c7e90bc * Sun Feb 07 2021 Zdenek Pytela <zpytela@redhat.com> - 3.14.7-18

Authored and Committed by zpytela 3 years ago
    * Sun Feb 07 2021 Zdenek Pytela <zpytela@redhat.com> - 3.14.7-18
    - Allow lockdown confidentiality for domains using perf_event
    - define lockdown class and access
    - Add perfmon capability for all domains using perf_event
    - Allow ptp4l_t bpf capability to run bpf programs
    - Revert "Allow ptp4l_t sys_admin capability to run bpf programs"
    - access_vectors: Add new capabilities to cap2
    - Allow systemd and systemd-resolved watch dbus pid objects
    - Add new watch interfaces in the base and userdomain policy
    - Add watch permissions for contrib packages
    - Allow xdm watch /usr directories
    - Allow getty watch its private runtime files
    - Add watch permissions for nscd and sssd
    - Add watch permissions for firewalld and NetworkManager
    - Add watch permissions for syslogd
    - Add watch permissions for systemd services
    - Allow restorecond watch /etc dirs
    - Add watch permissions for user domain types
    - Add watch permissions for init
    - Add basic watch interfaces for systemd
    - Add basic watch interfaces to the base module
    - Add additional watch object permissions sets and patterns
    - Allow init_t to watch localization symlinks
    - Allow init_t to watch mount directories
    - Allow init_t to watch cgroup files
    - Add basic watch patterns
    - Add new watch* permissions
    
        
file modified
+30 -2
file modified
+2 -2