Commit Graph

559 Commits

Author SHA1 Message Date
Chris PeBenito
a573790b4d make default for optional modules to module instead of base 2005-08-15 20:31:37 +00:00
Chris PeBenito
4806a05cfb fix broken xml of previous commit 2005-08-15 19:35:20 +00:00
Chris PeBenito
5f38a65aab try to knock out more of the distro_debian bootloader stuff 2005-08-15 19:31:37 +00:00
Chris PeBenito
21468a6076 add loadkeys 2005-08-15 14:46:17 +00:00
Chris PeBenito
8843093607 more comments 2005-08-12 19:28:30 +00:00
Chris PeBenito
f0b1efa2a2 all dev nodes assoc to tmpfs, since most everyone is moving to udev 2005-08-12 19:28:15 +00:00
Chris PeBenito
c5a6dcbc3e quiet file context validation 2005-08-12 18:15:00 +00:00
Chris PeBenito
35b494789d fix some udev naming 2005-08-12 18:13:03 +00:00
Chris PeBenito
aae06c1306 fix system spool file problem 2005-08-12 17:54:55 +00:00
Chris PeBenito
d06f3c3752 remove secdesc since desc is sufficient 2005-08-11 17:55:47 +00:00
Chris PeBenito
f7ebea06e3 finalize desc -> summary xml change 2005-08-11 17:46:39 +00:00
Chris PeBenito
4aa0dc20b4 add tcpd 2005-08-11 15:17:13 +00:00
Chris PeBenito
e694b51e6b fix no interface module handling in segenxml 2005-08-11 14:55:41 +00:00
Chris PeBenito
052c953ae5 add quota 2005-08-11 14:49:58 +00:00
Chris PeBenito
5a3895a9f6 tabbing fix 2005-08-11 14:35:52 +00:00
Chris PeBenito
e784300a62 add sudo 2005-08-09 19:30:43 +00:00
Chris PeBenito
b9d7d70b33 add template xml 2005-08-09 19:21:25 +00:00
Chris PeBenito
9489149ec0 add su 2005-08-08 21:03:23 +00:00
Chris PeBenito
9465452eec fix gen_user comment for more clarity 2005-08-08 18:13:56 +00:00
Chris PeBenito
dce68dc48d add updfstab 2005-08-08 15:51:15 +00:00
Chris PeBenito
f5e321b0f0 fix xml tags 2005-08-08 15:43:20 +00:00
Chris PeBenito
7057c18db0 a few more ssh touchups 2005-08-05 18:49:23 +00:00
Chris PeBenito
ed78ea0034 add tmpreaper 2005-08-05 15:32:27 +00:00
Chris PeBenito
9a66d4e562 add acct 2005-08-05 14:32:12 +00:00
Chris PeBenito
3fd8336882 misc cleanup 2005-08-04 20:54:51 +00:00
Chris PeBenito
42be7c214d add mysql 2005-08-03 17:56:26 +00:00
Chris PeBenito
046a21da80 search sbin dirs to find the pgms 2005-08-03 17:43:41 +00:00
Chris PeBenito
81343a6f90 * Rename ipsec connect interface for consistency.
* Add missing parts of unix stream socket connect interface
  of ipsec.
* Rename inetd connect interface for consistency.
2005-08-03 15:16:33 +00:00
Chris PeBenito
52a902b803 new release 2005-08-02 14:54:30 +00:00
Chris PeBenito
6db8e52a8f new release 2005-08-02 14:51:50 +00:00
Chris PeBenito
60abb5fdab add missing 2005-08-01 15:58:14 +00:00
Chris PeBenito
cd8fa41253 fix comparison bug 2005-08-01 15:49:05 +00:00
Chris PeBenito
96a150deac move file context validation to install 2005-07-29 20:49:52 +00:00
Chris PeBenito
bbdbdb9edf fix stray line that got out of TODO 2005-07-29 15:07:15 +00:00
Chris PeBenito
e5590ea5ec work on user transition 2005-07-28 20:52:55 +00:00
Chris PeBenito
c13146d97a update 2005-07-27 21:01:19 +00:00
Chris PeBenito
78d30cb1f4 Fix handling of ordered and unordered HTML lists. 2005-07-22 19:15:49 +00:00
Chris PeBenito
022f61c0e3 add connect interface on ports to handle name_connect tcp perm 2005-07-22 15:38:01 +00:00
Chris PeBenito
50527cf581 make network_interface able to support multiple interfaces having the same type 2005-07-22 14:00:38 +00:00
Chris PeBenito
953541a918 update from privmail 2005-07-21 20:34:57 +00:00
Chris PeBenito
80526ccbdd add an example module config for a targeted policy 2005-07-20 20:11:49 +00:00
Chris PeBenito
ea7d571bd7 /var/lib is now a mountpoint 2005-07-20 17:36:48 +00:00
Chris PeBenito
53857c8c05 unconfined can pass all constraints 2005-07-20 17:24:23 +00:00
Chris PeBenito
ef424c14d4 name_connect only on tcp_sockets 2005-07-20 17:10:07 +00:00
Chris PeBenito
9496fd5119 unconfined can name_connect to all ports 2005-07-20 17:08:07 +00:00
Chris PeBenito
d250634311 reorder kernel policy, add attributes for sysctl and proc entries. fix unconfined interface 2005-07-20 17:06:10 +00:00
Chris PeBenito
f82c6ac64c bah typo 2005-07-20 15:08:33 +00:00
Chris PeBenito
0b28a23114 user home dirs were missing file type in targ policy 2005-07-20 15:06:49 +00:00
Chris PeBenito
1e3f610b3b add missing dir and file perms for selinuxfs in unconfined 2005-07-20 14:57:13 +00:00
Chris PeBenito
689f6ddb35 fix typos and import some rules from NSA cvs to make targeted policy work 2005-07-20 14:25:24 +00:00
Chris PeBenito
474f43d13d should actually try compiling first :x 2005-07-20 13:39:10 +00:00
Chris PeBenito
bd7e7a6417 missed a line 2005-07-20 13:37:18 +00:00
Chris PeBenito
a28f6db576 add in some rules from NSA CVS to make targeted policy work 2005-07-20 13:30:06 +00:00
Chris PeBenito
8c3f438f75 corenet was missing from unconfined 2005-07-19 20:38:26 +00:00
Chris PeBenito
892266ca76 more targeted policy fixes 2005-07-19 20:26:02 +00:00
Chris PeBenito
21f47732b1 add new netlink socket class 2005-07-19 20:25:42 +00:00
Chris PeBenito
ec848d247f more fixes for targeted 2005-07-19 19:37:43 +00:00
Chris PeBenito
2ec4c9d38f more cleanup 2005-07-19 18:40:31 +00:00
Chris PeBenito
8b0bbdda34 fixes for targeted policy 2005-07-19 18:40:19 +00:00
Chris PeBenito
391edeb577 fix assertions for framework 2005-07-18 20:17:21 +00:00
Chris PeBenito
a5f339f134 more cleanup in system 2005-07-18 18:31:49 +00:00
Chris PeBenito
9f103ce14b fix to use context_template() 2005-07-18 14:25:05 +00:00
Chris PeBenito
3b6174a142 add missing context template 2005-07-15 20:54:24 +00:00
Chris PeBenito
50aca6d2f9 add raid (mdadm) 2005-07-15 20:45:26 +00:00
Chris PeBenito
d9fd8e7562 more pcmcia cleanup 2005-07-15 19:18:55 +00:00
Chris PeBenito
157c69416f add macro to expand object class sets for use in require blocks 2005-07-15 15:53:54 +00:00
Chris PeBenito
50f6503452 * break up files_getattr_all_files into correct interfaces
* move stuff out of pcmcia into the appropriate modules
2005-07-15 15:17:57 +00:00
Chris PeBenito
f136a944c5 reorder in alpha order of type, for sanity purposes 2005-07-15 14:30:19 +00:00
Chris PeBenito
316553a275 add pcmcia 2005-07-14 20:58:57 +00:00
Chris PeBenito
e0d57fbcb1 add pcmcia 2005-07-14 20:57:17 +00:00
Chris PeBenito
c429cb5e26 fix up the xml 2005-07-14 20:02:53 +00:00
Chris PeBenito
11633bbaa8 add ipsec 2005-07-14 18:15:47 +00:00
Chris PeBenito
493d6c4adc add nscd 2005-07-13 20:48:51 +00:00
Chris PeBenito
df00b2e235 * fix chroot exec interface
* more TODO cleanup
* move IPC out of generic domtrans interfaces
2005-07-13 18:29:08 +00:00
Chris PeBenito
25a0c61ffc add distro tunables. expand on a few comments 2005-07-13 18:08:12 +00:00
Chris PeBenito
b24f35d8a3 more cleanup of current TODOs 2005-07-12 20:34:24 +00:00
Chris PeBenito
20a22759a7 fix comments for templates to have same number of # as interfaces 2005-07-12 20:33:42 +00:00
Chris PeBenito
4051d15b62 fix xml 2005-07-11 19:15:54 +00:00
Chris PeBenito
ae9e2716c3 fix more TODOs. fix selinux.te to selinuxutil.te in optionals 2005-07-11 19:02:50 +00:00
Chris PeBenito
34bbe50d50 improve display of tunables and booleans 2005-07-11 14:41:21 +00:00
Chris PeBenito
4d7511ba57 add tun and bool descriptions 2005-07-11 13:49:15 +00:00
Chris PeBenito
249d461f23 initial global booleans and tunables support. also fix index
building, as it was being rebuilt for every module, rather then
once after all modules are loaded.
2005-07-08 21:02:59 +00:00
Chris PeBenito
a42ca7ebec another round of TODO cleanup 2005-07-08 20:44:57 +00:00
Chris PeBenito
4d0d4157f4 silly formatting fix 2005-07-08 19:44:12 +00:00
Chris PeBenito
c11958bd0f support for global booleans 2005-07-08 14:22:17 +00:00
Chris PeBenito
acb668edf1 * Added support for layer summaries.
* Added a "Index" link on the menu to link to index.html
* Added links from the master interface & template lists
  to their respective documentation in their module.
* Added links to "Interfaces" and "Templates" in modules
  that have both.
* Added "Return" links after the "Interfaces" and "Templates"
  section that go to the top of the module site.
2005-07-07 20:56:27 +00:00
Chris PeBenito
58c7777e14 tag for 20050707 release 2005-07-07 17:25:53 +00:00
Chris PeBenito
dfa83e924c add changelog 2005-07-07 17:13:17 +00:00
Chris PeBenito
e5f8060316 implement direct_sysadm_daemon 2005-07-07 15:25:28 +00:00
Chris PeBenito
1aa526281b missing rules uncovered by sediff 2005-07-07 15:20:24 +00:00
Chris PeBenito
c98340cfeb support for targeted policy 2005-07-06 20:28:29 +00:00
Chris PeBenito
83ce670b3d put back to strict. will have separate strict and targeted appconfig 2005-07-06 19:42:27 +00:00
Chris PeBenito
14b25bc455 validate file contexts 2005-07-06 18:34:27 +00:00
Chris PeBenito
ed1a92b88c ksu moves to su 2005-07-06 17:41:58 +00:00
Chris PeBenito
bb32544d61 add missing ssh file contexts 2005-07-06 15:59:54 +00:00
Chris PeBenito
a3fdcebc6a quiet the awk if modules.conf doesnt exist 2005-07-06 15:24:45 +00:00
Karl MacMillan
ebb884dec2 - Removed OUTPUT_VERSION as default.
- Added default name as refpolicy to avoid clobbering string installs
2005-07-06 15:23:28 +00:00
Chris PeBenito
e17cb83c3d update appconfig for unconfined login 2005-07-06 13:12:20 +00:00
Chris PeBenito
9726b31857 add unconfined 2005-07-05 20:59:51 +00:00
Chris PeBenito
e8f0055b6d fix quoting problem 2005-07-05 20:54:12 +00:00