fa67022 * Thu Jun 14 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-33

Authored and Committed by lvrabec 5 years ago
    * Thu Jun 14 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-33
    - Merge pull request #60 from vmojzis/rawhide
    - Allow tangd_t domain stream connect to sssd
    - Allow oddjob_t domain to chat with systemd via dbus
    - Allow freeipmi domains to mmap sysfs files
    - Fix typo in logwatch interface file
    - Allow spamd_t to manage logwatch_cache_t files/dirs
    - Allow dnsmasw_t domain to create own tmp files and manage mnt files
    - Allow fail2ban_client_t to inherit rlimit information from parent process
    - Allow nscd_t to read kernel sysctls
    - Label /var/log/conman.d as conman_log_t
    - Add dac_override capability to tor_t domain
    - Allow certmonger_t to readwrite to user_tmp_t dirs
    - Allow abrt_upload_watch_t domain to read general certs
    - Allow chornyd_t read phc2sys_t shared memory
    - Add several allow rules for pesign policy:
    - Add setgid and setuid capabilities to mysqlfd_safe_t domain
    - Add tomcat_can_network_connect_db boolean
    - Update virt_use_sanlock() boolean to read sanlock state
    - Add sanlock_read_state() interface
    - Allow zoneminder_t to getattr of fs_t
    - Allow rhsmcertd_t domain to send signull to postgresql_t domain
    - Add log file type to collectd and allow corresponding access
    - Allow policykit_t domain to dbus chat with dhcpc_t
    - Adding new boolean keepalived_connect_any()
    - Allow amanda to create own amanda_tmpfs_t files
    - Allow gdomap_t domain to connect to qdomap_port_t
    - Merge pull request #56 from lslebodn/selinux_child
    - Merge pull request #58 from milosmalik/fb-dictd-dbus
    - Merge pull request #59 from milosmalik/fb-ntop-service
    - /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type
    - Allow ntop_t domain to create/map various sockets/files.
    - Enable the dictd to communicate via D-bus.
    - Allow inetd_child process to chat via dbus with abrt
    - Allow zabbix_agent_t domain to connect to redis_port_t
    - Allow rhsmcertd_t domain to read xenfs_t files
    - Allow zabbix_agent_t to run zabbix scripts
    - Fix openvswith SELinux module
    - Fix wrong path in tlp context file BZ(1586329)
    - Update brltty SELinux module
    - Allow rabbitmq_t domain to create own tmp files/dirs
    - Allow policykit_t mmap policykit_auth_exec_t files
    - Allow ipmievd_t domain to read general certs
    - Add sys_ptrace capability to pcp_pmie_t domain
    - Allow squid domain to exec ldconfig
    - Update gpg SELinux policy module
    - Allow mailman_domain to read system network state
    - Allow openvswitch_t domain to read neutron state and read/write fixed disk devices
    - Allow antivirus_domain to read all domain system state
    - Allow targetd_t domain to red gconf_home_t files/dirs
    
        
file modified
+2 -0
file modified
+82 -3
file modified
+3 -3