318acc9 * Wed Jun 06 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.2-22

Authored and Committed by lvrabec 5 years ago
    * Wed Jun 06 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.2-22
    - Fix typo in authconfig policy
    - Update ctdb domain to support gNFS setup
    - Allow authconfig_t dbus chat with policykit
    - Allow lircd_t domain to read system state
    - Revert "Allow fsdaemon_t do send emails BZ(1582701)"
    - Typo in uuidd policy
    - Allow tangd_t domain read certs
    - Allow vpnc_t domain to read configfs_t files/dirs BZ(1583107)
    - Allow vpnc_t domain to read generic certs BZ(1583100)
    - Label /var/lib/phpMyAdmin directory as httpd_sys_rw_content_t BZ(1584811)
    - Allow NetworkManager_ssh_t domain to be system dbud client
    - Allow virt_qemu_ga_t read utmp
    - Add capability dac_override to system_mail_t domain
    - Update uuidd policy to reflect last changes from base branch
    - Add cap dac_override to procmail_t domain
    - Allow sendmail to mmap etc_aliases_t files BZ(1578569)
    - Add new interface dbus_read_pid_sock_files()
    - Allow mpd_t domain read config_home files if mpd_enable_homedirs boolean will be enabled
    - Allow fsdaemon_t do send emails BZ(1582701)
    - Allow firewalld_t domain to request kernel module BZ(1573501)
    - Allow chronyd_t domain to send send msg via dgram socket BZ(1584757)
    - Add sys_admin capability to fprint_t SELinux domain
    - Allow cyrus_t domain to create own files under /var/run BZ(1582885)
    - Allow cachefiles_kernel_t domain to have capability dac_override
    - Update policy for ypserv_t domain
    - Allow zebra_t domain to bind on tcp/udp ports labeled as qpasa_agent_port_t
    - Allow cyrus to have dac_override capability
    - Dontaudit action when abrt-hook-ccpp is writing to nscd sockets
    - Fix homedir polyinstantion under mls
    - Fixed typo in init.if file
    - Allow systemd to remove generic tmpt files BZ(1583144)
    - Update init_named_socket_activation() interface to also allow systemd create objects in /var/run with proper label during socket activation
    - Allow systemd-networkd and systemd-resolved services read system-dbusd socket BZ(1579075)
    - Fix typo in authlogin SELinux security module
    - Allod nsswitch_domain attribute to be system dbusd client BZ(1584632)
    - Allow audisp_t domain to mmap audisp_exec_t binary
    - Update ssh_domtrans_keygen interface to allow mmap ssh_keygen_exec_t binary file
    - Label tcp/udp ports 2612 as qpasa_agetn_port_t
    
        
file modified
+2 -0
file modified
+43 -3
file modified
+3 -3