selinux-refpolicy/policy/modules/system
Guido Trentalancia f4706daf3b locallogin: fine tune DAC override permissions
Improve the locallogin module by curbing on dac_override permissions
in the sulogin domain (read/search permissions only).

Thanks to Dominick Grift for suggesting this.

Other modules are likely affected by the same issue.

Signed-off-by: Guido Trentalancia <guido@trentalancia.net>
2017-04-29 11:25:59 -04:00
..
application.fc
application.if
application.te
authlogin.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
authlogin.if auth: Move optional out of auth_use_pam_systemd() to callers. 2017-02-26 12:08:02 -05:00
authlogin.te Module version bump for patches from Russell Coker and Guido Trentalancia. 2017-04-26 06:39:39 -04:00
clock.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
clock.if
clock.te Module version bump for patches from Russell Coker and Guido Trentalancia. 2017-04-26 06:39:39 -04:00
fstools.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
fstools.if Further strict systemd fixes from Russell Coker. 2017-04-20 20:00:34 -04:00
fstools.te little misc strict from Russell Coker. 2017-04-29 11:25:13 -04:00
getty.fc getty: overlook module 2017-02-27 19:21:39 +01:00
getty.if getty: overlook module 2017-02-27 19:21:39 +01:00
getty.te Module version bump for getty patch from cgzones. 2017-03-02 20:25:04 -05:00
hostname.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
hostname.if
hostname.te Module version bump for hostname fix from cgzones. 2017-02-18 13:58:29 -05:00
hotplug.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
hotplug.if
hotplug.te Module version bumps for fixes from cgzones. 2017-03-05 10:48:42 -05:00
init.fc Misc fc changes from Russell Coker. 2017-04-06 17:00:28 -04:00
init.if Further strict systemd fixes from Russell Coker. 2017-04-20 20:00:34 -04:00
init.te Module version bump for patches from Russell Coker and Guido Trentalancia. 2017-04-26 06:39:39 -04:00
ipsec.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
ipsec.if
ipsec.te Module version bumps for fixes from cgzones. 2017-03-05 10:48:42 -05:00
iptables.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
iptables.if kmod, lvm, brctl patches from Russell Coker 2017-04-18 21:17:36 -04:00
iptables.te kmod, lvm, brctl patches from Russell Coker 2017-04-18 21:17:36 -04:00
libraries.fc Misc fc changes from Russell Coker. 2017-04-06 17:00:28 -04:00
libraries.if
libraries.te Misc fc changes from Russell Coker. 2017-04-06 17:00:28 -04:00
locallogin.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
locallogin.if Fix interface descriptions when duplicate ones are found 2016-01-19 00:17:34 +01:00
locallogin.te locallogin: fine tune DAC override permissions 2017-04-29 11:25:59 -04:00
logging.fc /var/run -> /run again 2017-03-25 12:56:03 -04:00
logging.if systemd init from Russell Coker 2017-04-16 19:08:40 -04:00
logging.te systemd init from Russell Coker 2017-04-16 19:08:40 -04:00
lvm.fc Systemd-related changes from Russell Coker. 2017-04-06 17:37:50 -04:00
lvm.if lvm: small adjustments 2017-03-12 10:32:02 +01:00
lvm.te kmod, lvm, brctl patches from Russell Coker 2017-04-18 21:17:36 -04:00
metadata.xml
miscfiles.fc
miscfiles.if systemd-resolvd, sessions, and tmpfiles take2 2017-03-28 18:51:35 -04:00
miscfiles.te systemd-resolvd, sessions, and tmpfiles take2 2017-03-28 18:51:35 -04:00
modutils.fc systemd-tmpfiles: refactor runtime configs 2017-02-27 19:32:20 +01:00
modutils.if Further strict systemd fixes from Russell Coker. 2017-04-20 20:00:34 -04:00
modutils.te Module version bump for patches from Russell Coker and Guido Trentalancia. 2017-04-26 06:39:39 -04:00
mount.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
mount.if some little misc things from Russell Coker. 2017-04-26 18:03:02 -04:00
mount.te some little misc things from Russell Coker. 2017-04-26 18:03:02 -04:00
netlabel.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
netlabel.if
netlabel.te Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
selinuxutil.fc selinuxutil: adjustments 2017-02-16 16:53:06 +01:00
selinuxutil.if selinuxutil: allow setfiles to read semanage store 2016-09-18 16:40:45 -04:00
selinuxutil.te little misc strict from Russell Coker. 2017-04-29 11:25:13 -04:00
setrans.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
setrans.if
setrans.te Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
sysnetwork.fc /var/run -> /run again 2017-03-25 12:56:03 -04:00
sysnetwork.if Systemd-related changes from Russell Coker. 2017-04-06 17:37:50 -04:00
sysnetwork.te Systemd-related changes from Russell Coker. 2017-04-06 17:37:50 -04:00
systemd.fc Merge branch 'var_run' of git://github.com/cgzones/refpolicy 2017-03-25 13:03:32 -04:00
systemd.if more systemd stuff from Russell Coker 2017-04-16 19:48:04 -04:00
systemd.te apt/dpkg strict patches from Russell Coker. 2017-04-29 11:14:15 -04:00
udev.fc Misc fc changes from Russell Coker. 2017-04-06 17:00:28 -04:00
udev.if misc daemons from Russell Coker. 2017-04-18 20:38:13 -04:00
udev.te misc daemons from Russell Coker. 2017-04-18 20:38:13 -04:00
unconfined.fc Apache OpenOffice module (base policy part) 2016-12-06 20:08:06 -05:00
unconfined.if Systemd-related changes from Russell Coker. 2017-04-06 17:37:50 -04:00
unconfined.te some userdomain patches from Russell Coker 2017-04-18 21:41:45 -04:00
userdomain.fc base: use new genhomedircon template for username 2016-12-27 10:34:04 -05:00
userdomain.if Rename apm to acpi from Russell Coker. 2017-04-26 06:36:20 -04:00
userdomain.te Module version bump for patches from Russell Coker and Guido Trentalancia. 2017-04-26 06:39:39 -04:00