GitWeb
Get Gentoo!
gentoo.org sites
gentoo.org
Wiki
Bugs
Forums
Packages
Planet
Archives
Sources
Infra Status
Home
Gentoo Repository
Repositories
Projects
Developer Overlays
User Overlays
Data
Websites
index
:
proj/hardened-refpolicy.git
concord-dev
mailinfra
master
secmodel
Gentoo Hardened SELinux reference policy implementation
Sven Vermeulen <swift@gentoo.org>
about
summary
refs
log
tree
commit
diff
log msg
author
committer
range
path:
root
/
policy
/
modules
/
services
Commit message (
Expand
)
Author
Age
Files
Lines
*
Update mysql.fc
nisbet-hubbard
2024-09-21
1
-0
/
+1
*
systemd: add policy for systemd-nsresourced
Yi Zhao
2024-09-21
4
-0
/
+18
*
bluetooth: Move line.
Chris PeBenito
2024-09-21
1
-3
/
+2
*
Adding SE Policy rules to allow usage of unix stream sockets by dbus and blue...
Naga Bhavani Akella
2024-09-21
3
-0
/
+26
*
kubernetes: allow kubelet to connect all TCP ports
Kenton Groombridge
2024-09-21
1
-3
/
+1
*
container: allow reading generic certs
Kenton Groombridge
2024-09-21
1
-0
/
+1
*
various: rules required for DV manipulation in kubevirt
Kenton Groombridge
2024-09-21
3
-0
/
+23
*
container: add container_kvm_t and supporting kubevirt rules
Kenton Groombridge
2024-09-21
1
-1
/
+33
*
iptables: allow reading container engine tmp files
Kenton Groombridge
2024-09-21
1
-0
/
+20
*
container: allow spc various rules for kubevirt
Kenton Groombridge
2024-09-21
1
-2
/
+11
*
container, kubernetes: add supporting rules for kubevirt and multus
Kenton Groombridge
2024-09-21
3
-0
/
+50
*
dbus: dontaudit session bus domains the netadmin capability
Kenton Groombridge
2024-09-21
1
-1
/
+1
*
container: allow super privileged containers to manage BPF dirs
Kenton Groombridge
2024-09-21
1
-1
/
+1
*
kubernetes: allow kubelet to create unlabeled dirs
Kenton Groombridge
2024-09-21
1
-0
/
+3
*
haproxy: allow interactive usage
Kenton Groombridge
2024-09-21
1
-0
/
+4
*
podman: allow managing init runtime units
Kenton Groombridge
2024-09-21
1
-0
/
+6
*
sshd: label sshd-session as sshd_exec_t
Kenton Groombridge
2024-09-21
1
-0
/
+1
*
Setting bluetooth helper domain for bluetoothctl
Naga Bhavani Akella
2024-09-21
2
-0
/
+6
*
node_exporter: allow reading RPC sysctls
Kenton Groombridge
2024-09-21
1
-0
/
+1
*
asterisk: allow reading certbot lib
Kenton Groombridge
2024-09-21
1
-0
/
+4
*
postfix: allow postfix pipe to watch mail spool
Kenton Groombridge
2024-09-21
1
-0
/
+1
*
node_exporter: allow reading localization
Kenton Groombridge
2024-09-21
1
-0
/
+2
*
container: allow containers to execute tmpfs files
Kenton Groombridge
2024-09-21
1
-0
/
+1
*
haproxy: initial policy
Kenton Groombridge
2024-09-21
3
-0
/
+222
*
dbus, init: add interface for pidfd usage
Kenton Groombridge
2024-09-21
1
-0
/
+19
*
asterisk: allow watching spool dirs
Kenton Groombridge
2024-09-21
1
-0
/
+1
*
postfix: allow smtpd to mmap SASL keytab files
Kenton Groombridge
2024-09-21
2
-1
/
+20
*
Reorder perms and classes
freedom1b2830
2024-09-21
117
-396
/
+396
*
Sepolicy changes for bluez to access uhid
Amisha Jain
2024-09-21
1
-0
/
+1
*
Adding Sepolicy rules to allow bluetoothctl and dbus-daemon to access unix st...
Naga Bhavani Akella
2024-09-21
3
-2
/
+26
*
various: various fixes
Kenton Groombridge
2024-05-14
1
-0
/
+2
*
container, crio, kubernetes: minor fixes
Kenton Groombridge
2024-05-14
3
-0
/
+5
*
container, podman: various fixes
Kenton Groombridge
2024-05-14
2
-2
/
+50
*
container: allow containers to getcap
Kenton Groombridge
2024-05-14
1
-1
/
+1
*
container: allow system container engines to mmap runtime files
Kenton Groombridge
2024-05-14
1
-1
/
+1
*
matrixd: add tunable for binding to all unreserved ports
Kenton Groombridge
2024-05-14
1
-1
/
+15
*
asterisk: allow binding to all unreserved UDP ports
Kenton Groombridge
2024-05-14
1
-0
/
+1
*
postgres: add a standalone execmem tunable
Kenton Groombridge
2024-05-14
1
-1
/
+8
*
dovecot: allow dovecot-auth to read SASL keytab
Kenton Groombridge
2024-05-14
1
-0
/
+4
*
fail2ban: allow reading net sysctls
Kenton Groombridge
2024-05-14
1
-0
/
+1
*
init: allow systemd to use sshd pidfds
Kenton Groombridge
2024-05-14
1
-0
/
+19
*
files context for merged-usr profile on gentoo
Grzegorz Filo
2024-05-14
1
-0
/
+4
*
Need map perm for cockpit 300.4
Dave Sugar
2024-05-14
1
-1
/
+1
*
cockpit: Change $1_cockpit_tmpfs_t to a tmpfs file type.
Chris PeBenito
2024-05-14
1
-1
/
+1
*
certbot: Drop execmem.
Chris PeBenito
2024-05-14
1
-4
/
+0
*
xen: Drop xend/xm stack.
Chris PeBenito
2024-05-14
5
-8
/
+4
*
cups: Remove PTAL.
Chris PeBenito
2024-05-14
3
-108
/
+7
*
minissdpd: Revoke kernel module loading permissions.
Chris PeBenito
2024-05-14
1
-2
/
+1
*
docker: Fix dockerc typo in container_engine_executable_file
Chris PeBenito
2024-05-14
1
-1
/
+1
*
cron: Use raw entrypoint rule for system_cronjob_t.
Chris PeBenito
2024-05-14
1
-1
/
+1
[next]