-
Mon Jun 03 2019 Naoki Tanaka <naoki.tanaka@oracle.com> - 3.14.1-61.0.2
- Allow init_t to relabel all lock files [Orabug: 29846265]
-
Mon May 20 2019 Edward Leung <edward.leung@oracle.com> - 3.14.1-61.0.1
- Allow cloud_init_t to dbus chat with systemd_logind_t [Orabug: 29399653]
- Allow udev_t to load modules [Orabug: 28260775]
- Allow chronyd_t to execute shell scripts [Orabug: 28260775]
- Add vhost-scsi to be vhost_device_t type [Orabug: 27774921]
- Obsolete docker-engine-selinux [Orabug: 26439663]
- Fix container selinux policy [Orabug: 26427364]
- Allow ocfs2_dlmfs to be mounted with ocfs2_dlmfs_t type.
-
Fri Feb 22 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-61
- Add dac_override capability for sbd_t SELinux domain
Resolves: rhbz#1677325
- Allow syslogd_t domain to send null signal to all domains on system
Resolves: rhbz#1676923
-
Fri Feb 15 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-60
- Update kdump_manage_crash() interface to allow also manage dirs by caller domain
Resolves: rhbz#1627861
-
Mon Feb 11 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-59
- Add dac_override capability to spamd_t domain
Resolves: rhbz#1567073
-
Mon Feb 11 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-58
- Allow ibacm_t domain to read system state and label all ibacm sockets and symlinks as ibacm_var_run_t in /var/run
Resolves: rhbz#1635674
- Update mount_read_pid_files macro to allow also list mount_var_run_t dirs
Resolves: rhbz#1664448
- Allow userdomain to stop systemd user session during logout.
Resolves: rhbz#1664448
-
Wed Feb 06 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-57
- Allow read network state of system for processes labeled as ibacm_t
Resolves: rhbz#1635674
- Allow ibacm_t domain to send dgram sockets to kernel processes
Resolves: rhbz#1635674
- Allow virt_doamin to read/write dev device
Resolves: rhbz#1672188
- Update ibacm_t policy after testing lastest version of this component
Resolves: rhbz#1635674
- Allow sensord_t domain to mmap own log files
Resolves:rhbz#1656055
- Label /dev/sev char device as sev_device_t
Resolves: rhbz#1672188
-
Wed Feb 06 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-56
- Allow virt_doamin to read/write dev device
Resolves: rhbz#1672188
- Update ibacm_t policy after testing lastest version of this component
Resolves: rhbz#1635674
- Allow sensord_t domain to mmap own log files
Resolves:rhbz#1656055
- Add dac_override capability for ipa_helper_t
Resolves: rhbz#1668168
- Allow sensord_t domain to use nsswitch and execute shell
Resolves: rhbz#1656055
- Allow opafm_t domain to execute lib_t files
Resolves: rhbz#1627861
- Allow opafm_t domain to manage kdump_crash_t files and dirs
Resolves: rhbz#1627861
- Label /dev/sev char device as sev_device_t
Resolves: rhbz#1672188
-
Fri Feb 01 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-55
- Fix broken config files because of missing level specification in user_t contexts
Resolves: rhbz#1664448
-
Fri Feb 01 2019 Lukas Vrabec <lvrabec@redhat.com> - 3.14.1-54
- Allow sensord_t domain to use nsswitch and execute shell
Resolves: rhbz#1656055
- Allow opafm_t domain to execute lib_t files
Resolves: rhbz#1627861