan Walsh [Tue, 1 Mar 2011 20:52:19 +0000 (15:52 -0500)] 
Make calls from domain optional so I cam move init and seutil to modules

14 years agoAdd udev_run() interface and allow sysadm_t to run udev in udev_t domain
Miroslav Grepl [Tue, 1 Mar 2011 15:58:32 +0000 (15:58 +0000)] 
Add udev_run() interface and allow sysadm_t to run udev in udev_t domain

14 years agoOther fix for gnome_stream_connect_gkeyringd interface
Miroslav Grepl [Tue, 1 Mar 2011 15:17:27 +0000 (15:17 +0000)] 
Other fix for gnome_stream_connect_gkeyringd interface

14 years agoFix gnome_stream_connect_gkeyringd inteface
Miroslav Grepl [Tue, 1 Mar 2011 15:13:03 +0000 (15:13 +0000)] 
Fix gnome_stream_connect_gkeyringd inteface

14 years agoAlsa update from Miroslav Grepl
Chris PeBenito [Tue, 1 Mar 2011 13:40:55 +0000 (08:40 -0500)] 
Alsa update from Miroslav Grepl

* alsa creates tmp files
* add alsa_run() interface
* fix interface calling for alsa config files

14 years agogpg_t needs to talk to gnome-keyring
Dan Walsh [Mon, 28 Feb 2011 21:48:23 +0000 (16:48 -0500)] 
gpg_t needs to talk to gnome-keyring

14 years agonscd wants to read /usr/tmp->/var/tmp to generate randomziation in unixchkpwd
Dan Walsh [Mon, 28 Feb 2011 19:59:48 +0000 (14:59 -0500)] 
nscd wants to read /usr/tmp->/var/tmp to generate randomziation in unixchkpwd

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 28 Feb 2011 19:52:23 +0000 (14:52 -0500)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoenforce MCS labeling on nodes
Dan Walsh [Mon, 28 Feb 2011 19:52:10 +0000 (14:52 -0500)] 
enforce MCS labeling on nodes

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Mon, 28 Feb 2011 18:03:25 +0000 (18:03 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoAllow arpwatch to read meminfo
Miroslav Grepl [Mon, 28 Feb 2011 18:03:01 +0000 (18:03 +0000)] 
Allow arpwatch to read meminfo

14 years agoAllow gnomeclock to send itself signals.
Dan Walsh [Mon, 28 Feb 2011 16:53:33 +0000 (11:53 -0500)] 
Allow gnomeclock to send itself signals.

14 years agoAdd label for /root/bin to be bin_t, allow admins to write content in this dirctory...
Dan Walsh [Mon, 28 Feb 2011 15:41:34 +0000 (10:41 -0500)] 
Add label for /root/bin to be bin_t, allow admins to write content in this dirctory.  Maybe we should allow sysadm_t to execute admin_home_t?
init relabels /dev/.udev files on boot

14 years agogkeyringd has to transition back to staff_t when it runs commands in bin_t or shell_e...
Dan Walsh [Mon, 28 Feb 2011 15:13:32 +0000 (10:13 -0500)] 
gkeyringd has to transition back to staff_t when it runs commands in bin_t or shell_exec_t

14 years agonautilus checks access on /media directory before mounting usb sticks, dontaudit...
Dan Walsh [Mon, 28 Feb 2011 15:00:10 +0000 (10:00 -0500)] 
nautilus checks access on /media directory before mounting usb sticks, dontaudit access_check on mnt_t

14 years agoModule version bump for sysnetwork interface from Guido Trentalancia.
Chris PeBenito [Mon, 28 Feb 2011 14:35:02 +0000 (09:35 -0500)] 
Module version bump for sysnetwork interface from Guido Trentalancia.

14 years agoWhitespace fixes in sysnetwork.
Chris PeBenito [Mon, 28 Feb 2011 14:33:29 +0000 (09:33 -0500)] 
Whitespace fixes in sysnetwork.

14 years agopatch to add a missing interface in the sysnetwork module
Guido Trentalancia [Wed, 16 Feb 2011 06:33:46 +0000 (07:33 +0100)] 
patch to add a missing interface in the sysnetwork module

This patch adds a new interface to the sysnetwork module so
that the DHCP client state directories can be searched.

14 years agoModule version bump for init upstart fc patch from Guido Trentalancia.
Chris PeBenito [Mon, 28 Feb 2011 14:30:47 +0000 (09:30 -0500)] 
Module version bump for init upstart fc patch from Guido Trentalancia.

14 years agopatch to add a file context for /sbin/upstart
Guido Trentalancia [Wed, 16 Feb 2011 06:28:33 +0000 (07:28 +0100)] 
patch to add a file context for /sbin/upstart

This patch adds a file context for /sbin/upstart.

14 years agoModule version bump for authlogin patch from Guido Trentalancia.
Chris PeBenito [Mon, 28 Feb 2011 14:22:55 +0000 (09:22 -0500)] 
Module version bump for authlogin patch from Guido Trentalancia.

14 years agoWhitespace fixes in authlogin.
Chris PeBenito [Mon, 28 Feb 2011 14:22:26 +0000 (09:22 -0500)] 
Whitespace fixes in authlogin.

14 years agopatch to add needed permissions to the authlogin module
Guido Trentalancia [Wed, 16 Feb 2011 06:27:51 +0000 (07:27 +0100)] 
patch to add needed permissions to the authlogin module

This patch adds some needed permissions to the chkpwd_t domain
in policy/modules/system/authlogin.te.

14 years agoModule version bump for smartmon read usr files from Guido Trentalancia.
Chris PeBenito [Mon, 28 Feb 2011 14:10:40 +0000 (09:10 -0500)] 
Module version bump for smartmon read usr files from Guido Trentalancia.

14 years agoRearrange line in smartmon.
Chris PeBenito [Mon, 28 Feb 2011 14:10:08 +0000 (09:10 -0500)] 
Rearrange line in smartmon.

14 years agopatch to allow smartmon to read usr files
Guido Trentalancia [Wed, 16 Feb 2011 06:24:34 +0000 (07:24 +0100)] 
patch to allow smartmon to read usr files

This patch adds a permission to the smartmon module so
that it can read usr files.

14 years agopatch to fix a comment in the setroubleshoot module
Guido Trentalancia [Wed, 16 Feb 2011 06:23:49 +0000 (07:23 +0100)] 
patch to fix a comment in the setroubleshoot module

This patch clarifies a comment in the description of one of the
setroubleshoot interfaces.

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Mon, 28 Feb 2011 11:13:32 +0000 (11:13 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agodnsmasq can run as a dbus service, needs acquire service
Dan Walsh [Fri, 25 Feb 2011 21:24:42 +0000 (16:24 -0500)] 
dnsmasq can run as a dbus service, needs acquire service
mysql_admin should  be allowed to connect to mysql service

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Fri, 25 Feb 2011 17:47:12 +0000 (17:47 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoFix typo in certmonger policy
Miroslav Grepl [Fri, 25 Feb 2011 17:12:53 +0000 (17:12 +0000)] 
Fix typo in certmonger policy

14 years agovirt creates monitor sockets in the users home dir
Dan Walsh [Fri, 25 Feb 2011 16:14:43 +0000 (11:14 -0500)] 
virt creates monitor sockets in the users home dir

14 years agoCron needs to be able to run shutdown
Dan Walsh [Fri, 25 Feb 2011 15:50:20 +0000 (10:50 -0500)] 
Cron needs to be able to run shutdown
dontaudit read access to fixed disk by the admins

14 years agoAllow sysadm type people to look at usb devices
Dan Walsh [Fri, 25 Feb 2011 15:35:25 +0000 (10:35 -0500)] 
Allow sysadm type people to look at usb devices

14 years agoinit does a log of unmounting at shutdown time, also sets sched on thekernel
Dan Walsh [Fri, 25 Feb 2011 14:50:58 +0000 (09:50 -0500)] 
init does a log of unmounting at shutdown time, also sets sched on thekernel

14 years agoLooks like confined users need to read abrt_var_cache_t in order to report bugs with...
Dan Walsh [Fri, 25 Feb 2011 14:26:56 +0000 (09:26 -0500)] 
Looks like confined users need to read abrt_var_cache_t in order to report bugs with abrt
sysadm_t now seems to be launching a session bus

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 25 Feb 2011 14:10:15 +0000 (09:10 -0500)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agoOther fix for systemd_passwd_agent_dev_template interface
Miroslav Grepl [Fri, 25 Feb 2011 14:23:33 +0000 (14:23 +0000)] 
Other fix for systemd_passwd_agent_dev_template interface

14 years agoFixes for systemd_passwd_agent_dev_template device
Miroslav Grepl [Fri, 25 Feb 2011 13:59:48 +0000 (13:59 +0000)] 
Fixes for systemd_passwd_agent_dev_template device

14 years agoAdd systemd_passwd_agent_dev_template interface and use it for lvm
Miroslav Grepl [Fri, 25 Feb 2011 13:25:03 +0000 (13:25 +0000)] 
Add systemd_passwd_agent_dev_template interface and use it for lvm

14 years ago- Allow amavis sigkill
Miroslav Grepl [Fri, 25 Feb 2011 12:55:41 +0000 (12:55 +0000)] 
- Allow amavis sigkill
- Allow winbind to read network state information
- Add ajaxterm ssh client session

14 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 24 Feb 2011 22:57:38 +0000 (22:57 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

14 years agocertmonger wants to read keytab files
Dan Walsh [Thu, 24 Feb 2011 22:12:53 +0000 (17:12 -0500)] 
certmonger wants to read keytab files
puppetmaster does restorecon type functionality

14 years agomta search /var/lib/logcheck; sssd needs to bind to random UDP ports
Dan Walsh [Thu, 24 Feb 2011 21:00:01 +0000 (16:00 -0500)] 
mta search /var/lib/logcheck; sssd needs to bind to random UDP ports

14 years agoMoving to only one file type sandbox_file_t
Dan Walsh [Thu, 24 Feb 2011 19:07:55 +0000 (14:07 -0500)] 
Moving to only one file type sandbox_file_t

14 years agoAllow systemd to relabel /dev
Dan Walsh [Thu, 24 Feb 2011 18:46:45 +0000 (13:46 -0500)] 
Allow systemd to relabel /dev

14 years agoAdd mock_enable_homedirs boolean
Miroslav Grepl [Thu, 24 Feb 2011 15:57:22 +0000 (15:57 +0000)] 
Add mock_enable_homedirs boolean
Other fixes for mock policy

14 years ago- Allow systemd-ask-passwd to create unix dgram socket
Miroslav Grepl [Thu, 24 Feb 2011 15:41:37 +0000 (15:41 +0000)] 
- Allow systemd-ask-passwd to create unix dgram socket
- Allow puppet master to read usr files
- Fixes for mock policy

14 years agoSudo domains need to be able to signal all users "sysadm_t"
Dan Walsh [Wed, 23 Feb 2011 15:32:23 +0000 (10:32 -0500)] 
Sudo domains need to be able to signal all users "sysadm_t"

14 years agokeyringd daemon sends/recieves dbus messages from user types
Dan Walsh [Wed, 23 Feb 2011 15:29:22 +0000 (10:29 -0500)] 
keyringd daemon sends/recieves dbus messages from user types

14 years agoModule version bump for plymouth getsched perm from Guido Trentalancia.
Chris PeBenito [Wed, 23 Feb 2011 14:47:29 +0000 (09:47 -0500)] 
Module version bump for plymouth getsched perm from Guido Trentalancia.

14 years agopatch to allow plymouthd getsched permission
Guido Trentalancia [Wed, 16 Feb 2011 06:18:18 +0000 (07:18 +0100)] 
patch to allow plymouthd getsched permission

This patch adds a self:process getsched permission for plymouthd_t.

14 years agoSymantic places a pipe in the /opt directory tree that it expects syslogd to be able...
Dan Walsh [Tue, 22 Feb 2011 22:04:50 +0000 (17:04 -0500)] 
Symantic places a pipe in the /opt directory tree that it expects syslogd to be able to write to

14 years agognome-keyring-daemon needs nsswitch getpw calls
Dan Walsh [Tue, 22 Feb 2011 20:48:19 +0000 (15:48 -0500)] 
gnome-keyring-daemon needs nsswitch getpw calls
systemd-tmpfiles reads the network status

14 years agoModule version bump and changelog for cpufreqselector dbus patch from Guido Trentalancia.
Chris PeBenito [Tue, 22 Feb 2011 16:36:15 +0000 (11:36 -0500)] 
Module version bump and changelog for cpufreqselector dbus patch from Guido Trentalancia.