]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Miroslav Grepl [Tue, 30 Nov 2010 10:29:27 +0000 (10:29 +0000)]
Dontaudit piranha-gui to read and write snmpd libraries files
Dan Walsh [Mon, 29 Nov 2010 20:55:27 +0000 (15:55 -0500)]
Allow chrome sandbox to connect to web ports
allow dovecot to listem on lmtp and sieve ports
Allove ddclient to sesearch sysctl_net_t
Dan Walsh [Mon, 29 Nov 2010 20:31:03 +0000 (15:31 -0500)]
transition back to original domain if you execute the shell
Dan Walsh [Mon, 29 Nov 2010 19:52:40 +0000 (14:52 -0500)]
fixes to allow /var/run and /var/lock as tmpfs
Dan Walsh [Mon, 29 Nov 2010 19:42:27 +0000 (14:42 -0500)]
Update to fedora package from miroslav,
Add permissions for mount on mls machines
Dan Walsh [Mon, 29 Nov 2010 17:12:59 +0000 (12:12 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Conflicts:
policy/modules/kernel/kernel.if
policy/modules/services/portreserve.if
policy/modules/services/smokeping.te
policy/modules/system/miscfiles.fc
policy/modules/system/mount.te
policy/support/obj_perm_sets.spt
Dan Walsh [Mon, 29 Nov 2010 17:11:00 +0000 (12:11 -0500)]
mount needs to write_proc_to_clearance
Miroslav Grepl [Mon, 29 Nov 2010 09:52:53 +0000 (09:52 +0000)]
Allow jabberd domains to read system state information in /proc
Dominick Grift [Sun, 28 Nov 2010 16:49:12 +0000 (17:49 +0100)]
In Fedora 14 it is confirmed that cgconfig needs to be able to unmount cgroup_t:filesystem when you "service cgconfig stop".
Signed-off-by: Dominick Grift <domg472@gmail.com>
Miroslav Grepl [Thu, 25 Nov 2010 12:01:14 +0000 (12:01 +0000)]
Remove duplicate declaration
Miroslav Grepl [Thu, 25 Nov 2010 11:45:53 +0000 (11:45 +0000)]
Cleanup merge
Miroslav Grepl [Thu, 25 Nov 2010 09:55:36 +0000 (09:55 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 25 Nov 2010 09:51:31 +0000 (09:51 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy; branch 'master' of http://oss.tresys.com/git/refpolicy
Conflicts:
policy/modules/kernel/kernel.if
policy/modules/services/portreserve.if
policy/modules/services/smokeping.te
policy/modules/services/ulogd.te
policy/modules/services/uucp.te
policy/modules/system/miscfiles.fc
policy/modules/system/mount.te
policy/support/obj_perm_sets.spt
Dan Walsh [Wed, 24 Nov 2010 20:15:21 +0000 (15:15 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy; branch 'master' of http://oss.tresys.com/git/refpolicy
Conflicts:
policy/modules/kernel/kernel.if
policy/modules/services/portreserve.if
policy/modules/services/smokeping.te
policy/modules/services/ulogd.te
policy/modules/services/uucp.te
policy/modules/system/miscfiles.fc
policy/modules/system/mount.te
policy/support/obj_perm_sets.spt
Dan Walsh [Wed, 24 Nov 2010 18:43:30 +0000 (13:43 -0500)]
Add attribute to be able to select sandbox types
Dan Walsh [Wed, 24 Nov 2010 18:42:31 +0000 (13:42 -0500)]
Add attribute to be able to select sandbox types
Dan Walsh [Wed, 24 Nov 2010 17:09:46 +0000 (12:09 -0500)]
Cleanup for sandbox
Dan Walsh [Wed, 24 Nov 2010 17:09:21 +0000 (12:09 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 24 Nov 2010 17:09:09 +0000 (12:09 -0500)]
Cleanup for sandbox, allow httpd to read var_t symlinks
Miroslav Grepl [Wed, 24 Nov 2010 17:00:34 +0000 (17:00 +0000)]
Add virtio_device_t type
Fixes for vdagent policy
Dan Walsh [Wed, 24 Nov 2010 13:19:57 +0000 (08:19 -0500)]
Make unlabeled_t have the ability to be disabled
Dan Walsh [Tue, 23 Nov 2010 17:01:18 +0000 (12:01 -0500)]
Cleanup boolean desription
Dan Walsh [Tue, 23 Nov 2010 16:36:53 +0000 (11:36 -0500)]
dontaudit leak from init_t to mount_t
Dan Walsh [Tue, 23 Nov 2010 16:32:42 +0000 (11:32 -0500)]
cleanup boolean descriptions
Dan Walsh [Tue, 23 Nov 2010 16:11:40 +0000 (11:11 -0500)]
Cleanup boolean descriptions and fix files_relabel_all_tmp interfaces
Dan Walsh [Tue, 23 Nov 2010 15:34:44 +0000 (10:34 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Tue, 23 Nov 2010 15:34:31 +0000 (10:34 -0500)]
Cleanup boolean descriptions, so setroubleshoot can give better comments
Miroslav Grepl [Tue, 23 Nov 2010 12:21:40 +0000 (12:21 +0000)]
Add cgred_log_t type for cgred log file
Fixes for munin plugin policy
Dan Walsh [Mon, 22 Nov 2010 16:08:08 +0000 (11:08 -0500)]
Allow dbus system domain clients to send dgram messages to systemd
Dan Walsh [Mon, 22 Nov 2010 15:32:43 +0000 (10:32 -0500)]
Make sandbox work on nfs homedirs
Allow init to relabel all /tmp dirs
Allow avahi to signull rpcbind
Miroslav Grepl [Mon, 22 Nov 2010 11:14:29 +0000 (12:14 +0100)]
- Allow ddclient to fix file mode bits of ddclient conf file
Dan Walsh [Fri, 19 Nov 2010 20:51:49 +0000 (15:51 -0500)]
add label for gssd_tmp_t for /var/tmp/nfs_0, init leaks file descriptors to daemons
Chris PeBenito [Fri, 19 Nov 2010 19:31:33 +0000 (14:31 -0500)]
Module version bump for portreserve.
Jeremy Solt [Fri, 19 Nov 2010 14:44:21 +0000 (09:44 -0500)]
portreserve patch from Dan Walsh
"Add _admin domain."
Chris PeBenito [Fri, 19 Nov 2010 19:05:47 +0000 (14:05 -0500)]
Module version bump for privoxy.
Jeremy Solt [Thu, 18 Nov 2010 20:57:02 +0000 (15:57 -0500)]
privoxy patch from Dan Walsh
"split out squid port from http_cache. Need to allow all places that
connect to httpc_cache to connect to squid_port"
Edits:
- Removed tunable tabbing
Chris PeBenito [Fri, 19 Nov 2010 16:59:35 +0000 (11:59 -0500)]
Module version bump for radius.
Chris PeBenito [Fri, 19 Nov 2010 16:50:03 +0000 (11:50 -0500)]
Module version bump for smokeping.
Jeremy Solt [Fri, 12 Nov 2010 20:28:43 +0000 (15:28 -0500)]
smokeping patch from Dan Walsh
"smokeping tries to read shadow"
Jeremy Solt [Fri, 12 Nov 2010 21:23:24 +0000 (16:23 -0500)]
radius patch from Dan Walsh
"radious execs ntml_auth
tmpfs /var/run"
Chris PeBenito [Fri, 19 Nov 2010 16:39:51 +0000 (11:39 -0500)]
Module version bump for ulogd.
Chris PeBenito [Fri, 19 Nov 2010 16:39:36 +0000 (11:39 -0500)]
Move all ulogd networking into the mysql and postgres optionals.
Dan Walsh [Fri, 19 Nov 2010 15:09:38 +0000 (10:09 -0500)]
add labels for /etc/lirc/ and allow amavis_t to exec shell
Dan Walsh [Thu, 18 Nov 2010 21:08:18 +0000 (16:08 -0500)]
Fix lircd missing lircd_etc_t
Jeremy Solt [Fri, 12 Nov 2010 17:25:27 +0000 (12:25 -0500)]
ulogd patch from Dan Walsh
"communicates with mysql and postgres via the network"
Dan Walsh [Thu, 18 Nov 2010 15:57:17 +0000 (10:57 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 18 Nov 2010 15:56:47 +0000 (10:56 -0500)]
Fixes for rawhide boot,
Miroslav Grepl [Thu, 18 Nov 2010 15:37:42 +0000 (16:37 +0100)]
Turn on allow_postfix_local_write_mail_spool
Dan Walsh [Thu, 18 Nov 2010 13:22:14 +0000 (08:22 -0500)]
Allow initrc_t to transition to shutdown_t
Allow chrome_sandbox_t to read route table
Dan Walsh [Wed, 17 Nov 2010 18:10:11 +0000 (13:10 -0500)]
allow logwatch and cron to mls_read_to_clearance for MLS boxes
Allow wm to send signull to all applications and receive them from users
licd patch from field
login programs have to read /etc/samba
New prograns under /lib/systemd
Abrt needs to read config files
Chris PeBenito [Wed, 17 Nov 2010 16:00:07 +0000 (11:00 -0500)]
Module version bump for usbmuxd.
Jeremy Solt [Fri, 12 Nov 2010 16:45:01 +0000 (11:45 -0500)]
usbmuxd patch from Dan Walsh
"Lots of stuff labeled var_run_t"
Chris PeBenito [Wed, 17 Nov 2010 15:21:12 +0000 (10:21 -0500)]
Module version bump for uucp.
Jeremy Solt [Fri, 12 Nov 2010 16:33:22 +0000 (11:33 -0500)]
uucp patch from Dan Walsh
"Executes ssh to setup connection"
Chris PeBenito [Wed, 17 Nov 2010 15:05:36 +0000 (10:05 -0500)]
Module version bump for varnishd.
Jeremy Solt [Fri, 12 Nov 2010 16:10:14 +0000 (11:10 -0500)]
varnishd patch from Dan Walsh
"Kills it self
+ varnishd_read_lib_files(services_munin_plugin_t)"
Chris PeBenito [Wed, 17 Nov 2010 14:30:39 +0000 (09:30 -0500)]
Module version bump for hostname.
Chris PeBenito [Wed, 17 Nov 2010 14:29:40 +0000 (09:29 -0500)]
Module version bump for miscfiles.
Chris PeBenito [Wed, 17 Nov 2010 14:29:22 +0000 (09:29 -0500)]
Additional miscfiles tweaks.
Jeremy Solt [Thu, 11 Nov 2010 20:11:38 +0000 (15:11 -0500)]
system_miscfiles patch from Dan Walsh
"move cobbler, Allow policy to define certs."
Jeremy Solt [Fri, 12 Nov 2010 14:48:13 +0000 (09:48 -0500)]
hostname patch from Dan Walsh
"Hostname access Seems to attract leaks."
Edits:
- No dontaudit_leaks in refpolicy, dropped those interface calls, leaving only nis_use_ypbind
Dan Walsh [Wed, 17 Nov 2010 13:54:06 +0000 (08:54 -0500)]
Patch for Stephen Beahm for ulogd policy
Dan Walsh [Tue, 16 Nov 2010 18:05:42 +0000 (13:05 -0500)]
add fsetid to cgconfig_t
Dan Walsh [Tue, 16 Nov 2010 15:57:09 +0000 (10:57 -0500)]
add label for mcelog-client
Miroslav Grepl [Tue, 16 Nov 2010 12:18:17 +0000 (13:18 +0100)]
Remove duplicate declaration of files_search_spool() interface
Miroslav Grepl [Tue, 16 Nov 2010 12:15:53 +0000 (13:15 +0100)]
- lircd_etc_t label for lirc config is no longer needed
Miroslav Grepl [Tue, 16 Nov 2010 07:49:06 +0000 (08:49 +0100)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 15 Nov 2010 21:20:19 +0000 (16:20 -0500)]
dontaudit leaked sockets from userdomains to user domains
Dan Walsh [Mon, 15 Nov 2010 19:00:02 +0000 (14:00 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 15 Nov 2010 18:59:08 +0000 (13:59 -0500)]
Fixes for mcelog to handle scripts
Apply patch from Ruben Kerkhof
Allow syslog to search spool dirs
Miroslav Grepl [Mon, 15 Nov 2010 18:00:03 +0000 (19:00 +0100)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Mon, 15 Nov 2010 17:57:09 +0000 (18:57 +0100)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy; branch 'master' of http://oss.tresys.com/git/refpolicy
Ruben Kerkhof [Mon, 15 Nov 2010 14:08:46 +0000 (15:08 +0100)]
Fix typo in interface name
Signed-off-by: Ruben Kerkhof <ruben@rubenkerkhof.com>
Miroslav Grepl [Mon, 15 Nov 2010 16:50:45 +0000 (17:50 +0100)]
Allow apache to search zarafa config
Dan Walsh [Mon, 15 Nov 2010 16:25:43 +0000 (11:25 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 15 Nov 2010 16:25:14 +0000 (11:25 -0500)]
Allow system_mail_t to create mail_home_t
Dan Walsh [Mon, 15 Nov 2010 16:24:47 +0000 (11:24 -0500)]
Merge branch 'master' of http://oss.tresys.com/git/refpolicy
Miroslav Grepl [Mon, 15 Nov 2010 15:24:58 +0000 (16:24 +0100)]
Fix sasl_admin interface
Miroslav Grepl [Mon, 15 Nov 2010 14:26:37 +0000 (15:26 +0100)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Mon, 15 Nov 2010 14:25:29 +0000 (15:25 +0100)]
Allow nagios plugins to read usr files
Dan Walsh [Mon, 15 Nov 2010 14:03:55 +0000 (09:03 -0500)]
Fix labels on /etc/mcelog/triggers to bin_t
Miroslav Grepl [Mon, 15 Nov 2010 11:49:22 +0000 (12:49 +0100)]
- Allow mysqld-safe to send system log messages
- Fixes for ddclient policy
- Allow munin plugins to search /var/lib directory
- Allow gpsd to read sysfs_t
Dan Walsh [Fri, 12 Nov 2010 16:04:42 +0000 (11:04 -0500)]
Allow saslauthd_t to create krb5_host_rcache_t files in /tmp
Fix xserver interface
Fix definition of /var/run/lxdm
Dan Walsh [Fri, 12 Nov 2010 14:52:42 +0000 (09:52 -0500)]
init executes mcelog, initrc_t needs to manage faillog.
fix xserver_ralabel_xdm_tmp_dirs
Allow dovecot_deliver_t to list dovecot_etc_t
Run acroread as execmem_t
Dan Walsh [Fri, 12 Nov 2010 14:49:42 +0000 (09:49 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Fri, 12 Nov 2010 12:46:21 +0000 (13:46 +0100)]
- Fix typo
Dan Walsh [Thu, 11 Nov 2010 18:28:46 +0000 (13:28 -0500)]
Fix build problem
Chris PeBenito [Thu, 11 Nov 2010 14:48:43 +0000 (09:48 -0500)]
Add tun_socket ubac constraint and add tun_socket to socket_class_set.
Chris PeBenito [Thu, 11 Nov 2010 14:48:01 +0000 (09:48 -0500)]
Module version bump for Chris Richards' mount patchset.
Chris PeBenito [Thu, 11 Nov 2010 14:47:37 +0000 (09:47 -0500)]
Minor fixes for Chris Richards' mount patchset.
Dan Walsh [Thu, 11 Nov 2010 14:36:05 +0000 (09:36 -0500)]
kdump leaks kdump_etc_t to ifconfig, add dontaudit
uux needs to transition to uucpd_t
More init fixes relabels man,faillog
Remove maxima defs in libraries.fc
insmod needs to be able to create tmpfs_t files
ping needs setcap
Chris Richards [Tue, 9 Nov 2010 01:25:35 +0000 (19:25 -0600)]
dontaudit mount writes to newly mounted filesystems
Signed-off-by: Chris Richards <gizmo@giz-works.com>
Chris Richards [Tue, 9 Nov 2010 01:25:34 +0000 (19:25 -0600)]
dontaudit mount writes to newly mounted filesystems
Signed-off-by: Chris Richards <gizmo@giz-works.com>
Chris Richards [Tue, 9 Nov 2010 01:25:33 +0000 (19:25 -0600)]
dontaudit mount writes to newly mounted filesystems
Signed-off-by: Chris Richards <gizmo@giz-works.com>
Chris Richards [Tue, 9 Nov 2010 01:25:32 +0000 (19:25 -0600)]
dontaudit mount writes to newly mounted filesystems
Signed-off-by: Chris Richards <gizmo@giz-works.com>
Chris Richards [Tue, 9 Nov 2010 01:25:31 +0000 (19:25 -0600)]
dontaudit mount writes to newly mounted filesystems
As of util-linux-n 2.18, the mount utility now attempts to write to the root
of newly mounted filesystems. It does this in an attempt to ensure that the
r/w status of a filesystem as shown in mtab is correct. To detect whether
a filesystem is r/w, mount calls access() with the W_OK argument. This
results in an AVC denial with current policy. As a fallback, mount also
attempts to modify the access time of the directory being mounted on if
the call to access() fails. As mount already possesses the necessary
privileges, the modification of the access time succeeds (at least on systems
with the futimens() function, which has existed in linux since kernel 2.6.22
and glibc since version 2.6, or about July 2007).
Signed-off-by: Chris Richards <gizmo@giz-works.com>
Dan Walsh [Wed, 10 Nov 2010 17:36:38 +0000 (12:36 -0500)]
Remove bogus line in sandbox.te
fsadm_t wants to read fuse_device_t
allow init to relabel wtmp and tmpfiles
Allow sasl to create kerberos cache file
Dan Walsh [Wed, 10 Nov 2010 13:35:37 +0000 (08:35 -0500)]
Allow mount to read/write removable_t blk files
Dan Walsh [Wed, 10 Nov 2010 13:32:48 +0000 (08:32 -0500)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 10 Nov 2010 13:32:25 +0000 (08:32 -0500)]
Allow puppet to read certs and execute useradd and groupadd