Chris PeBenito
|
53857c8c05
|
unconfined can pass all constraints
|
2005-07-20 17:24:23 +00:00 |
|
Chris PeBenito
|
ef424c14d4
|
name_connect only on tcp_sockets
|
2005-07-20 17:10:07 +00:00 |
|
Chris PeBenito
|
9496fd5119
|
unconfined can name_connect to all ports
|
2005-07-20 17:08:07 +00:00 |
|
Chris PeBenito
|
d250634311
|
reorder kernel policy, add attributes for sysctl and proc entries. fix unconfined interface
|
2005-07-20 17:06:10 +00:00 |
|
Chris PeBenito
|
f82c6ac64c
|
bah typo
|
2005-07-20 15:08:33 +00:00 |
|
Chris PeBenito
|
0b28a23114
|
user home dirs were missing file type in targ policy
|
2005-07-20 15:06:49 +00:00 |
|
Chris PeBenito
|
1e3f610b3b
|
add missing dir and file perms for selinuxfs in unconfined
|
2005-07-20 14:57:13 +00:00 |
|
Chris PeBenito
|
689f6ddb35
|
fix typos and import some rules from NSA cvs to make targeted policy work
|
2005-07-20 14:25:24 +00:00 |
|
Chris PeBenito
|
474f43d13d
|
should actually try compiling first :x
|
2005-07-20 13:39:10 +00:00 |
|
Chris PeBenito
|
bd7e7a6417
|
missed a line
|
2005-07-20 13:37:18 +00:00 |
|
Chris PeBenito
|
a28f6db576
|
add in some rules from NSA CVS to make targeted policy work
|
2005-07-20 13:30:06 +00:00 |
|
Chris PeBenito
|
8c3f438f75
|
corenet was missing from unconfined
|
2005-07-19 20:38:26 +00:00 |
|
Chris PeBenito
|
892266ca76
|
more targeted policy fixes
|
2005-07-19 20:26:02 +00:00 |
|
Chris PeBenito
|
ec848d247f
|
more fixes for targeted
|
2005-07-19 19:37:43 +00:00 |
|
Chris PeBenito
|
2ec4c9d38f
|
more cleanup
|
2005-07-19 18:40:31 +00:00 |
|
Chris PeBenito
|
8b0bbdda34
|
fixes for targeted policy
|
2005-07-19 18:40:19 +00:00 |
|
Chris PeBenito
|
391edeb577
|
fix assertions for framework
|
2005-07-18 20:17:21 +00:00 |
|
Chris PeBenito
|
a5f339f134
|
more cleanup in system
|
2005-07-18 18:31:49 +00:00 |
|
Chris PeBenito
|
9f103ce14b
|
fix to use context_template()
|
2005-07-18 14:25:05 +00:00 |
|
Chris PeBenito
|
3b6174a142
|
add missing context template
|
2005-07-15 20:54:24 +00:00 |
|
Chris PeBenito
|
50aca6d2f9
|
add raid (mdadm)
|
2005-07-15 20:45:26 +00:00 |
|
Chris PeBenito
|
d9fd8e7562
|
more pcmcia cleanup
|
2005-07-15 19:18:55 +00:00 |
|
Chris PeBenito
|
157c69416f
|
add macro to expand object class sets for use in require blocks
|
2005-07-15 15:53:54 +00:00 |
|
Chris PeBenito
|
50f6503452
|
* break up files_getattr_all_files into correct interfaces
* move stuff out of pcmcia into the appropriate modules
|
2005-07-15 15:17:57 +00:00 |
|
Chris PeBenito
|
f136a944c5
|
reorder in alpha order of type, for sanity purposes
|
2005-07-15 14:30:19 +00:00 |
|
Chris PeBenito
|
e0d57fbcb1
|
add pcmcia
|
2005-07-14 20:57:17 +00:00 |
|
Chris PeBenito
|
c429cb5e26
|
fix up the xml
|
2005-07-14 20:02:53 +00:00 |
|
Chris PeBenito
|
11633bbaa8
|
add ipsec
|
2005-07-14 18:15:47 +00:00 |
|
Chris PeBenito
|
493d6c4adc
|
add nscd
|
2005-07-13 20:48:51 +00:00 |
|
Chris PeBenito
|
df00b2e235
|
* fix chroot exec interface
* more TODO cleanup
* move IPC out of generic domtrans interfaces
|
2005-07-13 18:29:08 +00:00 |
|
Chris PeBenito
|
b24f35d8a3
|
more cleanup of current TODOs
|
2005-07-12 20:34:24 +00:00 |
|
Chris PeBenito
|
4051d15b62
|
fix xml
|
2005-07-11 19:15:54 +00:00 |
|
Chris PeBenito
|
ae9e2716c3
|
fix more TODOs. fix selinux.te to selinuxutil.te in optionals
|
2005-07-11 19:02:50 +00:00 |
|
Chris PeBenito
|
a42ca7ebec
|
another round of TODO cleanup
|
2005-07-08 20:44:57 +00:00 |
|
Chris PeBenito
|
e5f8060316
|
implement direct_sysadm_daemon
|
2005-07-07 15:25:28 +00:00 |
|
Chris PeBenito
|
1aa526281b
|
missing rules uncovered by sediff
|
2005-07-07 15:20:24 +00:00 |
|
Chris PeBenito
|
c98340cfeb
|
support for targeted policy
|
2005-07-06 20:28:29 +00:00 |
|
Chris PeBenito
|
ed1a92b88c
|
ksu moves to su
|
2005-07-06 17:41:58 +00:00 |
|
Chris PeBenito
|
bb32544d61
|
add missing ssh file contexts
|
2005-07-06 15:59:54 +00:00 |
|
Chris PeBenito
|
9726b31857
|
add unconfined
|
2005-07-05 20:59:51 +00:00 |
|
Chris PeBenito
|
2745476e4a
|
add required tags
|
2005-07-05 17:47:15 +00:00 |
|
Chris PeBenito
|
a7a9799d79
|
convert can_kerberos()
|
2005-07-01 13:31:34 +00:00 |
|
Chris PeBenito
|
65c8613766
|
ul has to be in a p
|
2005-07-01 13:10:57 +00:00 |
|
Chris PeBenito
|
5e1ed4903e
|
initial commit
|
2005-06-30 21:11:54 +00:00 |
|
Chris PeBenito
|
fd89e19f12
|
more work on current modules
|
2005-06-30 18:54:08 +00:00 |
|
Chris PeBenito
|
ebdc3b7902
|
clean up more todos
|
2005-06-29 20:53:53 +00:00 |
|
Chris PeBenito
|
d233bfce3f
|
make layer summary required
|
2005-06-29 16:54:13 +00:00 |
|
Chris PeBenito
|
8fd3673225
|
another round of renaming, for consistency
|
2005-06-29 14:26:41 +00:00 |
|
Chris PeBenito
|
96ce00afcc
|
add logrotate, more low-hanging fruit
|
2005-06-28 20:54:49 +00:00 |
|
Chris PeBenito
|
ceebe3b4b0
|
change desc to summary
|
2005-06-28 19:51:46 +00:00 |
|
Chris PeBenito
|
cbca03f513
|
add lost_found_t manage, rename fs_type attribute to filesystem_type and rename fs_make_fs to fs_type
|
2005-06-28 17:48:59 +00:00 |
|
Chris PeBenito
|
783b38347e
|
more low hanging fruit cleanup
|
2005-06-28 17:32:57 +00:00 |
|
Chris PeBenito
|
58c3da55f3
|
add fstools, and more cleanup
|
2005-06-27 20:59:28 +00:00 |
|
Chris PeBenito
|
80436b9b8f
|
changes to make inetd work
|
2005-06-27 18:37:33 +00:00 |
|
Chris PeBenito
|
24bf11c62a
|
initial commit
|
2005-06-27 18:36:56 +00:00 |
|
Chris PeBenito
|
ab940a4cc1
|
autofs_t and ypbind cleanup
|
2005-06-27 16:30:55 +00:00 |
|
Chris PeBenito
|
e88003ffe3
|
xml updates and nis stuff
|
2005-06-24 20:37:09 +00:00 |
|
Chris PeBenito
|
73fbc771d1
|
initial commit
|
2005-06-24 19:49:46 +00:00 |
|
Chris PeBenito
|
62a7b02c5b
|
add/update comments
|
2005-06-24 13:36:57 +00:00 |
|
Chris PeBenito
|
414e415198
|
update for new documentation method
|
2005-06-23 21:30:57 +00:00 |
|
Chris PeBenito
|
aad5b98eba
|
more updates
|
2005-06-23 20:35:48 +00:00 |
|
Chris PeBenito
|
45239964e5
|
move ssh tunables into global_tunables
|
2005-06-23 19:57:15 +00:00 |
|
Chris PeBenito
|
19ea99d495
|
fix
|
2005-06-23 16:06:39 +00:00 |
|
Chris PeBenito
|
261e0e66ee
|
shorten some xml tags
|
2005-06-23 16:00:05 +00:00 |
|
Chris PeBenito
|
d3b892e4fd
|
convert a couple network macros
|
2005-06-23 15:44:18 +00:00 |
|
Chris PeBenito
|
007ca5600c
|
more setcurrent stuff
|
2005-06-23 15:37:39 +00:00 |
|
Chris PeBenito
|
2a3478cf15
|
fixes pointed out by steve, plus fixes revealed by the added assertions
|
2005-06-23 14:19:56 +00:00 |
|
Chris PeBenito
|
9ccd96dfc6
|
more work on ssh, plus import ssh-agent
|
2005-06-22 21:14:48 +00:00 |
|
Chris PeBenito
|
199895e201
|
move all interfaces over to the interface macro. add traceback debugging info
|
2005-06-22 19:21:31 +00:00 |
|
Chris PeBenito
|
cbc9d6951a
|
remove remaining _depend macros to prep for switchover to interface declaration macro
|
2005-06-22 16:07:14 +00:00 |
|
Chris PeBenito
|
0404a3903a
|
initial commit of ssh.
|
2005-06-21 21:07:46 +00:00 |
|
Chris PeBenito
|
21871a5cf6
|
work on newrole policy
|
2005-06-21 17:01:45 +00:00 |
|
Chris PeBenito
|
e04b8e7832
|
initial commit
|
2005-06-20 18:43:14 +00:00 |
|
Chris PeBenito
|
57869a681e
|
XML: encapsulate modules in layers, rather then layer being an attribute of
module tag
|
2005-06-20 18:40:44 +00:00 |
|
Chris PeBenito
|
7a2f20a315
|
more work to clean up and complete current modules
|
2005-06-20 17:41:29 +00:00 |
|
Chris PeBenito
|
2ba9a794db
|
interface review, and remove net_raw from raw node sends. only give
capability for raw send on an interface
|
2005-06-17 19:17:57 +00:00 |
|
Chris PeBenito
|
bc1fbab472
|
interface review, and remove net_raw from raw node sends. only give
capability for raw send on an interface
|
2005-06-17 18:59:34 +00:00 |
|
Chris PeBenito
|
5e6f9e5aac
|
services interfaces review
|
2005-06-17 18:41:07 +00:00 |
|
Chris PeBenito
|
7f2e39b8e6
|
review of admin interfaces
|
2005-06-17 18:27:08 +00:00 |
|
Chris PeBenito
|
139520a233
|
review of system interfaces
|
2005-06-17 17:59:26 +00:00 |
|
Chris PeBenito
|
a7c3a1b920
|
eliminate _depend macros
|
2005-06-16 21:06:29 +00:00 |
|
Chris PeBenito
|
0e721690dc
|
misc cleanup
|
2005-06-16 20:54:18 +00:00 |
|
Chris PeBenito
|
d35c621eb0
|
add a couple more nfs and cifs interfaces, to cover most of the
use_(nfs|cifs)_home_dirs tunable
|
2005-06-16 20:33:51 +00:00 |
|
Chris PeBenito
|
77c124c8cd
|
eliminate _depend macros
|
2005-06-16 20:30:59 +00:00 |
|
Chris PeBenito
|
828e03f635
|
initial commit
|
2005-06-15 13:53:48 +00:00 |
|
Chris PeBenito
|
5e0da6a03e
|
finish renaming system/selinux to system/selinuxutil
|
2005-06-14 20:48:34 +00:00 |
|
Chris PeBenito
|
ff7bc148e4
|
move security_t to selinux module
|
2005-06-14 20:40:09 +00:00 |
|
Chris PeBenito
|
be4a8011d4
|
move selinux to selinuxutil
|
2005-06-14 20:12:46 +00:00 |
|
Chris PeBenito
|
8bd6789954
|
move constraints interfaces to domain module. move sysfs and usbfs to
devices module
|
2005-06-14 19:56:46 +00:00 |
|
Chris PeBenito
|
810f2b7155
|
fix typo
|
2005-06-14 18:15:01 +00:00 |
|
Chris PeBenito
|
b57dd19400
|
stray renames in distro_redhat
|
2005-06-14 17:36:21 +00:00 |
|
Chris PeBenito
|
3eed10909e
|
convert relevant conditionals into tunable_policy
|
2005-06-14 14:43:04 +00:00 |
|
Chris PeBenito
|
92e928e1bd
|
start making genhomedircon work
|
2005-06-13 21:16:05 +00:00 |
|
Chris PeBenito
|
c24ac9c51c
|
rename requires_block_template to gen_require
|
2005-06-13 20:51:09 +00:00 |
|
Chris PeBenito
|
fa7bea8feb
|
rename requires_block_tempalte to gen_require
|
2005-06-13 20:47:04 +00:00 |
|
Chris PeBenito
|
34c8fabeeb
|
tunables work
|
2005-06-13 20:44:23 +00:00 |
|
Chris PeBenito
|
31908be07f
|
a few missed renames, and start fixing up tunables
|
2005-06-13 20:27:32 +00:00 |
|
Chris PeBenito
|
5a45e70177
|
rename setattr removable_device_t
|
2005-06-13 20:00:36 +00:00 |
|
Karl MacMillan
|
8700497fb1
|
Updates to documentation.
|
2005-06-13 19:22:00 +00:00 |
|
Chris PeBenito
|
d9507b1874
|
fix xml
|
2005-06-13 17:40:51 +00:00 |
|