GitWeb
Get Gentoo!
gentoo.org sites
gentoo.org
Wiki
Bugs
Forums
Packages
Planet
Archives
Sources
Infra Status
Home
Gentoo Repository
Repositories
Projects
Developer Overlays
User Overlays
Data
Websites
index
:
proj/hardened-refpolicy.git
concord-dev
mailinfra
master
secmodel
Gentoo Hardened SELinux reference policy implementation
Sven Vermeulen <swift@gentoo.org>
about
summary
refs
log
tree
commit
diff
log msg
author
committer
range
Commit message (
Expand
)
Author
Age
Files
Lines
*
Update generated policy and doc files
HEAD
2.20240226-r1
master
Kenton Groombridge
2024-03-01
3
-1780
/
+2745
*
Merge upstream
Kenton Groombridge
2024-03-01
1
-1
/
+1
*
Update Changelog and VERSION for release 2.20240226.
Chris PeBenito
2024-03-01
2
-1
/
+488
*
libraries: drop space in empty line
Christian Göttsche
2024-03-01
1
-1
/
+1
*
consolesetup: update
Christian Göttsche
2024-03-01
1
-0
/
+2
*
systemd: logind update
Christian Göttsche
2024-03-01
1
-0
/
+3
*
udev: update
Christian Göttsche
2024-03-01
2
-0
/
+33
*
systemd: generator updates
Christian Göttsche
2024-03-01
2
-1
/
+22
*
fs: add support for virtiofs
Christian Göttsche
2024-03-01
1
-0
/
+11
*
vnstatd: update
Christian Göttsche
2024-03-01
1
-0
/
+1
*
systemd: binfmt updates
Christian Göttsche
2024-03-01
2
-0
/
+43
*
fs: mark memory pressure type as file
Christian Göttsche
2024-03-01
1
-0
/
+1
*
userdom: permit reading PSI as admin
Christian Göttsche
2024-03-01
1
-0
/
+1
*
selinuxutil: ignore getattr proc in newrole
Christian Göttsche
2024-03-01
1
-0
/
+1
*
selinuxutil: setfiles updates
Christian Göttsche
2024-03-01
2
-0
/
+21
*
virt: label qemu configuration directory
Christian Göttsche
2024-03-01
1
-0
/
+2
*
Makefile: set PYTHONPATH for test toolchain
Christian Göttsche
2024-03-01
1
-3
/
+10
*
Makefile: use sepolgen-ifgen-attr-helper from test toolchain
Christian Göttsche
2024-03-01
1
-0
/
+4
*
Rules.modular: use temporary file to not ignore error
Christian Göttsche
2024-03-01
1
-2
/
+2
*
Rules.monolithic: pre-compile fcontexts on install
Christian Göttsche
2024-03-01
2
-0
/
+7
*
policy_capabilities: remove estimated from released versions
Christian Göttsche
2024-03-01
1
-1
/
+1
*
Support multi-line interface calls
Christian Göttsche
2024-03-01
1
-4
/
+9
*
fix misc typos
Christian Göttsche
2024-03-01
3
-4
/
+4
*
support/genhomedircon: support usr prefixed paths
Christian Göttsche
2024-03-01
1
-1
/
+1
*
access_vectors: define io_uring { cmd }
Christian Göttsche
2024-03-01
1
-0
/
+1
*
cloudinit: Add permissions derived from sysadm.
Chris PeBenito
2024-03-01
15
-26
/
+1216
*
systemd: Updates for systemd-locale.
Chris PeBenito
2024-03-01
1
-0
/
+5
*
cloud-init: Change udev rules
Chris PeBenito
2024-03-01
1
-0
/
+1
*
cloud-init: Add systemd permissions.
Chris PeBenito
2024-03-01
2
-4
/
+27
*
cloud-init: Allow use of sudo in runcmd.
Chris PeBenito
2024-03-01
2
-0
/
+33
*
chronyd: Read /dev/urandom.
Chris PeBenito
2024-03-01
1
-0
/
+1
*
unconfined: Add remaining watch_* permissions.
Chris PeBenito
2024-03-01
4
-29
/
+29
*
usermanage: Handle symlinks in /usr/share/cracklib.
Chris PeBenito
2024-03-01
2
-0
/
+2
*
kdump: Fixes from testing kdumpctl.
Chris PeBenito
2024-03-01
1
-0
/
+15
*
cloudinit: Add support for installing RPMs and setting passwords.
Chris PeBenito
2024-03-01
3
-0
/
+35
*
files: Handle symlinks for /media and /srv.
Chris PeBenito
2024-03-01
1
-1
/
+2
*
usermanage: Add sysctl access for groupadd to get number of groups.
Chris PeBenito
2024-03-01
1
-0
/
+4
*
sysnetwork: ifconfig searches debugfs.
Chris PeBenito
2024-03-01
1
-0
/
+1
*
selinuxutil: Semanage reads policy for export.
Chris PeBenito
2024-03-01
1
-0
/
+1
*
init: Allow nnp/nosuid transitions from systemd initrc_t.
Chris PeBenito
2024-03-01
1
-0
/
+2
*
rpm: Minor fixes
Chris PeBenito
2024-03-01
1
-1
/
+3
*
systemd: Minor coredump fixes.
Chris PeBenito
2024-03-01
2
-7
/
+24
*
Container: Minor fixes from interactive container use.
Chris PeBenito
2024-03-01
3
-1
/
+29
*
kernel: hv_utils shutdown on systemd systems.
Chris PeBenito
2024-03-01
1
-0
/
+5
*
systemd: systemd-cgroups reads kernel.cap_last_cap sysctl.
Chris PeBenito
2024-03-01
1
-0
/
+3
*
domain: Manage own fds.
Chris PeBenito
2024-03-01
1
-3
/
+4
*
kubernetes: allow kubelet to apply fsGroup to persistent volumes
Kenton Groombridge
2024-03-01
2
-0
/
+23
*
container: allow spc to map kubernetes runtime files
Kenton Groombridge
2024-03-01
2
-0
/
+19
*
crio: allow reading container home content
Kenton Groombridge
2024-03-01
2
-2
/
+22
*
systemd: allow systemd generator to list exports
Kenton Groombridge
2024-03-01
1
-0
/
+1
[next]