254caa6 * Wed Jul 18 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-35

Authored and Committed by lvrabec 5 years ago
    * Wed Jul 18 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-35
    - Allow cupsd_t domain to mmap cupsd_etc_t files
    - Allow kadmind_t domain to mmap krb5kdc_principal_t
    - Allow virtlogd_t domain to read virt_etc_t link files
    - Allow dirsrv_t domain to read crack db
    - Dontaudit pegasus_t to require sys_admin capability
    - Allow mysqld_t domain to exec mysqld_exec_t binary files
    - Allow abrt_t odmain to read rhsmcertd lib files
    - Allow winbind_t domain to request kernel module loads
    - Allow tomcat_domain to read cgroup_t files
    - Allow varnishlog_t domain to mmap varnishd_var_lib_t files
    - Allow innd_t domain to mmap news_spool_t files
    - Label HOME_DIR/mozilla.pdf file as mozilla_home_t instead of user_home_t
    - Allow fenced_t domain to reboot
    - Allow amanda_t domain to read network system state
    - Allow abrt_t domain to read rhsmcertd logs
    - Dontaudit syslogd to watching top llevel dirs when imfile module is enabled
    - Revert "Allow unconfined and sysadm users to use bpftool BZ(1591440)"
    - Allow userdomain sudo domains to use generic ptys
    - Allow systemd labeled as init_t to get sysvipc info BZ(1600877)
    - Label /sbin/xtables-legacy-multi and /sbin/xtables-nft-multi as iptables_exec_t BZ(1600690)
    
        
file modified
+2 -0
file modified
+25 -3
file modified
+3 -3