Compare commits

...

7 commits

Author SHA1 Message Date
Harald Hoyer ba9ad138e7 Merge remote-tracking branch 'origin/master' into harald-bak 2020-03-13 10:29:49 +01:00
Harald Hoyer 13fbf0b8c6 pkglist.txt 2020-03-13 09:25:38 +01:00
Harald Hoyer 69edd27a19 Merge remote-tracking branch 'origin/master' into harald 2020-03-13 09:15:42 +01:00
Harald Hoyer e9e992286b pkglist.txt: add skim 2020-03-13 09:03:19 +01:00
Harald Hoyer a806ac7119 10verity/verity-generator: --restart-on-corruption 2020-03-13 09:02:18 +01:00
Harald Hoyer 43724ed9e2 pkglist.txt: add ShellCheck 2020-02-28 08:19:26 +01:00
Harald Hoyer b9093fd208 Allow containers to access /dev/kvm 2020-02-27 10:31:20 +01:00
2 changed files with 98 additions and 2 deletions

View file

@ -34,6 +34,8 @@ require {
type user_home_dir_t; type user_home_dir_t;
type chkpwd_t; type chkpwd_t;
type xdm_var_lib_t; type xdm_var_lib_t;
type container_t;
type kvm_device_t;
class sock_file { create write }; class sock_file { create write };
class file { create getattr map open read relabelfrom relabelto rename setattr unlink write }; class file { create getattr map open read relabelfrom relabelto rename setattr unlink write };
class process { dyntransition setcurrent }; class process { dyntransition setcurrent };
@ -43,8 +45,13 @@ require {
class dbus send_msg; class dbus send_msg;
class sock_file { read write }; class sock_file { read write };
class lnk_file { getattr read }; class lnk_file { getattr read };
class chr_file { getattr ioctl open read write };
} }
#============= container_t ==============
allow container_t kvm_device_t:chr_file getattr;
allow container_t kvm_device_t:chr_file { ioctl open read write };
#============= NetworkManager_t ============== #============= NetworkManager_t ==============
allow NetworkManager_t iscsi_unit_file_t:service { reload status }; allow NetworkManager_t iscsi_unit_file_t:service { reload status };

View file

@ -3,24 +3,41 @@ adwaita-gtk2-theme
adwaita-icon-theme adwaita-icon-theme
alsa-firmware alsa-firmware
alsa-tools-firmware.x86_64 alsa-tools-firmware.x86_64
asciidoc
asciinema
atmel-firmware atmel-firmware
audit-libs-devel
authselect authselect
autofs autofs
b43-openfwwf b43-openfwwf
bash-completion bash-completion
bat
bfa-firmware bfa-firmware
bind-utils bind-utils
bzip2 bzip2
ca-certificates ca-certificates
@c-development
clang-devel
cmake
container-selinux container-selinux
crun crun
cryptsetup-devel
cups cups
cups-client cups-client
cups-ipptool cups-ipptool
@development-libs
@development-tools
dnf
docbook-dtds
docbook-style-xsl
ebtables ebtables
emacs elfutils-devel
exa
fd-find
fedora-gpg-keys fedora-gpg-keys
fedora-packager
fedora-release fedora-release
fedpkg
findutils findutils
firefox firefox
firewalld-filesystem firewalld-filesystem
@ -28,17 +45,33 @@ flatpak
@Fonts @Fonts
fwupd fwupd
gawk gawk
gcc
gcc-c++
GeoIP-GeoLite-data GeoIP-GeoLite-data
geolite2-city geolite2-city
geolite2-country geolite2-country
gettext
git git
glib2-devel
glibc-static
@GNOME @GNOME
gnome-initial-setup gnome-initial-setup
gnome-remote-desktop gnome-remote-desktop
gnu-efi gnu-efi
gnu-efi-devel
gnupg gnupg
gnutls-devel
gobject-introspection-devel
golang
gperf
gpgme-devel
gstreamer1-plugin-openh264
gtk3-devel
help2man help2man
ibm-plex-mono-fonts
ImageMagick
iptables iptables
iptables-devel
iputils iputils
ipw2100-firmware ipw2100-firmware
ipw2200-firmware ipw2200-firmware
@ -59,16 +92,50 @@ iwl6000g2a-firmware
iwl6000g2b-firmware iwl6000g2b-firmware
iwl6050-firmware iwl6050-firmware
iwl7260-firmware iwl7260-firmware
java
keybase
kmod-devel
kup
libacl-devel
libassuan-devel
libblkid-devel
libcap-devel
libcurl-devel
libertas-sd8686-firmware libertas-sd8686-firmware
libertas-sd8787-firmware libertas-sd8787-firmware
libertas-usb8388-firmware libertas-usb8388-firmware
libgcrypt-devel
libgpg-error-devel
libidn2-devel
libmicrohttpd-devel
libmount-devel
libpng12
libseccomp-devel
libselinux-devel
libvarlink-devel
libvarlink-util
libvirt-bash-completion
libvirt-client
libvirt-daemon-config-network
libvirt-daemon-kvm
libxkbcommon-devel
libxslt
linux-firmware linux-firmware
lld
lsof lsof
lz4
lz4-devel
make make
man-db man-db
mc mc
meson
midisport-firmware midisport-firmware
mosh mosh
mozilla-openh264
musl-clang
musl-devel
musl-gcc
musl-libc-static
nautilus nautilus
net-tools net-tools
NetworkManager NetworkManager
@ -85,17 +152,37 @@ nss-mdns
nss-tools nss-tools
opensc opensc
openssh-server openssh-server
openssl-devel
openssl-static
ostree-devel
pam-devel
pam_yubico
perl-File-Slurp
pesign pesign
pigz pigz
pkgconfig
podman podman
procps-ng
psmisc psmisc
python3-devel
python3-future
python3-lxml python3-lxml
python3-pip
python3-wheel python3-wheel
qemu-system-aarch64
qemu-system-arm
qemu-system-ppc
qemu-system-s390x
qrencode-devel
ripgrep
rlwrap
rpcbind rpcbind
rsync rsync
ruby
screen screen
slirp4netns
sssd-kcm sssd-kcm
systemd-devel
thunderbird
tmux tmux
toolbox toolbox
tree tree
@ -106,4 +193,6 @@ virt-manager
which which
xclip xclip
xz xz
xz-devel
zd1211-firmware zd1211-firmware
zlib-static