87f0e22 * Sat May 26 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-30

Authored and Committed by lvrabec 5 years ago
    * Sat May 26 2018 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-30
    - Add dac_override to exim policy BZ(1574303)
    - Fix typo in conntrackd.fc file
    - Allow sssd_t to kill sssd_selinux_manager_t
    - Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db  is turned on
    - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp
    - Allow policykit_auth_t to read udev db files BZ(1574419)
    - Allow varnishd_t do be dbus client BZ(1582251)
    - Allow cyrus_t domain to mmap own pid files BZ(1582183)
    - Allow user_mail_t domain to mmap etc_aliases_t files
    - Allow gkeyringd domains to run ssh agents
    - Allow gpg_pinentry_t domain read ssh state
    - Allow gpg_agent_t to send msgs to syslog/journal
    - Add dac_override capability to dovecot_t domain
    - Allow nscd_t domain to mmap system_db_t files
    - Allow tangd_t domain to create tcp sockets and add new interface tangd_read_db_files
    - Allow sysadm_u use xdm
    - Allow xdm_t domain to listen ofor unix dgram sockets BZ(1581495)
    - Add interface ssh_read_state()
    - Fix typo in sysnetwork.if file
    - Update dev_map_xserver_misc interface to allo mmaping char devices instead of files
    - Allow noatsecure permission for all domain transitions from systemd.
    - Allow systemd to read tangd db files
    - Fix typo in ssh.if file
    - Allow xdm_t domain to mmap xserver_misc_device_t files
    
        
file modified
+2 -0
file modified
+29 -3
file modified
+3 -3