summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* github: Only test hardened-refpolicy on distro gentoo2.20240916-r1Jason Zaman2024-09-212-2/+2
* Merge upstreamJason Zaman2024-09-211-1/+1
* Update Changelog and VERSION for release 2.20240916.Chris PeBenito2024-09-212-1/+137
* Update mysql.fcnisbet-hubbard2024-09-211-0/+1
* Additional permissions when fapolicyd.conf more strictDave Sugar2024-09-213-1/+64
* systemd: allow systemd-hostnamed to read vsock deviceYi Zhao2024-09-211-0/+1
* systemd: fix policy for systemd-ssh-generatorYi Zhao2024-09-211-0/+9
* devices: add label vsock_device_t for /dev/vsockYi Zhao2024-09-213-0/+61
* systemd: add policy for systemd-nsresourcedYi Zhao2024-09-217-0/+79
* systemd: allow system --user to create netlink_route_socketYi Zhao2024-09-211-0/+2
* systemd: allow systemd-networkd to manage sock files under /run/systemd/netifYi Zhao2024-09-211-0/+1
* systemd: set context to systemd_networkd_var_lib_t for /var/lib/systemd/networkYi Zhao2024-09-212-0/+8
* Allow interactive user terminal output for the NetLabel management tool.Guido Trentalancia2024-09-211-0/+2
* bluetooth: Move line.Chris PeBenito2024-09-211-3/+2
* Adding SE Policy rules to allow usage of unix stream sockets by dbus and blue...Naga Bhavani Akella2024-09-213-0/+26
* kubernetes: allow kubelet to connect all TCP portsKenton Groombridge2024-09-211-3/+1
* container: allow reading generic certsKenton Groombridge2024-09-211-0/+1
* testing: add container_kvm_t to net admin exempt listKenton Groombridge2024-09-211-0/+1
* Makefile: drop duplicate quotesChristian Göttsche2024-09-211-2/+2
* various: rules required for DV manipulation in kubevirtKenton Groombridge2024-09-217-0/+48
* container: add container_kvm_t and supporting kubevirt rulesKenton Groombridge2024-09-211-1/+33
* iptables: allow reading container engine tmp filesKenton Groombridge2024-09-212-2/+23
* container: allow spc various rules for kubevirtKenton Groombridge2024-09-212-2/+29
* container, kubernetes: add supporting rules for kubevirt and multusKenton Groombridge2024-09-213-0/+50
* dbus: dontaudit session bus domains the netadmin capabilityKenton Groombridge2024-09-211-1/+1
* container: allow super privileged containers to manage BPF dirsKenton Groombridge2024-09-212-1/+19
* kubernetes: allow kubelet to create unlabeled dirsKenton Groombridge2024-09-212-0/+21
* haproxy: allow interactive usageKenton Groombridge2024-09-211-0/+4
* podman: allow managing init runtime unitsKenton Groombridge2024-09-211-0/+6
* iptables: allow reading usr filesKenton Groombridge2024-09-211-0/+1
* filesystem, devices: move gadgetfs to usbfs_tDmitry Sharshakov2024-09-212-1/+1
* systemd: make xdg optionalYi Zhao2024-09-211-2/+8
* sshd: label sshd-session as sshd_exec_tKenton Groombridge2024-09-211-0/+1
* Setting bluetooth helper domain for bluetoothctlNaga Bhavani Akella2024-09-212-0/+6
* Adding Sepolicy rules to allow pulseaudio to access bluetooth sockets.Raghavender Reddy Bujala2024-09-211-0/+2
* systemd: allow logind to use locallogin pidfdsKenton Groombridge2024-09-211-0/+4
* userdomain: allow administrative user to get attributes of shadow history fileYi Zhao2024-09-212-0/+20
* node_exporter: allow reading RPC sysctlsKenton Groombridge2024-09-211-0/+1
* asterisk: allow reading certbot libKenton Groombridge2024-09-211-0/+4
* postfix: allow postfix pipe to watch mail spoolKenton Groombridge2024-09-211-0/+1
* netutils: allow ping to read net sysctlsKenton Groombridge2024-09-211-0/+1
* node_exporter: allow reading localizationKenton Groombridge2024-09-211-0/+2
* container: allow containers to execute tmpfs filesKenton Groombridge2024-09-211-0/+1
* sysadm: make haproxy adminKenton Groombridge2024-09-211-0/+4
* haproxy: initial policyKenton Groombridge2024-09-213-0/+222
* init: use pidfds from local loginKenton Groombridge2024-09-212-0/+22
* dbus, init: add interface for pidfd usageKenton Groombridge2024-09-212-1/+20
* asterisk: allow watching spool dirsKenton Groombridge2024-09-211-0/+1
* su, sudo: allow sudo to signal all su domainsKenton Groombridge2024-09-213-2/+27
* sudo: allow systemd-logind to read cgroup state of sudoKenton Groombridge2024-09-211-0/+2