selinux-refpolicy/policy/modules/kernel
Daniel Jurgens 25a5b24274 refpolicy: Infiniband pkeys and endports
Every Infiniband network will have a default pkey, so that is labeled.
The rest of the pkey configuration is network specific. The policy allows
access to the default and unlabeled pkeys for sysadm and staff users.
kernel_t is allowed access to all pkeys, which it needs to process and
route management datagrams.

Endports are all unlabeled by default, sysadm users are allowed to
manage the subnet on unlabeled endports. kernel_t is allowed to manage
the subnet on all ibendports, which is required for configuring the HCA.

This patch requires selinux series: "SELinux user space support for
Infiniband RDMA", due to the new ipkeycon labeling mechanism.

Signed-off-by: Daniel Jurgens <danielj@mellanox.com>
2017-05-24 19:23:18 -04:00
..
corecommands.fc corecommands: add consolekit fcontexts 2017-05-11 19:35:53 -04:00
corecommands.if corecommands: fix corecmd_*_bin() for usr merged systems 2017-03-03 11:53:35 +01:00
corecommands.te Module version bump for changes from Jason Zaman and Luis Ressel. 2017-05-11 19:54:25 -04:00
corenetwork.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
corenetwork.if.in refpolicy: Infiniband pkeys and endports 2017-05-24 19:23:18 -04:00
corenetwork.if.m4 refpolicy: Infiniband pkeys and endports 2017-05-24 19:23:18 -04:00
corenetwork.te.in refpolicy: Infiniband pkeys and endports 2017-05-24 19:23:18 -04:00
corenetwork.te.m4 refpolicy: Infiniband pkeys and endports 2017-05-24 19:23:18 -04:00
devices.fc Rename apm to acpi from Russell Coker. 2017-04-26 06:36:20 -04:00
devices.if Rename apm to acpi from Russell Coker. 2017-04-26 06:36:20 -04:00
devices.te Module version bump for patches from Russell Coker and Guido Trentalancia. 2017-04-26 06:39:39 -04:00
domain.fc remove extra level of directory 2006-07-12 20:32:27 +00:00
domain.if remove trailing whitespaces 2016-12-06 13:45:13 +01:00
domain.te Bump module versions for release. 2016-10-23 16:58:59 -04:00
files.fc Misc fc changes from Russell Coker. 2017-04-06 17:00:28 -04:00
files.if Enable /etc directory protection using ProtectSystem 2017-05-15 18:41:00 -04:00
files.te Module version bump for systemd fix from Krzysztof Nowicki. 2017-05-15 18:48:51 -04:00
filesystem.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
filesystem.if Further strict systemd fixes from Russell Coker. 2017-04-20 20:00:34 -04:00
filesystem.te Further strict systemd fixes from Russell Coker. 2017-04-20 20:00:34 -04:00
kernel.fc Add fc for /sys/kernel/debug as debugfs_t 2015-05-06 09:49:40 -04:00
kernel.if refpolicy: Infiniband pkeys and endports 2017-05-24 19:23:18 -04:00
kernel.te refpolicy: Infiniband pkeys and endports 2017-05-24 19:23:18 -04:00
mcs.fc remove extra level of directory 2006-07-12 20:32:27 +00:00
mcs.if remove trailing whitespaces 2016-12-06 13:45:13 +01:00
mcs.te Bump module versions for release. 2013-04-24 16:14:52 -04:00
metadata.xml remove extra level of directory 2006-07-12 20:32:27 +00:00
mls.fc remove extra level of directory 2006-07-12 20:32:27 +00:00
mls.if remove trailing whitespaces 2016-12-06 13:45:13 +01:00
mls.te remove trailing whitespaces 2016-12-06 13:45:13 +01:00
selinux.fc remove extra level of directory 2006-07-12 20:32:27 +00:00
selinux.if Revise selinux module interfaces for perms protected by neverallows. 2015-11-04 15:10:29 -05:00
selinux.te remove trailing whitespaces 2016-12-06 13:45:13 +01:00
storage.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
storage.if Fix interface descriptions when duplicate ones are found 2016-01-19 00:17:34 +01:00
storage.te Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
terminal.fc Misc fc changes from Russell Coker. 2017-04-06 17:00:28 -04:00
terminal.if systemd-nspawn again 2017-04-01 12:08:42 -04:00
terminal.te Misc fc changes from Russell Coker. 2017-04-06 17:00:28 -04:00
ubac.fc trunk: add missing ubac module. 2008-11-05 16:11:27 +00:00
ubac.if Improve the documentation of ubac_constrained(). 2010-03-02 11:28:44 -05:00
ubac.te Whitespace change: drop unnecessary blank line at the start of .te files. 2010-06-10 08:16:35 -04:00