36da6bb * Mon Jul 11 2016 Lukas Vrabec <lvrabec@redhat.com> 3.13.1-191.4

Authored and Committed by lvrabec 7 years ago
    * Mon Jul 11 2016 Lukas Vrabec <lvrabec@redhat.com> 3.13.1-191.4
    - Allow lttng tools to block suspending
    - Allow creation of vpnaas in openstack
    - Allow dnssec-trigger to chat with NetworkManager over DBUS BZ(1350100)
    - Allow opensm daemon to rw infiniband_mgmt_device_t
    - Allow virtual machines to rw infiniband devices. Resolves: rhbz#1210263
    - Fix typo in brltty policy
    - Add new SELinux module sbd
    - Allow pcp dmcache metrics collection
    - Allow pkcs_slotd_t to create dir in /var/lock Add label pkcs_slotd_log_t
    - Allow openvpn to create sock files labeled as openvpn_var_run_t
    - Allow hypervkvp daemon to getattr on  all filesystem types.
    - Allow firewalld to create net_conf_t files
    - Allow mock to use lvm
    - Allow mirromanager creating log files in /tmp
    - Allow vmtools_t to transition to rpm_script domain
    - Allow nsd daemon to manage nsd_conf_t dirs and files
    - Allow cluster to create dirs in /var/run labeled as cluster_var_run_t
    - Allow sssd read also sssd_conf_t dirs
    - Allow krb5kdc_t to communicate with sssd
    - Allow prosody to bind on prosody ports
    - Add dac_override caps for fail2ban-client Resolves: rhbz#1316678
    - dontaudit read access for svirt_t on the file /var/db/nscd/group Resolves: rhbz#1301637
    - Allow inetd child process to communicate via dbus with systemd-logind Resolves: rhbz#1333726
    - Add label for brltty log file Resolves: rhbz#1328818
    - Allow snort_t to communicate with sssd Resolves: rhbz#1284908
    - Add interface lttng_sessiond_tmpfs_t()
    - Add new policy for systemd-modules-load
    - Allow udev to manage systemd-hwdb files
    - Add interface systemd_hwdb_manage_config()
    - Fix paths to infiniband devices. This allows use more then two infiniband interfaces.
    - Make label for new infiniband_mgmt deivices
    - corecmd: Remove fcontext for /etc/sysconfig/libvirtd
    - iptables: add fcontext for nftables
    - Add interface lvm_getattr_exec_files()
    - Dontaudit su_role_template interface to getattr /proc/kcore Dontaudit su_role_template interface to getattr /dev/initctl
    - Add prosody ports Resolves: rhbz#1304664
    
        
file modified
+0 -0
file modified
+489 -419
file modified
+416 -114
file modified
+39 -1