Commit Graph

5780 Commits

Author SHA1 Message Date
Chris PeBenito
376fbc0be9 clean up usercanread 2006-09-11 18:23:09 +00:00
Chris PeBenito
b1bf2f7811 add last bit of role infrastructure 2006-09-11 15:26:25 +00:00
Chris PeBenito
95b8223eed cleanups 2006-09-08 17:21:28 +00:00
Daniel J Walsh
8b6c3732d7 - Fix location of xel log files
- Fix handling of sysadm_r -> rpm_exec_t
2006-09-08 17:10:41 +00:00
Daniel J Walsh
1ef9d40e46 - Fixes for autofs, lp 2006-09-07 19:15:29 +00:00
Chris PeBenito
bbcd3c97dd add main part of role-o-matic 2006-09-06 22:07:25 +00:00
Daniel J Walsh
937c1cc4df - Update from upstream 2006-09-06 18:29:35 +00:00
Chris PeBenito
75beb95014 patch from dan Tue, 05 Sep 2006 17:06:06 -0400 2006-09-06 16:36:23 +00:00
Daniel J Walsh
57075ee245 - Fixup for test6 2006-09-05 21:13:31 +00:00
Daniel J Walsh
66ca8d0003 - Fixup for test6 2006-09-05 20:19:56 +00:00
Daniel J Walsh
4bf7cf3e30 - Fixup for test6 2006-09-05 19:45:07 +00:00
Chris PeBenito
91dabf4d78 fix up usb.ids per distro 2006-09-05 14:31:27 +00:00
Chris PeBenito
686f11c22c add corenetwork.if dependency on corenetwork.te.in, since it is used to build the .if file 2006-09-05 14:29:37 +00:00
Daniel J Walsh
efb08979c0 - Update to upstream 2006-09-05 12:03:37 +00:00
Chris PeBenito
13d7cec671 patch from erich Sat, 02 Sep 2006 03:37:44 +0200 2006-09-04 18:22:12 +00:00
Chris PeBenito
5dbda5558a patch from dan Fri, 01 Sep 2006 15:45:24 -0400 2006-09-04 15:15:35 +00:00
Daniel J Walsh
928af41d8b - Update to upstream 2006-09-01 19:45:39 +00:00
Chris PeBenito
9b45c60308 This patch adds a polmatch avperm to arbitrate flow/state's access to
a xfrm policy. It also defines MLS policy for association { sendto,
recvfrom, polmatch }.

NOTE: When an inbound packet is not using an IPSec SA, a check is performed
between the socket label and the unlabeled sid (SYSTEM_HIGH MLS label). For
MLS purposes however, the target of the check should be the MLS label taken
from the node sid (or secmark in the new secmark world). This would present
a severe performance overhead (to make a new sid based on the unlabeled sid
with the MLS taken from the node sid or secmark and then using this sid as
the target). Pending reconciliation of the netlabel, ipsec and iptables contexts,
I have chosen to currently make an exception for unlabeled_t SAs if TE policy
allowed it. A similar problem exists for the outbound case and it has been similarly
handled in the policy below (by making an exception for unlabeled_t).

I am submitting the below limited patch pending a comprehensive patch from
Joy Latten at IBM (latten@austin.ibm.com).

I am not sure if I needed to manually do a "make tolib" in the flask subdir
and submit the results as well. Please let me know if I needed to.

Signed-off-by: Venkat Yekkirala <vyekkirala@TrustedCS.com>
2006-09-01 17:06:53 +00:00
Chris PeBenito
eac818f040 patch from dan Thu, 31 Aug 2006 15:16:30 -0400 2006-09-01 15:52:05 +00:00
Daniel J Walsh
04dd122d14 - Fix suspend to disk problems 2006-09-01 14:58:36 +00:00
Daniel J Walsh
a1c3b4ef0a - Lots of fixes for restarting daemons at the console. 2006-08-31 21:39:01 +00:00
Daniel J Walsh
3723ca6f56 - Lots of fixes for restarting daemons at the console. 2006-08-31 19:32:34 +00:00
Chris PeBenito
c634db20c6 fix makefile style so internal variables are lowercase 2006-08-31 17:28:35 +00:00
Daniel J Walsh
e4710b3b72 - Fix audit line
- Fix requires line
2006-08-31 12:13:31 +00:00
Daniel J Walsh
7f5a12d575 - Fix audit line
- Fix requires line
2006-08-30 21:44:22 +00:00
Daniel J Walsh
358adda620 - Fix requires line 2006-08-30 21:19:12 +00:00
Daniel J Walsh
06027c9ac0 - Upgrade to upstream 2006-08-30 20:59:51 +00:00
Chris PeBenito
a5e2133bc8 patch from dan Wed, 23 Aug 2006 14:03:49 -0400 2006-08-29 02:41:00 +00:00
Daniel J Walsh
1616552ae2 - Fix install problems 2006-08-28 21:49:05 +00:00
Chris PeBenito
ce6bf7cc23 more testing fixes 2006-08-28 02:46:20 +00:00
Daniel J Walsh
9e88149b16 - Allow setroubleshoot to getattr on all dirs to gather RPM data 2006-08-25 20:06:07 +00:00
Daniel J Walsh
4c348582ff - Set /usr/lib/ia32el/ia32x_loader to unconfined_execmem_exec_t for ia32
platform
- Fix spec for /dev/adsp
2006-08-25 17:32:13 +00:00
Chris PeBenito
e539a49638 This patch enables to use xattr on jffs2 filesystem.
The jffs2 filesystem is a filesystem for memory technology
devices (MTD), and xattr supporting on jffs2 is neccesary
to use SELinux with a small diskless PDA and so on.
This facility is queued for kernel 2.6.18 now, so I hope
to merge this small patch into the refpolicy repository.

Example of xattr/jffs2: SELinux on OpenZaurus :D
  http://www.kaigai.gr.jp/pub/sezaurus.jpg

Thanks,
--
KaiGai Kohei <kaigai@kaigai.gr.jp>
2006-08-25 13:28:57 +00:00
Chris PeBenito
de222824e9 fix gentoo /opt contexts 2006-08-25 13:26:21 +00:00
Daniel J Walsh
b2d3ebd7a0 - Fix xen tty devices 2006-08-24 20:53:40 +00:00
Daniel J Walsh
8cd82cf62b - Fixes for setroubleshoot 2006-08-24 20:31:13 +00:00
Daniel J Walsh
a5dcfa874f - Update to upstream 2006-08-23 20:42:38 +00:00
Chris PeBenito
98de871cee more strict testing fixes 2006-08-23 19:36:04 +00:00
Chris PeBenito
d15dd5a739 more testing fixes 2006-08-23 03:47:39 +00:00
Chris PeBenito
5b4ff3a104 fix ordering bug 2006-08-22 19:56:59 +00:00
Chris PeBenito
3ef029db7c add nscd_socket_use() to auth_use_nsswitch() since it caches nss lookups. 2006-08-22 19:37:56 +00:00
Chris PeBenito
2ed690dd9b fix typo in sxid 2006-08-21 13:35:51 +00:00
Daniel J Walsh
3559b5314e - Fixes for stunnel and postgresql
- Update from upstream
2006-08-20 15:11:37 +00:00
Daniel J Walsh
6f77ee084f - Fixes for stunnel and postgresql 2006-08-20 14:54:47 +00:00
Chris PeBenito
e9b9e45214 testing fixes 2006-08-18 18:20:22 +00:00
Daniel J Walsh
79b5c47536 - Update from upstream 2006-08-18 14:18:35 +00:00
Chris PeBenito
4bc6e32e28 fix for netfilter_contexts 2006-08-18 14:01:48 +00:00
Chris PeBenito
e50a55b9a4 clear executable bits 2006-08-17 20:42:38 +00:00
Chris PeBenito
ba1a545fb3 cleanup in authlogin 2006-08-17 15:35:14 +00:00
Chris PeBenito
3573908f1c fix cron_system_entry() rules 2006-08-16 13:52:18 +00:00