]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Chris PeBenito [Wed, 28 Jun 2006 13:55:52 +0000 (13:55 +0000)]
fix "no modules enabled" check
Chris PeBenito [Wed, 21 Jun 2006 21:04:14 +0000 (21:04 +0000)]
bump mod versions for key
Chris PeBenito [Wed, 21 Jun 2006 21:02:49 +0000 (21:02 +0000)]
add key support
Chris PeBenito [Wed, 21 Jun 2006 19:07:32 +0000 (19:07 +0000)]
list dans patches
Chris PeBenito [Wed, 21 Jun 2006 18:25:06 +0000 (18:25 +0000)]
patch from Dan Tue, 20 Jun 2006 16:19:13 -0400
Chris PeBenito [Tue, 20 Jun 2006 17:32:21 +0000 (17:32 +0000)]
need send_msg for merging dbus
Chris PeBenito [Fri, 16 Jun 2006 19:54:21 +0000 (19:54 +0000)]
remove raw network, make mta optional, and a little cleanup.
Chris PeBenito [Fri, 16 Jun 2006 13:10:40 +0000 (13:10 +0000)]
fix typo
Chris PeBenito [Thu, 15 Jun 2006 20:18:38 +0000 (20:18 +0000)]
remove redundant conditional
Chris PeBenito [Thu, 15 Jun 2006 17:37:47 +0000 (17:37 +0000)]
fix typo
Chris PeBenito [Thu, 15 Jun 2006 17:04:08 +0000 (17:04 +0000)]
fix typo
Chris PeBenito [Wed, 14 Jun 2006 20:52:45 +0000 (20:52 +0000)]
clean up usercanread
Chris PeBenito [Wed, 14 Jun 2006 14:10:24 +0000 (14:10 +0000)]
fix typos
Chris PeBenito [Tue, 13 Jun 2006 18:17:34 +0000 (18:17 +0000)]
add ftpdctl from paul howarth
Chris PeBenito [Tue, 13 Jun 2006 13:05:35 +0000 (13:05 +0000)]
undo dans reversion
Chris PeBenito [Mon, 12 Jun 2006 21:36:38 +0000 (21:36 +0000)]
patch from dan Mon, 12 Jun 2006 15:32:00 -0400
Chris PeBenito [Mon, 12 Jun 2006 17:27:15 +0000 (17:27 +0000)]
remove some extra endlines
Chris PeBenito [Mon, 12 Jun 2006 16:59:21 +0000 (16:59 +0000)]
Fix build system to not move type declarations out of optionals.
Chris PeBenito [Mon, 12 Jun 2006 16:55:18 +0000 (16:55 +0000)]
fix dbus_user_bus_client_template
Chris PeBenito [Mon, 12 Jun 2006 16:52:41 +0000 (16:52 +0000)]
fix to use ifndef convenience macro
Chris PeBenito [Mon, 12 Jun 2006 15:49:48 +0000 (15:49 +0000)]
add ifndef convenience macro
Chris PeBenito [Mon, 12 Jun 2006 15:42:13 +0000 (15:42 +0000)]
fix typo
Chris PeBenito [Mon, 12 Jun 2006 15:22:45 +0000 (15:22 +0000)]
use domtrans from initrc for insmod
Chris PeBenito [Mon, 12 Jun 2006 14:17:40 +0000 (14:17 +0000)]
fix up bad ifdefs and remove foo.te definition for modules.
Chris PeBenito [Fri, 9 Jun 2006 13:49:22 +0000 (13:49 +0000)]
another script in the apr build dir
Chris PeBenito [Fri, 9 Jun 2006 13:47:58 +0000 (13:47 +0000)]
shell scripts in the apr build dir
Chris PeBenito [Thu, 8 Jun 2006 17:18:25 +0000 (17:18 +0000)]
fix most bad rules in cups, bug 1771
Chris PeBenito [Wed, 7 Jun 2006 17:43:10 +0000 (17:43 +0000)]
patch from dan Tue, 06 Jun 2006 22:50:46 -0400
Chris PeBenito [Tue, 6 Jun 2006 17:51:24 +0000 (17:51 +0000)]
fix execmod all files rule in wine
Chris PeBenito [Tue, 6 Jun 2006 17:25:23 +0000 (17:25 +0000)]
improve warning message, with file and line numbers
Chris PeBenito [Tue, 6 Jun 2006 17:24:34 +0000 (17:24 +0000)]
fix bad use of templates
Chris PeBenito [Fri, 2 Jun 2006 17:44:44 +0000 (17:44 +0000)]
missing net_bind_service cap for bind_all_ports interfaces
Chris PeBenito [Fri, 2 Jun 2006 15:06:45 +0000 (15:06 +0000)]
packets
Chris PeBenito [Fri, 2 Jun 2006 13:48:34 +0000 (13:48 +0000)]
packets for inetd
Chris PeBenito [Thu, 1 Jun 2006 18:17:53 +0000 (18:17 +0000)]
fill out networking perms
Chris PeBenito [Wed, 31 May 2006 17:20:21 +0000 (17:20 +0000)]
packets for ftp
Chris PeBenito [Tue, 30 May 2006 19:46:34 +0000 (19:46 +0000)]
packets for services
Chris PeBenito [Mon, 29 May 2006 19:53:43 +0000 (19:53 +0000)]
packets for admin modules
Chris PeBenito [Mon, 29 May 2006 18:25:58 +0000 (18:25 +0000)]
add packets for apps
Chris PeBenito [Mon, 29 May 2006 15:04:49 +0000 (15:04 +0000)]
break packet_t into server_packet_t client_packet_t, and cover add packets to system modules where they make sense.
Chris PeBenito [Mon, 29 May 2006 14:16:22 +0000 (14:16 +0000)]
add gcc-config to portage
Chris PeBenito [Fri, 26 May 2006 20:46:37 +0000 (20:46 +0000)]
apache packets
Chris PeBenito [Fri, 26 May 2006 20:29:51 +0000 (20:29 +0000)]
updates for nfs, squid, and mta
Chris PeBenito [Fri, 26 May 2006 19:04:18 +0000 (19:04 +0000)]
more packets
Chris PeBenito [Fri, 26 May 2006 18:04:46 +0000 (18:04 +0000)]
packet updates for kernel, nscd, bind, ntp, spamassassin, and dhcpc
Chris PeBenito [Fri, 26 May 2006 14:40:12 +0000 (14:40 +0000)]
packets for users
Chris PeBenito [Fri, 26 May 2006 14:34:13 +0000 (14:34 +0000)]
fix typos
Chris PeBenito [Fri, 26 May 2006 14:33:44 +0000 (14:33 +0000)]
comment out .SECONDARY since its broken in make 3.81, and rawhide uses this make now
Chris PeBenito [Fri, 26 May 2006 13:49:13 +0000 (13:49 +0000)]
add client and server packet attributes
Chris PeBenito [Thu, 25 May 2006 20:18:24 +0000 (20:18 +0000)]
update ssh for packets
Chris PeBenito [Thu, 25 May 2006 18:42:32 +0000 (18:42 +0000)]
reorganize the file
Chris PeBenito [Thu, 25 May 2006 18:41:14 +0000 (18:41 +0000)]
packets from configuring cups from a web browser and printing a test page to a jetdirect
Chris PeBenito [Thu, 25 May 2006 17:59:50 +0000 (17:59 +0000)]
typo
Chris PeBenito [Thu, 25 May 2006 17:56:07 +0000 (17:56 +0000)]
initial packet rules
Chris PeBenito [Thu, 25 May 2006 17:01:36 +0000 (17:01 +0000)]
add generic packet interfaces, and fix up unconfined handling
Chris PeBenito [Thu, 25 May 2006 16:40:52 +0000 (16:40 +0000)]
remove debugging statemnet
Chris PeBenito [Thu, 25 May 2006 15:14:19 +0000 (15:14 +0000)]
add makefile support for netfilter contexts
Chris PeBenito [Thu, 25 May 2006 15:09:06 +0000 (15:09 +0000)]
fix copyright years
Chris PeBenito [Thu, 25 May 2006 15:04:39 +0000 (15:04 +0000)]
fix handling of comments at the end of the line, and add copyright
Chris PeBenito [Thu, 25 May 2006 14:10:55 +0000 (14:10 +0000)]
fix chain declaration
Chris PeBenito [Thu, 25 May 2006 14:02:41 +0000 (14:02 +0000)]
add command line arguments support, and mls/mcs support
Chris PeBenito [Thu, 25 May 2006 13:14:08 +0000 (13:14 +0000)]
add compute_av for doing rootok check
Chris PeBenito [Wed, 24 May 2006 21:28:49 +0000 (21:28 +0000)]
use network_port()s to declare packets, since packets match up with these ports
Chris PeBenito [Wed, 24 May 2006 21:27:52 +0000 (21:27 +0000)]
initial commit of netfilter config generator tool, still needs work on mls/mcs side.
Chris PeBenito [Tue, 23 May 2006 19:07:22 +0000 (19:07 +0000)]
allow iptables to relabelto all packets
Chris PeBenito [Tue, 23 May 2006 18:31:02 +0000 (18:31 +0000)]
initial support for packets
Chris PeBenito [Mon, 22 May 2006 20:47:05 +0000 (20:47 +0000)]
initial addition of packet policy, allow unconfined to send unlabeled packets.
Chris PeBenito [Mon, 22 May 2006 18:24:19 +0000 (18:24 +0000)]
no user contexts for strict policy
Chris PeBenito [Fri, 19 May 2006 20:02:41 +0000 (20:02 +0000)]
dontaudit just the kernel fd use, the others may indicate problems for other reasons.
Chris PeBenito [Fri, 19 May 2006 19:52:18 +0000 (19:52 +0000)]
add back stray file descriptors dontaudit for rhel4
Chris PeBenito [Fri, 19 May 2006 17:45:46 +0000 (17:45 +0000)]
add packet security class
Chris PeBenito [Fri, 19 May 2006 17:44:27 +0000 (17:44 +0000)]
cleanup init_t a little
Chris PeBenito [Fri, 19 May 2006 15:15:45 +0000 (15:15 +0000)]
move selinux unconfined to attribute setup, clean up unconfined interface a bit
Chris PeBenito [Fri, 19 May 2006 14:06:18 +0000 (14:06 +0000)]
patch from russell Fri, 19 May 2006 20:28:29 +1000
Chris PeBenito [Fri, 19 May 2006 14:02:24 +0000 (14:02 +0000)]
patch from dan Thu, 18 May 2006 11:56:22 -0400
Chris PeBenito [Fri, 19 May 2006 13:14:37 +0000 (13:14 +0000)]
fixes for gentoo
Chris PeBenito [Thu, 18 May 2006 17:55:03 +0000 (17:55 +0000)]
fix example.te
Chris PeBenito [Wed, 17 May 2006 20:55:12 +0000 (20:55 +0000)]
start cleaning up node binding and raw if/node access
Chris PeBenito [Wed, 17 May 2006 14:50:31 +0000 (14:50 +0000)]
most of patch from dan Mon, 15 May 2006 11:58:01 -0400
Chris PeBenito [Tue, 16 May 2006 18:36:25 +0000 (18:36 +0000)]
move old strict, targeted, and mls policies to archive
Chris PeBenito [Tue, 16 May 2006 15:05:40 +0000 (15:05 +0000)]
add info on build options
Chris PeBenito [Tue, 16 May 2006 13:36:57 +0000 (13:36 +0000)]
update admin template docs
Chris PeBenito [Mon, 15 May 2006 20:43:10 +0000 (20:43 +0000)]
gentoo has passwd in /bin
Chris PeBenito [Mon, 15 May 2006 15:21:43 +0000 (15:21 +0000)]
Add a copy of genhomedircon for monolithic policy building, so that a policycoreutils package update is not required for RHEL4 systems.
Chris PeBenito [Fri, 12 May 2006 19:37:56 +0000 (19:37 +0000)]
remove rules added to make sediff easier
Chris PeBenito [Fri, 12 May 2006 18:43:31 +0000 (18:43 +0000)]
clean up some apache networking perms
Chris PeBenito [Wed, 10 May 2006 20:24:40 +0000 (20:24 +0000)]
add apache_manage_all_content, bug 1602
Chris PeBenito [Wed, 10 May 2006 18:42:22 +0000 (18:42 +0000)]
fix sendmail_exec_t encapsulation breakage
Chris PeBenito [Wed, 10 May 2006 18:09:08 +0000 (18:09 +0000)]
document remaining interfaces w/o XML. turn on warnings for missing XML.
Chris PeBenito [Wed, 10 May 2006 18:08:40 +0000 (18:08 +0000)]
make executable
Chris PeBenito [Wed, 10 May 2006 18:08:06 +0000 (18:08 +0000)]
document postfix templates, remove postfix_public_domain_template()
Chris PeBenito [Wed, 10 May 2006 18:07:31 +0000 (18:07 +0000)]
document postfix templates, remove postfix_public_domain_template()
Chris PeBenito [Wed, 10 May 2006 14:17:51 +0000 (14:17 +0000)]
status update
Chris PeBenito [Tue, 9 May 2006 20:13:25 +0000 (20:13 +0000)]
fixes from testing
Chris PeBenito [Tue, 9 May 2006 18:39:35 +0000 (18:39 +0000)]
remove unreproducible notatsecure problem, bug 1411
Chris PeBenito [Tue, 9 May 2006 18:03:33 +0000 (18:03 +0000)]
pyzor does not have a per userdomain template
Chris PeBenito [Tue, 9 May 2006 15:24:11 +0000 (15:24 +0000)]
ssh_keysign_exec_t should be a bin
Chris PeBenito [Tue, 9 May 2006 15:12:17 +0000 (15:12 +0000)]
add nx, bug 1535
Chris PeBenito [Mon, 8 May 2006 14:16:10 +0000 (14:16 +0000)]
add clockspeed from petre rodan
Chris PeBenito [Mon, 8 May 2006 13:22:11 +0000 (13:22 +0000)]
fix broken macro calls