Commit Graph

16 Commits

Author SHA1 Message Date
Dan Walsh
662016aa11 We need to setcheckreqprot to 0 for security purposes 2015-04-16 14:00:38 -04:00
Lukas Vrabec
bfb6adef8b Added support for linuxptp policy. 2014-11-07 19:12:59 +01:00
Lukas Vrabec
2ca2a22c66 Added mon_statd_t and mon_procd_t to permissivedomains. 2014-10-13 15:45:06 +02:00
Lukas Vrabec
d805f9bbca Make cpuplug policy permissive 2014-10-06 15:23:35 +02:00
Lukas Vrabec
dbbe68629e Add brltty policy to permissive policies. 2014-10-06 13:10:48 +02:00
Lukas Vrabec
3ad626f241 Add support for naemon, Add naemon to permissive domains 2014-07-22 13:45:54 +02:00
Lukas Vrabec
1dda0950c8 Add kmscon policy to modules-targeted-contrib.conf and to
permissivedomains
2014-06-12 18:00:33 +02:00
Lukas Vrabec
e929b7e20b Added iotop to permissive domains, and modules-targeted-contrib 2014-05-12 15:42:54 +02:00
Miroslav Grepl
ab84f40064 - Allow init_t to stream connect to ipsec
- Add /usr/lib/systemd/systemd-networkd policy
- Add sysnet_manage_config_dirs()
- Add support for /var/run/systemd/network and labeled it as net_conf_t
- Allow unpriv SELinux users to dbus chat with firewalld
- Add lvm_write_metadata()
- Label /etc/yum.reposd dir as system_conf_t. Should be safe because system_conf_t is base_ro_file_type
- Add support for /dev/vmcp and /dev/sclp
- Add docker_connect_any boolean
- Fix zabbix policy
- Allow zabbix to send system log msgs
- Allow pegasus_openlmi_storage_t to write lvm metadata
- Updated pcp_bind_all_unreserved_ports
- Allow numad to write scan_sleep_millisecs
- Turn on entropyd_use_audio boolean by default
- Allow cgred to read /etc/cgconfig.conf because it contains templates used together with rules from /etc/cgrules.conf.
- Allow lscpu running as rhsmcertd_t to read /proc/sysinfo
2014-03-12 11:14:14 +01:00
Miroslav Grepl
4aa43e264a Rebuild permissivedomains.pp to reflect latest changes 2014-02-28 12:15:16 +01:00
Lukas Vrabec
4cde844b7e Added osad to permissive domains 2014-02-03 14:09:01 +01:00
Miroslav Grepl
73e97a2955 Rebuild permissivedomains.pp with correct selinux-policy-devel pkg 2013-11-12 11:42:46 +01:00
Miroslav Grepl
9637dbab40 Rebuild permisivedomains.pp 2013-11-12 10:09:09 +01:00
Dan Walsh
01be266ba7 Bump the policy version to 28 to match selinux userspace
- Rebuild versus latest libsepol
2013-01-06 10:35:25 -05:00
Miroslav Grepl
a270091f19 Make rawhide == f18 2012-12-17 17:21:00 +01:00
Miroslav Grepl
4daeee80d1 Add permissivedomains module
* sync with F17
2012-06-06 15:26:24 +02:00