350b6ab trunk: merge strict and targeted policies. merge shlib_t into lib_t.

Authored and Committed by Chris PeBenito 16 years ago
299 files changed. 1883 lines added. 3575 lines removed.
Changelog
file modified
+6 -0
Makefile
file modified
+2 -12
README
file modified
+4 -8
build.conf
file modified
+2 -4
config/appconfig-mcs/dbus_contextsconfig/appconfig-strict-mcs/dbus_contexts
file renamed
+0 -0
config/appconfig-mcs/default_contexts
file added
+15
config/appconfig-mcs/default_typeconfig/appconfig-strict-mcs/default_type
file renamed
+1 -0
config/appconfig-mcs/failsafe_contextconfig/appconfig-strict-mcs/failsafe_context
file renamed
+0 -0
config/appconfig-mcs/initrc_contextconfig/appconfig-strict-mcs/initrc_context
file renamed
+0 -0
config/appconfig-mcs/mediaconfig/appconfig-strict-mcs/media
file renamed
+0 -0
config/appconfig-mcs/removable_contextconfig/appconfig-strict-mcs/removable_context
file renamed
+0 -0
config/appconfig-mcs/root_default_contexts
file added
+11
config/appconfig-mcs/seusersconfig/appconfig-strict-mcs/seusers
file renamed
+0 -0
config/appconfig-mcs/userhelper_contextconfig/appconfig-strict-mcs/userhelper_context
file renamed
+0 -0
config/appconfig-mls/dbus_contextsconfig/appconfig-strict-mls/dbus_contexts
file renamed
+0 -0
config/appconfig-mls/default_contexts
file added
+15
config/appconfig-mls/default_typeconfig/appconfig-strict-mls/default_type
file renamed
+3 -2
config/appconfig-mls/failsafe_contextconfig/appconfig-strict-mls/failsafe_context
file renamed
+0 -0
config/appconfig-mls/initrc_contextconfig/appconfig-strict-mls/initrc_context
file renamed
+0 -0
config/appconfig-mls/mediaconfig/appconfig-strict-mls/media
file renamed
+0 -0
config/appconfig-mls/removable_contextconfig/appconfig-strict-mls/removable_context
file renamed
+0 -0
config/appconfig-mls/root_default_contexts
file added
+11
config/appconfig-mls/seusersconfig/appconfig-strict-mls/seusers
file renamed
+0 -0
config/appconfig-mls/userhelper_contextconfig/appconfig-strict-mls/userhelper_context
file renamed
+0 -0
config/appconfig-standard/dbus_contextsconfig/appconfig-strict/dbus_contexts
file renamed
+0 -0
config/appconfig-standard/default_contexts
file added
+15
config/appconfig-standard/default_typeconfig/appconfig-strict/default_type
file renamed
+1 -0
config/appconfig-standard/failsafe_contextconfig/appconfig-strict/failsafe_context
file renamed
+0 -0
config/appconfig-standard/initrc_contextconfig/appconfig-strict/initrc_context
file renamed
+0 -0
config/appconfig-standard/mediaconfig/appconfig-strict/media
file renamed
+0 -0
config/appconfig-standard/removable_contextconfig/appconfig-strict/removable_context
file renamed
+0 -0
config/appconfig-standard/root_default_contexts
file added
+11
config/appconfig-standard/seusersconfig/appconfig-strict/seusers
file renamed
+0 -0
config/appconfig-standard/userhelper_contextconfig/appconfig-strict/userhelper_context
file renamed
+0 -0
config/appconfig-strict-mcs/default_contexts
file removed
-12
config/appconfig-strict-mcs/root_default_contexts
file removed
-9
config/appconfig-strict-mls/default_contexts
file removed
-12
config/appconfig-strict-mls/root_default_contexts
file removed
-9
config/appconfig-strict/default_contexts
file removed
-12
config/appconfig-strict/root_default_contexts
file removed
-9
config/appconfig-targeted-mcs/dbus_contexts
file removed
-6
config/appconfig-targeted-mcs/default_contexts
file removed
-9
config/appconfig-targeted-mcs/default_type
file removed
-1
config/appconfig-targeted-mcs/failsafe_context
file removed
-1
config/appconfig-targeted-mcs/initrc_context
file removed
-1
config/appconfig-targeted-mcs/media
file removed
-3
config/appconfig-targeted-mcs/removable_context
file removed
-1
config/appconfig-targeted-mcs/root_default_contexts
file removed
-2
config/appconfig-targeted-mcs/seusers
file removed
-2
config/appconfig-targeted-mcs/userhelper_context
file removed
-1
config/appconfig-targeted-mls/dbus_contexts
file removed
-6
config/appconfig-targeted-mls/default_contexts
file removed
-9
config/appconfig-targeted-mls/default_type
file removed
-1
config/appconfig-targeted-mls/failsafe_context
file removed
-1
config/appconfig-targeted-mls/initrc_context
file removed
-1
config/appconfig-targeted-mls/media
file removed
-3
config/appconfig-targeted-mls/removable_context
file removed
-1
config/appconfig-targeted-mls/root_default_contexts
file removed
-2
config/appconfig-targeted-mls/seusers
file removed
-2
config/appconfig-targeted-mls/userhelper_context
file removed
-1
config/appconfig-targeted/dbus_contexts
file removed
-6
config/appconfig-targeted/default_contexts
file removed
-9
config/appconfig-targeted/default_type
file removed
-1
config/appconfig-targeted/failsafe_context
file removed
-1
config/appconfig-targeted/initrc_context
file removed
-1
config/appconfig-targeted/media
file removed
-3
config/appconfig-targeted/removable_context
file removed
-1
config/appconfig-targeted/root_default_contexts
file removed
-2
config/appconfig-targeted/seusers
file removed
-2
config/appconfig-targeted/userhelper_context
file removed
-1
policy/constraints
file modified
+16 -39
policy/global_booleans
file modified
+0 -2
policy/global_tunables
file modified
+17 -29
policy/modules/admin/acct.te
file modified
+0 -6
policy/modules/admin/apt.te
file modified
+4 -4
policy/modules/admin/bootloader.te
file modified
+0 -5
policy/modules/admin/brctl.te
file modified
+0 -5
policy/modules/admin/consoletype.te
file modified
+4 -10
policy/modules/admin/dmesg.if
file modified
+10 -30
policy/modules/admin/dmesg.te
file modified
+33 -45
policy/modules/admin/dmidecode.te
file modified
+0 -5
policy/modules/admin/dpkg.te
file modified
+12 -16
policy/modules/admin/firstboot.te
file modified
+4 -4
policy/modules/admin/kudzu.te
file modified
+9 -13
policy/modules/admin/mrtg.te
file modified
+0 -6
policy/modules/admin/netutils.te
file modified
+4 -23
policy/modules/admin/portage.te
file modified
+0 -1
policy/modules/admin/prelink.if
file modified
+31 -0
policy/modules/admin/prelink.te
file modified
+0 -13
policy/modules/admin/quota.te
file modified
+0 -6
policy/modules/admin/readahead.te
file modified
+0 -6
policy/modules/admin/rpm.te
file modified
+22 -36
policy/modules/admin/su.if
file modified
+9 -24
policy/modules/admin/sxid.te
file modified
+0 -6
policy/modules/admin/tzdata.if
file modified
+31 -0
policy/modules/admin/tzdata.te
file modified
+0 -5
policy/modules/admin/updfstab.te
file modified
+0 -7
policy/modules/apps/ada.fc
file modified
+0 -2
policy/modules/apps/ada.if
file modified
+12 -20
policy/modules/apps/ada.te
file modified
+4 -3
policy/modules/apps/cdrecord.te
file modified
+0 -2
policy/modules/apps/ethereal.fc
file modified
+1 -4
policy/modules/apps/evolution.fc
file modified
+6 -7
policy/modules/apps/games.te
file modified
+0 -6
policy/modules/apps/gift.fc
file modified
+2 -4
policy/modules/apps/gnome.fc
file modified
+3 -6
policy/modules/apps/gpg.fc
file modified
+1 -4
policy/modules/apps/irc.fc
file modified
+0 -2
policy/modules/apps/java.if
file modified
+5 -10
policy/modules/apps/java.te
file modified
+4 -5
policy/modules/apps/loadkeys.if
file modified
+15 -30
policy/modules/apps/loadkeys.te
file modified
+22 -32
policy/modules/apps/mono.te
file modified
+22 -25
policy/modules/apps/mozilla.fc
file modified
+6 -9
policy/modules/apps/mozilla.if
file modified
+0 -1
policy/modules/apps/mozilla.te
file modified
+0 -2
policy/modules/apps/mplayer.fc
file modified
+0 -2
policy/modules/apps/mplayer.te
file modified
+6 -14
policy/modules/apps/screen.fc
file modified
+0 -2
policy/modules/apps/thunderbird.fc
file modified
+0 -2
policy/modules/apps/uml.fc
file modified
+5 -4
policy/modules/apps/uml.te
file modified
+0 -7
policy/modules/apps/vmware.fc
file modified
+1 -3
policy/modules/apps/vmware.te
file modified
+0 -6
policy/modules/apps/webalizer.te
file modified
+0 -5
policy/modules/apps/wine.te
file modified
+1 -1
policy/modules/kernel/corecommands.fc
file modified
+0 -4
policy/modules/kernel/corecommands.if
file modified
+3 -11
policy/modules/kernel/domain.if
file modified
+2 -9
policy/modules/kernel/domain.te
file modified
+0 -14
policy/modules/kernel/files.if
file modified
+5 -10
policy/modules/kernel/files.te
file modified
+3 -8
policy/modules/kernel/kernel.te
file modified
+7 -8
policy/modules/kernel/terminal.te
file modified
+0 -9
policy/modules/services/amavis.te
file modified
+0 -5
policy/modules/services/apache.fc
file modified
+0 -5
policy/modules/services/apache.te
file modified
+4 -66
policy/modules/services/apcupsd.te
file modified
+0 -4
policy/modules/services/apm.te
file modified
+4 -7
policy/modules/services/arpwatch.te
file modified
+0 -6
policy/modules/services/asterisk.te
file modified
+0 -6
policy/modules/services/audioentropy.te
file modified
+0 -7
policy/modules/services/automount.te
file modified
+0 -6
policy/modules/services/avahi.te
file modified
+0 -6
policy/modules/services/bind.te
file modified
+0 -13
policy/modules/services/bluetooth.if
file modified
+128 -27
policy/modules/services/bluetooth.te
file modified
+4 -104
policy/modules/services/canna.te
file modified
+0 -6
policy/modules/services/ccs.te
file modified
+0 -5
policy/modules/services/cipe.te
file modified
+0 -6
policy/modules/services/clamav.te
file modified
+0 -5
policy/modules/services/courier.if
file modified
+0 -6
policy/modules/services/cpucontrol.te
file modified
+0 -12
policy/modules/services/cron.if
file modified
+11 -0
policy/modules/services/cron.te
file modified
+194 -234
policy/modules/services/cups.te
file modified
+0 -40
policy/modules/services/cyrus.te
file modified
+0 -7
policy/modules/services/dante.te
file modified
+0 -6
policy/modules/services/dbus.if
file modified
+1 -0
policy/modules/services/dbus.te
file modified
+1 -7
policy/modules/services/dcc.te
file modified
+0 -18
policy/modules/services/ddclient.te
file modified
+0 -6
policy/modules/services/dhcp.te
file modified
+0 -6
policy/modules/services/dictd.te
file modified
+0 -6
policy/modules/services/distcc.te
file modified
+0 -6
policy/modules/services/dnsmasq.te
file modified
+0 -6
policy/modules/services/dovecot.te
file modified
+0 -6
policy/modules/services/fail2ban.te
file modified
+0 -5
policy/modules/services/fetchmail.te
file modified
+0 -6
policy/modules/services/finger.te
file modified
+0 -6
policy/modules/services/ftp.if
file modified
+31 -0
policy/modules/services/ftp.te
file modified
+0 -15
policy/modules/services/gatekeeper.te
file modified
+0 -6
policy/modules/services/gpm.te
file modified
+0 -6
policy/modules/services/hal.te
file modified
+0 -20
policy/modules/services/howl.te
file modified
+0 -6
policy/modules/services/i18n_input.te
file modified
+0 -6
policy/modules/services/imaze.te
file modified
+0 -6
policy/modules/services/inetd.te
file modified
+5 -17
policy/modules/services/inn.te
file modified
+0 -6
policy/modules/services/ircd.te
file modified
+0 -6
policy/modules/services/irqbalance.te
file modified
+0 -6
policy/modules/services/jabber.te
file modified
+0 -6
policy/modules/services/kerberos.te
file modified
+0 -12
policy/modules/services/ktalk.te
file modified
+0 -5
policy/modules/services/ldap.te
file modified
+0 -15
policy/modules/services/lpd.te
file modified
+0 -11
policy/modules/services/monop.te
file modified
+0 -6
policy/modules/services/mta.if
file modified
+2 -4
policy/modules/services/mta.te
file modified
+2 -36
policy/modules/services/munin.te
file modified
+0 -6
policy/modules/services/mysql.te
file modified
+0 -6
policy/modules/services/nagios.te
file modified
+0 -12
policy/modules/services/nessus.te
file modified
+0 -6
policy/modules/services/networkmanager.te
file modified
+7 -12
policy/modules/services/nis.te
file modified
+0 -23
policy/modules/services/nscd.te
file modified
+0 -6
policy/modules/services/nsd.te
file modified
+0 -6
policy/modules/services/ntop.te
file modified
+0 -6
policy/modules/services/ntp.te
file modified
+0 -12
policy/modules/services/oav.te
file modified
+0 -6
policy/modules/services/oddjob.te
file modified
+0 -5
policy/modules/services/openct.te
file modified
+0 -6
policy/modules/services/openvpn.te
file modified
+0 -5
policy/modules/services/pcscd.te
file modified
+0 -5
policy/modules/services/pegasus.te
file modified
+4 -7
policy/modules/services/perdition.te
file modified
+0 -6
policy/modules/services/portmap.te
file modified
+0 -11
policy/modules/services/portslave.te
file modified
+0 -6
policy/modules/services/postfix.if
file modified
+0 -6
policy/modules/services/postfix.te
file modified
+0 -20
policy/modules/services/postgresql.te
file modified
+0 -22
policy/modules/services/postgrey.te
file modified
+0 -6
policy/modules/services/ppp.te
file modified
+0 -14
policy/modules/services/privoxy.te
file modified
+0 -6
policy/modules/services/pxe.te
file modified
+0 -6
policy/modules/services/pyzor.fc
file modified
+2 -4
policy/modules/services/pyzor.if
file modified
+37 -38
policy/modules/services/pyzor.te
file modified
+0 -11
policy/modules/services/radius.te
file modified
+0 -6
policy/modules/services/radvd.te
file modified
+0 -6
policy/modules/services/razor.fc
file modified
+0 -2
policy/modules/services/rdisc.te
file modified
+0 -6
policy/modules/services/remotelogin.te
file modified
+5 -5
policy/modules/services/resmgr.te
file modified
+0 -6
policy/modules/services/rhgb.te
file modified
+4 -14
policy/modules/services/ricci.te
file modified
+4 -12
policy/modules/services/roundup.te
file modified
+0 -6
policy/modules/services/rpc.if
file modified
+0 -6
policy/modules/services/rpc.te
file modified
+0 -7
policy/modules/services/rshd.te
file modified
+4 -4
policy/modules/services/rwho.te
file modified
+0 -5
policy/modules/services/samba.if
file modified
+32 -0
policy/modules/services/samba.te
file modified
+14 -46
policy/modules/services/sasl.te
file modified
+1 -7
policy/modules/services/sendmail.te
file modified
+0 -6
policy/modules/services/setroubleshoot.te
file modified
+0 -5
policy/modules/services/slrnpull.te
file modified
+0 -6
policy/modules/services/smartmon.te
file modified
+0 -6
policy/modules/services/snmp.te
file modified
+0 -6
policy/modules/services/snort.te
file modified
+0 -6
policy/modules/services/soundserver.te
file modified
+0 -6
policy/modules/services/spamassassin.fc
file modified
+1 -4
policy/modules/services/spamassassin.if
file modified
+6 -0
policy/modules/services/spamassassin.te
file modified
+0 -20
policy/modules/services/speedtouch.te
file modified
+0 -6
policy/modules/services/squid.te
file modified
+0 -6
policy/modules/services/ssh.fc
file modified
+4 -7
policy/modules/services/ssh.te
file modified
+29 -44
policy/modules/services/stunnel.te
file modified
+0 -6
policy/modules/services/tftp.te
file modified
+0 -6
policy/modules/services/timidity.te
file modified
+0 -6
policy/modules/services/transproxy.te
file modified
+0 -6
policy/modules/services/uptime.te
file modified
+0 -6
policy/modules/services/uucp.te
file modified
+0 -5
policy/modules/services/uwimap.te
file modified
+0 -6
policy/modules/services/watchdog.te
file modified
+0 -6
policy/modules/services/xfs.te
file modified
+0 -6
policy/modules/services/xprint.te
file modified
+0 -6
policy/modules/services/xserver.fc
file modified
+1 -6
policy/modules/services/xserver.if
file modified
+2 -6
policy/modules/services/xserver.te
file modified
+23 -26
policy/modules/services/zabbix.te
file modified
+0 -5
policy/modules/services/zebra.te
file modified
+4 -7
policy/modules/system/authlogin.if
file modified
+5 -14
policy/modules/system/authlogin.te
file modified
+5 -6
policy/modules/system/clock.te
file modified
+0 -6
policy/modules/system/fstools.te
file modified
+0 -5
policy/modules/system/getty.te
file modified
+0 -5
policy/modules/system/hotplug.te
file modified
+0 -5
policy/modules/system/init.fc
file modified
+2 -4
policy/modules/system/init.if
file modified
+18 -0
policy/modules/system/init.te
file modified
+28 -44
policy/modules/system/ipsec.te
file modified
+0 -6
policy/modules/system/iptables.te
file modified
+0 -7
policy/modules/system/iscsi.te
file modified
+0 -4
policy/modules/system/libraries.fc
file modified
+14 -43
policy/modules/system/libraries.if
file modified
+13 -24
policy/modules/system/libraries.te
file modified
+1 -19
policy/modules/system/locallogin.te
file modified
+7 -7
policy/modules/system/logging.te
file modified
+0 -25
policy/modules/system/lvm.te
file modified
+0 -13
policy/modules/system/modutils.te
file modified
+3 -13
policy/modules/system/mount.if
file modified
+39 -11
policy/modules/system/mount.te
file modified
+10 -13
policy/modules/system/pcmcia.te
file modified
+0 -8
policy/modules/system/raid.te
file modified
+0 -6
policy/modules/system/selinuxutil.te
file modified
+14 -31
policy/modules/system/sysnetwork.te
file modified
+0 -15
policy/modules/system/udev.te
file modified
+0 -6
policy/modules/system/unconfined.fc
file modified
+4 -5
policy/modules/system/unconfined.if
file modified
+94 -49
policy/modules/system/unconfined.te
file modified
+151 -135
policy/modules/system/userdomain.if
file modified
+149 -311
policy/modules/system/userdomain.te
file modified
+301 -363
policy/modules/system/xen.te
file modified
+0 -9
policy/rolemap
file modified
+6 -8
policy/users
file modified
+6 -11
support/Makefile.devel
file modified
+3 -13
    trunk: merge strict and targeted policies.  merge shlib_t into lib_t.
    
        
file modified
+6 -0
file modified
+2 -12
file modified
+4 -8
file modified
+2 -4
config/appconfig-mcs/dbus_contexts config/appconfig-strict-mcs/dbus_contexts
file renamed
file was renamed with no change to the file
config/appconfig-mcs/default_type config/appconfig-strict-mcs/default_type
file renamed
config/appconfig-mcs/failsafe_context config/appconfig-strict-mcs/failsafe_context
file renamed
file was renamed with no change to the file
config/appconfig-mcs/initrc_context config/appconfig-strict-mcs/initrc_context
file renamed
file was renamed with no change to the file
config/appconfig-mcs/media config/appconfig-strict-mcs/media
file renamed
file was renamed with no change to the file
config/appconfig-mcs/removable_context config/appconfig-strict-mcs/removable_context
file renamed
file was renamed with no change to the file
config/appconfig-mcs/seusers config/appconfig-strict-mcs/seusers
file renamed
file was renamed with no change to the file
config/appconfig-mcs/userhelper_context config/appconfig-strict-mcs/userhelper_context
file renamed
file was renamed with no change to the file
config/appconfig-mls/dbus_contexts config/appconfig-strict-mls/dbus_contexts
file renamed
file was renamed with no change to the file
config/appconfig-mls/default_type config/appconfig-strict-mls/default_type
file renamed
+3 -2
config/appconfig-mls/failsafe_context config/appconfig-strict-mls/failsafe_context
file renamed
file was renamed with no change to the file
config/appconfig-mls/initrc_context config/appconfig-strict-mls/initrc_context
file renamed
file was renamed with no change to the file
config/appconfig-mls/media config/appconfig-strict-mls/media
file renamed
file was renamed with no change to the file
config/appconfig-mls/removable_context config/appconfig-strict-mls/removable_context
file renamed
file was renamed with no change to the file
config/appconfig-mls/seusers config/appconfig-strict-mls/seusers
file renamed
file was renamed with no change to the file
config/appconfig-mls/userhelper_context config/appconfig-strict-mls/userhelper_context
file renamed
file was renamed with no change to the file
config/appconfig-standard/dbus_contexts config/appconfig-strict/dbus_contexts
file renamed
file was renamed with no change to the file
config/appconfig-standard/default_type config/appconfig-strict/default_type
file renamed
config/appconfig-standard/failsafe_context config/appconfig-strict/failsafe_context
file renamed
file was renamed with no change to the file
config/appconfig-standard/initrc_context config/appconfig-strict/initrc_context
file renamed
file was renamed with no change to the file
config/appconfig-standard/media config/appconfig-strict/media
file renamed
file was renamed with no change to the file
config/appconfig-standard/removable_context config/appconfig-strict/removable_context
file renamed
file was renamed with no change to the file
config/appconfig-standard/seusers config/appconfig-strict/seusers
file renamed
file was renamed with no change to the file
config/appconfig-standard/userhelper_context config/appconfig-strict/userhelper_context
file renamed
file was renamed with no change to the file
file modified
+16 -39
file modified
+0 -2
file modified
+17 -29
file modified
+0 -6
file modified
+4 -4
file modified
+10 -30
file modified
+33 -45
file modified
+12 -16
file modified
+9 -13
file modified
+0 -6
file modified
+22 -36
file modified
+9 -24
file modified
+0 -6
file modified
+0 -2
file modified
+12 -20
file modified
+4 -3
file modified
+0 -6
file modified
+2 -4
file modified
+3 -6
file modified
+1 -4
file modified
+0 -2
file modified
+5 -10
file modified
+4 -5
file modified
+15 -30
file modified
+22 -32
file modified
+22 -25
file modified
+5 -4
file modified
+0 -7
file modified
+1 -1
file modified
+194 -234
file modified
+29 -44
file modified
+18 -0
file modified
+28 -44
file modified
+0 -13
file modified
+39 -11
file modified
+10 -13
file modified
+0 -9
file modified
+6 -8
file modified
+6 -11
file modified
+3 -13