CBL-Mariner/SPECS/selinux-policy
Chris PeBenito 0ec698fbc6
Enable SELinux by default on all images. (#1757)
* Add prototype SELinux auto configure

* Add 'force_enforcing' option for SELinux

* Fix setools-console tools.

* Enable SELinux by default (permissive mode) on all images.

Drop build system unit test as it breaks with SELinux enabled on core-efi.

* selinux-policy: Update to 2.20210908.

* Update to 2.20220106.

Implement policy for systemd-homed and systemd-userdbd.

* Fix RPM changelog date.

* Finalize systemd-homed policy.

* Change SELinux enablement to not affect CONFIG_LSM.

* Document build settings

* Update cgmanifest

* Update toolkit/docs/formats/imageconfig.md

Co-authored-by: Christopher Co <35273088+christopherco@users.noreply.github.com>

* audit: Remove override so auditd starts by default.

* Add IsValid() call for SELinux inKkernelCommandLine

* Add unit test for missing selinux package

* Fix debug output for selinux setfiles

Co-authored-by: Daniel McIlvaney <damcilva@microsoft.com>
Co-authored-by: Christopher Co <35273088+christopherco@users.noreply.github.com>
2022-02-01 08:24:41 -05:00
..
0001-Makefile-Revise-relabel-targets-to-relabel-all-secla.patch Enable SELinux by default on all images. (#1757) 2022-02-01 08:24:41 -05:00
0002-cronyd-Add-dac_read_search.patch Enable SELinux by default on all images. (#1757) 2022-02-01 08:24:41 -05:00
0003-Temporary-fix-for-wrong-audit-log-directory.patch Enable SELinux by default on all images. (#1757) 2022-02-01 08:24:41 -05:00
0004-Set-default-login-to-unconfined_u.patch Enable SELinux by default on all images. (#1757) 2022-02-01 08:24:41 -05:00
0005-systemd-Add-systemd-homed-and-systemd-userdbd.patch Enable SELinux by default on all images. (#1757) 2022-02-01 08:24:41 -05:00
0006-systemd-ssh-Crypto-sysctl-use.patch Enable SELinux by default on all images. (#1757) 2022-02-01 08:24:41 -05:00
0007-systemd-Additional-fixes-for-fs-getattrs.patch Enable SELinux by default on all images. (#1757) 2022-02-01 08:24:41 -05:00
0008-systemd-Updates-for-generators-and-kmod-static-nodes.patch Enable SELinux by default on all images. (#1757) 2022-02-01 08:24:41 -05:00
Makefile.devel Merge 1.0 to dev branch 2021-08-19 13:46:51 -07:00
booleans_targeted.conf Enable SELinux by default on all images. (#1757) 2022-02-01 08:24:41 -05:00
selinux-policy.signatures.json Enable SELinux by default on all images. (#1757) 2022-02-01 08:24:41 -05:00
selinux-policy.spec Enable SELinux by default on all images. (#1757) 2022-02-01 08:24:41 -05:00