selinux-refpolicy/policy/modules/kernel
Dominick Grift 623e4f0885 1/1] Make the ability to mmap zero conditional where this is fapplicable.
Retry: forgot to include attribute mmap_low_domain_type attribute to domain_mmap_low()	:

Inspired by similar implementation in Fedora.
Wine and vbetool do not always actually need the ability to mmap a low area of the address space.
In some cases this can be silently denied.

Therefore introduce an interface that facilitates "mmap low" conditionally, and the corresponding boolean.
Also implement booleans for wine and vbetool that enables the ability to not audit attempts by wine and vbetool to mmap a low area of the address space.

Rename domain_mmap_low interface to domain_mmap_low_uncond.

Change call to domain_mmap_low to domain_mmap_low_uncond for xserver_t. Also move this call to distro redhat ifndef block because Redhat does not need this ability.

Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-01 09:41:56 -04:00
..
corecommands.fc Corecommands patch from Dan Walsh. 2010-06-07 09:04:08 -04:00
corecommands.if Fix corecmd_dontaudit_exec_all_executables doc. 2010-08-05 09:24:41 -04:00
corecommands.te Module version bumps and changelog for devtmpfs patchset. 2010-08-25 11:19:27 -04:00
corenetwork.fc
corenetwork.if.in Docs standardizing on the role portion of run interfaces. Additional docs cleanup. 2010-08-03 09:20:22 -04:00
corenetwork.if.m4
corenetwork.te.in Increase bindreservport range to 512-1024 in corenetwork, from Dan Walsh. 2010-07-19 14:22:44 -04:00
corenetwork.te.m4 Increase bindreservport range to 512-1024 in corenetwork, from Dan Walsh. 2010-07-19 14:22:44 -04:00
devices.fc Devices patch from Dan Walsh. 2010-06-07 09:20:18 -04:00
devices.if Early devtmpfs access 2010-08-25 11:01:27 -04:00
devices.te Module version bumps and changelog for devtmpfs patchset. 2010-08-25 11:19:27 -04:00
domain.fc
domain.if 1/1] Make the ability to mmap zero conditional where this is fapplicable. 2010-09-01 09:41:56 -04:00
domain.te 1/1] Make the ability to mmap zero conditional where this is fapplicable. 2010-09-01 09:41:56 -04:00
files.fc Files patch from Dan Walsh. 2010-06-09 09:09:34 -04:00
files.if Dbadm updates from KaiGai Kohei. 2010-08-19 08:41:39 -04:00
files.te Whitespace change: drop unnecessary blank line at the start of .te files. 2010-06-10 08:16:35 -04:00
filesystem.fc cgroup in filesystem. 2010-06-08 08:38:18 -04:00
filesystem.if Kernel layer xml fixes. 2010-08-05 09:08:07 -04:00
filesystem.te Module version bumps and changelog for devtmpfs patchset. 2010-08-25 11:19:27 -04:00
kernel.fc
kernel.if Kernel layer xml fixes. 2010-08-05 09:08:07 -04:00
kernel.te Module version bumps and changelog for devtmpfs patchset. 2010-08-25 11:19:27 -04:00
mcs.fc
mcs.if revise MCS constraints to use only MCS-specific attributes. 2009-10-07 11:48:14 -04:00
mcs.te Whitespace change: drop unnecessary blank line at the start of .te files. 2010-06-10 08:16:35 -04:00
metadata.xml
mls.fc
mls.if
mls.te Whitespace change: drop unnecessary blank line at the start of .te files. 2010-06-10 08:16:35 -04:00
selinux.fc
selinux.if Kernel layer xml fixes. 2010-08-05 09:08:07 -04:00
selinux.te Whitespace change: drop unnecessary blank line at the start of .te files. 2010-06-10 08:16:35 -04:00
storage.fc Take virtio disks into account. 2010-08-02 08:25:14 -04:00
storage.if Kernel layer xml fixes. 2010-08-05 09:08:07 -04:00
storage.te Virtio disk file context update from Mika Pfluger. 2010-08-02 08:33:41 -04:00
terminal.fc Add terminal patch from Dan Walsh. 2009-11-19 14:57:49 -05:00
terminal.if Kernel layer xml fixes. 2010-08-05 09:08:07 -04:00
terminal.te Whitespace change: drop unnecessary blank line at the start of .te files. 2010-06-10 08:16:35 -04:00
ubac.fc
ubac.if Improve the documentation of ubac_constrained(). 2010-03-02 11:28:44 -05:00
ubac.te Whitespace change: drop unnecessary blank line at the start of .te files. 2010-06-10 08:16:35 -04:00