Compare commits

...
Sign in to create a new pull request.

15 commits

Author SHA1 Message Date
Orion Poplawski
47267b8b95 Merge branch 'rawhide' into epel8 2023-03-30 10:35:40 -06:00
Orion Poplawski
4ddcc9cedd Merge branch 'rawhide' into epel8 2023-03-30 10:24:44 -06:00
Orion Poplawski
5b326afa43 Back port selinux policy for EL8 2023-03-30 10:19:55 -06:00
Orion Poplawski
0b591ce88f Merge branch 'rawhide' into epel8 2023-03-30 10:11:26 -06:00
Richard Shaw
5b24bf6347 Merge branch 'epel8' of ssh://pkgs.fedoraproject.org/rpms/fail2ban into epel8 2020-11-24 08:35:53 -06:00
Richard Shaw
9fee5ac98d Merge branch 'master' into epel8 2020-11-24 08:35:41 -06:00
Troy Dawson
77b10e8ff7 remove package.cfg per new epel-playground policy 2020-09-24 17:15:18 +00:00
Richard Shaw
d0e0203ac3 Merge branch 'master' into epel8 2020-08-28 06:52:11 -05:00
Richard Shaw
5bdf8a6e85 Add conditonals back for EL 7 as it's being brought up to date.
Add patch to deal with nftables not accepting ":" as a port separator.
2020-07-27 20:32:15 -05:00
Richard Shaw
ad4708c364 Change default firewalld backend from ipset to rich-rules as ipset causes
firewalld to use legacy iptables. Fixes RHBZ#1823746.
Remove conditionals for EL versions less than 7.
2020-04-16 07:38:51 -05:00
Orion Poplawski
704b2b845e Merge branch 'f31' into epel8 2020-01-20 21:08:50 -07:00
Orion Poplawski
02204f1e86 Merge branch 'f31' into epel8 2020-01-15 19:59:37 -07:00
Orion Poplawski
3faffef992 Merge branch 'master' into epel8 2019-11-23 16:44:17 -07:00
Orion Poplawski
f9761d0752 Merge branch 'master' into epel8 2019-08-19 08:37:18 -06:00
Igor Gnatenko
1877a39928 "Adding package.cfg file" 2019-08-19 08:14:47 +02:00

View file

@ -99,18 +99,40 @@ logging_read_syslog_pid(fail2ban_t)
logging_dontaudit_search_audit_logs(fail2ban_t)
logging_mmap_generic_logs(fail2ban_t)
logging_mmap_journal(fail2ban_t)
gen_require(`
type var_log_t, auditd_log_t;
class dir { watch };
class file { watch };
')
allow fail2ban_t fail2ban_log_t:file watch;
# Not in EL9 yet
#logging_watch_audit_log_files(fail2ban_t)
gen_require(`
type var_log_t, auditd_log_t;
')
watch_files_pattern(fail2ban_t, auditd_log_t, auditd_log_t)
# Not in EL8
#watch_files_pattern(fail2ban_t, auditd_log_t, auditd_log_t)
allow fail2ban_t auditd_log_t:dir search_dir_perms;
allow fail2ban_t auditd_log_t:file { getattr watch };
#logging_watch_audit_log_dirs(fail2ban_t)
allow fail2ban_t var_log_t:dir search_dir_perms;
watch_dirs_pattern(fail2ban_t, auditd_log_t, auditd_log_t)
logging_watch_generic_log_dirs(fail2ban_t)
logging_watch_journal_dir(fail2ban_t)
# Not in EL8
#watch_dirs_pattern(fail2ban_t, auditd_log_t, auditd_log_t)
allow fail2ban_t auditd_log_t:dir search_dir_perms;
allow fail2ban_t auditd_log_t:dir { getattr watch };
# Not in EL8
#logging_watch_generic_log_dirs(fail2ban_t)
files_search_var(fail2ban_t)
allow fail2ban_t var_log_t:dir { getattr watch };
# Not in EL8
#logging_watch_journal_dir(fail2ban_t)
gen_require(`
type syslogd_var_run_t;
')
allow fail2ban_t syslogd_var_run_t:dir { getattr watch };
mta_send_mail(fail2ban_t)