]>
git.ipfire.org Git - people/stevee/selinux-policy.git/log
Dan Walsh [Wed, 28 Sep 2011 19:37:33 +0000 (15:37 -0400)]
Until the kernel stops reporting every domain that uses the network for sys_module, I am just going to dontaudit it
Dan Walsh [Wed, 28 Sep 2011 19:20:57 +0000 (15:20 -0400)]
move permissive virt_qmf_t from virt.te to permissivedomains.te
Dan Walsh [Wed, 28 Sep 2011 19:19:27 +0000 (15:19 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 28 Sep 2011 19:18:18 +0000 (15:18 -0400)]
Allow ssh_t to use kernel keyrings
Dan Walsh [Wed, 28 Sep 2011 19:17:58 +0000 (15:17 -0400)]
Add policy for libvirt-qmf and more fixes for linux containers
Dan Walsh [Wed, 28 Sep 2011 19:17:16 +0000 (15:17 -0400)]
Allow ssh_t to use kernel keyrings
Dominick Grift [Wed, 28 Sep 2011 16:52:51 +0000 (18:52 +0200)]
modemmanager uses usb tty character device nodes. rhbz#741813
Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
Dominick Grift [Wed, 28 Sep 2011 16:41:39 +0000 (18:41 +0200)]
Merge branch 'polipo'
Dominick Grift [Wed, 28 Sep 2011 16:32:27 +0000 (18:32 +0200)]
Initial Polipo
Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
Dan Walsh [Wed, 28 Sep 2011 16:04:14 +0000 (12:04 -0400)]
Fix whitespace
Dan Walsh [Wed, 28 Sep 2011 15:38:04 +0000 (11:38 -0400)]
Sanlock needs to run ranged in order to kill svirt processes
Dan Walsh [Wed, 28 Sep 2011 15:33:15 +0000 (11:33 -0400)]
Allow smbcontrol to stream connect to ctdbd
Dan Walsh [Wed, 28 Sep 2011 15:15:19 +0000 (11:15 -0400)]
Switch ftp to use auth_use_pam and move the systemd communications stuff out of auth_login_pgm_domain into auth_use_pam, so ftp can communicate with pam_systemd
Dan Walsh [Wed, 28 Sep 2011 15:06:21 +0000 (11:06 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 28 Sep 2011 15:05:54 +0000 (11:05 -0400)]
Activate cron_admin_role for sysadm_t role
Dan Walsh [Tue, 27 Sep 2011 21:34:13 +0000 (17:34 -0400)]
latest policy for confined containers
Dominick Grift [Tue, 27 Sep 2011 18:59:59 +0000 (20:59 +0200)]
Merge branch 'modem_devices'
Dominick Grift [Tue, 27 Sep 2011 18:59:46 +0000 (20:59 +0200)]
Merge branch 'grub2'
Dominick Grift [Tue, 27 Sep 2011 15:36:29 +0000 (17:36 +0200)]
modem_device_t is probably more suitable for these: /dev/cdc-wdm[0-1]
Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
Miroslav Grepl [Tue, 27 Sep 2011 12:37:13 +0000 (12:37 +0000)]
Fixes for vdagent policy
Miroslav Grepl [Tue, 27 Sep 2011 12:40:02 +0000 (12:40 +0000)]
Add labeling for /var/run/cluster/fence_scsi.*
Dominick Grift [Tue, 27 Sep 2011 11:31:20 +0000 (13:31 +0200)]
Initial support for grub2
Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
Miroslav Grepl [Tue, 27 Sep 2011 08:11:36 +0000 (08:11 +0000)]
lapd_systemctl() interface should be ldap_systemctl
Miroslav Grepl [Mon, 26 Sep 2011 23:48:46 +0000 (23:48 +0000)]
dnsmasq_systemctl() needs to be called in NetworkManager policy
Miroslav Grepl [Mon, 26 Sep 2011 23:41:11 +0000 (23:41 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Mon, 26 Sep 2011 23:40:08 +0000 (23:40 +0000)]
Fix crond_systemctl interface
Miroslav Grepl [Mon, 26 Sep 2011 23:21:10 +0000 (23:21 +0000)]
networkmanager_systemctl() was badly named
Miroslav Grepl [Mon, 26 Sep 2011 22:41:17 +0000 (22:41 +0000)]
Fixes for thumb_t policy
Dan Walsh [Mon, 26 Sep 2011 21:05:27 +0000 (17:05 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 26 Sep 2011 21:05:18 +0000 (17:05 -0400)]
Standardize unit files to be called unit_file_t
Dan Walsh [Mon, 26 Sep 2011 21:02:25 +0000 (17:02 -0400)]
Fixes to make virt_lxc work
Dominick Grift [Mon, 26 Sep 2011 19:52:07 +0000 (21:52 +0200)]
Label ttyUSB[0-9]+ type usbtty_device_t
Allow lircd_t to use usb tty devices.
https://bugzilla.redhat.com/show_bug.cgi?id=703190
Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
Dan Walsh [Mon, 26 Sep 2011 19:15:44 +0000 (15:15 -0400)]
Add missing systemctl transitions
Dan Walsh [Mon, 26 Sep 2011 19:15:12 +0000 (15:15 -0400)]
Add missing systemctl transitions
Dan Walsh [Mon, 26 Sep 2011 19:15:05 +0000 (15:15 -0400)]
semanage no longer touches msctransd
Dan Walsh [Mon, 26 Sep 2011 19:12:22 +0000 (15:12 -0400)]
Add rpcd_unit_file_t, and nfsd_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 19:07:26 +0000 (15:07 -0400)]
Add slapd_unit_file_t support; along with other missing transitions
Dan Walsh [Mon, 26 Sep 2011 19:00:35 +0000 (15:00 -0400)]
Add ftpd_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 18:56:53 +0000 (14:56 -0400)]
Add pppd_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 18:53:46 +0000 (14:53 -0400)]
Add nscd_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 18:50:31 +0000 (14:50 -0400)]
Add nscd_unit_file_t support, and other systemctl transitions
Dan Walsh [Mon, 26 Sep 2011 18:45:14 +0000 (14:45 -0400)]
Add NetworkManager_unit_file_t support, and other systemctl transitions
Dan Walsh [Mon, 26 Sep 2011 18:40:02 +0000 (14:40 -0400)]
Add dhcpcd_unit_file_t support, and fix cut and paste errors in dhcpcd and named
Dan Walsh [Mon, 26 Sep 2011 18:37:39 +0000 (14:37 -0400)]
Add dhcpcd_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 18:35:16 +0000 (14:35 -0400)]
Add named_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 18:28:04 +0000 (14:28 -0400)]
Add samba_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 18:23:01 +0000 (14:23 -0400)]
Fix cut and paste error
Dan Walsh [Mon, 26 Sep 2011 18:22:37 +0000 (14:22 -0400)]
Add support for kdump systemd files
Dan Walsh [Mon, 26 Sep 2011 18:10:54 +0000 (14:10 -0400)]
Believe it or not I got an AVC about a mislabeled event10
Dan Walsh [Mon, 26 Sep 2011 18:04:58 +0000 (14:04 -0400)]
Nead to allow the creation/deletion on nfs homedirs
Dan Walsh [Mon, 26 Sep 2011 17:54:42 +0000 (13:54 -0400)]
Add iptables_unit_t definition and allow firewallgui to manage it
Dan Walsh [Mon, 26 Sep 2011 15:37:55 +0000 (11:37 -0400)]
Fixes for thumbnail module to access user_tmp_t and use fonts
Dan Walsh [Mon, 26 Sep 2011 15:06:23 +0000 (11:06 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 26 Sep 2011 14:56:15 +0000 (10:56 -0400)]
add thumbnailer protection
Dominick Grift [Mon, 26 Sep 2011 14:46:35 +0000 (16:46 +0200)]
redundant: nis_use_ypbind is included with auth_use_nsswitch
Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
Dominick Grift [Mon, 26 Sep 2011 14:27:21 +0000 (16:27 +0200)]
Remove duplicate interface call: auth_use_nsswitch(systemd_logind_t)
Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
Dominick Grift [Mon, 26 Sep 2011 14:15:07 +0000 (16:15 +0200)]
Merge branch 'newdevices'
Miroslav Grepl [Mon, 26 Sep 2011 15:29:33 +0000 (15:29 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 26 Sep 2011 13:25:29 +0000 (09:25 -0400)]
looks like systemd_logind uses getpw call, needs to resolve uid
Dan Walsh [Mon, 26 Sep 2011 13:17:32 +0000 (09:17 -0400)]
Continued work on getting libvirt-lxc to work with SELinux
Dan Walsh [Mon, 26 Sep 2011 13:16:56 +0000 (09:16 -0400)]
Allow puppet to transition to mount and allow domains to read/write puppet log file in tmp
Dan Walsh [Mon, 26 Sep 2011 13:16:45 +0000 (09:16 -0400)]
Allow puppet to transition to mount and allow domains to read/write puppet log file in tmp
Miroslav Grepl [Mon, 26 Sep 2011 12:14:25 +0000 (12:14 +0000)]
Make mta_role() active
Miroslav Grepl [Mon, 26 Sep 2011 11:45:23 +0000 (11:45 +0000)]
Allow asterisk to connect to jabber client port
Dominick Grift [Mon, 26 Sep 2011 11:01:28 +0000 (13:01 +0200)]
cdc-wdm0 : Ericsson F3507g Mobile Broadband Minicard Device Management
cdc-wdm1 : Ericsson F3507g Mobile Broadband Minicard PC SC Port
Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
Dominick Grift [Mon, 26 Sep 2011 10:54:12 +0000 (12:54 +0200)]
v4l2 media controller:
http://linuxtv.org/downloads/presentations/summit_jun_2010/
20100614 -v4l2_summit-media.pdf
Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
Miroslav Grepl [Mon, 26 Sep 2011 10:50:28 +0000 (10:50 +0000)]
Allow procmail to read utmp
Miroslav Grepl [Mon, 26 Sep 2011 10:48:29 +0000 (10:48 +0000)]
Add NIS support for systemd_logind_t
Allow systemd_logind_t to manage /run/user/$USER/dconf dir which is labeled as config_home_t
Miroslav Grepl [Sun, 25 Sep 2011 12:55:49 +0000 (12:55 +0000)]
Fix systemd_manage_unit_dirs() interface
Dan Walsh [Fri, 23 Sep 2011 18:31:10 +0000 (14:31 -0400)]
add label for /usr/sbin/libvirt-qmf
Dan Walsh [Fri, 23 Sep 2011 18:30:13 +0000 (14:30 -0400)]
Asterisk is now a jabber client
Dan Walsh [Fri, 23 Sep 2011 17:52:13 +0000 (13:52 -0400)]
Allow ssh_t to manage directories passed into it
Dan Walsh [Fri, 23 Sep 2011 17:51:49 +0000 (13:51 -0400)]
init needs to be able to create and delete unit file directories
Dan Walsh [Fri, 23 Sep 2011 17:51:17 +0000 (13:51 -0400)]
Fix typo in apache_exec_sys_script
Dan Walsh [Fri, 23 Sep 2011 14:57:01 +0000 (10:57 -0400)]
Tom London is seeing telepath_logger_t wanting to write to dconf/user file
Dan Walsh [Fri, 23 Sep 2011 14:49:00 +0000 (10:49 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 23 Sep 2011 14:48:52 +0000 (10:48 -0400)]
Add ability for logrotate to transition to awstat domain
Miroslav Grepl [Fri, 23 Sep 2011 13:51:36 +0000 (13:51 +0000)]
nconfined_domain(lxc_t) needs to be in optional block
Miroslav Grepl [Fri, 23 Sep 2011 13:39:40 +0000 (13:39 +0000)]
Define ssh_dyntransition_domain
Miroslav Grepl [Fri, 23 Sep 2011 13:27:17 +0000 (13:27 +0000)]
use_samba_home_dirs() needs to be used instead of use_cifs_home_dirs()
Miroslav Grepl [Fri, 23 Sep 2011 13:20:36 +0000 (13:20 +0000)]
Remove duplicate declaration
Miroslav Grepl [Fri, 23 Sep 2011 13:18:12 +0000 (13:18 +0000)]
Fix ssh_dyntransition_domain_template() interface
Miroslav Grepl [Fri, 23 Sep 2011 13:14:53 +0000 (13:14 +0000)]
More fixes for screen_role_template() interface
Miroslav Grepl [Fri, 23 Sep 2011 13:10:48 +0000 (13:10 +0000)]
Fix screen_role_template() interface
Miroslav Grepl [Fri, 23 Sep 2011 12:41:43 +0000 (12:41 +0000)]
Fix typo
Miroslav Grepl [Fri, 23 Sep 2011 12:26:23 +0000 (12:26 +0000)]
Add SELinux support for ssh pre-auth net process in F17
Dan Walsh [Thu, 22 Sep 2011 20:10:36 +0000 (16:10 -0400)]
Change screen to use screen_domain attribute and allow screen_domains to read all process domain state
Dan Walsh [Thu, 22 Sep 2011 15:22:58 +0000 (11:22 -0400)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 22 Sep 2011 15:38:00 +0000 (15:38 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 22 Sep 2011 15:37:08 +0000 (15:37 +0000)]
Add logging_syslogd_can_sendmail boolean
Dan Walsh [Thu, 22 Sep 2011 15:22:38 +0000 (11:22 -0400)]
Allow samba to search mountpoints for quota
Miroslav Grepl [Thu, 22 Sep 2011 13:56:22 +0000 (13:56 +0000)]
Add support for exim and confined users
Miroslav Grepl [Thu, 22 Sep 2011 13:25:18 +0000 (13:25 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 22 Sep 2011 13:24:24 +0000 (13:24 +0000)]
support for ommail module to send logs via mail
Dan Walsh [Thu, 22 Sep 2011 13:06:23 +0000 (09:06 -0400)]
sssd wants to read sysfs
Miroslav Grepl [Thu, 22 Sep 2011 12:40:15 +0000 (12:40 +0000)]
Services, which has systemd integration, needs to write to /var/run/systemd/notify when have been started
Miroslav Grepl [Thu, 22 Sep 2011 12:36:00 +0000 (12:36 +0000)]
Add execmem_execmod() to execmem role
Dan Walsh [Wed, 21 Sep 2011 19:50:57 +0000 (15:50 -0400)]
Allow passwd_t to search for terminals
Miroslav Grepl [Wed, 21 Sep 2011 16:16:05 +0000 (16:16 +0000)]
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 21 Sep 2011 16:15:44 +0000 (16:15 +0000)]
Dontaudit passwd getattr on /dev