9a58e62 * Fri Sep 02 2022 Zdenek Pytela <zpytela@redhat.com> - 37.10-1

Authored and Committed by zpytela 2 years ago
    * Fri Sep 02 2022 Zdenek Pytela <zpytela@redhat.com> - 37.10-1
    - Allow ipsec_t read/write tpm devices
    - Allow rhcd execute all executables
    - Update rhcd policy for executing additional commands 2
    - Update insights-client policy for additional commands execution 2
    - Allow sysadm_t read raw memory devices
    - Allow chronyd send and receive chronyd/ntp client packets
    - Allow ssh client read kerberos homedir config files
    - Label /var/log/rhc-worker-playbook with rhcd_var_log_t
    - Update insights-client policy (auditctl, gpg, journal)
    - Allow system_cronjob_t domtrans to rpm_script_t
    - Allow smbd_t process noatsecure permission for winbind_rpcd_t
    - Update tor_bind_all_unreserved_ports interface
    - Allow chronyd bind UDP sockets to ptp_event ports.
    - Allow unconfined and sysadm users transition for /root/.gnupg
    - Add gpg_filetrans_admin_home_content() interface
    - Update rhcd policy for executing additional commands
    - Update insights-client policy for additional commands execution
    - Add userdom_view_all_users_keys() interface
    - Allow gpg read and write generic pty type
    - Allow chronyc read and write generic pty type
    - Allow system_dbusd ioctl kernel with a unix stream sockets
    - Allow samba-bgqd to read a printer list
    - Allow stalld get and set scheduling policy of all domains.
    - Allow unconfined_t transition to targetclid_home_t
    
        
file modified
+28 -2
file modified
+2 -2