diff --git a/config.tgz b/config.tgz index 2619187..c5f15a6 100644 Binary files a/config.tgz and b/config.tgz differ diff --git a/config/appconfig-mcs/dbus_contexts b/config/appconfig-mcs/dbus_contexts deleted file mode 100644 index 116e684..0000000 --- a/config/appconfig-mcs/dbus_contexts +++ /dev/null @@ -1,6 +0,0 @@ - - - - - diff --git a/config/appconfig-mcs/default_contexts b/config/appconfig-mcs/default_contexts deleted file mode 100644 index 22aeb67..0000000 --- a/config/appconfig-mcs/default_contexts +++ /dev/null @@ -1,15 +0,0 @@ -system_r:crond_t:s0 user_r:cronjob_t:s0 staff_r:cronjob_t:s0 sysadm_r:cronjob_t:s0 system_r:cronjob_t:s0 unconfined_r:unconfined_cronjob_t:s0 -system_r:local_login_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0 -system_r:remote_login_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 unconfined_r:unconfined_t:s0 -system_r:sshd_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0 -system_r:sulogin_t:s0 sysadm_r:sysadm_t:s0 -system_r:xdm_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0 - -staff_r:staff_su_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 -staff_r:staff_sudo_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 - -sysadm_r:sysadm_su_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 -sysadm_r:sysadm_sudo_t:s0 sysadm_r:sysadm_t:s0 - -user_r:user_su_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 -user_r:user_sudo_t:s0 sysadm_r:sysadm_t:s0 user_r:user_t:s0 diff --git a/config/appconfig-mcs/default_type b/config/appconfig-mcs/default_type deleted file mode 100644 index 33528d6..0000000 --- a/config/appconfig-mcs/default_type +++ /dev/null @@ -1,6 +0,0 @@ -auditadm_r:auditadm_t -secadm_r:secadm_t -sysadm_r:sysadm_t -staff_r:staff_t -unconfined_r:unconfined_t -user_r:user_t diff --git a/config/appconfig-mcs/failsafe_context b/config/appconfig-mcs/failsafe_context deleted file mode 100644 index 999abd9..0000000 --- a/config/appconfig-mcs/failsafe_context +++ /dev/null @@ -1 +0,0 @@ -sysadm_r:sysadm_t:s0 diff --git a/config/appconfig-mcs/guest_u_default_contexts b/config/appconfig-mcs/guest_u_default_contexts deleted file mode 100644 index 90e5262..0000000 --- a/config/appconfig-mcs/guest_u_default_contexts +++ /dev/null @@ -1,6 +0,0 @@ -guest_r:guest_t:s0 guest_r:guest_t:s0 -system_r:crond_t:s0 guest_r:guest_t:s0 -system_r:initrc_su_t:s0 guest_r:guest_t:s0 -system_r:local_login_t:s0 guest_r:guest_t:s0 -system_r:remote_login_t:s0 guest_r:guest_t:s0 -system_r:sshd_t:s0 guest_r:guest_t:s0 diff --git a/config/appconfig-mcs/initrc_context b/config/appconfig-mcs/initrc_context deleted file mode 100644 index 30ab971..0000000 --- a/config/appconfig-mcs/initrc_context +++ /dev/null @@ -1 +0,0 @@ -system_u:system_r:initrc_t:s0 diff --git a/config/appconfig-mcs/media b/config/appconfig-mcs/media deleted file mode 100644 index 81f3463..0000000 --- a/config/appconfig-mcs/media +++ /dev/null @@ -1,3 +0,0 @@ -cdrom system_u:object_r:removable_device_t:s0 -floppy system_u:object_r:removable_device_t:s0 -disk system_u:object_r:fixed_disk_device_t:s0 diff --git a/config/appconfig-mcs/removable_context b/config/appconfig-mcs/removable_context deleted file mode 100644 index 7fcc56e..0000000 --- a/config/appconfig-mcs/removable_context +++ /dev/null @@ -1 +0,0 @@ -system_u:object_r:removable_t:s0 diff --git a/config/appconfig-mcs/root_default_contexts b/config/appconfig-mcs/root_default_contexts deleted file mode 100644 index 7805778..0000000 --- a/config/appconfig-mcs/root_default_contexts +++ /dev/null @@ -1,11 +0,0 @@ -system_r:crond_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:cronjob_t:s0 staff_r:cronjob_t:s0 user_r:cronjob_t:s0 -system_r:local_login_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 user_r:user_t:s0 - -staff_r:staff_su_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 user_r:user_t:s0 -sysadm_r:sysadm_su_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 user_r:user_t:s0 -user_r:user_su_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 user_r:user_t:s0 - -# -# Uncomment if you want to automatically login as sysadm_r -# -#system_r:sshd_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 user_r:user_t:s0 diff --git a/config/appconfig-mcs/securetty_types b/config/appconfig-mcs/securetty_types deleted file mode 100644 index 527d835..0000000 --- a/config/appconfig-mcs/securetty_types +++ /dev/null @@ -1 +0,0 @@ -user_tty_device_t diff --git a/config/appconfig-mcs/seusers b/config/appconfig-mcs/seusers deleted file mode 100644 index dc5f1e4..0000000 --- a/config/appconfig-mcs/seusers +++ /dev/null @@ -1,3 +0,0 @@ -system_u:system_u:s0-mcs_systemhigh -root:root:s0-mcs_systemhigh -__default__:user_u:s0 diff --git a/config/appconfig-mcs/staff_u_default_contexts b/config/appconfig-mcs/staff_u_default_contexts deleted file mode 100644 index 881a292..0000000 --- a/config/appconfig-mcs/staff_u_default_contexts +++ /dev/null @@ -1,10 +0,0 @@ -system_r:local_login_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 -system_r:remote_login_t:s0 staff_r:staff_t:s0 -system_r:sshd_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 -system_r:crond_t:s0 staff_r:cronjob_t:s0 -system_r:xdm_t:s0 staff_r:staff_t:s0 -staff_r:staff_su_t:s0 staff_r:staff_t:s0 -staff_r:staff_sudo_t:s0 staff_r:staff_t:s0 -sysadm_r:sysadm_su_t:s0 sysadm_r:sysadm_t:s0 -sysadm_r:sysadm_sudo_t:s0 sysadm_r:sysadm_t:s0 - diff --git a/config/appconfig-mcs/unconfined_u_default_contexts b/config/appconfig-mcs/unconfined_u_default_contexts deleted file mode 100644 index 106e093..0000000 --- a/config/appconfig-mcs/unconfined_u_default_contexts +++ /dev/null @@ -1,9 +0,0 @@ -system_r:crond_t:s0 unconfined_r:unconfined_t:s0 unconfined_r:unconfined_cronjob_t:s0 -system_r:initrc_t:s0 unconfined_r:unconfined_t:s0 -system_r:local_login_t:s0 unconfined_r:unconfined_t:s0 -system_r:remote_login_t:s0 unconfined_r:unconfined_t:s0 -system_r:rshd_t:s0 unconfined_r:unconfined_t:s0 -system_r:sshd_t:s0 unconfined_r:unconfined_t:s0 -system_r:sysadm_su_t:s0 unconfined_r:unconfined_t:s0 -system_r:unconfined_t:s0 unconfined_r:unconfined_t:s0 -system_r:xdm_t:s0 unconfined_r:unconfined_t:s0 diff --git a/config/appconfig-mcs/user_u_default_contexts b/config/appconfig-mcs/user_u_default_contexts deleted file mode 100644 index cacbc93..0000000 --- a/config/appconfig-mcs/user_u_default_contexts +++ /dev/null @@ -1,8 +0,0 @@ -system_r:local_login_t:s0 user_r:user_t:s0 -system_r:remote_login_t:s0 user_r:user_t:s0 -system_r:sshd_t:s0 user_r:user_t:s0 -system_r:crond_t:s0 user_r:cronjob_t:s0 -system_r:xdm_t:s0 user_r:user_t:s0 -user_r:user_su_t:s0 user_r:user_t:s0 -user_r:user_sudo_t:s0 user_r:user_t:s0 - diff --git a/config/appconfig-mcs/userhelper_context b/config/appconfig-mcs/userhelper_context deleted file mode 100644 index dc37a69..0000000 --- a/config/appconfig-mcs/userhelper_context +++ /dev/null @@ -1 +0,0 @@ -system_u:sysadm_r:sysadm_t:s0 diff --git a/config/appconfig-mcs/x_contexts b/config/appconfig-mcs/x_contexts deleted file mode 100644 index 0b32044..0000000 --- a/config/appconfig-mcs/x_contexts +++ /dev/null @@ -1,105 +0,0 @@ -# -# Config file for XSELinux extension -# - - -# -## -### Rules for X Clients -## -# - -# -# The default client rule defines a context to be used for all clients -# connecting to the server from a remote host. -# -client * system_u:object_r:remote_t:s0 - - -# -## -### Rules for X Properties -## -# - -# -# Property rules map a property name to a context. A default property -# rule indicated by an asterisk should follow all other property rules. -# -# Properties that normal clients may only read -property _SELINUX_* system_u:object_r:seclabel_xproperty_t:s0 - -# Clipboard and selection properties -property CUT_BUFFER? system_u:object_r:clipboard_xproperty_t:s0 - -# Default fallback type -property * system_u:object_r:xproperty_t:s0 - - -# -## -### Rules for X Extensions -## -# - -# -# Extension rules map an extension name to a context. A default extension -# rule indicated by an asterisk should follow all other extension rules. -# -# Restricted extensions -extension SELinux system_u:object_r:security_xextension_t:s0 - -# Standard extensions -extension * system_u:object_r:xextension_t:s0 - - -# -## -### Rules for X Selections -## -# - -# Selection rules map a selection name to a context. A default selection -# rule indicated by an asterisk should follow all other selection rules. -# -# Standard selections -selection PRIMARY system_u:object_r:clipboard_xselection_t:s0 -selection CLIPBOARD system_u:object_r:clipboard_xselection_t:s0 - -# Default fallback type -selection * system_u:object_r:xselection_t:s0 - - -# -## -### Rules for X Events -## -# - -# -# Event rules map an event protocol name to a context. A default event -# rule indicated by an asterisk should follow all other event rules. -# -# Input events -event X11:KeyPress system_u:object_r:input_xevent_t:s0 -event X11:KeyRelease system_u:object_r:input_xevent_t:s0 -event X11:ButtonPress system_u:object_r:input_xevent_t:s0 -event X11:ButtonRelease system_u:object_r:input_xevent_t:s0 -event X11:MotionNotify system_u:object_r:input_xevent_t:s0 -event XInputExtension:DeviceKeyPress system_u:object_r:input_xevent_t:s0 -event XInputExtension:DeviceKeyRelease system_u:object_r:input_xevent_t:s0 -event XInputExtension:DeviceButtonPress system_u:object_r:input_xevent_t:s0 -event XInputExtension:DeviceButtonRelease system_u:object_r:input_xevent_t:s0 -event XInputExtension:DeviceMotionNotify system_u:object_r:input_xevent_t:s0 -event XInputExtension:DeviceValuator system_u:object_r:input_xevent_t:s0 -event XInputExtension:ProximityIn system_u:object_r:input_xevent_t:s0 -event XInputExtension:ProximityOut system_u:object_r:input_xevent_t:s0 - -# Client message events -event X11:ClientMessage system_u:object_r:client_xevent_t:s0 -event X11:SelectionNotify system_u:object_r:client_xevent_t:s0 -event X11:UnmapNotify system_u:object_r:client_xevent_t:s0 -event X11:ConfigureNotify system_u:object_r:client_xevent_t:s0 - -# Default fallback type -event * system_u:object_r:xevent_t:s0 diff --git a/config/appconfig-mcs/xguest_u_default_contexts b/config/appconfig-mcs/xguest_u_default_contexts deleted file mode 100644 index 574363b..0000000 --- a/config/appconfig-mcs/xguest_u_default_contexts +++ /dev/null @@ -1,7 +0,0 @@ -system_r:crond_t:s0 xguest_r:xguest_t:s0 -system_r:initrc_su_t:s0 xguest_r:xguest_t:s0 -system_r:local_login_t:s0 xguest_r:xguest_t:s0 -system_r:remote_login_t:s0 xguest_r:xguest_t:s0 -system_r:sshd_t:s0 xguest_r:xguest_t:s0 -system_r:xdm_t:s0 xguest_r:xguest_t:s0 -xguest_r:xguest_t:s0 xguest_r:xguest_t:s0 diff --git a/config/appconfig-mls/dbus_contexts b/config/appconfig-mls/dbus_contexts deleted file mode 100644 index 116e684..0000000 --- a/config/appconfig-mls/dbus_contexts +++ /dev/null @@ -1,6 +0,0 @@ - - - - - diff --git a/config/appconfig-mls/default_contexts b/config/appconfig-mls/default_contexts deleted file mode 100644 index 22aeb67..0000000 --- a/config/appconfig-mls/default_contexts +++ /dev/null @@ -1,15 +0,0 @@ -system_r:crond_t:s0 user_r:cronjob_t:s0 staff_r:cronjob_t:s0 sysadm_r:cronjob_t:s0 system_r:cronjob_t:s0 unconfined_r:unconfined_cronjob_t:s0 -system_r:local_login_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0 -system_r:remote_login_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 unconfined_r:unconfined_t:s0 -system_r:sshd_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0 -system_r:sulogin_t:s0 sysadm_r:sysadm_t:s0 -system_r:xdm_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0 - -staff_r:staff_su_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 -staff_r:staff_sudo_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 - -sysadm_r:sysadm_su_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 -sysadm_r:sysadm_sudo_t:s0 sysadm_r:sysadm_t:s0 - -user_r:user_su_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 -user_r:user_sudo_t:s0 sysadm_r:sysadm_t:s0 user_r:user_t:s0 diff --git a/config/appconfig-mls/default_type b/config/appconfig-mls/default_type deleted file mode 100644 index 33528d6..0000000 --- a/config/appconfig-mls/default_type +++ /dev/null @@ -1,6 +0,0 @@ -auditadm_r:auditadm_t -secadm_r:secadm_t -sysadm_r:sysadm_t -staff_r:staff_t -unconfined_r:unconfined_t -user_r:user_t diff --git a/config/appconfig-mls/failsafe_context b/config/appconfig-mls/failsafe_context deleted file mode 100644 index 999abd9..0000000 --- a/config/appconfig-mls/failsafe_context +++ /dev/null @@ -1 +0,0 @@ -sysadm_r:sysadm_t:s0 diff --git a/config/appconfig-mls/guest_u_default_contexts b/config/appconfig-mls/guest_u_default_contexts deleted file mode 100644 index e2106ef..0000000 --- a/config/appconfig-mls/guest_u_default_contexts +++ /dev/null @@ -1,5 +0,0 @@ -guest_r:guest_t:s0 guest_r:guest_t:s0 -system_r:crond_t:s0 guest_r:guest_t:s0 -system_r:local_login_t:s0 guest_r:guest_t:s0 -system_r:remote_login_t:s0 guest_r:guest_t:s0 -system_r:sshd_t:s0 guest_r:guest_t:s0 diff --git a/config/appconfig-mls/initrc_context b/config/appconfig-mls/initrc_context deleted file mode 100644 index 4598f92..0000000 --- a/config/appconfig-mls/initrc_context +++ /dev/null @@ -1 +0,0 @@ -system_u:system_r:initrc_t:s0-mls_systemhigh diff --git a/config/appconfig-mls/media b/config/appconfig-mls/media deleted file mode 100644 index 81f3463..0000000 --- a/config/appconfig-mls/media +++ /dev/null @@ -1,3 +0,0 @@ -cdrom system_u:object_r:removable_device_t:s0 -floppy system_u:object_r:removable_device_t:s0 -disk system_u:object_r:fixed_disk_device_t:s0 diff --git a/config/appconfig-mls/removable_context b/config/appconfig-mls/removable_context deleted file mode 100644 index 7fcc56e..0000000 --- a/config/appconfig-mls/removable_context +++ /dev/null @@ -1 +0,0 @@ -system_u:object_r:removable_t:s0 diff --git a/config/appconfig-mls/root_default_contexts b/config/appconfig-mls/root_default_contexts deleted file mode 100644 index 7805778..0000000 --- a/config/appconfig-mls/root_default_contexts +++ /dev/null @@ -1,11 +0,0 @@ -system_r:crond_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:cronjob_t:s0 staff_r:cronjob_t:s0 user_r:cronjob_t:s0 -system_r:local_login_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 user_r:user_t:s0 - -staff_r:staff_su_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 user_r:user_t:s0 -sysadm_r:sysadm_su_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 user_r:user_t:s0 -user_r:user_su_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 user_r:user_t:s0 - -# -# Uncomment if you want to automatically login as sysadm_r -# -#system_r:sshd_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 user_r:user_t:s0 diff --git a/config/appconfig-mls/securetty_types b/config/appconfig-mls/securetty_types deleted file mode 100644 index 527d835..0000000 --- a/config/appconfig-mls/securetty_types +++ /dev/null @@ -1 +0,0 @@ -user_tty_device_t diff --git a/config/appconfig-mls/seusers b/config/appconfig-mls/seusers deleted file mode 100644 index dc156bf..0000000 --- a/config/appconfig-mls/seusers +++ /dev/null @@ -1,3 +0,0 @@ -system_u:system_u:s0-mls_systemhigh -root:root:s0-mls_systemhigh -__default__:user_u:s0 diff --git a/config/appconfig-mls/staff_u_default_contexts b/config/appconfig-mls/staff_u_default_contexts deleted file mode 100644 index 881a292..0000000 --- a/config/appconfig-mls/staff_u_default_contexts +++ /dev/null @@ -1,10 +0,0 @@ -system_r:local_login_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 -system_r:remote_login_t:s0 staff_r:staff_t:s0 -system_r:sshd_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 -system_r:crond_t:s0 staff_r:cronjob_t:s0 -system_r:xdm_t:s0 staff_r:staff_t:s0 -staff_r:staff_su_t:s0 staff_r:staff_t:s0 -staff_r:staff_sudo_t:s0 staff_r:staff_t:s0 -sysadm_r:sysadm_su_t:s0 sysadm_r:sysadm_t:s0 -sysadm_r:sysadm_sudo_t:s0 sysadm_r:sysadm_t:s0 - diff --git a/config/appconfig-mls/unconfined_u_default_contexts b/config/appconfig-mls/unconfined_u_default_contexts deleted file mode 100644 index 106e093..0000000 --- a/config/appconfig-mls/unconfined_u_default_contexts +++ /dev/null @@ -1,9 +0,0 @@ -system_r:crond_t:s0 unconfined_r:unconfined_t:s0 unconfined_r:unconfined_cronjob_t:s0 -system_r:initrc_t:s0 unconfined_r:unconfined_t:s0 -system_r:local_login_t:s0 unconfined_r:unconfined_t:s0 -system_r:remote_login_t:s0 unconfined_r:unconfined_t:s0 -system_r:rshd_t:s0 unconfined_r:unconfined_t:s0 -system_r:sshd_t:s0 unconfined_r:unconfined_t:s0 -system_r:sysadm_su_t:s0 unconfined_r:unconfined_t:s0 -system_r:unconfined_t:s0 unconfined_r:unconfined_t:s0 -system_r:xdm_t:s0 unconfined_r:unconfined_t:s0 diff --git a/config/appconfig-mls/user_u_default_contexts b/config/appconfig-mls/user_u_default_contexts deleted file mode 100644 index cacbc93..0000000 --- a/config/appconfig-mls/user_u_default_contexts +++ /dev/null @@ -1,8 +0,0 @@ -system_r:local_login_t:s0 user_r:user_t:s0 -system_r:remote_login_t:s0 user_r:user_t:s0 -system_r:sshd_t:s0 user_r:user_t:s0 -system_r:crond_t:s0 user_r:cronjob_t:s0 -system_r:xdm_t:s0 user_r:user_t:s0 -user_r:user_su_t:s0 user_r:user_t:s0 -user_r:user_sudo_t:s0 user_r:user_t:s0 - diff --git a/config/appconfig-mls/userhelper_context b/config/appconfig-mls/userhelper_context deleted file mode 100644 index dc37a69..0000000 --- a/config/appconfig-mls/userhelper_context +++ /dev/null @@ -1 +0,0 @@ -system_u:sysadm_r:sysadm_t:s0 diff --git a/config/appconfig-mls/x_contexts b/config/appconfig-mls/x_contexts deleted file mode 100644 index 0b32044..0000000 --- a/config/appconfig-mls/x_contexts +++ /dev/null @@ -1,105 +0,0 @@ -# -# Config file for XSELinux extension -# - - -# -## -### Rules for X Clients -## -# - -# -# The default client rule defines a context to be used for all clients -# connecting to the server from a remote host. -# -client * system_u:object_r:remote_t:s0 - - -# -## -### Rules for X Properties -## -# - -# -# Property rules map a property name to a context. A default property -# rule indicated by an asterisk should follow all other property rules. -# -# Properties that normal clients may only read -property _SELINUX_* system_u:object_r:seclabel_xproperty_t:s0 - -# Clipboard and selection properties -property CUT_BUFFER? system_u:object_r:clipboard_xproperty_t:s0 - -# Default fallback type -property * system_u:object_r:xproperty_t:s0 - - -# -## -### Rules for X Extensions -## -# - -# -# Extension rules map an extension name to a context. A default extension -# rule indicated by an asterisk should follow all other extension rules. -# -# Restricted extensions -extension SELinux system_u:object_r:security_xextension_t:s0 - -# Standard extensions -extension * system_u:object_r:xextension_t:s0 - - -# -## -### Rules for X Selections -## -# - -# Selection rules map a selection name to a context. A default selection -# rule indicated by an asterisk should follow all other selection rules. -# -# Standard selections -selection PRIMARY system_u:object_r:clipboard_xselection_t:s0 -selection CLIPBOARD system_u:object_r:clipboard_xselection_t:s0 - -# Default fallback type -selection * system_u:object_r:xselection_t:s0 - - -# -## -### Rules for X Events -## -# - -# -# Event rules map an event protocol name to a context. A default event -# rule indicated by an asterisk should follow all other event rules. -# -# Input events -event X11:KeyPress system_u:object_r:input_xevent_t:s0 -event X11:KeyRelease system_u:object_r:input_xevent_t:s0 -event X11:ButtonPress system_u:object_r:input_xevent_t:s0 -event X11:ButtonRelease system_u:object_r:input_xevent_t:s0 -event X11:MotionNotify system_u:object_r:input_xevent_t:s0 -event XInputExtension:DeviceKeyPress system_u:object_r:input_xevent_t:s0 -event XInputExtension:DeviceKeyRelease system_u:object_r:input_xevent_t:s0 -event XInputExtension:DeviceButtonPress system_u:object_r:input_xevent_t:s0 -event XInputExtension:DeviceButtonRelease system_u:object_r:input_xevent_t:s0 -event XInputExtension:DeviceMotionNotify system_u:object_r:input_xevent_t:s0 -event XInputExtension:DeviceValuator system_u:object_r:input_xevent_t:s0 -event XInputExtension:ProximityIn system_u:object_r:input_xevent_t:s0 -event XInputExtension:ProximityOut system_u:object_r:input_xevent_t:s0 - -# Client message events -event X11:ClientMessage system_u:object_r:client_xevent_t:s0 -event X11:SelectionNotify system_u:object_r:client_xevent_t:s0 -event X11:UnmapNotify system_u:object_r:client_xevent_t:s0 -event X11:ConfigureNotify system_u:object_r:client_xevent_t:s0 - -# Default fallback type -event * system_u:object_r:xevent_t:s0 diff --git a/config/appconfig-mls/xguest_u_default_contexts b/config/appconfig-mls/xguest_u_default_contexts deleted file mode 100644 index 574363b..0000000 --- a/config/appconfig-mls/xguest_u_default_contexts +++ /dev/null @@ -1,7 +0,0 @@ -system_r:crond_t:s0 xguest_r:xguest_t:s0 -system_r:initrc_su_t:s0 xguest_r:xguest_t:s0 -system_r:local_login_t:s0 xguest_r:xguest_t:s0 -system_r:remote_login_t:s0 xguest_r:xguest_t:s0 -system_r:sshd_t:s0 xguest_r:xguest_t:s0 -system_r:xdm_t:s0 xguest_r:xguest_t:s0 -xguest_r:xguest_t:s0 xguest_r:xguest_t:s0 diff --git a/config/appconfig-standard/dbus_contexts b/config/appconfig-standard/dbus_contexts deleted file mode 100644 index 116e684..0000000 --- a/config/appconfig-standard/dbus_contexts +++ /dev/null @@ -1,6 +0,0 @@ - - - - - diff --git a/config/appconfig-standard/default_contexts b/config/appconfig-standard/default_contexts deleted file mode 100644 index 6141347..0000000 --- a/config/appconfig-standard/default_contexts +++ /dev/null @@ -1,15 +0,0 @@ -system_r:crond_t user_r:cronjob_t staff_r:cronjob_t sysadm_r:cronjob_t system_r:system_crond_t unconfined_r:unconfined_cronjob_t -system_r:local_login_t user_r:user_t staff_r:staff_t sysadm_r:sysadm_t unconfined_r:unconfined_t -system_r:remote_login_t user_r:user_t staff_r:staff_t unconfined_r:unconfined_t -system_r:sshd_t user_r:user_t staff_r:staff_t sysadm_r:sysadm_t unconfined_r:unconfined_t -system_r:sulogin_t sysadm_r:sysadm_t -system_r:xdm_t user_r:user_t staff_r:staff_t sysadm_r:sysadm_t unconfined_r:unconfined_t - -staff_r:staff_su_t user_r:user_t staff_r:staff_t sysadm_r:sysadm_t -staff_r:staff_sudo_t sysadm_r:sysadm_t staff_r:staff_t - -sysadm_r:sysadm_su_t user_r:user_t staff_r:staff_t sysadm_r:sysadm_t -sysadm_r:sysadm_sudo_t sysadm_r:sysadm_t - -user_r:user_su_t user_r:user_t staff_r:staff_t sysadm_r:sysadm_t -user_r:user_sudo_t sysadm_r:sysadm_t user_r:user_t diff --git a/config/appconfig-standard/default_type b/config/appconfig-standard/default_type deleted file mode 100644 index 33528d6..0000000 --- a/config/appconfig-standard/default_type +++ /dev/null @@ -1,6 +0,0 @@ -auditadm_r:auditadm_t -secadm_r:secadm_t -sysadm_r:sysadm_t -staff_r:staff_t -unconfined_r:unconfined_t -user_r:user_t diff --git a/config/appconfig-standard/failsafe_context b/config/appconfig-standard/failsafe_context deleted file mode 100644 index 2f96c9f..0000000 --- a/config/appconfig-standard/failsafe_context +++ /dev/null @@ -1 +0,0 @@ -sysadm_r:sysadm_t diff --git a/config/appconfig-standard/guest_u_default_contexts b/config/appconfig-standard/guest_u_default_contexts deleted file mode 100644 index 85a35fb..0000000 --- a/config/appconfig-standard/guest_u_default_contexts +++ /dev/null @@ -1,7 +0,0 @@ -guest_r:guest_t guest_r:guest_t -system_r:crond_t guest_r:guest_t -system_r:initrc_su_t guest_r:guest_t -system_r:local_login_t guest_r:guest_t -system_r:remote_login_t guest_r:guest_t -system_r:sshd_t guest_r:guest_t - diff --git a/config/appconfig-standard/initrc_context b/config/appconfig-standard/initrc_context deleted file mode 100644 index 7fcf70b..0000000 --- a/config/appconfig-standard/initrc_context +++ /dev/null @@ -1 +0,0 @@ -system_u:system_r:initrc_t diff --git a/config/appconfig-standard/media b/config/appconfig-standard/media deleted file mode 100644 index de2a652..0000000 --- a/config/appconfig-standard/media +++ /dev/null @@ -1,3 +0,0 @@ -cdrom system_u:object_r:removable_device_t -floppy system_u:object_r:removable_device_t -disk system_u:object_r:fixed_disk_device_t diff --git a/config/appconfig-standard/removable_context b/config/appconfig-standard/removable_context deleted file mode 100644 index d4921f0..0000000 --- a/config/appconfig-standard/removable_context +++ /dev/null @@ -1 +0,0 @@ -system_u:object_r:removable_t diff --git a/config/appconfig-standard/root_default_contexts b/config/appconfig-standard/root_default_contexts deleted file mode 100644 index f522568..0000000 --- a/config/appconfig-standard/root_default_contexts +++ /dev/null @@ -1,11 +0,0 @@ -system_r:crond_t unconfined_r:unconfined_t sysadm_r:cronjob_t staff_r:cronjob_t user_r:cronjob_t -system_r:local_login_t unconfined_r:unconfined_t sysadm_r:sysadm_t staff_r:staff_t user_r:user_t - -staff_r:staff_su_t unconfined_r:unconfined_t sysadm_r:sysadm_t staff_r:staff_t user_r:user_t -sysadm_r:sysadm_su_t unconfined_r:unconfined_t sysadm_r:sysadm_t staff_r:staff_t user_r:user_t -user_r:user_su_t unconfined_r:unconfined_t sysadm_r:sysadm_t staff_r:staff_t user_r:user_t - -# -# Uncomment if you want to automatically login as sysadm_r -# -#system_r:sshd_t unconfined_r:unconfined_t sysadm_r:sysadm_t staff_r:staff_t user_r:user_t diff --git a/config/appconfig-standard/securetty_types b/config/appconfig-standard/securetty_types deleted file mode 100644 index 527d835..0000000 --- a/config/appconfig-standard/securetty_types +++ /dev/null @@ -1 +0,0 @@ -user_tty_device_t diff --git a/config/appconfig-standard/seusers b/config/appconfig-standard/seusers deleted file mode 100644 index 36b193b..0000000 --- a/config/appconfig-standard/seusers +++ /dev/null @@ -1,3 +0,0 @@ -system_u:system_u -root:root -__default__:user_u diff --git a/config/appconfig-standard/staff_u_default_contexts b/config/appconfig-standard/staff_u_default_contexts deleted file mode 100644 index c2a5ea8..0000000 --- a/config/appconfig-standard/staff_u_default_contexts +++ /dev/null @@ -1,10 +0,0 @@ -system_r:local_login_t staff_r:staff_t sysadm_r:sysadm_t -system_r:remote_login_t staff_r:staff_t -system_r:sshd_t staff_r:staff_t sysadm_r:sysadm_t -system_r:crond_t staff_r:cronjob_t -system_r:xdm_t staff_r:staff_t -staff_r:staff_su_t staff_r:staff_t -staff_r:staff_sudo_t staff_r:staff_t -sysadm_r:sysadm_su_t sysadm_r:sysadm_t -sysadm_r:sysadm_sudo_t sysadm_r:sysadm_t - diff --git a/config/appconfig-standard/unconfined_u_default_contexts b/config/appconfig-standard/unconfined_u_default_contexts deleted file mode 100644 index e340b21..0000000 --- a/config/appconfig-standard/unconfined_u_default_contexts +++ /dev/null @@ -1,9 +0,0 @@ -system_r:crond_t unconfined_r:unconfined_t unconfined_r:unconfined_cronjob_t -system_r:initrc_t unconfined_r:unconfined_t -system_r:local_login_t unconfined_r:unconfined_t -system_r:remote_login_t unconfined_r:unconfined_t -system_r:rshd_t unconfined_r:unconfined_t -system_r:sshd_t unconfined_r:unconfined_t -system_r:sysadm_su_t unconfined_r:unconfined_t -system_r:unconfined_t unconfined_r:unconfined_t -system_r:xdm_t unconfined_r:unconfined_t diff --git a/config/appconfig-standard/user_u_default_contexts b/config/appconfig-standard/user_u_default_contexts deleted file mode 100644 index f5bfac3..0000000 --- a/config/appconfig-standard/user_u_default_contexts +++ /dev/null @@ -1,8 +0,0 @@ -system_r:local_login_t user_r:user_t -system_r:remote_login_t user_r:user_t -system_r:sshd_t user_r:user_t -system_r:crond_t user_r:cronjob_t -system_r:xdm_t user_r:user_t -user_r:user_su_t user_r:user_t -user_r:user_sudo_t user_r:user_t - diff --git a/config/appconfig-standard/userhelper_context b/config/appconfig-standard/userhelper_context deleted file mode 100644 index 081e93b..0000000 --- a/config/appconfig-standard/userhelper_context +++ /dev/null @@ -1 +0,0 @@ -system_u:sysadm_r:sysadm_t diff --git a/config/appconfig-standard/x_contexts b/config/appconfig-standard/x_contexts deleted file mode 100644 index 5b752f8..0000000 --- a/config/appconfig-standard/x_contexts +++ /dev/null @@ -1,105 +0,0 @@ -# -# Config file for XSELinux extension -# - - -# -## -### Rules for X Clients -## -# - -# -# The default client rule defines a context to be used for all clients -# connecting to the server from a remote host. -# -client * system_u:object_r:remote_t - - -# -## -### Rules for X Properties -## -# - -# -# Property rules map a property name to a context. A default property -# rule indicated by an asterisk should follow all other property rules. -# -# Properties that normal clients may only read -property _SELINUX_* system_u:object_r:seclabel_xproperty_t - -# Clipboard and selection properties -property CUT_BUFFER? system_u:object_r:clipboard_xproperty_t - -# Default fallback type -property * system_u:object_r:xproperty_t - - -# -## -### Rules for X Extensions -## -# - -# -# Extension rules map an extension name to a context. A default extension -# rule indicated by an asterisk should follow all other extension rules. -# -# Restricted extensions -extension SELinux system_u:object_r:security_xextension_t - -# Standard extensions -extension * system_u:object_r:xextension_t - - -# -## -### Rules for X Selections -## -# - -# Selection rules map a selection name to a context. A default selection -# rule indicated by an asterisk should follow all other selection rules. -# -# Standard selections -selection PRIMARY system_u:object_r:clipboard_xselection_t -selection CLIPBOARD system_u:object_r:clipboard_xselection_t - -# Default fallback type -selection * system_u:object_r:xselection_t - - -# -## -### Rules for X Events -## -# - -# -# Event rules map an event protocol name to a context. A default event -# rule indicated by an asterisk should follow all other event rules. -# -# Input events -event X11:KeyPress system_u:object_r:input_xevent_t -event X11:KeyRelease system_u:object_r:input_xevent_t -event X11:ButtonPress system_u:object_r:input_xevent_t -event X11:ButtonRelease system_u:object_r:input_xevent_t -event X11:MotionNotify system_u:object_r:input_xevent_t -event XInputExtension:DeviceKeyPress system_u:object_r:input_xevent_t -event XInputExtension:DeviceKeyRelease system_u:object_r:input_xevent_t -event XInputExtension:DeviceButtonPress system_u:object_r:input_xevent_t -event XInputExtension:DeviceButtonRelease system_u:object_r:input_xevent_t -event XInputExtension:DeviceMotionNotify system_u:object_r:input_xevent_t -event XInputExtension:DeviceValuator system_u:object_r:input_xevent_t -event XInputExtension:ProximityIn system_u:object_r:input_xevent_t -event XInputExtension:ProximityOut system_u:object_r:input_xevent_t - -# Client message events -event X11:ClientMessage system_u:object_r:client_xevent_t -event X11:SelectionNotify system_u:object_r:client_xevent_t -event X11:UnmapNotify system_u:object_r:client_xevent_t -event X11:ConfigureNotify system_u:object_r:client_xevent_t - -# Default fallback type -event * system_u:object_r:xevent_t diff --git a/config/appconfig-standard/xguest_u_default_contexts b/config/appconfig-standard/xguest_u_default_contexts deleted file mode 100644 index 55d44d1..0000000 --- a/config/appconfig-standard/xguest_u_default_contexts +++ /dev/null @@ -1,7 +0,0 @@ -system_r:crond_t xguest_r:xguest_t -system_r:initrc_su_t xguest_r:xguest_t -system_r:local_login_t xguest_r:xguest_t -system_r:remote_login_t xguest_r:xguest_t -system_r:sshd_t xguest_r:xguest_t -system_r:xdm_t xguest_r:xguest_t -xguest_r:xguest_t xguest_r:xguest_t diff --git a/config/local.users b/config/local.users deleted file mode 100644 index 7e2bf7a..0000000 --- a/config/local.users +++ /dev/null @@ -1,21 +0,0 @@ -################################## -# -# User configuration. -# -# This file defines additional users recognized by the system security policy. -# Only the user identities defined in this file and the system.users file -# may be used as the user attribute in a security context. -# -# Each user has a set of roles that may be entered by processes -# with the users identity. The syntax of a user declaration is: -# -# user username roles role_set [ level default_level range allowed_range ]; -# -# The MLS default level and allowed range should only be specified if -# MLS was enabled in the policy. - -# sample for administrative user -# user jadmin roles { staff_r sysadm_r }; - -# sample for regular user -#user jdoe roles { user_r };