Chris PeBenito
6c8aba7b31
trunk: confine sendmail and logrotate on targeted
2007-06-19 17:01:39 +00:00
Chris PeBenito
cb10a2d5bf
trunk: Tunable connection to postgresql for users from KaiGai Kohei.
2007-06-19 14:30:06 +00:00
Chris PeBenito
41337aa8b9
Memprotect support patch from Stephen Smalley.
2007-06-19 13:02:26 +00:00
Chris PeBenito
d139413c64
trunk: 2 patches from dan
2007-06-13 13:54:56 +00:00
Chris PeBenito
a74d1ad7cd
trunk: add amtu from dan
2007-06-12 18:58:36 +00:00
Chris PeBenito
d5b81a81ff
trunk: Add logging_send_audit_msgs() interface and deprecate send_audit_msgs_pattern().
2007-06-12 18:46:14 +00:00
Chris PeBenito
262def165a
trunk: version bumps for previous commit.
2007-06-12 13:08:19 +00:00
Chris PeBenito
f7101c5430
trunk: 7 simple patches from dan.
2007-06-12 13:06:13 +00:00
Chris PeBenito
6649aec9d0
trunk: 3 patches from dan
2007-06-11 15:43:37 +00:00
Chris PeBenito
d534d35a7e
trunk: 5 patches from dan
2007-06-11 15:01:10 +00:00
Chris PeBenito
f6a590d7b4
six simple patches from dan
2007-06-11 14:09:09 +00:00
Chris PeBenito
7782966db1
add fc entry for make_reiser4
2007-06-08 20:01:34 +00:00
Chris PeBenito
17b9cb7dda
trunk: fix line in evolution to be strict-only; was being covered up by genhomedircon.
2007-05-22 17:01:38 +00:00
Chris PeBenito
a39a931362
trunk: snmp tweak from dan
2007-05-15 18:06:31 +00:00
Chris PeBenito
c412be6bef
trunk: remaining pieces for apcupsd module
2007-05-15 15:43:00 +00:00
Chris PeBenito
38d0cf1b8a
trunk: long overdue cleanup from when range_transitions were only in the base module
2007-05-14 15:35:47 +00:00
Chris PeBenito
762d2cb989
merge restorecon into setfiles
2007-05-11 17:10:43 +00:00
Chris PeBenito
12217cc286
Patch to begin separating out hald helper programs from Dan Walsh.
2007-05-07 17:57:48 +00:00
Chris PeBenito
78f17e6d6c
add apcupsd from dan
2007-05-07 14:55:54 +00:00
Chris PeBenito
b129e2001c
Fixes for squid, dovecot, and snmp from Dan Walsh.
2007-05-07 13:45:17 +00:00
Chris PeBenito
4967aaa320
Miscellaneous consolekit fixes from Dan Walsh.
2007-05-03 14:15:38 +00:00
Chris PeBenito
0ef5d66468
textrel lib update from dan
2007-05-03 13:43:44 +00:00
Chris PeBenito
7f819d806d
add missing rename_dir_perms
2007-05-03 13:15:48 +00:00
Chris PeBenito
ed4b7301fb
Patch to have avahi use the nsswitch interface rather than individual permissions from Dan Walsh.
2007-05-03 12:45:28 +00:00
Chris PeBenito
517618f0b4
Patch to dontaudit logrotate searching avahi pid directory from Dan Walsh.
2007-05-02 17:55:03 +00:00
Chris PeBenito
882186c933
- Patch to allow insmod to mount kvmfs and dontaudit rw unconfined_t pipes
...
to handle usage from userhelper.
2007-05-02 17:31:38 +00:00
Chris PeBenito
6a2975706a
add rwho from Nalin Dahyabhai
2007-04-30 17:39:01 +00:00
Chris PeBenito
747ab18400
Patch to allow amavis to read spamassassin libraries from Dan Walsh.
2007-04-30 15:19:47 +00:00
Chris PeBenito
ae32fb7e7b
trivial aide fix from dan
2007-04-30 15:09:15 +00:00
Chris PeBenito
f9029fc5b6
Patch to allow slocate to getattr other filesystems and directories on those filesystems from Dan Walsh.
2007-04-30 15:01:19 +00:00
Chris PeBenito
27c570f755
trivial fix for netutils from dan
2007-04-30 14:44:04 +00:00
Chris PeBenito
7487a66705
trivial fix from dan for bluetooth
2007-04-30 14:33:12 +00:00
Chris PeBenito
b4beb0a0fb
missed piece of clip patch
2007-04-30 14:32:31 +00:00
Chris PeBenito
d28e528b0d
Fixes for RHEL4 from the CLIP project.
2007-04-27 15:08:15 +00:00
Chris PeBenito
cd16fe6e2c
Replace the old lrrd fc entries with correct munin ones.
2007-04-23 17:36:35 +00:00
Chris PeBenito
b4dfdc7d30
Move program admin template usage out of userdom_admin_user_template() to sysadm policy in userdomain.te to fix usage of the template for third parties.
2007-04-19 14:30:57 +00:00
Chris PeBenito
7a4bd42ea3
Fix clockspeed_run_cli() declaration, it was incorrectly defined as a template instead of an interface.
2007-04-19 14:24:02 +00:00
Chris PeBenito
0251df3e39
bump module versions for release
2007-04-17 13:28:09 +00:00
Chris PeBenito
4029f11670
last piece of previous consolekit patch
2007-04-11 20:02:59 +00:00
Chris PeBenito
97e8156ecb
add zabbix from dan
2007-04-11 18:55:44 +00:00
Chris PeBenito
697489040e
5 patches from dan. confine insmod and udev on targeted, misc fc fixes, sasl kerberos use, and samba port fixes
2007-04-11 17:56:03 +00:00
Chris PeBenito
99064c9fbd
more consolekit updates from dan
2007-04-11 14:04:35 +00:00
Chris PeBenito
82e284bb89
last piece of dan's previous patch
2007-04-11 13:31:10 +00:00
Chris PeBenito
19b2dee3cc
confine ldconfig in targeted, from dan
2007-04-10 19:39:22 +00:00
Chris PeBenito
ebc1e8be97
from dan:
...
kadmind trys to setattr on krb5kdc file. Just a library checking access.
2007-04-10 17:20:07 +00:00
Chris PeBenito
9af48eef6e
six patches from dan
2007-04-10 13:10:58 +00:00
Chris PeBenito
98faba122c
gentoo /lib can be a symlink on x86-64 systems
2007-04-02 13:33:18 +00:00
Chris PeBenito
39d8dcdb4f
fix http_script_domains, it was incorrectly applied to the content type rather than the script domain. bug #24 .
2007-04-02 13:20:55 +00:00
Chris PeBenito
f88ef60ac0
emit "null" instead of NULL for userspace headers
2007-03-30 20:33:51 +00:00
Chris PeBenito
f6ddd6b9b7
bools in modules fix to require the boolean in optionals that are part of the base module, and move bool declarations in the base module/monolithic
2007-03-30 12:43:15 +00:00
Chris PeBenito
a26923c32e
Two patches from Paul Moore to for ipsec to remove redundant rules and have setkey read the config file.
2007-03-28 18:47:45 +00:00
Chris PeBenito
9e8f65c83e
six trivial patches from dan for iptables, netutils, ipsec, devices, filesystem and cpuspeed
2007-03-26 20:47:29 +00:00
Chris PeBenito
56e1b3d207
- Move booleans and tunables to modules when it is only used in a single
...
module.
- Add support for tunables and booleans local to a module.
2007-03-26 18:41:45 +00:00
Chris PeBenito
8021cb4f63
Merge sbin_t and ls_exec_t into bin_t.
2007-03-23 23:24:59 +00:00
Chris PeBenito
ab514d6a89
remove disable_trans booleans
2007-03-23 21:01:49 +00:00
Chris PeBenito
e9b0042f35
Output different header sets for kernel and userland from flask headers.
2007-03-23 20:32:23 +00:00
Chris PeBenito
1852cdabce
deprecated pax class
2007-03-23 20:21:06 +00:00
Chris PeBenito
5f5b7a1ec6
network fix from dan
2007-03-22 14:33:00 +00:00
Chris PeBenito
cc9130b90a
one-liner from dan
2007-03-22 14:01:55 +00:00
Chris PeBenito
19fd9301e6
patch from dan to have ricci modstorage transition to lvm
2007-03-21 20:02:50 +00:00
Chris PeBenito
cd3ee91a4b
add fail2ban from dan
2007-03-21 15:51:52 +00:00
Chris PeBenito
efcf9df253
kudzu will telinit to make init re-read the inittab after configuring serial consoles
2007-03-20 19:00:35 +00:00
Chris PeBenito
a5f5eba459
Add dontaudits for init fds and console to init_daemon_domain().
2007-03-20 18:47:18 +00:00
Chris PeBenito
4832f0e066
create user gpg keys dir patch from dan
2007-03-19 19:10:43 +00:00
Chris PeBenito
93784927ca
add kvmfs support, from dan
2007-03-19 18:48:14 +00:00
Chris PeBenito
7200146ea8
trivial patch for radius from dan
2007-03-19 18:42:57 +00:00
Chris PeBenito
86b28c9594
trivial patch from dan for sysstat access to sysfs
2007-03-19 18:38:54 +00:00
Chris PeBenito
e66689f7be
other part of consolekit addition
2007-03-19 18:36:36 +00:00
Chris PeBenito
c224d91c7b
from Dan:
...
This is a new policy for the User Switching capability coming in gnome.
consolekit is a daemon that communicates with xdm_t and hal through dbus to change the
ownership/access on certain devices when the login session changes from one user to another
2007-03-19 18:01:15 +00:00
Chris PeBenito
6c20f77e80
patch from Dan for sudo:
...
sudo should be able to getattr on all executables not just
bin_t/sbin_t. Confined executeables run from sudo need this.
sudo_exec_t needs to be marked as exec_type so prelink will work correctly.
sudo semanage should work
2007-03-19 16:32:44 +00:00
Chris PeBenito
b50f2ee48d
It was just pointed out to me that the raw IP socket class is missing from the
...
recvfrom MLS constraint.
Signed-off-by: Paul Moore
2007-03-09 14:45:19 +00:00
Chris PeBenito
0cca516db7
fix for rh bug 203290
2007-03-08 19:01:21 +00:00
Chris PeBenito
b5a6c86f46
last bit of dans patch
2007-03-08 17:53:52 +00:00
Chris PeBenito
cdc91b9aeb
Patch for handling restart of nscd when ran from useradd, groupadd, and admin passwd, from Dan Walsh.
2007-03-08 15:14:45 +00:00
Chris PeBenito
59bedc1886
procmail uses /tmp files
...
Wants to send signull to itself
Can exec ls
Read spamassinn_lib_dirs
New directory for spamassin /var/lib/
pyzor uses tmp files
2007-03-07 21:33:22 +00:00
Chris PeBenito
7aefc69117
trivial change from dan
2007-03-06 17:44:26 +00:00
Chris PeBenito
7aca2aa827
setroubleshoot has a plugin that checks the file context on disk versus a matchpathcon. So needs additional privs
2007-03-06 17:16:08 +00:00
Chris PeBenito
c23eb5b1c4
Patch for gssd fixes from Dan Walsh
2007-03-06 16:18:59 +00:00
Chris PeBenito
c5561c777d
patches for lvm and ricci fixes from Dan Walsh.
2007-03-06 15:35:02 +00:00
Chris PeBenito
f2c69c47b3
lmtp and smtp are the same file require same context of setfiles complains
...
postfix_pickup_t wants to read postfix_spool_maildrop_t dir
2007-03-01 20:41:19 +00:00
Chris PeBenito
ecc98e19e3
patches for file contexts in networkmanager, miscfiles, corecommands, devices, and java from Dan Walsh.
2007-03-01 15:43:39 +00:00
Chris PeBenito
4900fdf7d1
Patch for kerberized telnet fixes from Dan Walsh.
2007-02-28 17:17:52 +00:00
Chris PeBenito
09c56f5496
Patch for kerberized ftp and other ftp fixes from Dan Walsh.
2007-02-28 17:01:47 +00:00
Chris PeBenito
2aea366ffc
Patch for an additional wine executable from Dan Walsh.
2007-02-28 16:23:06 +00:00
Chris PeBenito
bf39cdb807
Patch for additional games file contexts from Dan Walsh.
2007-02-28 15:30:38 +00:00
Chris PeBenito
86d754eed6
Add support for libselinux 2.0.5 init_selinuxmnt() changes.
2007-02-27 17:02:35 +00:00
Chris PeBenito
ca448bd66c
add init_exec() to init_telinit().
2007-02-26 20:19:53 +00:00
Chris PeBenito
f0eaed31be
Patch for misc fixes to bluetooth from Dan Walsh.
2007-02-26 17:23:52 +00:00
Chris PeBenito
5b06477c8e
On Tue, 2007-02-20 at 12:02 -0500, Daniel J Walsh wrote:
...
> Eliminate excess avc messages created when using kerberos libraries
>
> krb5kdc wans to setsched
>
> Also uses a fifo_file to communicate.
>
> Needs to search_network_sysctl
2007-02-26 17:04:56 +00:00
Chris PeBenito
bbb7cc8927
Patch to start deprecating usercanread attribute from Ryan Bradetich.
2007-02-26 16:13:23 +00:00
Chris PeBenito
a715dc0995
add dccp_socket object class
2007-02-26 15:39:59 +00:00
Chris PeBenito
3a39015792
On Tue, 2007-02-20 at 12:30 -0500, Daniel J Walsh wrote:
...
> prelink creates temporarly files that it then needs to relabel.
2007-02-23 21:20:46 +00:00
Chris PeBenito
5c45eaede1
On Tue, 2007-02-20 at 12:28 -0500, Daniel J Walsh wrote:
...
> audit needs fsetid
>
> syslog needs to be able to create a tcp_socket for off machine logging.
2007-02-23 20:19:29 +00:00
Chris PeBenito
66cf194680
Patch to remove redundant mls_trusted_object() call from Dan Walsh.
2007-02-23 20:05:12 +00:00
Chris PeBenito
4685213857
Patch for misc fixes to nis ypxfr policy from Dan Walsh.
2007-02-23 19:52:52 +00:00
Chris PeBenito
aeb54c6dd0
Patch to allow apmd to telinit from Dan Walsh.
2007-02-23 19:41:41 +00:00
Chris PeBenito
d114071e7a
While using samba and SELinux with Debian GNU/Linux (etch) the
...
following files need to be labeled correctly:
/var/run/samba/gencache.tdb
/var/run/samba/share_info.tdb
Should also concern other distributions than Debian.
-Stefan
2007-02-23 19:30:17 +00:00
Chris PeBenito
bcac3a5e3d
Patch to remove incorrect cron labeling in apache.fc from Ryan Bradetich.
2007-02-23 19:08:45 +00:00
Chris PeBenito
f1be09c2b1
make ttys and ptys device nodes
2007-02-20 20:17:07 +00:00
Chris PeBenito
6b19be3360
patch from dan, Thu, 2007-01-25 at 08:12 -0500
2007-02-16 23:01:42 +00:00