aboutsummaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Update generated policy and doc files2.20221101-r4Kenton Groombridge2023-03-311-806/+944
* Merge upstreamKenton Groombridge2023-03-311-1/+1
* systemd: allow systemd-resolved to search directories on tmpfs and ramfsYi Zhao2023-03-311-0/+2
* kubernetes: allow kubelet to read etc runtime filesKenton Groombridge2023-03-311-0/+2
* glusterfs: allow glusterd to bind to all TCP unreserved portsKenton Groombridge2023-03-311-0/+1
* fstools: allow fsadm to read utabKenton Groombridge2023-03-311-1/+1
* raid: allow mdadm to create generic links in /dev/mdKenton Groombridge2023-03-311-0/+2
* raid: allow mdadm to read udev runtime filesKenton Groombridge2023-03-311-0/+2
* init: allow initrc_t to create netlink_kobject_uevent_socketsKenton Groombridge2023-03-311-0/+1
* systemd: allow systemd-resolved to bind to UDP port 5353Kenton Groombridge2023-03-311-0/+1
* init: allow systemd-init to set the attributes of unallocated terminalsKenton Groombridge2023-03-311-0/+1
* fs, init: allow systemd-init to set the attributes of efivarfs filesKenton Groombridge2023-03-312-0/+21
* systemd: allow systemd-pcrphase to read generic certsKenton Groombridge2023-03-311-0/+2
* systemd: add rules for systemd-zram-generatorKenton Groombridge2023-03-311-3/+6
* files, systemd: allow systemd-tmpfiles to relabel config file symlinksKenton Groombridge2023-03-312-1/+21
* logging, systemd: allow relabelfrom,relabelto on systemd journal files by sys...Kenton Groombridge2023-03-312-0/+20
* fs, udev: allow systemd-udevd various cgroup permsKenton Groombridge2023-03-312-2/+44
* logging: allow systemd-journald to list cgroupsKenton Groombridge2023-03-311-0/+2
* systemd: allow systemd-userdbd to getcapKenton Groombridge2023-03-311-1/+1
* init: allow initrc_t to getcapKenton Groombridge2023-03-311-1/+1
* init, systemd: allow init to create userdb runtime symlinksKenton Groombridge2023-03-312-0/+19
* various: make /etc/machine-id etc_runtime_tKenton Groombridge2023-03-313-0/+9
* init: make init_runtime_t useable for systemd unitsKenton Groombridge2023-03-311-0/+1
* zfs: add runtime filetrans for dirsKenton Groombridge2023-03-311-1/+1
* zfs: allow sending signals to itselfKenton Groombridge2023-03-311-1/+1
* kernel, zfs: add filetrans for kernel creating zpool cache fileKenton Groombridge2023-03-312-0/+21
* netutils: fixes for iftopKenton Groombridge2023-03-312-0/+3
* podman, selinux: move lines, add missing rules for --network=hostKenton Groombridge2023-03-312-3/+44
* redis: add missing rules for runtime filetransKenton Groombridge2023-03-311-0/+2
* node_exporter: various fixesKenton Groombridge2023-03-311-1/+8
* container: fixes for podman run --log-driver=passthroughKenton Groombridge2023-03-311-0/+3
* container: fixes for podman 4.4.0Kenton Groombridge2023-03-311-0/+7
* container, init, systemd: add policy for quadletKenton Groombridge2023-03-314-1/+34
* container: Allow user namespace creation for all container engines.Chris PeBenito2023-03-311-0/+1
* systemd: Allow user namespace creation.Chris PeBenito2023-03-312-0/+3
* mozilla: Allow user namespace creation.Chris PeBenito2023-03-311-0/+1
* chromium: Allow user namespace creation.Chris PeBenito2023-03-311-0/+1
* Define user_namespace object class.Chris PeBenito2023-03-312-0/+7
* systemd: allow systemd-sysctl to search directories on ramfsYi Zhao2023-03-311-0/+1
* systemd: add capability sys_resource to systemd_userdbd_tYi Zhao2023-03-311-1/+1
* Set label systemd-oomdLuca Boccassi2023-03-311-0/+1
* portage: add misc mising rulesCorentin LABBE2023-03-312-2/+11
* portage: cleanup duplicated file contextsKenton Groombridge2023-02-131-9/+0
* Merge upstreamKenton Groombridge2023-02-131-1/+1
* sysnetwork: Rename sysnet_dontaudit_rw_dhcpc_unix_dgram_sockets()Chris PeBenito2023-02-131-1/+1
* Signed-off-by: George Zenner <zen@pyl.onl>George Zenner2023-02-131-0/+19
* container: add missing filetrans and filecon for containerd/dockerKenton Groombridge2023-02-132-1/+2
* lvm: Add fc entry for /etc/multipath/*Chris PeBenito2023-02-131-0/+2
* iscsi: Read initiatorname.iscsi.Chris PeBenito2023-02-131-0/+2
* openvpn: Allow netlink genlDavid Sommerseth2023-02-131-0/+1