selinux-refpolicy/policy/modules/system
Krzysztof Nowicki 900a51f134 Allow systemd-tmpfilesd to relabel generic files inside /etc
Enable this only with the systemd_tmpfilesd_factory tunable, otherwise
silence the messages with a dontaudit rule.

Fixes:

avc:  denied  { relabelfrom } for comm="systemd-tmpfile"
name="pam.d" dev= ino=
scontext=system_u:system_r:systemd_tmpfiles_t:s0
tcontext=system_u:object_r:etc_t:s0 tclass=dir

Signed-off-by: Krzysztof Nowicki <krissn@op.pl>
2021-02-09 13:52:01 +01:00
..
application.fc
application.if
application.te
authlogin.fc
authlogin.if machined 2021-02-02 13:46:42 -05:00
authlogin.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
clock.fc
clock.if
clock.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
daemontools.fc
daemontools.if
daemontools.te
fstools.fc
fstools.if
fstools.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
getty.fc
getty.if
getty.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
hostname.fc
hostname.if
hostname.te
init.fc init: upstream fcontexts from gentoo policy 2020-11-22 14:00:34 -05:00
init.if remove deprecated from 20190201 2021-01-25 08:59:34 -05:00
init.te Fix systemd-journal-flush service 2021-02-09 13:24:51 +01:00
ipsec.fc
ipsec.if
ipsec.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
iptables.fc
iptables.if
iptables.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
iscsi.fc
iscsi.if
iscsi.te
libraries.fc
libraries.if
libraries.te
locallogin.fc
locallogin.if
locallogin.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
logging.fc
logging.if Allow use of systemd UNIX sockets created at initrd execution 2021-02-09 13:24:51 +01:00
logging.te Allow use of systemd UNIX sockets created at initrd execution 2021-02-09 13:24:51 +01:00
lvm.fc
lvm.if
lvm.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
metadata.xml
miscfiles.fc
miscfiles.if miscfiles: Rename miscfiles_manage_generic_tls_privkey_lnk_files. 2021-01-19 09:02:13 -05:00
miscfiles.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
modutils.fc
modutils.if remove deprecated from 20190201 2021-01-25 08:59:34 -05:00
modutils.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
mount.fc
mount.if
mount.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
netlabel.fc
netlabel.if
netlabel.te
raid.fc
raid.if
raid.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
selinuxutil.fc
selinuxutil.if
selinuxutil.te Fix interface naming convention (plural predicates) 2021-02-09 13:24:43 +01:00
setrans.fc
setrans.if
setrans.te
sysnetwork.fc misc network patches with Dominick's changes*2 2021-01-28 11:22:07 -05:00
sysnetwork.if Also grant directory permissions in sysnet_manage_config 2021-02-09 13:24:50 +01:00
sysnetwork.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
systemd.fc Enable factory directory support in systemd-tmpfilesd 2021-02-09 13:24:52 +01:00
systemd.if When using systemd_tmpfilesd_managed also grant directory permissions 2021-02-09 13:24:52 +01:00
systemd.te Allow systemd-tmpfilesd to relabel generic files inside /etc 2021-02-09 13:52:01 +01:00
udev.fc udev: Systemd 246 merged udev and udevadm executables. 2021-01-13 15:12:18 -05:00
udev.if udev: Systemd 246 merged udev and udevadm executables. 2021-01-13 15:12:18 -05:00
udev.te Fix interface naming convention (plural predicates) 2021-02-09 13:24:43 +01:00
unconfined.fc
unconfined.if
unconfined.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
userdomain.fc
userdomain.if Work with xdg module disabled 2021-01-28 18:13:33 -05:00
userdomain.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
xdg.fc
xdg.if userdomain: Add watch on home dirs 2020-11-22 14:00:34 -05:00
xdg.te Bump module versions for release. 2021-02-03 08:38:26 -05:00
xen.fc
xen.if
xen.te Bump module versions for release. 2021-02-03 08:38:26 -05:00