selinux-refpolicy/policy
Sven Vermeulen 017b505110 Allow unconfined users to call portage features
The unconfined user is currently not allowed to call portage-related
functions. However, in a targeted system (with unconfined domains
enabled), users (including administrators) should be allowed to
transition to the portage domain.

We position the portage-related calls outside the "ifdef(distro_gentoo)"
as other distributions support Portage as well.

Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
2011-09-14 12:33:11 -04:00
..
flask Update access vectors. 2011-03-28 11:45:46 -04:00
modules Allow unconfined users to call portage features 2011-09-14 12:33:11 -04:00
support
constraints Allow user and role changes on dynamic transitions with the same constraints as regular transitions. 2011-09-02 09:59:26 -04:00
global_booleans Change secure_mode_insmod to control sys_module capability rather than controlling domain transitions to insmod. 2011-09-13 14:45:14 -04:00
global_tunables
mcs Pull in mcs constraint changes from Fedora. 2011-03-31 08:28:01 -04:00
mls
policy_capabilities
rolemap
users