Chris Richards
d56b33a1e4
Create new interface and type for managing /etc/udev/rules.d
...
udev_var_run_t is used for managing files in /etc/udev/rules.d as well as other files, including udev pid files. This patch creates a type specifically for rules.d files, and an interface for managing them. It also gives access to this type to initrc_t so that rules can be properly populated during startup. This also fixes a problem on Gentoo where udev rules are NOT properly populated on startup.
Signed-off-by: Chris Richards <gizmo@giz-works.com>
Signed-off-by: Chris PeBenito <cpebenito@tresys.com>
2010-05-18 10:20:55 -04:00
Chris PeBenito
1b2f08ea10
Abrt patch from Dan Walsh.
2010-05-18 10:18:12 -04:00
Chris PeBenito
e9e43f04b3
Plymouthd policy from Dan Walsh.
2010-05-18 09:54:18 -04:00
Chris PeBenito
b0c2cae14a
Hal patch from Dan Walsh.
...
Lots of random access for hal.
2010-05-18 09:06:36 -04:00
Chris PeBenito
2e4e39d26a
Loadkeys patch from Dan Walsh.
2010-05-14 11:40:26 -04:00
Chris PeBenito
84940a0995
Java patch from Dan Walsh.
...
Additional java context
unconfined_Java apps needs to execmod any file since we do not know where the jave content will be labeled
We want unconfined java apps to transition to rpm when they execute rpm_exec_t. To maintain proper labeling.
2010-05-14 10:40:59 -04:00
Chris PeBenito
299db7080c
CVS patch from Dan Walsh.
...
cvs needs dac_override when it tries to read shadow
2010-05-14 10:24:11 -04:00
Chris PeBenito
bcc6e65421
SETroubleshoot patch from Dan Walsh.
...
Policy to handle the fixit button in setroubleshoot.
2010-05-13 13:22:53 -04:00
Chris PeBenito
ada61e1529
Asterisk patch from Dan Walsh.
...
asterisk_manage_lib_files(logrotate_t)
asterisk_exec(logrotate_t)
Needs net_admin
Drops capabilities
connects to unix_stream
execs itself
Requests kernel load modules
Execs shells
Connects to postgresql and snmp ports
Reads urand and generic usb devices
Has mysql and postgresql back ends
sends mail
2010-05-13 11:35:58 -04:00
Chris PeBenito
24e0b9b3a4
Munin patch from Dan Walsh.
2010-05-13 11:20:54 -04:00
Chris PeBenito
16070400a8
RPM patch from Dan Walsh.
2010-05-11 11:11:40 -04:00
Chris PeBenito
27afb97c29
Minor fixes on a2524cf
. Module version bump.
2010-05-11 08:33:04 -04:00
Chris PeBenito
aeb7a4e180
Whitespace fixes on cobbler.
2010-05-11 08:23:02 -04:00
Jeremy Solt
a2524cfa77
cobbler patch from Dan Walsh
2010-05-11 08:17:33 -04:00
Chris PeBenito
fb3fc9e4f0
Cyrus patch from Dan Walsh.
2010-05-03 15:14:50 -04:00
Chris PeBenito
4804cd43a0
Clamav patch from Dan Walsh.
2010-05-03 15:01:35 -04:00
Chris PeBenito
d8eb3c71c6
Dovecot patch from Dan Walsh.
2010-05-03 14:37:19 -04:00
Chris PeBenito
baea7b1dc6
Networkmanager patch from Dan Walsh.
2010-05-03 14:01:26 -04:00
Chris PeBenito
03a6e03926
Add kernel access to devtmpfs. Also add workround while devtmpfs is tmpfs_t instead of device_t.
2010-05-03 11:17:16 -04:00
Chris PeBenito
a3108c60c0
Consolekit patch from Dan Walsh.
2010-05-03 10:21:48 -04:00
Chris PeBenito
b0076a1413
Arpwatch patch from Dan Walsh.
2010-05-03 09:49:33 -04:00
Chris PeBenito
98ac98623c
Dbus patch from Dan Walsh.
2010-05-03 09:34:42 -04:00
Chris PeBenito
61738f11ec
Devicekit patch from Dan Walsh.
2010-05-03 09:01:46 -04:00
Chris PeBenito
857d37e84a
GPG patch from Dan Walsh.
2010-04-30 15:24:19 -04:00
Chris PeBenito
3b72786090
Add trusted object condition to unix socket connectto/sendto, to fix label translation.
2010-04-29 11:29:39 -04:00
Chris PeBenito
87a9469fc9
Add networking rules for spamd to connect to mysql/postgresql over the network, from Chris St. Pierre.
2010-04-27 10:31:47 -04:00
Chris PeBenito
45696ab282
Add missing secmark rules in ntop, from Dominick Grift.
2010-04-27 09:31:30 -04:00
Chris PeBenito
a53c6c65a4
FTP patch from Dan Walsh.
2010-04-26 15:15:23 -04:00
Chris PeBenito
d7ebbd9d22
Module version bump for 34838aa
.
2010-04-26 13:40:21 -04:00
Jeremy Solt
34838aa62a
Samba patch from Dan Walsh
...
- signal interfaces
- fusefs support
- bug 566984: getattrs on all blk and chr files
Did not include:
- changes related to samba_unconfined_script_t and samba_unconfined_net_t
- samba_helper_template (didn't appear to be used)
- manage_lnk_files_pattern in samba_manage_var_files
- signal allow rule in samba_domtrans_winbind_helper
- samba_role_notrans
- userdom_manage_user_home_content
Some style and spacing fixes
2010-04-26 13:28:21 -04:00
Chris Richards
9b3e798ea3
bootmisc init script, 2nd try
...
Allow to create /var/lock/.keep. This prevents Portage from destroying /var/lock under certain conditions. This patch is Gentoo specific.
Signed-off-by: Chris Richards <gizmo@giz-works.com>
Signed-off-by: Chris PeBenito <cpebenito@tresys.com>
2010-04-26 12:59:12 -04:00
Chris PeBenito
05a2e3e2d7
Lircd patch from Dan Walsh.
2010-04-26 12:59:02 -04:00
Chris PeBenito
e07fbc004d
Add DenyHosts from Dan Walsh.
2010-04-26 12:59:02 -04:00
Chris PeBenito
44b3808ba5
Djbdns patch from Dan Walsh.
2010-04-26 12:59:02 -04:00
Chris PeBenito
4a8bd017aa
Module version bump and extra comments for 194d61f
.
2010-04-24 08:10:43 -04:00
Chris Richards
194d61fd3c
modutils patch for update-modules
...
update-modules on Gentoo throws errors when run because it sources /etc/init.d/functions.sh, which always scans /var/lib/init.d to set SOFTLEVEL environment var. This is never used by update-modules.
Signed-off-by: Chris Richards <gizmo@giz-works.com>
Signed-off-by: Chris PeBenito <pebenito@gentoo.org>
2010-04-24 08:08:15 -04:00
Chris PeBenito
78352db924
Module version bump for 8c38fba
.
2010-04-24 08:07:51 -04:00
Chris Richards
8c38fba0f0
allow syslog-ng to setrlimit
...
syslog-ng wants to increase the number of permissible open files from 256 to 4096 on unix/linux systems.
Signed-off-by: Chris Richards <gizmo@giz-works.com>
Signed-off-by: Chris PeBenito <pebenito@gentoo.org>
2010-04-24 08:02:23 -04:00
Chris PeBenito
5c3274d7bf
Module version bump for 4b121a5
.
2010-04-19 10:23:11 -04:00
Chris PeBenito
46879922d8
Additional whitespace fix in nis.
2010-04-19 10:20:19 -04:00
Jeremy Solt
f49fc19e5a
Style changes
2010-04-19 10:19:46 -04:00
Jeremy Solt
4b121a5f53
nis patch from Dan Walsh
...
Made a couple style changes.
Removed unnecessary require in nis_use_ypbind interface
2010-04-19 10:19:44 -04:00
Chris PeBenito
da5940411c
Additional whitespace fixes in certmonger.
2010-04-19 10:17:24 -04:00
Jeremy Solt
0e5494a3d9
Fix some whitespace and style issues.
2010-04-19 10:07:20 -04:00
Jeremy Solt
33793ec2ce
certmonger policy from Dan Walsh
...
Removed manage_var_run and manage_var_lib interfaces
Added missing requires to admin interface
Removed permissive line
Fixed some spacing / style issues
2010-04-19 10:07:17 -04:00
Chris PeBenito
86ff008754
Module version bump for 4f7b413
.
2010-04-19 10:05:22 -04:00
Jeremy Solt
e6e2a769ac
Remove excess white space from ntop.te
...
Move ntop ports declaration to correct location.
2010-04-19 09:55:01 -04:00
Jeremy Solt
4f7b413cdc
Ntop policy from Dan Walsh
...
Added alias for ntop_http_content_t in apache
Pulled in ntop port from corenetwork patch
2010-04-19 09:54:58 -04:00
Chris PeBenito
98759716fe
Module version bump for 46e16a2
.
2010-04-19 09:54:13 -04:00
Jeremy Solt
d86d4f6069
Move optional policy to correct location for style
2010-04-19 09:50:42 -04:00
Jeremy Solt
01bfe1d20e
kerberos patch from Dan Walsh
2010-04-19 09:50:39 -04:00
Chris PeBenito
46e16a2d2a
Use port range notation in corenetwork where it makes sense.
2010-04-13 11:55:04 -04:00
Chris PeBenito
3829eecb12
Clean up output of generated corenetwork.te.
2010-04-13 11:52:09 -04:00
Chris PeBenito
85e71c86da
Fix network_port() in corenetwork to correctly handle port ranges.
2010-04-13 11:06:02 -04:00
KaiGai Kohei
ec8d32c8e9
[BUGFIX] lack of type transition on dbadm domain (Re: dbadm.pp is not available in selinux-policy package)
...
I found out a bug when we initialize the database with dbadm_r:dbadm_t
which belongs to sepgsql_admin_type attribute.
In the case when sepgsql_admin_type create a new database objects,
it does not have valid type_transition rules. So, it was failed.
Sorry, I didn't find out it for a long time.
And db_procedure:{execute} on the sepgsql_proc_exec_t might be necessary
for the administrative domain independently from sepgsql_unconfined_dbadm,
because we need to execute some of system defined procedures to look up
system tables.
2010-04-12 10:37:21 -04:00
Chris PeBenito
23ad802a9d
Module version bump for 5d3214f
and 795b733
.
2010-04-12 10:01:39 -04:00
Jeremy Solt
795b733a71
pcscd patch from Dan Walsh: manage pub files and fifo files
2010-04-12 09:10:37 -04:00
Jeremy Solt
5d3214f5a9
gpsd path from Dan Walsh
2010-04-12 09:07:50 -04:00
Chris PeBenito
e399e3abea
Add devtmpfs labeling.
2010-04-07 08:55:33 -04:00
Dominick Grift
91b12ad94c
Move kernel_request_load_module(gssd_t) to the proper place.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-04-06 15:05:22 -04:00
Dominick Grift
6d9925c872
Fix requires for apache tmp interfaces.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-04-06 15:05:12 -04:00
Chris PeBenito
b577852a98
Portreserve patch from Dan Walsh.
2010-04-05 14:50:23 -04:00
Chris PeBenito
38db49c545
PPP patch from Dan Walsh.
2010-04-05 14:38:30 -04:00
Chris PeBenito
372acd0037
Rpc patch from Dan Walsh.
2010-04-05 14:26:21 -04:00
Chris PeBenito
20fa703294
Whitespace fixes on Apache.
2010-04-05 14:05:05 -04:00
Chris PeBenito
da0608ba38
Module version bump for 170a46d
, f8b3b7f
, and a49a82c
.
2010-04-05 13:49:00 -04:00
Chris PeBenito
b7d3db1860
Tweak for 170a46d
.
2010-04-05 13:48:01 -04:00
Jeremy Solt
a49a82c295
snort patch from Dan Walsh
...
Didn't rearrange all the kernel calls, but did add the kernel_request_load_module.
Didn't include the usbmod (doesn't exist in refpolicy at this time).
Included the generic usb device permissions because snort uses libpcap, which can also be used to monitor USB traffic, so this may be a side effect.
From the red hat bug (559861), it sounds as though snort was failing without these permissions, so it doesn't look like a dontaudit would work.
2010-04-05 13:46:11 -04:00
Jeremy Solt
f8b3b7fa48
Nut policy from Dan Walsh
...
Dropped optional policy for shutdown_domtrans
Dropped commented can_exec line
2010-04-05 13:45:31 -04:00
Jeremy Solt
170a46d6c5
memcached patch from Dan Walsh
...
Moved term_dontaudits up for style
2010-04-05 13:43:58 -04:00
Chris PeBenito
60def66b13
Second part of Apache patch from Dan Walsh.
2010-04-05 10:57:52 -04:00
Chris PeBenito
83caba3eb9
First part of apache patch from Dan Walsh: file context changes, including renaming script ro/ra/rw files.
2010-04-01 08:17:50 -04:00
Chris PeBenito
25d81d2655
Tor patch from Dan Walsh.
2010-03-29 14:30:52 -04:00
Chris PeBenito
2b93b88584
Sssd patch from Dan Walsh.
2010-03-29 14:08:52 -04:00
Chris PeBenito
ee2d2dda24
Add usbmuxd from Dan Walsh.
2010-03-29 13:29:18 -04:00
Chris PeBenito
6d4dbd20ae
Vhostmd from Dan Walsh.
2010-03-29 11:25:06 -04:00
Chris PeBenito
bf54d5be44
Module version bumps for c586c1b
, dcbb332
, 4c05dff
, 84ce9c3
, 2b012ba
, and 1868383
.
2010-03-29 09:21:59 -04:00
Chris PeBenito
ad0071bbe4
Tweaks on pulseaudio 1868383
, ksmtuned d279dd6
, and smokeping f3c346c
.
2010-03-29 09:19:40 -04:00
Jeremy Solt
f3c346cc07
Smokeping policy from Dan Walsh
...
Made some style / spacing changes
Did not include read access to /etc/shadow
Removed manage_var_run and manage_var_lib interfaces
Removed permissive line
2010-03-29 08:46:30 -04:00
Jeremy Solt
18683835fd
pulseaudio patch from Dan Walsh
...
Fixed template where it should have been interface
Replaced read_home and manage_home interfaces with read_home_files, manage_home_files and reduced access
Removed admin_dir reference
Replaced rtkit_daemon_system_domain with rtkit_scheduled
Fixed style / spacing issues
2010-03-29 08:41:45 -04:00
Jeremy Solt
d279dd603f
ksmtuned policy from Dan Walsh
...
Couple style/space fixes.
Used ps_process_pattern in admin interface
2010-03-29 08:36:53 -04:00
Jeremy Solt
2b012bacb6
Prelude patch from Dan Walsh
2010-03-29 08:36:15 -04:00
Jeremy Solt
84ce9c3333
Bluetooth patch (sys_admin and debugfs) from Dan Walsh
...
Added comments to reference redhat bugs
2010-03-29 08:36:05 -04:00
Jeremy Solt
4c05dff3d1
avahi patch from Dan Walsh
...
Didn't include the file read in the dbus_chat interface.
2010-03-29 08:36:00 -04:00
Jeremy Solt
dcbb332992
chronyd patch from Dan Walsh
...
Fixed a couple style/spacing issues.
Added files_search_etc for chronyd_keys file
2010-03-29 08:35:52 -04:00
Jeremy Solt
c586c1bfa6
Give dcc setgid from Dan Walsh
2010-03-29 08:35:34 -04:00
Chris PeBenito
7656af7a6f
Module version bump for c37d843
.
2010-03-23 08:07:19 -04:00
Chris PeBenito
be8311279e
Minor bind XML tweaks.
2010-03-23 08:05:00 -04:00
Jeremy Solt
c37d843fa1
bind patch from Dan Walsh
...
some fixes in interfaces, added bind_setattr_zone_dirs interface
sysnet_read_config not needed with auth_use_nsswitch
Did not include init_read_script_tmp_files for named_t
2010-03-23 08:01:05 -04:00
Chris PeBenito
390b8a821b
Radvd patch from Dan Walsh.
2010-03-22 15:19:50 -04:00
Chris PeBenito
1b22152c2c
Rdisc patch from Dan Walsh.
2010-03-22 15:09:27 -04:00
Chris PeBenito
6c40309ef1
Module version bump for 1d348bd
.
2010-03-22 13:53:24 -04:00
Jeremy Solt
1d348bd253
Afs needs sys_admin, sends signals, and resolves hostnames from Dan Walsh
2010-03-22 13:52:19 -04:00
Chris PeBenito
df29613c72
Module version bump for 75c8a69
.
2010-03-22 13:51:35 -04:00
Jeremy Solt
75c8a691ee
gitosis read/manage lib interfaces from Dan Walsh
...
Only giving manage_files_pattern for gitosis_manage_lib_files
2010-03-22 13:48:39 -04:00
Chris PeBenito
cf7eb082d2
Sasl patch from Dan Walsh.
2010-03-22 11:22:25 -04:00
Chris PeBenito
449d2069ac
Snmp patch from Dan Walsh.
2010-03-22 11:08:31 -04:00
Chris PeBenito
08d7c7339b
Sysstat patch from Dan Walsh.
2010-03-22 10:47:41 -04:00
Chris PeBenito
98ac3f5ace
Telnet patch from Dan Walsh.
2010-03-22 10:40:37 -04:00
Chris PeBenito
461b53e028
Tuned patch from Dan Walsh.
2010-03-22 10:33:31 -04:00
Chris PeBenito
7630200e1b
Virt patch from Dan Walsh.
2010-03-22 10:24:34 -04:00
Chris PeBenito
064d1b469e
Rename rtkit_schedule() to rtkit_scheduled().
2010-03-22 09:54:58 -04:00
Chris PeBenito
e13a9ef5fe
Module version bump for ac19f1a
.
2010-03-22 08:59:04 -04:00
Chris PeBenito
c7a4cf3179
Module version bump for 9681df1
.
2010-03-22 08:58:41 -04:00
Chris PeBenito
32103f250f
Module version bump for d3b5907
.
2010-03-22 08:58:20 -04:00
Chris PeBenito
340af119b0
Minor tweaks on icecast.
2010-03-22 08:56:32 -04:00
Jeremy Solt
584dfaca45
icecast policy from Dan Walsh
...
Fixed some style and spacing issues
Replace manage_var_run interface with manage_pid_files with fewer permissions
Replaced rkit_daemon_system_domain with rtkit_schedule
2010-03-22 08:49:54 -04:00
Jeremy Solt
ac19f1ac26
rtkit patch from Dan Walsh:
...
rtkit_daemon_system_domain interface allows domains to say rtkit can setsched on their process.
Needs sys_nice capability
Needs to getsched on all domains.
Fix bug in te file
Me:
changed interface name from rtkit_daemon_system_domain to rtkit_schedule
Already had sys_nice capability
2010-03-22 08:41:42 -04:00
Jeremy Solt
9681df1c8d
postgresql patch from Dan Walsh:
...
"File context for /etc/sysconfig/pgsql and other bugs.
Sends audit messages connect to posgresql_server port
Reads its own process info"
Moved signal interface for style.
2010-03-22 08:39:15 -04:00
Jeremy Solt
d3b5907ea4
openvpn needs ipc_lock capability, connects to http ports,
...
and manages net_conf_t files - from Dan Walsh
2010-03-22 08:36:47 -04:00
Chris PeBenito
47293bd8d6
Tftp patch from Dan Walsh.
2010-03-19 15:56:14 -04:00
Chris PeBenito
788ba75491
Uucp patch from Dan Walsh.
2010-03-19 15:49:12 -04:00
Chris PeBenito
bed0a44560
Zebra patch from Dan Walsh.
2010-03-19 15:45:25 -04:00
Chris PeBenito
bc31d12725
Libraries patch from Dan Walsh.
2010-03-19 14:21:23 -04:00
Chris PeBenito
0d86ea1d7b
Xen patch from Dan Walsh.
2010-03-19 11:54:50 -04:00
Chris PeBenito
b60df9f57d
Getty patch from Dan Walsh.
2010-03-19 11:05:56 -04:00
Chris PeBenito
1fa92b8a55
Sysnetwork patch from Dan Walsh.
2010-03-18 15:40:04 -04:00
Chris PeBenito
ddd786e404
Init patch from Dan Walsh.
2010-03-18 10:19:49 -04:00
Chris PeBenito
153ed8751a
Authlogin patch from Dan Walsh.
2010-03-18 08:59:25 -04:00
Chris PeBenito
4fbcd778de
Iptables patch from Dan Walsh.
2010-03-18 08:10:21 -04:00
Chris PeBenito
a124c0a81f
Udev patch from Dan Walsh.
2010-03-17 15:17:48 -04:00
Chris PeBenito
7a8807b627
Logging patch from Dan Walsh.
2010-03-17 14:40:06 -04:00
Chris PeBenito
90e65feca5
Ipsec patch from Dan Walsh.
2010-03-17 13:52:07 -04:00
Chris PeBenito
d13c6758a4
Modutils patch from Dan Walsh.
2010-03-17 11:59:14 -04:00
Chris PeBenito
0417386142
Kernel patch from Dan Walsh.
2010-03-17 11:16:25 -04:00
Chris PeBenito
1f6d975502
Domain patch from Dan Walsh.
2010-03-17 10:02:07 -04:00
Chris PeBenito
7b50b7053d
Module version bump for 6a03548
.
2010-03-17 09:42:46 -04:00
Jeremy Solt
6a035482dc
amavis uses uptime which reads utmp, and reads certs - from Dan Walsh
2010-03-17 09:41:18 -04:00
Chris PeBenito
827060cb04
Style fixes and module version bumps for 38fc1bd
.
2010-03-17 09:28:18 -04:00
Dominick Grift
38fc1bd180
Likewise policy.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-03-17 08:48:45 -04:00
Chris PeBenito
2a62db7883
Module version bump for 414a570
.
2010-03-16 15:28:36 -04:00
Jeremy Solt
414a5704df
fetchmail executes programs in bin (uname), from Dan Walsh
2010-03-16 15:27:40 -04:00
Chris PeBenito
e8871c2092
Add additional documentation to kernel_request_load_module().
2010-03-16 15:08:00 -04:00
Chris PeBenito
5911f3dbca
Module version bump for 935151a
.
2010-03-16 14:35:09 -04:00
Chris PeBenito
c6491af860
Module version bump for d12f18e
.
2010-03-16 14:34:50 -04:00
Chris PeBenito
9a59893e5a
Module version bump for d7ec247
.
2010-03-16 14:34:23 -04:00
Chris PeBenito
9570fc108e
Module version bump for 591af7b
.
2010-03-16 14:34:05 -04:00
Chris PeBenito
ce693cbbec
Module version bump for ae07c9e
.
2010-03-16 14:33:43 -04:00
Chris PeBenito
1656bf730f
Whitespace fixes in mailman.
2010-03-16 13:51:51 -04:00
Jeremy Solt
935151afcd
Change kernel_load_module to kernel_request_load_module for howl from Dan Walsh
2010-03-16 13:44:55 -04:00
Jeremy Solt
d12f18e452
Change kernel_load_module to kernel_request_load_module from Dan Walsh
2010-03-16 13:44:52 -04:00
Jeremy Solt
d7ec24785b
File context update for certmaster from Dan Walsh
2010-03-16 13:44:50 -04:00
Jeremy Solt
591af7be0c
file context updates from Dan Walsh
2010-03-16 13:44:48 -04:00
Jeremy Solt
ae07c9e2e8
Screen needs to setattr on user_ttydevice_t from Dan Walsh
2010-03-16 13:36:45 -04:00
Chris PeBenito
fad6e761bf
Whitespace fix for mcelog.
2010-03-16 13:15:38 -04:00
Chris PeBenito
fce868d074
Module version bump for f7d413a
.
2010-03-16 13:15:00 -04:00
Chris PeBenito
bf140fc32c
Rearrange interfaces in fail2ban.
2010-03-16 13:14:46 -04:00
Chris PeBenito
580279da88
Module version bump for 74b51e6
.
2010-03-16 13:12:22 -04:00
Chris PeBenito
6bc64c4be7
Whitespace fixes for smoltclient.
2010-03-16 13:11:53 -04:00
Chris PeBenito
ba1c45337b
Module version bump for 3137148
.
2010-03-16 13:10:14 -04:00