- Allow domains to use kerberos to read file_context file
- Allow mozilla_plugin to connect to port 8081
- Tighten security on virtual machines
- block_suspend is caps2
- Allow realmd to run ipa, really needs to be an unconfined_domain
- Allow sandbox domains to use inherted terminals
- Allow pscd to use devices labeled svirt_image_t in order to use cat cards.
- Add label for new alsa pid
- Alsa now uses a pid file and needs to setsched
- Allow nova domains to connect to mysql port
- Allow quantum to connect to keystone port
- Allow nova-console to talk with mysql over unix stream socket
- Allow dirsrv to stream connect to uuidd
- Fix transition for cobbler lib files
- Label all nagios plugin as unconfined by default
- Add httpd_serve_cobbler_files()
- Allow mdadm to read /dev/sr0 and create tmp files
- Allow certwatch to send mails
- Allow livecd to transition to rpm_script_t
- Add cache dir support for cobbler
- label shared libraries in /opt/google/chrome as testrel_shlib_t
- Fix labeling for nagios plugins
- Disable support for .xsession-errors-:[digit] file name transition for now unti