* Mon Apr 16 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-21
- Allow certwatch to manage cert files BZ(1561418)
- Allow abrt_dump_oops_t domain to mmap all non security files BZ(1565748)
- Allow gpg_t domain mmap cert_t files Allow gpg_t mmap gpg_agent_t files
- Allow NetworkManager_ssh_t domain use generic ptys. BZ(1565851)
- Allow pppd_t domain read/write l2tpd pppox sockets BZ(1566096)
- Allow xguest user use bluetooth sockets if xguest_use_bluetooth boolean is turned on.
- Allow pppd_t domain creating pppox sockets BZ(1566271)
- Allow abrt to map var_lib_t files
- Allow chronyc to read system state BZ(1565217)
- Allow keepalived_t domain to chat with systemd via dbus
- Allow git to mmap git_(sys|user)_content_t files BZ(1518027)
- removed boinc dev_getattr_*_dev
- Allow iptables_t domain to create dirs in etc_t with system_conf_t labels
- Allow x userdomain to mmap xserver_tmpfs_t files
- Allow sysadm_t to mount tracefs_t
- Allow unconfined user all perms under bpf class BZ(1565738)
- Allow SELinux users (except guest and xguest) to using bluetooth sockets
- Add new interface files_map_var_lib_files()
- Allow user_t and staff_t domains create netlink tcpdiag sockets
- Allow systemd-networkd to read sysctl_t files
- Allow systemd_networkd_t to read/write tun tap devices
- refpolicy: Update for kernel sctp support