summaryrefslogtreecommitdiffstats
path: root/recipes-security/selinux/libselinux_2.3.bb
diff options
context:
space:
mode:
authorYi Zhao <yi.zhao@windriver.com>2026-04-21 13:55:05 +0800
committerYi Zhao <yi.zhao@windriver.com>2026-06-06 22:26:06 +0800
commit1c30b4eddcef9e0594dd15c15e1f675e2a0c93a2 (patch)
treec018f317ed7489080f4d5429e9c9c2a8d4d49769 /recipes-security/selinux/libselinux_2.3.bb
parent1ba26da4b9bec3f102bd831efe0db00c7d61f7f2 (diff)
downloadmeta-selinux-master.tar.gz
refpolicy: update to latest git revHEADmaster
* fbae93917 btrfs (#1144) * da94ce004 dmesg: allow dmesg_t access to init script stream sockets * 78f8b23d4 fapolicyd: fix issue with tmpfs_t write * 319ac618d fsadm (#1129) * 7d1dc1f06 systemd: allow tmpfiles to handle auditd_log_t * d30582816 systemd: allow tmpfiles to relabel various unlabeled objects * 01f6bb2bc systemd: allow tmpfiles to setrlimit * d156ca9a6 sshd: guard dbus calls with optional_policy * 6b7da9b01 sudo: guard auth_use_pam_systemd call * cd06b5f4b authlogin: guard auth_use_pam_systemd->dbus_system_bus_client calls with optional_policy * 586caeace Add SELinux policy support for Userspace Resource Manager (URM) (#1097) * 4e360aab8 tor_pluggable_transports2 (#1133) * 444f9a669 apt_dpkg_strict (#1131) * 2cc5c825b corecommands: label /usr/share/pam/security/namespace.init as bin_t * 6aeb605e8 authlogin: allow pam_domain to read /usr/share/pam * d97274873 systemd: resolved has a systemd-networkd hook * fac3aba88 systemd: allow resolved access to /etc/localtime * a57ca559e authlogin: systemd reads /proc/sys/kernel/random/boot_id via nss * f6e4064fe Add boolean user_ptrace to allow user domains to strace themselves * d25098a7d incus: Update module to reflect new incus selinux support * 73be75170 selinux: Add selinux_read_fs interface * a75373c3b incus: Allow setting of per instance oom_score_adj * a8ff7c56b incus: Add incus_entry_type interface * e4684de6d incus: Fix start of virtual networking in incus >=6.15 * 4b38f2f05 virt: Add virt_relabel_images interface * 3b11df9e2 container: Add container_write_all_container_state interface * 0dbad021c qemu: Update incus support * 69141a369 qemu: Add qemu_manage_image_symlinks interface * 373d1ee9f qemu: Add qemu_write_state interface * 6ef6df8b0 qemu: Add qemu_getattr interface * 5684dae89 selinux: allow ModemManager to send DBus messages to initrc_t. * a7d4c1333 libvirt_leasesh: Added read and search permission on kernel sysctls * 75079752d systemd-coredum: Added sepolicy permission to read namespace file * e0fd56a58 refpolicy: Addressing denial seen on alsa to allow write on event dev node * 694c913f8 tee_supplicant: Add necessary SELinux policy for qtee_supplicant * eb28c5a1b su: use auth_use_pam * e396a31e2 systemd: allow user systemd-tmpfiles to setfscreate * 26f457f50 systemd: allow systemd-userwork to speak to systemd-machined * 8762d07ad systemd: allow systemd-nsresourced to interact w/ bpf * 0b7c88000 kernel: treat /efi similarly to /boot * 99d522a1d snmpd: snmpd doesn't seem to need dac_override capability * 192fe63a2 gpg: adapt to Gentoo's app-alternatives/gpg * ebafd639e selinux: allow seatd to use unallocated TTYs * cea89176e https://picasa.google.com/ * 8d49a23bd matrixd: gatekeep postgresql calls in an optional policy block * 169f725b3 newrole_t, run_init_t: call auth_run_pam() * ffadd83c7 ping: allow execution and PTY access * e15ac27e0 devices: Add label for /dev/isst_interface * d4084b9fa Add new kernel security class memfd_file and new kernel permissions * 928e3bcbb Add new policy cababilities * 559688316 userdomain: kernel_dontaudit_request_load_module for all users * 0e76a2a30 Add op-tee based tee supplicant policy Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Diffstat (limited to 'recipes-security/selinux/libselinux_2.3.bb')
0 files changed, 0 insertions, 0 deletions