aboutsummaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* remove unnecessary codeHEAD2.20240226-r2masterGrzegorz Filo2024-05-142-6/+0
* Merge upstreamKenton Groombridge2024-05-141-1/+1
* various: various fixesKenton Groombridge2024-05-146-1/+28
* container, crio, kubernetes: minor fixesKenton Groombridge2024-05-143-0/+5
* container, podman: various fixesKenton Groombridge2024-05-143-2/+70
* systemd: allow systemd-sysctl to search tmpfsKenton Groombridge2024-05-141-0/+1
* container: allow containers to getcapKenton Groombridge2024-05-141-1/+1
* container: allow system container engines to mmap runtime filesKenton Groombridge2024-05-141-1/+1
* matrixd: add tunable for binding to all unreserved portsKenton Groombridge2024-05-141-1/+15
* bootloader: allow systemd-boot to manage EFI binariesKenton Groombridge2024-05-142-0/+23
* asterisk: allow binding to all unreserved UDP portsKenton Groombridge2024-05-141-0/+1
* postgres: add a standalone execmem tunableKenton Groombridge2024-05-141-1/+8
* userdom: allow users to read user home dir symlinksKenton Groombridge2024-05-141-0/+3
* dovecot: allow dovecot-auth to read SASL keytabKenton Groombridge2024-05-141-0/+4
* fail2ban: allow reading net sysctlsKenton Groombridge2024-05-141-0/+1
* init: allow systemd to use sshd pidfdsKenton Groombridge2024-05-142-0/+23
* files context for merged-usr profile on gentooGrzegorz Filo2024-05-146-0/+24
* Need map perm for cockpit 300.4Dave Sugar2024-05-141-1/+1
* tests.yml: Add sechecker testing.Chris PeBenito2024-05-143-12/+480
* cockpit: Change $1_cockpit_tmpfs_t to a tmpfs file type.Chris PeBenito2024-05-141-1/+1
* certbot: Drop execmem.Chris PeBenito2024-05-141-4/+0
* xen: Drop xend/xm stack.Chris PeBenito2024-05-1414-408/+54
* Allow systemd to pass down sig maskMatt Sheets2024-05-141-0/+1
* cups: Remove PTAL.Chris PeBenito2024-05-144-109/+7
* xen: Revoke kernel module loading permissions.Chris PeBenito2024-05-141-1/+0
* minissdpd: Revoke kernel module loading permissions.Chris PeBenito2024-05-141-2/+1
* docker: Fix dockerc typo in container_engine_executable_fileChris PeBenito2024-05-141-1/+1
* cron: Use raw entrypoint rule for system_cronjob_t.Chris PeBenito2024-05-141-1/+1
* uml: Remove excessive access from user domains on uml_exec_t.Chris PeBenito2024-05-141-2/+2
* Set the type on /etc/machine-info to net_conf_t so hostnamectl can manipulate...Rick Alther2024-05-141-0/+1
* fix: minor correction in MCS_CATS range commentRick Alther2024-05-141-1/+1
* systemd: allow notify client to stat socketChristian Göttsche2024-05-141-1/+1
* quote: read localizationChristian Göttsche2024-05-141-0/+2
* getty: grant checkpoint_restoreChristian Göttsche2024-05-141-0/+1
* Update SOS report to work on RHEL9Dave Sugar2024-05-142-5/+43
* Setup domain for dbus selinux interfaceDave Sugar2024-05-143-0/+47
* Update generated policy and doc files2.20240226-r1Kenton Groombridge2024-03-013-1780/+2745
* Merge upstreamKenton Groombridge2024-03-011-1/+1
* Update Changelog and VERSION for release 2.20240226.Chris PeBenito2024-03-012-1/+488
* libraries: drop space in empty lineChristian Göttsche2024-03-011-1/+1
* consolesetup: updateChristian Göttsche2024-03-011-0/+2
* systemd: logind updateChristian Göttsche2024-03-011-0/+3
* udev: updateChristian Göttsche2024-03-012-0/+33
* systemd: generator updatesChristian Göttsche2024-03-012-1/+22
* fs: add support for virtiofsChristian Göttsche2024-03-011-0/+11
* vnstatd: updateChristian Göttsche2024-03-011-0/+1
* systemd: binfmt updatesChristian Göttsche2024-03-012-0/+43
* fs: mark memory pressure type as fileChristian Göttsche2024-03-011-0/+1
* userdom: permit reading PSI as adminChristian Göttsche2024-03-011-0/+1
* selinuxutil: ignore getattr proc in newroleChristian Göttsche2024-03-011-0/+1