GitWeb
Get Gentoo!
gentoo.org sites
gentoo.org
Wiki
Bugs
Forums
Packages
Planet
Archives
Sources
Infra Status
Home
Gentoo Repository
Repositories
Projects
Developer Overlays
User Overlays
Data
Websites
index
:
proj/hardened-refpolicy.git
concord-dev
mailinfra
master
secmodel
Gentoo Hardened SELinux reference policy implementation
Sven Vermeulen <swift@gentoo.org>
about
summary
refs
log
tree
commit
diff
log msg
author
committer
range
Commit message (
Expand
)
Author
Age
Files
Lines
...
*
selinuxutil: setfiles updates
Christian Göttsche
2024-03-01
2
-0
/
+21
*
virt: label qemu configuration directory
Christian Göttsche
2024-03-01
1
-0
/
+2
*
Makefile: set PYTHONPATH for test toolchain
Christian Göttsche
2024-03-01
1
-3
/
+10
*
Makefile: use sepolgen-ifgen-attr-helper from test toolchain
Christian Göttsche
2024-03-01
1
-0
/
+4
*
Rules.modular: use temporary file to not ignore error
Christian Göttsche
2024-03-01
1
-2
/
+2
*
Rules.monolithic: pre-compile fcontexts on install
Christian Göttsche
2024-03-01
2
-0
/
+7
*
policy_capabilities: remove estimated from released versions
Christian Göttsche
2024-03-01
1
-1
/
+1
*
Support multi-line interface calls
Christian Göttsche
2024-03-01
1
-4
/
+9
*
fix misc typos
Christian Göttsche
2024-03-01
3
-4
/
+4
*
support/genhomedircon: support usr prefixed paths
Christian Göttsche
2024-03-01
1
-1
/
+1
*
access_vectors: define io_uring { cmd }
Christian Göttsche
2024-03-01
1
-0
/
+1
*
cloudinit: Add permissions derived from sysadm.
Chris PeBenito
2024-03-01
15
-26
/
+1216
*
systemd: Updates for systemd-locale.
Chris PeBenito
2024-03-01
1
-0
/
+5
*
cloud-init: Change udev rules
Chris PeBenito
2024-03-01
1
-0
/
+1
*
cloud-init: Add systemd permissions.
Chris PeBenito
2024-03-01
2
-4
/
+27
*
cloud-init: Allow use of sudo in runcmd.
Chris PeBenito
2024-03-01
2
-0
/
+33
*
chronyd: Read /dev/urandom.
Chris PeBenito
2024-03-01
1
-0
/
+1
*
unconfined: Add remaining watch_* permissions.
Chris PeBenito
2024-03-01
4
-29
/
+29
*
usermanage: Handle symlinks in /usr/share/cracklib.
Chris PeBenito
2024-03-01
2
-0
/
+2
*
kdump: Fixes from testing kdumpctl.
Chris PeBenito
2024-03-01
1
-0
/
+15
*
cloudinit: Add support for installing RPMs and setting passwords.
Chris PeBenito
2024-03-01
3
-0
/
+35
*
files: Handle symlinks for /media and /srv.
Chris PeBenito
2024-03-01
1
-1
/
+2
*
usermanage: Add sysctl access for groupadd to get number of groups.
Chris PeBenito
2024-03-01
1
-0
/
+4
*
sysnetwork: ifconfig searches debugfs.
Chris PeBenito
2024-03-01
1
-0
/
+1
*
selinuxutil: Semanage reads policy for export.
Chris PeBenito
2024-03-01
1
-0
/
+1
*
init: Allow nnp/nosuid transitions from systemd initrc_t.
Chris PeBenito
2024-03-01
1
-0
/
+2
*
rpm: Minor fixes
Chris PeBenito
2024-03-01
1
-1
/
+3
*
systemd: Minor coredump fixes.
Chris PeBenito
2024-03-01
2
-7
/
+24
*
Container: Minor fixes from interactive container use.
Chris PeBenito
2024-03-01
3
-1
/
+29
*
kernel: hv_utils shutdown on systemd systems.
Chris PeBenito
2024-03-01
1
-0
/
+5
*
systemd: systemd-cgroups reads kernel.cap_last_cap sysctl.
Chris PeBenito
2024-03-01
1
-0
/
+3
*
domain: Manage own fds.
Chris PeBenito
2024-03-01
1
-3
/
+4
*
kubernetes: allow kubelet to apply fsGroup to persistent volumes
Kenton Groombridge
2024-03-01
2
-0
/
+23
*
container: allow spc to map kubernetes runtime files
Kenton Groombridge
2024-03-01
2
-0
/
+19
*
crio: allow reading container home content
Kenton Groombridge
2024-03-01
2
-2
/
+22
*
systemd: allow systemd generator to list exports
Kenton Groombridge
2024-03-01
1
-0
/
+1
*
dbus: allow the system bus to get the status of generic units
Kenton Groombridge
2024-03-01
1
-0
/
+3
*
rpc: fix not labeling exports.d directory
Kenton Groombridge
2024-03-01
1
-1
/
+1
*
bootloader, init, udev: misc minor fixes
Kenton Groombridge
2024-03-01
3
-2
/
+4
*
systemd: label systemd-tpm2-setup as systemd-pcrphase
Kenton Groombridge
2024-03-01
1
-0
/
+1
*
init: allow using system bus anon pidfs
Kenton Groombridge
2024-03-01
1
-0
/
+1
*
kernel: allow managing mouse devices
Kenton Groombridge
2024-03-01
2
-0
/
+21
*
zfs: allow zfs to write to exports
Kenton Groombridge
2024-03-01
2
-0
/
+21
*
systemd: label systemd-pcrlock as systemd-pcrphase
Kenton Groombridge
2024-03-01
1
-0
/
+1
*
kubernetes: fix kubelet accounting
Kenton Groombridge
2024-03-01
2
-0
/
+65
*
container, kubernetes: allow kubernetes to use fuse-overlayfs
Kenton Groombridge
2024-03-01
4
-0
/
+49
*
systemd: add policy for systemd-machine-id-setup
Kenton Groombridge
2024-03-01
2
-0
/
+29
*
init, systemd: allow systemd-pcrphase to write TPM measurements
Kenton Groombridge
2024-03-01
2
-0
/
+106
*
container: add filecons for rook-ceph
Kenton Groombridge
2024-03-01
1
-0
/
+3
*
kernel: dontaudit read fixed disk devices
Kenton Groombridge
2024-03-01
1
-0
/
+4
[prev]
[next]