selinux-refpolicy/policy/modules/kernel
Sven Vermeulen 765e7b71ee Supporting interfaces for the /run changes
Since most distributions now support /run (which, thanks the the
file context substitutions, is marked as var_run_t), we need to update the
SELinux policies to support "dynamically" building up /run. Unlike /var/run,
which is most likely statically defined during distribution installation, /run
is a tmpfs which is built up from scratch on each and every boot.

But not only that, many services also use this location for other purposes than
just PID files (which is to be expected as these "other reasons" is why /run
came to be in the first place), so we need to support other types within this
location easily.

For this reason, we introduce support to
- creating the /run/lock location
- supporting named file transitions when init scripts create stuff in /run

Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
2012-07-24 08:42:10 -04:00
..
corecommands.fc Whitespace fixes from fc.subs changes. 2012-05-10 10:33:54 -04:00
corecommands.if Additional rearrangement in corecommands, along with module version bump. 2010-10-27 14:09:00 -04:00
corecommands.te Module verion bump for simplify file contexts based on file context path substitutions, from Sven Vermeulen. 2012-05-10 10:36:06 -04:00
corenetwork.fc Start pulling in kernel layer pieces from Fedora. 2011-03-29 10:33:43 -04:00
corenetwork.if.in Corenetwork policy size optimization from Dan Walsh. 2011-08-26 09:03:25 -04:00
corenetwork.if.m4
corenetwork.te.in Module version bump for http_cache port update from Sven Vermeulen. 2012-05-04 11:20:33 -04:00
corenetwork.te.m4 Fix corenetwork port declaration to choose either reserved or unreserved. 2011-10-04 15:31:08 -04:00
devices.fc Debian file locations patch from Russell Coker. 2011-11-16 15:29:18 -05:00
devices.if Add optional name for kernel and system filetrans interfaces. 2012-05-10 09:53:45 -04:00
devices.te Add optional name for kernel and system filetrans interfaces. 2012-05-10 09:53:45 -04:00
domain.fc
domain.if Start pulling in kernel layer pieces from Fedora. 2011-03-29 10:33:43 -04:00
domain.te Bump module versions for release. 2012-02-15 14:32:45 -05:00
files.fc Allow mount to write to all of its runtime files, from Guido Trentalancia 2012-06-26 09:51:57 -04:00
files.if Supporting interfaces for the /run changes 2012-07-24 08:42:10 -04:00
files.te Module version bump, changelog, pull contrib 2012-07-10 08:58:37 -04:00
filesystem.fc Pull in cgroup changes from Fedora policy, in particular to handle systemd usage. 2011-04-29 13:22:47 -04:00
filesystem.if Add optional name for kernel and system filetrans interfaces. 2012-05-10 09:53:45 -04:00
filesystem.te Add optional name for kernel and system filetrans interfaces. 2012-05-10 09:53:45 -04:00
kernel.fc
kernel.if Change secure_mode_insmod to control sys_module capability rather than controlling domain transitions to insmod. 2011-09-13 14:45:14 -04:00
kernel.te Module version bump and changelog for non-auth file attribute to eliminate set expressions, from James Carter. 2012-05-04 09:14:00 -04:00
mcs.fc
mcs.if revise MCS constraints to use only MCS-specific attributes. 2009-10-07 11:48:14 -04:00
mcs.te Whitespace change: drop unnecessary blank line at the start of .te files. 2010-06-10 08:16:35 -04:00
metadata.xml
mls.fc
mls.if
mls.te Whitespace change: drop unnecessary blank line at the start of .te files. 2010-06-10 08:16:35 -04:00
selinux.fc
selinux.if Change secure_mode_policyload to disable only toggling of this Boolean rather than disabling all Boolean toggling permissions. 2011-09-26 10:44:27 -04:00
selinux.te Module version bump and changelog for virt updates from Sven Vermeulen. 2012-04-23 10:43:15 -04:00
storage.fc Mark temporary block device as fixed_disk_device_t 2012-02-22 08:32:42 -05:00
storage.if Pull in additional changes in kernel layer from Fedora. 2011-03-31 09:49:01 -04:00
storage.te Module version bump for Mark temporary block device as fixed_disk_device_t from Sven Vermeulen. 2012-02-22 08:44:15 -05:00
terminal.fc Pull in additional changes in kernel layer from Fedora. 2011-03-31 09:49:01 -04:00
terminal.if Pull in additional changes in kernel layer from Fedora. 2011-03-31 09:49:01 -04:00
terminal.te Module version bump for release. 2011-07-26 08:11:01 -04:00
ubac.fc
ubac.if Improve the documentation of ubac_constrained(). 2010-03-02 11:28:44 -05:00
ubac.te Whitespace change: drop unnecessary blank line at the start of .te files. 2010-06-10 08:16:35 -04:00