Ecosyste.ms: OpenCollective
An open API service for software projects hosted on Open Collective.
github.com/QubesOS/qubes-core-agent-linux
Qubes component: core-agent-linux
https://github.com/QubesOS/qubes-core-agent-linux
[email protected] was missing a Before=network.target
ordering. Such an ordering is ...
65d1045f26d0a2fbbf86562bc86aeae5a7da1ea4 authored almost 2 years ago by Maja Kądziołka <[email protected]>
Besides SELinux not supported on Debian here, default behaviour of
maintainer scripts there woul...
c140522b20084bd3842e899375d4c62c530bfa5b authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
This broke due to an SELinux policy bug.
560ee2aabd8209cda8d9d36529ba046777ff3d68 authored almost 2 years ago by Demi Marie Obenour <[email protected]>c7a0ed9dc0fe81ab3dbe7417422bc4ea46512405 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Move it together with related preset file that disables conflicting
pipewire.
That was the last...
57862b0860f3cd62d9935647cb9a0d85133a5e77 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>Don't support SELinux in Debian yet.
43e671472aad9a904426ce7f4842b6b860645ade authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
* origin/pr/343: (53 commits)
Allow init_t and unconfined_service_t to transition to anything
...
dbus-send is used in qubes.Suspend{Pre,Post} services.
289bb581f85a957eadcd275c447bb72b3b054719 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>3323957d743e97429f84e48d2bc91fbf831f289f authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Fix typo, use correct variable.
91c4e12f2908e6c01481b97e19c4fb21a795d939 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
The former is needed for SELinuxContext= in systemd unit files to work
for all domains. The lat...
Needed for block device export.
bc96279546928f0735fb19b482c4670e3246106b authored almost 2 years ago by Demi Marie Obenour <[email protected]>Otherwise the system will not boot.
9c0618ebfea170feb254e98f05881faa49e6587d authored almost 2 years ago by Demi Marie Obenour <[email protected]>It won't make the R4.2 release.
fc9e7eb96c2f82ebfb49be2a4c6429c54d354713 authored almost 2 years ago by Demi Marie Obenour <[email protected]>
All scripts in init/ get installed, but relabel-root.sh is expected only
for SELinux, which isn'...
18003b71dc6dfc8fda165e29dc11baaee69b837a authored almost 2 years ago by Demi Marie Obenour <[email protected]>
2019a3a60076cf8c60f66134ef1a53001408f584 authored almost 2 years ago by Demi Marie Obenour <[email protected]>
It probably does not work.
7e6d634ca2082dd60192174bda5a0e646a4af7f0 authored almost 2 years ago by Demi Marie Obenour <[email protected]>This file will always exist at runtime.
23e3624130e2e9d9ddb66af9fb97479fa9e7a19e authored almost 2 years ago by Demi Marie Obenour <[email protected]>239bde8991a81a4443d6508603e9c725e302c1a8 authored almost 2 years ago by Demi Marie Obenour <[email protected]>
0e22478fb6671c49ac38bef47ec790d8c94abbba authored almost 2 years ago by Demi Marie Obenour <[email protected]>
-i was being considered an argument for -e, but it isn't syntactically
correct.
fdcadde5715290601b5fab0176894b58231ed2b8 authored almost 2 years ago by Demi Marie Obenour <[email protected]>
which will happen if selinux-autorelabel.service (which now just runs
/bin/true) cannot be started.
da2d9b09a4ebc76d037292ace4d8d2fb429b92fe authored almost 2 years ago by Demi Marie Obenour <[email protected]>
This will trigger a relabel on the next reboot.
27980b3d481a386e0f585d32c9597ea9bce21cb5 authored almost 2 years ago by Demi Marie Obenour <[email protected]>It breaks the Debian build.
de88b38d9686e25d69c2809118e80e6ad8a63ac5 authored almost 2 years ago by Demi Marie Obenour <[email protected]>They are noarch, so mark them as such.
fe8ea757ff6d68bffed23ec4be34714eab5e399e authored almost 2 years ago by Demi Marie Obenour <[email protected]>It does not belong in the main package.
204c8b05352935818bc2065934a209912c1b96a4 authored almost 2 years ago by Demi Marie Obenour <[email protected]>It is a worse user experience.
This reverts commit 4886bc6451dfb9f8b473e9d6aa3d708c0a1e241a.
77b30eab13b9c08fe27637bfecbf5026a3ff14ec authored almost 2 years ago by Demi Marie Obenour <[email protected]>53a4b710eb2d9defba34d46ef24440cd4cd68d7c authored almost 2 years ago by Demi Marie Obenour <[email protected]>
e463b833de33bf037afd9c311e25b374ae074cbf authored almost 2 years ago by Demi Marie Obenour <[email protected]>
If relabeling fails then so should boot.
fdfba65ccca3c80affe9ebeebc50ef3d98a383b7 authored almost 2 years ago by Demi Marie Obenour <[email protected]>cdc05a7b2a83bf2739a78c89863e03d19f8fe046 authored almost 2 years ago by Demi Marie Obenour <[email protected]>
Force it to pull in qubes-relabel-root.service instead of the default
selinux-autorelabel.servic...
The rest will be relabeled after reboot.
e973bb1d82e021d8aad17d9ae0851f322cdb6765 authored almost 2 years ago by Demi Marie Obenour <[email protected]>Otherwise it will fail if /.autorelabel doesn’t exist.
91d3a1093cdbfa66fe2dd55b28dacd50b663de63 authored almost 2 years ago by Demi Marie Obenour <[email protected]>The label of PID 1 might be wrong. Also conflict with shutdown.target.
b55bda2a115e25fb72955d12a0943906a4cc77d7 authored almost 2 years ago by Demi Marie Obenour <[email protected]>This replaces the standard service.
09ed7455a71f0186538ae19880688e8a63685bda authored almost 2 years ago by Demi Marie Obenour <[email protected]>Otherwise the user could wind up with a broken system.
25e301341b45e98f8c5974bcb4cf5d0ee9257f9e authored almost 2 years ago by Demi Marie Obenour <[email protected]>
This is necessary to ensure that the system is properly labeled for the
next boot.
selinux-autorelabel.service is buggy and does a bunch of stuff that
makes no sense in Qubes OS. ...
If a volume is not persistent, then the next boot of the VM would need
to relabel it again. Ins...
Otherwise various mount points do not get relabeled, which causes
breakage.
This will be used by later autorelabel code.
26d2cdb10451bc578e2ab36a847cdb058af05aab authored almost 2 years ago by Demi Marie Obenour <[email protected]>
This changes qubes-sysinit.sh to check for bad service names and for
errors. This ensures that ...
This might be a cause of OpenQA failures.
eb68f88c7bd033593993452ca473d65bb759bef8 authored almost 2 years ago by Demi Marie Obenour <[email protected]>Needed by qrexec possibly?
1f235d8360d66e25770befa52430e614cce16ce1 authored almost 2 years ago by Demi Marie Obenour <[email protected]>b21e4134835cfe74d38a8db3cb35055d7cf4a526 authored almost 2 years ago by Demi Marie Obenour <[email protected]>
This is probably a bug somewhere else.
db5ed057663080711093548b957818f2d29d7b31 authored almost 2 years ago by Demi Marie Obenour <[email protected]>
This ensures correct labeling of volumes. systemd units are used to
ensure that SELinux being e...
Needed for rather obvious reasons.
db8538e15dc800b1c0780a78f6fc4f1ab7c73186 authored almost 2 years ago by Demi Marie Obenour <[email protected]>Trivial performance win
cf6ba7ad3c2e3ae52ec1df039fe35ad583387335 authored almost 2 years ago by Demi Marie Obenour <[email protected]>I believe this is why qubesdb kept failing to start.
3906db418e0495b9b1ab32a677e4d332db167556 authored almost 2 years ago by Demi Marie Obenour <[email protected]>
The scriptlet needs to handle the case where the file is empty, which
breaks sed. Also lock bot...
These needed to be added to qubes-misc.fc.
f028aadcc777dd451d575a215337f755848a3f7a authored almost 2 years ago by Demi Marie Obenour <[email protected]>so /rw/usrlocal and /usr/local need to be handled separately.
ca5c51a85677e3956ab795bd50e623d51e465b8e authored almost 2 years ago by Demi Marie Obenour <[email protected]>
It didn't uninstall the qubes-misc policy module, and it unconditionally
removed the substitutio...
Also avoid depending on a specific policy type
e20cb8fd618b03dbae5054b92590e3228233f15a authored almost 2 years ago by Demi Marie Obenour <[email protected]>This uses RPM rich dependency syntax.
1b1711a8f04e85e30eadc623e53d3608ef232e41 authored almost 2 years ago by Demi Marie Obenour <[email protected]>Another step towards making Qubes OS work with SELinux enforcing.
f955f2f1952c33c543f3456abaaad735d1214385 authored almost 2 years ago by Demi Marie Obenour <[email protected]>This avoids problems due to SELinux.
8c712b975c0acdef557c62caf023f111417f51b1 authored about 2 years ago by Demi Marie Obenour <[email protected]>
This sets up the needed file context substitutions. It also provides
polices for qfile-unpacker...
* origin/pr/391:
Add upgrades-status-notify and upgrades-installed-check to archlinux package
* origin/pr/354:
Declare each target (other than .PHONY) only once
makefile fix
simplify m...
* origin/pr/393:
qvm-template: fallback to other mirrors
* origin/pr/397:
Replace ImageMagick with GraphicsMagick
e248fae8e4b7cc89dc6f1b26e68b114fabbdf78a authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
f2bd5c5e4fc29809bb78f27fab8b41beaa5e61fc authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
* origin/pr/399:
Add purging of no longer allowed connections from conntrack
765661af37e447eb009278ceaedcd26d744b4246 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
f2db11ae93593682c2868df920e99c8649947b83 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Finally switch to R4.2 repositories.
This reverts commit cdc12084ef6cbd935ffee2803ed782b2175fc156.
90478b0b197b93623f263073af88220797516787 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Previously adding a firewall rule didn't close already established connections:
https://github.c...
Using GLib.spawn_async instead of subprocess.call or subprocess.Popen
This prevents Nautilus fro...
https://github.com/QubesOS/qubes-issues/issues/5009
a1f4ebfad988d523c26c9a4a8c2b21ad6f092cdf authored about 2 years ago by Mateusz Piórkowski <[email protected]>The get_file_items method of Nautilus.MenuProvider no longer take the window argument.
https://g...
0f7f0d6f811039a22208fd402cef21ebc02f801f authored about 2 years ago by noskb <[email protected]>45a7af946524c63e1fb3328a571a5fb626db8e5a authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
c7ca77d4d263ddbb83e254a6f4e0aa8ac91b5b30 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
16e32363377973df2fde5b24f723b18d8d4081a9 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
6bfc858e3930735f114ae65b8b4b02a477ca5cad authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
761230f0b8e61d7d5a46d5dbfcc2cb424ba082b4 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
* origin/pr/371:
Cohere with debian guidance on using 3rd party repos
If download from a selected mirror failed to start at all (missing file,
connection error etc), ...
This avoids a pitfall: if commands are given for a target in more than
one place, all but the la...
d10d43cfc63b269b43b982ccefa8ad4dca235cbe authored about 2 years ago by Demi Marie Obenour <[email protected]>
190e3619afb4ae9ab20988b720a0b65bd2010020 authored about 2 years ago by Demi Marie Obenour <[email protected]>
This lets the harden-network-interfaces service control hardening.
cae4590add76e66ebb4c95e9376d143ec035f6a7 authored about 2 years ago by Demi Marie Obenour <[email protected]>
This ensures that any Qubes-provided configuration can be overridden by
the user.
to ensure that errors are properly handled
c6874f26c595f35857519cd925d6f6365f5dff9f authored about 2 years ago by Demi Marie Obenour <[email protected]>This indicates a serious problem.
674fb76d4f2d5ff21335a9ef26f65ee5e1a9b3e7 authored about 2 years ago by Demi Marie Obenour <[email protected]>This is done via various sysctls.
42560df2e8f889d17a17fe37bcc279bae06cf079 authored about 2 years ago by Demi Marie Obenour <[email protected]>
* origin/pr/347:
Make qubes-sync-time.service oneshot
Better error message when 'date' fails...
eee6b0a3b219d06cfd8d8fa46c70a9afcec69c00 authored about 2 years ago by Alexander Paetzelt <[email protected]>
'zenity --progress --auto-close' exits on reading a progress input of
100 or more. If the estima...
* origin/pr/384:
Use link scope for routes
* origin/pr/385:
prepare-suspend: do not disable virtual interfaces before suspend
prepare-s...
* qvm-template-resume:
qvm-template: resume failed downloads
qvm-template: move cleanup to '...