John Johansen
|
9b7912c39f
|
add an extra hash level to distiguish between allow and deny - only use allow
|
2008-04-18 21:07:16 +00:00 |
|
John Johansen
|
36e0d38fc4
|
rename global vartable to the filetable
|
2008-04-18 21:06:24 +00:00 |
|
John Johansen
|
8d715ce9d6
|
make it so just reading an embedded hat doesn't cause the profile to be rewritten
|
2008-04-18 21:04:54 +00:00 |
|
John Johansen
|
6e87b3f004
|
add enough support for cx modes that parsing can succeed
|
2008-04-18 21:04:16 +00:00 |
|
John Johansen
|
bc652326a7
|
refactor to pass the profile down, as a step to making routines more generic and independant
|
2008-04-18 21:03:28 +00:00 |
|
John Johansen
|
1c8b9a51e4
|
make modes be stored as a bit set and use bit operations
|
2008-04-18 21:02:47 +00:00 |
|
John Johansen
|
83a35b57c2
|
give paths a sub hash to store mode into
|
2008-04-18 21:02:07 +00:00 |
|
John Johansen
|
e43a4769be
|
retain the filename the profile was loaded from and use that when writting it back out
|
2008-04-18 21:01:10 +00:00 |
|
John Johansen
|
f213706f17
|
support retaining variables in the head of the file
|
2008-04-18 21:00:35 +00:00 |
|
John Johansen
|
5a088a1a47
|
change order that rules are output in
|
2008-04-18 20:59:42 +00:00 |
|
John Johansen
|
0cbaee9902
|
support parsing retaining of subset on link rules
|
2008-04-18 20:59:00 +00:00 |
|
John Johansen
|
a67cfbbb30
|
keep variables
|
2008-04-18 20:58:07 +00:00 |
|
John Johansen
|
2a0dc5aae9
|
keep change_hat rules
|
2008-04-18 20:57:51 +00:00 |
|
John Johansen
|
d07689e2a7
|
support and keep profiles using the profile keyword
|
2008-04-18 20:57:33 +00:00 |
|
John Johansen
|
5d1d6d31c3
|
keep set capability rules
|
2008-04-18 20:57:01 +00:00 |
|
John Johansen
|
03728a0155
|
keep rlimit rules
|
2008-04-18 20:56:41 +00:00 |
|
John Johansen
|
715952ce0d
|
keep alias rules
|
2008-04-18 20:56:26 +00:00 |
|
John Johansen
|
de95e8b6ef
|
keep change_profile rules
|
2008-04-18 20:56:08 +00:00 |
|
John Johansen
|
cda1e94f8a
|
basic patch to link rules
|
2008-04-18 20:55:43 +00:00 |
|
John Johansen
|
7ec531f4e8
|
try to make some general writer routines
|
2008-04-18 20:55:11 +00:00 |
|
John Johansen
|
e48fccb6d0
|
simple patch to map u::g modes into old style
|
2008-04-18 20:50:18 +00:00 |
|
John Johansen
|
e25c4dad06
|
fix bug where task was getting dropped
|
2008-04-18 20:49:48 +00:00 |
|
John Johansen
|
89b9ef516a
|
don't change locale if yast has already set them
|
2008-04-18 20:49:00 +00:00 |
|
John Johansen
|
3efb4ea353
|
allow bare x in named transitions
|
2008-04-18 00:40:40 +00:00 |
|
Steve Beattie
|
7a751a53f6
|
Not sure why the close of stdout and redirection of the pipe was here,
given that the following write was to the specific file descriptor in
the pipe.
|
2008-04-17 22:09:05 +00:00 |
|
Steve Beattie
|
c0275d06eb
|
Fix up some dependencies in parser_misc.c's unit test build.
|
2008-04-16 16:27:23 +00:00 |
|
Steve Beattie
|
e41a326ef5
|
Add a flag so that 'make check V=1' will turn on verbose output.
|
2008-04-16 16:09:36 +00:00 |
|
John Johansen
|
ee03760c1d
|
disable named transition conversion to cx. Needs to be reworked
|
2008-04-16 08:48:06 +00:00 |
|
John Johansen
|
11f925abba
|
fix named transition, enable cx to imply transition to local profile, without having to specify name
|
2008-04-16 06:54:51 +00:00 |
|
John Johansen
|
015df061e3
|
Named transition - but disabled due to a bug
|
2008-04-16 04:45:02 +00:00 |
|
John Johansen
|
db34aac811
|
Basis for named transitions
|
2008-04-16 04:44:21 +00:00 |
|
John Johansen
|
051a3f8c01
|
add missing parser_alias.c + fix parameter bug in parser.h
|
2008-04-11 17:43:22 +00:00 |
|
Steve Beattie
|
666a8ec51b
|
Fix up prototype error.
|
2008-04-10 22:24:35 +00:00 |
|
John Johansen
|
3092aaa821
|
Various profile updates touching on bnc#255270, bnc#331444, bnc#307365
bnc#230700
|
2008-04-10 08:54:05 +00:00 |
|
John Johansen
|
c6666773d9
|
update config to point the repo to 11.0
|
2008-04-10 08:51:29 +00:00 |
|
John Johansen
|
9961c4b895
|
skip vim swp files in the profile dir. bnc#205105
|
2008-04-10 08:40:52 +00:00 |
|
John Johansen
|
e59f8bfd29
|
fix bnc@304205. Stop redefining LC_MESSAGES when it yast has alread
defined it.
|
2008-04-10 08:25:23 +00:00 |
|
John Johansen
|
6850b933dc
|
Fix bnc#257286, so that if complain or enfore fail to load the profile,
they will fail and dump the profiles error message.
|
2008-04-10 07:25:46 +00:00 |
|
John Johansen
|
16b5a26306
|
update for ptrace rules
|
2008-04-09 23:56:31 +00:00 |
|
John Johansen
|
4dd0e8ead8
|
allow for ptrace rules
|
2008-04-09 09:04:08 +00:00 |
|
John Johansen
|
78590d1823
|
allow for simpe alias rules
|
2008-04-09 09:03:17 +00:00 |
|
John Johansen
|
b742da7751
|
allow <= to be used instead of subset in link rules
|
2008-04-09 09:02:51 +00:00 |
|
John Johansen
|
add2b93657
|
update interface version
|
2008-04-08 20:30:06 +00:00 |
|
John Johansen
|
4016ae5fb3
|
bump version to 2.3
|
2008-04-07 18:37:57 +00:00 |
|
John Johansen
|
26e1f20262
|
rename-rlimit.diff to apparmor-rlimit.diff
|
2008-04-07 18:00:34 +00:00 |
|
John Johansen
|
2ed2bc67f0
|
merge patches down to start cleaning up
|
2008-04-07 17:55:03 +00:00 |
|
John Johansen
|
1daeaa9308
|
reorder patches in preparation for patch merging
|
2008-04-07 17:48:20 +00:00 |
|
John Johansen
|
d3eb6500f5
|
oops, reenable setting the rlimits
|
2008-04-07 14:51:26 +00:00 |
|
John Johansen
|
aef0eb93dd
|
Fix rlimits so that it doesn't try to do nproc checks when moving
to an unconfined state; which would result in dereferencing a null
profile pointer.
|
2008-04-07 04:47:08 +00:00 |
|
John Johansen
|
aba82ff427
|
reject rlimit cpu in the parser
|
2008-04-07 04:26:02 +00:00 |
|