23c551e * Fri Aug 06 2021 Zdenek Pytela <zpytela@redhat.com> - 34.15-1

Authored and Committed by zpytela 2 years ago
    * Fri Aug 06 2021 Zdenek Pytela <zpytela@redhat.com> - 34.15-1
    - Disable seccomp on CI containers
    - Allow systemd-machined stop generic service units
    - Allow virtlogd_t read process state of user domains
    - Add "/" at the beginning of dev/shm/var\.lib\.opencryptoki.* regexp
    - Label /dev/crypto/nx-gzip with accelerator_device_t
    - Update the policy for systemd-journal-upload
    - Allow unconfined domains to bpf all other domains
    - Confine rhsm service and rhsm-facts service as rhsmcertd_t
    - Allow fcoemon talk with unconfined user over unix domain datagram socket
    - Allow abrt_domain read and write z90crypt device
    - Allow mdadm read iscsi pid files
    - Change dev_getattr_infiniband_dev() to use getattr_chr_files_pattern()
    - Label /usr/lib/pcs/pcs_snmp_agent with cluster_exec_t
    - Allow hostapd bind UDP sockets to the dhcpd port
    - Unconfined domains should not be confined
    
        
file modified
+19 -2
file modified
+2 -2