]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
18 years agotrivial aide fix from dan
Chris PeBenito [Mon, 30 Apr 2007 15:09:15 +0000 (15:09 +0000)] 
trivial aide fix from dan

18 years agoPatch to allow slocate to getattr other filesystems and directories on those filesyst...
Chris PeBenito [Mon, 30 Apr 2007 15:01:19 +0000 (15:01 +0000)] 
Patch to allow slocate to getattr other filesystems and directories on those filesystems from Dan Walsh.

18 years agotrivial fix for netutils from dan
Chris PeBenito [Mon, 30 Apr 2007 14:44:04 +0000 (14:44 +0000)] 
trivial fix for netutils from dan

18 years agotrivial fix from dan for bluetooth
Chris PeBenito [Mon, 30 Apr 2007 14:33:12 +0000 (14:33 +0000)] 
trivial fix from dan for bluetooth

18 years agomissed piece of clip patch
Chris PeBenito [Mon, 30 Apr 2007 14:32:31 +0000 (14:32 +0000)] 
missed piece of clip patch

18 years agoFixes for RHEL4 from the CLIP project.
Chris PeBenito [Fri, 27 Apr 2007 15:08:15 +0000 (15:08 +0000)] 
Fixes for RHEL4 from the CLIP project.

18 years agoReplace the old lrrd fc entries with correct munin ones.
Chris PeBenito [Mon, 23 Apr 2007 17:36:35 +0000 (17:36 +0000)] 
Replace the old lrrd fc entries with correct munin ones.

18 years agoMove program admin template usage out of userdom_admin_user_template() to sysadm...
Chris PeBenito [Thu, 19 Apr 2007 14:30:57 +0000 (14:30 +0000)] 
Move program admin template usage out of userdom_admin_user_template() to sysadm policy in userdomain.te to fix usage of the template for third parties.

18 years agoFix clockspeed_run_cli() declaration, it was incorrectly defined as a template instea...
Chris PeBenito [Thu, 19 Apr 2007 14:24:02 +0000 (14:24 +0000)] 
Fix clockspeed_run_cli() declaration, it was incorrectly defined as a template instead of an interface.

18 years agofinal release entries for 20070417
Chris PeBenito [Tue, 17 Apr 2007 14:20:24 +0000 (14:20 +0000)] 
final release entries for 20070417

18 years agobump module versions for release
Chris PeBenito [Tue, 17 Apr 2007 13:28:09 +0000 (13:28 +0000)] 
bump module versions for release

18 years agolast piece of previous consolekit patch
Chris PeBenito [Wed, 11 Apr 2007 20:02:59 +0000 (20:02 +0000)] 
last piece of previous consolekit patch

18 years agoadd zabbix from dan
Chris PeBenito [Wed, 11 Apr 2007 18:55:44 +0000 (18:55 +0000)] 
add zabbix from dan

18 years ago5 patches from dan. confine insmod and udev on targeted, misc fc fixes, sasl kerbero...
Chris PeBenito [Wed, 11 Apr 2007 17:56:03 +0000 (17:56 +0000)] 
5 patches from dan.  confine insmod and udev on targeted, misc fc fixes, sasl kerberos use, and samba port fixes

18 years agomore consolekit updates from dan
Chris PeBenito [Wed, 11 Apr 2007 14:04:35 +0000 (14:04 +0000)] 
more consolekit updates from dan

18 years agolast piece of dan's previous patch
Chris PeBenito [Wed, 11 Apr 2007 13:31:10 +0000 (13:31 +0000)] 
last piece of dan's previous patch

18 years agoconfine ldconfig in targeted, from dan
Chris PeBenito [Tue, 10 Apr 2007 19:39:22 +0000 (19:39 +0000)] 
confine ldconfig in targeted, from dan

18 years agofrom dan:
Chris PeBenito [Tue, 10 Apr 2007 17:20:07 +0000 (17:20 +0000)] 
from dan:

kadmind trys to setattr on krb5kdc file.  Just a library checking access.

18 years agosix patches from dan
Chris PeBenito [Tue, 10 Apr 2007 13:10:58 +0000 (13:10 +0000)] 
six patches from dan

18 years agoman page updates from dan
Chris PeBenito [Mon, 2 Apr 2007 13:58:33 +0000 (13:58 +0000)] 
man page updates from dan

18 years agogentoo /lib can be a symlink on x86-64 systems
Chris PeBenito [Mon, 2 Apr 2007 13:33:18 +0000 (13:33 +0000)] 
gentoo /lib can be a symlink on x86-64 systems

18 years agofix http_script_domains, it was incorrectly applied to the content type rather than...
Chris PeBenito [Mon, 2 Apr 2007 13:20:55 +0000 (13:20 +0000)] 
fix http_script_domains, it was incorrectly applied to the content type rather than the script domain.  bug #24.

18 years agoemit "null" instead of NULL for userspace headers
Chris PeBenito [Fri, 30 Mar 2007 20:33:51 +0000 (20:33 +0000)] 
emit "null" instead of NULL for userspace headers

18 years agobools in modules fix to require the boolean in optionals that are part of the base...
Chris PeBenito [Fri, 30 Mar 2007 12:43:15 +0000 (12:43 +0000)] 
bools in modules fix to require the boolean in optionals that are part of the base module, and move bool declarations in the base module/monolithic

18 years agoadd refresh target to devel makefile which tries to reload all of the modules current...
Chris PeBenito [Thu, 29 Mar 2007 12:08:00 +0000 (12:08 +0000)] 
add refresh target to devel makefile which tries to reload all of the modules currently in the store.

18 years agoTwo patches from Paul Moore to for ipsec to remove redundant rules and have setkey...
Chris PeBenito [Wed, 28 Mar 2007 18:47:45 +0000 (18:47 +0000)] 
Two patches from Paul Moore to for ipsec to remove redundant rules and have setkey read the config file.

18 years agosix trivial patches from dan for iptables, netutils, ipsec, devices, filesystem and...
Chris PeBenito [Mon, 26 Mar 2007 20:47:29 +0000 (20:47 +0000)] 
six trivial patches from dan for iptables, netutils, ipsec, devices, filesystem and cpuspeed

18 years ago- Move booleans and tunables to modules when it is only used in a single
Chris PeBenito [Mon, 26 Mar 2007 18:41:45 +0000 (18:41 +0000)] 
- Move booleans and tunables to modules when it is only used in a single
  module.
- Add support for tunables and booleans local to a module.

18 years agoMerge sbin_t and ls_exec_t into bin_t.
Chris PeBenito [Fri, 23 Mar 2007 23:24:59 +0000 (23:24 +0000)] 
Merge sbin_t and ls_exec_t into bin_t.

18 years agoremove disable_trans booleans
Chris PeBenito [Fri, 23 Mar 2007 21:01:49 +0000 (21:01 +0000)] 
remove disable_trans booleans

18 years agoOutput different header sets for kernel and userland from flask headers.
Chris PeBenito [Fri, 23 Mar 2007 20:32:23 +0000 (20:32 +0000)] 
Output different header sets for kernel and userland from flask headers.

18 years agodeprecated pax class
Chris PeBenito [Fri, 23 Mar 2007 20:21:06 +0000 (20:21 +0000)] 
deprecated pax class

18 years agonetwork fix from dan
Chris PeBenito [Thu, 22 Mar 2007 14:33:00 +0000 (14:33 +0000)] 
network fix from dan

18 years agoone-liner from dan
Chris PeBenito [Thu, 22 Mar 2007 14:01:55 +0000 (14:01 +0000)] 
one-liner from dan

18 years agopatch from dan to have ricci modstorage transition to lvm
Chris PeBenito [Wed, 21 Mar 2007 20:02:50 +0000 (20:02 +0000)] 
patch from dan to have ricci modstorage transition to lvm

18 years agostop adding netfilter contexts, as decided at the developers summit
Chris PeBenito [Wed, 21 Mar 2007 19:40:55 +0000 (19:40 +0000)] 
stop adding netfilter contexts, as decided at the developers summit

18 years agoadd fail2ban from dan
Chris PeBenito [Wed, 21 Mar 2007 15:51:52 +0000 (15:51 +0000)] 
add fail2ban from dan

18 years agokudzu will telinit to make init re-read the inittab after configuring serial consoles
Chris PeBenito [Tue, 20 Mar 2007 19:00:35 +0000 (19:00 +0000)] 
kudzu will telinit to make init re-read the inittab after configuring serial consoles

18 years agoAdd dontaudits for init fds and console to init_daemon_domain().
Chris PeBenito [Tue, 20 Mar 2007 18:47:18 +0000 (18:47 +0000)] 
Add dontaudits for init fds and console to init_daemon_domain().

18 years agocreate user gpg keys dir patch from dan
Chris PeBenito [Mon, 19 Mar 2007 19:10:43 +0000 (19:10 +0000)] 
create user gpg keys dir patch from dan

18 years agoadd kvmfs support, from dan
Chris PeBenito [Mon, 19 Mar 2007 18:48:14 +0000 (18:48 +0000)] 
add kvmfs support, from dan

18 years agotrivial patch for radius from dan
Chris PeBenito [Mon, 19 Mar 2007 18:42:57 +0000 (18:42 +0000)] 
trivial patch for radius from dan

18 years agotrivial patch from dan for sysstat access to sysfs
Chris PeBenito [Mon, 19 Mar 2007 18:38:54 +0000 (18:38 +0000)] 
trivial patch from dan for sysstat access to sysfs

18 years agoother part of consolekit addition
Chris PeBenito [Mon, 19 Mar 2007 18:36:36 +0000 (18:36 +0000)] 
other part of consolekit addition

18 years agofrom Dan:
Chris PeBenito [Mon, 19 Mar 2007 18:01:15 +0000 (18:01 +0000)] 
from Dan:
This is a new policy for the User Switching capability coming in gnome.

consolekit is a daemon that communicates with xdm_t and hal through dbus to change the
ownership/access on certain devices when the login session changes from one user to another

18 years agopatch from Dan for sudo:
Chris PeBenito [Mon, 19 Mar 2007 16:32:44 +0000 (16:32 +0000)] 
patch from Dan for sudo:
sudo should be able to getattr on all executables not just
bin_t/sbin_t.  Confined executeables run from sudo need this.

sudo_exec_t needs to be marked as exec_type so prelink will work correctly.

sudo semanage should work

18 years agoIt was just pointed out to me that the raw IP socket class is missing from the
Chris PeBenito [Fri, 9 Mar 2007 14:45:19 +0000 (14:45 +0000)] 
It was just pointed out to me that the raw IP socket class is missing from the
recvfrom MLS constraint.

Signed-off-by: Paul Moore
18 years agofix for rh bug 203290
Chris PeBenito [Thu, 8 Mar 2007 19:01:21 +0000 (19:01 +0000)] 
fix for rh bug 203290

18 years agolast bit of dans patch
Chris PeBenito [Thu, 8 Mar 2007 17:53:52 +0000 (17:53 +0000)] 
last bit of dans patch

18 years agoPatch for handling restart of nscd when ran from useradd, groupadd, and admin passwd...
Chris PeBenito [Thu, 8 Mar 2007 15:14:45 +0000 (15:14 +0000)] 
Patch for handling restart of nscd when ran from useradd, groupadd, and admin passwd, from Dan Walsh.

18 years agoprocmail uses /tmp files
Chris PeBenito [Wed, 7 Mar 2007 21:33:22 +0000 (21:33 +0000)] 
procmail uses /tmp files
Wants to send signull to itself
Can exec ls
Read spamassinn_lib_dirs
New directory for spamassin /var/lib/
pyzor uses tmp files

18 years agotrivial change from dan
Chris PeBenito [Tue, 6 Mar 2007 17:44:26 +0000 (17:44 +0000)] 
trivial change from dan

18 years agosetroubleshoot has a plugin that checks the file context on disk versus a matchpathco...
Chris PeBenito [Tue, 6 Mar 2007 17:16:08 +0000 (17:16 +0000)] 
setroubleshoot has a plugin that checks the file context on disk versus a matchpathcon.  So needs additional privs

18 years agoPatch for gssd fixes from Dan Walsh
Chris PeBenito [Tue, 6 Mar 2007 16:18:59 +0000 (16:18 +0000)] 
Patch for gssd fixes from Dan Walsh

18 years agopatches for lvm and ricci fixes from Dan Walsh.
Chris PeBenito [Tue, 6 Mar 2007 15:35:02 +0000 (15:35 +0000)] 
patches for lvm and ricci fixes from Dan Walsh.

18 years agolmtp and smtp are the same file require same context of setfiles complains
Chris PeBenito [Thu, 1 Mar 2007 20:41:19 +0000 (20:41 +0000)] 
lmtp and smtp are the same file require same context of setfiles complains
postfix_pickup_t wants to read postfix_spool_maildrop_t dir

18 years agopatches for file contexts in networkmanager, miscfiles, corecommands, devices, and...
Chris PeBenito [Thu, 1 Mar 2007 15:43:39 +0000 (15:43 +0000)] 
patches for file contexts in networkmanager, miscfiles, corecommands, devices, and java from Dan Walsh.

18 years agoPatch for kerberized telnet fixes from Dan Walsh.
Chris PeBenito [Wed, 28 Feb 2007 17:17:52 +0000 (17:17 +0000)] 
Patch for kerberized telnet fixes from Dan Walsh.

18 years agoPatch for kerberized ftp and other ftp fixes from Dan Walsh.
Chris PeBenito [Wed, 28 Feb 2007 17:01:47 +0000 (17:01 +0000)] 
Patch for kerberized ftp and other ftp fixes from Dan Walsh.

18 years agoPatch for an additional wine executable from Dan Walsh.
Chris PeBenito [Wed, 28 Feb 2007 16:23:06 +0000 (16:23 +0000)] 
Patch for an additional wine executable from Dan Walsh.

18 years agoPatch for additional games file contexts from Dan Walsh.
Chris PeBenito [Wed, 28 Feb 2007 15:30:38 +0000 (15:30 +0000)] 
Patch for additional games file contexts from Dan Walsh.

18 years agoAdd support for libselinux 2.0.5 init_selinuxmnt() changes.
Chris PeBenito [Tue, 27 Feb 2007 17:02:35 +0000 (17:02 +0000)] 
Add support for libselinux 2.0.5 init_selinuxmnt() changes.

18 years agofix man page patch from dan walsh
Chris PeBenito [Mon, 26 Feb 2007 20:44:35 +0000 (20:44 +0000)] 
fix man page patch from dan walsh

18 years agoadd init_exec() to init_telinit().
Chris PeBenito [Mon, 26 Feb 2007 20:19:53 +0000 (20:19 +0000)] 
add init_exec() to init_telinit().

18 years agoPatch for misc fixes to bluetooth from Dan Walsh.
Chris PeBenito [Mon, 26 Feb 2007 17:23:52 +0000 (17:23 +0000)] 
Patch for misc fixes to bluetooth from Dan Walsh.

18 years agoOn Tue, 2007-02-20 at 12:02 -0500, Daniel J Walsh wrote:
Chris PeBenito [Mon, 26 Feb 2007 17:04:56 +0000 (17:04 +0000)] 
On Tue, 2007-02-20 at 12:02 -0500, Daniel J Walsh wrote:
> Eliminate excess avc messages created when using kerberos libraries
>
> krb5kdc wans to setsched
>
> Also uses a fifo_file to communicate.
>
> Needs to search_network_sysctl

18 years agoPatch to start deprecating usercanread attribute from Ryan Bradetich.
Chris PeBenito [Mon, 26 Feb 2007 16:13:23 +0000 (16:13 +0000)] 
Patch to start deprecating usercanread attribute from Ryan Bradetich.

18 years agoadd dccp_socket object class
Chris PeBenito [Mon, 26 Feb 2007 15:39:59 +0000 (15:39 +0000)] 
add dccp_socket object class

18 years agoOn Tue, 2007-02-20 at 12:30 -0500, Daniel J Walsh wrote:
Chris PeBenito [Fri, 23 Feb 2007 21:20:46 +0000 (21:20 +0000)] 
On Tue, 2007-02-20 at 12:30 -0500, Daniel J Walsh wrote:
> prelink creates temporarly files that it then needs to relabel.

18 years agoOn Tue, 2007-02-20 at 12:28 -0500, Daniel J Walsh wrote:
Chris PeBenito [Fri, 23 Feb 2007 20:19:29 +0000 (20:19 +0000)] 
On Tue, 2007-02-20 at 12:28 -0500, Daniel J Walsh wrote:
> audit needs fsetid
>
> syslog needs to be able to create a tcp_socket for off machine logging.

18 years agoPatch to remove redundant mls_trusted_object() call from Dan Walsh.
Chris PeBenito [Fri, 23 Feb 2007 20:05:12 +0000 (20:05 +0000)] 
Patch to remove redundant mls_trusted_object() call from Dan Walsh.

18 years agoPatch for misc fixes to nis ypxfr policy from Dan Walsh.
Chris PeBenito [Fri, 23 Feb 2007 19:52:52 +0000 (19:52 +0000)] 
Patch for misc fixes to nis ypxfr policy from Dan Walsh.

18 years agoPatch to allow apmd to telinit from Dan Walsh.
Chris PeBenito [Fri, 23 Feb 2007 19:41:41 +0000 (19:41 +0000)] 
Patch to allow apmd to telinit from Dan Walsh.

18 years agoWhile using samba and SELinux with Debian GNU/Linux (etch) the
Chris PeBenito [Fri, 23 Feb 2007 19:30:17 +0000 (19:30 +0000)] 
While using samba and SELinux with Debian GNU/Linux (etch) the
following files need to be labeled correctly:
/var/run/samba/gencache.tdb
/var/run/samba/share_info.tdb

Should also concern other distributions than Debian.

-Stefan

18 years agoPatch to remove incorrect cron labeling in apache.fc from Ryan Bradetich.
Chris PeBenito [Fri, 23 Feb 2007 19:08:45 +0000 (19:08 +0000)] 
Patch to remove incorrect cron labeling in apache.fc from Ryan Bradetich.

18 years agomake ttys and ptys device nodes
Chris PeBenito [Tue, 20 Feb 2007 20:17:07 +0000 (20:17 +0000)] 
make ttys and ptys device nodes

18 years agopatch from dan, Thu, 2007-01-25 at 08:12 -0500
Chris PeBenito [Fri, 16 Feb 2007 23:01:42 +0000 (23:01 +0000)] 
patch from dan, Thu, 2007-01-25 at 08:12 -0500

18 years agoFix explicit use of httpd_t in openca_domtrans(), bug #22.
Chris PeBenito [Wed, 7 Feb 2007 22:16:18 +0000 (22:16 +0000)] 
Fix explicit use of httpd_t in openca_domtrans(), bug #22.

18 years agoFix explicit use of httpd_t in openca_domtrans(), bug #22.
Chris PeBenito [Wed, 7 Feb 2007 22:10:45 +0000 (22:10 +0000)] 
Fix explicit use of httpd_t in openca_domtrans(), bug #22.

18 years agoClean up file context regexes in apache and java, from Eamon Walsh:
Chris PeBenito [Wed, 24 Jan 2007 17:10:31 +0000 (17:10 +0000)] 
Clean up file context regexes in apache and java, from Eamon Walsh:

Some file_contexts regular expressions in refpolicy-strict are causing
genhomedircon to die; refpolicy is failing to build for me entirely.

The regular expressions seem redundant to me, perhaps I am missing
something, but the following patch fixes the problems for me.  Please
review and apply

18 years agoupdate version and changelog for release
Chris PeBenito [Tue, 12 Dec 2006 21:59:26 +0000 (21:59 +0000)] 
update version and changelog for release

18 years agobump versions for release.
Chris PeBenito [Tue, 12 Dec 2006 21:22:47 +0000 (21:22 +0000)] 
bump versions for release.

18 years agomerge policy patterns to trunk
Chris PeBenito [Tue, 12 Dec 2006 20:08:08 +0000 (20:08 +0000)] 
merge policy patterns to trunk

18 years agopatch from dan Wed, 29 Nov 2006 17:06:40 -0500
Chris PeBenito [Mon, 4 Dec 2006 20:10:56 +0000 (20:10 +0000)] 
patch from dan Wed, 29 Nov 2006 17:06:40 -0500

18 years agopatch from dan for some missing gen_require()s
Chris PeBenito [Wed, 29 Nov 2006 13:44:40 +0000 (13:44 +0000)] 
patch from dan for some missing gen_require()s

18 years agofix dontaudit interface that was allowing instead of dontauditing; thanks to karl...
Chris PeBenito [Tue, 28 Nov 2006 15:57:22 +0000 (15:57 +0000)] 
fix dontaudit interface that was allowing instead of dontauditing; thanks to karl for pointing this out.

18 years agofix dontaudit interface that was allowing instead of dontauditing; thanks to karl...
Chris PeBenito [Tue, 28 Nov 2006 15:47:47 +0000 (15:47 +0000)] 
fix dontaudit interface that was allowing instead of dontauditing; thanks to karl for pointing this out.

18 years agoadd aide, ccs, and ricci
Chris PeBenito [Thu, 16 Nov 2006 20:56:24 +0000 (20:56 +0000)] 
add aide, ccs, and ricci

18 years agoThis modifies the mls constraint for polmatch in the association class.
Chris PeBenito [Thu, 16 Nov 2006 13:38:14 +0000 (13:38 +0000)] 
This modifies the mls constraint for polmatch in the association class.
Specifically:

- polmatch need no longer make an exception for unlabeled_t
  since a flow will now always match SPD rules with no contexts (per
  the IPSec leak fix patch upstreamed a few weeks back), as
  opposed to needing polmatch access to unlabeled_t.

Signed-off-by: Venkat Yekkirala <vyekkirala@TrustedCS.com>
18 years agoOn Tue, 2006-11-07 at 16:51 -0500, James Antill wrote:
Chris PeBenito [Tue, 14 Nov 2006 13:38:52 +0000 (13:38 +0000)] 
On Tue, 2006-11-07 at 16:51 -0500, James Antill wrote:
> Here is the policy changes needed for the context contains security
> checking in PAM and cron.

18 years ago- Add a reload target to Modules.devel and change the load
Chris PeBenito [Mon, 13 Nov 2006 03:36:13 +0000 (03:36 +0000)] 
- Add a reload target to Modules.devel and change the load
  target to only insert modules that were changed.

18 years agofixes from gentoo strict testing:
Chris PeBenito [Mon, 13 Nov 2006 03:24:07 +0000 (03:24 +0000)] 
fixes from gentoo strict testing:
- Allow semanage to read from /root on strict non-MLS for
  local policy modules.
- Gentoo init script fixes for udev.
- Allow udev to read kernel modules.inputmap.
- Dnsmasq fixes from testing.
- Allow kernel NFS server to getattr filesystems so df can work
  on clients.

18 years agoadd missing gentoo file contexts for initrc and lvm
Chris PeBenito [Tue, 7 Nov 2006 19:38:10 +0000 (19:38 +0000)] 
add missing gentoo file contexts for initrc and lvm

18 years agoChristopher J. PeBenito wrote:
Chris PeBenito [Wed, 1 Nov 2006 15:42:22 +0000 (15:42 +0000)] 
Christopher J. PeBenito wrote:
> We could add another 'or' on the above constraint:
>
> or ( (t2 == mlsfilewrite_in_range) and (l1 dom l2) and (h1 domby h2) )
>
> I believe that would be the constraint you were looking for.  I don't
> like the name of that attribute, but I couldn't come up with a better
> one off the top of my head. :)
>

Attached is a patch which I've tested against selinux-policy-2.4.2-1
that implements this additional constraint.  The name is still a bit
forced, but it works.

-matt <mra at hp dot com>

18 years agopatch from dan Tue, 24 Oct 2006 11:00:28 -0400
Chris PeBenito [Tue, 31 Oct 2006 21:01:48 +0000 (21:01 +0000)] 
patch from dan Tue, 24 Oct 2006 11:00:28 -0400

18 years agofix up corecommands perm sets, add seutil_manage_config_dirs()
Chris PeBenito [Fri, 27 Oct 2006 13:55:35 +0000 (13:55 +0000)] 
fix up corecommands perm sets, add seutil_manage_config_dirs()

18 years agoadd seutil_rw_config()
Chris PeBenito [Wed, 25 Oct 2006 20:48:04 +0000 (20:48 +0000)] 
add seutil_rw_config()

18 years agomake load target more friendly and add reload target
Chris PeBenito [Wed, 25 Oct 2006 20:38:33 +0000 (20:38 +0000)] 
make load target more friendly and add reload target

18 years agoenhanced setransd support from darrel goeddel
Chris PeBenito [Fri, 20 Oct 2006 14:44:23 +0000 (14:44 +0000)] 
enhanced setransd support from darrel goeddel

18 years ago20061018 release
Chris PeBenito [Wed, 18 Oct 2006 20:26:45 +0000 (20:26 +0000)] 
20061018 release