c13001 * Fri Apr 01 2016 Lukas Vrabec <lvrabec@redhat.com> 3.13.1-181

Authored and Committed by Lukas Vrabec 8 years ago
    * Fri Apr 01 2016 Lukas Vrabec <lvrabec@redhat.com> 3.13.1-181
    - Label /usr/libexec/rpm-ostreed as rpm_exec_t. BZ(1309075)
    - /bin/mailx is labeled sendmail_exec_t, and enters the sendmail_t domain on execution.  If /usr/sbin/sendmail does not have its own domain to transition to, and is not one of several products whose behavior is allowed by the sendmail_t policy, execution will fail. In this case we need to label /bin/mailx as bin_t. BZ(1323224)
    - Label all run tgtd files, not just socket files.
    - Allow prosody to stream connect to sasl. This will allow using cyrus authentication in prosody.
    - Allow prosody to listen on port 5000 for mod_proxy65. BZ(1322815)
    - Allow targetd to read/write to /dev/mapper/control device. BZ(1241415)
    - Label /etc/selinux/(minimum|mls|targeted)/active/ as semanage_store_t.
    - Allow systemd_resolved to read systemd_networkd run files. BZ(1322921)
    - New cgroup2 file system in Rawhide
    
        
file modified
+0 -0
file modified
+24 -17
file modified
+18 -13
file modified
+12 -1