6b0b96 * Thu May 27 2021 Zdenek Pytela <zpytela@redhat.com> - 34.9-1

Authored and Committed by Zdenek Pytela 3 years ago
    * Thu May 27 2021 Zdenek Pytela <zpytela@redhat.com> - 34.9-1
    - Add kerberos object filetrans for nsswitchdomain
    - Allow fail2ban watch various log files
    - Add logging_watch_audit_log_files() and logging_watch_audit_log_dirs()
    - Remove further modules recently removed from refpolicy
    - Remove modules not shipped and not present in refpolicy
    - Revert "Add permission open to files_read_inherited_tmp_files() interface"
    - Revert "Allow pcp_pmlogger_t to use setrlimit BZ(1708951)"
    - Revert "Dontaudit logrotate to setrlimit itself. rhbz#1309604"
    - Revert "Allow cockpit_ws_t domain to set limits BZ(1701703)"
    - Dontaudit setrlimit for domains that exec systemctl
    - Allow kdump_t net_admin capability
    - Allow nsswitch_domain read init pid lnk_files
    - Label /dev/trng with random_device_t
    - Label /run/systemd/default-hostname with hostname_etc_t
    - Add default file context specification for dnf log files
    - Label /dev/zram[0-9]+ block device files with fixed_disk_device_t
    - Label /dev/udmabuf character device with dma_device_t
    - Label /dev/dma_heap/* char devices with dma_device_t
    - Label /dev/acpi_thermal_rel char device with acpi_device_t
    
        
file modified
+24 -3
file modified
+2 -2