146b7fd * Wed May 2 2012 Miroslav Grepl <mgrepl@redhat.com> 3.10.0-120

Authored and Committed by mgrepl 12 years ago
    * Wed May 2 2012 Miroslav Grepl <mgrepl@redhat.com> 3.10.0-120
    - Add clamscan_can_scan_system boolean
    - Allow mysqld to read kernel network state
    - Allow sshd to read/write condor lib files
    - Allow sshd to read/write condor-startd tcp socket
    - Fix description on httpd_graceful_shutdown
    - Allow glance_registry to communicate with mysql
    - dbus_system_domain is using systemd to lauch applications
    - add interfaces to allow domains to send kill signals to user mail agents
    - Remove unnessary access for svirt_lxc domains, add privs for virtd_lxc_t
    - Lots of new access required for secure containers
    - Corosync needs sys_admin capability
    - ALlow colord to create shm
    - .orc should be allowed to be created by any app that can create gstream ho
    - Add boolean to control whether or not mozilla plugins can create random co
    -  Add new interface to allow domains to list msyql_db directories, needed f
    - shutdown has to be allowed to delete etc_runtime_t
    - Fail2ban needs to read /etc/passwd
    -  Allow ldconfig to create /var/cache/ldconfig
    - Allow tgtd to read hardware state information
    - Allow collectd to create packet socket
    - Allow chronyd to send signal to itself
    - Allow collectd to read /dev/random
    - Allow collectd to send signal to itself
    - firewalld needs to execute restorecon
    - Allow restorecon and other login domains to execute restorecon
    
        
file modified
+991 -485
file modified
+28 -1