diff options
| author | Yi Zhao <yi.zhao@windriver.com> | 2026-04-21 13:55:05 +0800 |
|---|---|---|
| committer | Yi Zhao <yi.zhao@windriver.com> | 2026-06-06 22:26:06 +0800 |
| commit | 1c30b4eddcef9e0594dd15c15e1f675e2a0c93a2 (patch) | |
| tree | c018f317ed7489080f4d5429e9c9c2a8d4d49769 /recipes-security/selinux/libselinux_2.3.bb | |
| parent | 1ba26da4b9bec3f102bd831efe0db00c7d61f7f2 (diff) | |
| download | meta-selinux-master.tar.gz | |
* fbae93917 btrfs (#1144)
* da94ce004 dmesg: allow dmesg_t access to init script stream sockets
* 78f8b23d4 fapolicyd: fix issue with tmpfs_t write
* 319ac618d fsadm (#1129)
* 7d1dc1f06 systemd: allow tmpfiles to handle auditd_log_t
* d30582816 systemd: allow tmpfiles to relabel various unlabeled objects
* 01f6bb2bc systemd: allow tmpfiles to setrlimit
* d156ca9a6 sshd: guard dbus calls with optional_policy
* 6b7da9b01 sudo: guard auth_use_pam_systemd call
* cd06b5f4b authlogin: guard auth_use_pam_systemd->dbus_system_bus_client calls with optional_policy
* 586caeace Add SELinux policy support for Userspace Resource Manager (URM) (#1097)
* 4e360aab8 tor_pluggable_transports2 (#1133)
* 444f9a669 apt_dpkg_strict (#1131)
* 2cc5c825b corecommands: label /usr/share/pam/security/namespace.init as bin_t
* 6aeb605e8 authlogin: allow pam_domain to read /usr/share/pam
* d97274873 systemd: resolved has a systemd-networkd hook
* fac3aba88 systemd: allow resolved access to /etc/localtime
* a57ca559e authlogin: systemd reads /proc/sys/kernel/random/boot_id via nss
* f6e4064fe Add boolean user_ptrace to allow user domains to strace themselves
* d25098a7d incus: Update module to reflect new incus selinux support
* 73be75170 selinux: Add selinux_read_fs interface
* a75373c3b incus: Allow setting of per instance oom_score_adj
* a8ff7c56b incus: Add incus_entry_type interface
* e4684de6d incus: Fix start of virtual networking in incus >=6.15
* 4b38f2f05 virt: Add virt_relabel_images interface
* 3b11df9e2 container: Add container_write_all_container_state interface
* 0dbad021c qemu: Update incus support
* 69141a369 qemu: Add qemu_manage_image_symlinks interface
* 373d1ee9f qemu: Add qemu_write_state interface
* 6ef6df8b0 qemu: Add qemu_getattr interface
* 5684dae89 selinux: allow ModemManager to send DBus messages to initrc_t.
* a7d4c1333 libvirt_leasesh: Added read and search permission on kernel sysctls
* 75079752d systemd-coredum: Added sepolicy permission to read namespace file
* e0fd56a58 refpolicy: Addressing denial seen on alsa to allow write on event dev node
* 694c913f8 tee_supplicant: Add necessary SELinux policy for qtee_supplicant
* eb28c5a1b su: use auth_use_pam
* e396a31e2 systemd: allow user systemd-tmpfiles to setfscreate
* 26f457f50 systemd: allow systemd-userwork to speak to systemd-machined
* 8762d07ad systemd: allow systemd-nsresourced to interact w/ bpf
* 0b7c88000 kernel: treat /efi similarly to /boot
* 99d522a1d snmpd: snmpd doesn't seem to need dac_override capability
* 192fe63a2 gpg: adapt to Gentoo's app-alternatives/gpg
* ebafd639e selinux: allow seatd to use unallocated TTYs
* cea89176e https://picasa.google.com/
* 8d49a23bd matrixd: gatekeep postgresql calls in an optional policy block
* 169f725b3 newrole_t, run_init_t: call auth_run_pam()
* ffadd83c7 ping: allow execution and PTY access
* e15ac27e0 devices: Add label for /dev/isst_interface
* d4084b9fa Add new kernel security class memfd_file and new kernel permissions
* 928e3bcbb Add new policy cababilities
* 559688316 userdomain: kernel_dontaudit_request_load_module for all users
* 0e76a2a30 Add op-tee based tee supplicant policy
Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Diffstat (limited to 'recipes-security/selinux/libselinux_2.3.bb')
0 files changed, 0 insertions, 0 deletions
