]> git.ipfire.org Git - people/stevee/selinux-policy.git/log
people/stevee/selinux-policy.git
13 years agoUntil the kernel stops reporting every domain that uses the network for sys_module...
Dan Walsh [Wed, 28 Sep 2011 19:37:33 +0000 (15:37 -0400)] 
Until the kernel stops reporting every domain that uses the network for sys_module, I am just going to dontaudit it

13 years agomove permissive virt_qmf_t from virt.te to permissivedomains.te
Dan Walsh [Wed, 28 Sep 2011 19:20:57 +0000 (15:20 -0400)] 
move permissive virt_qmf_t from virt.te to permissivedomains.te

13 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 28 Sep 2011 19:19:27 +0000 (15:19 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

13 years agoAllow ssh_t to use kernel keyrings
Dan Walsh [Wed, 28 Sep 2011 19:18:18 +0000 (15:18 -0400)] 
Allow ssh_t to use kernel keyrings

13 years agoAdd policy for libvirt-qmf and more fixes for linux containers
Dan Walsh [Wed, 28 Sep 2011 19:17:58 +0000 (15:17 -0400)] 
Add policy for libvirt-qmf and more fixes for linux containers

13 years agoAllow ssh_t to use kernel keyrings
Dan Walsh [Wed, 28 Sep 2011 19:17:16 +0000 (15:17 -0400)] 
Allow ssh_t to use kernel keyrings

13 years agomodemmanager uses usb tty character device nodes. rhbz#741813
Dominick Grift [Wed, 28 Sep 2011 16:52:51 +0000 (18:52 +0200)] 
modemmanager uses usb tty character device nodes. rhbz#741813

Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
13 years agoMerge branch 'polipo'
Dominick Grift [Wed, 28 Sep 2011 16:41:39 +0000 (18:41 +0200)] 
Merge branch 'polipo'

13 years agoInitial Polipo
Dominick Grift [Wed, 28 Sep 2011 16:32:27 +0000 (18:32 +0200)] 
Initial Polipo

Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
13 years agoFix whitespace
Dan Walsh [Wed, 28 Sep 2011 16:04:14 +0000 (12:04 -0400)] 
Fix whitespace

13 years agoSanlock needs to run ranged in order to kill svirt processes
Dan Walsh [Wed, 28 Sep 2011 15:38:04 +0000 (11:38 -0400)] 
Sanlock needs to run ranged in order to kill svirt processes

13 years agoAllow smbcontrol to stream connect to ctdbd
Dan Walsh [Wed, 28 Sep 2011 15:33:15 +0000 (11:33 -0400)] 
Allow smbcontrol to stream connect to ctdbd

13 years agoSwitch ftp to use auth_use_pam and move the systemd communications stuff out of auth_...
Dan Walsh [Wed, 28 Sep 2011 15:15:19 +0000 (11:15 -0400)] 
Switch ftp to use auth_use_pam and move the systemd communications stuff out of auth_login_pgm_domain into auth_use_pam, so ftp can communicate with pam_systemd

13 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Wed, 28 Sep 2011 15:06:21 +0000 (11:06 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

13 years agoActivate cron_admin_role for sysadm_t role
Dan Walsh [Wed, 28 Sep 2011 15:05:54 +0000 (11:05 -0400)] 
Activate cron_admin_role for sysadm_t role

13 years agolatest policy for confined containers
Dan Walsh [Tue, 27 Sep 2011 21:34:13 +0000 (17:34 -0400)] 
latest policy for confined containers

13 years agoMerge branch 'modem_devices'
Dominick Grift [Tue, 27 Sep 2011 18:59:59 +0000 (20:59 +0200)] 
Merge branch 'modem_devices'

13 years agoMerge branch 'grub2'
Dominick Grift [Tue, 27 Sep 2011 18:59:46 +0000 (20:59 +0200)] 
Merge branch 'grub2'

13 years agomodem_device_t is probably more suitable for these: /dev/cdc-wdm[0-1]
Dominick Grift [Tue, 27 Sep 2011 15:36:29 +0000 (17:36 +0200)] 
modem_device_t is probably more suitable for these: /dev/cdc-wdm[0-1]

Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
13 years agoFixes for vdagent policy
Miroslav Grepl [Tue, 27 Sep 2011 12:37:13 +0000 (12:37 +0000)] 
Fixes for vdagent policy

13 years agoAdd labeling for /var/run/cluster/fence_scsi.*
Miroslav Grepl [Tue, 27 Sep 2011 12:40:02 +0000 (12:40 +0000)] 
Add labeling for /var/run/cluster/fence_scsi.*

13 years agoInitial support for grub2
Dominick Grift [Tue, 27 Sep 2011 11:31:20 +0000 (13:31 +0200)] 
Initial support for grub2

Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
13 years agolapd_systemctl() interface should be ldap_systemctl
Miroslav Grepl [Tue, 27 Sep 2011 08:11:36 +0000 (08:11 +0000)] 
lapd_systemctl() interface should be ldap_systemctl

13 years agodnsmasq_systemctl() needs to be called in NetworkManager policy
Miroslav Grepl [Mon, 26 Sep 2011 23:48:46 +0000 (23:48 +0000)] 
dnsmasq_systemctl() needs to be called in NetworkManager policy

13 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Mon, 26 Sep 2011 23:41:11 +0000 (23:41 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

13 years agoFix crond_systemctl interface
Miroslav Grepl [Mon, 26 Sep 2011 23:40:08 +0000 (23:40 +0000)] 
Fix crond_systemctl interface

13 years agonetworkmanager_systemctl() was badly named
Miroslav Grepl [Mon, 26 Sep 2011 23:21:10 +0000 (23:21 +0000)] 
networkmanager_systemctl() was badly named

13 years agoFixes for thumb_t policy
Miroslav Grepl [Mon, 26 Sep 2011 22:41:17 +0000 (22:41 +0000)] 
Fixes for thumb_t policy

13 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 26 Sep 2011 21:05:27 +0000 (17:05 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

13 years agoStandardize unit files to be called unit_file_t
Dan Walsh [Mon, 26 Sep 2011 21:05:18 +0000 (17:05 -0400)] 
Standardize unit files to be called unit_file_t

13 years agoFixes to make virt_lxc work
Dan Walsh [Mon, 26 Sep 2011 21:02:25 +0000 (17:02 -0400)] 
Fixes to make virt_lxc work

13 years agoLabel ttyUSB[0-9]+ type usbtty_device_t
Dominick Grift [Mon, 26 Sep 2011 19:52:07 +0000 (21:52 +0200)] 
Label ttyUSB[0-9]+ type usbtty_device_t
Allow lircd_t to use usb tty devices.

https://bugzilla.redhat.com/show_bug.cgi?id=703190

Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
13 years agoAdd missing systemctl transitions
Dan Walsh [Mon, 26 Sep 2011 19:15:44 +0000 (15:15 -0400)] 
Add missing systemctl transitions

13 years agoAdd missing systemctl transitions
Dan Walsh [Mon, 26 Sep 2011 19:15:12 +0000 (15:15 -0400)] 
Add missing systemctl transitions

13 years agosemanage no longer touches msctransd
Dan Walsh [Mon, 26 Sep 2011 19:15:05 +0000 (15:15 -0400)] 
semanage no longer touches msctransd

13 years agoAdd rpcd_unit_file_t, and nfsd_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 19:12:22 +0000 (15:12 -0400)] 
Add rpcd_unit_file_t, and nfsd_unit_file_t support

13 years agoAdd slapd_unit_file_t support; along with other missing transitions
Dan Walsh [Mon, 26 Sep 2011 19:07:26 +0000 (15:07 -0400)] 
Add slapd_unit_file_t support; along with other missing transitions

13 years agoAdd ftpd_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 19:00:35 +0000 (15:00 -0400)] 
Add ftpd_unit_file_t support

13 years agoAdd pppd_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 18:56:53 +0000 (14:56 -0400)] 
Add pppd_unit_file_t support

13 years agoAdd nscd_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 18:53:46 +0000 (14:53 -0400)] 
Add nscd_unit_file_t support

13 years agoAdd nscd_unit_file_t support, and other systemctl transitions
Dan Walsh [Mon, 26 Sep 2011 18:50:31 +0000 (14:50 -0400)] 
Add nscd_unit_file_t support, and other systemctl transitions

13 years agoAdd NetworkManager_unit_file_t support, and other systemctl transitions
Dan Walsh [Mon, 26 Sep 2011 18:45:14 +0000 (14:45 -0400)] 
Add NetworkManager_unit_file_t support, and other systemctl transitions

13 years agoAdd dhcpcd_unit_file_t support, and fix cut and paste errors in dhcpcd and named
Dan Walsh [Mon, 26 Sep 2011 18:40:02 +0000 (14:40 -0400)] 
Add dhcpcd_unit_file_t support, and fix cut and paste errors in dhcpcd and named

13 years agoAdd dhcpcd_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 18:37:39 +0000 (14:37 -0400)] 
Add dhcpcd_unit_file_t support

13 years agoAdd named_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 18:35:16 +0000 (14:35 -0400)] 
Add named_unit_file_t support

13 years agoAdd samba_unit_file_t support
Dan Walsh [Mon, 26 Sep 2011 18:28:04 +0000 (14:28 -0400)] 
Add samba_unit_file_t support

13 years agoFix cut and paste error
Dan Walsh [Mon, 26 Sep 2011 18:23:01 +0000 (14:23 -0400)] 
Fix cut and paste error

13 years agoAdd support for kdump systemd files
Dan Walsh [Mon, 26 Sep 2011 18:22:37 +0000 (14:22 -0400)] 
Add support for kdump systemd files

13 years agoBelieve it or not I got an AVC about a mislabeled event10
Dan Walsh [Mon, 26 Sep 2011 18:10:54 +0000 (14:10 -0400)] 
Believe it or not I got an AVC about a mislabeled event10

13 years agoNead to allow the creation/deletion on nfs homedirs
Dan Walsh [Mon, 26 Sep 2011 18:04:58 +0000 (14:04 -0400)] 
Nead to allow the creation/deletion on nfs homedirs

13 years agoAdd iptables_unit_t definition and allow firewallgui to manage it
Dan Walsh [Mon, 26 Sep 2011 17:54:42 +0000 (13:54 -0400)] 
Add iptables_unit_t definition and allow firewallgui to manage it

13 years agoFixes for thumbnail module to access user_tmp_t and use fonts
Dan Walsh [Mon, 26 Sep 2011 15:37:55 +0000 (11:37 -0400)] 
Fixes for thumbnail module to access user_tmp_t and use fonts

13 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Mon, 26 Sep 2011 15:06:23 +0000 (11:06 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

13 years agoadd thumbnailer protection
Dan Walsh [Mon, 26 Sep 2011 14:56:15 +0000 (10:56 -0400)] 
add thumbnailer protection

13 years agoredundant: nis_use_ypbind is included with auth_use_nsswitch
Dominick Grift [Mon, 26 Sep 2011 14:46:35 +0000 (16:46 +0200)] 
redundant: nis_use_ypbind is included with auth_use_nsswitch

Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
13 years agoRemove duplicate interface call: auth_use_nsswitch(systemd_logind_t)
Dominick Grift [Mon, 26 Sep 2011 14:27:21 +0000 (16:27 +0200)] 
Remove duplicate interface call: auth_use_nsswitch(systemd_logind_t)

Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
13 years agoMerge branch 'newdevices'
Dominick Grift [Mon, 26 Sep 2011 14:15:07 +0000 (16:15 +0200)] 
Merge branch 'newdevices'

13 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Mon, 26 Sep 2011 15:29:33 +0000 (15:29 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

13 years agolooks like systemd_logind uses getpw call, needs to resolve uid
Dan Walsh [Mon, 26 Sep 2011 13:25:29 +0000 (09:25 -0400)] 
looks like systemd_logind uses getpw call, needs to resolve uid

13 years agoContinued work on getting libvirt-lxc to work with SELinux
Dan Walsh [Mon, 26 Sep 2011 13:17:32 +0000 (09:17 -0400)] 
Continued work on getting libvirt-lxc to work with SELinux

13 years agoAllow puppet to transition to mount and allow domains to read/write puppet log file...
Dan Walsh [Mon, 26 Sep 2011 13:16:56 +0000 (09:16 -0400)] 
Allow puppet to transition to mount and allow domains to read/write puppet log file in tmp

13 years agoAllow puppet to transition to mount and allow domains to read/write puppet log file...
Dan Walsh [Mon, 26 Sep 2011 13:16:45 +0000 (09:16 -0400)] 
Allow puppet to transition to mount and allow domains to read/write puppet log file in tmp

13 years agoMake mta_role() active
Miroslav Grepl [Mon, 26 Sep 2011 12:14:25 +0000 (12:14 +0000)] 
Make mta_role() active

13 years agoAllow asterisk to connect to jabber client port
Miroslav Grepl [Mon, 26 Sep 2011 11:45:23 +0000 (11:45 +0000)] 
Allow asterisk to connect to jabber client port

13 years agocdc-wdm0 : Ericsson F3507g Mobile Broadband Minicard Device Management
Dominick Grift [Mon, 26 Sep 2011 11:01:28 +0000 (13:01 +0200)] 
cdc-wdm0 : Ericsson F3507g Mobile Broadband Minicard Device Management
cdc-wdm1 : Ericsson F3507g Mobile Broadband Minicard PC SC Port

Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
13 years agov4l2 media controller:
Dominick Grift [Mon, 26 Sep 2011 10:54:12 +0000 (12:54 +0200)] 
v4l2 media controller:

http://linuxtv.org/downloads/presentations/summit_jun_2010/20100614-v4l2_summit-media.pdf

Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
13 years agoAllow procmail to read utmp
Miroslav Grepl [Mon, 26 Sep 2011 10:50:28 +0000 (10:50 +0000)] 
Allow procmail to read utmp

13 years agoAdd NIS support for systemd_logind_t
Miroslav Grepl [Mon, 26 Sep 2011 10:48:29 +0000 (10:48 +0000)] 
Add NIS support for systemd_logind_t
Allow systemd_logind_t to manage /run/user/$USER/dconf dir which is labeled as config_home_t

13 years agoFix systemd_manage_unit_dirs() interface
Miroslav Grepl [Sun, 25 Sep 2011 12:55:49 +0000 (12:55 +0000)] 
Fix systemd_manage_unit_dirs() interface

13 years agoadd label for /usr/sbin/libvirt-qmf
Dan Walsh [Fri, 23 Sep 2011 18:31:10 +0000 (14:31 -0400)] 
add label for /usr/sbin/libvirt-qmf

13 years agoAsterisk is now a jabber client
Dan Walsh [Fri, 23 Sep 2011 18:30:13 +0000 (14:30 -0400)] 
Asterisk is now a jabber client

13 years agoAllow ssh_t to manage directories passed into it
Dan Walsh [Fri, 23 Sep 2011 17:52:13 +0000 (13:52 -0400)] 
Allow ssh_t to manage directories passed into it

13 years agoinit needs to be able to create and delete unit file directories
Dan Walsh [Fri, 23 Sep 2011 17:51:49 +0000 (13:51 -0400)] 
init needs to be able to create and delete unit file directories

13 years agoFix typo in apache_exec_sys_script
Dan Walsh [Fri, 23 Sep 2011 17:51:17 +0000 (13:51 -0400)] 
Fix typo in apache_exec_sys_script

13 years agoTom London is seeing telepath_logger_t wanting to write to dconf/user file
Dan Walsh [Fri, 23 Sep 2011 14:57:01 +0000 (10:57 -0400)] 
Tom London is seeing telepath_logger_t wanting to write to dconf/user file

13 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Fri, 23 Sep 2011 14:49:00 +0000 (10:49 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

13 years agoAdd ability for logrotate to transition to awstat domain
Dan Walsh [Fri, 23 Sep 2011 14:48:52 +0000 (10:48 -0400)] 
Add ability for logrotate to transition to awstat domain

13 years agonconfined_domain(lxc_t) needs to be in optional block
Miroslav Grepl [Fri, 23 Sep 2011 13:51:36 +0000 (13:51 +0000)] 
nconfined_domain(lxc_t) needs to be in optional block

13 years agoDefine ssh_dyntransition_domain
Miroslav Grepl [Fri, 23 Sep 2011 13:39:40 +0000 (13:39 +0000)] 
Define ssh_dyntransition_domain

13 years agouse_samba_home_dirs() needs to be used instead of use_cifs_home_dirs()
Miroslav Grepl [Fri, 23 Sep 2011 13:27:17 +0000 (13:27 +0000)] 
use_samba_home_dirs() needs to be used instead of use_cifs_home_dirs()

13 years agoRemove duplicate declaration
Miroslav Grepl [Fri, 23 Sep 2011 13:20:36 +0000 (13:20 +0000)] 
Remove duplicate declaration

13 years agoFix ssh_dyntransition_domain_template() interface
Miroslav Grepl [Fri, 23 Sep 2011 13:18:12 +0000 (13:18 +0000)] 
Fix ssh_dyntransition_domain_template() interface

13 years agoMore fixes for screen_role_template() interface
Miroslav Grepl [Fri, 23 Sep 2011 13:14:53 +0000 (13:14 +0000)] 
More fixes for screen_role_template() interface

13 years agoFix screen_role_template() interface
Miroslav Grepl [Fri, 23 Sep 2011 13:10:48 +0000 (13:10 +0000)] 
Fix screen_role_template() interface

13 years agoFix typo
Miroslav Grepl [Fri, 23 Sep 2011 12:41:43 +0000 (12:41 +0000)] 
Fix typo

13 years agoAdd SELinux support for ssh pre-auth net process in F17
Miroslav Grepl [Fri, 23 Sep 2011 12:26:23 +0000 (12:26 +0000)] 
Add SELinux support for ssh pre-auth net process in F17

13 years agoChange screen to use screen_domain attribute and allow screen_domains to read all...
Dan Walsh [Thu, 22 Sep 2011 20:10:36 +0000 (16:10 -0400)] 
Change screen to use screen_domain attribute and allow screen_domains to read all process domain state

13 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Dan Walsh [Thu, 22 Sep 2011 15:22:58 +0000 (11:22 -0400)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

13 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 22 Sep 2011 15:38:00 +0000 (15:38 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

13 years agoAdd logging_syslogd_can_sendmail boolean
Miroslav Grepl [Thu, 22 Sep 2011 15:37:08 +0000 (15:37 +0000)] 
Add logging_syslogd_can_sendmail boolean

13 years agoAllow samba to search mountpoints for quota
Dan Walsh [Thu, 22 Sep 2011 15:22:38 +0000 (11:22 -0400)] 
Allow samba to search mountpoints for quota

13 years agoAdd support for exim and confined users
Miroslav Grepl [Thu, 22 Sep 2011 13:56:22 +0000 (13:56 +0000)] 
Add support for exim and confined users

13 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Thu, 22 Sep 2011 13:25:18 +0000 (13:25 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

13 years agosupport for ommail module to send logs via mail
Miroslav Grepl [Thu, 22 Sep 2011 13:24:24 +0000 (13:24 +0000)] 
support for ommail module to send logs via mail

13 years agosssd wants to read sysfs
Dan Walsh [Thu, 22 Sep 2011 13:06:23 +0000 (09:06 -0400)] 
sssd wants to read sysfs

13 years agoServices, which has systemd integration, needs to write to /var/run/systemd/notify...
Miroslav Grepl [Thu, 22 Sep 2011 12:40:15 +0000 (12:40 +0000)] 
Services, which has systemd integration, needs to write to /var/run/systemd/notify when have been started

13 years agoAdd execmem_execmod() to execmem role
Miroslav Grepl [Thu, 22 Sep 2011 12:36:00 +0000 (12:36 +0000)] 
Add execmem_execmod() to execmem role

13 years agoAllow passwd_t to search for terminals
Dan Walsh [Wed, 21 Sep 2011 19:50:57 +0000 (15:50 -0400)] 
Allow passwd_t to search for terminals

13 years agoMerge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
Miroslav Grepl [Wed, 21 Sep 2011 16:16:05 +0000 (16:16 +0000)] 
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy

13 years agoDontaudit passwd getattr on /dev
Miroslav Grepl [Wed, 21 Sep 2011 16:15:44 +0000 (16:15 +0000)] 
Dontaudit passwd getattr on /dev