]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
15 years agoAdditional whitespace fix in nis.
Chris PeBenito [Mon, 19 Apr 2010 14:20:19 +0000 (10:20 -0400)] 
Additional whitespace fix in nis.

15 years agoStyle changes
Jeremy Solt [Mon, 12 Apr 2010 20:02:45 +0000 (16:02 -0400)] 
Style changes

15 years agonis patch from Dan Walsh
Jeremy Solt [Fri, 9 Apr 2010 15:52:54 +0000 (11:52 -0400)] 
nis patch from Dan Walsh

Made a couple style changes.
Removed unnecessary require in nis_use_ypbind interface

15 years agoAdditional whitespace fixes in certmonger.
Chris PeBenito [Mon, 19 Apr 2010 14:17:24 +0000 (10:17 -0400)] 
Additional whitespace fixes in certmonger.

15 years agoFix some whitespace and style issues.
Jeremy Solt [Mon, 12 Apr 2010 19:54:18 +0000 (15:54 -0400)] 
Fix some whitespace and style issues.

15 years agocertmonger policy from Dan Walsh
Jeremy Solt [Fri, 9 Apr 2010 17:05:52 +0000 (13:05 -0400)] 
certmonger policy from Dan Walsh

Removed manage_var_run and manage_var_lib interfaces
Added missing requires to admin interface
Removed permissive line
Fixed some spacing / style issues

15 years agoModule version bump for 4f7b413.
Chris PeBenito [Mon, 19 Apr 2010 14:05:22 +0000 (10:05 -0400)] 
Module version bump for 4f7b413.

15 years agoRemove excess white space from ntop.te
Jeremy Solt [Mon, 12 Apr 2010 19:31:43 +0000 (15:31 -0400)] 
Remove excess white space from ntop.te
Move ntop ports declaration to correct location.

15 years agoNtop policy from Dan Walsh
Jeremy Solt [Thu, 8 Apr 2010 14:28:53 +0000 (10:28 -0400)] 
Ntop policy from Dan Walsh

Added alias for ntop_http_content_t in apache
Pulled in ntop port from corenetwork patch

15 years agoModule version bump for 46e16a2.
Chris PeBenito [Mon, 19 Apr 2010 13:54:13 +0000 (09:54 -0400)] 
Module version bump for 46e16a2.

15 years agoMove optional policy to correct location for style
Jeremy Solt [Mon, 12 Apr 2010 19:23:36 +0000 (15:23 -0400)] 
Move optional policy to correct location for style

15 years agokerberos patch from Dan Walsh
Jeremy Solt [Thu, 8 Apr 2010 20:02:18 +0000 (16:02 -0400)] 
kerberos patch from Dan Walsh

15 years agoUse port range notation in corenetwork where it makes sense.
Chris PeBenito [Tue, 13 Apr 2010 15:55:04 +0000 (11:55 -0400)] 
Use port range notation in corenetwork where it makes sense.

15 years agoClean up output of generated corenetwork.te.
Chris PeBenito [Tue, 13 Apr 2010 15:52:09 +0000 (11:52 -0400)] 
Clean up output of generated corenetwork.te.

15 years agoFix network_port() in corenetwork to correctly handle port ranges.
Chris PeBenito [Tue, 13 Apr 2010 15:06:02 +0000 (11:06 -0400)] 
Fix network_port() in corenetwork to correctly handle port ranges.

15 years ago[BUGFIX] lack of type transition on dbadm domain (Re: dbadm.pp is not available in...
KaiGai Kohei [Mon, 12 Apr 2010 14:14:10 +0000 (10:14 -0400)] 
[BUGFIX] lack of type transition on dbadm domain (Re: dbadm.pp is not available in selinux-policy package)

I found out a bug when we initialize the database with dbadm_r:dbadm_t
which belongs to sepgsql_admin_type attribute.

In the case when sepgsql_admin_type create a new database objects,
it does not have valid type_transition rules. So, it was failed.
Sorry, I didn't find out it for a long time.

And db_procedure:{execute} on the sepgsql_proc_exec_t might be necessary
for the administrative domain independently from sepgsql_unconfined_dbadm,
because we need to execute some of system defined procedures to look up
system tables.

15 years agoModule version bump for 5d3214f and 795b733.
Chris PeBenito [Mon, 12 Apr 2010 14:01:39 +0000 (10:01 -0400)] 
Module version bump for 5d3214f and 795b733.

15 years agopcscd patch from Dan Walsh: manage pub files and fifo files
Jeremy Solt [Fri, 9 Apr 2010 14:14:05 +0000 (10:14 -0400)] 
pcscd patch from Dan Walsh: manage pub files and fifo files

15 years agogpsd path from Dan Walsh
Jeremy Solt [Thu, 8 Apr 2010 19:29:56 +0000 (15:29 -0400)] 
gpsd path from Dan Walsh

15 years agoAdd devtmpfs labeling.
Chris PeBenito [Wed, 7 Apr 2010 12:55:33 +0000 (08:55 -0400)] 
Add devtmpfs labeling.

15 years agoMove kernel_request_load_module(gssd_t) to the proper place.
Dominick Grift [Tue, 6 Apr 2010 13:24:23 +0000 (15:24 +0200)] 
Move kernel_request_load_module(gssd_t) to the proper place.

Signed-off-by: Dominick Grift <domg472@gmail.com>
15 years agoFix requires for apache tmp interfaces.
Dominick Grift [Tue, 6 Apr 2010 13:22:42 +0000 (15:22 +0200)] 
Fix requires for apache tmp interfaces.

Signed-off-by: Dominick Grift <domg472@gmail.com>
15 years agoPortreserve patch from Dan Walsh.
Chris PeBenito [Mon, 5 Apr 2010 18:50:23 +0000 (14:50 -0400)] 
Portreserve patch from Dan Walsh.

15 years agoPPP patch from Dan Walsh.
Chris PeBenito [Mon, 5 Apr 2010 18:38:30 +0000 (14:38 -0400)] 
PPP patch from Dan Walsh.

15 years agoRpc patch from Dan Walsh.
Chris PeBenito [Mon, 5 Apr 2010 18:26:21 +0000 (14:26 -0400)] 
Rpc patch from Dan Walsh.

15 years agoWhitespace fixes on Apache.
Chris PeBenito [Mon, 5 Apr 2010 18:05:05 +0000 (14:05 -0400)] 
Whitespace fixes on Apache.

15 years agoModule version bump for 170a46d, f8b3b7f, and a49a82c.
Chris PeBenito [Mon, 5 Apr 2010 17:49:00 +0000 (13:49 -0400)] 
Module version bump for 170a46df8b3b7f, and a49a82c.

15 years agoTweak for 170a46d.
Chris PeBenito [Mon, 5 Apr 2010 17:48:01 +0000 (13:48 -0400)] 
Tweak for 170a46d.

15 years agosnort patch from Dan Walsh
Jeremy Solt [Wed, 31 Mar 2010 18:16:34 +0000 (14:16 -0400)] 
snort patch from Dan Walsh

Didn't rearrange all the kernel calls, but did add the kernel_request_load_module.
Didn't include the usbmod (doesn't exist in refpolicy at this time).
Included the generic usb device permissions because snort uses libpcap, which can also be used to monitor USB traffic, so this may be a side effect.
From the red hat bug (559861), it sounds as though snort was failing without these permissions, so it doesn't look like a dontaudit would work.

15 years agoNut policy from Dan Walsh
Jeremy Solt [Wed, 31 Mar 2010 19:23:29 +0000 (15:23 -0400)] 
Nut policy from Dan Walsh

Dropped optional policy for shutdown_domtrans
Dropped commented can_exec line

15 years agomemcached patch from Dan Walsh
Jeremy Solt [Thu, 1 Apr 2010 14:49:29 +0000 (10:49 -0400)] 
memcached patch from Dan Walsh

Moved term_dontaudits up for style

15 years agoSecond part of Apache patch from Dan Walsh.
Chris PeBenito [Mon, 5 Apr 2010 14:57:52 +0000 (10:57 -0400)] 
Second part of Apache patch from Dan Walsh.

15 years agoFirst part of apache patch from Dan Walsh: file context changes, including renaming...
Chris PeBenito [Thu, 1 Apr 2010 12:17:50 +0000 (08:17 -0400)] 
First part of apache patch from Dan Walsh: file context changes, including renaming script ro/ra/rw files.

15 years agoTor patch from Dan Walsh.
Chris PeBenito [Mon, 29 Mar 2010 18:30:52 +0000 (14:30 -0400)] 
Tor patch from Dan Walsh.

15 years agoSssd patch from Dan Walsh.
Chris PeBenito [Mon, 29 Mar 2010 18:08:52 +0000 (14:08 -0400)] 
Sssd patch from Dan Walsh.

15 years agoAdd usbmuxd from Dan Walsh.
Chris PeBenito [Mon, 29 Mar 2010 17:29:18 +0000 (13:29 -0400)] 
Add usbmuxd from Dan Walsh.

15 years agoVhostmd from Dan Walsh.
Chris PeBenito [Mon, 29 Mar 2010 15:25:06 +0000 (11:25 -0400)] 
Vhostmd from Dan Walsh.

15 years agoModule version bumps for c586c1b, dcbb332, 4c05dff, 84ce9c3, 2b012ba, and 1868383.
Chris PeBenito [Mon, 29 Mar 2010 13:21:59 +0000 (09:21 -0400)] 
Module version bumps for c586c1bdcbb3324c05dff84ce9c32b012ba, and 1868383.

15 years agoTweaks on pulseaudio 1868383, ksmtuned d279dd6, and smokeping f3c346c.
Chris PeBenito [Mon, 29 Mar 2010 13:19:40 +0000 (09:19 -0400)] 
Tweaks on pulseaudio 1868383, ksmtuned d279dd6, and smokeping f3c346c.

15 years agoSmokeping policy from Dan Walsh
Jeremy Solt [Tue, 23 Mar 2010 18:43:08 +0000 (14:43 -0400)] 
Smokeping policy from Dan Walsh

Made some style / spacing changes
Did not include read access to /etc/shadow
Removed manage_var_run and manage_var_lib interfaces
Removed permissive line

15 years agopulseaudio patch from Dan Walsh
Jeremy Solt [Tue, 23 Mar 2010 19:51:04 +0000 (15:51 -0400)] 
pulseaudio patch from Dan Walsh

Fixed template where it should have been interface
Replaced read_home and manage_home interfaces with read_home_files, manage_home_files and reduced access
Removed admin_dir reference
Replaced rtkit_daemon_system_domain with rtkit_scheduled
Fixed style / spacing issues

15 years agoksmtuned policy from Dan Walsh
Jeremy Solt [Wed, 24 Mar 2010 14:29:39 +0000 (10:29 -0400)] 
ksmtuned policy from Dan Walsh

Couple style/space fixes.
Used ps_process_pattern in admin interface

15 years agoPrelude patch from Dan Walsh
Jeremy Solt [Wed, 24 Mar 2010 13:46:14 +0000 (09:46 -0400)] 
Prelude patch from Dan Walsh

15 years agoBluetooth patch (sys_admin and debugfs) from Dan Walsh
Jeremy Solt [Wed, 24 Mar 2010 15:54:10 +0000 (11:54 -0400)] 
Bluetooth patch (sys_admin and debugfs) from Dan Walsh

Added comments to reference redhat bugs

15 years agoavahi patch from Dan Walsh
Jeremy Solt [Wed, 24 Mar 2010 18:19:30 +0000 (14:19 -0400)] 
avahi patch from Dan Walsh

Didn't include the file read in the dbus_chat interface.

15 years agochronyd patch from Dan Walsh
Jeremy Solt [Wed, 24 Mar 2010 19:57:15 +0000 (15:57 -0400)] 
chronyd patch from Dan Walsh

Fixed a couple style/spacing issues.
Added files_search_etc for chronyd_keys file

15 years agoGive dcc setgid from Dan Walsh
Jeremy Solt [Thu, 25 Mar 2010 14:58:47 +0000 (10:58 -0400)] 
Give dcc setgid from Dan Walsh

15 years agoModule version bump for c37d843.
Chris PeBenito [Tue, 23 Mar 2010 12:07:19 +0000 (08:07 -0400)] 
Module version bump for c37d843.

15 years agoMinor bind XML tweaks.
Chris PeBenito [Tue, 23 Mar 2010 12:05:00 +0000 (08:05 -0400)] 
Minor bind XML tweaks.

15 years agobind patch from Dan Walsh
Jeremy Solt [Mon, 22 Mar 2010 19:14:47 +0000 (15:14 -0400)] 
bind patch from Dan Walsh
some fixes in interfaces, added bind_setattr_zone_dirs interface
sysnet_read_config not needed with auth_use_nsswitch

Did not include init_read_script_tmp_files for named_t

15 years agoRadvd patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 19:19:50 +0000 (15:19 -0400)] 
Radvd patch from Dan Walsh.

15 years agoRdisc patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 19:09:27 +0000 (15:09 -0400)] 
Rdisc patch from Dan Walsh.

15 years agoModule version bump for 1d348bd.
Chris PeBenito [Mon, 22 Mar 2010 17:53:24 +0000 (13:53 -0400)] 
Module version bump for 1d348bd.

15 years agoAfs needs sys_admin, sends signals, and resolves hostnames from Dan Walsh
Jeremy Solt [Mon, 22 Mar 2010 17:25:07 +0000 (13:25 -0400)] 
Afs needs sys_admin, sends signals, and resolves hostnames from Dan Walsh

15 years agoModule version bump for 75c8a69.
Chris PeBenito [Mon, 22 Mar 2010 17:51:35 +0000 (13:51 -0400)] 
Module version bump for 75c8a69.

15 years agogitosis read/manage lib interfaces from Dan Walsh
Jeremy Solt [Mon, 22 Mar 2010 15:34:54 +0000 (11:34 -0400)] 
gitosis read/manage lib interfaces from Dan Walsh

Only giving manage_files_pattern for gitosis_manage_lib_files

15 years agoSasl patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 15:22:25 +0000 (11:22 -0400)] 
Sasl patch from Dan Walsh.

15 years agoSnmp patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 15:08:31 +0000 (11:08 -0400)] 
Snmp patch from Dan Walsh.

15 years agoSysstat patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 14:47:41 +0000 (10:47 -0400)] 
Sysstat patch from Dan Walsh.

15 years agoTelnet patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 14:40:37 +0000 (10:40 -0400)] 
Telnet patch from Dan Walsh.

15 years agoTuned patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 14:33:31 +0000 (10:33 -0400)] 
Tuned patch from Dan Walsh.

15 years agoVirt patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 14:24:34 +0000 (10:24 -0400)] 
Virt patch from Dan Walsh.

15 years agoRename rtkit_schedule() to rtkit_scheduled().
Chris PeBenito [Mon, 22 Mar 2010 13:54:58 +0000 (09:54 -0400)] 
Rename rtkit_schedule() to rtkit_scheduled().

15 years agoModule version bump for ac19f1a.
Chris PeBenito [Mon, 22 Mar 2010 12:59:04 +0000 (08:59 -0400)] 
Module version bump for ac19f1a.

15 years agoModule version bump for 9681df1.
Chris PeBenito [Mon, 22 Mar 2010 12:58:41 +0000 (08:58 -0400)] 
Module version bump for 9681df1.

15 years agoModule version bump for d3b5907.
Chris PeBenito [Mon, 22 Mar 2010 12:58:20 +0000 (08:58 -0400)] 
Module version bump for d3b5907.

15 years agoMinor tweaks on icecast.
Chris PeBenito [Mon, 22 Mar 2010 12:56:32 +0000 (08:56 -0400)] 
Minor tweaks on icecast.

15 years agoicecast policy from Dan Walsh
Jeremy Solt [Fri, 19 Mar 2010 19:46:59 +0000 (15:46 -0400)] 
icecast policy from Dan Walsh

Fixed some style and spacing issues
Replace manage_var_run interface with manage_pid_files with fewer permissions
Replaced rkit_daemon_system_domain with rtkit_schedule

15 years agortkit patch from Dan Walsh:
Jeremy Solt [Fri, 19 Mar 2010 18:28:27 +0000 (14:28 -0400)] 
rtkit patch from Dan Walsh:
rtkit_daemon_system_domain interface allows domains to say rtkit can setsched on their process.
Needs sys_nice capability
Needs to getsched on all domains.
Fix bug in te file

Me:
changed interface name from rtkit_daemon_system_domain to rtkit_schedule
Already had sys_nice capability

15 years agopostgresql patch from Dan Walsh:
Jeremy Solt [Fri, 19 Mar 2010 17:51:32 +0000 (13:51 -0400)] 
postgresql patch from Dan Walsh:
"File context for /etc/sysconfig/pgsql and other bugs.
Sends audit messages connect to posgresql_server port
Reads its own process info"

Moved signal interface for style.

15 years agoopenvpn needs ipc_lock capability, connects to http ports,
Jeremy Solt [Fri, 19 Mar 2010 17:04:27 +0000 (13:04 -0400)] 
openvpn needs ipc_lock capability, connects to http ports,
and manages net_conf_t files - from Dan Walsh

15 years agoTftp patch from Dan Walsh.
Chris PeBenito [Fri, 19 Mar 2010 19:56:14 +0000 (15:56 -0400)] 
Tftp patch from Dan Walsh.

15 years agoUucp patch from Dan Walsh.
Chris PeBenito [Fri, 19 Mar 2010 19:49:12 +0000 (15:49 -0400)] 
Uucp patch from Dan Walsh.

15 years agoZebra patch from Dan Walsh.
Chris PeBenito [Fri, 19 Mar 2010 19:45:25 +0000 (15:45 -0400)] 
Zebra patch from Dan Walsh.

15 years agoLibraries patch from Dan Walsh.
Chris PeBenito [Fri, 19 Mar 2010 18:21:23 +0000 (14:21 -0400)] 
Libraries patch from Dan Walsh.

15 years agoXen patch from Dan Walsh.
Chris PeBenito [Fri, 19 Mar 2010 15:54:50 +0000 (11:54 -0400)] 
Xen patch from Dan Walsh.

15 years agoGetty patch from Dan Walsh.
Chris PeBenito [Fri, 19 Mar 2010 15:05:56 +0000 (11:05 -0400)] 
Getty patch from Dan Walsh.

15 years agoSysnetwork patch from Dan Walsh.
Chris PeBenito [Thu, 18 Mar 2010 19:40:04 +0000 (15:40 -0400)] 
Sysnetwork patch from Dan Walsh.

15 years agoInit patch from Dan Walsh.
Chris PeBenito [Thu, 18 Mar 2010 14:19:49 +0000 (10:19 -0400)] 
Init patch from Dan Walsh.

15 years agoAuthlogin patch from Dan Walsh.
Chris PeBenito [Thu, 18 Mar 2010 12:59:25 +0000 (08:59 -0400)] 
Authlogin patch from Dan Walsh.

15 years agoIptables patch from Dan Walsh.
Chris PeBenito [Thu, 18 Mar 2010 12:10:21 +0000 (08:10 -0400)] 
Iptables patch from Dan Walsh.

15 years agoUdev patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 19:17:48 +0000 (15:17 -0400)] 
Udev patch from Dan Walsh.

15 years agoLogging patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 18:40:06 +0000 (14:40 -0400)] 
Logging patch from Dan Walsh.

15 years agoIpsec patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 17:52:07 +0000 (13:52 -0400)] 
Ipsec patch from Dan Walsh.

15 years agoModutils patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 15:59:14 +0000 (11:59 -0400)] 
Modutils patch from Dan Walsh.

15 years agoKernel patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 15:16:25 +0000 (11:16 -0400)] 
Kernel patch from Dan Walsh.

15 years agoDomain patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 14:02:07 +0000 (10:02 -0400)] 
Domain patch from Dan Walsh.

15 years agoModule version bump for 6a03548.
Chris PeBenito [Wed, 17 Mar 2010 13:42:46 +0000 (09:42 -0400)] 
Module version bump for 6a03548.

15 years agoamavis uses uptime which reads utmp, and reads certs - from Dan Walsh
Jeremy Solt [Tue, 16 Mar 2010 19:55:16 +0000 (15:55 -0400)] 
amavis uses uptime which reads utmp, and reads certs - from Dan Walsh

15 years agoStyle fixes and module version bumps for 38fc1bd.
Chris PeBenito [Wed, 17 Mar 2010 13:28:18 +0000 (09:28 -0400)] 
Style fixes and module version bumps for 38fc1bd.

15 years agoLikewise policy.
Dominick Grift [Mon, 15 Mar 2010 17:13:34 +0000 (18:13 +0100)] 
Likewise policy.

Signed-off-by: Dominick Grift <domg472@gmail.com>
15 years agoModule version bump for 414a570.
Chris PeBenito [Tue, 16 Mar 2010 19:28:36 +0000 (15:28 -0400)] 
Module version bump for 414a570.

15 years agofetchmail executes programs in bin (uname), from Dan Walsh
Jeremy Solt [Tue, 16 Mar 2010 18:55:52 +0000 (14:55 -0400)] 
fetchmail executes programs in bin (uname), from Dan Walsh

15 years agoAdd additional documentation to kernel_request_load_module().
Chris PeBenito [Tue, 16 Mar 2010 19:08:00 +0000 (15:08 -0400)] 
Add additional documentation to kernel_request_load_module().

15 years agoModule version bump for 935151a.
Chris PeBenito [Tue, 16 Mar 2010 18:35:09 +0000 (14:35 -0400)] 
Module version bump for 935151a.

15 years agoModule version bump for d12f18e.
Chris PeBenito [Tue, 16 Mar 2010 18:34:50 +0000 (14:34 -0400)] 
Module version bump for d12f18e.

15 years agoModule version bump for d7ec247.
Chris PeBenito [Tue, 16 Mar 2010 18:34:23 +0000 (14:34 -0400)] 
Module version bump for d7ec247.

15 years agoModule version bump for 591af7b.
Chris PeBenito [Tue, 16 Mar 2010 18:34:05 +0000 (14:34 -0400)] 
Module version bump for 591af7b.

15 years agoModule version bump for ae07c9e.
Chris PeBenito [Tue, 16 Mar 2010 18:33:43 +0000 (14:33 -0400)] 
Module version bump for ae07c9e.

15 years agoWhitespace fixes in mailman.
Chris PeBenito [Tue, 16 Mar 2010 17:51:51 +0000 (13:51 -0400)] 
Whitespace fixes in mailman.