All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] admin_rpm.patch
@ 2010-06-02 19:53 Daniel J Walsh
  0 siblings, 0 replies; 4+ messages in thread
From: Daniel J Walsh @ 2010-06-02 19:53 UTC (permalink / raw)
  To: refpolicy

http://people.fedoraproject.org/~dwalsh/SELinux/F14/admin_rpm.patch

I wanted to separate out debuginfo-install from rpm so abrt could only 
install this package and not full rpm

Added interface for rpm leaks, So I can just dontaudit them from domain.

rpm and its post install scripts are loaded with leaks.

^ permalink raw reply	[flat|nested] 4+ messages in thread
* [refpolicy] admin_rpm.patch
@ 2010-08-26 20:35 Daniel J Walsh
  0 siblings, 0 replies; 4+ messages in thread
From: Daniel J Walsh @ 2010-08-26 20:35 UTC (permalink / raw)
  To: refpolicy

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

http://people.fedoraproject.org/~dwalsh/SELinux/F14/admin_rpm.patch

Add labeling for

Handle domains that pass the open descriptor on to apps that transition.

Add interface to allow rpm to leak.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.16 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/

iEYEARECAAYFAkx20BoACgkQrlYvE4MpobM8kwCgoezvElBLYXrRBhYRowWHim38
AcgAn2krShujHVCwtjSKiIv3cL0W5a5W
=T2Om
-----END PGP SIGNATURE-----

^ permalink raw reply	[flat|nested] 4+ messages in thread
* [refpolicy] admin_rpm.patch
@ 2010-02-23 22:22 Daniel J Walsh
  0 siblings, 0 replies; 4+ messages in thread
From: Daniel J Walsh @ 2010-02-23 22:22 UTC (permalink / raw)
  To: refpolicy

http://people.fedoraproject.org/~dwalsh/SELinux/F13/admin_rpm.patch

rpm policy mainly added file context and interfaces to ignore leaks.

^ permalink raw reply	[flat|nested] 4+ messages in thread
* [refpolicy] admin_rpm.patch
@ 2009-05-21 14:16 Daniel J Walsh
  0 siblings, 0 replies; 4+ messages in thread
From: Daniel J Walsh @ 2009-05-21 14:16 UTC (permalink / raw)
  To: refpolicy

http://people.fedoraproject.org/~dwalsh/SELinux/F11/admin_rpm.patch

This is my current rpm policy and interfaces.

rpm is pretty much an unconfined domain, but many interfaces are used.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2010-08-26 20:35 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-06-02 19:53 [refpolicy] admin_rpm.patch Daniel J Walsh
  -- strict thread matches above, loose matches on Subject: below --
2010-08-26 20:35 Daniel J Walsh
2010-02-23 22:22 Daniel J Walsh
2009-05-21 14:16 Daniel J Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.