d02146b * Wed Sep 14 2022 Zdenek Pytela <zpytela@redhat.com> - 37.11-1

Authored and Committed by zpytela 2 years ago
    * Wed Sep 14 2022 Zdenek Pytela <zpytela@redhat.com> - 37.11-1
    - Allow tor get filesystem attributes
    - Allow utempter append to login_userdomain stream
    - Allow login_userdomain accept a stream connection to XDM
    - Allow login_userdomain write to boltd named pipes
    - Allow staff_u and user_u users write to bolt pipe
    - Allow login_userdomain watch various directories
    - Update rhcd policy for executing additional commands 5
    - Update rhcd policy for executing additional commands 4
    - Allow rhcd create rpm hawkey logs with correct label
    - Allow systemd-gpt-auto-generator to check for empty dirs
    - Update rhcd policy for executing additional commands 3
    - Allow journalctl read rhcd fifo files
    - Update insights-client policy for additional commands execution 5
    - Allow init remount all file_type filesystems
    - Confine insights-client systemd unit
    - Update insights-client policy for additional commands execution 4
    - Allow pcp pmcd search tracefs and acct_data dirs
    - Allow httpd read network sysctls
    - Dontaudit domain map permission on directories
    - Revert "Allow X userdomains to mmap user_fonts_cache_t dirs"
    - Revert "Allow xdm_t domain to mmap /var/lib/gdm/.cache/fontconfig BZ(1725509)"
    - Update insights-client policy for additional commands execution 3
    - Allow systemd permissions needed for sandboxed services
    - Add rhcd module
    - Make dependency on rpm-plugin-selinux unordered
    
        
file modified
+29 -2
file modified
+2 -2