Daniel J Walsh
7a5e03cc74
- Allow cupsd_config_t to be started by dbus
...
- Add smoltclient policy
2009-08-18 22:29:11 +00:00
Chris PeBenito
0484277038
reorganize dbus.fc.
2009-08-18 13:37:46 -04:00
Chris PeBenito
62c80e2546
module version bumps and changelog update for the previous 3 commits.
2009-08-18 13:20:01 -04:00
LABBE Corentin
0d700b0fa1
Gentoo dbus in libexec
2009-08-18 13:13:40 -04:00
LABBE Corentin
755c52b8f7
portage need capability sys_nice
2009-08-18 13:13:31 -04:00
LABBE Corentin
58cc9903dd
Missing comma in policykit
2009-08-18 13:13:26 -04:00
Chris PeBenito
909922027b
Debian policykit fixes from Martin Orr.
...
The policykit binaries on Debian live in /usr/lib/policykit so add file
contexts for that. Also a couple of policykit rules.
2009-08-18 09:49:31 -04:00
Daniel J Walsh
9c270225e5
- Add policycoreutils-python to pre install
2009-08-18 12:34:26 +00:00
Chris PeBenito
b2648249d9
Fix unconfined_r use of unconfined_java_t.
...
The unconfined role is running java in the unconfined_java_t. The current
policy only has a domtrans interface, so the unconfined_java_t domain is not
added to unconfined_r. Add a run interface and change the unconfined module
to use this new interface.
2009-08-17 13:19:26 -04:00
Chris PeBenito
0bf2bc9156
Fix Makefile info message for installing policy headers
...
The Makefile is currently using the policy TYPE (standard|mls|mcs) rather
than the more informative NAME (eg strict, targeted, etc). Fix the Makefile
to use NAME.
2009-08-17 09:49:53 -04:00
Chris PeBenito
4254cec711
Add missing x_device rules for XI2 functions, from Eamon Walsh.
...
> Whats the difference between add/remove and create/destroy?
>
> The devices are in a kind of hierarchy. You can now create one or more
> "master devices" (mouse cursor and keyboard focus). The physical input
> devices are "slave devices" that attach to master devices.
>
> Add/remove controls the ability to add/remove slave devices from a
> master device. Create/destroy controls the ability to create new master
> devices.
2009-08-14 13:18:16 -04:00
Daniel J Walsh
b2c5e72a15
- Make all unconfined_domains permissive so we can see what AVC's happen
2009-08-13 22:33:07 +00:00
Daniel J Walsh
7fe210d864
- Add pt_chown policy
2009-08-12 20:10:51 +00:00
Daniel J Walsh
cbedd06c12
- Add kdump policy for Miroslav Grepl
...
- Turn off execstack boolean
2009-08-12 20:09:21 +00:00
Chris PeBenito
2a77737d4e
Add missing rules to make unconfined_cronjob_t a valid cron job domain.
...
Unconfined_cronjob_t is not a valid cron job domain because the cron
module is lacking a transition from the crond to the unconfined_cronjob_t
domain. This adds the transition and also a constraints exemption since
part of the transition is also a seuser and role change typically.
2009-08-12 14:15:39 -04:00
Chris PeBenito
97e42114db
remove redundant xen_append_log() call in hostname.
2009-08-11 14:19:38 -04:00
Chris PeBenito
0f5e26b620
Add btrfs and ext4 to labeling targets.
2009-08-11 09:01:58 -04:00
Daniel J Walsh
867473ac62
- Add kdump policy for Miroslav Grepl
...
- Turn off execstack boolean
2009-08-10 18:22:10 +00:00
Chris PeBenito
90286f4292
Fix infrastructure to expand macros in initrc_context when installing.
...
The initrc_context file uses the mls_systemhigh macro and needs to be properly
expanded based on the build.conf settings. Add makefile support to do this.
2009-08-10 14:00:34 -04:00
Chris PeBenito
e51390dfcb
fix refpolicy ticket #48 .
2009-08-10 11:14:03 -04:00
Bill Nottingham
ac7bbfa65a
- Turn on execstack on a temporary basis ( #512845 )
2009-08-07 19:36:54 +00:00
Daniel J Walsh
4de3826dbf
- Allow nsplugin to connecto the session bus
...
- Allow samba_net to write to coolkey data
2009-08-07 11:51:54 +00:00
Daniel J Walsh
e21330348f
- Allow devicekit_disk to list inotify
2009-08-05 21:31:17 +00:00
Daniel J Walsh
4816e90c52
- Allow svirt images to create sock_file in svirt_var_run_t
2009-08-05 20:37:39 +00:00
Daniel J Walsh
b270c763b4
- Allow svirt images to create sock_file in svirt_var_run_t
2009-08-05 20:18:06 +00:00
Daniel J Walsh
f3b436ca6a
- Allow svirt images to create sock_file in svirt_var_run_t
2009-08-05 19:37:52 +00:00
Chris PeBenito
02e594d5dc
Handle unix_chkpwd usage by useradd and groupadd; fixes ticket #49 .
2009-08-05 14:19:54 -04:00
Chris PeBenito
e335910197
Add missing compatibility aliases for xdm_xserver*_t types.
...
When collapsing all of the xdm_xserver*_t types into xserver*_t, aliases for
compatibility were mistakenly not added to the policy.
2009-08-05 11:17:53 -04:00
Chris PeBenito
9570b28801
module version number bump for release 2.20090730 that was mistakenly omitted.
2009-08-05 10:59:21 -04:00
Chris PeBenito
d69616c625
fix ordering in sysnetwork.
2009-08-05 10:23:50 -04:00
Chris PeBenito
48bf6397fc
fix ordering in raid.
2009-08-05 10:19:28 -04:00
Chris PeBenito
4b218bd646
fix ordering in pcmcia.
2009-08-05 10:18:31 -04:00
Chris PeBenito
f0e959b4d2
fix ordering in mount.
2009-08-05 10:16:41 -04:00
Chris PeBenito
54327d48ee
fix ordering in modutils.
2009-08-05 10:15:45 -04:00
Chris PeBenito
568efbe895
fix ordering of interface calls in lvm.
2009-08-05 10:07:35 -04:00
Chris PeBenito
8cd1306e5b
fix ordering of interface calls in locallogin.
2009-08-05 10:06:04 -04:00
Chris PeBenito
e6985f91ab
fix ordering of interface calls in iptables.
2009-08-05 10:04:13 -04:00
Chris PeBenito
464ffa57fd
fix ordering of interface calls in init.
2009-08-05 10:01:06 -04:00
Chris PeBenito
14d282253f
fix ordering of interface calls in hostname.
2009-08-05 09:57:14 -04:00
Chris PeBenito
5b5300c823
fix ordering of interface calls in getty.
2009-08-05 09:55:58 -04:00
Chris PeBenito
79ca728b5f
fix ordering of interface calls in fstools.
2009-08-05 09:54:52 -04:00
Chris PeBenito
08638af216
fix ordering of interface calls in clock.
2009-08-05 09:52:34 -04:00
Chris PeBenito
2acba7bbdb
fix ordering of interface calls in authlogin.
2009-08-05 09:51:47 -04:00
Chris PeBenito
9c47227c7a
fix ordering of interface calls in sudo.
2009-08-05 09:48:46 -04:00
Daniel J Walsh
4673269d66
- Allow exim to getattr on mountpoints
...
- Fixes for pulseaudio
2009-08-04 11:32:06 +00:00
Daniel J Walsh
bebd8db8df
- Allow svirt_t to stream_connect to virtd_t
2009-08-04 09:06:45 +00:00
Daniel J Walsh
4c8c1814a9
- Allow svirt_t to stream_connect to virtd_t
2009-08-04 08:54:56 +00:00
Daniel J Walsh
947b439e10
- Allow svirt_t to stream_connect to virtd_t
2009-07-31 19:05:34 +00:00
Daniel J Walsh
af4fa8266c
- Allod hald_dccm_t to create sock_files in /tmp
2009-07-31 11:02:24 +00:00
Daniel J Walsh
43fb726b4b
- More fixes from upstream
2009-07-30 21:38:54 +00:00