86eb7dc * Tue Aug 23 2016 Lukas Vrabec <lvrabec@redhat.com> 3.13.1-191.13

Authored and Committed by lvrabec 7 years ago
    * Tue  Aug 23 2016 Lukas Vrabec <lvrabec@redhat.com> 3.13.1-191.13
    - Label /var/run/corosync-qnetd and /var/run/corosync-qdevice as cluster_var_run_t. Note: corosync policy is now par of rhcs module
    - Allow krb5kdc_t to read krb4kdc_conf_t dirs.
    - Update networkmanager_filetrans_named_content() interface to allow source domain to create also temad dir in /var/run.
    - Make confined users working again
    - Fix hypervkvp module
    - Allow ipmievd domain to create lock files in /var/lock/subsys/
    - Update policy for ipmievd daemon. Contain:    Allowing reading sysfs, passwd,kernel modules   Execuring bin_t,insmod_t
    - Allow systemd to stop systemd-machined daemon. This allows stop virtual machines.
    - Label /usr/libexec/iptables/iptables.init as iptables_exec_t Allow iptables creating lock file in /var/lock/subsys/
    
        
file modified
+0 -0
file modified
+93 -79
file modified
+59 -32
file modified
+12 -1