]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
17 years agotrunk: fix unconditional call to nscd from usermanage run interfaces.
Chris PeBenito [Mon, 15 Oct 2007 18:16:00 +0000 (18:16 +0000)] 
trunk: fix unconditional call to nscd from usermanage run interfaces.

17 years agotrunk: gdm is in /usr/sbin on rawhide machines, from Eamon Walsh.
Chris PeBenito [Mon, 15 Oct 2007 17:50:07 +0000 (17:50 +0000)] 
trunk: gdm is in /usr/sbin on rawhide machines, from Eamon Walsh.

17 years agotrunk: reorganize amanda and bind
Chris PeBenito [Fri, 12 Oct 2007 17:50:11 +0000 (17:50 +0000)] 
trunk: reorganize amanda and bind

17 years agotrunk: 2 patches from dan.
Chris PeBenito [Fri, 12 Oct 2007 17:35:56 +0000 (17:35 +0000)] 
trunk: 2 patches from dan.

17 years agotrunk: 10 patches from dan.
Chris PeBenito [Thu, 11 Oct 2007 18:12:29 +0000 (18:12 +0000)] 
trunk: 10 patches from dan.

17 years agoDeprecate some old file and dir permission set macros in favor of the newer, more...
Chris PeBenito [Tue, 9 Oct 2007 17:29:48 +0000 (17:29 +0000)] 
Deprecate some old file and dir permission set macros in favor of the newer, more consistently-named macros.

17 years agotrunk: remove stale user_net_control reference in usernetctl.if.
Chris PeBenito [Mon, 8 Oct 2007 13:38:25 +0000 (13:38 +0000)] 
trunk: remove stale user_net_control reference in usernetctl.if.

17 years agotrunk: Patch to clean up unescaped periods in several file context entries from Jan...
Chris PeBenito [Fri, 5 Oct 2007 18:00:55 +0000 (18:00 +0000)] 
trunk: Patch to clean up unescaped periods in several file context entries from Jan-Frode Myklebust.

17 years agotrunk: module version bumps for previous commit.
Chris PeBenito [Tue, 2 Oct 2007 17:15:07 +0000 (17:15 +0000)] 
trunk: module version bumps for previous commit.

17 years agotrunk: merge strict and targeted policies. merge shlib_t into lib_t.
Chris PeBenito [Tue, 2 Oct 2007 16:04:50 +0000 (16:04 +0000)] 
trunk: merge strict and targeted policies.  merge shlib_t into lib_t.

17 years agotrunk: update version and changelog for release.
Chris PeBenito [Fri, 28 Sep 2007 15:14:55 +0000 (15:14 +0000)] 
trunk: update version and changelog for release.

17 years agotrunk: update sources rpm spec file.
Chris PeBenito [Fri, 28 Sep 2007 15:14:18 +0000 (15:14 +0000)] 
trunk: update sources rpm spec file.

17 years agotrunk: bump version numbers for release.
Chris PeBenito [Fri, 28 Sep 2007 13:58:24 +0000 (13:58 +0000)] 
trunk: bump version numbers for release.

17 years agotrunk: Add support for setting the unknown permissions handling.
Chris PeBenito [Thu, 27 Sep 2007 13:41:09 +0000 (13:41 +0000)] 
trunk: Add support for setting the unknown permissions handling.

17 years agotrunk: one-liner from Shintaro Fujiwara
Chris PeBenito [Wed, 26 Sep 2007 14:28:20 +0000 (14:28 +0000)] 
trunk: one-liner from Shintaro Fujiwara

17 years agotrunk: xml doc one-liner from Stefan Schulze Frielinghaus.
Chris PeBenito [Mon, 24 Sep 2007 13:01:17 +0000 (13:01 +0000)] 
trunk: xml doc one-liner from Stefan Schulze Frielinghaus.

17 years agotrunk: Fix XML building for external reference builds and headers builds.
Chris PeBenito [Fri, 21 Sep 2007 15:06:58 +0000 (15:06 +0000)] 
trunk: Fix XML building for external reference builds and headers builds.

17 years agotrunk: one-liner from Shintaro Fujiwara.
Chris PeBenito [Tue, 18 Sep 2007 19:49:35 +0000 (19:49 +0000)] 
trunk: one-liner from Shintaro Fujiwara.

17 years agotrunk: Patch to add missing requirements in userdomain interfaces from Shintaro Fujiwara.
Chris PeBenito [Mon, 17 Sep 2007 18:04:35 +0000 (18:04 +0000)] 
trunk: Patch to add missing requirements in userdomain interfaces from Shintaro Fujiwara.

17 years agotrunk: add awstats from Stefan Schulze Frielinghaus.
Chris PeBenito [Mon, 17 Sep 2007 17:25:40 +0000 (17:25 +0000)] 
trunk: add awstats from Stefan Schulze Frielinghaus.

17 years agotrunk: add bitlbee from devin carraway and add tcpd_wrapped_domain().
Chris PeBenito [Mon, 17 Sep 2007 14:33:40 +0000 (14:33 +0000)] 
trunk: add bitlbee from devin carraway and add tcpd_wrapped_domain().

18 years agotrunk: 3 patches from dan.
Chris PeBenito [Wed, 12 Sep 2007 14:53:39 +0000 (14:53 +0000)] 
trunk: 3 patches from dan.

18 years agotrunk: 3 patches from dan.
Chris PeBenito [Tue, 11 Sep 2007 19:24:32 +0000 (19:24 +0000)] 
trunk: 3 patches from dan.

18 years agotrunk: 6 patches from dan.
Chris PeBenito [Fri, 7 Sep 2007 13:41:20 +0000 (13:41 +0000)] 
trunk: 6 patches from dan.

18 years agotrunk: two tiny patches from Stefan Schulze Frielinghaus
Chris PeBenito [Thu, 6 Sep 2007 19:29:54 +0000 (19:29 +0000)] 
trunk: two tiny patches from Stefan Schulze Frielinghaus

18 years agotrunk: six patches from dan.
Chris PeBenito [Thu, 6 Sep 2007 18:34:40 +0000 (18:34 +0000)] 
trunk: six patches from dan.

18 years agotrunk: udev update and brctl module from dan.
Chris PeBenito [Wed, 5 Sep 2007 17:55:57 +0000 (17:55 +0000)] 
trunk: udev update and brctl module from dan.

18 years agotrunk: 4 patches from dan.
Chris PeBenito [Wed, 5 Sep 2007 14:48:21 +0000 (14:48 +0000)] 
trunk: 4 patches from dan.

18 years agotrunk: 5 patches from dan.
Chris PeBenito [Tue, 4 Sep 2007 18:57:58 +0000 (18:57 +0000)] 
trunk: 5 patches from dan.

18 years agotrunk: make coda nfs_t, ticket #39.
Chris PeBenito [Tue, 4 Sep 2007 13:38:39 +0000 (13:38 +0000)] 
trunk: make coda nfs_t, ticket #39.

18 years agotrunk: fix certwatch_run() interface, which had a typo in the name.
Chris PeBenito [Thu, 30 Aug 2007 15:01:48 +0000 (15:01 +0000)] 
trunk: fix certwatch_run() interface, which had a typo in the name.

18 years agotrunk: fix example.if xml problems
Chris PeBenito [Wed, 29 Aug 2007 18:14:27 +0000 (18:14 +0000)] 
trunk: fix example.if xml problems

18 years agotrunk: 7 patches from dan, slocate, games, amavis, radius, sendmail, rshd, logrotate.
Chris PeBenito [Mon, 27 Aug 2007 17:57:36 +0000 (17:57 +0000)] 
trunk: 7 patches from dan, slocate, games, amavis, radius, sendmail, rshd, logrotate.

18 years agotrunk: patch to allow sendmail to read ssl/tls certificates from Stefan Schulze Friel...
Chris PeBenito [Mon, 27 Aug 2007 17:00:18 +0000 (17:00 +0000)] 
trunk: patch to allow sendmail to read ssl/tls certificates from Stefan Schulze Frielinghaus.

18 years agotrunk: add missing commas in can_exec in daemontools that worked by luck.
Chris PeBenito [Fri, 24 Aug 2007 15:55:06 +0000 (15:55 +0000)] 
trunk: add missing commas in can_exec in daemontools that worked by luck.

18 years agoUpdate MLS constraints from LSPP evaluated policy.
Chris PeBenito [Fri, 24 Aug 2007 14:14:29 +0000 (14:14 +0000)] 
Update MLS constraints from LSPP evaluated policy.

18 years agotrunk: switch daemons from inheriting from all levels to initrc_t sharing to all...
Chris PeBenito [Wed, 22 Aug 2007 20:21:52 +0000 (20:21 +0000)] 
trunk: switch daemons from inheriting from all levels to initrc_t sharing to all levels.

18 years agotrunk: updates from dan on 9 modules
Chris PeBenito [Wed, 22 Aug 2007 20:02:41 +0000 (20:02 +0000)] 
trunk: updates from dan on 9 modules

18 years agotrunk: add some info to the readme about building from headers
Chris PeBenito [Wed, 22 Aug 2007 15:34:23 +0000 (15:34 +0000)] 
trunk: add some info to the readme about building from headers

18 years agotrunk: Files and radvd updates from Stefan Schulze Frielinghaus.
Chris PeBenito [Tue, 21 Aug 2007 19:03:34 +0000 (19:03 +0000)] 
trunk: Files and radvd updates from Stefan Schulze Frielinghaus.

18 years agotrunk: fix gdm xsession scripts on redhat machines.
Chris PeBenito [Mon, 20 Aug 2007 18:54:29 +0000 (18:54 +0000)] 
trunk: fix gdm xsession scripts on redhat machines.

18 years agotrunk: Deprecate mls_file_write_down() and mls_file_read_up(), replaced with mls_writ...
Chris PeBenito [Mon, 20 Aug 2007 18:26:08 +0000 (18:26 +0000)] 
trunk: Deprecate mls_file_write_down() and mls_file_read_up(), replaced with mls_write_all_levels() and mls_read_all_levels(), for consistency.

18 years agotrunk: several MLS enhancements.
Chris PeBenito [Mon, 20 Aug 2007 15:15:03 +0000 (15:15 +0000)] 
trunk: several MLS enhancements.

18 years agotrunk: Database userspace object manager classes from KaiGai Kohei.
Chris PeBenito [Thu, 9 Aug 2007 13:15:07 +0000 (13:15 +0000)] 
trunk: Database userspace object manager classes from KaiGai Kohei.

18 years agotrunk: filesystem patch from dan
Chris PeBenito [Wed, 8 Aug 2007 20:04:28 +0000 (20:04 +0000)] 
trunk: filesystem patch from dan

18 years agotrunk: 3 patches from dan
Chris PeBenito [Tue, 7 Aug 2007 17:06:32 +0000 (17:06 +0000)] 
trunk: 3 patches from dan

18 years agotrunk: several support macro fixes.
Chris PeBenito [Tue, 31 Jul 2007 15:11:22 +0000 (15:11 +0000)] 
trunk: several support macro fixes.

18 years agotrunk: add 3rd party interface for apache cgi.
Chris PeBenito [Thu, 26 Jul 2007 19:48:40 +0000 (19:48 +0000)] 
trunk: add 3rd party interface for apache cgi.

18 years agotrunk: fix pipe permission set in domtrans_pattern().
Chris PeBenito [Thu, 26 Jul 2007 19:41:15 +0000 (19:41 +0000)] 
trunk: fix pipe permission set in domtrans_pattern().

18 years agotrunk: add getserv and shmemserv nscd permissions.
Chris PeBenito [Tue, 24 Jul 2007 19:52:18 +0000 (19:52 +0000)] 
trunk: add getserv and shmemserv nscd permissions.

18 years agotrunk: fix targeted sshd. When the domain was unaliased from unconfined_t, a transit...
Chris PeBenito [Fri, 20 Jul 2007 18:25:26 +0000 (18:25 +0000)] 
trunk: fix targeted sshd.  When the domain was unaliased from unconfined_t, a transition to unconfined_t was not added.

18 years agotrunk: add application module
Chris PeBenito [Thu, 19 Jul 2007 18:57:48 +0000 (18:57 +0000)] 
trunk: add application module

18 years agotrunk: fix missed netlabel deprecation
Chris PeBenito [Thu, 19 Jul 2007 15:11:19 +0000 (15:11 +0000)] 
trunk: fix missed netlabel deprecation

18 years agotrunk: Add debian apcupsd binary location, from Stefan Schulze Frielinghaus.
Chris PeBenito [Mon, 2 Jul 2007 15:25:46 +0000 (15:25 +0000)] 
trunk: Add debian apcupsd binary location, from Stefan Schulze Frielinghaus.

18 years agotrunk: updated version and changelog for release
Chris PeBenito [Fri, 29 Jun 2007 15:30:58 +0000 (15:30 +0000)] 
trunk: updated version and changelog for release

18 years agotrunk: update module version numbers for release.
Chris PeBenito [Fri, 29 Jun 2007 14:48:13 +0000 (14:48 +0000)] 
trunk: update module version numbers for release.

18 years agoFix incorrectly named files_lib_filetrans_shared_lib() interface in the libraries...
Chris PeBenito [Thu, 28 Jun 2007 17:25:46 +0000 (17:25 +0000)] 
Fix incorrectly named files_lib_filetrans_shared_lib() interface in the libraries module.

18 years agotrunk: add templates to tags generation
Chris PeBenito [Thu, 28 Jun 2007 13:13:55 +0000 (13:13 +0000)] 
trunk: add templates to tags generation

18 years agotrunk, strict-targeted-merge: add mmap_zero to xserver domains.
Chris PeBenito [Thu, 28 Jun 2007 12:34:08 +0000 (12:34 +0000)] 
trunk, strict-targeted-merge: add mmap_zero to xserver domains.

18 years agotrunk: minor amanda update from dan
Chris PeBenito [Wed, 27 Jun 2007 19:19:20 +0000 (19:19 +0000)] 
trunk: minor amanda update from dan

18 years agotrunk: add rpcbind from dan
Chris PeBenito [Wed, 27 Jun 2007 16:31:55 +0000 (16:31 +0000)] 
trunk: add rpcbind from dan

18 years agotrunk: Unified labeled networking policy from Paul Moore.
Chris PeBenito [Wed, 27 Jun 2007 15:23:21 +0000 (15:23 +0000)] 
trunk: Unified labeled networking policy from Paul Moore.

The latest revision of the labeled policy patches which enable both labeled
and unlabeled policy support for NetLabel.  This revision takes into account
Chris' feedback from the first version and reduces the number of interface
calls in each domain down to two at present: one for unlabeled access, one for
NetLabel access.  The older, transport layer specific interfaces, are still
present for use by third-party modules but are not used in the default policy
modules.

trunk: Use netmsg initial SID for MLS-only Netlabel packets, from Paul Moore.

This patch changes the policy to use the netmsg initial SID as the "base"
SID/context for NetLabel packets which only have MLS security attributes.
Currently we use the unlabeled initial SID which makes it very difficult to
distinquish between actual unlabeled packets and those packets which have MLS
security attributes.

18 years agotrunk: pyzor and clamav updates from dan
Chris PeBenito [Tue, 26 Jun 2007 18:43:11 +0000 (18:43 +0000)] 
trunk: pyzor and clamav updates from dan

18 years agotrunk: fix typo in vmware.fc
Chris PeBenito [Tue, 26 Jun 2007 14:31:31 +0000 (14:31 +0000)] 
trunk: fix typo in vmware.fc

18 years agotrunk: nagios update from dan
Chris PeBenito [Thu, 21 Jun 2007 17:23:19 +0000 (17:23 +0000)] 
trunk: nagios update from dan

18 years agotrunk: procmail tweak from dan.
Chris PeBenito [Thu, 21 Jun 2007 14:54:34 +0000 (14:54 +0000)] 
trunk: procmail tweak from dan.

18 years agotrunk: xen updates from dan
Chris PeBenito [Thu, 21 Jun 2007 13:36:05 +0000 (13:36 +0000)] 
trunk: xen updates from dan

18 years agotrunk: trivial gentoo tweaks
Chris PeBenito [Wed, 20 Jun 2007 20:08:26 +0000 (20:08 +0000)] 
trunk: trivial gentoo tweaks

18 years agotrunk: 3 patches from dan
Chris PeBenito [Wed, 20 Jun 2007 19:47:10 +0000 (19:47 +0000)] 
trunk: 3 patches from dan

18 years agotrunk: radius one-liner from dan
Chris PeBenito [Wed, 20 Jun 2007 15:03:55 +0000 (15:03 +0000)] 
trunk: radius one-liner from dan

18 years agotrunk: big samba update from dan
Chris PeBenito [Tue, 19 Jun 2007 19:11:35 +0000 (19:11 +0000)] 
trunk: big samba update from dan

18 years agotrunk: drop snmpd_etc_t.
Chris PeBenito [Tue, 19 Jun 2007 17:39:35 +0000 (17:39 +0000)] 
trunk: drop snmpd_etc_t.

18 years agotrunk: confine sendmail and logrotate on targeted
Chris PeBenito [Tue, 19 Jun 2007 17:01:39 +0000 (17:01 +0000)] 
trunk: confine sendmail and logrotate on targeted

18 years agotrunk: Tunable connection to postgresql for users from KaiGai Kohei.
Chris PeBenito [Tue, 19 Jun 2007 14:30:06 +0000 (14:30 +0000)] 
trunk: Tunable connection to postgresql for users from KaiGai Kohei.

18 years agoMemprotect support patch from Stephen Smalley.
Chris PeBenito [Tue, 19 Jun 2007 13:02:26 +0000 (13:02 +0000)] 
Memprotect support patch from Stephen Smalley.

18 years agotrunk: 2 patches from dan
Chris PeBenito [Wed, 13 Jun 2007 13:54:56 +0000 (13:54 +0000)] 
trunk: 2 patches from dan

18 years agotrunk: add amtu from dan
Chris PeBenito [Tue, 12 Jun 2007 18:58:36 +0000 (18:58 +0000)] 
trunk: add amtu from dan

18 years agotrunk: Add logging_send_audit_msgs() interface and deprecate send_audit_msgs_pattern().
Chris PeBenito [Tue, 12 Jun 2007 18:46:14 +0000 (18:46 +0000)] 
trunk: Add logging_send_audit_msgs() interface and deprecate send_audit_msgs_pattern().

18 years agotrunk: version bumps for previous commit.
Chris PeBenito [Tue, 12 Jun 2007 13:08:19 +0000 (13:08 +0000)] 
trunk: version bumps for previous commit.

18 years agotrunk: 7 simple patches from dan.
Chris PeBenito [Tue, 12 Jun 2007 13:06:13 +0000 (13:06 +0000)] 
trunk: 7 simple patches from dan.

18 years agotrunk: 3 patches from dan
Chris PeBenito [Mon, 11 Jun 2007 15:43:37 +0000 (15:43 +0000)] 
trunk: 3 patches from dan

18 years agotrunk: 5 patches from dan
Chris PeBenito [Mon, 11 Jun 2007 15:01:10 +0000 (15:01 +0000)] 
trunk: 5 patches from dan

18 years agosix simple patches from dan
Chris PeBenito [Mon, 11 Jun 2007 14:09:09 +0000 (14:09 +0000)] 
six simple patches from dan

18 years agoadd fc entry for make_reiser4
Chris PeBenito [Fri, 8 Jun 2007 20:01:34 +0000 (20:01 +0000)] 
add fc entry for make_reiser4

18 years agotrunk: fix line in evolution to be strict-only; was being covered up by genhomedircon.
Chris PeBenito [Tue, 22 May 2007 17:01:38 +0000 (17:01 +0000)] 
trunk: fix line in evolution to be strict-only; was being covered up by genhomedircon.

18 years agotrunk: snmp tweak from dan
Chris PeBenito [Tue, 15 May 2007 18:06:31 +0000 (18:06 +0000)] 
trunk: snmp tweak from dan

18 years agotrunk: remaining pieces for apcupsd module
Chris PeBenito [Tue, 15 May 2007 15:43:00 +0000 (15:43 +0000)] 
trunk: remaining pieces for apcupsd module

18 years agotrunk: long overdue cleanup from when range_transitions were only in the base module
Chris PeBenito [Mon, 14 May 2007 15:35:47 +0000 (15:35 +0000)] 
trunk: long overdue cleanup from when range_transitions were only in the base module

18 years agomerge restorecon into setfiles
Chris PeBenito [Fri, 11 May 2007 17:10:43 +0000 (17:10 +0000)] 
merge restorecon into setfiles

18 years agoPatch to begin separating out hald helper programs from Dan Walsh.
Chris PeBenito [Mon, 7 May 2007 17:57:48 +0000 (17:57 +0000)] 
Patch to begin separating out hald helper programs from Dan Walsh.

18 years agoadd apcupsd from dan
Chris PeBenito [Mon, 7 May 2007 14:55:54 +0000 (14:55 +0000)] 
add apcupsd from dan

18 years agoFixes for squid, dovecot, and snmp from Dan Walsh.
Chris PeBenito [Mon, 7 May 2007 13:45:17 +0000 (13:45 +0000)] 
Fixes for squid, dovecot, and snmp from Dan Walsh.

18 years agoMiscellaneous consolekit fixes from Dan Walsh.
Chris PeBenito [Thu, 3 May 2007 14:15:38 +0000 (14:15 +0000)] 
Miscellaneous consolekit fixes from Dan Walsh.

18 years agotextrel lib update from dan
Chris PeBenito [Thu, 3 May 2007 13:43:44 +0000 (13:43 +0000)] 
textrel lib update from dan

18 years agoadd missing rename_dir_perms
Chris PeBenito [Thu, 3 May 2007 13:15:48 +0000 (13:15 +0000)] 
add missing rename_dir_perms

18 years agoPatch to have avahi use the nsswitch interface rather than individual permissions...
Chris PeBenito [Thu, 3 May 2007 12:45:28 +0000 (12:45 +0000)] 
Patch to have avahi use the nsswitch interface rather than individual permissions from Dan Walsh.

18 years agoPatch to dontaudit logrotate searching avahi pid directory from Dan Walsh.
Chris PeBenito [Wed, 2 May 2007 17:55:03 +0000 (17:55 +0000)] 
Patch to dontaudit logrotate searching avahi pid directory from Dan Walsh.

18 years ago- Patch to allow insmod to mount kvmfs and dontaudit rw unconfined_t pipes
Chris PeBenito [Wed, 2 May 2007 17:31:38 +0000 (17:31 +0000)] 
- Patch to allow insmod to mount kvmfs and dontaudit rw unconfined_t pipes
  to handle usage from userhelper.

18 years agoadd rwho from Nalin Dahyabhai
Chris PeBenito [Mon, 30 Apr 2007 17:39:01 +0000 (17:39 +0000)] 
add rwho from Nalin Dahyabhai

18 years agoPatch to allow amavis to read spamassassin libraries from Dan Walsh.
Chris PeBenito [Mon, 30 Apr 2007 15:19:47 +0000 (15:19 +0000)] 
Patch to allow amavis to read spamassassin libraries from Dan Walsh.