aboutsummaryrefslogtreecommitdiff
path: root/policy
Commit message (Expand)AuthorAgeFilesLines
...
* systemd: label systemd-pcrlock as systemd-pcrphaseKenton Groombridge2024-03-011-0/+1
* kubernetes: fix kubelet accountingKenton Groombridge2024-03-012-0/+65
* container, kubernetes: allow kubernetes to use fuse-overlayfsKenton Groombridge2024-03-014-0/+49
* systemd: add policy for systemd-machine-id-setupKenton Groombridge2024-03-012-0/+29
* init, systemd: allow systemd-pcrphase to write TPM measurementsKenton Groombridge2024-03-012-0/+106
* container: add filecons for rook-cephKenton Groombridge2024-03-011-0/+3
* kernel: dontaudit read fixed disk devicesKenton Groombridge2024-03-011-0/+4
* container, kubernetes: add support for rook-cephKenton Groombridge2024-03-018-3/+237
* fstools: allow reading container device blk filesKenton Groombridge2024-03-012-0/+22
* fstools: allow fsadm to ioctl cgroup dirsKenton Groombridge2024-03-011-0/+2
* mount: make mount_runtime_t a kubernetes mountpointKenton Groombridge2024-03-011-0/+4
* udev: fix for systemd-udevdYi Zhao2024-03-011-1/+1
* systemd: allow systemd-rfkill to getopt from uevent socketsYi Zhao2024-03-011-1/+1
* systemd: allow systemd-hostnamed to read machine-id and localization filesYi Zhao2024-03-011-0/+3
* Resolve error when cockpit initiate shutdownDave Sugar2024-03-013-1/+5
* Fix password changing from cockpit login screenDave Sugar2024-03-011-0/+1
* Denial during cockpit useDave Sugar2024-03-011-0/+2
* Additional access for systemctlDave Sugar2024-03-011-0/+2
* Add watchesDave Sugar2024-03-013-0/+61
* Add dontaudit to quiet down a bitDave Sugar2024-03-014-0/+101
* Allow key manipulationDave Sugar2024-03-011-0/+4
* admin can read/write web socketDave Sugar2024-03-011-0/+39
* This works instead of allow exec on user_tmpfs_t!Dave Sugar2024-03-012-0/+46
* This seems important for administrative accessDave Sugar2024-03-011-0/+1
* Signal during logoutDave Sugar2024-03-012-0/+19
* The L+ tmpfiles option needs to read the symlinkDave Sugar2024-03-011-1/+1
* Allow sudo dbus chat w/sysemd-logindDave Sugar2024-03-012-1/+2
* cockpit ssh as userDave Sugar2024-03-012-0/+41
* allow system --user to execute systemd-tmpfiles in <user>_systemd_tmpfiles_t ...Dave Sugar2024-03-011-1/+28
* Fix denial while cleaning up pidfile symlinkDave Sugar2024-03-011-1/+1
* SELinux policy for cockpitDave Sugar2024-03-016-0/+494
* kernel: allow delete and setattr on generic SCSI and USB devicesKenton Groombridge2024-03-013-0/+44
* su: various fixesKenton Groombridge2024-03-011-2/+13
* zfs: dontaudit net_admin capability by zedKenton Groombridge2024-03-011-0/+1
* zed: allow managing /etc/exports.d/zfs.exportsKenton Groombridge2024-03-012-0/+24
* rpc: add filecon for /etc/exports.dKenton Groombridge2024-03-011-0/+1
* systemd: allow networkd to use netlink netfilter socketsKenton Groombridge2024-03-011-0/+1
* systemd: fixes for systemd-pcrphaseKenton Groombridge2024-03-013-0/+25
* init: allow all daemons to write to init runtime socketsKenton Groombridge2024-03-011-0/+3
* udev: allow reading kernel fs sysctlsKenton Groombridge2024-03-011-0/+2
* init, systemd: label systemd-executor as init_exec_tKenton Groombridge2024-03-012-0/+4
* Needed to allow environment variable to process started (for cockpit)Dave Sugar2024-03-011-0/+1
* devicedisk: reorder optional blockChristian Göttsche2024-03-011-4/+4
* systemd: reorder optional blockChristian Göttsche2024-03-011-4/+4
* SELint userspace class tweaksChristian Göttsche2024-03-0111-18/+32
* xguest ues systemd --userDave Sugar2024-03-011-0/+4
* Firewalld need to relabel direct.xml fileDave Sugar2024-03-011-1/+1
* init: only grant getattr in init_getattr_generic_units_files()Christian Göttsche2024-03-012-2/+2
* kubernetes: allow container engines to mount on DRI devices if enabledKenton Groombridge2024-03-012-0/+22
* container, kubernetes: add support for ciliumKenton Groombridge2024-03-016-2/+226