]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Dan Walsh [Mon, 7 Mar 2011 17:04:20 +0000 (12:04 -0500)]
Add colord and allow user_t and staff_t to dbus chat with it
Chris PeBenito [Mon, 7 Mar 2011 15:47:09 +0000 (10:47 -0500)]
Pull in devices changes from Fedora.
Dan Walsh [Mon, 7 Mar 2011 15:45:46 +0000 (10:45 -0500)]
Move to allow systemd to create sock_files in random locations
Dan Walsh [Mon, 7 Mar 2011 15:18:43 +0000 (10:18 -0500)]
systemd is creating sockets in avahi_var_run and system_dbusd_var_run
Miroslav Grepl [Fri, 4 Mar 2011 14:34:37 +0000 (14:34 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Chris PeBenito [Fri, 4 Mar 2011 14:33:56 +0000 (09:33 -0500)]
Add list dir perms to consolekit_read_pids().
Miroslav Grepl [Fri, 4 Mar 2011 14:33:54 +0000 (14:33 +0000)]
Add lvm_exec_t label for kpartx
Allow mozilla_plugin_t to connect to mmcc port
Fix udev_run interface
Chris PeBenito [Fri, 4 Mar 2011 13:59:27 +0000 (08:59 -0500)]
Remove unnecessary etc_runtime_t labeling.
Dan Walsh [Thu, 3 Mar 2011 20:55:43 +0000 (15:55 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 3 Mar 2011 20:55:17 +0000 (15:55 -0500)]
Dontaudit reading the mail_spool_t link from sandbox -X
Miroslav Grepl [Thu, 3 Mar 2011 19:40:17 +0000 (19:40 +0000)]
Additional fixes
Miroslav Grepl [Thu, 3 Mar 2011 19:08:21 +0000 (19:08 +0000)]
Try to make rpm module independent
Miroslav Grepl [Thu, 3 Mar 2011 18:55:35 +0000 (18:55 +0000)]
Try to make lvm module independent
Miroslav Grepl [Thu, 3 Mar 2011 18:51:12 +0000 (18:51 +0000)]
More fixes to make some modules independent
Miroslav Grepl [Thu, 3 Mar 2011 18:30:36 +0000 (18:30 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 3 Mar 2011 18:09:23 +0000 (18:09 +0000)]
Fix a typo
Miroslav Grepl [Thu, 3 Mar 2011 18:06:07 +0000 (18:06 +0000)]
Make consoletype policy module independent
Miroslav Grepl [Thu, 3 Mar 2011 17:34:22 +0000 (17:34 +0000)]
Fix a typo
Miroslav Grepl [Thu, 3 Mar 2011 17:27:59 +0000 (17:27 +0000)]
Try to make cron module independent
Dan Walsh [Thu, 3 Mar 2011 17:25:23 +0000 (12:25 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 3 Mar 2011 17:25:06 +0000 (12:25 -0500)]
Update to make new seunshare/sandbox work
Miroslav Grepl [Thu, 3 Mar 2011 16:58:13 +0000 (16:58 +0000)]
Make cron policy module independent
Miroslav Grepl [Thu, 3 Mar 2011 16:41:30 +0000 (16:41 +0000)]
Fix related to fstools policy
Fixes for dirsrv-admin policy
Miroslav Grepl [Thu, 3 Mar 2011 16:19:45 +0000 (16:19 +0000)]
Fix for gkeyringd_domain
Miroslav Grepl [Thu, 3 Mar 2011 15:25:26 +0000 (15:25 +0000)]
Fix which allows removing of squid policy module
Miroslav Grepl [Thu, 3 Mar 2011 15:14:26 +0000 (15:14 +0000)]
Fix for fpt policy to allow remove postgresql module
Miroslav Grepl [Thu, 3 Mar 2011 15:02:41 +0000 (15:02 +0000)]
Allow removing remotelogin policy module
Miroslav Grepl [Thu, 3 Mar 2011 14:54:51 +0000 (14:54 +0000)]
Fix modemmanager policy to allow remove NM policy module
Chris PeBenito [Thu, 3 Mar 2011 14:53:41 +0000 (09:53 -0500)]
Module version bump for xserver patch from Sven Vermeulen.
Miroslav Grepl [Thu, 3 Mar 2011 14:33:06 +0000 (14:33 +0000)]
Allow removing of nscd policy module
Sven Vermeulen [Tue, 22 Feb 2011 20:30:39 +0000 (21:30 +0100)]
Without allow siginh, we get a huge timeout wait period (15 seconds)
Allow xserver_restricted_role domains to call/start Xorg (using startx), fixes
15-second lag/timeout (needs siginh permission as provided by
xserver_domtrans).
Apparently, the 15-second lag (or some other behavior) was already detected
in the past, giving rise to the SIGINH permission in the xserver_domtrans()
interface.
However, domains that are given the xserver_(restricted_)role do not call
the xserver_domtrans but rather the "standard" domtrans_pattern.
The new patch suggests to use xserver_domtrans in the
xserver_restricted_role, which automatically includes the siginh permission
then.
Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
Miroslav Grepl [Thu, 3 Mar 2011 14:06:10 +0000 (14:06 +0000)]
Fixes which allow removing of modutils policy module
Miroslav Grepl [Thu, 3 Mar 2011 13:11:43 +0000 (13:11 +0000)]
Fixes for kdumpgui and amavis policy
Miroslav Grepl [Thu, 3 Mar 2011 13:04:50 +0000 (13:04 +0000)]
Fixes which allow removing of iptables policy module
Miroslav Grepl [Thu, 3 Mar 2011 12:59:15 +0000 (12:59 +0000)]
Fixes which allows removing of hostname policy module
Miroslav Grepl [Thu, 3 Mar 2011 12:52:28 +0000 (12:52 +0000)]
Fix allowing to remove consolekit policy module
Miroslav Grepl [Thu, 3 Mar 2011 11:47:15 +0000 (11:47 +0000)]
Fix allowing to remove clock policy module
Miroslav Grepl [Thu, 3 Mar 2011 11:31:07 +0000 (11:31 +0000)]
Fix allowing to remove bootloader policy module
Dan Walsh [Wed, 2 Mar 2011 21:51:39 +0000 (16:51 -0500)]
allow virt_domains to use inherited noxattrs file systems
Dan Walsh [Wed, 2 Mar 2011 21:46:56 +0000 (16:46 -0500)]
fix interface
Dan Walsh [Wed, 2 Mar 2011 21:36:32 +0000 (16:36 -0500)]
Allow svirt to use inherited file descriptors from libvirt
Dan Walsh [Wed, 2 Mar 2011 20:18:25 +0000 (15:18 -0500)]
Dont allow svirt_t to send kill signals
Dan Walsh [Wed, 2 Mar 2011 20:09:37 +0000 (15:09 -0500)]
Cleanup policy to allow less modules in base
Dan Walsh [Wed, 2 Mar 2011 18:37:31 +0000 (13:37 -0500)]
Cleanup to allow minimal files in base policy
Dan Walsh [Tue, 1 Mar 2011 20:52:34 +0000 (15:52 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 1 Mar 2011 20:52:19 +0000 (15:52 -0500)]
Make calls from domain optional so I cam move init and seutil to modules
Miroslav Grepl [Tue, 1 Mar 2011 15:58:32 +0000 (15:58 +0000)]
Add udev_run() interface and allow sysadm_t to run udev in udev_t domain
Miroslav Grepl [Tue, 1 Mar 2011 15:17:27 +0000 (15:17 +0000)]
Other fix for gnome_stream_connect_gkeyringd interface
Miroslav Grepl [Tue, 1 Mar 2011 15:13:03 +0000 (15:13 +0000)]
Fix gnome_stream_connect_gkeyringd inteface
Chris PeBenito [Tue, 1 Mar 2011 13:40:55 +0000 (08:40 -0500)]
Alsa update from Miroslav Grepl
* alsa creates tmp files
* add alsa_run() interface
* fix interface calling for alsa config files
Dan Walsh [Mon, 28 Feb 2011 21:48:23 +0000 (16:48 -0500)]
gpg_t needs to talk to gnome-keyring
Dan Walsh [Mon, 28 Feb 2011 19:59:48 +0000 (14:59 -0500)]
nscd wants to read /usr/tmp->/var/tmp to generate randomziation in unixchkpwd
Dan Walsh [Mon, 28 Feb 2011 19:52:23 +0000 (14:52 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 28 Feb 2011 19:52:10 +0000 (14:52 -0500)]
enforce MCS labeling on nodes
Miroslav Grepl [Mon, 28 Feb 2011 18:03:25 +0000 (18:03 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Mon, 28 Feb 2011 18:03:01 +0000 (18:03 +0000)]
Allow arpwatch to read meminfo
Dan Walsh [Mon, 28 Feb 2011 16:53:33 +0000 (11:53 -0500)]
Allow gnomeclock to send itself signals.
Dan Walsh [Mon, 28 Feb 2011 15:41:34 +0000 (10:41 -0500)]
Add label for /root/bin to be bin_t, allow admins to write content in this dirctory. Maybe we should allow sysadm_t to execute admin_home_t?
init relabels /dev/.udev files on boot
Dan Walsh [Mon, 28 Feb 2011 15:13:32 +0000 (10:13 -0500)]
gkeyringd has to transition back to staff_t when it runs commands in bin_t or shell_exec_t
Dan Walsh [Mon, 28 Feb 2011 15:00:10 +0000 (10:00 -0500)]
nautilus checks access on /media directory before mounting usb sticks, dontaudit access_check on mnt_t
Chris PeBenito [Mon, 28 Feb 2011 14:35:02 +0000 (09:35 -0500)]
Module version bump for sysnetwork interface from Guido Trentalancia.
Chris PeBenito [Mon, 28 Feb 2011 14:33:29 +0000 (09:33 -0500)]
Whitespace fixes in sysnetwork.
Guido Trentalancia [Wed, 16 Feb 2011 06:33:46 +0000 (07:33 +0100)]
patch to add a missing interface in the sysnetwork module
This patch adds a new interface to the sysnetwork module so
that the DHCP client state directories can be searched.
Chris PeBenito [Mon, 28 Feb 2011 14:30:47 +0000 (09:30 -0500)]
Module version bump for init upstart fc patch from Guido Trentalancia.
Guido Trentalancia [Wed, 16 Feb 2011 06:28:33 +0000 (07:28 +0100)]
patch to add a file context for /sbin/upstart
This patch adds a file context for /sbin/upstart.
Chris PeBenito [Mon, 28 Feb 2011 14:22:55 +0000 (09:22 -0500)]
Module version bump for authlogin patch from Guido Trentalancia.
Chris PeBenito [Mon, 28 Feb 2011 14:22:26 +0000 (09:22 -0500)]
Whitespace fixes in authlogin.
Guido Trentalancia [Wed, 16 Feb 2011 06:27:51 +0000 (07:27 +0100)]
patch to add needed permissions to the authlogin module
This patch adds some needed permissions to the chkpwd_t domain
in policy/modules/system/authlogin.te.
Chris PeBenito [Mon, 28 Feb 2011 14:10:40 +0000 (09:10 -0500)]
Module version bump for smartmon read usr files from Guido Trentalancia.
Chris PeBenito [Mon, 28 Feb 2011 14:10:08 +0000 (09:10 -0500)]
Rearrange line in smartmon.
Guido Trentalancia [Wed, 16 Feb 2011 06:24:34 +0000 (07:24 +0100)]
patch to allow smartmon to read usr files
This patch adds a permission to the smartmon module so
that it can read usr files.
Guido Trentalancia [Wed, 16 Feb 2011 06:23:49 +0000 (07:23 +0100)]
patch to fix a comment in the setroubleshoot module
This patch clarifies a comment in the description of one of the
setroubleshoot interfaces.
Miroslav Grepl [Mon, 28 Feb 2011 11:13:32 +0000 (11:13 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 25 Feb 2011 21:24:42 +0000 (16:24 -0500)]
dnsmasq can run as a dbus service, needs acquire service
mysql_admin should be allowed to connect to mysql service
Miroslav Grepl [Fri, 25 Feb 2011 17:47:12 +0000 (17:47 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Fri, 25 Feb 2011 17:12:53 +0000 (17:12 +0000)]
Fix typo in certmonger policy
Dan Walsh [Fri, 25 Feb 2011 16:14:43 +0000 (11:14 -0500)]
virt creates monitor sockets in the users home dir
Dan Walsh [Fri, 25 Feb 2011 15:50:20 +0000 (10:50 -0500)]
Cron needs to be able to run shutdown
dontaudit read access to fixed disk by the admins
Dan Walsh [Fri, 25 Feb 2011 15:35:25 +0000 (10:35 -0500)]
Allow sysadm type people to look at usb devices
Dan Walsh [Fri, 25 Feb 2011 14:50:58 +0000 (09:50 -0500)]
init does a log of unmounting at shutdown time, also sets sched on thekernel
Dan Walsh [Fri, 25 Feb 2011 14:26:56 +0000 (09:26 -0500)]
Looks like confined users need to read abrt_var_cache_t in order to report bugs with abrt
sysadm_t now seems to be launching a session bus
Dan Walsh [Fri, 25 Feb 2011 14:10:15 +0000 (09:10 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Fri, 25 Feb 2011 14:23:33 +0000 (14:23 +0000)]
Other fix for systemd_passwd_agent_dev_template interface
Miroslav Grepl [Fri, 25 Feb 2011 13:59:48 +0000 (13:59 +0000)]
Fixes for systemd_passwd_agent_dev_template device
Miroslav Grepl [Fri, 25 Feb 2011 13:25:03 +0000 (13:25 +0000)]
Add systemd_passwd_agent_dev_template interface and use it for lvm
Miroslav Grepl [Fri, 25 Feb 2011 12:55:41 +0000 (12:55 +0000)]
- Allow amavis sigkill
- Allow winbind to read network state information
- Add ajaxterm ssh client session
Miroslav Grepl [Thu, 24 Feb 2011 22:57:38 +0000 (22:57 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 24 Feb 2011 22:12:53 +0000 (17:12 -0500)]
certmonger wants to read keytab files
puppetmaster does restorecon type functionality
Dan Walsh [Thu, 24 Feb 2011 21:00:01 +0000 (16:00 -0500)]
mta search /var/lib/logcheck; sssd needs to bind to random UDP ports
Dan Walsh [Thu, 24 Feb 2011 19:07:55 +0000 (14:07 -0500)]
Moving to only one file type sandbox_file_t
Dan Walsh [Thu, 24 Feb 2011 18:46:45 +0000 (13:46 -0500)]
Allow systemd to relabel /dev
Miroslav Grepl [Thu, 24 Feb 2011 15:57:22 +0000 (15:57 +0000)]
Add mock_enable_homedirs boolean
Other fixes for mock policy
Miroslav Grepl [Thu, 24 Feb 2011 15:41:37 +0000 (15:41 +0000)]
- Allow systemd-ask-passwd to create unix dgram socket
- Allow puppet master to read usr files
- Fixes for mock policy
Dan Walsh [Wed, 23 Feb 2011 15:32:23 +0000 (10:32 -0500)]
Sudo domains need to be able to signal all users "sysadm_t"
Dan Walsh [Wed, 23 Feb 2011 15:29:22 +0000 (10:29 -0500)]
keyringd daemon sends/recieves dbus messages from user types
Chris PeBenito [Wed, 23 Feb 2011 14:47:29 +0000 (09:47 -0500)]
Module version bump for plymouth getsched perm from Guido Trentalancia.
Guido Trentalancia [Wed, 16 Feb 2011 06:18:18 +0000 (07:18 +0100)]
patch to allow plymouthd getsched permission
This patch adds a self:process getsched permission for plymouthd_t.
Dan Walsh [Tue, 22 Feb 2011 22:04:50 +0000 (17:04 -0500)]
Symantic places a pipe in the /opt directory tree that it expects syslogd to be able to write to
Dan Walsh [Tue, 22 Feb 2011 20:48:19 +0000 (15:48 -0500)]
gnome-keyring-daemon needs nsswitch getpw calls
systemd-tmpfiles reads the network status
Chris PeBenito [Tue, 22 Feb 2011 16:36:15 +0000 (11:36 -0500)]
Module version bump and changelog for cpufreqselector dbus patch from Guido Trentalancia.