]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Chris PeBenito [Mon, 30 Apr 2007 15:09:15 +0000 (15:09 +0000)]
trivial aide fix from dan
Chris PeBenito [Mon, 30 Apr 2007 15:01:19 +0000 (15:01 +0000)]
Patch to allow slocate to getattr other filesystems and directories on those filesystems from Dan Walsh.
Chris PeBenito [Mon, 30 Apr 2007 14:44:04 +0000 (14:44 +0000)]
trivial fix for netutils from dan
Chris PeBenito [Mon, 30 Apr 2007 14:33:12 +0000 (14:33 +0000)]
trivial fix from dan for bluetooth
Chris PeBenito [Mon, 30 Apr 2007 14:32:31 +0000 (14:32 +0000)]
missed piece of clip patch
Chris PeBenito [Fri, 27 Apr 2007 15:08:15 +0000 (15:08 +0000)]
Fixes for RHEL4 from the CLIP project.
Chris PeBenito [Mon, 23 Apr 2007 17:36:35 +0000 (17:36 +0000)]
Replace the old lrrd fc entries with correct munin ones.
Chris PeBenito [Thu, 19 Apr 2007 14:30:57 +0000 (14:30 +0000)]
Move program admin template usage out of userdom_admin_user_template() to sysadm policy in userdomain.te to fix usage of the template for third parties.
Chris PeBenito [Thu, 19 Apr 2007 14:24:02 +0000 (14:24 +0000)]
Fix clockspeed_run_cli() declaration, it was incorrectly defined as a template instead of an interface.
Chris PeBenito [Tue, 17 Apr 2007 14:20:24 +0000 (14:20 +0000)]
final release entries for
20070417
Chris PeBenito [Tue, 17 Apr 2007 13:28:09 +0000 (13:28 +0000)]
bump module versions for release
Chris PeBenito [Wed, 11 Apr 2007 20:02:59 +0000 (20:02 +0000)]
last piece of previous consolekit patch
Chris PeBenito [Wed, 11 Apr 2007 18:55:44 +0000 (18:55 +0000)]
add zabbix from dan
Chris PeBenito [Wed, 11 Apr 2007 17:56:03 +0000 (17:56 +0000)]
5 patches from dan. confine insmod and udev on targeted, misc fc fixes, sasl kerberos use, and samba port fixes
Chris PeBenito [Wed, 11 Apr 2007 14:04:35 +0000 (14:04 +0000)]
more consolekit updates from dan
Chris PeBenito [Wed, 11 Apr 2007 13:31:10 +0000 (13:31 +0000)]
last piece of dan's previous patch
Chris PeBenito [Tue, 10 Apr 2007 19:39:22 +0000 (19:39 +0000)]
confine ldconfig in targeted, from dan
Chris PeBenito [Tue, 10 Apr 2007 17:20:07 +0000 (17:20 +0000)]
from dan:
kadmind trys to setattr on krb5kdc file. Just a library checking access.
Chris PeBenito [Tue, 10 Apr 2007 13:10:58 +0000 (13:10 +0000)]
six patches from dan
Chris PeBenito [Mon, 2 Apr 2007 13:58:33 +0000 (13:58 +0000)]
man page updates from dan
Chris PeBenito [Mon, 2 Apr 2007 13:33:18 +0000 (13:33 +0000)]
gentoo /lib can be a symlink on x86-64 systems
Chris PeBenito [Mon, 2 Apr 2007 13:20:55 +0000 (13:20 +0000)]
fix http_script_domains, it was incorrectly applied to the content type rather than the script domain. bug #24.
Chris PeBenito [Fri, 30 Mar 2007 20:33:51 +0000 (20:33 +0000)]
emit "null" instead of NULL for userspace headers
Chris PeBenito [Fri, 30 Mar 2007 12:43:15 +0000 (12:43 +0000)]
bools in modules fix to require the boolean in optionals that are part of the base module, and move bool declarations in the base module/monolithic
Chris PeBenito [Thu, 29 Mar 2007 12:08:00 +0000 (12:08 +0000)]
add refresh target to devel makefile which tries to reload all of the modules currently in the store.
Chris PeBenito [Wed, 28 Mar 2007 18:47:45 +0000 (18:47 +0000)]
Two patches from Paul Moore to for ipsec to remove redundant rules and have setkey read the config file.
Chris PeBenito [Mon, 26 Mar 2007 20:47:29 +0000 (20:47 +0000)]
six trivial patches from dan for iptables, netutils, ipsec, devices, filesystem and cpuspeed
Chris PeBenito [Mon, 26 Mar 2007 18:41:45 +0000 (18:41 +0000)]
- Move booleans and tunables to modules when it is only used in a single
module.
- Add support for tunables and booleans local to a module.
Chris PeBenito [Fri, 23 Mar 2007 23:24:59 +0000 (23:24 +0000)]
Merge sbin_t and ls_exec_t into bin_t.
Chris PeBenito [Fri, 23 Mar 2007 21:01:49 +0000 (21:01 +0000)]
remove disable_trans booleans
Chris PeBenito [Fri, 23 Mar 2007 20:32:23 +0000 (20:32 +0000)]
Output different header sets for kernel and userland from flask headers.
Chris PeBenito [Fri, 23 Mar 2007 20:21:06 +0000 (20:21 +0000)]
deprecated pax class
Chris PeBenito [Thu, 22 Mar 2007 14:33:00 +0000 (14:33 +0000)]
network fix from dan
Chris PeBenito [Thu, 22 Mar 2007 14:01:55 +0000 (14:01 +0000)]
one-liner from dan
Chris PeBenito [Wed, 21 Mar 2007 20:02:50 +0000 (20:02 +0000)]
patch from dan to have ricci modstorage transition to lvm
Chris PeBenito [Wed, 21 Mar 2007 19:40:55 +0000 (19:40 +0000)]
stop adding netfilter contexts, as decided at the developers summit
Chris PeBenito [Wed, 21 Mar 2007 15:51:52 +0000 (15:51 +0000)]
add fail2ban from dan
Chris PeBenito [Tue, 20 Mar 2007 19:00:35 +0000 (19:00 +0000)]
kudzu will telinit to make init re-read the inittab after configuring serial consoles
Chris PeBenito [Tue, 20 Mar 2007 18:47:18 +0000 (18:47 +0000)]
Add dontaudits for init fds and console to init_daemon_domain().
Chris PeBenito [Mon, 19 Mar 2007 19:10:43 +0000 (19:10 +0000)]
create user gpg keys dir patch from dan
Chris PeBenito [Mon, 19 Mar 2007 18:48:14 +0000 (18:48 +0000)]
add kvmfs support, from dan
Chris PeBenito [Mon, 19 Mar 2007 18:42:57 +0000 (18:42 +0000)]
trivial patch for radius from dan
Chris PeBenito [Mon, 19 Mar 2007 18:38:54 +0000 (18:38 +0000)]
trivial patch from dan for sysstat access to sysfs
Chris PeBenito [Mon, 19 Mar 2007 18:36:36 +0000 (18:36 +0000)]
other part of consolekit addition
Chris PeBenito [Mon, 19 Mar 2007 18:01:15 +0000 (18:01 +0000)]
from Dan:
This is a new policy for the User Switching capability coming in gnome.
consolekit is a daemon that communicates with xdm_t and hal through dbus to change the
ownership/access on certain devices when the login session changes from one user to another
Chris PeBenito [Mon, 19 Mar 2007 16:32:44 +0000 (16:32 +0000)]
patch from Dan for sudo:
sudo should be able to getattr on all executables not just
bin_t/sbin_t. Confined executeables run from sudo need this.
sudo_exec_t needs to be marked as exec_type so prelink will work correctly.
sudo semanage should work
Chris PeBenito [Fri, 9 Mar 2007 14:45:19 +0000 (14:45 +0000)]
It was just pointed out to me that the raw IP socket class is missing from the
recvfrom MLS constraint.
Signed-off-by: Paul Moore
Chris PeBenito [Thu, 8 Mar 2007 19:01:21 +0000 (19:01 +0000)]
fix for rh bug 203290
Chris PeBenito [Thu, 8 Mar 2007 17:53:52 +0000 (17:53 +0000)]
last bit of dans patch
Chris PeBenito [Thu, 8 Mar 2007 15:14:45 +0000 (15:14 +0000)]
Patch for handling restart of nscd when ran from useradd, groupadd, and admin passwd, from Dan Walsh.
Chris PeBenito [Wed, 7 Mar 2007 21:33:22 +0000 (21:33 +0000)]
procmail uses /tmp files
Wants to send signull to itself
Can exec ls
Read spamassinn_lib_dirs
New directory for spamassin /var/lib/
pyzor uses tmp files
Chris PeBenito [Tue, 6 Mar 2007 17:44:26 +0000 (17:44 +0000)]
trivial change from dan
Chris PeBenito [Tue, 6 Mar 2007 17:16:08 +0000 (17:16 +0000)]
setroubleshoot has a plugin that checks the file context on disk versus a matchpathcon. So needs additional privs
Chris PeBenito [Tue, 6 Mar 2007 16:18:59 +0000 (16:18 +0000)]
Patch for gssd fixes from Dan Walsh
Chris PeBenito [Tue, 6 Mar 2007 15:35:02 +0000 (15:35 +0000)]
patches for lvm and ricci fixes from Dan Walsh.
Chris PeBenito [Thu, 1 Mar 2007 20:41:19 +0000 (20:41 +0000)]
lmtp and smtp are the same file require same context of setfiles complains
postfix_pickup_t wants to read postfix_spool_maildrop_t dir
Chris PeBenito [Thu, 1 Mar 2007 15:43:39 +0000 (15:43 +0000)]
patches for file contexts in networkmanager, miscfiles, corecommands, devices, and java from Dan Walsh.
Chris PeBenito [Wed, 28 Feb 2007 17:17:52 +0000 (17:17 +0000)]
Patch for kerberized telnet fixes from Dan Walsh.
Chris PeBenito [Wed, 28 Feb 2007 17:01:47 +0000 (17:01 +0000)]
Patch for kerberized ftp and other ftp fixes from Dan Walsh.
Chris PeBenito [Wed, 28 Feb 2007 16:23:06 +0000 (16:23 +0000)]
Patch for an additional wine executable from Dan Walsh.
Chris PeBenito [Wed, 28 Feb 2007 15:30:38 +0000 (15:30 +0000)]
Patch for additional games file contexts from Dan Walsh.
Chris PeBenito [Tue, 27 Feb 2007 17:02:35 +0000 (17:02 +0000)]
Add support for libselinux 2.0.5 init_selinuxmnt() changes.
Chris PeBenito [Mon, 26 Feb 2007 20:44:35 +0000 (20:44 +0000)]
fix man page patch from dan walsh
Chris PeBenito [Mon, 26 Feb 2007 20:19:53 +0000 (20:19 +0000)]
add init_exec() to init_telinit().
Chris PeBenito [Mon, 26 Feb 2007 17:23:52 +0000 (17:23 +0000)]
Patch for misc fixes to bluetooth from Dan Walsh.
Chris PeBenito [Mon, 26 Feb 2007 17:04:56 +0000 (17:04 +0000)]
On Tue, 2007-02-20 at 12:02 -0500, Daniel J Walsh wrote:
> Eliminate excess avc messages created when using kerberos libraries
>
> krb5kdc wans to setsched
>
> Also uses a fifo_file to communicate.
>
> Needs to search_network_sysctl
Chris PeBenito [Mon, 26 Feb 2007 16:13:23 +0000 (16:13 +0000)]
Patch to start deprecating usercanread attribute from Ryan Bradetich.
Chris PeBenito [Mon, 26 Feb 2007 15:39:59 +0000 (15:39 +0000)]
add dccp_socket object class
Chris PeBenito [Fri, 23 Feb 2007 21:20:46 +0000 (21:20 +0000)]
On Tue, 2007-02-20 at 12:30 -0500, Daniel J Walsh wrote:
> prelink creates temporarly files that it then needs to relabel.
Chris PeBenito [Fri, 23 Feb 2007 20:19:29 +0000 (20:19 +0000)]
On Tue, 2007-02-20 at 12:28 -0500, Daniel J Walsh wrote:
> audit needs fsetid
>
> syslog needs to be able to create a tcp_socket for off machine logging.
Chris PeBenito [Fri, 23 Feb 2007 20:05:12 +0000 (20:05 +0000)]
Patch to remove redundant mls_trusted_object() call from Dan Walsh.
Chris PeBenito [Fri, 23 Feb 2007 19:52:52 +0000 (19:52 +0000)]
Patch for misc fixes to nis ypxfr policy from Dan Walsh.
Chris PeBenito [Fri, 23 Feb 2007 19:41:41 +0000 (19:41 +0000)]
Patch to allow apmd to telinit from Dan Walsh.
Chris PeBenito [Fri, 23 Feb 2007 19:30:17 +0000 (19:30 +0000)]
While using samba and SELinux with Debian GNU/Linux (etch) the
following files need to be labeled correctly:
/var/run/samba/gencache.tdb
/var/run/samba/share_info.tdb
Should also concern other distributions than Debian.
-Stefan
Chris PeBenito [Fri, 23 Feb 2007 19:08:45 +0000 (19:08 +0000)]
Patch to remove incorrect cron labeling in apache.fc from Ryan Bradetich.
Chris PeBenito [Tue, 20 Feb 2007 20:17:07 +0000 (20:17 +0000)]
make ttys and ptys device nodes
Chris PeBenito [Fri, 16 Feb 2007 23:01:42 +0000 (23:01 +0000)]
patch from dan, Thu, 2007-01-25 at 08:12 -0500
Chris PeBenito [Wed, 7 Feb 2007 22:16:18 +0000 (22:16 +0000)]
Fix explicit use of httpd_t in openca_domtrans(), bug #22.
Chris PeBenito [Wed, 7 Feb 2007 22:10:45 +0000 (22:10 +0000)]
Fix explicit use of httpd_t in openca_domtrans(), bug #22.
Chris PeBenito [Wed, 24 Jan 2007 17:10:31 +0000 (17:10 +0000)]
Clean up file context regexes in apache and java, from Eamon Walsh:
Some file_contexts regular expressions in refpolicy-strict are causing
genhomedircon to die; refpolicy is failing to build for me entirely.
The regular expressions seem redundant to me, perhaps I am missing
something, but the following patch fixes the problems for me. Please
review and apply
Chris PeBenito [Tue, 12 Dec 2006 21:59:26 +0000 (21:59 +0000)]
update version and changelog for release
Chris PeBenito [Tue, 12 Dec 2006 21:22:47 +0000 (21:22 +0000)]
bump versions for release.
Chris PeBenito [Tue, 12 Dec 2006 20:08:08 +0000 (20:08 +0000)]
merge policy patterns to trunk
Chris PeBenito [Mon, 4 Dec 2006 20:10:56 +0000 (20:10 +0000)]
patch from dan Wed, 29 Nov 2006 17:06:40 -0500
Chris PeBenito [Wed, 29 Nov 2006 13:44:40 +0000 (13:44 +0000)]
patch from dan for some missing gen_require()s
Chris PeBenito [Tue, 28 Nov 2006 15:57:22 +0000 (15:57 +0000)]
fix dontaudit interface that was allowing instead of dontauditing; thanks to karl for pointing this out.
Chris PeBenito [Tue, 28 Nov 2006 15:47:47 +0000 (15:47 +0000)]
fix dontaudit interface that was allowing instead of dontauditing; thanks to karl for pointing this out.
Chris PeBenito [Thu, 16 Nov 2006 20:56:24 +0000 (20:56 +0000)]
add aide, ccs, and ricci
Chris PeBenito [Thu, 16 Nov 2006 13:38:14 +0000 (13:38 +0000)]
This modifies the mls constraint for polmatch in the association class.
Specifically:
- polmatch need no longer make an exception for unlabeled_t
since a flow will now always match SPD rules with no contexts (per
the IPSec leak fix patch upstreamed a few weeks back), as
opposed to needing polmatch access to unlabeled_t.
Signed-off-by: Venkat Yekkirala <vyekkirala@TrustedCS.com>
Chris PeBenito [Tue, 14 Nov 2006 13:38:52 +0000 (13:38 +0000)]
On Tue, 2006-11-07 at 16:51 -0500, James Antill wrote:
> Here is the policy changes needed for the context contains security
> checking in PAM and cron.
Chris PeBenito [Mon, 13 Nov 2006 03:36:13 +0000 (03:36 +0000)]
- Add a reload target to Modules.devel and change the load
target to only insert modules that were changed.
Chris PeBenito [Mon, 13 Nov 2006 03:24:07 +0000 (03:24 +0000)]
fixes from gentoo strict testing:
- Allow semanage to read from /root on strict non-MLS for
local policy modules.
- Gentoo init script fixes for udev.
- Allow udev to read kernel modules.inputmap.
- Dnsmasq fixes from testing.
- Allow kernel NFS server to getattr filesystems so df can work
on clients.
Chris PeBenito [Tue, 7 Nov 2006 19:38:10 +0000 (19:38 +0000)]
add missing gentoo file contexts for initrc and lvm
Chris PeBenito [Wed, 1 Nov 2006 15:42:22 +0000 (15:42 +0000)]
Christopher J. PeBenito wrote:
> We could add another 'or' on the above constraint:
>
> or ( (t2 == mlsfilewrite_in_range) and (l1 dom l2) and (h1 domby h2) )
>
> I believe that would be the constraint you were looking for. I don't
> like the name of that attribute, but I couldn't come up with a better
> one off the top of my head. :)
>
Attached is a patch which I've tested against selinux-policy-2.4.2-1
that implements this additional constraint. The name is still a bit
forced, but it works.
-matt <mra at hp dot com>
Chris PeBenito [Tue, 31 Oct 2006 21:01:48 +0000 (21:01 +0000)]
patch from dan Tue, 24 Oct 2006 11:00:28 -0400
Chris PeBenito [Fri, 27 Oct 2006 13:55:35 +0000 (13:55 +0000)]
fix up corecommands perm sets, add seutil_manage_config_dirs()
Chris PeBenito [Wed, 25 Oct 2006 20:48:04 +0000 (20:48 +0000)]
add seutil_rw_config()
Chris PeBenito [Wed, 25 Oct 2006 20:38:33 +0000 (20:38 +0000)]
make load target more friendly and add reload target
Chris PeBenito [Fri, 20 Oct 2006 14:44:23 +0000 (14:44 +0000)]
enhanced setransd support from darrel goeddel
Chris PeBenito [Wed, 18 Oct 2006 20:26:45 +0000 (20:26 +0000)]