selinux-refpolicy/policy
Sven Vermeulen 356c704f4d Introduce portage_fetch_t as an application domain
Enhance portage_fetch_t from an application type to a domain. Introduce
the proper portage_fetch_exec_t and add the necessary privileges to the
domain definition to allow portage_fetch_t to be used by Portage
management utilities like layman and emerge-webrsync.

We enhance portage_domtrans() to include portage_fetch_t support.
Providing a different interface (portage_fetch_domtrans) is possible
too, but since every application and role that needs to deal with
portage needs to deal with the fetching as well, and vice versa, we keep
this in portage_domtrans.

Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
2011-09-06 13:22:52 -04:00
..
flask Update access vectors. 2011-03-28 11:45:46 -04:00
modules Introduce portage_fetch_t as an application domain 2011-09-06 13:22:52 -04:00
support
constraints Allow user and role changes on dynamic transitions with the same constraints as regular transitions. 2011-09-02 09:59:26 -04:00
global_booleans
global_tunables
mcs Pull in mcs constraint changes from Fedora. 2011-03-31 08:28:01 -04:00
mls
policy_capabilities
rolemap
users