Commit Graph

24 Commits

Author SHA1 Message Date
Radovan Sroka
6228fd0a74 Rebase to 1.1.5
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2022-09-29 11:11:31 +02:00
Radovan Sroka
26e3a4e777 Rebase to 1.1.4
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2022-08-18 18:05:02 +02:00
Radovan Sroka
40537635b8 Rebase to 1.1.3
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2022-06-22 10:20:36 +02:00
Radovan Sroka
182cc455be
Rebase to v1.1.2
- fixed CVE-2022-1117
Resolves: rhbz#2089692

Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2022-05-25 13:41:20 +02:00
Radovan Sroka
16e5a8779e
Rebase to v1.1.1
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2022-03-30 14:01:49 +02:00
Radovan Sroka
f87a5c2885 Rebase to v1.1
- added rules.d support
2022-01-26 15:01:47 +01:00
Radovan Sroka
34bdf6e5b0
Rebase to 1.0.4
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2021-12-10 18:07:27 +01:00
Radovan Sroka
907e9a087e
Rebase to 1.0.3
- sync fedora spec with rhel

Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2021-04-01 22:48:40 +02:00
Radovan Sroka
3cdc28b4cb
Rebase to 1.0.2
- enabled make check
- dnf-plugin is now required subpackage
2021-01-06 17:51:52 +01:00
Radovan Sroka
e97bf03c73
Rebase to 1.0.1
- introduced uthash dependency
- SELinux prevents the fapolicyd process from writing to /run/dbus/system_bus_socket
  Resolves: rhbz#1874491
- SELinux prevents the fapolicyd process from writing to /var/lib/rpm directory
  Resolves: rhbz#1876538
2020-11-17 09:45:08 +01:00
Radovan Sroka
dbbcd10a89
New update of fapolicyd
- backported few cosmetic small patches from upstream master
- rebase selinux tarbal to v0.3
- file context pattern for /run/fapolicyd.pid is missing
  Resolves: rhbz#1834674

Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2020-06-24 17:18:23 +02:00
Radovan Sroka
5edde88663 Rebase fapolicyd to 1.0.0
- release now has 3 integrity modes: file size, IMA, and sha256 based
- it can now send event information to syslog
- the syslog event information is tailorable to how you'd like to see it
- there is now the ability to create sets of words that can be matched
  against in the rules engine
- there are now 2 policies shipped: known-libs and restrictive
- fapolicyd-cli can now dump the trust db for inspection
- the integrity system needs sha256 hashes,
  it will print a warning for files in rpms that do not have them
2020-05-25 15:20:08 +02:00
Radovan Sroka
9f13f29104 Rebase fapolicyd to 0.9.4
- polished the pattern detection engine
- rpm backend now drops most of the files in /usr/share/ to dramatically reduce
  memory consumption and improve startup speed
- the commandline utility can now delete the lmdb trust database and manage
    the file trust source
2020-03-23 18:57:05 +01:00
Radovan Sroka
4ffeb28e23 Rebase fapolicyd to 0.9.3
- dramatically improved startup time
- fapolicyd-cli has picked up --list and --ftype commands to help debug/write policy
- file type identification has been improved
- trust database statistics have been added to the reports
2020-02-24 14:20:46 +01:00
Radovan Sroka
193b9f0cdf Rebase to fapolicyd 0.9.2
- allows watched mount points to be specified by file system types
- ELF file detection was improved
- the rules have been rewritten to express the policy based on subject
  object trust for better performance and reliability
- exceptions for dracut and ansible were added to the rules to avoid problems
  under normal system use
- adds an admin defined trust database (fapolicyd.trust)
- setting boost, queue, user, and group on the daemon
  command line are deprecated
2020-02-03 12:35:43 +01:00
Marek Tamaskovic
e46e1e19b2 Update fapolicyd-selinux subpackage to version v0.2 2019-11-05 15:01:27 +01:00
Radovan Sroka
73b7231dfc Added fapolicyd-selinux subpackage 2019-10-07 14:46:26 +02:00
Radovan Sroka
32c7f28dc8 New upstream release
Improved subject cache management, performance improvements, drop need for
fapolicyd.mounts file - daemon detects filesystems to monitor, stop collecting
documentation in the trust database, and handle long paths.
2019-10-07 13:40:06 +02:00
Radovan Sroka
157f8de90e Rebase to 0.8.10 2019-08-30 13:05:25 +02:00
Radovan Sroka
c8075c471d New upstream release
This release features:
- systemd usage updates
- file permission adjustments based on selinux policy review
- unterminated reads of auid & sessionid values was fixed
- ld_preload pattern is deprecated for now
2019-05-06 12:27:39 +02:00
Radovan Sroka
f575ae0ed6 New upstream release
- Added new DNF plugin that can update the trust database when rpms are installed
- Added support for FAN_OPEN_EXEC_PERM
2019-03-11 12:23:07 +01:00
Steve Grubb
c2c99a33af New upstream bugfix release 2018-10-03 18:24:56 -04:00
Steve Grubb
1e0f11df55 New upstream feature release 2018-06-07 09:01:29 -04:00
Steve Grubb
c6fc94a305 Initial import (#1544468) 2018-02-16 13:58:12 -05:00