]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Miroslav Grepl [Wed, 10 Nov 2010 10:05:36 +0000 (11:05 +0100)]
- Allow groupd transition to fenced domain when executes fence_node
- Fixes for rchs policy
- Allow mpd to be able to read samba/nfs files
Dan Walsh [Tue, 9 Nov 2010 20:39:51 +0000 (15:39 -0500)]
Since all domains that use_nfs_home_dirs call read or write nfs, I am adding the ability to search automountpoints directory
Dan Walsh [Tue, 9 Nov 2010 17:06:52 +0000 (12:06 -0500)]
- Allow bitlebee to setsched
- Allow certmonger to execute ipa- commands and connect to apache ports
- Qpidd talks to corosync
- Add labeling for /var/log/faillock
- Stop relabling from going into /var/lib/debug
Dan Walsh [Tue, 9 Nov 2010 12:39:21 +0000 (07:39 -0500)]
Fix up corecommands.fc to match upstream
Make sure /lib/systemd/* is labeled init_exec_t
mount wants to setattr on all mountpoints
dovecot auth wants to read dovecot etc files
nscd daemon looks at the exe file of the comunicating daemon
openvpn wants to read utmp file
postfix apps now set sys_nice and lower limits
remote_login (telnetd/login) wants to use telnetd_devpts_t and user_devpts_t to work correctly
Also resolves nsswitch
Fix labels on /etc/hosts.*
Dan Walsh [Fri, 5 Nov 2010 18:29:45 +0000 (14:29 -0400)]
Cleanup to make upsteam patch work
allow abrt to read etc_runtime_t
Dan Walsh [Fri, 5 Nov 2010 17:46:35 +0000 (13:46 -0400)]
Update to upstream
Chris PeBenito [Fri, 5 Nov 2010 17:13:42 +0000 (13:13 -0400)]
AIDE can be configured to log to syslog
Chris PeBenito [Fri, 5 Nov 2010 17:13:21 +0000 (13:13 -0400)]
Change /dev/log fc to MLS system high.
When the syslog recreates this sock_file on startup, it gets this sensitivity anyway.
This will prevent incorrect relabeling if /dev is relabeled.
Dan Walsh [Fri, 5 Nov 2010 16:22:42 +0000 (12:22 -0400)]
Move kdump to admin dir
Dan Walsh [Fri, 5 Nov 2010 16:12:37 +0000 (12:12 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy; branch 'master' of http://oss.tresys.com/git/refpolicy
Conflicts:
policy/modules/kernel/corecommands.fc
policy/modules/roles/sysadm.te
policy/modules/roles/unprivuser.te
policy/modules/services/bitlbee.te
policy/modules/services/oident.te
policy/modules/services/tor.te
policy/modules/system/kdump.if
policy/modules/system/kdump.te
Dan Walsh [Fri, 5 Nov 2010 16:02:59 +0000 (12:02 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 5 Nov 2010 16:02:30 +0000 (12:02 -0400)]
Update dirsrv to build
Miroslav Grepl [Fri, 5 Nov 2010 15:35:49 +0000 (16:35 +0100)]
Allow corosync transition to drbd domain
Miroslav Grepl [Fri, 5 Nov 2010 15:33:59 +0000 (16:33 +0100)]
Add initial policy for drbd service
Miroslav Grepl [Fri, 5 Nov 2010 13:14:06 +0000 (14:14 +0100)]
Fixes for corosync policy
Dan Walsh [Thu, 4 Nov 2010 19:15:42 +0000 (15:15 -0400)]
- Fix sandbox to work on nfs homedirs
- Allow cdrecord to setrlimit
- Allow mozilla_plugin to read xauth
- Change label on systemd-logger to syslogd_exec_t
- Install dirsrv policy from dirsrv package
Dan Walsh [Tue, 2 Nov 2010 21:23:48 +0000 (17:23 -0400)]
Add virt_home_t, allow init to setattr on xserver_tmp_t and relabel it
Udev needs to stream connect to init and kernel
Miroslav Grepl [Tue, 2 Nov 2010 17:37:07 +0000 (18:37 +0100)]
Add xdm_exec_bootloader boolean, which allows xdm to execute /sbin/grub and read files in /boot directory
Chris PeBenito [Tue, 2 Nov 2010 13:17:16 +0000 (09:17 -0400)]
Fix deprecated interface usage in vlock.
Chris PeBenito [Tue, 2 Nov 2010 13:09:05 +0000 (09:09 -0400)]
Whitespace fix in secadm.te and auditadm.te.
Harry Ciao [Tue, 2 Nov 2010 04:20:27 +0000 (12:20 +0800)]
Make auditadm & secadm able to use vlock
Make the auditadm and secadm able to use the vlock program.
Also bump their module versions.
Signed-off-by: Harry Ciao <qingtao.cao@windriver.com>
Dan Walsh [Mon, 1 Nov 2010 18:23:06 +0000 (14:23 -0400)]
Allow NetworkManager to read openvpn_etc_t
- Dontaudit hplip to write of /usr dirs
- Allow system_mail_t to create /root/dead.letter as mail_home_t
- Add vdagent policy for spice agent daemon
Chris PeBenito [Mon, 1 Nov 2010 15:22:25 +0000 (11:22 -0400)]
Module version bump for vlock. Changelog entry.
Chris PeBenito [Mon, 1 Nov 2010 15:22:07 +0000 (11:22 -0400)]
Rename vlock interfaces.
Chris PeBenito [Mon, 1 Nov 2010 15:21:02 +0000 (11:21 -0400)]
Rearrange rules in vlock.
Harry Ciao [Tue, 26 Oct 2010 06:34:11 +0000 (14:34 +0800)]
Adding support for the vlock program.
Both the system administrator and the unprivileged user could use vlock
to lock the current console when logging in either from the serial console
or by ssh.
Signed-off-by: Harry Ciao <qingtao.cao@windriver.com>
Miroslav Grepl [Mon, 1 Nov 2010 08:36:13 +0000 (09:36 +0100)]
Dontaudit hplip to write of /usr dirs
Dan Walsh [Thu, 28 Oct 2010 19:53:02 +0000 (15:53 -0400)]
- Dontaudit sandbox sending sigkill to all user domains
- Add policy for rssh_chroot_helper
- Add missing flask definitions
- Allow udev to relabelto removable_t
- Fix label on /var/log/wicd.log
- Transition to initrc_t from init when executing bin_t
- Add audit_access permissions to file
- Make removable_t a device_node
- Fix label on /lib/systemd/*
Chris PeBenito [Thu, 28 Oct 2010 18:35:29 +0000 (14:35 -0400)]
Git man page from Dominick Grift.
Chris PeBenito [Thu, 28 Oct 2010 18:34:10 +0000 (14:34 -0400)]
FTPd man page patch from Dan Walsh.
Chris PeBenito [Thu, 28 Oct 2010 18:32:16 +0000 (14:32 -0400)]
Add mounting interfaces for selinuxfs.
Chris PeBenito [Wed, 27 Oct 2010 19:17:02 +0000 (15:17 -0400)]
Module version bump for oident. Additional comments for kernel loading.
Jeremy Solt [Wed, 1 Sep 2010 14:30:15 +0000 (10:30 -0400)]
oident patch from Dan Walsh
Chris PeBenito [Wed, 27 Oct 2010 19:04:40 +0000 (15:04 -0400)]
Additional rearrangement in tor and module version bump.
Jeremy Solt [Fri, 17 Sep 2010 15:36:57 +0000 (11:36 -0400)]
tor patch from Dan Walsh
Added additional access for dns server (bind on the port shouldn't be enough)
Chris PeBenito [Wed, 27 Oct 2010 18:09:00 +0000 (14:09 -0400)]
Additional rearrangement in corecommands, along with module version bump.
Jeremy Solt [Fri, 22 Oct 2010 20:19:46 +0000 (16:19 -0400)]
corecommands patch from Dan Walsh: "Lots of bin_t files"
Chris PeBenito [Tue, 26 Oct 2010 19:24:02 +0000 (15:24 -0400)]
Sosreport changelog entry.
Chris PeBenito [Tue, 26 Oct 2010 19:23:20 +0000 (15:23 -0400)]
Move sosreport to admin layer.
Chris PeBenito [Tue, 26 Oct 2010 19:22:24 +0000 (15:22 -0400)]
Minor sosreport cleanup.
Miroslav Grepl [Mon, 25 Oct 2010 08:18:19 +0000 (10:18 +0200)]
Allow lowatch to use zz-disk_space logwatch script
Dan Walsh [Fri, 22 Oct 2010 20:14:26 +0000 (16:14 -0400)]
Dontaudit firstboot leaks
Allow sandbox web to read alsa config
Allow nrpe_t to read config
Allow dhcpc_t to read /etc/pki
Jeremy Solt [Fri, 24 Sep 2010 18:58:20 +0000 (14:58 -0400)]
sosreport policy from Dan Walsh
- A couple style fixes
Chris PeBenito [Thu, 21 Oct 2010 14:45:20 +0000 (10:45 -0400)]
Move kdump to admin layer.
Chris PeBenito [Thu, 21 Oct 2010 14:15:40 +0000 (10:15 -0400)]
Module version bump for kdump.
Chris PeBenito [Thu, 21 Oct 2010 14:11:12 +0000 (10:11 -0400)]
Module version bump for setrans.
Jeremy Solt [Fri, 24 Sep 2010 20:14:00 +0000 (16:14 -0400)]
setrans patch from Dan Walsh
Edits:
- Leaving out the mls_trusted_object(setrans_t) for now
Jeremy Solt [Fri, 17 Sep 2010 19:56:06 +0000 (15:56 -0400)]
kdump patch from Dan Walsh
Chris PeBenito [Thu, 21 Oct 2010 13:56:35 +0000 (09:56 -0400)]
Module version bump for asterisk.
Jeremy Solt [Mon, 30 Aug 2010 14:14:44 +0000 (10:14 -0400)]
asterisk patch from Dan Walsh
Dan Walsh [Tue, 19 Oct 2010 15:52:14 +0000 (11:52 -0400)]
- Allow chome to create netlink_route_socket
- Add additional MATHLAB file context
- Define nsplugin as an application_domain
- Dontaudit sending signals from sandboxed domains to other domains
- systemd requires init to build /tmp /var/auth and /var/lock dirs
- mount wants to read devicekit_power /proc/ entries
- mpd wants to connect to soundd port
- Openoffice causes a setattr on a lib_t file for normal users, add dontaudit
- Treat lib_t and textrel_shlib_t directories the same
- Allow mount read access on virtual images
Dan Walsh [Mon, 18 Oct 2010 14:58:29 +0000 (10:58 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 18 Oct 2010 14:57:00 +0000 (10:57 -0400)]
Allow devicekit_power to domtrans to mount
Allow dhcp to bind to udp ports > 1024 to do named stuff
Allow ssh_t to exec ssh_exec_t
Chris PeBenito [Mon, 18 Oct 2010 13:51:16 +0000 (09:51 -0400)]
Module version bump for hotplug.
Chris PeBenito [Mon, 18 Oct 2010 13:44:37 +0000 (09:44 -0400)]
Module version bump for bitlbee.
Chris PeBenito [Mon, 18 Oct 2010 13:34:47 +0000 (09:34 -0400)]
Module version bump for wireshark patch.
Jeremy Solt [Fri, 17 Sep 2010 13:14:41 +0000 (09:14 -0400)]
wireshark patch from Dan Walsh
files_poly_member is provided by userdom_user_home_content
Whitespace fixes
Chris PeBenito [Mon, 18 Oct 2010 13:23:28 +0000 (09:23 -0400)]
Module version bump for apcupsd patch.
Chris PeBenito [Mon, 18 Oct 2010 13:21:35 +0000 (09:21 -0400)]
Module version bump for avahi patch.
Jeremy Solt [Fri, 15 Oct 2010 18:20:00 +0000 (14:20 -0400)]
Avahi patch from Dan Walsh
Dropped file read from dbus_chat
Jeremy Solt [Fri, 17 Sep 2010 13:27:03 +0000 (09:27 -0400)]
apcupsd patch from Dan Walsh
Jeremy Solt [Fri, 15 Oct 2010 18:53:00 +0000 (14:53 -0400)]
bitlbee patch from Dan Walsh
Jeremy Solt [Tue, 28 Sep 2010 18:13:52 +0000 (14:13 -0400)]
hotplug patch from Dan Walsh
Miroslav Grepl [Mon, 18 Oct 2010 13:50:25 +0000 (15:50 +0200)]
Remove telepathy_butterfly_rw_tmp_files(), dev_read_printk() interfaces which are nolonger used
Fix clamav_append_log() intefaces
Miroslav Grepl [Mon, 18 Oct 2010 13:28:32 +0000 (15:28 +0200)]
Fix 'psad_rw_fifo_file' interface
Dan Walsh [Fri, 15 Oct 2010 19:07:09 +0000 (15:07 -0400)]
remove setroubleshoot stuff
Dan Walsh [Fri, 15 Oct 2010 14:24:04 +0000 (10:24 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/setroubleshoot
Dan Walsh [Fri, 15 Oct 2010 14:23:10 +0000 (10:23 -0400)]
Don't transition to mount but allow devicekit_power_t to execute it.
Dan Walsh [Fri, 15 Oct 2010 13:53:52 +0000 (09:53 -0400)]
Mount seems to be doing an access(W_OK) check on all file systems before mounting, Need to allow this so mount will succeed.
Chrome sandbox needs to read gnome_home content
mailers need to be able to append to dead.letter
Dan Walsh [Fri, 15 Oct 2010 12:51:57 +0000 (08:51 -0400)]
Add sys_resource capability to httpd when httpd_setrlimit is turned on
Dan Walsh [Fri, 15 Oct 2010 12:09:50 +0000 (08:09 -0400)]
Allow devicekit_power_t to transition to readahead and mount
Allow devicekit_power_t to get the privs of hal
Add privs to systemd to be able to run systemd-tmpfiles
Fix definition of rw_inherited_term_perms
Sandbox seems to be attempting to send signull to applications
Dan Walsh [Fri, 15 Oct 2010 12:09:09 +0000 (08:09 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 13 Oct 2010 08:10:16 +0000 (10:10 +0200)]
Add role parameter for these interfaces
Dan Walsh [Tue, 12 Oct 2010 20:44:50 +0000 (16:44 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy; branch 'master' of http://oss.tresys.com/git/refpolicy
Conflicts:
policy/support/obj_perm_sets.spt
Dan Walsh [Tue, 12 Oct 2010 20:40:05 +0000 (16:40 -0400)]
Dontlabel systemd-tmpfiles as tmpreaper_exec_t
Dan Walsh [Tue, 12 Oct 2010 20:09:45 +0000 (16:09 -0400)]
Fix /var/lib/rsyslog file context
Dan Walsh [Tue, 12 Oct 2010 19:57:48 +0000 (15:57 -0400)]
Allow dnsmasq to read resolv.conf under ppp directories
Allow loginprograms to connect to userdomain ssh-agent for pam_ssh
Dan Walsh [Tue, 12 Oct 2010 19:34:27 +0000 (15:34 -0400)]
fix typo
Dan Walsh [Tue, 12 Oct 2010 19:28:08 +0000 (15:28 -0400)]
Mount command from a confined user generates setattr on /etc/mtab file, need to dontaudit this access
dovecot-auth_t needs ipc_lock
gpm needs to use the user terminal
Allow system_mail_t to append ~/dead.letter
Allow NetworkManager to edit /etc/NetworkManager/NetworkManager.conf
Add pid file to vnstatd
Allow mount to communicate with gfs_controld
Dontaudit hal leaks in setfiles
Dominick Grift [Mon, 11 Oct 2010 16:03:49 +0000 (18:03 +0200)]
obj_perm_sets: so that use_terminal interfaces also allow append.
Signed-off-by: Dominick Grift <domg472@gmail.com>
Dominick Grift [Fri, 8 Oct 2010 20:40:58 +0000 (22:40 +0200)]
Two insignificant fixes that i stumbled on when merging dev_getattr_fs()
Signed-off-by: Dominick Grift <domg472@gmail.com>
Chris PeBenito [Mon, 11 Oct 2010 13:36:56 +0000 (09:36 -0400)]
Module version bump for Dominick's su cleanup.
Chris PeBenito [Mon, 11 Oct 2010 13:36:31 +0000 (09:36 -0400)]
Rename init_search_script_key() to init_search_script_keys().
Dominick Grift [Fri, 8 Oct 2010 13:08:57 +0000 (15:08 +0200)]
su: wants to read inits script keyring.
Signed-off-by: Dominick Grift <domg472@gmail.com>
Dominick Grift [Fri, 8 Oct 2010 13:57:09 +0000 (15:57 +0200)]
su: redundant, init_dontaudit_use_script_ptys($1_su_t)
Signed-off-by: Dominick Grift <domg472@gmail.com>
Chris PeBenito [Mon, 11 Oct 2010 13:27:27 +0000 (09:27 -0400)]
Module version bump for Dominick's consoletype cleanup.
Dominick Grift [Wed, 6 Oct 2010 13:19:54 +0000 (15:19 +0200)]
consoletype: redundant.
Signed-off-by: Dominick Grift <domg472@gmail.com>
Dominick Grift [Wed, 6 Oct 2010 13:21:31 +0000 (15:21 +0200)]
consoletype: needs to use system dbus file descriptors.
Signed-off-by: Dominick Grift <domg472@gmail.com>
Dan Walsh [Fri, 8 Oct 2010 20:56:49 +0000 (16:56 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dominick Grift [Fri, 8 Oct 2010 19:29:03 +0000 (21:29 +0200)]
Remove duplicate interface.
Dominick Grift [Fri, 8 Oct 2010 19:22:57 +0000 (21:22 +0200)]
Missing file context specifications for /lib/udev/devices.
Chris PeBenito [Fri, 8 Oct 2010 18:33:04 +0000 (14:33 -0400)]
Module version bump for Dominick's sudo cleanup.
Dominick Grift [Mon, 4 Oct 2010 18:23:48 +0000 (20:23 +0200)]
sudo: wants to get attributes of device_t filesystems.
Signed-off-by: Dominick Grift <domg472@gmail.com>
Dan Walsh [Fri, 8 Oct 2010 15:56:02 +0000 (11:56 -0400)]
More fixes for systemd
Dan Walsh [Fri, 8 Oct 2010 15:53:09 +0000 (11:53 -0400)]
Parts of systemd are now doing readahead and tmpreaper functionality
systemd relabeles tmpfs_t to cgroup_t
Other systemd fixes
Dominick Grift [Mon, 4 Oct 2010 18:23:50 +0000 (20:23 +0200)]
sudo: wants to get attributes of generic pts filesystems.
Signed-off-by: Dominick Grift <domg472@gmail.com>
Chris PeBenito [Fri, 8 Oct 2010 13:15:17 +0000 (09:15 -0400)]
Revert su default_t rule.
Chris PeBenito [Fri, 8 Oct 2010 12:54:01 +0000 (08:54 -0400)]
Module version bump for Dominick's su cleanup.
Dominick Grift [Mon, 4 Oct 2010 18:23:47 +0000 (20:23 +0200)]
su: search parent.
Signed-off-by: Dominick Grift <domg472@gmail.com>
Dominick Grift [Mon, 4 Oct 2010 18:23:45 +0000 (20:23 +0200)]
su: wants to search callers keyring.
Signed-off-by: Dominick Grift <domg472@gmail.com>