0ec1286 * Mon Feb 05 2024 Zdenek Pytela <zpytela@redhat.com> - 40.11-1

Authored and Committed by zpytela 3 months ago
    * Mon Feb 05 2024 Zdenek Pytela <zpytela@redhat.com> - 40.11-1
    - Replace init domtrans rule for confined users to allow exec init
    - Update dbus_role_template() to allow user service status
    - Allow polkit status all systemd services
    - Allow setroubleshootd create and use inherited io_uring
    - Allow load_policy read and write generic ptys
    - Allow gpg manage rpm cache
    - Allow login_userdomain name_bind to howl and xmsg udp ports
    - Allow rules for confined users logged in plasma
    - Label /dev/iommu with iommu_device_t
    - Remove duplicate file context entries in /run
    - Dontaudit getty and plymouth the checkpoint_restore capability
    - Allow su domains write login records
    - Revert "Allow su domains write login records"
    - Allow login_userdomain delete session dbusd tmp socket files
    - Allow unix dgram sendto between exim processes
    - Allow su domains write login records
    - Allow smbd_t to watch user_home_dir_t if samba_enable_home_dirs is on
    
        
file modified
+21 -2
file modified
+2 -2