651a4e5 * Tue Apr 18 2017 Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-225.13

Authored and Committed by lvrabec 7 years ago
    * Tue Apr 18 2017 Lukas Vrabec  <lvrabec@redhat.com> - 3.13.1-225.13
    - Add interface gssd_noatsecure()
    - Add interface gssproxy_noatsecure()
    - Fix policy to reflect all changes in new IPA release
    - Allow tlp_t domain to ioctl removable devices BZ(1436830)
    - Allow tlp_t domain domtrans into mount_t BZ(1442571)
    - Allow lircd_t to read/write to sysfs BZ(1442443)
    - Allow virtlogd_t to creating tmp files with virt_tmp_t labels.
    - Allow sbd_t to read/write fixed disk devices
    - Allow sendmail to search network sysctls
    - Allow certmonger to start haproxy service
    - Allow drbd load modules
    - Revert "Add sys_module capability for drbd"
    - Fix cockpit module
    - Fix init Module
    - Make groupadd_t domain as system bus client BZ(1416963)
    - Allow init noatsecure for gssd and gssproxy
    - Make useradd_t domain as system bus client BZ(1442572)
    - Allow xdm_t to gettattr /dev/loop-control device BZ(1385090)
    - Dontaudit gdm-session-worker to view key unknown. BZ(1433191)
    - Allow staff user to read fwupd_cache_t files
    - Allow xdm_t to execute files labeled as xdm_var_lib_t
    - Remove /proc <<none>> from fedora policy, it's no longer necessary
    
        
file modified
+0 -0
file modified
+352 -199
file modified
+187 -96
file modified
+25 -1