GitWeb
Get Gentoo!
gentoo.org sites
gentoo.org
Wiki
Bugs
Forums
Packages
Planet
Archives
Sources
Infra Status
Home
Gentoo Repository
Repositories
Projects
Developer Overlays
User Overlays
Data
Websites
index
:
proj/hardened-refpolicy.git
concord-dev
mailinfra
master
secmodel
Gentoo Hardened SELinux reference policy implementation
Sven Vermeulen <swift@gentoo.org>
about
summary
refs
log
tree
commit
diff
log msg
author
committer
range
path:
root
/
policy
/
modules
/
kernel
/
devices.if
Commit message (
Expand
)
Author
Age
Files
Lines
*
kernel: create /dev/vsock with correct context
Christian Göttsche
3 days
1
-0
/
+19
*
Fix complaints in STIG about unlabeled device files
Dave Sugar
3 days
1
-0
/
+18
*
devices: add label vsock_device_t for /dev/vsock
Yi Zhao
2024-09-21
1
-0
/
+54
*
various: rules required for DV manipulation in kubevirt
Kenton Groombridge
2024-09-21
1
-0
/
+18
*
container: allow spc various rules for kubevirt
Kenton Groombridge
2024-09-21
1
-0
/
+18
*
Reorder perms and classes
freedom1b2830
2024-09-21
1
-8
/
+8
*
devices: Change dev_rw_uhid() to use a policy pattern.
Chris PeBenito
2024-09-21
1
-2
/
+2
*
device: Move dev_rw_uhid definition.
Chris PeBenito
2024-09-21
1
-18
/
+19
*
Sepolicy changes for bluez to access uhid
Amisha Jain
2024-09-21
1
-0
/
+18
*
various: various fixes
Kenton Groombridge
2024-05-14
1
-0
/
+19
*
kernel: allow managing mouse devices
Kenton Groombridge
2024-03-01
1
-0
/
+18
*
container, kubernetes: add support for rook-ceph
Kenton Groombridge
2024-03-01
1
-0
/
+19
*
Add dontaudit to quiet down a bit
Dave Sugar
2024-03-01
1
-0
/
+18
*
kernel: allow delete and setattr on generic SCSI and USB devices
Kenton Groombridge
2024-03-01
1
-0
/
+18
*
kubernetes: allow container engines to mount on DRI devices if enabled
Kenton Groombridge
2024-03-01
1
-0
/
+18
*
patches for nspawn policy (#721)
Russell Coker
2023-10-20
1
-0
/
+18
*
iio-sensor-proxy (Debian package iio-sensor-proxy) IIO sensors to D-Bus proxy...
Russell Coker
2023-10-06
1
-0
/
+18
*
eg25-manager (Debian package eg25-manager) is a daemon aimed at configuring a...
Russell Coker
2023-10-06
1
-0
/
+18
*
various: fixes for libvirtd and systemd-machined
Kenton Groombridge
2022-12-13
1
-0
/
+18
*
This patch removes deprecated interfaces that were deprecated in the 20210203...
Russell Coker
2022-12-13
1
-45
/
+0
*
devices: add interface to rw infiniband devices
Kenton Groombridge
2022-11-02
1
-0
/
+18
*
hypervkvp: Port updated module from Fedora policy.
Chris PeBenito
2022-09-03
1
-0
/
+36
*
devices: add interfaces to remount sysfs and device filesystems
Kenton Groombridge
2022-01-29
1
-0
/
+36
*
devices, kernel: deprecate dev_mounton_sysfs
Kenton Groombridge
2022-01-29
1
-7
/
+4
*
policy: interfaces: doc: indent param blocks consistently
Markus Linnala
2021-09-05
1
-33
/
+33
*
policy devices: dev_filetrans: doc: change param from file to file_type
Markus Linnala
2021-09-05
1
-1
/
+1
*
bootloader, devices: dontaudit grub writing on legacy efi variables
Kenton Groombridge
2021-09-05
1
-0
/
+18
*
devices, userdomain: dontaudit userdomain setattr on null device nodes
Kenton Groombridge
2021-09-05
1
-1
/
+1
*
devices, userdomain: dontaudit userdomain setattr on null device nodes
Kenton Groombridge
2021-09-05
1
-0
/
+19
*
remove deprecated from 20190201
Russell Coker
2021-01-31
1
-14
/
+0
*
devices: add interface for IOCTL on input devices
Kenton Groombridge
2021-01-31
1
-0
/
+18
*
Fix selint issues
2.20200818-r1
Jason Zaman
2020-10-11
1
-1
/
+1
*
Add selinux-policy for systemd-pstore service
Deepak Rawat
2020-10-11
1
-0
/
+26
*
allow most common permissions for systemd sandboxing options
bauen1
2020-08-09
1
-0
/
+36
*
devices/storage: quote arguments to tunable_policy
Christian Göttsche
2020-08-09
1
-3
/
+3
*
Fix mismatches between object class and permission macro.
Daniel Burgener
2020-08-09
1
-3
/
+3
*
devices: label /dev/sysdig0
Nicolas Iooss
2020-08-09
1
-0
/
+19
*
Make raw memory access tunable
Topi Miettinen
2020-08-09
1
-0
/
+108
*
Add interface to read/write /dev/ipmi
Dave Sugar
2020-08-09
1
-0
/
+18
*
This patch improves a previous commit by restricting down the permissions to ...
Guido Trentalancia
2020-08-09
1
-0
/
+18
*
systemd_tmpfiles_t: Allow systemd_tempfiles_t to change permissions in sysfs
Peter Morrow
2020-02-15
1
-0
/
+20
*
Add an interface to allow watch permission on generic device directories.
Guido Trentalancia
2020-02-15
1
-0
/
+18
*
Fix situations where require blocks in interfaces listed types not actually r...
Daniel Burgener
2020-02-15
1
-4
/
+4
*
udev: Watch devices.
Chris PeBenito
2020-02-15
1
-0
/
+5
*
Add requires to interfaces that reference types or attributes without requiri...
Daniel Burgener
2020-02-15
1
-8
/
+19
*
init: allow systemd to mount over /dev/kmsg and /proc/kmsg
Nicolas Iooss
2020-02-15
1
-0
/
+18
*
devices: Change netcontrol devices to pmqos.
Chris PeBenito
2019-04-28
1
-18
/
+63
*
Changes to support plymouth working in enforcing
Dave Sugar
2019-04-28
1
-0
/
+18
*
remove duplicated dev_dontaudit_read_sysfs files_dontaudit_read_etc_files
Jason Zaman
2019-02-10
1
-20
/
+0
*
devices: introduce dev_dontaudit_read_sysfs
Jason Zaman
2019-02-10
1
-0
/
+20
[next]