| Commit message (Collapse) | Author | Age | Files | Lines |
|
|
|
| |
Signed-off-by: Jason Zaman <jason@perfinion.com>
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
Put in libx32 subs entries that refer to directories with fc entries.
Allow dpkg_t to transition to dpkg_script_t when it executes bin_t for
dpkg-reconfigure.
Some dontaudit rules for mta processes spawned by mon for notification.
Lots of tiny changes that are obvious.
|
| |
|
|
|
|
|
|
| |
Remove file context aliases and update file context paths to use the /run filesystem path.
Add backward compatibility file context alias for /var/run using applications like https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=783321
Lock files are still seated at /var/lock
|
| |
|
| |
|
| |
|
|
|
|
|
|
|
|
|
| |
selinux_lxc_contexts_path() function in upstream libselinux points to
this config file. It is ATM used by libvirt.
The file from Fedora also contains sandbox_lxc_process and
sandbox_kvm_process parameters, but I cannot find where they are used,
keep them out of the file for the time being.
|
|
|
|
|
| |
On Debian, systemd binaries are installed in / not /usr, add an
equivalence for this.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
When cron_userdomain_transition boolean is set to on, the user cronjobs
are supposed to run in their domains. Without this patch the default
context is not properly computed:
$ /usr/sbin/getdefaultcon user_u system_u:system_r:crond_t:s0
/usr/sbin/getdefaultcon: Invalid argument
$ /usr/sbin/getdefaultcon staff_u system_u:system_r:crond_t:s0
staff_u:sysadm_r:sysadm_t:s0
With this patch applied:
$ /usr/sbin/getdefaultcon user_u system_u:system_r:crond_t:s0
user_u:user_r:user_t:s0
$ /usr/sbin/getdefaultcon staff_ system_u:system_r:crond_t:s0
staff_u:staff_r:staff_t:s0
|
| |
|
|
|
|
|
|
| |
In Gentoo, the kerberos location is /var/lib/krb5kdc instead of
/var/kerberos/krb5kdc. As there are multiple file contexts underneith, add in a
substitution entry for /var/lib/krb5kdc -> /var/kerberos/krb5kdc.
|
| |
|
| |
|
|
|
|
|
|
| |
Since the content of /etc/init.d and /etc/rc.d/init.d is the same (and same
labels), it makes sense to just define them once and put in a translation for
this location.
|
|
|
|
|
|
| |
The translation of /usr/local to /usr is not supported upstream and might lead
to issues later, so undo those changes. Keep the /usr/local/lib* stuff in
though.
|
| |
|
|
|
|
|
|
|
| |
The various modules currently contain references to /usr/lib(64)? or have duplicate entries (one for /usr/lib, another for
/usr/lib64). Same for /lib(64)?. Because we now support subs_dist, this differentiation is no longer needed.
Fixes bug #410951
|
|
|