]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Chris PeBenito [Mon, 19 Apr 2010 14:20:19 +0000 (10:20 -0400)]
Additional whitespace fix in nis.
Jeremy Solt [Mon, 12 Apr 2010 20:02:45 +0000 (16:02 -0400)]
Style changes
Jeremy Solt [Fri, 9 Apr 2010 15:52:54 +0000 (11:52 -0400)]
nis patch from Dan Walsh
Made a couple style changes.
Removed unnecessary require in nis_use_ypbind interface
Chris PeBenito [Mon, 19 Apr 2010 14:17:24 +0000 (10:17 -0400)]
Additional whitespace fixes in certmonger.
Jeremy Solt [Mon, 12 Apr 2010 19:54:18 +0000 (15:54 -0400)]
Fix some whitespace and style issues.
Jeremy Solt [Fri, 9 Apr 2010 17:05:52 +0000 (13:05 -0400)]
certmonger policy from Dan Walsh
Removed manage_var_run and manage_var_lib interfaces
Added missing requires to admin interface
Removed permissive line
Fixed some spacing / style issues
Chris PeBenito [Mon, 19 Apr 2010 14:05:22 +0000 (10:05 -0400)]
Module version bump for
4f7b413 .
Jeremy Solt [Mon, 12 Apr 2010 19:31:43 +0000 (15:31 -0400)]
Remove excess white space from ntop.te
Move ntop ports declaration to correct location.
Jeremy Solt [Thu, 8 Apr 2010 14:28:53 +0000 (10:28 -0400)]
Ntop policy from Dan Walsh
Added alias for ntop_http_content_t in apache
Pulled in ntop port from corenetwork patch
Chris PeBenito [Mon, 19 Apr 2010 13:54:13 +0000 (09:54 -0400)]
Module version bump for
46e16a2 .
Jeremy Solt [Mon, 12 Apr 2010 19:23:36 +0000 (15:23 -0400)]
Move optional policy to correct location for style
Jeremy Solt [Thu, 8 Apr 2010 20:02:18 +0000 (16:02 -0400)]
kerberos patch from Dan Walsh
Chris PeBenito [Tue, 13 Apr 2010 15:55:04 +0000 (11:55 -0400)]
Use port range notation in corenetwork where it makes sense.
Chris PeBenito [Tue, 13 Apr 2010 15:52:09 +0000 (11:52 -0400)]
Clean up output of generated corenetwork.te.
Chris PeBenito [Tue, 13 Apr 2010 15:06:02 +0000 (11:06 -0400)]
Fix network_port() in corenetwork to correctly handle port ranges.
KaiGai Kohei [Mon, 12 Apr 2010 14:14:10 +0000 (10:14 -0400)]
[BUGFIX] lack of type transition on dbadm domain (Re: dbadm.pp is not available in selinux-policy package)
I found out a bug when we initialize the database with dbadm_r:dbadm_t
which belongs to sepgsql_admin_type attribute.
In the case when sepgsql_admin_type create a new database objects,
it does not have valid type_transition rules. So, it was failed.
Sorry, I didn't find out it for a long time.
And db_procedure:{execute} on the sepgsql_proc_exec_t might be necessary
for the administrative domain independently from sepgsql_unconfined_dbadm,
because we need to execute some of system defined procedures to look up
system tables.
Chris PeBenito [Mon, 12 Apr 2010 14:01:39 +0000 (10:01 -0400)]
Module version bump for
5d3214f and
795b733 .
Jeremy Solt [Fri, 9 Apr 2010 14:14:05 +0000 (10:14 -0400)]
pcscd patch from Dan Walsh: manage pub files and fifo files
Jeremy Solt [Thu, 8 Apr 2010 19:29:56 +0000 (15:29 -0400)]
gpsd path from Dan Walsh
Chris PeBenito [Wed, 7 Apr 2010 12:55:33 +0000 (08:55 -0400)]
Add devtmpfs labeling.
Dominick Grift [Tue, 6 Apr 2010 13:24:23 +0000 (15:24 +0200)]
Move kernel_request_load_module(gssd_t) to the proper place.
Signed-off-by: Dominick Grift <domg472@gmail.com>
Dominick Grift [Tue, 6 Apr 2010 13:22:42 +0000 (15:22 +0200)]
Fix requires for apache tmp interfaces.
Signed-off-by: Dominick Grift <domg472@gmail.com>
Chris PeBenito [Mon, 5 Apr 2010 18:50:23 +0000 (14:50 -0400)]
Portreserve patch from Dan Walsh.
Chris PeBenito [Mon, 5 Apr 2010 18:38:30 +0000 (14:38 -0400)]
PPP patch from Dan Walsh.
Chris PeBenito [Mon, 5 Apr 2010 18:26:21 +0000 (14:26 -0400)]
Rpc patch from Dan Walsh.
Chris PeBenito [Mon, 5 Apr 2010 18:05:05 +0000 (14:05 -0400)]
Whitespace fixes on Apache.
Chris PeBenito [Mon, 5 Apr 2010 17:49:00 +0000 (13:49 -0400)]
Module version bump for
170a46d ,
f8b3b7f , and
a49a82c .
Chris PeBenito [Mon, 5 Apr 2010 17:48:01 +0000 (13:48 -0400)]
Jeremy Solt [Wed, 31 Mar 2010 18:16:34 +0000 (14:16 -0400)]
snort patch from Dan Walsh
Didn't rearrange all the kernel calls, but did add the kernel_request_load_module.
Didn't include the usbmod (doesn't exist in refpolicy at this time).
Included the generic usb device permissions because snort uses libpcap, which can also be used to monitor USB traffic, so this may be a side effect.
From the red hat bug (559861), it sounds as though snort was failing without these permissions, so it doesn't look like a dontaudit would work.
Jeremy Solt [Wed, 31 Mar 2010 19:23:29 +0000 (15:23 -0400)]
Nut policy from Dan Walsh
Dropped optional policy for shutdown_domtrans
Dropped commented can_exec line
Jeremy Solt [Thu, 1 Apr 2010 14:49:29 +0000 (10:49 -0400)]
memcached patch from Dan Walsh
Moved term_dontaudits up for style
Chris PeBenito [Mon, 5 Apr 2010 14:57:52 +0000 (10:57 -0400)]
Second part of Apache patch from Dan Walsh.
Chris PeBenito [Thu, 1 Apr 2010 12:17:50 +0000 (08:17 -0400)]
First part of apache patch from Dan Walsh: file context changes, including renaming script ro/ra/rw files.
Chris PeBenito [Mon, 29 Mar 2010 18:30:52 +0000 (14:30 -0400)]
Tor patch from Dan Walsh.
Chris PeBenito [Mon, 29 Mar 2010 18:08:52 +0000 (14:08 -0400)]
Sssd patch from Dan Walsh.
Chris PeBenito [Mon, 29 Mar 2010 17:29:18 +0000 (13:29 -0400)]
Add usbmuxd from Dan Walsh.
Chris PeBenito [Mon, 29 Mar 2010 15:25:06 +0000 (11:25 -0400)]
Vhostmd from Dan Walsh.
Chris PeBenito [Mon, 29 Mar 2010 13:21:59 +0000 (09:21 -0400)]
Chris PeBenito [Mon, 29 Mar 2010 13:19:40 +0000 (09:19 -0400)]
Tweaks on pulseaudio
1868383 , ksmtuned
d279dd6 , and smokeping
f3c346c .
Jeremy Solt [Tue, 23 Mar 2010 18:43:08 +0000 (14:43 -0400)]
Smokeping policy from Dan Walsh
Made some style / spacing changes
Did not include read access to /etc/shadow
Removed manage_var_run and manage_var_lib interfaces
Removed permissive line
Jeremy Solt [Tue, 23 Mar 2010 19:51:04 +0000 (15:51 -0400)]
pulseaudio patch from Dan Walsh
Fixed template where it should have been interface
Replaced read_home and manage_home interfaces with read_home_files, manage_home_files and reduced access
Removed admin_dir reference
Replaced rtkit_daemon_system_domain with rtkit_scheduled
Fixed style / spacing issues
Jeremy Solt [Wed, 24 Mar 2010 14:29:39 +0000 (10:29 -0400)]
ksmtuned policy from Dan Walsh
Couple style/space fixes.
Used ps_process_pattern in admin interface
Jeremy Solt [Wed, 24 Mar 2010 13:46:14 +0000 (09:46 -0400)]
Prelude patch from Dan Walsh
Jeremy Solt [Wed, 24 Mar 2010 15:54:10 +0000 (11:54 -0400)]
Bluetooth patch (sys_admin and debugfs) from Dan Walsh
Added comments to reference redhat bugs
Jeremy Solt [Wed, 24 Mar 2010 18:19:30 +0000 (14:19 -0400)]
avahi patch from Dan Walsh
Didn't include the file read in the dbus_chat interface.
Jeremy Solt [Wed, 24 Mar 2010 19:57:15 +0000 (15:57 -0400)]
chronyd patch from Dan Walsh
Fixed a couple style/spacing issues.
Added files_search_etc for chronyd_keys file
Jeremy Solt [Thu, 25 Mar 2010 14:58:47 +0000 (10:58 -0400)]
Give dcc setgid from Dan Walsh
Chris PeBenito [Tue, 23 Mar 2010 12:07:19 +0000 (08:07 -0400)]
Module version bump for
c37d843 .
Chris PeBenito [Tue, 23 Mar 2010 12:05:00 +0000 (08:05 -0400)]
Minor bind XML tweaks.
Jeremy Solt [Mon, 22 Mar 2010 19:14:47 +0000 (15:14 -0400)]
bind patch from Dan Walsh
some fixes in interfaces, added bind_setattr_zone_dirs interface
sysnet_read_config not needed with auth_use_nsswitch
Did not include init_read_script_tmp_files for named_t
Chris PeBenito [Mon, 22 Mar 2010 19:19:50 +0000 (15:19 -0400)]
Radvd patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 19:09:27 +0000 (15:09 -0400)]
Rdisc patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 17:53:24 +0000 (13:53 -0400)]
Module version bump for
1d348bd .
Jeremy Solt [Mon, 22 Mar 2010 17:25:07 +0000 (13:25 -0400)]
Afs needs sys_admin, sends signals, and resolves hostnames from Dan Walsh
Chris PeBenito [Mon, 22 Mar 2010 17:51:35 +0000 (13:51 -0400)]
Module version bump for
75c8a69 .
Jeremy Solt [Mon, 22 Mar 2010 15:34:54 +0000 (11:34 -0400)]
gitosis read/manage lib interfaces from Dan Walsh
Only giving manage_files_pattern for gitosis_manage_lib_files
Chris PeBenito [Mon, 22 Mar 2010 15:22:25 +0000 (11:22 -0400)]
Sasl patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 15:08:31 +0000 (11:08 -0400)]
Snmp patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 14:47:41 +0000 (10:47 -0400)]
Sysstat patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 14:40:37 +0000 (10:40 -0400)]
Telnet patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 14:33:31 +0000 (10:33 -0400)]
Tuned patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 14:24:34 +0000 (10:24 -0400)]
Virt patch from Dan Walsh.
Chris PeBenito [Mon, 22 Mar 2010 13:54:58 +0000 (09:54 -0400)]
Rename rtkit_schedule() to rtkit_scheduled().
Chris PeBenito [Mon, 22 Mar 2010 12:59:04 +0000 (08:59 -0400)]
Module version bump for
ac19f1a .
Chris PeBenito [Mon, 22 Mar 2010 12:58:41 +0000 (08:58 -0400)]
Module version bump for
9681df1 .
Chris PeBenito [Mon, 22 Mar 2010 12:58:20 +0000 (08:58 -0400)]
Module version bump for
d3b5907 .
Chris PeBenito [Mon, 22 Mar 2010 12:56:32 +0000 (08:56 -0400)]
Minor tweaks on icecast.
Jeremy Solt [Fri, 19 Mar 2010 19:46:59 +0000 (15:46 -0400)]
icecast policy from Dan Walsh
Fixed some style and spacing issues
Replace manage_var_run interface with manage_pid_files with fewer permissions
Replaced rkit_daemon_system_domain with rtkit_schedule
Jeremy Solt [Fri, 19 Mar 2010 18:28:27 +0000 (14:28 -0400)]
rtkit patch from Dan Walsh:
rtkit_daemon_system_domain interface allows domains to say rtkit can setsched on their process.
Needs sys_nice capability
Needs to getsched on all domains.
Fix bug in te file
Me:
changed interface name from rtkit_daemon_system_domain to rtkit_schedule
Already had sys_nice capability
Jeremy Solt [Fri, 19 Mar 2010 17:51:32 +0000 (13:51 -0400)]
postgresql patch from Dan Walsh:
"File context for /etc/sysconfig/pgsql and other bugs.
Sends audit messages connect to posgresql_server port
Reads its own process info"
Moved signal interface for style.
Jeremy Solt [Fri, 19 Mar 2010 17:04:27 +0000 (13:04 -0400)]
openvpn needs ipc_lock capability, connects to http ports,
and manages net_conf_t files - from Dan Walsh
Chris PeBenito [Fri, 19 Mar 2010 19:56:14 +0000 (15:56 -0400)]
Tftp patch from Dan Walsh.
Chris PeBenito [Fri, 19 Mar 2010 19:49:12 +0000 (15:49 -0400)]
Uucp patch from Dan Walsh.
Chris PeBenito [Fri, 19 Mar 2010 19:45:25 +0000 (15:45 -0400)]
Zebra patch from Dan Walsh.
Chris PeBenito [Fri, 19 Mar 2010 18:21:23 +0000 (14:21 -0400)]
Libraries patch from Dan Walsh.
Chris PeBenito [Fri, 19 Mar 2010 15:54:50 +0000 (11:54 -0400)]
Xen patch from Dan Walsh.
Chris PeBenito [Fri, 19 Mar 2010 15:05:56 +0000 (11:05 -0400)]
Getty patch from Dan Walsh.
Chris PeBenito [Thu, 18 Mar 2010 19:40:04 +0000 (15:40 -0400)]
Sysnetwork patch from Dan Walsh.
Chris PeBenito [Thu, 18 Mar 2010 14:19:49 +0000 (10:19 -0400)]
Init patch from Dan Walsh.
Chris PeBenito [Thu, 18 Mar 2010 12:59:25 +0000 (08:59 -0400)]
Authlogin patch from Dan Walsh.
Chris PeBenito [Thu, 18 Mar 2010 12:10:21 +0000 (08:10 -0400)]
Iptables patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 19:17:48 +0000 (15:17 -0400)]
Udev patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 18:40:06 +0000 (14:40 -0400)]
Logging patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 17:52:07 +0000 (13:52 -0400)]
Ipsec patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 15:59:14 +0000 (11:59 -0400)]
Modutils patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 15:16:25 +0000 (11:16 -0400)]
Kernel patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 14:02:07 +0000 (10:02 -0400)]
Domain patch from Dan Walsh.
Chris PeBenito [Wed, 17 Mar 2010 13:42:46 +0000 (09:42 -0400)]
Module version bump for
6a03548 .
Jeremy Solt [Tue, 16 Mar 2010 19:55:16 +0000 (15:55 -0400)]
amavis uses uptime which reads utmp, and reads certs - from Dan Walsh
Chris PeBenito [Wed, 17 Mar 2010 13:28:18 +0000 (09:28 -0400)]
Style fixes and module version bumps for
38fc1bd .
Dominick Grift [Mon, 15 Mar 2010 17:13:34 +0000 (18:13 +0100)]
Likewise policy.
Signed-off-by: Dominick Grift <domg472@gmail.com>
Chris PeBenito [Tue, 16 Mar 2010 19:28:36 +0000 (15:28 -0400)]
Module version bump for
414a570 .
Jeremy Solt [Tue, 16 Mar 2010 18:55:52 +0000 (14:55 -0400)]
fetchmail executes programs in bin (uname), from Dan Walsh
Chris PeBenito [Tue, 16 Mar 2010 19:08:00 +0000 (15:08 -0400)]
Add additional documentation to kernel_request_load_module().
Chris PeBenito [Tue, 16 Mar 2010 18:35:09 +0000 (14:35 -0400)]
Module version bump for
935151a .
Chris PeBenito [Tue, 16 Mar 2010 18:34:50 +0000 (14:34 -0400)]
Module version bump for
d12f18e .
Chris PeBenito [Tue, 16 Mar 2010 18:34:23 +0000 (14:34 -0400)]
Module version bump for
d7ec247 .
Chris PeBenito [Tue, 16 Mar 2010 18:34:05 +0000 (14:34 -0400)]
Module version bump for
591af7b .
Chris PeBenito [Tue, 16 Mar 2010 18:33:43 +0000 (14:33 -0400)]
Module version bump for
ae07c9e .
Chris PeBenito [Tue, 16 Mar 2010 17:51:51 +0000 (13:51 -0400)]
Whitespace fixes in mailman.