GitWeb
Get Gentoo!
gentoo.org sites
gentoo.org
Wiki
Bugs
Forums
Packages
Planet
Archives
Sources
Infra Status
Home
Gentoo Repository
Repositories
Projects
Developer Overlays
User Overlays
Data
Websites
index
:
proj/hardened-refpolicy.git
concord-dev
mailinfra
master
secmodel
Gentoo Hardened SELinux reference policy implementation
Sven Vermeulen <swift@gentoo.org>
about
summary
refs
log
tree
commit
diff
log msg
author
committer
range
path:
root
/
policy
/
modules
Commit message (
Expand
)
Author
Age
Files
Lines
*
cron: Use raw entrypoint rule for system_cronjob_t.
Chris PeBenito
2024-05-14
1
-1
/
+1
*
uml: Remove excessive access from user domains on uml_exec_t.
Chris PeBenito
2024-05-14
1
-2
/
+2
*
Set the type on /etc/machine-info to net_conf_t so hostnamectl can manipulate...
Rick Alther
2024-05-14
1
-0
/
+1
*
systemd: allow notify client to stat socket
Christian Göttsche
2024-05-14
1
-1
/
+1
*
quote: read localization
Christian Göttsche
2024-05-14
1
-0
/
+2
*
getty: grant checkpoint_restore
Christian Göttsche
2024-05-14
1
-0
/
+1
*
Update SOS report to work on RHEL9
Dave Sugar
2024-05-14
2
-5
/
+43
*
Setup domain for dbus selinux interface
Dave Sugar
2024-05-14
3
-0
/
+47
*
libraries: drop space in empty line
Christian Göttsche
2024-03-01
1
-1
/
+1
*
consolesetup: update
Christian Göttsche
2024-03-01
1
-0
/
+2
*
systemd: logind update
Christian Göttsche
2024-03-01
1
-0
/
+3
*
udev: update
Christian Göttsche
2024-03-01
2
-0
/
+33
*
systemd: generator updates
Christian Göttsche
2024-03-01
2
-1
/
+22
*
fs: add support for virtiofs
Christian Göttsche
2024-03-01
1
-0
/
+11
*
vnstatd: update
Christian Göttsche
2024-03-01
1
-0
/
+1
*
systemd: binfmt updates
Christian Göttsche
2024-03-01
2
-0
/
+43
*
fs: mark memory pressure type as file
Christian Göttsche
2024-03-01
1
-0
/
+1
*
userdom: permit reading PSI as admin
Christian Göttsche
2024-03-01
1
-0
/
+1
*
selinuxutil: ignore getattr proc in newrole
Christian Göttsche
2024-03-01
1
-0
/
+1
*
selinuxutil: setfiles updates
Christian Göttsche
2024-03-01
2
-0
/
+21
*
virt: label qemu configuration directory
Christian Göttsche
2024-03-01
1
-0
/
+2
*
cloudinit: Add permissions derived from sysadm.
Chris PeBenito
2024-03-01
14
-26
/
+1215
*
systemd: Updates for systemd-locale.
Chris PeBenito
2024-03-01
1
-0
/
+5
*
cloud-init: Change udev rules
Chris PeBenito
2024-03-01
1
-0
/
+1
*
cloud-init: Add systemd permissions.
Chris PeBenito
2024-03-01
2
-4
/
+27
*
cloud-init: Allow use of sudo in runcmd.
Chris PeBenito
2024-03-01
2
-0
/
+33
*
chronyd: Read /dev/urandom.
Chris PeBenito
2024-03-01
1
-0
/
+1
*
unconfined: Add remaining watch_* permissions.
Chris PeBenito
2024-03-01
4
-29
/
+29
*
usermanage: Handle symlinks in /usr/share/cracklib.
Chris PeBenito
2024-03-01
2
-0
/
+2
*
kdump: Fixes from testing kdumpctl.
Chris PeBenito
2024-03-01
1
-0
/
+15
*
cloudinit: Add support for installing RPMs and setting passwords.
Chris PeBenito
2024-03-01
3
-0
/
+35
*
files: Handle symlinks for /media and /srv.
Chris PeBenito
2024-03-01
1
-1
/
+2
*
usermanage: Add sysctl access for groupadd to get number of groups.
Chris PeBenito
2024-03-01
1
-0
/
+4
*
sysnetwork: ifconfig searches debugfs.
Chris PeBenito
2024-03-01
1
-0
/
+1
*
selinuxutil: Semanage reads policy for export.
Chris PeBenito
2024-03-01
1
-0
/
+1
*
init: Allow nnp/nosuid transitions from systemd initrc_t.
Chris PeBenito
2024-03-01
1
-0
/
+2
*
rpm: Minor fixes
Chris PeBenito
2024-03-01
1
-1
/
+3
*
systemd: Minor coredump fixes.
Chris PeBenito
2024-03-01
2
-7
/
+24
*
Container: Minor fixes from interactive container use.
Chris PeBenito
2024-03-01
3
-1
/
+29
*
kernel: hv_utils shutdown on systemd systems.
Chris PeBenito
2024-03-01
1
-0
/
+5
*
systemd: systemd-cgroups reads kernel.cap_last_cap sysctl.
Chris PeBenito
2024-03-01
1
-0
/
+3
*
domain: Manage own fds.
Chris PeBenito
2024-03-01
1
-3
/
+4
*
kubernetes: allow kubelet to apply fsGroup to persistent volumes
Kenton Groombridge
2024-03-01
2
-0
/
+23
*
container: allow spc to map kubernetes runtime files
Kenton Groombridge
2024-03-01
2
-0
/
+19
*
crio: allow reading container home content
Kenton Groombridge
2024-03-01
2
-2
/
+22
*
systemd: allow systemd generator to list exports
Kenton Groombridge
2024-03-01
1
-0
/
+1
*
dbus: allow the system bus to get the status of generic units
Kenton Groombridge
2024-03-01
1
-0
/
+3
*
rpc: fix not labeling exports.d directory
Kenton Groombridge
2024-03-01
1
-1
/
+1
*
bootloader, init, udev: misc minor fixes
Kenton Groombridge
2024-03-01
3
-2
/
+4
*
systemd: label systemd-tpm2-setup as systemd-pcrphase
Kenton Groombridge
2024-03-01
1
-0
/
+1
[next]