selinux-refpolicy/policy/modules/system
Stephen Smalley 58b3029576 Update netlink socket classes.
Define new netlink socket security classes introduced by kernel commit
223ae516404a7a65f09e79a1c0291521c233336e.

Note that this does not remove the long-since obsolete
netlink_firewall_socket and netlink_ip6_fw_socket classes
from refpolicy in case they are still needed for legacy
distribution policies.

Add the new socket classes to socket_class_set.
Update ubac and mls constraints for the new socket classes.
Add allow rules for a few specific known cases (netutils, iptables,
netlabel, ifconfig, udev) in core policy that require access.
Further refinement for the contrib tree will be needed.  Any allow
rule previously written on :netlink_socket may need to be rewritten or
duplicated for one of the more specific classes.  For now, we retain the
existing :netlink_socket rules for compatibility on older kernels.

Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
2015-05-22 08:29:03 -04:00
..
application.fc
application.if Start pulling in pieces of Fedora policy in system layer. 2011-03-31 13:29:59 -04:00
application.te Start pulling in pieces of Fedora policy in system layer. 2011-03-31 13:29:59 -04:00
authlogin.fc authlogin: Sudo file context specification did not catch paths (squash me) 2013-09-26 09:25:27 -04:00
authlogin.if Add auth_pid_filetrans_pam_var_run 2014-12-02 09:16:05 -05:00
authlogin.te Bump module versions for release. 2014-12-03 13:37:38 -05:00
clock.fc
clock.if Rearrange interfaces in files, clock, and udev. 2012-10-30 14:16:30 -04:00
clock.te Bump module versions for release. 2014-03-11 08:16:57 -04:00
fstools.fc fstools: add in filetrans for /run dir 2015-04-15 12:16:32 -04:00
fstools.if system/fstools.if: Add fstools_use_fds interface 2014-08-18 15:24:46 -04:00
fstools.te Module version bump for fstools blkid fix from Jason Zaman 2015-04-15 12:17:30 -04:00
getty.fc
getty.if System layer xml fixes. 2010-08-05 09:25:55 -04:00
getty.te Bump module versions for release. 2013-04-24 16:14:52 -04:00
hostname.fc
hostname.if System layer xml fixes. 2010-08-05 09:25:55 -04:00
hostname.te Bump module versions for release. 2014-03-11 08:16:57 -04:00
hotplug.fc
hotplug.if System layer xml fixes. 2010-08-05 09:25:55 -04:00
hotplug.te Bump module versions for release. 2014-03-11 08:16:57 -04:00
init.fc Move systemd fc entry. 2014-09-12 09:42:59 -04:00
init.if Fix minor typo in init.if 2014-10-04 10:53:50 +02:00
init.te Bump module versions for release. 2014-12-03 13:37:38 -05:00
ipsec.fc Add /var/lib/racoon as runtime directory for ipsec 2014-12-02 09:16:06 -05:00
ipsec.if Pull in some changes from Fedora policy system layer. 2011-04-14 11:36:56 -04:00
ipsec.te Bump module versions for release. 2014-12-03 13:37:38 -05:00
iptables.fc Add conntrack fc entry. 2013-04-05 09:45:04 -04:00
iptables.if Add role attributes in iptables. 2011-09-21 08:27:24 -04:00
iptables.te Update netlink socket classes. 2015-05-22 08:29:03 -04:00
libraries.fc Label /lib symlink as lib_t for every distro 2014-07-08 08:49:37 -04:00
libraries.if Pull in some changes from Fedora policy system layer. 2011-04-14 11:36:56 -04:00
libraries.te Bump module versions for release. 2014-12-03 13:37:38 -05:00
locallogin.fc Pull in some changes from Fedora policy system layer. 2011-04-14 11:36:56 -04:00
locallogin.if System layer xml fixes. 2010-08-05 09:25:55 -04:00
locallogin.te Bump module versions for release. 2014-03-11 08:16:57 -04:00
logging.fc Whitespace change in logging.fc. 2014-09-12 09:49:37 -04:00
logging.if /dev/log symlinks are not labeled devlog_t. 2014-09-12 14:25:01 -04:00
logging.te Bump module versions for release. 2014-12-03 13:37:38 -05:00
lvm.fc udev-acl.ck lists /run/udev/tags/udev-acl udev blocks suspend, and compromises kernel 2013-09-27 16:35:28 -04:00
lvm.if System layer xml fixes. 2010-08-05 09:25:55 -04:00
lvm.te Bump module versions for release. 2014-03-11 08:16:57 -04:00
metadata.xml
miscfiles.fc Label /etc/locale.alias as locale_t on Debian 2014-04-21 09:02:26 -04:00
miscfiles.if Fix misspelling 2014-06-09 08:21:45 -04:00
miscfiles.te Bump module versions for release. 2014-12-03 13:37:38 -05:00
modutils.fc split kmod fc into two lines. 2012-10-02 10:08:09 -04:00
modutils.if Changes to the modutils policy module 2012-10-19 08:14:32 -04:00
modutils.te Bump module versions for release. 2014-03-11 08:16:57 -04:00
mount.fc Rearrange ZFS fc entries. 2014-01-21 08:55:28 -05:00
mount.if system/mount.if: Add mount_rw_loopback_files interface 2014-08-18 15:24:46 -04:00
mount.te Bump module versions for release. 2014-12-03 13:37:38 -05:00
netlabel.fc
netlabel.if System layer xml fixes. 2010-08-05 09:25:55 -04:00
netlabel.te Update netlink socket classes. 2015-05-22 08:29:03 -04:00
selinuxutil.fc Update policy for selinux userspace moving the policy store to /var/lib/selinux 2014-12-03 13:36:31 -05:00
selinuxutil.if Update policy for selinux userspace moving the policy store to /var/lib/selinux 2014-12-03 13:36:31 -05:00
selinuxutil.te Bump module versions for release. 2014-12-03 13:37:38 -05:00
setrans.fc
setrans.if System layer xml fixes. 2010-08-05 09:25:55 -04:00
setrans.te Bump module versions for release. 2014-12-03 13:37:38 -05:00
sysnetwork.fc Label /sbin/iw as ifconfig_exec_t 2014-10-23 08:07:44 -04:00
sysnetwork.if hostname: do not audit attempts by hostname to read and write dhcpc udp sockets (looks like a leaked fd) 2013-09-27 15:13:19 -04:00
sysnetwork.te Update netlink socket classes. 2015-05-22 08:29:03 -04:00
udev.fc Label /usr/share/virtualbox/VBoxCreateUSBNode.sh as udev_helper_exec_t 2014-04-21 10:15:51 -04:00
udev.if udev.if: Call files_search_pid instead of files_search_var_lib in udev_manage_pid_files 2013-01-23 07:09:05 -05:00
udev.te Update netlink socket classes. 2015-05-22 08:29:03 -04:00
unconfined.fc Simplify .fc in light of file_contexts.subs_dist 2012-05-10 10:09:00 -04:00
unconfined.if Allow unconfined domains to use syslog capability 2014-06-09 09:28:33 -04:00
unconfined.te Bump module versions for release. 2014-12-03 13:37:38 -05:00
userdomain.fc
userdomain.if Remove duplicate role declarations 2014-09-17 10:44:04 -04:00
userdomain.te Bump module versions for release. 2014-12-03 13:37:38 -05:00