6c07cc8 * Wed Sep 10 2014 Lukas Vrabec <lvrabec@redhat.com> 3.13.1-79

Authored and Committed by lvrabec 9 years ago
    * Wed Sep 10 2014 Lukas Vrabec <lvrabec@redhat.com> 3.13.1-79
    - Re-arange openshift_net_read_t rules.
    - Kernel is reporting random block_suspends, we should dontaudit these until the kernel is fixed in Rawhide
    - Allow jockey_t to use tmpfs files
    - Allow pppd to create sock_files in /var/run
    - Allow geoclue to stream connect to smart card service
    - Allow docker to read all of /proc
    - ALlow passeneger to read/write apache stream socket.
    - Dontaudit read init state for svirt_t.
    - Label /usr/sbin/unbound-control as named_exec_t (#1130510)
    - Add support for /var/lbi/cockpit directory.
    - Add support for ~/. speech-dispatcher.
    - Allow nmbd to read /proc/sys/kernel/core_pattern.
    - aLlow wine domains to create wine_home symlinks.
    - Allow policykit_auth_t access check and read usr config files.
    - Dontaudit access check on home_root_t for policykit-auth.
    - hv_vss_daemon wants to list /boot
    - update gpg_agent_env_file booelan to allow manage user tmp files for gpg-agent
    - Fix label for /usr/bin/courier/bin/sendmail
    - Allow munin services plugins to execute fail2ban-client in fail2ban_client_t domain.
    - Allow unconfined_r to access unconfined_service_t.
    - Add label for ~/.local/share/fonts
    - Add init_dontaudit_read_state() interface.
    - Add systemd_networkd_var_run_t labeling for /var/run/systemd/netif and allow systemd-networkd to manage it.
    - Allow udev_t mounton udev_var_run_t dirs #(1128618)
    - Add files_dontaudit_access_check_home_dir() inteface.
    
        
file modified
+431 -296
file modified
+423 -302
file modified
+28 -1