-
Fri Feb 21 2020 Naoki Tanaka <naoki.tanaka@oracle.com> - 3.14.3-20.0.3
- Allow virt_domain to mmap virt_content_t files [Orabug: 30932671]
-
Tue Dec 03 2019 Naoki Tanaka <naoki.tanaka@oracle.com> - 3.14.3-20.0.2
- Enable NetworkManager and dhclient to use initramfs-configured DHCP connection [Orabug: 30537515]
-
Sun Oct 06 2019 Natalya Naumova <natalya.naumova@oracle.com> - 3.14.3-20.0.1
- Enable policykit and sssd policy modules with minimum policy [Orabug: 29744511] (Naoki Tanaka)
- Allow init_t to relabel all lock files [Orabug: 29846265] (Naoki Tanaka)
- Allow cloud_init_t to dbus chat with systemd_logind_t [Orabug: 29399653]
- Allow udev_t to load modules [Orabug: 28260775]
- Add vhost-scsi to be vhost_device_t type [Orabug: 27774921]
- Obsolete docker-engine-selinux [Orabug: 26439663]
- Fix container selinux policy [Orabug: 26427364]
- Allow ocfs2_dlmfs to be mounted with ocfs2_dlmfs_t type.
-
Mon Sep 16 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.3-20
- Label /var/log/hawkey.log as rpm_log_t and update rpm named filetrans interfaces.
- Allow sysadm_t to create hawkey log file with rpm_log_t SELinux label
Resolves: rhbz#1720639
-
Fri Aug 30 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.3-19
- Update cpucontrol_t SELinux policy
Resolves: rhbz#1743930
-
Mon Aug 19 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.3-18
- Allow dlm_controld_t domain to transition to the lvm_t
Resolves: rhbz#1732956
-
Fri Aug 16 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.3-17
- Label /usr/libexec/microcode_ctl/reload_microcode as cpucontrol_exec_t
Resolves: rhbz#1669485
- Fix typo in networkmanager_append_log() interface
Resolves: rhbz#1687460
- Update gpg policy to make ti working with confined users
Resolves: rhbz#1640296
-
Wed Aug 14 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.3-16
- Allow audisp_remote_t domain to read kerberos keytab
Resolves: rhbz#1740146
-
Mon Aug 12 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.3-15
- Dontaudit abrt_t domain to read root_t files
Resolves: rhbz#1734403
- Allow ipa_dnskey_t domain to read kerberos keytab
Resolves: rhbz#1730144
- Update ibacm_t policy
- Allow dlm_controld_t domain setgid capability
Resolves: rhbz#1738608
- Allow auditd_t domain to create auditd_tmp_t temporary files and dirs in /tmp or /var/tmp
Resolves: rhbz#1740146
- Update systemd_dontaudit_read_unit_files() interface to dontaudit alos listing dirs
Resolves: rhbz#1670139
-
Wed Aug 07 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.3-14
- Allow cgdcbxd_t domain to list cgroup dirs
Resolves: rhbz#1651991