328d370 * Mon Dec 19 2022 Zdenek Pytela <zpytela@redhat.com> - 38.4-1

Authored and Committed by zpytela 2 years ago
    * Mon Dec 19 2022 Zdenek Pytela <zpytela@redhat.com> - 38.4-1
    - Allow NetworkManager and wpa_supplicant the bpf capability
    - Allow systemd-rfkill the bpf capability
    - Allow winbind-rpcd manage samba_share_t files and dirs
    - Label /var/lib/httpd/md(/.*)? with httpd_sys_rw_content_t
    - Allow gpsd the sys_ptrace userns capability
    - Introduce gpsd_tmp_t for sockfiles managed by gpsd_t
    - Allow load_policy_t write to unallocated ttys
    - Allow ndc read hardware state information
    - Allow system mail service read inherited certmonger runtime files
    - Add lpr_roles  to system_r roles
    - Revert "Allow insights-client run lpr and allow the proper role"
    - Allow stalld to read /sys/kernel/security/lockdown file
    - Allow keepalived to set resource limits
    - Add policy for mptcpd
    - Add policy for rshim
    - Allow admin users to create user namespaces
    - Allow journalctl relabel with var_log_t and syslogd_var_run_t files
    - Do not run restorecon /etc/NetworkManager/dispatcher.d in targeted
    - Trim changelog so that it starts at F35 time
    - Add mptcpd and rshim modules
    
        
file modified
+24 -2
file modified
+2 -2