895396 * Fri Feb 26 2016 Lukas Vrabec <lvrabec@redhat.com> 3.13.1-158.8

Authored and Committed by lvrabec 4 years ago
    * Fri Feb 26 2016 Lukas Vrabec <lvrabec@redhat.com> 3.13.1-158.8
    - Allow amanda to manipulate the tape changer to load the necessary tapes. rhbz#1311759
    - Allow keepalived to create netlink generic sockets. rhbz#1311756
    - Allow modemmanager to read /etc/passwd file.
    - Fix macro name from snmp_manage_snmp_var_lib_files to snmp_manage_var_lib_files in cupsd policy.
    - Allow hplip driver to write to its MIB index files stored in the /var/lib/net-snmp/mib_indexes. Resolves: rhbz#1291033
    - Allow collectd setgid capability Resolves:#1310896
    - Allow adcli running as sssd_t to write krb5.keytab file.
    - Allow abrt-hook-ccpp to getattr on all executables. BZ(1284304)
    - Revert "Label /usr/libexec/rpm-ostreed as rpm_exec_t. BZ(1309075)"
    - Allow kexec to read kernel module files in /usr/lib/modules.
    - Label /usr/libexec/rpm-ostreed as rpm_exec_t. BZ(1309075)
    - Label all files named /var/run/.*nologin.* as systemd_logind_var_run_t.
    - Allow systemd-logind to create .#nologinXXXXXX labeled as systemd_logind_var_run_t in /var/run/systemd/ rhbz#1285019
    - Allow systemd_networkd_t to write kmsg, when kernel was started with following params: systemd.debug systemd.log_level=debug systemd.log_target=kmsg rhbz#1311444
    - Allow ipsec to read home certs, when connecting to VPN. rhbz#1301319
    - ipsec: fix stringSwan charon-nm
file modified
+43 -26
file modified
+49 -24
file modified
+19 -1