Commit Graph

5617 Commits

Author SHA1 Message Date
Chris PeBenito
d5ae683e2b add seutil_rw_config() 2006-10-25 20:48:04 +00:00
Chris PeBenito
76bac89cf0 make load target more friendly and add reload target 2006-10-25 20:38:33 +00:00
Daniel J Walsh
08efeffbe5 - Fixes for ricci using saslauthd 2006-10-25 15:31:39 +00:00
Daniel J Walsh
dc804f3593 - Allow mountpoint on home_dir_t and home_t 2006-10-24 19:55:28 +00:00
Daniel J Walsh
8ff9d6e5a3 - Update xen to read nfs files 2006-10-24 16:12:29 +00:00
Daniel J Walsh
3d011ff2e8 Mon Oct 23 2006 Dan Walsh <dwalsh@redhat.com> 2.4-4
- Allow noxattrfs to associate with other noxattrfs
2006-10-23 20:54:50 +00:00
Daniel J Walsh
11d7ea1908 - Allow hal to use power_device_t 2006-10-23 17:26:25 +00:00
Daniel J Walsh
d6926f7f13 - Allow procemail to look at autofs_t
- Allow xen_image_t to work as a fixed device
2006-10-20 21:08:15 +00:00
Chris PeBenito
a8671ae5b2 enhanced setransd support from darrel goeddel 2006-10-20 14:44:23 +00:00
Daniel J Walsh
e2eecb7a01 - Refupdate from upstream 2006-10-19 15:52:02 +00:00
Daniel J Walsh
302afb6db1 - Add lots of fixes for mls cups 2006-10-19 14:32:27 +00:00
Daniel J Walsh
6fa5ecef5d - Lots of fixes for ricci 2006-10-18 20:58:51 +00:00
Chris PeBenito
248cccf7ce 20061018 release 2006-10-18 20:26:45 +00:00
Chris PeBenito
a52b4d4f23 bump versions to release numbers 2006-10-18 19:25:27 +00:00
Chris PeBenito
b04eccd87b fix duplicate /usr/bin/mplayer fc match for targeted 2006-10-18 17:31:14 +00:00
Chris PeBenito
d4a48c41c2 make inetd optional 2006-10-18 15:49:45 +00:00
Daniel J Walsh
2d1b4a450f - Fix number of cats 2006-10-17 19:59:07 +00:00
Daniel J Walsh
da08298372 - Update to upstream 2006-10-17 18:43:08 +00:00
Chris PeBenito
130f8a4aa5 merge netlabel stuff from labeled-networking branch 2006-10-17 16:58:17 +00:00
Chris PeBenito
aeaae5185e fix ticket #16 2006-10-16 16:51:57 +00:00
Chris PeBenito
e45324d1ee gentoo integrated run_init rules in wrong build option. 2006-10-15 00:23:06 +00:00
Chris PeBenito
0e5c5442c6 fix term_tty() associations 2006-10-14 23:32:30 +00:00
Chris PeBenito
009b377174 more realplayer entries 2006-10-14 23:31:33 +00:00
Chris PeBenito
14b1684aae gentoo testing fixes. 2006-10-13 21:44:02 +00:00
jantill
a3698a1d5b - More iSCSI changes for #209854 2006-10-12 15:43:58 +00:00
jantill
cd0a0d2169 - Test ISCSI fixes for #209854 2006-10-12 15:24:06 +00:00
Chris PeBenito
8a2492a2df fix makefile to install root default contexts 2006-10-12 13:18:21 +00:00
Chris PeBenito
d508474f08 add load target to Makefile.devel 2006-10-10 15:23:17 +00:00
Chris PeBenito
212832373e mkdir policy and file contexts dirs in make load of modular policy. 2006-10-10 15:09:59 +00:00
Chris PeBenito
85f0c35922 make optional the inetd dependency in samba 2006-10-10 13:11:58 +00:00
Chris PeBenito
93ddc66983 change transition from run_init to initrc to spec. 2006-10-09 18:52:19 +00:00
Daniel J Walsh
ed9a4ccc00 - allow semodule to rmdir selinux_config_t dir 2006-10-08 21:45:47 +00:00
Daniel J Walsh
70e2dbc497 - Fix boot_runtime_t problem on ppc. Should not be creating these files. 2006-10-06 20:38:14 +00:00
Chris PeBenito
f76d07072a fix some stuff that does not affect policy 2006-10-06 17:31:52 +00:00
Chris PeBenito
830c12eb2d apply contested part of russell's last patch 2006-10-06 13:38:49 +00:00
Chris PeBenito
546c81ce25 more non .so lib files for acrobat 2006-10-05 20:39:25 +00:00
Chris PeBenito
3c3c0439f6 patch from russell, Thu, 5 Oct 2006 22:44:49 +1000
Allow unconfined processes to see unlabeled processes in ps.

Removed a redundant rule in samba.te

Removed support for the pre-Fedora Red Hat code to create sym-links in /boot.

Removed support for devpts_t files in /tmp (there is no way that would ever 
work).

Allowed postgrey to create socket files.

Made the specs for the /lib and /lib64 directories better support stem 
compression.
2006-10-05 19:57:37 +00:00
Daniel J Walsh
16c971a867 - Fix context mounts on reboot
- Fix ccs creation of directory in /var/log
2006-10-05 19:31:33 +00:00
Daniel J Walsh
7316db5b42 - Update for tallylog 2006-10-05 15:11:16 +00:00
Daniel J Walsh
bfcffeacff - Allow xend to rewrite dhcp conf files
- Allow mgetty sys_admin capability
2006-10-05 13:48:32 +00:00
Daniel J Walsh
160281be0a - Make xentapctrl work 2006-10-04 19:31:42 +00:00
Chris PeBenito
e070dd2df0 - Move range transitions to modules.
- Make number of MLS sensitivities, and number of MLS and MCS
  categories configurable as build options.
2006-10-04 17:25:34 +00:00
Daniel J Walsh
46f098ac91 - Don't transition unconfined_t to bootloader_t
- Fix label in /dev/xen/blktap
2006-10-03 20:35:40 +00:00
Daniel J Walsh
f21d67baff - Patch for labeled networking 2006-10-03 18:47:06 +00:00
Daniel J Walsh
42dd742837 - Fix crond handling for mls 2006-10-02 19:45:00 +00:00
Chris PeBenito
00219064d7 This patch adds a GConf policy to refpolicy.
This policy is much tighter than the GConf policy from the old example
policy.  It only allows gconfd to access configuration data stored by
GConf.  Users can modify configuration data using gconftool-2 or
gconf-editor, both of which use gconfd.  GConf manages multiple
configuration sources, so gconfd should be used to make any changes
anyway.  Normal users who aren't trying to directly edit the
configuration data of GConf won't notice anything different.

There is also a difference between this policy and the old example
policy in handling directories in /tmp.  The old example policy
labeled /tmp/gconfd-USER with ROLE_gconfd_tmp_t, but, since there was no
use of the file_type_auto_trans macro, if that directory was deleted
gconfd would create one labeled as tmp_t.  This policy uses the
files_tmp-filetrans macro to cause a directory in /tmp created by gconfd
to be labeled as $1_tmp_t.  It is not labeled with $1_gconf_tmp_t,
because if /tmp/orbit-USER is deleted, gconfd will create it (through
use of ORBit) and it would get the $1_gconf_tmp_t label.  By having
gconfd create $1_tmp_t directories in /tmp and $1_gconf_tmp_t files and
directories in directories labeled with $1_tmp_t, it can control its
data without requiring any future bonobo or Gnome policies to have
access to $1_gconf_tmp_t.

This patch is related to work that I am doing in making gconfd an
userspace object manager.  If any user program can modify the
configuration data that GConf stores, than making gconfd an userspace
object manager would be useless.

Signed-off-by:  James Carter <jwcart2@tycho.nsa.gov>
2006-10-02 15:22:48 +00:00
Daniel J Walsh
8fff699602 - Update to upstream 2006-09-29 19:19:18 +00:00
Daniel J Walsh
52ba98baf2 - Remove bluetooth-helper transition
- Add selinux_validate for semanage
- Require new version of libsemanage
2006-09-29 18:12:18 +00:00
Chris PeBenito
f8cfddbb76 fix ticket #15. 2006-09-29 18:00:21 +00:00
Chris PeBenito
49317e6b49 fix corenetwork so the ifdef enable_mls survives to regular processing. 2006-09-29 17:37:57 +00:00