Commit Graph

  • 432fd8a0d8
    bump to v2.203.0 v2.203.0 Lokesh Mandvekar 2023-03-07 19:18:37 +0530
  • 75f7d29eff
    Merge pull request #208 from lsm5/Makefile-and-packit-updates Daniel J Walsh 2023-03-06 10:15:17 -0500
  • 4f3b18b04e
    Packit: Use custom copr project Lokesh Mandvekar 2023-03-03 20:13:57 +0530
  • cc9d5c00a5
    spec.rpkg: New file addition Lokesh Mandvekar 2023-03-03 17:52:18 +0530
  • 581898d86c
    Makefile: install.udica-templates target and DATADIR variable Lokesh Mandvekar 2023-03-03 17:49:38 +0530
  • 1c4fffa9c3
    Merge pull request #206 from zpytela/spc-rpm-trans-script Lokesh Mandvekar 2023-03-03 07:50:39 -0500
  • 69fa227e30 Add system_r role to rpm_transition_script(spc_t) Zdenek Pytela 2023-03-03 10:48:44 +0100
  • 018cb36d55
    Allow spc_t to transption to rpm_script_t v2.202.0 Daniel J Walsh 2023-03-02 16:57:11 -0800
  • 29bb5db136
    Fixes for container_init_t v2.201.0 Daniel J Walsh 2023-02-22 14:27:35 -0500
  • b2cd19138c
    Packit: Use custom copr project Lokesh Mandvekar 2023-02-10 17:30:09 +0530
  • 159f7178c5
    Makefile: include DATADIR variable Lokesh Mandvekar 2023-02-10 17:09:14 +0530
  • ff63c7c981
    Makefile: install.udica-templates target Lokesh Mandvekar 2023-02-08 17:21:54 +0530
  • 8ed2899953
    Add support to new user_namespace access check v2.200.0 Daniel J Walsh 2023-02-07 06:28:59 -0500
  • 7293dae800
    Allow unconfined domains to transition to container_runtime_t v2.199.0 Daniel J Walsh 2023-01-29 11:14:40 -0500
  • dfc8db8e0d Allow spc_t to use localectl Johannes Segitz 2023-01-12 14:06:20 +0100
  • a488c9260e Allow spc_t to use timedatectl Johannes Segitz 2023-01-11 15:49:37 +0100
  • 8d1f141034
    Fix spc_t transition rules on tmpfs_t v2.198.0 Daniel J Walsh 2023-01-05 14:57:53 -0500
  • 94b26180d6
    Add containers_use_ecryptfs boolean v2.197.0 Daniel J Walsh 2023-01-03 18:13:16 -0500
  • 6e0cb6e1dc
    Readd missing container policy v2.195.1 Daniel J Walsh 2022-12-14 18:55:38 -0500
  • 24e5784852
    Rearange policy to allow other container types to be isolated v2.195.0 Daniel J Walsh 2022-12-13 15:47:24 -0500
  • 735aaf40e5
    Allow syslogd_t to use tmpfs files created by container runtime v2.194.0 Daniel J Walsh 2022-12-13 12:57:53 -0500
  • 88f904d48e
    Label spc_t as a init initrc daemon v2.193.0 Daniel J Walsh 2022-11-22 11:06:52 -0500
  • d03f7c541e
    Allow userdomains to run containers Daniel J Walsh 2022-11-14 13:43:44 -0500
  • 9852880cea
    Merge pull request #196 from rhrazdil/allow_tmpfs_passt Daniel J Walsh 2022-11-16 07:02:26 -0500
  • 6dff9fd395 Allow containers to mount tmpfs_t file systems Radim Hrazdil 2022-11-15 09:17:03 +0100
  • 7fafd46ad0
    Add container_logwriter_t policy type v2.191.0 Daniel J Walsh 2022-10-28 10:11:29 -0400
  • cfc7e10032
    Bump to v2.190.1 v2.190.1 Daniel J Walsh 2022-10-27 10:24:40 -0400
  • 7d6d18a57d
    Merge pull request #192 from ningmingxiao/dev2 Daniel J Walsh 2022-10-27 10:23:33 -0400
  • a51e0cb47c
    Merge pull request #193 from AkihiroSuda/buildkit Daniel J Walsh 2022-10-27 10:21:27 -0400
  • 62fd58c22b
    Merge pull request #194 from ManaSugi/add-kata-agent Daniel J Walsh 2022-10-27 10:19:11 -0400
  • 6abad0754e support nerdctl ningmingxiao 2022-10-20 10:15:17 +0800
  • 39f83cc74d container.fc: Set label for kata-agent Manabu Sugimoto 2022-10-26 19:02:50 +0900
  • 8ca4b89b82
    Support BuildKit (cont.) Akihiro Suda 2022-10-20 13:46:20 +0900
  • a7a101307a
    Merge pull request #189 from AkihiroSuda/buildkit Daniel J Walsh 2022-10-19 14:21:11 -0400
  • 6e07a445ca
    Support BuildKit Akihiro Suda 2022-10-19 18:57:39 +0900
  • ef1b1bd7e9
    Allow iptables to list container_file_t directories v2.190.0 Daniel J Walsh 2022-09-13 10:47:30 -0400
  • e23f8bc320
    Merge pull request #185 from lsm5/packit Daniel J Walsh 2022-09-06 16:03:10 -0400
  • 6f3af2046c
    Packit: initial enablement Lokesh Mandvekar 2022-09-01 09:34:57 -0400
  • bff5e917ed add nerdctl ningmingxiao 2022-08-25 09:19:53 +0800
  • bca5876c01
    don't audit searching process domains v2.189.0 Daniel J Walsh 2022-07-14 10:16:55 -0400
  • ce85ca52a4
    Bump to v2.188.0 v2.188.0 Daniel J Walsh 2022-06-23 10:56:13 -0400
  • a2be2c44dc
    Merge pull request #181 from nalind/confined-overlay Daniel J Walsh 2022-06-23 10:55:19 -0400
  • 9aa07fa35c Allow confined containers to mount overlay filesystems Nalin Dahyabhai 2022-06-22 16:34:13 -0400
  • 0e5ef1a636
    Allow container domains to use /dev/zero v2.187.0 Daniel J Walsh 2022-05-24 12:37:23 -0400
  • 72d1b726b5
    Allow containers to shutdown & setopt userdomain:sockets v2.186.0 Daniel J Walsh 2022-05-24 10:56:43 -0400
  • 15c20d72b1
    Merge pull request #178 from rhatdan/main Daniel J Walsh 2022-05-04 11:29:44 -0400
  • cf704e467c
    Create policy for a container_device_t Daniel J Walsh 2022-04-22 09:49:49 -0400
  • 687cc50a6d
    Allow containers to remount file systems fs_t file systems Daniel J Walsh 2022-04-29 11:09:51 -0400
  • abcef2aee3 Add a domain for intelplugins and give them required access Manish Regmi 2022-04-13 14:44:13 -0400
  • 34e62c8faa
    Allow containers to inherit all socket classes v2.183.0 Daniel J Walsh 2022-04-18 06:20:45 -0400
  • 3d10445d42
    Allow containers to inherit all socket classes v2.182.0 Daniel J Walsh 2022-04-18 06:12:32 -0400
  • 22eaf702c7
    Allow containers to use udp and tcp socket activated sockets v2.181.0 Daniel J Walsh 2022-03-23 12:50:30 -0400
  • 23043a7b32
    Allow container domains to read/write kvm_device_t v2.180.0 Daniel J Walsh 2022-03-03 09:20:15 -0500
  • 3e8548b3ae
    Update kublet mappings to inlcude /usr/local/* v2.179.1 Daniel J Walsh 2022-02-27 08:49:52 -0500
  • ec17f3b71b
    Allow container domains to use container runtime tcp and udp sockets v2.179.0 Daniel J Walsh 2022-02-21 14:38:59 -0500
  • e27d703b76 Dontaudit associating container_t with proc_t filesystems Ondrej Mosnacek 2022-02-17 12:24:04 +0100
  • 9bc0e7edf0
    Alow containers to use unix_stream_sockets leaked from container runtimes v2.178.0 Daniel J Walsh 2022-02-10 20:21:52 -0500
  • e9ec0d48d8
    Allow userdomains to execute conmon_exec_t and use it as an entrypoint v2.177.0 Daniel J Walsh 2022-02-09 14:26:34 -0500
  • 82be248d93
    Allow conmon_exec_t as an entrypoint v2.176.0 Daniel J Walsh 2022-02-03 08:48:53 -0500
  • b3e56e2470
    Add boolean to allow containers to use any device v2.175.0 Daniel J Walsh 2022-02-03 08:25:13 -0500
  • 95e524aaec
    Bump to v2.174.0 v2.174.0 Daniel J Walsh 2022-02-01 14:08:21 -0500
  • ef3330939f
    Merge pull request #166 from 0xC0ncord/conmon-ranged-transition Daniel J Walsh 2022-01-31 12:31:27 -0500
  • 662890a32f Add explicit range transition for conmon Kenton Groombridge 2022-01-31 11:52:19 -0500
  • a31e3e65b1
    Update package for new file context v2.173.2 Daniel J Walsh 2022-01-26 13:16:18 -0500
  • b7c56fcf67
    Merge pull request #165 from fire833/main Daniel J Walsh 2022-01-26 13:15:31 -0500
  • cf3da79372 Update file labeling type for /var/lib/kubelet Kendall Tauser 2022-01-22 20:29:50 -0600
  • 0ea4477353
    Bump version to handle fixes in interface v2.173.1 Daniel J Walsh 2022-01-18 10:36:13 -0500
  • d405b78442
    Merge pull request #163 from zpytela/container-runtime-dbus-class Daniel J Walsh 2022-01-14 12:53:51 -0500
  • 72c7843f7f Add missing dbus class declaration into container_runtime_run() Zdenek Pytela 2022-01-14 18:17:26 +0100
  • 84d09cedf2
    Remove lockdown allow rules v2.173.0 Daniel J Walsh 2022-01-11 06:46:14 -0500
  • 168a6874e2
    Bump to v2.172.1 v2.172.1 Daniel J Walsh 2022-01-06 15:08:05 -0500
  • f2a05408b9
    Merge pull request #162 from dweomer/remove-k3s-fcontexts Daniel J Walsh 2022-01-06 07:57:16 -0500
  • 40c3af5eea remove k3s fcontexts Jacob Blain Christen 2022-01-05 15:16:33 -0700
  • c98794ef01
    Allow container domains to be used by user roles v2.172.0 Daniel J Walsh 2021-11-22 17:11:54 -0500
  • db7dcc5b83
    Bump to v2.171.0 v2.171.0 Daniel J Walsh 2021-11-10 17:21:41 -0500
  • 165172674b
    Merge pull request #156 from dweomer/k3s-data-container-runtime-exec Daniel J Walsh 2021-11-05 14:15:08 -0400
  • 3bd8813375
    Merge pull request #157 from 0xC0ncord/master Daniel J Walsh 2021-11-05 14:12:00 -0400
  • ff8aca0553 Remove noxattrfs from container_file_t Kenton Groombridge 2021-11-05 12:10:39 -0400
  • 729318e6e1 some entries under the k3s data-dir should not be container_runtime_exec_t Jacob Blain Christen 2021-11-04 15:28:10 -0700
  • 57d36abd18
    container_runtime create all tmpfs content as container_runtime_tmpfs_t v2.170.0 2.170.0 Daniel J Walsh 2021-10-05 14:57:50 -0400
  • 7ef0012fb3
    Merge pull request #154 from fire833/main Daniel J Walsh 2021-10-01 14:43:54 -0400
  • e9fc8ef8fa
    Updated type in README Kendall Tauser 2021-10-01 10:45:06 -0500
  • 887d683715
    Allow container_logread_t to read logfile sym links v2.169.0 Daniel J Walsh 2021-09-24 16:45:03 -0400
  • ce3c132c47
    Merge pull request #153 from cjellick/master Daniel J Walsh 2021-09-23 14:21:17 -0400
  • fe18e51ead Remove broken links from README.md Craig Jellick 2021-09-23 09:17:05 -0700
  • 60e121d1b3 remove file-contexts specific to k3s Jacob Blain Christen 2021-09-14 13:15:38 -0700
  • 91de4e44d0
    Merge pull request #148 from rhatdan/main v2.168.0 Daniel J Walsh 2021-09-13 13:55:10 -0400
  • 65bb4836b0
    Allow iptables to use fifo files of a container runtime Daniel J Walsh 2021-09-10 10:36:40 -0400
  • 55254f366c
    Merge pull request #146 from vmojzis/udica_templates Daniel J Walsh 2021-09-09 14:14:10 -0400
  • 6190140c45 Add udica policy templates Vit Mojzis 2021-09-08 18:00:31 +0200
  • aebd24daab
    Allow containers to be socket activated v2.167.0 Daniel J Walsh 2021-08-26 09:03:50 -0400
  • 3779162e1d
    Allow staff_t to signal container domains Daniel J Walsh 2021-08-25 10:37:47 -0400
  • 2bb3a2b09f
    Fix files_config_file interface name v2.165.1 Daniel J Walsh 2021-08-25 08:21:48 -0400
  • eabeb4a35b Fix a typo: files_config_type to files_config_file Zdenek Pytela 2021-08-24 20:30:29 +0200
  • d5f3c5884e
    Define kubernetes_file_t as a config_type v2.165.0 2.165.0 Daniel J Walsh 2021-08-24 13:03:36 -0400
  • 90816a53ef
    Bump to v2.164.2 v2.164.2 Daniel J Walsh 2021-08-02 13:18:31 -0400
  • b558aa305c
    Merge pull request #140 from Conan-Kudo/k3s-selinux Daniel J Walsh 2021-08-02 13:17:01 -0400
  • 7e5f3cae10 Add support for k3s Neal Gompa 2021-08-02 12:22:49 -0400
  • 563ba3f269
    Fix compilation errors. v2.164.1 Daniel J Walsh 2021-07-16 13:40:10 -0400
  • 6b0d68fbdb
    Merge pull request #139 from zpytela/no-double-slash Daniel J Walsh 2021-07-16 13:39:08 -0400