GitWeb
Get Gentoo!
gentoo.org sites
gentoo.org
Wiki
Bugs
Forums
Packages
Planet
Archives
Sources
Infra Status
Home
Gentoo Repository
Repositories
Projects
Developer Overlays
User Overlays
Data
Websites
index
:
proj/hardened-refpolicy.git
concord-dev
mailinfra
master
secmodel
Gentoo Hardened SELinux reference policy implementation
Sven Vermeulen <swift@gentoo.org>
about
summary
refs
log
tree
commit
diff
log msg
author
committer
range
Commit message (
Expand
)
Author
Age
Files
Lines
*
netutils: add file context for ss in /usr/bin
concord-dev
Kenton Groombridge
2022-10-12
1
-0
/
+1
*
nginx: add file context for nginx in /usr/bin
Kenton Groombridge
2022-10-12
1
-0
/
+1
*
lvm: add file context for dmeventd in /usr/bin
Kenton Groombridge
2022-10-12
1
-0
/
+1
*
miscfiles: add file context for /usr/share/ca-certificates
2.20221101-r1
2.20220520-r1
Kenton Groombridge
2022-09-03
1
-0
/
+3
*
phpfpm: various fixes and new tunables
Kenton Groombridge
2022-09-03
1
-0
/
+73
*
nginx: various fixes
Kenton Groombridge
2022-09-03
1
-0
/
+15
*
apache: add gentoo-specific interface to map httpd sys content
Kenton Groombridge
2022-09-03
1
-0
/
+20
*
portage: allow portage to map ebuild files
Kenton Groombridge
2022-09-03
1
-0
/
+2
*
iptables: add file context for /usr/libexec/nftables/nftables.sh
Kenton Groombridge
2022-09-03
1
-0
/
+2
*
iptables: add file context for saved rules
Kenton Groombridge
2022-09-03
2
-1
/
+5
*
xserver: Revert the rest of the sddm changes
Jason Zaman
2022-09-03
4
-14
/
+0
*
Update generated policy and doc files
Jason Zaman
2022-09-03
5
-7266
/
+8226
*
Merge upstream
Jason Zaman
2022-09-03
1
-1
/
+1
*
systemd: systemd-update-done fix startup issue
Dave Sugar
2022-09-03
1
-0
/
+1
*
systemd: init_t creates systemd-logind 'linger' directory
Dave Sugar
2022-09-03
2
-0
/
+22
*
firewalld: firewalld-cmd uses dbus
Dave Sugar
2022-09-03
1
-0
/
+2
*
firewalld: write tmpfs files
Dave Sugar
2022-09-03
1
-0
/
+8
*
firewalld: allow to load kernel modules
Dave Sugar
2022-09-03
1
-0
/
+1
*
firewalld: create netfilter socket
Dave Sugar
2022-09-03
1
-0
/
+1
*
firewalld: read to read fips_enabled sysctl
Dave Sugar
2022-09-03
1
-0
/
+1
*
usbguard: Allow to read fips_enabled sysctl
Dave Sugar
2022-09-03
1
-0
/
+1
*
chronyd: allow chronyd to read /usr/share/crypto-policies
Dave Sugar
2022-09-03
1
-0
/
+2
*
chronyd: Allow to read fips_enabled sysctl
Dave Sugar
2022-09-03
1
-0
/
+1
*
ssh: allow ssh_keygen to read /usr/share/crypto-policies/
Dave Sugar
2022-09-03
1
-0
/
+1
*
hypervkvp: Port updated module from Fedora policy.
Chris PeBenito
2022-09-03
8
-7
/
+258
*
Add cloud-init.
Chris PeBenito
2022-09-03
11
-2
/
+356
*
systemd: Add interface for systemctl exec.
Chris PeBenito
2022-09-03
1
-0
/
+31
*
Drop explicit calls to seutil and kernel module interfaces in broad files int...
Daniel Burgener
2022-09-03
1
-8
/
+0
*
mls: Add setsockcreate constraint.
Chris PeBenito
2022-09-03
1
-1
/
+1
*
mcs: Reorganize file.
Chris PeBenito
2022-09-03
1
-17
/
+36
*
mcs: Remove duplicate node_bind constraint.
Chris PeBenito
2022-09-03
1
-3
/
+0
*
mcs: Add missing process permission constraints.
Chris PeBenito
2022-09-03
1
-1
/
+1
*
mcs: Add additional socket constraints.
Chris PeBenito
2022-09-03
1
-0
/
+12
*
mcs: Collapse constraints.
Chris PeBenito
2022-09-03
1
-32
/
+4
*
mcs: Add additional SysV IPC constraints.
Chris PeBenito
2022-09-03
1
-1
/
+10
*
filesystem: Move ecryptfs interface definitions.
Chris PeBenito
2022-09-03
1
-78
/
+78
*
container: Boolean for ecryptfs
Pat Riehecky
2022-09-03
2
-0
/
+92
*
systemd: Misc updates.
Chris PeBenito
2022-09-03
2
-4
/
+9
*
application: Allow apps to use init fds.
Chris PeBenito
2022-09-03
1
-0
/
+5
*
container: Getattr generic device nodes.
Chris PeBenito
2022-09-03
1
-0
/
+2
*
container: Allow container engines to connect to http cache ports.
Chris PeBenito
2022-09-03
3
-0
/
+23
*
systemd: Fixes for coredumps in containers.
Chris PeBenito
2022-09-03
2
-4
/
+32
*
files: Make etc_runtime_t a config file.
Chris PeBenito
2022-09-03
1
-1
/
+1
*
files: Add prerequisite access for files_mounton_non_security().
Chris PeBenito
2022-09-03
1
-2
/
+2
*
storage: Add fc for /dev/ng*n* devices.
Chris PeBenito
2022-09-03
1
-0
/
+1
*
devices: Add type for infiniband devices.
Chris PeBenito
2022-09-03
2
-0
/
+8
*
iptables: Ioctl cgroup dirs.
Chris PeBenito
2022-09-03
2
-0
/
+20
*
devices: Add file context for /dev/vhost-vsock.
Chris PeBenito
2022-09-03
1
-0
/
+1
*
devices: Add type for SAS management devices.
Chris PeBenito
2022-09-03
2
-0
/
+7
*
container, docker: Fixes for containerd and kubernetes testing.
Chris PeBenito
2022-09-03
4
-0
/
+29
[next]