97359b4 * Tue Sep 22 2015 Lukas Vrabec <lvrabec@redhat.com> 3.13.1-148

Authored and Committed by lvrabec 8 years ago
    * Tue Sep 22 2015 Lukas Vrabec <lvrabec@redhat.com> 3.13.1-148
    - Allow rpcbind_t domain to change file owner and group
    - rpm-ostree has a daemon mode now and need to speak to polkit/logind for authorization. BZ(#1264988)
    - Allow dnssec-trigger to send generic signal to Network-Manager. BZ(#1242578)
    - Allow smbcontrol to create a socket in /var/samba which uses for a communication with smbd, nmbd and winbind.
    - Add apache_read_pid_files() interface
    - Remove duplicate rules in dirsrv-admin policy
    - Allow dirsrv-admin read httpd pid files.
    - Allow dirsrv-admin read httpd pid files.
    - Add label for dirsrv-admin unit file.
    - Allow qpid daemon to connect on amqp tcp port.
    - Allow dirsrvadmin-script read /etc/passwd file Allow dirsrvadmin-script exec systemctl
    - Add labels for afs binaries: dafileserver, davolserver, salvageserver, dasalvager
    - Add lsmd_plugin_t sys_admin capability, Allow lsmd_plugin_t getattr from sysfs filesystem.
    - Allow rhsmcertd_t send signull to unconfined_service_t domains.
    - Revert "Allow pcp to read docker lib files."
    - Label /usr/libexec/dbus-1/dbus-daemon-launch-helper  as dbusd_exec_t to have systemd dbus services running in the correct domain instead of unconfined_service_t if unconfined.pp module is enabled. BZ(#1262993)
    - Allow pcp to read docker lib files.
    - Label /etc/ipa/nssdb dir as cert_t
    - Add interface unconfined_server_signull() to allow domains send signull to unconfined_service_t
    
        
file modified
+42 -37
file modified
+225 -111
file modified
+22 -1