aboutsummaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* kernel: create /dev/vsock with correct contextChristian Göttsche3 days1-0/+19
* Fix complaints in STIG about unlabeled device filesDave Sugar3 days1-0/+18
* devices: add label vsock_device_t for /dev/vsockYi Zhao2024-09-211-0/+54
* various: rules required for DV manipulation in kubevirtKenton Groombridge2024-09-211-0/+18
* container: allow spc various rules for kubevirtKenton Groombridge2024-09-211-0/+18
* Reorder perms and classesfreedom1b28302024-09-211-8/+8
* devices: Change dev_rw_uhid() to use a policy pattern.Chris PeBenito2024-09-211-2/+2
* device: Move dev_rw_uhid definition.Chris PeBenito2024-09-211-18/+19
* Sepolicy changes for bluez to access uhidAmisha Jain2024-09-211-0/+18
* various: various fixesKenton Groombridge2024-05-141-0/+19
* kernel: allow managing mouse devicesKenton Groombridge2024-03-011-0/+18
* container, kubernetes: add support for rook-cephKenton Groombridge2024-03-011-0/+19
* Add dontaudit to quiet down a bitDave Sugar2024-03-011-0/+18
* kernel: allow delete and setattr on generic SCSI and USB devicesKenton Groombridge2024-03-011-0/+18
* kubernetes: allow container engines to mount on DRI devices if enabledKenton Groombridge2024-03-011-0/+18
* patches for nspawn policy (#721)Russell Coker2023-10-201-0/+18
* iio-sensor-proxy (Debian package iio-sensor-proxy) IIO sensors to D-Bus proxy...Russell Coker2023-10-061-0/+18
* eg25-manager (Debian package eg25-manager) is a daemon aimed at configuring a...Russell Coker2023-10-061-0/+18
* various: fixes for libvirtd and systemd-machinedKenton Groombridge2022-12-131-0/+18
* This patch removes deprecated interfaces that were deprecated in the 20210203...Russell Coker2022-12-131-45/+0
* devices: add interface to rw infiniband devicesKenton Groombridge2022-11-021-0/+18
* hypervkvp: Port updated module from Fedora policy.Chris PeBenito2022-09-031-0/+36
* devices: add interfaces to remount sysfs and device filesystemsKenton Groombridge2022-01-291-0/+36
* devices, kernel: deprecate dev_mounton_sysfsKenton Groombridge2022-01-291-7/+4
* policy: interfaces: doc: indent param blocks consistentlyMarkus Linnala2021-09-051-33/+33
* policy devices: dev_filetrans: doc: change param from file to file_typeMarkus Linnala2021-09-051-1/+1
* bootloader, devices: dontaudit grub writing on legacy efi variablesKenton Groombridge2021-09-051-0/+18
* devices, userdomain: dontaudit userdomain setattr on null device nodesKenton Groombridge2021-09-051-1/+1
* devices, userdomain: dontaudit userdomain setattr on null device nodesKenton Groombridge2021-09-051-0/+19
* remove deprecated from 20190201Russell Coker2021-01-311-14/+0
* devices: add interface for IOCTL on input devicesKenton Groombridge2021-01-311-0/+18
* Fix selint issues2.20200818-r1Jason Zaman2020-10-111-1/+1
* Add selinux-policy for systemd-pstore serviceDeepak Rawat2020-10-111-0/+26
* allow most common permissions for systemd sandboxing optionsbauen12020-08-091-0/+36
* devices/storage: quote arguments to tunable_policyChristian Göttsche2020-08-091-3/+3
* Fix mismatches between object class and permission macro.Daniel Burgener2020-08-091-3/+3
* devices: label /dev/sysdig0Nicolas Iooss2020-08-091-0/+19
* Make raw memory access tunableTopi Miettinen2020-08-091-0/+108
* Add interface to read/write /dev/ipmiDave Sugar2020-08-091-0/+18
* This patch improves a previous commit by restricting down the permissions to ...Guido Trentalancia2020-08-091-0/+18
* systemd_tmpfiles_t: Allow systemd_tempfiles_t to change permissions in sysfsPeter Morrow2020-02-151-0/+20
* Add an interface to allow watch permission on generic device directories.Guido Trentalancia2020-02-151-0/+18
* Fix situations where require blocks in interfaces listed types not actually r...Daniel Burgener2020-02-151-4/+4
* udev: Watch devices.Chris PeBenito2020-02-151-0/+5
* Add requires to interfaces that reference types or attributes without requiri...Daniel Burgener2020-02-151-8/+19
* init: allow systemd to mount over /dev/kmsg and /proc/kmsgNicolas Iooss2020-02-151-0/+18
* devices: Change netcontrol devices to pmqos.Chris PeBenito2019-04-281-18/+63
* Changes to support plymouth working in enforcingDave Sugar2019-04-281-0/+18
* remove duplicated dev_dontaudit_read_sysfs files_dontaudit_read_etc_filesJason Zaman2019-02-101-20/+0
* devices: introduce dev_dontaudit_read_sysfsJason Zaman2019-02-101-0/+20