]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Chris PeBenito [Fri, 29 Jul 2005 20:49:52 +0000 (20:49 +0000)]
move file context validation to install
Chris PeBenito [Fri, 29 Jul 2005 15:07:15 +0000 (15:07 +0000)]
fix stray line that got out of TODO
Chris PeBenito [Thu, 28 Jul 2005 20:52:55 +0000 (20:52 +0000)]
work on user transition
Chris PeBenito [Wed, 27 Jul 2005 21:01:19 +0000 (21:01 +0000)]
update
Chris PeBenito [Wed, 27 Jul 2005 14:33:01 +0000 (14:33 +0000)]
update version from last release
Chris PeBenito [Wed, 27 Jul 2005 14:32:12 +0000 (14:32 +0000)]
initial commit
Chris PeBenito [Fri, 22 Jul 2005 19:15:49 +0000 (19:15 +0000)]
Fix handling of ordered and unordered HTML lists.
Chris PeBenito [Fri, 22 Jul 2005 15:38:01 +0000 (15:38 +0000)]
add connect interface on ports to handle name_connect tcp perm
Chris PeBenito [Fri, 22 Jul 2005 14:00:38 +0000 (14:00 +0000)]
make network_interface able to support multiple interfaces having the same type
Chris PeBenito [Thu, 21 Jul 2005 20:34:57 +0000 (20:34 +0000)]
update from privmail
Chris PeBenito [Thu, 21 Jul 2005 20:34:12 +0000 (20:34 +0000)]
massive updates
Chris PeBenito [Wed, 20 Jul 2005 20:11:49 +0000 (20:11 +0000)]
add an example module config for a targeted policy
Chris PeBenito [Wed, 20 Jul 2005 17:36:48 +0000 (17:36 +0000)]
/var/lib is now a mountpoint
Chris PeBenito [Wed, 20 Jul 2005 17:24:23 +0000 (17:24 +0000)]
unconfined can pass all constraints
Chris PeBenito [Wed, 20 Jul 2005 17:10:07 +0000 (17:10 +0000)]
name_connect only on tcp_sockets
Chris PeBenito [Wed, 20 Jul 2005 17:08:07 +0000 (17:08 +0000)]
unconfined can name_connect to all ports
Chris PeBenito [Wed, 20 Jul 2005 17:06:10 +0000 (17:06 +0000)]
reorder kernel policy, add attributes for sysctl and proc entries. fix unconfined interface
Chris PeBenito [Wed, 20 Jul 2005 15:08:33 +0000 (15:08 +0000)]
bah typo
Chris PeBenito [Wed, 20 Jul 2005 15:06:49 +0000 (15:06 +0000)]
user home dirs were missing file type in targ policy
Chris PeBenito [Wed, 20 Jul 2005 14:57:13 +0000 (14:57 +0000)]
add missing dir and file perms for selinuxfs in unconfined
Chris PeBenito [Wed, 20 Jul 2005 14:25:24 +0000 (14:25 +0000)]
fix typos and import some rules from NSA cvs to make targeted policy work
Chris PeBenito [Wed, 20 Jul 2005 13:39:10 +0000 (13:39 +0000)]
should actually try compiling first :x
Chris PeBenito [Wed, 20 Jul 2005 13:37:18 +0000 (13:37 +0000)]
missed a line
Chris PeBenito [Wed, 20 Jul 2005 13:30:06 +0000 (13:30 +0000)]
add in some rules from NSA CVS to make targeted policy work
Chris PeBenito [Tue, 19 Jul 2005 20:38:26 +0000 (20:38 +0000)]
corenet was missing from unconfined
Chris PeBenito [Tue, 19 Jul 2005 20:26:02 +0000 (20:26 +0000)]
more targeted policy fixes
Chris PeBenito [Tue, 19 Jul 2005 20:25:42 +0000 (20:25 +0000)]
add new netlink socket class
Chris PeBenito [Tue, 19 Jul 2005 19:37:43 +0000 (19:37 +0000)]
more fixes for targeted
Chris PeBenito [Tue, 19 Jul 2005 18:40:31 +0000 (18:40 +0000)]
more cleanup
Chris PeBenito [Tue, 19 Jul 2005 18:40:19 +0000 (18:40 +0000)]
fixes for targeted policy
Chris PeBenito [Mon, 18 Jul 2005 20:17:21 +0000 (20:17 +0000)]
fix assertions for framework
Chris PeBenito [Mon, 18 Jul 2005 18:31:49 +0000 (18:31 +0000)]
more cleanup in system
Chris PeBenito [Mon, 18 Jul 2005 14:25:05 +0000 (14:25 +0000)]
fix to use context_template()
Chris PeBenito [Fri, 15 Jul 2005 20:54:24 +0000 (20:54 +0000)]
add missing context template
Chris PeBenito [Fri, 15 Jul 2005 20:45:26 +0000 (20:45 +0000)]
add raid (mdadm)
Chris PeBenito [Fri, 15 Jul 2005 19:18:55 +0000 (19:18 +0000)]
more pcmcia cleanup
Chris PeBenito [Fri, 15 Jul 2005 15:53:54 +0000 (15:53 +0000)]
add macro to expand object class sets for use in require blocks
Chris PeBenito [Fri, 15 Jul 2005 15:17:57 +0000 (15:17 +0000)]
* break up files_getattr_all_files into correct interfaces
* move stuff out of pcmcia into the appropriate modules
Chris PeBenito [Fri, 15 Jul 2005 14:30:19 +0000 (14:30 +0000)]
reorder in alpha order of type, for sanity purposes
Chris PeBenito [Thu, 14 Jul 2005 20:58:57 +0000 (20:58 +0000)]
add pcmcia
Chris PeBenito [Thu, 14 Jul 2005 20:57:17 +0000 (20:57 +0000)]
add pcmcia
Chris PeBenito [Thu, 14 Jul 2005 20:02:53 +0000 (20:02 +0000)]
fix up the xml
Chris PeBenito [Thu, 14 Jul 2005 18:15:47 +0000 (18:15 +0000)]
add ipsec
Chris PeBenito [Wed, 13 Jul 2005 20:50:20 +0000 (20:50 +0000)]
more updates
Chris PeBenito [Wed, 13 Jul 2005 20:48:51 +0000 (20:48 +0000)]
add nscd
Chris PeBenito [Wed, 13 Jul 2005 18:29:08 +0000 (18:29 +0000)]
* fix chroot exec interface
* more TODO cleanup
* move IPC out of generic domtrans interfaces
Chris PeBenito [Wed, 13 Jul 2005 18:08:12 +0000 (18:08 +0000)]
add distro tunables. expand on a few comments
Chris PeBenito [Tue, 12 Jul 2005 20:34:24 +0000 (20:34 +0000)]
more cleanup of current TODOs
Chris PeBenito [Tue, 12 Jul 2005 20:33:42 +0000 (20:33 +0000)]
fix comments for templates to have same number of # as interfaces
Chris PeBenito [Mon, 11 Jul 2005 19:15:54 +0000 (19:15 +0000)]
fix xml
Chris PeBenito [Mon, 11 Jul 2005 19:02:50 +0000 (19:02 +0000)]
fix more TODOs. fix selinux.te to selinuxutil.te in optionals
Chris PeBenito [Mon, 11 Jul 2005 14:41:21 +0000 (14:41 +0000)]
improve display of tunables and booleans
Chris PeBenito [Mon, 11 Jul 2005 13:49:15 +0000 (13:49 +0000)]
add tun and bool descriptions
Chris PeBenito [Fri, 8 Jul 2005 21:02:59 +0000 (21:02 +0000)]
initial global booleans and tunables support. also fix index
building, as it was being rebuilt for every module, rather then
once after all modules are loaded.
Chris PeBenito [Fri, 8 Jul 2005 20:44:57 +0000 (20:44 +0000)]
another round of TODO cleanup
Chris PeBenito [Fri, 8 Jul 2005 19:44:12 +0000 (19:44 +0000)]
silly formatting fix
Chris PeBenito [Fri, 8 Jul 2005 14:22:17 +0000 (14:22 +0000)]
support for global booleans
Chris PeBenito [Thu, 7 Jul 2005 20:56:27 +0000 (20:56 +0000)]
* Added support for layer summaries.
* Added a "Index" link on the menu to link to index.html
* Added links from the master interface & template lists
to their respective documentation in their module.
* Added links to "Interfaces" and "Templates" in modules
that have both.
* Added "Return" links after the "Interfaces" and "Templates"
section that go to the top of the module site.
Chris PeBenito [Thu, 7 Jul 2005 17:25:53 +0000 (17:25 +0000)]
Chris PeBenito [Thu, 7 Jul 2005 17:19:13 +0000 (17:19 +0000)]
update for
20050707 release
Chris PeBenito [Thu, 7 Jul 2005 17:13:17 +0000 (17:13 +0000)]
add changelog
Chris PeBenito [Thu, 7 Jul 2005 15:25:28 +0000 (15:25 +0000)]
implement direct_sysadm_daemon
Chris PeBenito [Thu, 7 Jul 2005 15:20:24 +0000 (15:20 +0000)]
missing rules uncovered by sediff
Chris PeBenito [Wed, 6 Jul 2005 20:28:29 +0000 (20:28 +0000)]
support for targeted policy
Chris PeBenito [Wed, 6 Jul 2005 19:42:27 +0000 (19:42 +0000)]
put back to strict. will have separate strict and targeted appconfig
Chris PeBenito [Wed, 6 Jul 2005 18:34:27 +0000 (18:34 +0000)]
validate file contexts
Chris PeBenito [Wed, 6 Jul 2005 17:41:58 +0000 (17:41 +0000)]
ksu moves to su
Chris PeBenito [Wed, 6 Jul 2005 15:59:54 +0000 (15:59 +0000)]
add missing ssh file contexts
Chris PeBenito [Wed, 6 Jul 2005 15:24:45 +0000 (15:24 +0000)]
quiet the awk if modules.conf doesnt exist
Karl MacMillan [Wed, 6 Jul 2005 15:23:28 +0000 (15:23 +0000)]
- Removed OUTPUT_VERSION as default.
- Added default name as refpolicy to avoid clobbering string installs
Chris PeBenito [Wed, 6 Jul 2005 13:12:20 +0000 (13:12 +0000)]
update appconfig for unconfined login
Chris PeBenito [Tue, 5 Jul 2005 20:59:51 +0000 (20:59 +0000)]
add unconfined
Chris PeBenito [Tue, 5 Jul 2005 20:54:12 +0000 (20:54 +0000)]
fix quoting problem
Chris PeBenito [Tue, 5 Jul 2005 19:42:11 +0000 (19:42 +0000)]
fix for new new modules.conf behavior
Chris PeBenito [Tue, 5 Jul 2005 19:35:07 +0000 (19:35 +0000)]
update for required tag
Karl MacMillan [Tue, 5 Jul 2005 18:59:08 +0000 (18:59 +0000)]
Minor doc updates.
Chris PeBenito [Tue, 5 Jul 2005 17:47:15 +0000 (17:47 +0000)]
add required tags
Chris PeBenito [Tue, 5 Jul 2005 16:03:47 +0000 (16:03 +0000)]
add tag for required modules
Chris PeBenito [Tue, 5 Jul 2005 13:36:21 +0000 (13:36 +0000)]
update for
20050705 release
Chris PeBenito [Fri, 1 Jul 2005 16:39:31 +0000 (16:39 +0000)]
update for
20050701 release
Chris PeBenito [Fri, 1 Jul 2005 16:39:21 +0000 (16:39 +0000)]
update for xml changes
Chris PeBenito [Fri, 1 Jul 2005 13:31:34 +0000 (13:31 +0000)]
convert can_kerberos()
Chris PeBenito [Fri, 1 Jul 2005 13:10:57 +0000 (13:10 +0000)]
ul has to be in a p
Chris PeBenito [Thu, 30 Jun 2005 21:11:54 +0000 (21:11 +0000)]
initial commit
Chris PeBenito [Thu, 30 Jun 2005 18:54:08 +0000 (18:54 +0000)]
more work on current modules
Chris PeBenito [Wed, 29 Jun 2005 20:53:53 +0000 (20:53 +0000)]
clean up more todos
Chris PeBenito [Wed, 29 Jun 2005 16:55:13 +0000 (16:55 +0000)]
dont show interface/template hotlinks if the module doesnt have one of them.
Chris PeBenito [Wed, 29 Jun 2005 16:54:13 +0000 (16:54 +0000)]
make layer summary required
Chris PeBenito [Wed, 29 Jun 2005 14:48:28 +0000 (14:48 +0000)]
change messages for missing docs
Chris PeBenito [Wed, 29 Jun 2005 14:48:13 +0000 (14:48 +0000)]
make interfaces or templates section not shown if empty
Chris PeBenito [Wed, 29 Jun 2005 14:26:41 +0000 (14:26 +0000)]
another round of renaming, for consistency
Chris PeBenito [Wed, 29 Jun 2005 13:05:16 +0000 (13:05 +0000)]
link fix
Chris PeBenito [Tue, 28 Jun 2005 20:54:49 +0000 (20:54 +0000)]
add logrotate, more low-hanging fruit
Chris PeBenito [Tue, 28 Jun 2005 20:41:50 +0000 (20:41 +0000)]
add templates
Chris PeBenito [Tue, 28 Jun 2005 19:51:46 +0000 (19:51 +0000)]
change desc to summary
Chris PeBenito [Tue, 28 Jun 2005 19:50:38 +0000 (19:50 +0000)]
add comments and error handling
Chris PeBenito [Tue, 28 Jun 2005 18:01:47 +0000 (18:01 +0000)]
preserve tunable values if tunables.conf exists
Chris PeBenito [Tue, 28 Jun 2005 17:48:59 +0000 (17:48 +0000)]
add lost_found_t manage, rename fs_type attribute to filesystem_type and rename fs_make_fs to fs_type
Chris PeBenito [Tue, 28 Jun 2005 17:32:57 +0000 (17:32 +0000)]
more low hanging fruit cleanup
Chris PeBenito [Tue, 28 Jun 2005 17:31:50 +0000 (17:31 +0000)]
better handling of whitespace