* Tue Apr 23 2024 Zdenek Pytela <zpytela@redhat.com> - 39.6-1
- Allow smbd_t to watch user_home_dir_t if samba_enable_home_dirs is on
- Allow auditd read all domains process state
- Allow keyutils-dns-resolver connect to the system log service
- dontaudit execmem for modemmanager
- Dontaudit systemd-hwdb dac_override capability
- Allow plymouthd log during shutdown
- Allow journalctl_t read filesystem sysctls
- Replace init domtrans rule for confined users to allow exec init
- Allow sulogin relabel tty1
- Dontaudit sulogin the checkpoint_restore capability
- Allow wireguard work with firewall-cmd