2afcf88 - Add label for dns lib files

Authored and Committed by mgrepl 11 years ago
    - Add label for dns lib files
    - Allow svirt_t images to compromise_kernel when using pci-passthrough
    - Blueman uses ctypes which ends up triggering execmem priv.
    - Dontaudit attempts by thumb_t to use nscd
    - fsdaemon reads all images, if relabeled to svirt_image_t, it should be able to read it
    - Allow abrt to read proc_net_t
    - Allw NM to transition to l2tpd
    - Dontaudit chrome-nacl to append gnome config files
    - Add gnome_dontaudit_append_config_files()
    - Allow svirt_tcg_t to create netlink_route_socket
    - Label /var/lib/unbound as named_cache_t to allow named to write to this directory
    - Allow postfix domains to list /tmp
    - Allow dnsmasq to list tftpdir_rw_t content
    - Allow lxc domains to read fusefs, since libvirt is mounding a fuse file system at /proc/me
    - Allow tmpreaper to delete tmpfs files in tmp
    - Dontaudit access check on tmp_t files/directories
    - dontaudit access checks on file systems types by firewalld
    - Allow mail_munin_plugins domain to run postconf
    - Allow spamd_update to manage gnupg directory
    - Add missing postfix_run_postqueue() interface
    - Add ntp_exec() interface
    - Fix setroubleshoot_fixit_t policy
    - Allow setroubleshoot_fixit to execute rpm
    - zoneminder needs to connect to httpd ports where remote cameras are listening
    - Allow firewalld to execute content created in /run directory
    - Allow svirt_t to read generic certs
    - Add label for Xvnc
    - Add interface to dontaudit access checks on tmp_t
    - Fix interface for dontaudit access check to include directory
    - interface to dontaudit access checks on file systems types
    - Add interface for postgesql_filetrans_name_content to make sure log directories get create
    - Allow sshd_t sys_admin for use with afs logins
    - Allow systemd to read/write all sysctls
    - Additional fix for chroot_user_t backported from RHEL6
    - Allow chroot_user_t to getattr on filesystems
    - Dontaudit vi attempting to relabel to self files
    - Sudo domain is attempting to get the additributes of proc_kcore_t
    - Unbound uses port 8953
    
        
file modified
+328 -275
file modified
+254 -139
file modified
+45 -1