ce2f6a7 * Tue Sep 18 2012 Miroslav Grepl <mgreplh@redhat.com> 3.11.1-22

Authored and Committed by mgrepl 11 years ago
    * Tue Sep 18 2012 Miroslav Grepl <mgreplh@redhat.com> 3.11.1-22
    - Stop using attributes form netlabel_peer and syslog, auth_use_nsswitch setsup n
    - Move netlable_peer check out of booleans
    - Remove call to recvfrom_netlabel for kerberos call
    - Remove use of attributes when calling syslog call
    - Move -miscfiles_read_localization to domain.te to save hundreds of allow rules
    - Allow all domains to read locale files.  This eliminates around 1500 allow rule
    - Allow rndc to block suspend
    - tuned needs to modify the schedule of the kernel
    - Allow svirt_t domains to read alsa configuration files
    - ighten security on irc domains and make sure they label content in homedir corr
    - Add filetrans_home_content for irc files
    - Dontaudit all getattr access for devices and filesystems for sandbox domains
    - Allow stapserver to search cgroups directories
    - Allow all postfix domains to talk to spamd
    
        
file modified
+888 -631
file modified
+3643 -2425
file modified
+16 -0