* Tue Jun 11 2024 Zdenek Pytela <zpytela@redhat.com> - 41.3-1
- Update systemd-generator policy
- Remove permissive domain for bootupd_t
- Remove permissive domain for coreos_installer_t
- Remove permissive domain for afterburn_t
- Add the sap module to modules.conf
- Move unconfined_domain(sap_unconfined_t) to an optional block
- Create the sap module
- Allow systemd-coredumpd sys_admin and sys_resource capabilities
- Allow systemd-coredump read nsfs files
- Allow generators auto file transition only for plain files
- Allow systemd-hwdb write to the kernel messages device
- Escape "interface" as a file name in a virt filetrans pattern
- Allow gnome-software work for login_userdomain
- Allow systemd-machined manage runtime sockets
- Revert "Allow systemd-machined manage runtime sockets"