Chris PeBenito
2d0c9cecaf
trunk: several MLS enhancements.
2007-08-20 15:15:03 +00:00
Chris PeBenito
9760cbec2d
trunk: Database userspace object manager classes from KaiGai Kohei.
2007-08-09 13:15:07 +00:00
Chris PeBenito
3d6e962dfa
trunk: filesystem patch from dan
2007-08-08 20:04:28 +00:00
Chris PeBenito
939a4287b3
trunk: 3 patches from dan
2007-08-07 17:06:32 +00:00
Chris PeBenito
c040ea12b2
trunk: several support macro fixes.
2007-07-31 15:11:22 +00:00
Chris PeBenito
371d11ec04
trunk: add 3rd party interface for apache cgi.
2007-07-26 19:48:40 +00:00
Chris PeBenito
63acaf59d7
trunk: fix pipe permission set in domtrans_pattern().
2007-07-26 19:41:15 +00:00
Chris PeBenito
924f3cc2cb
trunk: add getserv and shmemserv nscd permissions.
2007-07-24 19:52:18 +00:00
Chris PeBenito
708aab1393
trunk: fix targeted sshd. When the domain was unaliased from unconfined_t, a transition to unconfined_t was not added.
2007-07-20 18:25:26 +00:00
Chris PeBenito
d46cfe45cd
trunk: add application module
2007-07-19 18:57:48 +00:00
Chris PeBenito
6929521e0a
trunk: fix missed netlabel deprecation
2007-07-19 15:11:19 +00:00
Chris PeBenito
f80a0e4f25
trunk: Add debian apcupsd binary location, from Stefan Schulze Frielinghaus.
2007-07-02 15:25:46 +00:00
Chris PeBenito
116c1da330
trunk: update module version numbers for release.
2007-06-29 14:48:13 +00:00
Chris PeBenito
113b4fc4a2
Fix incorrectly named files_lib_filetrans_shared_lib() interface in the libraries module.
2007-06-28 17:25:46 +00:00
Chris PeBenito
e5e55ace89
trunk, strict-targeted-merge: add mmap_zero to xserver domains.
2007-06-28 12:34:08 +00:00
Chris PeBenito
f5842c1fa5
trunk: minor amanda update from dan
2007-06-27 19:19:20 +00:00
Chris PeBenito
7b61fe506d
trunk: add rpcbind from dan
2007-06-27 16:31:55 +00:00
Chris PeBenito
1900668638
trunk: Unified labeled networking policy from Paul Moore.
...
The latest revision of the labeled policy patches which enable both labeled
and unlabeled policy support for NetLabel. This revision takes into account
Chris' feedback from the first version and reduces the number of interface
calls in each domain down to two at present: one for unlabeled access, one for
NetLabel access. The older, transport layer specific interfaces, are still
present for use by third-party modules but are not used in the default policy
modules.
trunk: Use netmsg initial SID for MLS-only Netlabel packets, from Paul Moore.
This patch changes the policy to use the netmsg initial SID as the "base"
SID/context for NetLabel packets which only have MLS security attributes.
Currently we use the unlabeled initial SID which makes it very difficult to
distinquish between actual unlabeled packets and those packets which have MLS
security attributes.
2007-06-27 15:23:21 +00:00
Chris PeBenito
2c3ac47d45
trunk: pyzor and clamav updates from dan
2007-06-26 18:43:11 +00:00
Chris PeBenito
22bff65f4d
trunk: fix typo in vmware.fc
2007-06-26 14:31:31 +00:00
Chris PeBenito
02f2c3e979
trunk: nagios update from dan
2007-06-21 17:23:19 +00:00
Chris PeBenito
a90a256f64
trunk: procmail tweak from dan.
2007-06-21 14:54:34 +00:00
Chris PeBenito
7f089782ae
trunk: xen updates from dan
2007-06-21 13:36:05 +00:00
Chris PeBenito
92d1ade254
trunk: trivial gentoo tweaks
2007-06-20 20:08:26 +00:00
Chris PeBenito
5bf9deb5bb
trunk: 3 patches from dan
2007-06-20 19:47:10 +00:00
Chris PeBenito
99b5a56cb6
trunk: radius one-liner from dan
2007-06-20 15:03:55 +00:00
Chris PeBenito
40df56772f
trunk: big samba update from dan
2007-06-19 19:11:35 +00:00
Chris PeBenito
788d88c923
trunk: drop snmpd_etc_t.
2007-06-19 17:39:35 +00:00
Chris PeBenito
6c8aba7b31
trunk: confine sendmail and logrotate on targeted
2007-06-19 17:01:39 +00:00
Chris PeBenito
cb10a2d5bf
trunk: Tunable connection to postgresql for users from KaiGai Kohei.
2007-06-19 14:30:06 +00:00
Chris PeBenito
41337aa8b9
Memprotect support patch from Stephen Smalley.
2007-06-19 13:02:26 +00:00
Chris PeBenito
d139413c64
trunk: 2 patches from dan
2007-06-13 13:54:56 +00:00
Chris PeBenito
a74d1ad7cd
trunk: add amtu from dan
2007-06-12 18:58:36 +00:00
Chris PeBenito
d5b81a81ff
trunk: Add logging_send_audit_msgs() interface and deprecate send_audit_msgs_pattern().
2007-06-12 18:46:14 +00:00
Chris PeBenito
262def165a
trunk: version bumps for previous commit.
2007-06-12 13:08:19 +00:00
Chris PeBenito
f7101c5430
trunk: 7 simple patches from dan.
2007-06-12 13:06:13 +00:00
Chris PeBenito
6649aec9d0
trunk: 3 patches from dan
2007-06-11 15:43:37 +00:00
Chris PeBenito
d534d35a7e
trunk: 5 patches from dan
2007-06-11 15:01:10 +00:00
Chris PeBenito
f6a590d7b4
six simple patches from dan
2007-06-11 14:09:09 +00:00
Chris PeBenito
7782966db1
add fc entry for make_reiser4
2007-06-08 20:01:34 +00:00
Chris PeBenito
17b9cb7dda
trunk: fix line in evolution to be strict-only; was being covered up by genhomedircon.
2007-05-22 17:01:38 +00:00
Chris PeBenito
a39a931362
trunk: snmp tweak from dan
2007-05-15 18:06:31 +00:00
Chris PeBenito
c412be6bef
trunk: remaining pieces for apcupsd module
2007-05-15 15:43:00 +00:00
Chris PeBenito
38d0cf1b8a
trunk: long overdue cleanup from when range_transitions were only in the base module
2007-05-14 15:35:47 +00:00
Chris PeBenito
762d2cb989
merge restorecon into setfiles
2007-05-11 17:10:43 +00:00
Chris PeBenito
12217cc286
Patch to begin separating out hald helper programs from Dan Walsh.
2007-05-07 17:57:48 +00:00
Chris PeBenito
78f17e6d6c
add apcupsd from dan
2007-05-07 14:55:54 +00:00
Chris PeBenito
b129e2001c
Fixes for squid, dovecot, and snmp from Dan Walsh.
2007-05-07 13:45:17 +00:00
Chris PeBenito
4967aaa320
Miscellaneous consolekit fixes from Dan Walsh.
2007-05-03 14:15:38 +00:00
Chris PeBenito
0ef5d66468
textrel lib update from dan
2007-05-03 13:43:44 +00:00
Chris PeBenito
7f819d806d
add missing rename_dir_perms
2007-05-03 13:15:48 +00:00
Chris PeBenito
ed4b7301fb
Patch to have avahi use the nsswitch interface rather than individual permissions from Dan Walsh.
2007-05-03 12:45:28 +00:00
Chris PeBenito
517618f0b4
Patch to dontaudit logrotate searching avahi pid directory from Dan Walsh.
2007-05-02 17:55:03 +00:00
Chris PeBenito
882186c933
- Patch to allow insmod to mount kvmfs and dontaudit rw unconfined_t pipes
...
to handle usage from userhelper.
2007-05-02 17:31:38 +00:00
Chris PeBenito
6a2975706a
add rwho from Nalin Dahyabhai
2007-04-30 17:39:01 +00:00
Chris PeBenito
747ab18400
Patch to allow amavis to read spamassassin libraries from Dan Walsh.
2007-04-30 15:19:47 +00:00
Chris PeBenito
ae32fb7e7b
trivial aide fix from dan
2007-04-30 15:09:15 +00:00
Chris PeBenito
f9029fc5b6
Patch to allow slocate to getattr other filesystems and directories on those filesystems from Dan Walsh.
2007-04-30 15:01:19 +00:00
Chris PeBenito
27c570f755
trivial fix for netutils from dan
2007-04-30 14:44:04 +00:00
Chris PeBenito
7487a66705
trivial fix from dan for bluetooth
2007-04-30 14:33:12 +00:00
Chris PeBenito
b4beb0a0fb
missed piece of clip patch
2007-04-30 14:32:31 +00:00
Chris PeBenito
d28e528b0d
Fixes for RHEL4 from the CLIP project.
2007-04-27 15:08:15 +00:00
Chris PeBenito
cd16fe6e2c
Replace the old lrrd fc entries with correct munin ones.
2007-04-23 17:36:35 +00:00
Chris PeBenito
b4dfdc7d30
Move program admin template usage out of userdom_admin_user_template() to sysadm policy in userdomain.te to fix usage of the template for third parties.
2007-04-19 14:30:57 +00:00
Chris PeBenito
7a4bd42ea3
Fix clockspeed_run_cli() declaration, it was incorrectly defined as a template instead of an interface.
2007-04-19 14:24:02 +00:00
Chris PeBenito
0251df3e39
bump module versions for release
2007-04-17 13:28:09 +00:00
Chris PeBenito
4029f11670
last piece of previous consolekit patch
2007-04-11 20:02:59 +00:00
Chris PeBenito
97e8156ecb
add zabbix from dan
2007-04-11 18:55:44 +00:00
Chris PeBenito
697489040e
5 patches from dan. confine insmod and udev on targeted, misc fc fixes, sasl kerberos use, and samba port fixes
2007-04-11 17:56:03 +00:00
Chris PeBenito
99064c9fbd
more consolekit updates from dan
2007-04-11 14:04:35 +00:00
Chris PeBenito
82e284bb89
last piece of dan's previous patch
2007-04-11 13:31:10 +00:00
Chris PeBenito
19b2dee3cc
confine ldconfig in targeted, from dan
2007-04-10 19:39:22 +00:00
Chris PeBenito
ebc1e8be97
from dan:
...
kadmind trys to setattr on krb5kdc file. Just a library checking access.
2007-04-10 17:20:07 +00:00
Chris PeBenito
9af48eef6e
six patches from dan
2007-04-10 13:10:58 +00:00
Chris PeBenito
98faba122c
gentoo /lib can be a symlink on x86-64 systems
2007-04-02 13:33:18 +00:00
Chris PeBenito
39d8dcdb4f
fix http_script_domains, it was incorrectly applied to the content type rather than the script domain. bug #24 .
2007-04-02 13:20:55 +00:00
Chris PeBenito
f88ef60ac0
emit "null" instead of NULL for userspace headers
2007-03-30 20:33:51 +00:00
Chris PeBenito
f6ddd6b9b7
bools in modules fix to require the boolean in optionals that are part of the base module, and move bool declarations in the base module/monolithic
2007-03-30 12:43:15 +00:00
Chris PeBenito
a26923c32e
Two patches from Paul Moore to for ipsec to remove redundant rules and have setkey read the config file.
2007-03-28 18:47:45 +00:00
Chris PeBenito
9e8f65c83e
six trivial patches from dan for iptables, netutils, ipsec, devices, filesystem and cpuspeed
2007-03-26 20:47:29 +00:00
Chris PeBenito
56e1b3d207
- Move booleans and tunables to modules when it is only used in a single
...
module.
- Add support for tunables and booleans local to a module.
2007-03-26 18:41:45 +00:00
Chris PeBenito
8021cb4f63
Merge sbin_t and ls_exec_t into bin_t.
2007-03-23 23:24:59 +00:00
Chris PeBenito
ab514d6a89
remove disable_trans booleans
2007-03-23 21:01:49 +00:00
Chris PeBenito
e9b0042f35
Output different header sets for kernel and userland from flask headers.
2007-03-23 20:32:23 +00:00
Chris PeBenito
1852cdabce
deprecated pax class
2007-03-23 20:21:06 +00:00
Chris PeBenito
5f5b7a1ec6
network fix from dan
2007-03-22 14:33:00 +00:00
Chris PeBenito
cc9130b90a
one-liner from dan
2007-03-22 14:01:55 +00:00
Chris PeBenito
19fd9301e6
patch from dan to have ricci modstorage transition to lvm
2007-03-21 20:02:50 +00:00
Chris PeBenito
cd3ee91a4b
add fail2ban from dan
2007-03-21 15:51:52 +00:00
Chris PeBenito
efcf9df253
kudzu will telinit to make init re-read the inittab after configuring serial consoles
2007-03-20 19:00:35 +00:00
Chris PeBenito
a5f5eba459
Add dontaudits for init fds and console to init_daemon_domain().
2007-03-20 18:47:18 +00:00
Chris PeBenito
4832f0e066
create user gpg keys dir patch from dan
2007-03-19 19:10:43 +00:00
Chris PeBenito
93784927ca
add kvmfs support, from dan
2007-03-19 18:48:14 +00:00
Chris PeBenito
7200146ea8
trivial patch for radius from dan
2007-03-19 18:42:57 +00:00
Chris PeBenito
86b28c9594
trivial patch from dan for sysstat access to sysfs
2007-03-19 18:38:54 +00:00
Chris PeBenito
e66689f7be
other part of consolekit addition
2007-03-19 18:36:36 +00:00
Chris PeBenito
c224d91c7b
from Dan:
...
This is a new policy for the User Switching capability coming in gnome.
consolekit is a daemon that communicates with xdm_t and hal through dbus to change the
ownership/access on certain devices when the login session changes from one user to another
2007-03-19 18:01:15 +00:00
Chris PeBenito
6c20f77e80
patch from Dan for sudo:
...
sudo should be able to getattr on all executables not just
bin_t/sbin_t. Confined executeables run from sudo need this.
sudo_exec_t needs to be marked as exec_type so prelink will work correctly.
sudo semanage should work
2007-03-19 16:32:44 +00:00
Chris PeBenito
b50f2ee48d
It was just pointed out to me that the raw IP socket class is missing from the
...
recvfrom MLS constraint.
Signed-off-by: Paul Moore
2007-03-09 14:45:19 +00:00
Chris PeBenito
0cca516db7
fix for rh bug 203290
2007-03-08 19:01:21 +00:00
Chris PeBenito
b5a6c86f46
last bit of dans patch
2007-03-08 17:53:52 +00:00
Chris PeBenito
cdc91b9aeb
Patch for handling restart of nscd when ran from useradd, groupadd, and admin passwd, from Dan Walsh.
2007-03-08 15:14:45 +00:00
Chris PeBenito
59bedc1886
procmail uses /tmp files
...
Wants to send signull to itself
Can exec ls
Read spamassinn_lib_dirs
New directory for spamassin /var/lib/
pyzor uses tmp files
2007-03-07 21:33:22 +00:00
Chris PeBenito
7aefc69117
trivial change from dan
2007-03-06 17:44:26 +00:00
Chris PeBenito
7aca2aa827
setroubleshoot has a plugin that checks the file context on disk versus a matchpathcon. So needs additional privs
2007-03-06 17:16:08 +00:00
Chris PeBenito
c23eb5b1c4
Patch for gssd fixes from Dan Walsh
2007-03-06 16:18:59 +00:00
Chris PeBenito
c5561c777d
patches for lvm and ricci fixes from Dan Walsh.
2007-03-06 15:35:02 +00:00
Chris PeBenito
f2c69c47b3
lmtp and smtp are the same file require same context of setfiles complains
...
postfix_pickup_t wants to read postfix_spool_maildrop_t dir
2007-03-01 20:41:19 +00:00
Chris PeBenito
ecc98e19e3
patches for file contexts in networkmanager, miscfiles, corecommands, devices, and java from Dan Walsh.
2007-03-01 15:43:39 +00:00
Chris PeBenito
4900fdf7d1
Patch for kerberized telnet fixes from Dan Walsh.
2007-02-28 17:17:52 +00:00
Chris PeBenito
09c56f5496
Patch for kerberized ftp and other ftp fixes from Dan Walsh.
2007-02-28 17:01:47 +00:00
Chris PeBenito
2aea366ffc
Patch for an additional wine executable from Dan Walsh.
2007-02-28 16:23:06 +00:00
Chris PeBenito
bf39cdb807
Patch for additional games file contexts from Dan Walsh.
2007-02-28 15:30:38 +00:00
Chris PeBenito
86d754eed6
Add support for libselinux 2.0.5 init_selinuxmnt() changes.
2007-02-27 17:02:35 +00:00
Chris PeBenito
ca448bd66c
add init_exec() to init_telinit().
2007-02-26 20:19:53 +00:00
Chris PeBenito
f0eaed31be
Patch for misc fixes to bluetooth from Dan Walsh.
2007-02-26 17:23:52 +00:00
Chris PeBenito
5b06477c8e
On Tue, 2007-02-20 at 12:02 -0500, Daniel J Walsh wrote:
...
> Eliminate excess avc messages created when using kerberos libraries
>
> krb5kdc wans to setsched
>
> Also uses a fifo_file to communicate.
>
> Needs to search_network_sysctl
2007-02-26 17:04:56 +00:00
Chris PeBenito
bbb7cc8927
Patch to start deprecating usercanread attribute from Ryan Bradetich.
2007-02-26 16:13:23 +00:00
Chris PeBenito
a715dc0995
add dccp_socket object class
2007-02-26 15:39:59 +00:00
Chris PeBenito
3a39015792
On Tue, 2007-02-20 at 12:30 -0500, Daniel J Walsh wrote:
...
> prelink creates temporarly files that it then needs to relabel.
2007-02-23 21:20:46 +00:00
Chris PeBenito
5c45eaede1
On Tue, 2007-02-20 at 12:28 -0500, Daniel J Walsh wrote:
...
> audit needs fsetid
>
> syslog needs to be able to create a tcp_socket for off machine logging.
2007-02-23 20:19:29 +00:00
Chris PeBenito
66cf194680
Patch to remove redundant mls_trusted_object() call from Dan Walsh.
2007-02-23 20:05:12 +00:00
Chris PeBenito
4685213857
Patch for misc fixes to nis ypxfr policy from Dan Walsh.
2007-02-23 19:52:52 +00:00
Chris PeBenito
aeb54c6dd0
Patch to allow apmd to telinit from Dan Walsh.
2007-02-23 19:41:41 +00:00
Chris PeBenito
d114071e7a
While using samba and SELinux with Debian GNU/Linux (etch) the
...
following files need to be labeled correctly:
/var/run/samba/gencache.tdb
/var/run/samba/share_info.tdb
Should also concern other distributions than Debian.
-Stefan
2007-02-23 19:30:17 +00:00
Chris PeBenito
bcac3a5e3d
Patch to remove incorrect cron labeling in apache.fc from Ryan Bradetich.
2007-02-23 19:08:45 +00:00
Chris PeBenito
f1be09c2b1
make ttys and ptys device nodes
2007-02-20 20:17:07 +00:00
Chris PeBenito
6b19be3360
patch from dan, Thu, 2007-01-25 at 08:12 -0500
2007-02-16 23:01:42 +00:00
Chris PeBenito
10e12095d6
Fix explicit use of httpd_t in openca_domtrans(), bug #22 .
2007-02-07 22:10:45 +00:00
Chris PeBenito
ff943a1b9b
Clean up file context regexes in apache and java, from Eamon Walsh:
...
Some file_contexts regular expressions in refpolicy-strict are causing
genhomedircon to die; refpolicy is failing to build for me entirely.
The regular expressions seem redundant to me, perhaps I am missing
something, but the following patch fixes the problems for me. Please
review and apply
2007-01-24 17:10:31 +00:00
Chris PeBenito
42c5c5f612
bump versions for release.
2006-12-12 21:22:47 +00:00
Chris PeBenito
c0868a7a3b
merge policy patterns to trunk
2006-12-12 20:08:08 +00:00
Chris PeBenito
d6d16b9796
patch from dan Wed, 29 Nov 2006 17:06:40 -0500
2006-12-04 20:10:56 +00:00
Chris PeBenito
563e58e863
patch from dan for some missing gen_require()s
2006-11-29 13:44:40 +00:00
Chris PeBenito
bff907113d
fix dontaudit interface that was allowing instead of dontauditing; thanks to karl for pointing this out.
2006-11-28 15:57:22 +00:00
Chris PeBenito
c31f6724c0
fix dontaudit interface that was allowing instead of dontauditing; thanks to karl for pointing this out.
2006-11-28 15:47:47 +00:00
Chris PeBenito
fa45da0efd
add aide, ccs, and ricci
2006-11-16 20:56:24 +00:00
Chris PeBenito
d31d3c159e
This modifies the mls constraint for polmatch in the association class.
...
Specifically:
- polmatch need no longer make an exception for unlabeled_t
since a flow will now always match SPD rules with no contexts (per
the IPSec leak fix patch upstreamed a few weeks back), as
opposed to needing polmatch access to unlabeled_t.
Signed-off-by: Venkat Yekkirala <vyekkirala@TrustedCS.com>
2006-11-16 13:38:14 +00:00
Chris PeBenito
c6a60bb28d
On Tue, 2006-11-07 at 16:51 -0500, James Antill wrote:
...
> Here is the policy changes needed for the context contains security
> checking in PAM and cron.
2006-11-14 13:38:52 +00:00
Chris PeBenito
ed38ca9f3d
fixes from gentoo strict testing:
...
- Allow semanage to read from /root on strict non-MLS for
local policy modules.
- Gentoo init script fixes for udev.
- Allow udev to read kernel modules.inputmap.
- Dnsmasq fixes from testing.
- Allow kernel NFS server to getattr filesystems so df can work
on clients.
2006-11-13 03:24:07 +00:00
Chris PeBenito
0f9a2be65d
add missing gentoo file contexts for initrc and lvm
2006-11-07 19:38:10 +00:00
Chris PeBenito
f497b8df50
Christopher J. PeBenito wrote:
...
> We could add another 'or' on the above constraint:
>
> or ( (t2 == mlsfilewrite_in_range) and (l1 dom l2) and (h1 domby h2) )
>
> I believe that would be the constraint you were looking for. I don't
> like the name of that attribute, but I couldn't come up with a better
> one off the top of my head. :)
>
Attached is a patch which I've tested against selinux-policy-2.4.2-1
that implements this additional constraint. The name is still a bit
forced, but it works.
-matt <mra at hp dot com>
2006-11-01 15:42:22 +00:00
Chris PeBenito
d9845ae92a
patch from dan Tue, 24 Oct 2006 11:00:28 -0400
2006-10-31 21:01:48 +00:00
Chris PeBenito
582438054d
fix up corecommands perm sets, add seutil_manage_config_dirs()
2006-10-27 13:55:35 +00:00
Chris PeBenito
d5ae683e2b
add seutil_rw_config()
2006-10-25 20:48:04 +00:00
Chris PeBenito
a8671ae5b2
enhanced setransd support from darrel goeddel
2006-10-20 14:44:23 +00:00
Chris PeBenito
a52b4d4f23
bump versions to release numbers
2006-10-18 19:25:27 +00:00
Chris PeBenito
b04eccd87b
fix duplicate /usr/bin/mplayer fc match for targeted
2006-10-18 17:31:14 +00:00
Chris PeBenito
d4a48c41c2
make inetd optional
2006-10-18 15:49:45 +00:00
Chris PeBenito
130f8a4aa5
merge netlabel stuff from labeled-networking branch
2006-10-17 16:58:17 +00:00
Chris PeBenito
aeaae5185e
fix ticket #16
2006-10-16 16:51:57 +00:00
Chris PeBenito
e45324d1ee
gentoo integrated run_init rules in wrong build option.
2006-10-15 00:23:06 +00:00
Chris PeBenito
0e5c5442c6
fix term_tty() associations
2006-10-14 23:32:30 +00:00
Chris PeBenito
009b377174
more realplayer entries
2006-10-14 23:31:33 +00:00
Chris PeBenito
14b1684aae
gentoo testing fixes.
2006-10-13 21:44:02 +00:00
Chris PeBenito
85f0c35922
make optional the inetd dependency in samba
2006-10-10 13:11:58 +00:00
Chris PeBenito
93ddc66983
change transition from run_init to initrc to spec.
2006-10-09 18:52:19 +00:00
Chris PeBenito
f76d07072a
fix some stuff that does not affect policy
2006-10-06 17:31:52 +00:00
Chris PeBenito
830c12eb2d
apply contested part of russell's last patch
2006-10-06 13:38:49 +00:00
Chris PeBenito
546c81ce25
more non .so lib files for acrobat
2006-10-05 20:39:25 +00:00
Chris PeBenito
3c3c0439f6
patch from russell, Thu, 5 Oct 2006 22:44:49 +1000
...
Allow unconfined processes to see unlabeled processes in ps.
Removed a redundant rule in samba.te
Removed support for the pre-Fedora Red Hat code to create sym-links in /boot.
Removed support for devpts_t files in /tmp (there is no way that would ever
work).
Allowed postgrey to create socket files.
Made the specs for the /lib and /lib64 directories better support stem
compression.
2006-10-05 19:57:37 +00:00
Chris PeBenito
e070dd2df0
- Move range transitions to modules.
...
- Make number of MLS sensitivities, and number of MLS and MCS
categories configurable as build options.
2006-10-04 17:25:34 +00:00
Chris PeBenito
00219064d7
This patch adds a GConf policy to refpolicy.
...
This policy is much tighter than the GConf policy from the old example
policy. It only allows gconfd to access configuration data stored by
GConf. Users can modify configuration data using gconftool-2 or
gconf-editor, both of which use gconfd. GConf manages multiple
configuration sources, so gconfd should be used to make any changes
anyway. Normal users who aren't trying to directly edit the
configuration data of GConf won't notice anything different.
There is also a difference between this policy and the old example
policy in handling directories in /tmp. The old example policy
labeled /tmp/gconfd-USER with ROLE_gconfd_tmp_t, but, since there was no
use of the file_type_auto_trans macro, if that directory was deleted
gconfd would create one labeled as tmp_t. This policy uses the
files_tmp-filetrans macro to cause a directory in /tmp created by gconfd
to be labeled as $1_tmp_t. It is not labeled with $1_gconf_tmp_t,
because if /tmp/orbit-USER is deleted, gconfd will create it (through
use of ORBit) and it would get the $1_gconf_tmp_t label. By having
gconfd create $1_tmp_t directories in /tmp and $1_gconf_tmp_t files and
directories in directories labeled with $1_tmp_t, it can control its
data without requiring any future bonobo or Gnome policies to have
access to $1_gconf_tmp_t.
This patch is related to work that I am doing in making gconfd an
userspace object manager. If any user program can modify the
configuration data that GConf stores, than making gconfd an userspace
object manager would be useless.
Signed-off-by: James Carter <jwcart2@tycho.nsa.gov>
2006-10-02 15:22:48 +00:00
Chris PeBenito
f8cfddbb76
fix ticket #15 .
2006-09-29 18:00:21 +00:00
Chris PeBenito
49317e6b49
fix corenetwork so the ifdef enable_mls survives to regular processing.
2006-09-29 17:37:57 +00:00
Chris PeBenito
6c63996d9b
fix build error
2006-09-29 14:24:57 +00:00
Chris PeBenito
e2b84ef79a
patch from dan Mon, 25 Sep 2006 15:46:40 -0400
2006-09-28 14:37:29 +00:00
Chris PeBenito
693d4aedb5
patch from dan Fri, 22 Sep 2006 16:30:34 -0400
2006-09-25 18:53:06 +00:00
Chris PeBenito
8708d9bef2
patch from dan Wed, 20 Sep 2006 12:12:49 -0400
2006-09-22 17:14:35 +00:00
Chris PeBenito
a9e03b3752
* add a macro for generating category declarations
...
* fix userdom_search_all_users_home_content() to use search_dir_perms;
* change ssh daemon macro to use userdom_search_all_users_home_dirs() instead of _home_content()
2006-09-21 15:48:15 +00:00
Chris PeBenito
bf469d7669
gentoo testing fixes
2006-09-19 17:02:29 +00:00
Chris PeBenito
cf7af137c0
add mls fd constraints
2006-09-15 19:05:03 +00:00
Chris PeBenito
2b571d6880
common users list inotifyfs
2006-09-14 18:19:04 +00:00
Chris PeBenito
9dfbd81493
forgot to bump policy vers
2006-09-13 18:42:49 +00:00
Chris PeBenito
73ca55d311
patches from erich Wed, 13 Sep 2006 16:18:18 +0200
2006-09-13 18:35:10 +00:00
Chris PeBenito
2cac32a605
fix miscfiles_read_localization()
2006-09-13 18:08:17 +00:00
Chris PeBenito
0d96ff339e
misc fixes
2006-09-13 14:23:04 +00:00
Chris PeBenito
376fbc0be9
clean up usercanread
2006-09-11 18:23:09 +00:00
Chris PeBenito
b1bf2f7811
add last bit of role infrastructure
2006-09-11 15:26:25 +00:00
Chris PeBenito
95b8223eed
cleanups
2006-09-08 17:21:28 +00:00
Chris PeBenito
bbcd3c97dd
add main part of role-o-matic
2006-09-06 22:07:25 +00:00
Chris PeBenito
75beb95014
patch from dan Tue, 05 Sep 2006 17:06:06 -0400
2006-09-06 16:36:23 +00:00
Chris PeBenito
91dabf4d78
fix up usb.ids per distro
2006-09-05 14:31:27 +00:00
Chris PeBenito
13d7cec671
patch from erich Sat, 02 Sep 2006 03:37:44 +0200
2006-09-04 18:22:12 +00:00
Chris PeBenito
5dbda5558a
patch from dan Fri, 01 Sep 2006 15:45:24 -0400
2006-09-04 15:15:35 +00:00
Chris PeBenito
9b45c60308
This patch adds a polmatch avperm to arbitrate flow/state's access to
...
a xfrm policy. It also defines MLS policy for association { sendto,
recvfrom, polmatch }.
NOTE: When an inbound packet is not using an IPSec SA, a check is performed
between the socket label and the unlabeled sid (SYSTEM_HIGH MLS label). For
MLS purposes however, the target of the check should be the MLS label taken
from the node sid (or secmark in the new secmark world). This would present
a severe performance overhead (to make a new sid based on the unlabeled sid
with the MLS taken from the node sid or secmark and then using this sid as
the target). Pending reconciliation of the netlabel, ipsec and iptables contexts,
I have chosen to currently make an exception for unlabeled_t SAs if TE policy
allowed it. A similar problem exists for the outbound case and it has been similarly
handled in the policy below (by making an exception for unlabeled_t).
I am submitting the below limited patch pending a comprehensive patch from
Joy Latten at IBM (latten@austin.ibm.com ).
I am not sure if I needed to manually do a "make tolib" in the flask subdir
and submit the results as well. Please let me know if I needed to.
Signed-off-by: Venkat Yekkirala <vyekkirala@TrustedCS.com>
2006-09-01 17:06:53 +00:00
Chris PeBenito
eac818f040
patch from dan Thu, 31 Aug 2006 15:16:30 -0400
2006-09-01 15:52:05 +00:00
Chris PeBenito
a5e2133bc8
patch from dan Wed, 23 Aug 2006 14:03:49 -0400
2006-08-29 02:41:00 +00:00
Chris PeBenito
ce6bf7cc23
more testing fixes
2006-08-28 02:46:20 +00:00
Chris PeBenito
e539a49638
This patch enables to use xattr on jffs2 filesystem.
...
The jffs2 filesystem is a filesystem for memory technology
devices (MTD), and xattr supporting on jffs2 is neccesary
to use SELinux with a small diskless PDA and so on.
This facility is queued for kernel 2.6.18 now, so I hope
to merge this small patch into the refpolicy repository.
Example of xattr/jffs2: SELinux on OpenZaurus :D
http://www.kaigai.gr.jp/pub/sezaurus.jpg
Thanks,
--
KaiGai Kohei <kaigai@kaigai.gr.jp>
2006-08-25 13:28:57 +00:00
Chris PeBenito
de222824e9
fix gentoo /opt contexts
2006-08-25 13:26:21 +00:00
Chris PeBenito
98de871cee
more strict testing fixes
2006-08-23 19:36:04 +00:00
Chris PeBenito
d15dd5a739
more testing fixes
2006-08-23 03:47:39 +00:00
Chris PeBenito
5b4ff3a104
fix ordering bug
2006-08-22 19:56:59 +00:00
Chris PeBenito
3ef029db7c
add nscd_socket_use() to auth_use_nsswitch() since it caches nss lookups.
2006-08-22 19:37:56 +00:00
Chris PeBenito
2ed690dd9b
fix typo in sxid
2006-08-21 13:35:51 +00:00
Chris PeBenito
e9b9e45214
testing fixes
2006-08-18 18:20:22 +00:00
Chris PeBenito
4bc6e32e28
fix for netfilter_contexts
2006-08-18 14:01:48 +00:00
Chris PeBenito
ba1a545fb3
cleanup in authlogin
2006-08-17 15:35:14 +00:00
Chris PeBenito
3573908f1c
fix cron_system_entry() rules
2006-08-16 13:52:18 +00:00
Chris PeBenito
33c7e6b4e8
remove dead selopt rules
2006-08-15 20:00:58 +00:00
Chris PeBenito
bd56da4aa5
clean up constraints
2006-08-15 15:30:08 +00:00
Chris PeBenito
497da0953c
ps/ptrace dontaudit cleanup
2006-08-08 17:49:03 +00:00
Chris PeBenito
4846dc8ad4
patch from Stefan for mrtg daemon operation.
2006-08-07 17:14:00 +00:00
Chris PeBenito
80f928e24b
display warning if using loadkeys_domtrans() in targeted
2006-08-03 18:02:28 +00:00
Chris PeBenito
85476e94d8
fix up mtrr interfaces. missing the file class on a few interfaces, and read and write cannot be split.
2006-08-01 14:43:10 +00:00
Chris PeBenito
4b3b46d7ef
add authlogin interface to abstract common login program perms
2006-07-31 22:26:59 +00:00
Chris PeBenito
46551033aa
patch from dan Wed, 26 Jul 2006 14:42:46 -0400
2006-07-28 15:13:58 +00:00
Chris PeBenito
81aa67fcc0
more ssh agent fixes
2006-07-26 21:16:45 +00:00
Chris PeBenito
528811e040
clean up most of the remaining ssh TODO
2006-07-26 20:34:09 +00:00
Chris PeBenito
79f5f5e8fd
add gdm Xsession fc
2006-07-26 20:33:23 +00:00
Chris PeBenito
d617143ba4
remove deprecated mount_send_nfs_client_request() from stunnel
2006-07-25 22:28:47 +00:00
Chris PeBenito
ea3c1f508a
add helpers for printing warning and error messages
2006-07-25 17:27:00 +00:00
Chris PeBenito
8b9ebd3769
some cleanup in the kernel layer
2006-07-25 15:23:13 +00:00
Chris PeBenito
19ebf01d6a
patch to fix escaping of . in file contexts from james athey
2006-07-24 15:43:57 +00:00
Chris PeBenito
d822675850
add access to keys for unconfined
2006-07-14 13:11:42 +00:00
Chris PeBenito
da9bbc655a
fix up audit message perms now that audit_write denials are being audited by the kernel.
2006-07-13 17:22:08 +00:00
Chris PeBenito
133000c286
remove setbool auditallow, except for distro_rhel4.
2006-07-13 14:22:21 +00:00
Chris PeBenito
17de1b790b
remove extra level of directory
2006-07-12 20:32:27 +00:00