From: "Jason Zaman" <perfinion@gentoo.org> To: gentoo-commits@lists.gentoo.org Subject: [gentoo-commits] proj/hardened-refpolicy:next commit in: policy/modules/contrib/ Date: Sat, 25 Feb 2017 14:59:39 +0000 (UTC) [thread overview] Message-ID: <1488034254.232701f0d9090cd34c22f350a7dfbda7c58a0ea0.perfinion@gentoo> (raw) commit: 232701f0d9090cd34c22f350a7dfbda7c58a0ea0 Author: Chris PeBenito <pebenito <AT> ieee <DOT> org> AuthorDate: Fri Feb 24 01:58:41 2017 +0000 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> CommitDate: Sat Feb 25 14:50:54 2017 +0000 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=232701f0 mailman: Fixes from Russell Coker. policy/modules/contrib/cron.if | 18 +++++++ policy/modules/contrib/cron.te | 2 +- policy/modules/contrib/mailman.fc | 24 ++++----- policy/modules/contrib/mailman.te | 100 +++++++++++++++++++++++++++++++++++--- policy/modules/contrib/mta.if | 18 +++++++ policy/modules/contrib/mta.te | 2 +- 6 files changed, 143 insertions(+), 21 deletions(-) diff --git a/policy/modules/contrib/cron.if b/policy/modules/contrib/cron.if index 6737f53c..5739d4f0 100644 --- a/policy/modules/contrib/cron.if +++ b/policy/modules/contrib/cron.if @@ -705,6 +705,24 @@ interface(`cron_manage_system_spool',` ######################################## ## <summary> +## Read and write crond temporary files. +## </summary> +## <param name="domain"> +## <summary> +## Domain allowed access. +## </summary> +## </param> +# +interface(`cron_rw_tmp_files',` + gen_require(` + type crond_tmp_t; + ') + + allow $1 crond_tmp_t:file rw_file_perms; +') + +######################################## +## <summary> ## Read system cron job lib files. ## </summary> ## <param name="domain"> diff --git a/policy/modules/contrib/cron.te b/policy/modules/contrib/cron.te index 3513e1f2..b51524a4 100644 --- a/policy/modules/contrib/cron.te +++ b/policy/modules/contrib/cron.te @@ -1,4 +1,4 @@ -policy_module(cron, 2.11.1) +policy_module(cron, 2.11.2) gen_require(` class passwd rootok; diff --git a/policy/modules/contrib/mailman.fc b/policy/modules/contrib/mailman.fc index 1a226daf..d5734fc9 100644 --- a/policy/modules/contrib/mailman.fc +++ b/policy/modules/contrib/mailman.fc @@ -2,11 +2,11 @@ /etc/mailman.* gen_context(system_u:object_r:mailman_data_t,s0) -/usr/lib/mailman.*/bin/mailmanctl -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) -/usr/lib/mailman.*/bin/mm-handler.* -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) -/usr/lib/mailman.*/cron/.* -- gen_context(system_u:object_r:mailman_queue_exec_t,s0) +/usr/lib/mailman/bin/mailmanctl -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/lib/mailman/bin/mm-handler.* -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/lib/mailman/cron/.* -- gen_context(system_u:object_r:mailman_queue_exec_t,s0) /var/lib/mailman.* gen_context(system_u:object_r:mailman_data_t,s0) -/var/lib/mailman.*/archives(/.*)? gen_context(system_u:object_r:mailman_archive_t,s0) +/var/lib/mailman/archives(/.*)? gen_context(system_u:object_r:mailman_archive_t,s0) /var/lock/mailman.* gen_context(system_u:object_r:mailman_lock_t,s0) /var/lock/subsys/mailman.* -- gen_context(system_u:object_r:mailman_lock_t,s0) @@ -17,16 +17,16 @@ /var/spool/mailman.* gen_context(system_u:object_r:mailman_data_t,s0) -/usr/lib/cgi-bin/mailman.*/.* -- gen_context(system_u:object_r:mailman_cgi_exec_t,s0) -/usr/lib/mailman.*/bin/qrunner -- gen_context(system_u:object_r:mailman_queue_exec_t,s0) -/usr/lib/mailman.*/cgi-bin/.* -- gen_context(system_u:object_r:mailman_cgi_exec_t,s0) -/usr/lib/mailman.*/mail/mailman -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) -/usr/lib/mailman.*/mail/wrapper -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) -/usr/lib/mailman.*/scripts/mailman -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/lib/cgi-bin/mailman/.* -- gen_context(system_u:object_r:mailman_cgi_exec_t,s0) +/usr/lib/mailman/bin/qrunner -- gen_context(system_u:object_r:mailman_queue_exec_t,s0) +/usr/lib/mailman/cgi-bin/.* -- gen_context(system_u:object_r:mailman_cgi_exec_t,s0) +/usr/lib/mailman/mail/mailman -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/lib/mailman/mail/wrapper -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/lib/mailman/scripts/mailman -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) -/usr/mailman.*/mail/wrapper -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/mailman/mail/wrapper -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) -/usr/share/doc/mailman.*/mm-handler.* -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/share/doc/mailman/mm-handler.* -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) ifdef(`distro_gentoo',` # Bug 536666 diff --git a/policy/modules/contrib/mailman.te b/policy/modules/contrib/mailman.te index 7421ce3a..3de43d20 100644 --- a/policy/modules/contrib/mailman.te +++ b/policy/modules/contrib/mailman.te @@ -1,4 +1,4 @@ -policy_module(mailman, 1.12.0) +policy_module(mailman, 1.12.1) ######################################## # @@ -91,12 +91,39 @@ miscfiles_read_localization(mailman_domain) # CGI local policy # +allow mailman_cgi_t self:unix_dgram_socket { create connect }; + +allow mailman_cgi_t mailman_archive_t:dir search_dir_perms; +allow mailman_cgi_t mailman_archive_t:file read_file_perms; + +allow mailman_cgi_t mailman_data_t:dir rw_dir_perms; +allow mailman_cgi_t mailman_data_t:file manage_file_perms; +allow mailman_cgi_t mailman_data_t:lnk_file read_lnk_file_perms; + +allow mailman_cgi_t mailman_lock_t:dir manage_dir_perms; +allow mailman_cgi_t mailman_lock_t:file manage_file_perms; + +allow mailman_cgi_t mailman_log_t:file { append_file_perms read_file_perms }; +allow mailman_cgi_t mailman_log_t:dir search_dir_perms; + +kernel_read_crypto_sysctls(mailman_cgi_t) +kernel_read_system_state(mailman_cgi_t) + +corecmd_exec_bin(mailman_cgi_t) + dev_read_urand(mailman_cgi_t) +files_search_locks(mailman_cgi_t) + term_use_controlling_term(mailman_cgi_t) libs_dontaudit_write_lib_dirs(mailman_cgi_t) +logging_search_logs(mailman_cgi_t) + +miscfiles_read_localization(mailman_cgi_t) + + optional_policy(` apache_sigchld(mailman_cgi_t) apache_use_fds(mailman_cgi_t) @@ -116,24 +143,61 @@ optional_policy(` # allow mailman_mail_t self:capability { dac_override kill setgid setuid sys_tty_config }; -allow mailman_mail_t self:process { signal signull }; +allow mailman_mail_t self:process { signal signull setsched }; + +allow mailman_mail_t mailman_archive_t:dir manage_dir_perms; +allow mailman_mail_t mailman_archive_t:file manage_file_perms; +allow mailman_mail_t mailman_archive_t:lnk_file manage_lnk_file_perms; + +allow mailman_mail_t mailman_data_t:dir rw_dir_perms; +allow mailman_mail_t mailman_data_t:file manage_file_perms; +allow mailman_mail_t mailman_data_t:lnk_file read_lnk_file_perms; + +allow mailman_mail_t mailman_lock_t:dir rw_dir_perms; +allow mailman_mail_t mailman_lock_t:file manage_file_perms; + +allow mailman_mail_t mailman_log_t:dir search; +allow mailman_mail_t mailman_log_t:file read_file_perms; + +domtrans_pattern(mailman_mail_t, mailman_queue_exec_t, mailman_queue_t) +allow mailman_mail_t mailman_queue_exec_t:file ioctl; + +can_exec(mailman_mail_t, mailman_mail_exec_t) manage_files_pattern(mailman_mail_t, mailman_var_run_t, mailman_var_run_t) manage_dirs_pattern(mailman_mail_t, mailman_var_run_t, mailman_var_run_t) files_pid_filetrans(mailman_mail_t, mailman_var_run_t, { file dir }) -corenet_sendrecv_innd_client_packets(mailman_mail_t) -corenet_tcp_connect_innd_port(mailman_mail_t) -corenet_tcp_sendrecv_innd_port(mailman_mail_t) +kernel_read_system_state(mailman_mail_t) +corenet_tcp_connect_smtp_port(mailman_mail_t) corenet_sendrecv_spamd_client_packets(mailman_mail_t) +corenet_sendrecv_innd_client_packets(mailman_mail_t) +corenet_tcp_connect_innd_port(mailman_mail_t) corenet_tcp_connect_spamd_port(mailman_mail_t) +corenet_tcp_sendrecv_innd_port(mailman_mail_t) corenet_tcp_sendrecv_spamd_port(mailman_mail_t) dev_read_urand(mailman_mail_t) +corecmd_exec_bin(mailman_mail_t) + +files_search_locks(mailman_mail_t) + fs_rw_anon_inodefs_files(mailman_mail_t) +# this is far from ideal, but systemd reduces the importance of initrc_t +init_signal_script(mailman_mail_t) +init_signull_script(mailman_mail_t) + +# for python .path file +libs_read_lib_files(mailman_mail_t) + +logging_search_logs(mailman_mail_t) + +miscfiles_read_localization(mailman_mail_t) + +mta_use_mailserver_fds(mailman_mail_t) mta_dontaudit_rw_delivery_tcp_sockets(mailman_mail_t) mta_dontaudit_rw_queue(mailman_mail_t) @@ -159,18 +223,40 @@ allow mailman_queue_t self:capability { setgid setuid }; allow mailman_queue_t self:process { setsched signal_perms }; allow mailman_queue_t self:fifo_file rw_fifo_file_perms; +allow mailman_queue_t mailman_archive_t:dir manage_dir_perms; +allow mailman_queue_t mailman_archive_t:file manage_file_perms; + +allow mailman_queue_t mailman_data_t:dir rw_dir_perms; +allow mailman_queue_t mailman_data_t:file manage_file_perms; +allow mailman_queue_t mailman_data_t:lnk_file read_lnk_file_perms; + +allow mailman_queue_t mailman_lock_t:dir rw_dir_perms; +allow mailman_queue_t mailman_lock_t:file manage_file_perms; + +allow mailman_queue_t mailman_log_t:dir list_dir_perms; +allow mailman_queue_t mailman_log_t:file manage_file_perms; + +kernel_read_system_state(mailman_queue_t) + +auth_domtrans_chk_passwd(mailman_queue_t) + +corecmd_read_bin_files(mailman_queue_t) +corecmd_read_bin_symlinks(mailman_queue_t) corenet_sendrecv_innd_client_packets(mailman_queue_t) corenet_tcp_connect_innd_port(mailman_queue_t) corenet_tcp_sendrecv_innd_port(mailman_queue_t) -auth_domtrans_chk_passwd(mailman_queue_t) - files_dontaudit_search_pids(mailman_queue_t) +files_search_locks(mailman_queue_t) + +miscfiles_read_localization(mailman_queue_t) seutil_dontaudit_search_config(mailman_queue_t) userdom_search_user_home_dirs(mailman_queue_t) +cron_rw_tmp_files(mailman_queue_t) + optional_policy(` apache_read_config(mailman_queue_t) ') diff --git a/policy/modules/contrib/mta.if b/policy/modules/contrib/mta.if index a5034276..7e268b80 100644 --- a/policy/modules/contrib/mta.if +++ b/policy/modules/contrib/mta.if @@ -338,6 +338,24 @@ interface(`mta_sendmail_mailserver',` typeattribute $1 mailserver_domain; ') +######################################## +## <summary> +## Inherit FDs from mailserver_domain domains +## </summary> +## <param name="type"> +## <summary> +## Type for a list server or delivery agent that inherits fds +## </summary> +## </param> +# +interface(`mta_use_mailserver_fds',` + gen_require(` + attribute mailserver_domain; + ') + + allow $1 mailserver_domain:fd use; +') + ####################################### ## <summary> ## Make a type a mailserver type used diff --git a/policy/modules/contrib/mta.te b/policy/modules/contrib/mta.te index 9a3ee20e..f7280b11 100644 --- a/policy/modules/contrib/mta.te +++ b/policy/modules/contrib/mta.te @@ -1,4 +1,4 @@ -policy_module(mta, 2.8.1) +policy_module(mta, 2.8.2) ######################################## #
WARNING: multiple messages have this Message-ID (diff)
From: "Jason Zaman" <perfinion@gentoo.org> To: gentoo-commits@lists.gentoo.org Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/contrib/ Date: Sat, 25 Feb 2017 14:51:43 +0000 (UTC) [thread overview] Message-ID: <1488034254.232701f0d9090cd34c22f350a7dfbda7c58a0ea0.perfinion@gentoo> (raw) Message-ID: <20170225145143.OJsZrwqMWh-c-e3NoKE1eUpFa1jKwb8MF3AIh8-iAMg@z> (raw) commit: 232701f0d9090cd34c22f350a7dfbda7c58a0ea0 Author: Chris PeBenito <pebenito <AT> ieee <DOT> org> AuthorDate: Fri Feb 24 01:58:41 2017 +0000 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> CommitDate: Sat Feb 25 14:50:54 2017 +0000 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=232701f0 mailman: Fixes from Russell Coker. policy/modules/contrib/cron.if | 18 +++++++ policy/modules/contrib/cron.te | 2 +- policy/modules/contrib/mailman.fc | 24 ++++----- policy/modules/contrib/mailman.te | 100 +++++++++++++++++++++++++++++++++++--- policy/modules/contrib/mta.if | 18 +++++++ policy/modules/contrib/mta.te | 2 +- 6 files changed, 143 insertions(+), 21 deletions(-) diff --git a/policy/modules/contrib/cron.if b/policy/modules/contrib/cron.if index 6737f53c..5739d4f0 100644 --- a/policy/modules/contrib/cron.if +++ b/policy/modules/contrib/cron.if @@ -705,6 +705,24 @@ interface(`cron_manage_system_spool',` ######################################## ## <summary> +## Read and write crond temporary files. +## </summary> +## <param name="domain"> +## <summary> +## Domain allowed access. +## </summary> +## </param> +# +interface(`cron_rw_tmp_files',` + gen_require(` + type crond_tmp_t; + ') + + allow $1 crond_tmp_t:file rw_file_perms; +') + +######################################## +## <summary> ## Read system cron job lib files. ## </summary> ## <param name="domain"> diff --git a/policy/modules/contrib/cron.te b/policy/modules/contrib/cron.te index 3513e1f2..b51524a4 100644 --- a/policy/modules/contrib/cron.te +++ b/policy/modules/contrib/cron.te @@ -1,4 +1,4 @@ -policy_module(cron, 2.11.1) +policy_module(cron, 2.11.2) gen_require(` class passwd rootok; diff --git a/policy/modules/contrib/mailman.fc b/policy/modules/contrib/mailman.fc index 1a226daf..d5734fc9 100644 --- a/policy/modules/contrib/mailman.fc +++ b/policy/modules/contrib/mailman.fc @@ -2,11 +2,11 @@ /etc/mailman.* gen_context(system_u:object_r:mailman_data_t,s0) -/usr/lib/mailman.*/bin/mailmanctl -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) -/usr/lib/mailman.*/bin/mm-handler.* -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) -/usr/lib/mailman.*/cron/.* -- gen_context(system_u:object_r:mailman_queue_exec_t,s0) +/usr/lib/mailman/bin/mailmanctl -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/lib/mailman/bin/mm-handler.* -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/lib/mailman/cron/.* -- gen_context(system_u:object_r:mailman_queue_exec_t,s0) /var/lib/mailman.* gen_context(system_u:object_r:mailman_data_t,s0) -/var/lib/mailman.*/archives(/.*)? gen_context(system_u:object_r:mailman_archive_t,s0) +/var/lib/mailman/archives(/.*)? gen_context(system_u:object_r:mailman_archive_t,s0) /var/lock/mailman.* gen_context(system_u:object_r:mailman_lock_t,s0) /var/lock/subsys/mailman.* -- gen_context(system_u:object_r:mailman_lock_t,s0) @@ -17,16 +17,16 @@ /var/spool/mailman.* gen_context(system_u:object_r:mailman_data_t,s0) -/usr/lib/cgi-bin/mailman.*/.* -- gen_context(system_u:object_r:mailman_cgi_exec_t,s0) -/usr/lib/mailman.*/bin/qrunner -- gen_context(system_u:object_r:mailman_queue_exec_t,s0) -/usr/lib/mailman.*/cgi-bin/.* -- gen_context(system_u:object_r:mailman_cgi_exec_t,s0) -/usr/lib/mailman.*/mail/mailman -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) -/usr/lib/mailman.*/mail/wrapper -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) -/usr/lib/mailman.*/scripts/mailman -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/lib/cgi-bin/mailman/.* -- gen_context(system_u:object_r:mailman_cgi_exec_t,s0) +/usr/lib/mailman/bin/qrunner -- gen_context(system_u:object_r:mailman_queue_exec_t,s0) +/usr/lib/mailman/cgi-bin/.* -- gen_context(system_u:object_r:mailman_cgi_exec_t,s0) +/usr/lib/mailman/mail/mailman -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/lib/mailman/mail/wrapper -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/lib/mailman/scripts/mailman -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) -/usr/mailman.*/mail/wrapper -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/mailman/mail/wrapper -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) -/usr/share/doc/mailman.*/mm-handler.* -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) +/usr/share/doc/mailman/mm-handler.* -- gen_context(system_u:object_r:mailman_mail_exec_t,s0) ifdef(`distro_gentoo',` # Bug 536666 diff --git a/policy/modules/contrib/mailman.te b/policy/modules/contrib/mailman.te index 7421ce3a..3de43d20 100644 --- a/policy/modules/contrib/mailman.te +++ b/policy/modules/contrib/mailman.te @@ -1,4 +1,4 @@ -policy_module(mailman, 1.12.0) +policy_module(mailman, 1.12.1) ######################################## # @@ -91,12 +91,39 @@ miscfiles_read_localization(mailman_domain) # CGI local policy # +allow mailman_cgi_t self:unix_dgram_socket { create connect }; + +allow mailman_cgi_t mailman_archive_t:dir search_dir_perms; +allow mailman_cgi_t mailman_archive_t:file read_file_perms; + +allow mailman_cgi_t mailman_data_t:dir rw_dir_perms; +allow mailman_cgi_t mailman_data_t:file manage_file_perms; +allow mailman_cgi_t mailman_data_t:lnk_file read_lnk_file_perms; + +allow mailman_cgi_t mailman_lock_t:dir manage_dir_perms; +allow mailman_cgi_t mailman_lock_t:file manage_file_perms; + +allow mailman_cgi_t mailman_log_t:file { append_file_perms read_file_perms }; +allow mailman_cgi_t mailman_log_t:dir search_dir_perms; + +kernel_read_crypto_sysctls(mailman_cgi_t) +kernel_read_system_state(mailman_cgi_t) + +corecmd_exec_bin(mailman_cgi_t) + dev_read_urand(mailman_cgi_t) +files_search_locks(mailman_cgi_t) + term_use_controlling_term(mailman_cgi_t) libs_dontaudit_write_lib_dirs(mailman_cgi_t) +logging_search_logs(mailman_cgi_t) + +miscfiles_read_localization(mailman_cgi_t) + + optional_policy(` apache_sigchld(mailman_cgi_t) apache_use_fds(mailman_cgi_t) @@ -116,24 +143,61 @@ optional_policy(` # allow mailman_mail_t self:capability { dac_override kill setgid setuid sys_tty_config }; -allow mailman_mail_t self:process { signal signull }; +allow mailman_mail_t self:process { signal signull setsched }; + +allow mailman_mail_t mailman_archive_t:dir manage_dir_perms; +allow mailman_mail_t mailman_archive_t:file manage_file_perms; +allow mailman_mail_t mailman_archive_t:lnk_file manage_lnk_file_perms; + +allow mailman_mail_t mailman_data_t:dir rw_dir_perms; +allow mailman_mail_t mailman_data_t:file manage_file_perms; +allow mailman_mail_t mailman_data_t:lnk_file read_lnk_file_perms; + +allow mailman_mail_t mailman_lock_t:dir rw_dir_perms; +allow mailman_mail_t mailman_lock_t:file manage_file_perms; + +allow mailman_mail_t mailman_log_t:dir search; +allow mailman_mail_t mailman_log_t:file read_file_perms; + +domtrans_pattern(mailman_mail_t, mailman_queue_exec_t, mailman_queue_t) +allow mailman_mail_t mailman_queue_exec_t:file ioctl; + +can_exec(mailman_mail_t, mailman_mail_exec_t) manage_files_pattern(mailman_mail_t, mailman_var_run_t, mailman_var_run_t) manage_dirs_pattern(mailman_mail_t, mailman_var_run_t, mailman_var_run_t) files_pid_filetrans(mailman_mail_t, mailman_var_run_t, { file dir }) -corenet_sendrecv_innd_client_packets(mailman_mail_t) -corenet_tcp_connect_innd_port(mailman_mail_t) -corenet_tcp_sendrecv_innd_port(mailman_mail_t) +kernel_read_system_state(mailman_mail_t) +corenet_tcp_connect_smtp_port(mailman_mail_t) corenet_sendrecv_spamd_client_packets(mailman_mail_t) +corenet_sendrecv_innd_client_packets(mailman_mail_t) +corenet_tcp_connect_innd_port(mailman_mail_t) corenet_tcp_connect_spamd_port(mailman_mail_t) +corenet_tcp_sendrecv_innd_port(mailman_mail_t) corenet_tcp_sendrecv_spamd_port(mailman_mail_t) dev_read_urand(mailman_mail_t) +corecmd_exec_bin(mailman_mail_t) + +files_search_locks(mailman_mail_t) + fs_rw_anon_inodefs_files(mailman_mail_t) +# this is far from ideal, but systemd reduces the importance of initrc_t +init_signal_script(mailman_mail_t) +init_signull_script(mailman_mail_t) + +# for python .path file +libs_read_lib_files(mailman_mail_t) + +logging_search_logs(mailman_mail_t) + +miscfiles_read_localization(mailman_mail_t) + +mta_use_mailserver_fds(mailman_mail_t) mta_dontaudit_rw_delivery_tcp_sockets(mailman_mail_t) mta_dontaudit_rw_queue(mailman_mail_t) @@ -159,18 +223,40 @@ allow mailman_queue_t self:capability { setgid setuid }; allow mailman_queue_t self:process { setsched signal_perms }; allow mailman_queue_t self:fifo_file rw_fifo_file_perms; +allow mailman_queue_t mailman_archive_t:dir manage_dir_perms; +allow mailman_queue_t mailman_archive_t:file manage_file_perms; + +allow mailman_queue_t mailman_data_t:dir rw_dir_perms; +allow mailman_queue_t mailman_data_t:file manage_file_perms; +allow mailman_queue_t mailman_data_t:lnk_file read_lnk_file_perms; + +allow mailman_queue_t mailman_lock_t:dir rw_dir_perms; +allow mailman_queue_t mailman_lock_t:file manage_file_perms; + +allow mailman_queue_t mailman_log_t:dir list_dir_perms; +allow mailman_queue_t mailman_log_t:file manage_file_perms; + +kernel_read_system_state(mailman_queue_t) + +auth_domtrans_chk_passwd(mailman_queue_t) + +corecmd_read_bin_files(mailman_queue_t) +corecmd_read_bin_symlinks(mailman_queue_t) corenet_sendrecv_innd_client_packets(mailman_queue_t) corenet_tcp_connect_innd_port(mailman_queue_t) corenet_tcp_sendrecv_innd_port(mailman_queue_t) -auth_domtrans_chk_passwd(mailman_queue_t) - files_dontaudit_search_pids(mailman_queue_t) +files_search_locks(mailman_queue_t) + +miscfiles_read_localization(mailman_queue_t) seutil_dontaudit_search_config(mailman_queue_t) userdom_search_user_home_dirs(mailman_queue_t) +cron_rw_tmp_files(mailman_queue_t) + optional_policy(` apache_read_config(mailman_queue_t) ') diff --git a/policy/modules/contrib/mta.if b/policy/modules/contrib/mta.if index a5034276..7e268b80 100644 --- a/policy/modules/contrib/mta.if +++ b/policy/modules/contrib/mta.if @@ -338,6 +338,24 @@ interface(`mta_sendmail_mailserver',` typeattribute $1 mailserver_domain; ') +######################################## +## <summary> +## Inherit FDs from mailserver_domain domains +## </summary> +## <param name="type"> +## <summary> +## Type for a list server or delivery agent that inherits fds +## </summary> +## </param> +# +interface(`mta_use_mailserver_fds',` + gen_require(` + attribute mailserver_domain; + ') + + allow $1 mailserver_domain:fd use; +') + ####################################### ## <summary> ## Make a type a mailserver type used diff --git a/policy/modules/contrib/mta.te b/policy/modules/contrib/mta.te index 9a3ee20e..f7280b11 100644 --- a/policy/modules/contrib/mta.te +++ b/policy/modules/contrib/mta.te @@ -1,4 +1,4 @@ -policy_module(mta, 2.8.1) +policy_module(mta, 2.8.2) ######################################## #
next reply other threads:[~2017-02-25 15:00 UTC|newest] Thread overview: 414+ messages / expand[flat|nested] mbox.gz Atom feed top 2017-02-25 14:59 Jason Zaman [this message] 2017-02-25 14:51 ` [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/contrib/ Jason Zaman -- strict thread matches above, loose matches on Subject: below -- 2017-09-10 14:03 [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-09-10 14:03 Jason Zaman 2017-09-10 14:03 Jason Zaman 2017-09-10 14:03 Jason Zaman 2017-09-10 14:03 Jason Zaman 2017-09-10 14:03 Jason Zaman 2017-09-10 14:03 Jason Zaman 2017-09-10 14:03 Jason Zaman 2017-09-10 14:03 Jason Zaman 2017-09-10 14:03 Jason Zaman 2017-09-10 14:03 Jason Zaman 2017-09-10 14:03 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:08 Jason Zaman 2017-05-25 17:04 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-05-25 17:08 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:47 Jason Zaman 2017-05-07 17:41 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-05-07 17:47 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-05-07 16:09 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-05-07 17:47 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-05-07 16:09 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-05-07 17:47 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-05-07 16:09 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-05-07 17:47 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-05-07 16:09 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-05-07 17:47 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:40 Jason Zaman 2017-04-30 9:32 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-04-30 9:40 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-04-30 9:32 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-04-30 9:40 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-04-30 9:32 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-04-30 9:40 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-04-30 9:32 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-04-30 9:40 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-04-30 9:32 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-04-30 9:40 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-04-30 9:32 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-04-30 9:40 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:09 Jason Zaman 2017-03-30 17:06 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-03-30 17:09 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-03-30 17:06 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-03-30 17:09 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-03-30 17:06 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-03-30 17:09 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-03-30 17:06 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-03-30 17:09 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-03-30 17:06 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-03-30 17:09 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-02-27 11:40 Jason Zaman 2017-02-27 11:40 Jason Zaman 2017-02-27 11:40 Jason Zaman 2017-02-27 11:40 Jason Zaman 2017-02-27 11:40 Jason Zaman 2017-02-27 11:40 Jason Zaman 2017-02-27 11:40 Jason Zaman 2017-02-27 11:40 Jason Zaman 2017-02-27 10:50 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-02-27 11:40 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-02-25 16:58 Jason Zaman 2017-02-25 16:58 Jason Zaman 2017-02-25 16:58 Jason Zaman 2017-02-25 16:58 Jason Zaman 2017-02-25 16:58 Jason Zaman 2017-02-25 16:58 Jason Zaman 2017-02-25 16:58 Jason Zaman 2017-02-25 16:58 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-02-25 16:58 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-02-25 15:28 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-02-25 16:58 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-02-25 14:59 Jason Zaman 2017-02-25 14:59 Jason Zaman 2017-02-25 14:59 Jason Zaman 2017-02-25 14:59 Jason Zaman 2017-02-25 14:59 Jason Zaman 2017-02-25 14:59 Jason Zaman 2017-02-25 14:59 Jason Zaman 2017-02-25 14:59 Jason Zaman 2017-02-25 14:59 Jason Zaman 2017-02-25 14:59 Jason Zaman 2017-02-25 14:51 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-02-25 14:59 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-02-25 14:51 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-02-25 14:59 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-02-25 14:51 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-02-25 14:59 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-02-17 8:50 Jason Zaman 2017-02-17 8:50 Jason Zaman 2017-02-17 8:50 Jason Zaman 2017-02-17 8:50 Jason Zaman 2017-02-17 8:50 Jason Zaman 2017-02-17 8:50 Jason Zaman 2017-02-17 8:50 Jason Zaman 2017-02-17 8:50 Jason Zaman 2017-02-17 8:50 Jason Zaman 2017-02-17 8:50 Jason Zaman 2017-02-17 8:50 Jason Zaman 2017-02-17 8:50 Jason Zaman 2017-02-17 8:44 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-02-17 8:50 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-02-17 8:44 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-02-17 8:50 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-02-17 8:44 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-02-17 8:50 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-02-17 8:44 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-02-17 8:50 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-02-17 8:44 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-02-17 8:50 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-02-17 8:44 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2017-02-17 8:50 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2017-01-01 16:47 Jason Zaman 2017-01-01 16:47 Jason Zaman 2017-01-01 16:47 Jason Zaman 2017-01-01 16:47 Jason Zaman 2017-01-01 16:47 Jason Zaman 2017-01-01 16:37 Jason Zaman 2017-01-01 16:37 Jason Zaman 2017-01-01 16:37 Jason Zaman 2017-01-01 16:37 Jason Zaman 2017-01-01 16:37 Jason Zaman 2016-12-08 5:03 Jason Zaman 2016-12-08 5:03 Jason Zaman 2016-12-08 5:03 Jason Zaman 2016-12-08 5:03 Jason Zaman 2016-12-08 5:03 Jason Zaman 2016-12-08 5:03 Jason Zaman 2016-12-08 4:47 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-12-08 5:03 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-12-06 15:10 Jason Zaman 2016-12-06 15:10 Jason Zaman 2016-12-06 15:10 Jason Zaman 2016-12-06 15:10 Jason Zaman 2016-12-06 15:10 Jason Zaman 2016-12-06 15:10 Jason Zaman 2016-12-06 14:25 Jason Zaman 2016-12-06 14:25 Jason Zaman 2016-12-06 14:25 Jason Zaman 2016-12-06 14:25 Jason Zaman 2016-12-06 14:25 Jason Zaman 2016-12-06 14:25 Jason Zaman 2016-12-06 14:25 Jason Zaman 2016-12-06 14:25 Jason Zaman 2016-12-06 14:25 Jason Zaman 2016-12-06 14:21 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-12-06 14:25 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-12-06 13:39 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-12-06 14:25 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-12-06 13:39 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-12-06 14:25 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-12-06 13:39 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-12-06 14:25 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-12-06 13:39 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-12-06 14:25 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-12-06 13:39 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-12-06 14:25 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-12-06 13:39 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-12-06 14:25 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-12-06 13:39 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-12-06 14:25 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-12-06 13:39 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-12-06 14:25 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-12-06 13:39 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-12-06 14:25 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-10-26 11:08 Jason Zaman 2016-10-26 11:08 Jason Zaman 2016-10-26 11:08 Jason Zaman 2016-10-26 11:08 Jason Zaman 2016-10-26 11:08 Jason Zaman 2016-10-26 11:08 Jason Zaman 2016-10-26 11:08 Jason Zaman 2016-10-24 17:14 Sven Vermeulen 2016-10-24 17:14 Sven Vermeulen 2016-10-24 17:14 Sven Vermeulen 2016-10-24 17:14 Sven Vermeulen 2016-10-24 17:14 Sven Vermeulen 2016-10-24 16:56 [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen 2016-10-24 17:13 ` [gentoo-commits] proj/hardened-refpolicy:next " Sven Vermeulen 2016-10-24 16:03 Sven Vermeulen 2016-10-24 16:03 Sven Vermeulen 2016-10-24 16:03 Sven Vermeulen 2016-10-24 16:03 Sven Vermeulen 2016-10-24 16:03 Sven Vermeulen 2016-10-24 16:03 Sven Vermeulen 2016-10-24 16:03 Sven Vermeulen 2016-10-24 16:02 [gentoo-commits] proj/hardened-refpolicy:swift " Sven Vermeulen 2016-10-24 16:03 ` [gentoo-commits] proj/hardened-refpolicy:next " Sven Vermeulen 2016-10-24 16:02 [gentoo-commits] proj/hardened-refpolicy:swift " Sven Vermeulen 2016-10-24 16:03 ` [gentoo-commits] proj/hardened-refpolicy:next " Sven Vermeulen 2016-10-24 16:02 [gentoo-commits] proj/hardened-refpolicy:swift " Sven Vermeulen 2016-10-24 16:03 ` [gentoo-commits] proj/hardened-refpolicy:next " Sven Vermeulen 2016-10-24 16:02 [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen 2016-10-24 16:03 ` [gentoo-commits] proj/hardened-refpolicy:next " Sven Vermeulen 2016-10-24 15:44 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:26 Jason Zaman 2016-10-03 6:20 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-10-03 6:26 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-10-03 6:20 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-10-03 6:26 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-10-03 6:20 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-10-03 6:26 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-10-03 6:20 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-10-03 6:26 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-10-03 6:20 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-10-03 6:26 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-10-03 6:20 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-10-03 6:26 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-10-03 6:20 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-10-03 6:26 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-08-17 16:59 Jason Zaman 2016-08-17 16:59 Jason Zaman 2016-08-17 16:59 Jason Zaman 2016-08-17 16:59 Jason Zaman 2016-08-17 16:59 Jason Zaman 2016-08-17 16:59 Jason Zaman 2016-08-17 16:59 Jason Zaman 2016-08-17 16:59 Jason Zaman 2016-08-17 16:59 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-08-17 16:59 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-08-17 16:59 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-08-17 16:59 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-08-17 16:59 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-08-17 16:59 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-08-13 18:35 Jason Zaman 2016-08-13 18:35 Jason Zaman 2016-08-13 18:35 Jason Zaman 2016-08-13 18:35 Jason Zaman 2016-08-13 18:35 Jason Zaman 2016-08-13 18:35 Jason Zaman 2016-08-13 18:35 Jason Zaman 2016-08-13 18:35 Jason Zaman 2016-08-13 18:35 Jason Zaman 2016-08-13 18:35 Jason Zaman 2016-08-13 18:35 Jason Zaman 2016-08-13 18:35 Jason Zaman 2016-08-13 18:32 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-08-13 18:35 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-08-13 18:32 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-08-13 18:35 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-08-13 18:32 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-08-13 18:35 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-08-13 18:32 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-08-13 18:35 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-08-13 18:32 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-08-13 18:35 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-08-13 18:32 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2016-08-13 18:35 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2016-05-26 19:28 Jason Zaman 2016-05-26 19:28 Jason Zaman 2016-05-26 17:39 Jason Zaman 2016-05-26 17:39 Jason Zaman 2016-05-26 15:54 Jason Zaman 2016-05-26 15:54 Jason Zaman 2015-12-18 4:14 Jason Zaman 2015-12-18 3:49 Jason Zaman 2015-12-17 18:52 Jason Zaman 2015-12-17 18:49 Jason Zaman 2015-12-17 18:49 Jason Zaman 2015-12-17 18:49 Jason Zaman 2015-12-17 18:49 Jason Zaman 2015-12-17 18:49 Jason Zaman 2015-12-17 18:49 Jason Zaman 2015-12-17 18:49 Jason Zaman 2015-12-17 18:49 Jason Zaman 2015-12-17 18:49 Jason Zaman 2015-12-17 18:49 Jason Zaman 2015-12-17 18:49 Jason Zaman 2015-12-17 16:10 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-12-17 18:49 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-12-17 16:10 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-12-17 18:49 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-12-17 16:10 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-12-17 18:49 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-12-17 16:10 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-12-17 18:49 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-12-17 16:10 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-12-17 18:49 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-12-17 16:10 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-12-17 18:49 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-11-23 13:42 Jason Zaman 2015-11-22 10:14 Jason Zaman 2015-11-22 10:14 Jason Zaman 2015-10-26 5:48 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-10-26 5:36 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-10-26 5:48 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-10-26 5:36 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-10-26 5:36 Jason Zaman 2015-10-22 13:44 Jason Zaman 2015-10-17 17:02 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-10-17 17:02 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-10-17 17:02 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-10-17 17:02 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-10-17 17:02 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-10-17 17:02 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-10-17 17:02 Jason Zaman 2015-10-11 10:48 Jason Zaman 2015-10-11 10:48 Jason Zaman 2015-09-20 7:00 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-10-11 10:48 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-09-06 11:25 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-09-06 11:23 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-09-06 11:25 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-09-06 11:23 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-09-06 11:23 Jason Zaman 2015-09-06 11:23 Jason Zaman 2015-09-02 14:41 Jason Zaman 2015-09-02 14:41 Jason Zaman 2015-08-27 19:52 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-08-27 19:52 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-08-27 19:11 Jason Zaman 2015-08-27 19:11 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-08-27 19:11 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-08-27 19:11 Jason Zaman 2015-08-27 19:11 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-08-27 19:11 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-08-27 19:11 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-08-27 19:11 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-08-27 19:11 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-08-27 19:11 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-08-27 18:58 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-08-26 6:46 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-08-27 18:00 Jason Zaman 2015-08-27 17:49 Jason Zaman 2015-08-27 13:26 Jason Zaman 2015-08-26 6:46 Jason Zaman 2015-08-26 6:46 Jason Zaman 2015-08-26 6:46 Jason Zaman 2015-08-26 6:46 Jason Zaman 2015-08-23 4:13 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-08-26 6:46 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-08-02 19:06 Jason Zaman 2015-08-02 19:06 Jason Zaman 2015-08-02 19:06 Jason Zaman 2015-08-02 19:06 Jason Zaman 2015-08-02 19:06 Jason Zaman 2015-08-02 19:06 Jason Zaman 2015-07-31 14:15 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-08-02 19:06 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-07-13 21:45 Jason Zaman 2015-07-13 21:45 Jason Zaman 2015-07-13 21:45 Jason Zaman 2015-07-13 21:45 Jason Zaman 2015-07-13 21:45 Jason Zaman 2015-07-13 21:45 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-07-13 21:45 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-07-13 21:45 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-07-13 21:45 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-07-13 20:59 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-07-13 21:45 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-07-11 19:57 Jason Zaman 2015-07-11 19:57 Jason Zaman 2015-07-11 19:57 Jason Zaman 2015-07-11 19:57 Jason Zaman 2015-07-11 19:57 Jason Zaman 2015-07-11 19:55 Jason Zaman 2015-07-11 19:52 Jason Zaman 2015-07-11 19:52 Jason Zaman 2015-07-11 19:52 Jason Zaman 2015-07-11 19:52 Jason Zaman 2015-07-11 19:52 Jason Zaman 2015-07-11 19:52 Jason Zaman 2015-07-02 19:28 Jason Zaman 2015-07-02 18:37 Jason Zaman 2015-07-02 18:07 Jason Zaman 2015-07-02 18:07 Jason Zaman 2015-07-02 18:07 Jason Zaman 2015-07-02 18:07 Jason Zaman 2015-07-02 17:07 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-07-02 18:07 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-05-11 22:57 Jason Zaman 2015-05-11 22:10 Jason Zaman 2015-05-11 21:49 Jason Zaman 2015-03-29 10:01 Jason Zaman 2015-03-29 10:01 Jason Zaman 2015-03-29 10:01 Jason Zaman 2015-03-29 10:01 Jason Zaman 2015-03-29 9:59 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-03-29 10:01 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-03-25 16:01 Jason Zaman 2015-03-25 16:01 Jason Zaman 2015-03-25 16:01 Jason Zaman 2015-03-25 16:01 Jason Zaman 2015-03-25 16:01 Jason Zaman 2015-03-25 16:01 Jason Zaman 2015-03-25 16:01 Jason Zaman 2015-03-25 16:01 Jason Zaman 2015-03-25 16:01 Jason Zaman 2015-03-25 16:01 Jason Zaman 2015-03-25 16:01 Jason Zaman 2015-03-25 15:55 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-03-25 16:01 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-03-25 2:17 Jason Zaman 2015-03-24 13:25 Jason Zaman 2015-03-24 13:25 Jason Zaman 2015-03-23 14:58 Jason Zaman 2015-03-23 14:58 Jason Zaman 2015-03-23 14:58 Jason Zaman 2015-03-04 17:03 Sven Vermeulen 2015-03-04 17:03 Sven Vermeulen 2015-02-24 17:11 Jason Zaman 2015-02-24 17:11 Jason Zaman 2015-02-24 17:11 Jason Zaman 2015-02-24 17:11 Jason Zaman 2015-02-24 17:11 Jason Zaman 2015-02-24 17:11 Jason Zaman 2015-02-24 17:11 Jason Zaman 2015-02-24 17:11 Jason Zaman 2015-02-09 18:35 [gentoo-commits] proj/hardened-refpolicy:adminroles " Jason Zaman 2015-02-09 18:33 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-02-09 18:33 Jason Zaman 2015-01-29 9:12 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-01-29 8:38 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-01-29 9:12 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-01-29 8:38 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-01-29 8:38 Jason Zaman 2015-01-29 8:38 Jason Zaman 2015-01-29 8:38 Jason Zaman 2015-01-29 6:51 Jason Zaman 2015-01-29 6:51 Jason Zaman 2015-01-29 6:51 Jason Zaman 2015-01-29 6:51 Jason Zaman 2015-01-29 6:51 Jason Zaman 2015-01-26 5:59 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2015-01-29 6:51 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2015-01-25 13:46 Sven Vermeulen 2015-01-25 13:46 Sven Vermeulen 2015-01-25 13:46 Sven Vermeulen 2015-01-25 13:46 Sven Vermeulen 2015-01-25 13:46 Sven Vermeulen 2015-01-20 15:08 Jason Zaman 2015-01-20 15:08 Jason Zaman 2015-01-20 15:08 Jason Zaman 2015-01-20 15:08 Jason Zaman 2015-01-20 15:08 Jason Zaman 2014-12-21 12:49 [gentoo-commits] proj/hardened-refpolicy:master " Jason Zaman 2014-12-20 15:49 ` [gentoo-commits] proj/hardened-refpolicy:next " Jason Zaman 2014-11-28 11:16 Sven Vermeulen 2014-11-28 10:44 Sven Vermeulen 2014-11-28 9:40 [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen 2014-11-28 10:04 ` [gentoo-commits] proj/hardened-refpolicy:next " Sven Vermeulen 2014-11-23 13:22 [gentoo-commits] proj/hardened-refpolicy:master " Sven Vermeulen 2014-11-28 10:04 ` [gentoo-commits] proj/hardened-refpolicy:next " Sven Vermeulen
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=1488034254.232701f0d9090cd34c22f350a7dfbda7c58a0ea0.perfinion@gentoo \ --to=perfinion@gentoo.org \ --cc=gentoo-commits@lists.gentoo.org \ --cc=gentoo-dev@lists.gentoo.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: linkBe sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox