Justin P. Mattock
5b6bd09213
Fix a typo of SElinux to SELinux.
...
Signed-off-by: Justin P. Mattock <justinmattock@gmail.com>
2009-10-22 09:47:52 -04:00
Chris PeBenito
c5967300e2
add changelog entry for e4928c5f79
2009-10-22 09:22:14 -04:00
Chris PeBenito
7ca3f559d7
add open to search_dir_perms.
2009-10-22 09:13:04 -04:00
Eamon Walsh
e4928c5f79
Add separate x_pointer and x_keyboard classes inheriting from x_device.
...
This is needed to allow more fine-grained control over X devices without
using different types. Using different types is problematic because
devices act as subjects in the X Flask implementation, and subjects
cannot be labeled through a type transition (since the output role is
hardcoded to object_r).
Signed-off-by: Eamon Walsh <ewalsh@tycho.nsa.gov>
2009-10-14 08:44:44 -04:00
Chris PeBenito
808341bb9b
revise MCS constraints to use only MCS-specific attributes.
2009-10-07 11:48:14 -04:00
Daniel J Walsh
32594a1112
- Allow vpnc request the kernel to load modules
2009-10-02 15:15:36 +00:00
Daniel J Walsh
aaf52ff041
- Add plymouth policy
2009-09-30 18:50:23 +00:00
Daniel J Walsh
d976a83a17
- Allow cupsd_config to read user tmp
...
- Allow snmpd_t to signal itself
- Allow sysstat_t to makedir in sysstat_log_t
2009-09-30 17:37:44 +00:00
Daniel J Walsh
7f2ac12f13
- Update rhcs policy
2009-09-29 20:51:16 +00:00
Daniel J Walsh
5b96313949
- Update rhcs policy
2009-09-29 19:47:31 +00:00
Daniel J Walsh
9b29bf3f78
- Update rhcs policy
2009-09-29 19:44:06 +00:00
Daniel J Walsh
8b10e3abd7
- Update rhcs policy
2009-09-29 12:38:58 +00:00
Chris PeBenito
4be8dd10b9
add seunshare from dan.
2009-09-28 15:40:06 -04:00
Daniel J Walsh
85582d623f
- Allow users to exec restorecond
2009-09-25 18:47:07 +00:00
Daniel J Walsh
f5a104d238
- Allow sendmail to request kernel modules load
2009-09-24 23:30:16 +00:00
Daniel J Walsh
4c2f298bf2
- Fix all kernel_request_load_module domains
2009-09-22 12:49:53 +00:00
Daniel J Walsh
405a74c394
- Fix all kernel_request_load_module domains
2009-09-21 13:55:41 +00:00
Daniel J Walsh
41f8e385a1
- Remove allow_exec* booleans for confined users. Only available for
...
unconfined_t
2009-09-20 14:32:30 +00:00
Daniel J Walsh
8323d545c4
- More fixes for sandbox_web_t
2009-09-19 02:03:03 +00:00
Daniel J Walsh
2bf7d82f60
- More fixes for sandbox_web_t
2009-09-19 01:38:29 +00:00
Daniel J Walsh
ab462917cf
- Allow sshd to create .ssh directory and content
2009-09-18 22:12:25 +00:00
Daniel J Walsh
da08b5716a
- Fix request_module line to module_request
2009-09-18 22:11:35 +00:00
Daniel J Walsh
d53d158d2b
- Fix request_module line to module_request
2009-09-18 20:44:00 +00:00
Daniel J Walsh
1fb0a98434
- Fix sandbox policy to allow it to run under firefox.
...
- Dont audit leaks.
2009-09-18 16:20:05 +00:00
Daniel J Walsh
9de7033708
- Fixes for sandbox
2009-09-17 21:41:30 +00:00
Chris PeBenito
5a6b1fe2b4
add dkim from stefan schulze frielinghaus.
2009-09-17 09:12:33 -04:00
Daniel J Walsh
69290fd9df
- Update to upstream
...
- Dontaudit nsplugin search /root
- Dontaudit nsplugin sys_nice
2009-09-16 17:50:32 +00:00
Chris PeBenito
21b1d1096f
add gnomeclock from dan.
2009-09-16 08:38:58 -04:00
Daniel J Walsh
23e7082b4b
- Fix label on /usr/bin/notepad, /usr/sbin/vboxadd-service
...
- Remove policycoreutils-python requirement except for minimum
2009-09-15 21:45:12 +00:00
Daniel J Walsh
6b7b0c1cdc
- Fix devicekit_disk_t to getattr on all domains sockets and fifo_files
...
- Conflicts seedit (You can not use selinux-policy-targeted and seedit at
the same time.)
2009-09-15 18:26:13 +00:00
Chris PeBenito
ed70158a39
add rtkit from dan.
2009-09-15 09:53:24 -04:00
Chris PeBenito
1d3b9e384c
clean up xscreensaver.
2009-09-15 09:41:42 -04:00
corentin.labbe
31f9c109c1
SELinux xscreensaver policy support
...
Hello
This a patch for adding xscreensaver policy.
I think it need a specific policy because of the auth_domtrans_chk_passwd.
cordially
Signed-off-by: LABBE Corentin <corentin.labbe@geomatys.fr>
2009-09-15 08:46:28 -04:00
Chris PeBenito
c141d835f1
add modemmanager from dan.
2009-09-14 09:48:13 -04:00
Chris PeBenito
e3a90e358a
add abrt from dan.
2009-09-14 09:22:24 -04:00
Daniel J Walsh
e20e351e10
- Add wordpress/wp-content/uploads label
...
- Fixes for sandbox when run from staff_t
2009-09-11 21:15:35 +00:00
Daniel J Walsh
ddc8588081
- Update to upstream
...
- Fixes for devicekit_disk
2009-09-10 15:38:44 +00:00
Daniel J Walsh
1b1ad1395f
- Update to upstream
...
- Fixes for devicekit_disk
2009-09-10 15:31:01 +00:00
Daniel J Walsh
ab8f807545
- More fixes
2009-09-09 21:08:02 +00:00
Chris PeBenito
6af53d08ed
rearrange readahead rules.
2009-09-09 09:53:28 -04:00
Chris PeBenito
c1e5b195f7
readahead patch from dan.
2009-09-09 09:45:34 -04:00
Chris PeBenito
937b2c4d91
nscd patch from dan.
2009-09-09 09:35:37 -04:00
Chris PeBenito
c61b35048a
cron patch from dan.
2009-09-09 09:28:04 -04:00
Chris PeBenito
163ddfaa80
prelink patch from dan.
2009-09-09 08:18:51 -04:00
Daniel J Walsh
b8498d1e5b
- More fixes
2009-09-08 23:55:31 +00:00
Chris PeBenito
81bca10b28
nslcd policy from dan.
2009-09-08 10:31:19 -04:00
Daniel J Walsh
123ae9957d
- Lots of fixes for initrc and other unconfined domains
2009-09-08 14:30:36 +00:00
Chris PeBenito
f67bc918d4
term_write_all_terms() patch from Stefan Schulze Frielinghaus
2009-09-08 10:06:38 -04:00
Daniel J Walsh
72bc25da0e
- Allow xserver to use netlink_kobject_uevent_socket
2009-09-07 01:29:07 +00:00
Daniel J Walsh
35651d45d8
- Allow xserver to use netlink_kobject_uevent_socket
2009-09-07 01:18:05 +00:00