d10a38c * Mon Nov 06 2017 Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-283.15

Authored and Committed by lvrabec 6 years ago
    * Mon Nov 06 2017 Lukas Vrabec <lvrabec@redhat.com> - 3.13.1-283.15
    - Allow jabber domains to connect to postgresql ports
    - Dontaudit slapd_t to block suspend system
    - Allow spamc_t to stream connect to cyrys.
    - Allow passenger to connect to mysqld_port_t
    - Allow ipmievd to use nsswitch
    - Label all files /var/log/opensm.* as opensm_log_t because opensm creating new log files with name opensm-subnet.lst
    - Fix typo bug in tlp module
    - Allow userdomain gkeyringd domain to create stream socket with userdomain
    - Allow condor domain to read sysctl_vm_t files BZ(1508712)
    - Allow tlp_t domain transition to udev_t domain and also reading removable devices BZ(1403782)
    - Allow mozilla_plugin_t domain to dbus chat with devicekit
    - Dontaudit leaked logwatch pipes
    - Label /usr/bin/VGAuthService as vmtools_exec_t to confine this daemon.
    - Allow httpd_t domain to execute hugetlbfs_t files BZ(1444546)
    - Allow pdns to read network system state BZ(1507244)
    - Allow gssproxy to read network system state Resolves: rhbz#1507191
    - Allow nfsd_t domain to read configfs_t files/dirs
    - Allow tgtd_t domain to read generic certs
    - Allow ptp4l to send msgs via dgram socket to unprivileged user domains
    - Allow dirsrv_snmp_t to use inherited user ptys and read system state
    - Allow glusterd_t domain to create own tmpfs dirs/files
    - Allow keepalived stream connect to snmp
    
        
file modified
+0 -0
file modified
+31 -27
file modified
+324 -242
file modified
+25 -1