GitWeb
Get Gentoo!
gentoo.org sites
gentoo.org
Wiki
Bugs
Forums
Packages
Planet
Archives
Sources
Infra Status
Home
Gentoo Repository
Repositories
Projects
Developer Overlays
User Overlays
Data
Websites
index
:
proj/hardened-refpolicy.git
concord-dev
mailinfra
master
secmodel
Gentoo Hardened SELinux reference policy implementation
Sven Vermeulen <swift@gentoo.org>
about
summary
refs
log
tree
commit
diff
log msg
author
committer
range
path:
root
/
policy
/
modules
/
system
Commit message (
Expand
)
Author
Age
Files
Lines
*
systemd: allow systemd-hostnamed to read vsock device
Yi Zhao
2024-09-21
1
-0
/
+1
*
systemd: fix policy for systemd-ssh-generator
Yi Zhao
2024-09-21
1
-0
/
+9
*
systemd: add policy for systemd-nsresourced
Yi Zhao
2024-09-21
3
-0
/
+61
*
systemd: allow system --user to create netlink_route_socket
Yi Zhao
2024-09-21
1
-0
/
+2
*
systemd: allow systemd-networkd to manage sock files under /run/systemd/netif
Yi Zhao
2024-09-21
1
-0
/
+1
*
systemd: set context to systemd_networkd_var_lib_t for /var/lib/systemd/network
Yi Zhao
2024-09-21
2
-0
/
+8
*
Allow interactive user terminal output for the NetLabel management tool.
Guido Trentalancia
2024-09-21
1
-0
/
+2
*
various: rules required for DV manipulation in kubevirt
Kenton Groombridge
2024-09-21
2
-0
/
+6
*
iptables: allow reading container engine tmp files
Kenton Groombridge
2024-09-21
1
-2
/
+3
*
iptables: allow reading usr files
Kenton Groombridge
2024-09-21
1
-0
/
+1
*
systemd: make xdg optional
Yi Zhao
2024-09-21
1
-2
/
+8
*
systemd: allow logind to use locallogin pidfds
Kenton Groombridge
2024-09-21
1
-0
/
+4
*
userdomain: allow administrative user to get attributes of shadow history file
Yi Zhao
2024-09-21
2
-0
/
+20
*
init: use pidfds from local login
Kenton Groombridge
2024-09-21
2
-0
/
+22
*
dbus, init: add interface for pidfd usage
Kenton Groombridge
2024-09-21
1
-1
/
+1
*
sysnetwork: allow ifconfig to read usr files
Kenton Groombridge
2024-09-21
1
-0
/
+1
*
systemd: allow systemd-logind to use sshd pidfds
Kenton Groombridge
2024-09-21
1
-0
/
+6
*
Reorder perms and classes
freedom1b2830
2024-09-21
26
-132
/
+132
*
selinuxutil: make policykit optional
Yi Zhao
2024-09-21
1
-2
/
+4
*
newrole: allow newrole to search faillock runtime directory
Yi Zhao
2024-09-21
2
-0
/
+19
*
sysnetwork: fixes for dhcpcd
Yi Zhao
2024-09-21
1
-0
/
+5
*
init: Add homectl dbus access.
Chris PeBenito
2024-09-21
2
-0
/
+25
*
filesystem/systemd: memory.pressure fixes.
Chris PeBenito
2024-09-21
1
-0
/
+2
*
systemd: Add basic systemd-analyze rules.
Chris PeBenito
2024-09-21
1
-0
/
+23
*
various: various fixes
Kenton Groombridge
2024-05-14
4
-1
/
+7
*
container, podman: various fixes
Kenton Groombridge
2024-05-14
1
-0
/
+20
*
systemd: allow systemd-sysctl to search tmpfs
Kenton Groombridge
2024-05-14
1
-0
/
+1
*
userdom: allow users to read user home dir symlinks
Kenton Groombridge
2024-05-14
1
-0
/
+3
*
init: allow systemd to use sshd pidfds
Kenton Groombridge
2024-05-14
1
-0
/
+4
*
files context for merged-usr profile on gentoo
Grzegorz Filo
2024-05-14
3
-0
/
+11
*
xen: Drop xend/xm stack.
Chris PeBenito
2024-05-14
6
-396
/
+50
*
Allow systemd to pass down sig mask
Matt Sheets
2024-05-14
1
-0
/
+1
*
cups: Remove PTAL.
Chris PeBenito
2024-05-14
1
-1
/
+0
*
xen: Revoke kernel module loading permissions.
Chris PeBenito
2024-05-14
1
-1
/
+0
*
Set the type on /etc/machine-info to net_conf_t so hostnamectl can manipulate...
Rick Alther
2024-05-14
1
-0
/
+1
*
systemd: allow notify client to stat socket
Christian Göttsche
2024-05-14
1
-1
/
+1
*
getty: grant checkpoint_restore
Christian Göttsche
2024-05-14
1
-0
/
+1
*
Setup domain for dbus selinux interface
Dave Sugar
2024-05-14
3
-0
/
+47
*
libraries: drop space in empty line
Christian Göttsche
2024-03-01
1
-1
/
+1
*
systemd: logind update
Christian Göttsche
2024-03-01
1
-0
/
+3
*
udev: update
Christian Göttsche
2024-03-01
2
-0
/
+33
*
systemd: generator updates
Christian Göttsche
2024-03-01
2
-1
/
+22
*
systemd: binfmt updates
Christian Göttsche
2024-03-01
1
-0
/
+6
*
userdom: permit reading PSI as admin
Christian Göttsche
2024-03-01
1
-0
/
+1
*
selinuxutil: ignore getattr proc in newrole
Christian Göttsche
2024-03-01
1
-0
/
+1
*
selinuxutil: setfiles updates
Christian Göttsche
2024-03-01
1
-0
/
+3
*
cloudinit: Add permissions derived from sysadm.
Chris PeBenito
2024-03-01
8
-3
/
+73
*
systemd: Updates for systemd-locale.
Chris PeBenito
2024-03-01
1
-0
/
+5
*
cloud-init: Add systemd permissions.
Chris PeBenito
2024-03-01
1
-0
/
+19
*
sysnetwork: ifconfig searches debugfs.
Chris PeBenito
2024-03-01
1
-0
/
+1
[next]