Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

selinux-policy-mls-40.15-1.fc41 RPM for noarch

From Fedora Rawhide for aarch64 / s

Name: selinux-policy-mls Distribution: Fedora Project
Version: 40.15 Vendor: Fedora Project
Release: 1.fc41 Build date: Sat Mar 16 00:12:06 2024
Group: Unspecified Build host: buildvm-s390x-01.s390.fedoraproject.org
Size: 10931915 Source RPM: selinux-policy-40.15-1.fc41.src.rpm
Packager: Fedora Project
Url: https://github.com/fedora-selinux/selinux-policy
Summary: SELinux MLS policy
SELinux MLS (Multi Level Security) policy package.

Provides

Requires

License

GPL-2.0-or-later

Changelog

* Fri Mar 15 2024 Zdenek Pytela <zpytela@redhat.com> - 40.15-1
  - Update mmap_rw_file_perms to include the lock permission
  - Allow plymouthd log during shutdown
  - Add logging_watch_all_log_dirs() and logging_watch_all_log_files()
  - Allow journalctl_t read filesystem sysctls
  - Allow cgred_t to get attributes of cgroup filesystems
  - Allow wdmd read hardware state information
  - Allow wdmd list the contents of the sysfs directories
  - Allow linuxptp configure phc2sys and chronyd over a unix domain socket
  - Allow sulogin relabel tty1
  - Dontaudit sulogin the checkpoint_restore capability
  - Modify sudo_role_template() to allow getpgid
  - Remove incorrect "local" usage in varrun-convert.sh
* Thu Mar 07 2024 Zdenek Pytela <zpytela@redhat.com> - 40.14-2
  - Update varrun-convert.sh script to check for existing duplicate entries
* Mon Feb 26 2024 Zdenek Pytela <zpytela@redhat.com> - 40.14-1
  - Allow userdomain get attributes of files on an nsfs filesystem
  - Allow opafm create NFS files and directories
  - Allow virtqemud create and unlink files in /etc/libvirt/
  - Allow virtqemud domain transition on swtpm execution
  - Add the swtpm.if interface file for interactions with other domains
  - Allow samba to have dac_override capability
  - systemd: allow sys_admin capability for systemd_notify_t
  - systemd: allow systemd_notify_t to send data to kernel_t datagram sockets
  - Allow thumb_t to watch and watch_reads mount_var_run_t
  - Allow krb5kdc_t map krb5kdc_principal_t files
  - Allow unprivileged confined user dbus chat with setroubleshoot
  - Allow login_userdomain map files in /var
  - Allow wireguard work with firewall-cmd
  - Differentiate between staff and sysadm when executing crontab with sudo
  - Add crontab_admin_domtrans interface
  - Allow abrt_t nnp domain transition to abrt_handle_event_t
  - Allow xdm_t to watch and watch_reads mount_var_run_t
  - Dontaudit subscription manager setfscreate and read file contexts
  - Don't audit crontab_domain write attempts to user home
  - Transition from sudodomains to crontab_t when executing crontab_exec_t
  - Add crontab_domtrans interface
  - Fix label of pseudoterminals created from sudodomain
  - Allow utempter_t use ptmx
  - Dontaudit rpmdb attempts to connect to sssd over a unix stream socket
  - Allow admin user read/write on fixed_disk_device_t
* Mon Feb 12 2024 Zdenek Pytela <zpytela@redhat.com> - 40.13-1
  - Only allow confined user domains to login locally without unconfined_login
  - Add userdom_spec_domtrans_confined_admin_users interface
  - Only allow admindomain to execute shell via ssh with ssh_sysadm_login
  - Add userdom_spec_domtrans_admin_users interface
  - Move ssh dyntrans to unconfined inside unconfined_login tunable policy
  - Update ssh_role_template() for user ssh-agent type
  - Allow init to inherit system DBus file descriptors
  - Allow init to inherit fds from syslogd
  - Allow any domain to inherit fds from rpm-ostree
  - Update afterburn policy
  - Allow init_t nnp domain transition to abrtd_t
* Tue Feb 06 2024 Zdenek Pytela <zpytela@redhat.com> - 40.12-1
  - Rename all /var/lock file context entries to /run/lock
  - Rename all /var/run file context entries to /run
  - Invert the "/var/run = /run" equivalency
* Mon Feb 05 2024 Zdenek Pytela <zpytela@redhat.com> - 40.11-1
  - Replace init domtrans rule for confined users to allow exec init
  - Update dbus_role_template() to allow user service status
  - Allow polkit status all systemd services
  - Allow setroubleshootd create and use inherited io_uring
  - Allow load_policy read and write generic ptys
  - Allow gpg manage rpm cache
  - Allow login_userdomain name_bind to howl and xmsg udp ports
  - Allow rules for confined users logged in plasma
  - Label /dev/iommu with iommu_device_t
  - Remove duplicate file context entries in /run
  - Dontaudit getty and plymouth the checkpoint_restore capability
  - Allow su domains write login records
  - Revert "Allow su domains write login records"
  - Allow login_userdomain delete session dbusd tmp socket files
  - Allow unix dgram sendto between exim processes
  - Allow su domains write login records
  - Allow smbd_t to watch user_home_dir_t if samba_enable_home_dirs is on
* Wed Jan 24 2024 Zdenek Pytela <zpytela@redhat.com> - 40.10-1
  - Allow chronyd-restricted read chronyd key files
  - Allow conntrackd_t to use bpf capability2
  - Allow systemd-networkd manage its runtime socket files
  - Allow init_t nnp domain transition to colord_t
  - Allow polkit status systemd services
  - nova: Fix duplicate declarations
  - Allow httpd work with PrivateTmp
  - Add interfaces for watching and reading ifconfig_var_run_t
  - Allow collectd read raw fixed disk device
  - Allow collectd read udev pid files
  - Set correct label on /etc/pki/pki-tomcat/kra
  - Allow systemd domains watch system dbus pid socket files
  - Allow certmonger read network sysctls
  - Allow mdadm list stratisd data directories
  - Allow syslog to run unconfined scripts conditionally
  - Allow syslogd_t nnp_transition to syslogd_unconfined_script_t
  - Allow qatlib set attributes of vfio device files
* Tue Jan 09 2024 Zdenek Pytela <zpytela@redhat.com> - 40.9-1
  - Allow systemd-sleep set attributes of efivarfs files
  - Allow samba-dcerpcd read public files
  - Allow spamd_update_t the sys_ptrace capability in user namespace
  - Allow bluetooth devices work with alsa
  - Allow alsa get attributes filesystems with extended attributes
* Tue Jan 02 2024 Yaakov Selkowitz <yselkowi@redhat.com> - 40.8-2
  - Limit %selinux_requires to version, not release
* Thu Dec 21 2023 Zdenek Pytela <zpytela@redhat.com> - 40.8-1
  - Allow hypervkvp_t write access to NetworkManager_etc_rw_t
  - Add interface for write-only access to NetworkManager rw conf
  - Allow systemd-sleep send a message to syslog over a unix dgram socket
  - Allow init create and use netlink netfilter socket
  - Allow qatlib load kernel modules
  - Allow qatlib run lspci
  - Allow qatlib manage its private runtime socket files
  - Allow qatlib read/write vfio devices
  - Label /etc/redis.conf with redis_conf_t
  - Remove the lockdown-class rules from the policy
  - Allow init read all non-security socket files
  - Replace redundant dnsmasq pattern macros
  - Remove unneeded symlink perms in dnsmasq.if
  - Add additions to dnsmasq interface
  - Allow nvme_stas_t create and use netlink kobject uevent socket
  - Allow collectd connect to statsd port
  - Allow keepalived_t to use sys_ptrace of cap_userns
  - Allow dovecot_auth_t connect to postgresql using UNIX socket
* Wed Dec 13 2023 Zdenek Pytela <zpytela@redhat.com> - 40.7-1
  - Make named_zone_t and named_var_run_t a part of the mountpoint attribute
  - Allow sysadm execute traceroute in sysadm_t domain using sudo
  - Allow sysadm execute tcpdump in sysadm_t domain using sudo
  - Allow opafm search nfs directories
  - Add support for syslogd unconfined scripts
  - Allow gpsd use /dev/gnss devices
  - Allow gpg read rpm cache
  - Allow virtqemud additional permissions
  - Allow virtqemud manage its private lock files
  - Allow virtqemud use the io_uring api
  - Allow ddclient send e-mail notifications
  - Allow postfix_master_t map postfix data files
  - Allow init create and use vsock sockets
  - Allow thumb_t append to init unix domain stream sockets
  - Label /dev/vas with vas_device_t
  - Change domain_kernel_load_modules boolean to true
  - Create interface selinux_watch_config and add it to SELinux users
* Tue Nov 28 2023 Zdenek Pytela <zpytela@redhat.com> - 40.6-1
  - Add afterburn to modules-targeted-contrib.conf
  - Update cifs interfaces to include fs_search_auto_mountpoints()
  - Allow sudodomain read var auth files
  - Allow spamd_update_t read hardware state information
  - Allow virtnetworkd domain transition on tc command execution
  - Allow sendmail MTA connect to sendmail LDA
  - Allow auditd read all domains process state
  - Allow rsync read network sysctls
  - Add dhcpcd bpf capability to run bpf programs
  - Dontaudit systemd-hwdb dac_override capability
  - Allow systemd-sleep create efivarfs files
* Tue Nov 14 2023 Zdenek Pytela <zpytela@redhat.com> - 40.5-1
  - Allow map xserver_tmpfs_t files when xserver_clients_write_xshm is on
  - Allow graphical applications work in Wayland
  - Allow kdump work with PrivateTmp
  - Allow dovecot-auth work with PrivateTmp
  - Allow nfsd get attributes of all filesystems
  - Allow unconfined_domain_type use io_uring cmd on domain
  - ci: Only run Rawhide revdeps tests on the rawhide branch
  - Label /var/run/auditd.state as auditd_var_run_t
  - Allow fido-device-onboard (FDO) read the crack database
  - Allow ip an explicit domain transition to other domains
  - Label /usr/libexec/selinux/selinux-autorelabel with semanage_exec_t
  - Allow  winbind_rpcd_t processes access when samba_export_all_* is on
  - Enable NetworkManager and dhclient to use initramfs-configured DHCP connection
  - Allow ntp to bind and connect to ntske port.
  - Allow system_mail_t manage exim spool files and dirs
  - Dontaudit keepalived setattr on keepalived_unconfined_script_exec_t
  - Label /run/pcsd.socket with cluster_var_run_t
  - ci: Run cockpit tests in PRs
* Thu Oct 19 2023 Zdenek Pytela <zpytela@redhat.com> - 40.4-1
  - Add map_read map_write to kernel_prog_run_bpf
  - Allow systemd-fstab-generator read all symlinks
  - Allow systemd-fstab-generator the dac_override capability
  - Allow rpcbind read network sysctls
  - Support using systemd containers
  - Allow sysadm_t to connect to iscsid using a unix domain stream socket
  - Add policy for coreos installer
  - Add coreos_installer to modules-targeted-contrib.conf
* Tue Oct 17 2023 Zdenek Pytela <zpytela@redhat.com> - 40.3-1
  - Add policy for nvme-stas
  - Confine systemd fstab,sysv,rc-local
  - Label /etc/aliases.lmdb with etc_aliases_t
  - Create policy for afterburn
  - Add nvme_stas to modules-targeted-contrib.conf
  - Add plans/tests.fmf
* Tue Oct 10 2023 Zdenek Pytela <zpytela@redhat.com> - 40.2-1
  - Add the virt_supplementary module to modules-targeted-contrib.conf
  - Make new virt drivers permissive
  - Split virt policy, introduce virt_supplementary module
  - Allow apcupsd cgi scripts read /sys
  - Merge pull request #1893 from WOnder93/more-early-boot-overlay-fixes
  - Allow kernel_t to manage and relabel all files
  - Add missing optional_policy() to files_relabel_all_files()
* Tue Oct 03 2023 Zdenek Pytela <zpytela@redhat.com> - 40.1-1
  - Allow named and ndc use the io_uring api
  - Deprecate common_anon_inode_perms usage
  - Improve default file context(None) of /var/lib/authselect/backups
  - Allow udev_t to search all directories with a filesystem type
  - Implement proper anon_inode support
  - Allow targetd write to the syslog pid sock_file
  - Add ipa_pki_retrieve_key_exec() interface
  - Allow kdumpctl_t to list all directories with a filesystem type
  - Allow udev additional permissions
  - Allow udev load kernel module
  - Allow sysadm_t to mmap modules_object_t files
  - Add the unconfined_read_files() and unconfined_list_dirs() interfaces
  - Set default file context of HOME_DIR/tmp/.* to <<none>>
  - Allow kernel_generic_helper_t to execute mount(1)
* Fri Sep 29 2023 Zdenek Pytela <zpytela@redhat.com> - 38.29-1
  - Allow sssd send SIGKILL to passkey_child running in ipa_otpd_t
  - Allow systemd-localed create Xserver config dirs
  - Allow sssd read symlinks in /etc/sssd
  - Label /dev/gnss[0-9] with gnss_device_t
  - Allow systemd-sleep read/write efivarfs variables
  - ci: Fix version number of packit generated srpms
  - Dontaudit rhsmcertd write memory device
  - Allow ssh_agent_type create a sockfile in /run/user/USERID
  - Set default file context of /var/lib/authselect/backups to <<none>>
  - Allow prosody read network sysctls
  - Allow cupsd_t to use bpf capability
* Fri Sep 15 2023 Zdenek Pytela <zpytela@redhat.com> - 38.28-1
  - Allow sssd domain transition on passkey_child execution conditionally
  - Allow login_userdomain watch lnk_files in /usr
  - Allow login_userdomain watch video4linux devices
  - Change systemd-network-generator transition to include class file
  - Revert "Change file transition for systemd-network-generator"
  - Allow nm-dispatcher winbind plugin read/write samba var files
  - Allow systemd-networkd write to cgroup files
  - Allow kdump create and use its memfd: objects
* Thu Aug 31 2023 Zdenek Pytela <zpytela@redhat.com> - 38.27-1
  - Allow fedora-third-party get generic filesystem attributes
  - Allow sssd use usb devices conditionally
  - Update policy for qatlib
  - Allow ssh_agent_type manage generic cache home files
* Thu Aug 24 2023 Zdenek Pytela <zpytela@redhat.com> - 38.26-1
  - Change file transition for systemd-network-generator
  - Additional support for gnome-initial-setup
  - Update gnome-initial-setup policy for geoclue
  - Allow openconnect vpn open vhost net device
  - Allow cifs.upcall to connect to SSSD also through the /var/run socket
  - Grant cifs.upcall more required capabilities
  - Allow xenstored map xenfs files
  - Update policy for fdo
  - Allow keepalived watch var_run dirs
  - Allow svirt to rw /dev/udmabuf
  - Allow qatlib  to modify hardware state information.
  - Allow key.dns_resolve connect to avahi over a unix stream socket
  - Allow key.dns_resolve create and use unix datagram socket
  - Use quay.io as the container image source for CI
* Fri Aug 11 2023 Zdenek Pytela <zpytela@redhat.com> - 38.25-1
  - ci: Move srpm/rpm build to packit
  - .copr: Avoid subshell and changing directory
  - Allow gpsd, oddjob and oddjob_mkhomedir_t write user_tty_device_t chr_file
  - Label /usr/libexec/openssh/ssh-pkcs11-helper with ssh_agent_exec_t
  - Make insights_client_t an unconfined domain
  - Allow insights-client manage user temporary files
  - Allow insights-client create all rpm logs with a correct label
  - Allow insights-client manage generic logs
  - Allow cloud_init create dhclient var files and init_t manage net_conf_t
  - Allow insights-client read and write cluster tmpfs files
  - Allow ipsec read nsfs files
  - Make tuned work with mls policy
  - Remove nsplugin_role from mozilla.if
  - allow mon_procd_t self:cap_userns sys_ptrace
  - Allow pdns name_bind and name_connect all ports
  - Set the MLS range of fsdaemon_t to s0 - mls_systemhigh
  - ci: Move to actions/checkout@v3 version
  - .copr: Replace chown call with standard workflow safe.directory setting
  - .copr: Enable `set -u` for robustness
  - .copr: Simplify root directory variable
* Fri Aug 04 2023 Zdenek Pytela <zpytela@redhat.com> - 38.24-1
  - Allow rhsmcertd dbus chat with policykit
  - Allow polkitd execute pkla-check-authorization with nnp transition
  - Allow user_u and staff_u get attributes of non-security dirs
  - Allow unconfined user filetrans chrome_sandbox_home_t
  - Allow svnserve execute postdrop with a transition
  - Do not make postfix_postdrop_t type an MTA executable file
  - Allow samba-dcerpc service manage samba tmp files
  - Add use_nfs_home_dirs boolean for mozilla_plugin
  - Fix labeling for no-stub-resolv.conf
* Wed Aug 02 2023 Zdenek Pytela <zpytela@redhat.com> - 38.23-1
  - Revert "Allow winbind-rpcd use its private tmp files"
  - Allow upsmon execute upsmon via a helper script
  - Allow openconnect vpn read/write inherited vhost net device
  - Allow winbind-rpcd use its private tmp files
  - Update samba-dcerpc policy for printing
  - Allow gpsd,oddjob,oddjob_mkhomedir rw user domain pty
  - Allow nscd watch system db dirs
  - Allow qatlib to read sssd public files
  - Allow fedora-third-party read /sys and proc
  - Allow systemd-gpt-generator mount a tmpfs filesystem
  - Allow journald write to cgroup files
  - Allow rpc.mountd read network sysctls
  - Allow blueman read the contents of the sysfs filesystem
  - Allow logrotate_t to map generic files in /etc
  - Boolean: Allow virt_qemu_ga create ssh directory
* Tue Jul 25 2023 Zdenek Pytela <zpytela@redhat.com> - 38.22-1
  - Allow systemd-network-generator send system log messages
  - Dontaudit the execute permission on sock_file globally
  - Allow fsadm_t the file mounton permission
  - Allow named and ndc the io_uring sqpoll permission
  - Allow sssd io_uring sqpoll permission
  - Fix location for /run/nsd
  - Allow qemu-ga get fixed disk devices attributes
  - Update bitlbee policy
  - Label /usr/sbin/sos with sosreport_exec_t
  - Update policy for the sblim-sfcb service
  - Add the files_getattr_non_auth_dirs() interface
  - Fix the CI to work with DNF5
* Sat Jul 22 2023 Fedora Release Engineering <releng@fedoraproject.org> - 38.21-2
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jul 13 2023 Zdenek Pytela <zpytela@redhat.com> - 38.21-1
  - Make systemd_tmpfiles_t MLS trusted for lowering the level of files
  - Revert "Allow insights client map cache_home_t"
  - Allow nfsidmapd connect to systemd-machined over a unix socket
  - Allow snapperd connect to kernel over a unix domain stream socket
  - Allow virt_qemu_ga_t create .ssh dir with correct label
  - Allow targetd read network sysctls
  - Set the abrt_handle_event boolean to on
  - Permit kernel_t to change the user identity in object contexts
  - Allow insights client map cache_home_t
  - Label /usr/sbin/mariadbd with mysqld_exec_t
  - Trim changelog so that it starts at F37 time
  - Define equivalency for /run/systemd/generator.early
* Thu Jun 29 2023 Zdenek Pytela <zpytela@redhat.com> - 38.20-1
  - Allow httpd tcp connect to redis port conditionally
  - Label only /usr/sbin/ripd and ripngd with zebra_exec_t
  - Dontaudit aide the execmem permission
  - Remove permissive from fdo
  - Allow sa-update manage spamc home files
  - Allow sa-update connect to systemlog services
  - Label /usr/lib/systemd/system/mimedefang.service with antivirus_unit_file_t
  - Allow nsd_crond_t write nsd_var_run_t & connectto nsd_t
  - Allow bootupd search EFI directory
* Tue Jun 27 2023 Zdenek Pytela <zpytela@redhat.com> - 38.19-1
  - Change init_audit_control default value to true
  - Allow nfsidmapd connect to systemd-userdbd with a unix socket
  - Add the qatlib  module
  - Add the fdo module
  - Add the bootupd module
  - Set default ports for keylime policy
  - Create policy for qatlib
  - Add policy for FIDO Device Onboard
  - Add policy for bootupd
  - Add the qatlib module
  - Add the fdo module
  - Add the bootupd module
* Sun Jun 25 2023 Zdenek Pytela <zpytela@redhat.com> - 38.18-1
  - Add support for kafs-dns requested by keyutils
  - Allow insights-client execmem
  - Add support for chronyd-restricted
  - Add init_explicit_domain() interface
  - Allow fsadm_t to get attributes of cgroup filesystems
  - Add list_dir_perms to kerberos_read_keytab
  - Label /var/run/tmpfiles.d/static-nodes.conf with kmod_var_run_t
  - Allow sendmail manage its runtime files
  - Allow keyutils_dns_resolver_exec_t be an entrypoint
  - Allow collectd_t read network state symlinks
  - Revert "Allow collectd_t read proc_net link files"
  - Allow nfsd_t to list exports_t dirs
  - Allow cupsd dbus chat with xdm
  - Allow haproxy read hardware state information
  - Add the kafs module
* Thu Jun 15 2023 Zdenek Pytela <zpytela@redhat.com> - 38.17-1
  - Label /dev/userfaultfd with userfaultfd_t
  - Allow blueman send general signals to unprivileged user domains
  - Allow dkim-milter domain transition to sendmail
  - Label /usr/sbin/cifs.idmap with cifs_helper_exec_t
  - Allow cifs-helper read sssd kerberos configuration files
  - Allow rpm_t sys_admin capability
  - Allow dovecot_deliver_t create/map dovecot_spool_t dir/file
  - Allow collectd_t read proc_net link files
  - Allow insights-client getsession process permission
  - Allow insights-client work with pipe and socket tmp files
  - Allow insights-client map generic log files
  - Update cyrus_stream_connect() to use sockets in /run
  - Allow keyutils-dns-resolver read/view kernel key ring
  - Label /var/log/kdump.log with kdump_log_t
* Fri Jun 09 2023 Zdenek Pytela <zpytela@redhat.com> - 38.16-1
  - Add support for the systemd-pstore service
  - Allow kdumpctl_t to execmem
  - Update sendmail policy module for opensmtpd
  - Allow nagios-mail-plugin exec postfix master
  - Allow subscription-manager execute ip
  - Allow ssh client connect with a user dbus instance
  - Add support for ksshaskpass
  - Allow rhsmcertd file transition in /run also for socket files
  - Allow keyutils_dns_resolver_t execute keyutils_dns_resolver_exec_t
  - Allow plymouthd read/write X server miscellaneous devices
  - Allow systemd-sleep read udev pid files
  - Allow exim read network sysctls
  - Allow sendmail request load module
  - Allow named map its conf files
  - Allow squid map its cache files
  - Allow NetworkManager_dispatcher_dhclient_t to execute shells without a domain transition
* Tue May 30 2023 Zdenek Pytela <zpytela@redhat.com> - 38.15-1
  - Update policy for systemd-sleep
  - Remove permissive domain for rshim_t
  - Remove permissive domain for mptcpd_t
  - Allow systemd-bootchartd the sys_ptrace userns capability
  - Allow sysadm_t read nsfs files
  - Allow sysadm_t run kernel bpf programs
  - Update ssh_role_template for ssh-agent
  - Update ssh_role_template to allow read/write unallocated ttys
  - Add the booth module to modules.conf
  - Allow firewalld rw ica_tmpfs_t files
* Fri May 26 2023 Zdenek Pytela <zpytela@redhat.com> - 38.14-1
  - Remove permissive domain for cifs_helper_t
  - Update the cifs-helper policy
  - Replace cifsutils_helper_domtrans() with keyutils_request_domtrans_to()
  - Update pkcsslotd policy for sandboxing
  - Allow abrt_t read kernel persistent storage files
  - Dontaudit targetd search httpd config dirs
  - Allow init_t nnp domain transition to policykit_t
  - Allow rpcd_lsad setcap and use generic ptys
  - Allow samba-dcerpcd connect to systemd_machined over a unix socket
  - Allow wireguard to rw network sysctls
  - Add policy for boothd
  - Allow kernel to manage its own BPF objects
  - Label /usr/lib/systemd/system/proftpd.* & vsftpd.* with ftpd_unit_file_t
* Mon May 22 2023 Zdenek Pytela <zpytela@redhat.com> - 38.13-1
  - Add initial policy for cifs-helper
  - Label key.dns_resolver with keyutils_dns_resolver_exec_t
  - Allow unconfined_service_t to create .gnupg labeled as gpg_secret_t
  - Allow some systemd services write to cgroup files
  - Allow NetworkManager_dispatcher_dhclient_t to read the DHCP configuration files
  - Allow systemd resolved to bind to arbitrary nodes
  - Allow plymouthd_t bpf capability to run bpf programs
  - Allow cupsd to create samba_var_t files
  - Allow rhsmcert request the kernel to load a module
  - Allow virsh name_connect virt_port_t
  - Allow certmonger manage cluster library files
  - Allow plymouthd read init process state
  - Add chromium_sandbox_t setcap capability
  - Allow snmpd read raw disk data
  - Allow samba-rpcd work with passwords
  - Allow unconfined service inherit signal state from init
  - Allow cloud-init manage gpg admin home content
  - Allow cluster_t dbus chat with various services
  - Allow nfsidmapd work with systemd-userdbd and sssd
  - Allow unconfined_domain_type use IORING_OP_URING_CMD on all device nodes
  - Allow plymouthd map dri and framebuffer devices
  - Allow rpmdb_migrate execute rpmdb
  - Allow logrotate dbus chat with systemd-hostnamed
  - Allow icecast connect to kernel using a unix stream socket
  - Allow lldpad connect to systemd-userdbd over a unix socket
  - Allow journalctl open user domain ptys and ttys
  - Allow keepalived to manage its tmp files
  - Allow ftpd read network sysctls
  - Label /run/bgpd with zebra_var_run_t
  - Allow gssproxy read network sysctls
  - Add the cifsutils module
* Tue Apr 25 2023 Zdenek Pytela <zpytela@redhat.com> - 38.12-1
  - Allow telnetd read network sysctls
  - Allow munin system plugin read generic SSL certificates
  - Allow munin system plugin create and use netlink generic socket
  - Allow login_userdomain create user namespaces
  - Allow request-key to send syslog messages
  - Allow request-key to read/view any key
  - Add fs_delete_pstore_files() interface
  - Allow insights-client work with teamdctl
  - Allow insights-client read unconfined service semaphores
  - Allow insights-client get quotas of all filesystems
  - Add fs_read_pstore_files() interface
  - Allow generic kernel helper to read inherited kernel pipes
* Fri Apr 14 2023 Zdenek Pytela <zpytela@redhat.com> - 38.11-1
  - Allow dovecot-deliver write to the main process runtime fifo files
  - Allow dmidecode write to cloud-init tmp files
  - Allow chronyd send a message to cloud-init over a datagram socket
  - Allow cloud-init domain transition to insights-client domain
  - Allow mongodb read filesystem sysctls
  - Allow mongodb read network sysctls
  - Allow accounts-daemon read generic systemd unit lnk files
  - Allow blueman watch generic device dirs
  - Allow nm-dispatcher tlp plugin create tlp dirs
  - Allow systemd-coredump mounton /usr
  - Allow rabbitmq to read network sysctls
* Tue Apr 04 2023 Zdenek Pytela <zpytela@redhat.com> - 38.10-1
  - Allow certmonger dbus chat with the cron system domain
  - Allow geoclue read network sysctls
  - Allow geoclue watch the /etc directory
  - Allow logwatch_mail_t read network sysctls
  - Allow insights-client read all sysctls
  - Allow passt manage qemu pid sock files
* Fri Mar 24 2023 Zdenek Pytela <zpytela@redhat.com> - 38.9-1
  - Allow sssd read accountsd fifo files
  - Add support for the passt_t domain
  - Allow virtd_t and svirt_t work with passt
  - Add new interfaces in the virt module
  - Add passt interfaces defined conditionally
  - Allow tshark the setsched capability
  - Allow poweroff create connections to system dbus
  - Allow wg load kernel modules, search debugfs dir
  - Boolean: allow qemu-ga manage ssh home directory
  - Label smtpd with sendmail_exec_t
  - Label msmtp and msmtpd with sendmail_exec_t
  - Allow dovecot to map files in /var/spool/dovecot
* Fri Mar 03 2023 Zdenek Pytela <zpytela@redhat.com> - 38.8-1
  - Confine gnome-initial-setup
  - Allow qemu-guest-agent create and use vsock socket
  - Allow login_pgm setcap permission
  - Allow chronyc read network sysctls
  - Enhancement of the /usr/sbin/request-key helper policy
  - Fix opencryptoki file names in /dev/shm
  - Allow system_cronjob_t transition to rpm_script_t
  - Revert "Allow system_cronjob_t domtrans to rpm_script_t"
  - Add tunable to allow squid bind snmp port
  - Allow staff_t getattr init pid chr & blk files and read krb5
  - Allow firewalld to rw z90crypt device
  - Allow httpd work with tokens in /dev/shm
  - Allow svirt to map svirt_image_t char files
  - Allow sysadm_t run initrc_t script and sysadm_r role access
  - Allow insights-client manage fsadm pid files
* Wed Feb 08 2023 Zdenek Pytela <zpytela@redhat.com> - 38.7-1
  - Allowing snapper to create snapshots of /home/ subvolume/partition
  - Add boolean qemu-ga to run unconfined script
  - Label systemd-journald feature LogNamespace
  - Add none file context for polyinstantiated tmp dirs
  - Allow certmonger read the contents of the sysfs filesystem
  - Add journalctl the sys_resource capability
  - Allow nm-dispatcher plugins read generic files in /proc
  - Add initial policy for the /usr/sbin/request-key helper
  - Additional support for rpmdb_migrate
  - Add the keyutils module
* Mon Jan 30 2023 Zdenek Pytela <zpytela@redhat.com> - 38.6-1
  - Boolean: allow qemu-ga read ssh home directory
  - Allow kernel_t to read/write all sockets
  - Allow kernel_t to UNIX-stream connect to all domains
  - Allow systemd-resolved send a datagram to journald
  - Allow kernel_t to manage and have "execute" access to all files
  - Fix the files_manage_all_files() interface
  - Allow rshim bpf cap2 and read sssd public files
  - Allow insights-client work with su and lpstat
  - Allow insights-client tcp connect to all ports
  - Allow nm-cloud-setup dispatcher plugin restart nm services
  - Allow unconfined user filetransition for sudo log files
  - Allow modemmanager create hardware state information files
  - Allow ModemManager all permissions for netlink route socket
  - Allow wg to send msg to kernel, write to syslog and dbus connections
  - Allow hostname_t to read network sysctls.
  - Dontaudit ftpd the execmem permission
  - Allow svirt request the kernel to load a module
  - Allow icecast rename its log files
  - Allow upsd to send signal to itself
  - Allow wireguard to create udp sockets and read net_conf
  - Use '
  %setup       -q
  
  
  ' instead of '%setup'
  - Pass -p 1 to '
  %setup       -q
  
  
  '
* Sat Jan 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 38.5-2
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Fri Jan 13 2023 Zdenek Pytela <zpytela@redhat.com> - 38.5-1
  - Allow insights client work with gluster and pcp
  - Add insights additional capabilities
  - Add interfaces in domain, files, and unconfined modules
  - Label fwupdoffline and fwupd-detect-cet with fwupd_exec_t
  - Allow sudodomain use sudo.log as a logfile
  - Allow pdns server map its library files and bind to unreserved ports
  - Allow sysadm_t read/write ipmi devices
  - Allow prosody manage its runtime socket files
  - Allow kernel threads manage kernel keys
  - Allow systemd-userdbd the sys_resource capability
  - Allow systemd-journal list cgroup directories
  - Allow apcupsd dbus chat with systemd-logind
  - Allow nut_domain manage also files and sock_files in /var/run
  - Allow winbind-rpcd make a TCP connection to the ldap port
  - Label /usr/lib/rpm/rpmdb_migrate with rpmdb_exec_t
  - Allow tlp read generic SSL certificates
  - Allow systemd-resolved watch tmpfs directories
  - Revert "Allow systemd-resolved watch tmpfs directories"
* Mon Dec 19 2022 Zdenek Pytela <zpytela@redhat.com> - 38.4-1
  - Allow NetworkManager and wpa_supplicant the bpf capability
  - Allow systemd-rfkill the bpf capability
  - Allow winbind-rpcd manage samba_share_t files and dirs
  - Label /var/lib/httpd/md(/.*)? with httpd_sys_rw_content_t
  - Allow gpsd the sys_ptrace userns capability
  - Introduce gpsd_tmp_t for sockfiles managed by gpsd_t
  - Allow load_policy_t write to unallocated ttys
  - Allow ndc read hardware state information
  - Allow system mail service read inherited certmonger runtime files
  - Add lpr_roles  to system_r roles
  - Revert "Allow insights-client run lpr and allow the proper role"
  - Allow stalld to read /sys/kernel/security/lockdown file
  - Allow keepalived to set resource limits
  - Add policy for mptcpd
  - Add policy for rshim
  - Allow admin users to create user namespaces
  - Allow journalctl relabel with var_log_t and syslogd_var_run_t files
  - Do not run restorecon /etc/NetworkManager/dispatcher.d in targeted
  - Trim changelog so that it starts at F35 time
  - Add mptcpd and rshim modules
* Wed Dec 14 2022 Zdenek Pytela <zpytela@redhat.com> - 38.3-1
  - Allow insights-client dbus chat with various services
  - Allow insights-client tcp connect to various ports
  - Allow insights-client run lpr and allow the proper role
  - Allow insights-client work with pcp and manage user config files
  - Allow redis get user names
  - Allow kernel threads to use fds from all domains
  - Allow systemd-modules-load load kernel modules
  - Allow login_userdomain watch systemd-passwd pid dirs
  - Allow insights-client dbus chat with abrt
  - Grant kernel_t certain permissions in the system class
  - Allow systemd-resolved watch tmpfs directories
  - Allow systemd-timedated watch init runtime dir
  - Make `bootc` be `install_exec_t`
  - Allow systemd-coredump create user_namespace
  - Allow syslog the setpcap capability
  - donaudit virtlogd and dnsmasq execmem
* Tue Dec 06 2022 Zdenek Pytela <zpytela@redhat.com> - 38.2-1
  - Don't make kernel_t an unconfined domain
  - Don't allow kernel_t to execute bin_t/usr_t binaries without a transition
  - Allow kernel_t to execute systemctl to do a poweroff/reboot
  - Grant basic permissions to the domain created by systemd_systemctl_domain()
  - Allow kernel_t to request module loading
  - Allow kernel_t to do compute_create
  - Allow kernel_t to manage perf events
  - Grant almost all capabilities to kernel_t
  - Allow kernel_t to fully manage all devices
  - Revert "In domain_transition_pattern there is no permission allowing caller domain to execu_no_trans on entrypoint, this patch fixing this issue"
  - Allow pulseaudio to write to session_dbusd tmp socket files
  - Allow systemd and unconfined_domain_type create user_namespace
  - Add the user_namespace security class
  - Reuse tmpfs_t also for the ramfs filesystem
  - Label udf tools with fsadm_exec_t
  - Allow networkmanager_dispatcher_plugin work with nscd
  - Watch_sb all file type directories.
  - Allow spamc read hardware state information files
  - Allow sysadm read ipmi devices
  - Allow insights client communicate with cupsd, mysqld, openvswitch, redis
  - Allow insights client read raw memory devices
  - Allow the spamd_update_t domain get generic filesystem attributes
  - Dontaudit systemd-gpt-generator the sys_admin capability
  - Allow ipsec_t only read tpm devices
  - Allow cups-pdf connect to the system log service
  - Allow postfix/smtpd read kerberos key table
  - Allow syslogd read network sysctls
  - Allow cdcc mmap dcc-client-map files
  - Add watch and watch_sb dosfs interface
* Mon Nov 21 2022 Zdenek Pytela <zpytela@redhat.com> - 38.1-1
  - Revert "Allow sysadm_t read raw memory devices"
  - Allow systemd-socket-proxyd get attributes of cgroup filesystems
  - Allow rpc.gssd read network sysctls
  - Allow winbind-rpcd get attributes of device and pty filesystems
  - Allow insights-client domain transition on semanage execution
  - Allow insights-client create gluster log dir with a transition
  - Allow insights-client manage generic locks
  - Allow insights-client unix_read all domain semaphores
  - Add domain_unix_read_all_semaphores() interface
  - Allow winbind-rpcd use the terminal multiplexor
  - Allow mrtg send mails
  - Allow systemd-hostnamed dbus chat with init scripts
  - Allow sssd dbus chat with system cronjobs
  - Add interface to watch all filesystems
  - Add watch_sb interfaces
  - Add watch interfaces
  - Allow dhcpd bpf capability to run bpf programs
  - Allow netutils and traceroute bpf capability to run bpf programs
  - Allow pkcs_slotd_t bpf capability to run bpf programs
  - Allow xdm bpf capability to run bpf programs
  - Allow pcscd bpf capability to run bpf programs
  - Allow lldpad bpf capability to run bpf programs
  - Allow keepalived bpf capability to run bpf programs
  - Allow ipsec bpf capability to run bpf programs
  - Allow fprintd bpf capability to run bpf programs
  - Allow systemd-socket-proxyd get filesystems attributes
  - Allow dirsrv_snmp_t to manage dirsrv_config_t & dirsrv_var_run_t files
* Mon Oct 31 2022 Zdenek Pytela <zpytela@redhat.com> - 37.14-1
  - Allow rotatelogs read httpd_log_t symlinks
  - Add winbind-rpcd to samba_enable_home_dirs boolean
  - Allow system cronjobs dbus chat with setroubleshoot
  - Allow setroubleshootd read device sysctls
  - Allow virt_domain read device sysctls
  - Allow rhcd compute selinux access vector
  - Allow insights-client manage samba var dirs
  - Label ports 10161-10162 tcp/udp with snmp
  - Allow aide to connect to systemd_machined with a unix socket.
  - Allow samba-dcerpcd use NSCD services over a unix stream socket
  - Allow vlock search the contents of the /dev/pts directory
  - Allow insights-client send null signal to rpm and system cronjob
  - Label port 15354/tcp and 15354/udp with opendnssec
  - Allow ftpd map ftpd_var_run files
  - Allow targetclid to manage tmp files
  - Allow insights-client connect to postgresql with a unix socket
  - Allow insights-client domtrans on unix_chkpwd execution
  - Add file context entries for insights-client and rhc
  - Allow pulseaudio create gnome content (~/.config)
  - Allow login_userdomain dbus chat with rhsmcertd
  - Allow sbd the sys_ptrace capability
  - Allow ptp4l_t name_bind ptp_event_port_t
* Mon Oct 03 2022 Zdenek Pytela <zpytela@redhat.com> - 37.13-1
  - Remove the ipa module
  - Allow sss daemons read/write unnamed pipes of cloud-init
  - Allow postfix_mailqueue create and use unix dgram sockets
  - Allow xdm watch user home directories
  - Allow nm-dispatcher ddclient plugin load a kernel module
  - Stop ignoring standalone interface files
  - Drop cockpit module
  - Allow init map its private tmp files
  - Allow xenstored change its hard resource limits
  - Allow system_mail-t read network sysctls
  - Add bgpd sys_chroot capability
* Thu Sep 22 2022 Zdenek Pytela <zpytela@redhat.com> - 37.12-1
  - nut-upsd: kernel_read_system_state, fs_getattr_cgroup
  - Add numad the ipc_owner capability
  - Allow gst-plugin-scanner read virtual memory sysctls
  - Allow init read/write inherited user fifo files
  - Update dnssec-trigger policy: setsched, module_request
  - added policy for systemd-socket-proxyd
  - Add the new 'cmd' permission to the 'io_uring' class
  - Allow winbind-rpcd read and write its key ring
  - Label /run/NetworkManager/no-stub-resolv.conf net_conf_t
  - blueman-mechanism can read ~/.local/lib/python*/site-packages directory
  - pidof executed by abrt can readlink /proc/*/exe
  - Fix typo in comment
  - Do not run restorecon /etc/NetworkManager/dispatcher.d in mls and minimum
* Wed Sep 14 2022 Zdenek Pytela <zpytela@redhat.com> - 37.11-1
  - Allow tor get filesystem attributes
  - Allow utempter append to login_userdomain stream
  - Allow login_userdomain accept a stream connection to XDM
  - Allow login_userdomain write to boltd named pipes
  - Allow staff_u and user_u users write to bolt pipe
  - Allow login_userdomain watch various directories
  - Update rhcd policy for executing additional commands 5
  - Update rhcd policy for executing additional commands 4
  - Allow rhcd create rpm hawkey logs with correct label
  - Allow systemd-gpt-auto-generator to check for empty dirs
  - Update rhcd policy for executing additional commands 3
  - Allow journalctl read rhcd fifo files
  - Update insights-client policy for additional commands execution 5
  - Allow init remount all file_type filesystems
  - Confine insights-client systemd unit
  - Update insights-client policy for additional commands execution 4
  - Allow pcp pmcd search tracefs and acct_data dirs
  - Allow httpd read network sysctls
  - Dontaudit domain map permission on directories
  - Revert "Allow X userdomains to mmap user_fonts_cache_t dirs"
  - Revert "Allow xdm_t domain to mmap /var/lib/gdm/.cache/fontconfig BZ(1725509)"
  - Update insights-client policy for additional commands execution 3
  - Allow systemd permissions needed for sandboxed services
  - Add rhcd module
  - Make dependency on rpm-plugin-selinux unordered
* Fri Sep 02 2022 Zdenek Pytela <zpytela@redhat.com> - 37.10-1
  - Allow ipsec_t read/write tpm devices
  - Allow rhcd execute all executables
  - Update rhcd policy for executing additional commands 2
  - Update insights-client policy for additional commands execution 2
  - Allow sysadm_t read raw memory devices
  - Allow chronyd send and receive chronyd/ntp client packets
  - Allow ssh client read kerberos homedir config files
  - Label /var/log/rhc-worker-playbook with rhcd_var_log_t
  - Update insights-client policy (auditctl, gpg, journal)
  - Allow system_cronjob_t domtrans to rpm_script_t
  - Allow smbd_t process noatsecure permission for winbind_rpcd_t
  - Update tor_bind_all_unreserved_ports interface
  - Allow chronyd bind UDP sockets to ptp_event ports.
  - Allow unconfined and sysadm users transition for /root/.gnupg
  - Add gpg_filetrans_admin_home_content() interface
  - Update rhcd policy for executing additional commands
  - Update insights-client policy for additional commands execution
  - Add userdom_view_all_users_keys() interface
  - Allow gpg read and write generic pty type
  - Allow chronyc read and write generic pty type
  - Allow system_dbusd ioctl kernel with a unix stream sockets
  - Allow samba-bgqd to read a printer list
  - Allow stalld get and set scheduling policy of all domains.
  - Allow unconfined_t transition to targetclid_home_t
* Thu Aug 11 2022 Zdenek Pytela <zpytela@redhat.com> - 37.9-1
  - Allow nm-dispatcher custom plugin dbus chat with nm
  - Allow nm-dispatcher sendmail plugin get status of systemd services
  - Allow xdm read the kernel key ring
  - Allow login_userdomain check status of mount units
  - Allow postfix/smtp and postfix/virtual read kerberos key table
  - Allow services execute systemd-notify
  - Do not allow login_userdomain use sd_notify()
  - Allow launch-xenstored read filesystem sysctls
  - Allow systemd-modules-load write to /dev/kmsg and send a message to syslogd
  - Allow openvswitch fsetid capability
  - Allow openvswitch use its private tmpfs files and dirs
  - Allow openvswitch search tracefs dirs
  - Allow pmdalinux read files on an nfsd filesystem
  - Allow winbind-rpcd write to winbind pid files
  - Allow networkmanager to signal unconfined process
  - Allow systemd_hostnamed label /run/systemd/* as hostnamed_etc_t
  - Allow samba-bgqd get a printer list
  - fix(init.fc): Fix section description
  - Allow fedora-third-party read the passwords file
  - Remove permissive domain for rhcd_t
  - Allow pmie read network state information and network sysctls
  - Revert "Dontaudit domain the fowner capability"
  - Allow sysadm_t to run bpftool on the userdomain attribute
  - Add the userdom_prog_run_bpf_userdomain() interface
  - Allow insights-client rpm named file transitions
  - Add /var/tmp/insights-archive to insights_client_filetrans_named_content
* Mon Aug 01 2022 Zdenek Pytela <zpytela@redhat.com> - 37.8-1
  - Allow sa-update to get init status and start systemd files
  - Use insights_client_filetrans_named_content
  - Make default file context match with named transitions
  - Allow nm-dispatcher tlp plugin send system log messages
  - Allow nm-dispatcher tlp plugin create and use unix_dgram_socket
  - Add permissions to manage lnk_files into gnome_manage_home_config
  - Allow rhsmcertd to read insights config files
  - Label /etc/insights-client/machine-id
  - fix(devices.fc): Replace single quote in comment to solve parsing issues
  - Make NetworkManager_dispatcher_custom_t an unconfined domain
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 37.7-2
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Thu Jul 14 2022 Zdenek Pytela <zpytela@redhat.com> - 37.7-1
  - Update winbind_rpcd_t
  - Allow some domains use sd_notify()
  - Revert "Allow rabbitmq to use systemd notify"
  - fix(sedoctool.py): Fix syntax warning: "is not" with a literal
  - Allow nm-dispatcher console plugin manage etc files
  - Allow networkmanager_dispatcher_plugin list NetworkManager_etc_t dirs
  - Allow nm-dispatcher console plugin setfscreate
  - Support using systemd-update-helper in rpm scriptlets
  - Allow nm-dispatcher winbind plugin read samba config files
  - Allow domain use userfaultfd over all domains
  - Allow cups-lpd read network sysctls
* Wed Jun 29 2022 Zdenek Pytela <zpytela@redhat.com> - 37.6-1
  - Allow stalld set scheduling policy of kernel threads
  - Allow targetclid read /var/target files
  - Allow targetclid read generic SSL certificates (fixed)
  - Allow firewalld read the contents of the sysfs filesystem
  - Fix file context pattern for /var/target
  - Use insights_client_etc_t in insights_search_config()
  - Allow nm-dispatcher ddclient plugin handle systemd services
  - Allow nm-dispatcher winbind plugin run smbcontrol
  - Allow nm-dispatcher custom plugin create and use unix dgram socket
  - Update samba-dcerpcd policy for kerberos usage 2
  - Allow keepalived read the contents of the sysfs filesystem
  - Allow amandad read network sysctls
  - Allow cups-lpd read network sysctls
  - Allow kpropd read network sysctls
  - Update insights_client_filetrans_named_content()
  - Allow rabbitmq to use systemd notify
  - Label /var/target with targetd_var_t
  - Allow targetclid read generic SSL certificates
  - Update rhcd policy
  - Allow rhcd search insights configuration directories
  - Add the kernel_read_proc_files() interface
  - Require policycoreutils >= 3.4-1
  - Add a script for enclosing interfaces in ifndef statements
  - Disable rpm verification on interface_info
* Wed Jun 22 2022 Zdenek Pytela <zpytela@redhat.com> - 37.5-1
  - Allow transition to insights_client named content
  - Add the insights_client_filetrans_named_content() interface
  - Update policy for insights-client to run additional commands 3
  - Allow dhclient manage pid files used by chronyd
  - Allow stalld get scheduling policy of kernel threads
  - Allow samba-dcerpcd work with sssd
  - Allow dlm_controld send a null signal to a cluster daemon
  - Allow ksmctl create hardware state information files
  - Allow winbind_rpcd_t connect to self over a unix_stream_socket
  - Update samba-dcerpcd policy for kerberos usage
  - Allow insights-client execute its private memfd: objects
  - Update policy for insights-client to run additional commands 2
  - Use insights_client_tmp_t instead of insights_client_var_tmp_t
  - Change space indentation to tab in insights-client
  - Use socket permissions sets in insights-client
  - Update policy for insights-client to run additional commands
  - Change rpm_setattr_db_files() to use a pattern
  - Allow init_t to rw insights_client unnamed pipe
  - Add rpm setattr db files macro
  - Fix insights client
  - Update kernel_read_unix_sysctls() for sysctl_net_unix_t handling
  - Allow rabbitmq to access its private memfd: objects
  - Update policy for samba-dcerpcd
  - Allow stalld setsched and sys_nice
* Tue Jun 07 2022 Zdenek Pytela <zpytela@redhat.com> - 37.4-1
  - Allow auditd_t noatsecure for a transition to audisp_remote_t
  - Allow ctdbd nlmsg_read on netlink_tcpdiag_socket
  - Allow pcp_domain execute its private memfd: objects
  - Add support for samba-dcerpcd
  - Add policy for wireguard
  - Confine targetcli
  - Allow systemd work with install_t unix stream sockets
  - Allow iscsid the sys_ptrace userns capability
  - Allow xdm connect to unconfined_service_t over a unix stream socket
* Fri May 27 2022 Zdenek Pytela <zpytela@redhat.com> - 37.3-1
  - Allow nm-dispatcher custom plugin execute systemctl
  - Allow nm-dispatcher custom plugin dbus chat with nm
  - Allow nm-dispatcher custom plugin create and use udp socket
  - Allow nm-dispatcher custom plugin create and use netlink_route_socket
  - Use create_netlink_socket_perms in netlink_route_socket class permissions
  - Add support for nm-dispatcher sendmail scripts
  - Allow sslh net_admin capability
  - Allow insights-client manage gpg admin home content
  - Add the gpg_manage_admin_home_content() interface
  - Allow rhsmcertd create generic log files
  - Update logging_create_generic_logs() to use create_files_pattern()
  - Label /var/cache/insights with insights_client_cache_t
  - Allow insights-client search gconf homedir
  - Allow insights-client create and use unix_dgram_socket
  - Allow blueman execute its private memfd: files
  - Move the chown call into make-srpm.sh
* Fri May 06 2022 Zdenek Pytela <zpytela@redhat.com> - 37.2-1
  - Use the networkmanager_dispatcher_plugin attribute in allow rules
  - Make a custom nm-dispatcher plugin transition
  - Label port 4784/tcp and 4784/udp with bfd_multi
  - Allow systemd watch and watch_reads user ptys
  - Allow sblim-gatherd the kill capability
  - Label more vdsm utils with virtd_exec_t
  - Add ksm service to ksmtuned
  - Add rhcd policy
  - Dontaudit guest attempts to dbus chat with systemd domains
  - Dontaudit guest attempts to dbus chat with system bus types
  - Use a named transition in systemd_hwdb_manage_config()
  - Add default fc specifications for patterns in /opt
  - Add the files_create_etc_files() interface
  - Allow nm-dispatcher console plugin create and write files in /etc
  - Allow nm-dispatcher console plugin transition to the setfiles domain
  - Allow more nm-dispatcher plugins append to init stream sockets
  - Allow nm-dispatcher tlp plugin dbus chat with nm
  - Reorder networkmanager_dispatcher_plugin_template() calls
  - Allow svirt connectto virtlogd
  - Allow blueman map its private memfd: files
  - Allow sysadm user execute init scripts with a transition
  - Allow sblim-sfcbd connect to sblim-reposd stream
  - Allow keepalived_unconfined_script_t dbus chat with init
  - Run restorecon with "-i" not to report errors
* Mon May 02 2022 Zdenek Pytela <zpytela@redhat.com> - 37.1-1
  - Fix users for SELinux userspace 3.4
  - Label /var/run/machine-id as machineid_t
  - Add stalld to modules.conf
  - Use files_tmpfs_file() for rhsmcertd_tmpfs_t
  - Allow blueman read/write its private memfd: objects
  - Allow insights-client read rhnsd config files
  - Allow insights-client create_socket_perms for tcp/udp sockets

Files

/etc/selinux/mls
/etc/selinux/mls/.policy.sha512
/etc/selinux/mls/booleans.subs_dist
/etc/selinux/mls/contexts
/etc/selinux/mls/contexts/customizable_types
/etc/selinux/mls/contexts/dbus_contexts
/etc/selinux/mls/contexts/default_contexts
/etc/selinux/mls/contexts/default_type
/etc/selinux/mls/contexts/failsafe_context
/etc/selinux/mls/contexts/files
/etc/selinux/mls/contexts/files/file_contexts
/etc/selinux/mls/contexts/files/file_contexts.bin
/etc/selinux/mls/contexts/files/file_contexts.homedirs
/etc/selinux/mls/contexts/files/file_contexts.homedirs.bin
/etc/selinux/mls/contexts/files/file_contexts.local
/etc/selinux/mls/contexts/files/file_contexts.local.bin
/etc/selinux/mls/contexts/files/file_contexts.subs
/etc/selinux/mls/contexts/files/file_contexts.subs_dist
/etc/selinux/mls/contexts/files/media
/etc/selinux/mls/contexts/initrc_context
/etc/selinux/mls/contexts/lxc_contexts
/etc/selinux/mls/contexts/openssh_contexts
/etc/selinux/mls/contexts/removable_context
/etc/selinux/mls/contexts/securetty_types
/etc/selinux/mls/contexts/sepgsql_contexts
/etc/selinux/mls/contexts/snapperd_contexts
/etc/selinux/mls/contexts/systemd_contexts
/etc/selinux/mls/contexts/userhelper_context
/etc/selinux/mls/contexts/users
/etc/selinux/mls/contexts/users/guest_u
/etc/selinux/mls/contexts/users/root
/etc/selinux/mls/contexts/users/staff_u
/etc/selinux/mls/contexts/users/unconfined_u
/etc/selinux/mls/contexts/users/user_u
/etc/selinux/mls/contexts/users/xguest_u
/etc/selinux/mls/contexts/virtual_domain_context
/etc/selinux/mls/contexts/virtual_image_context
/etc/selinux/mls/contexts/x_contexts
/etc/selinux/mls/logins
/etc/selinux/mls/policy
/etc/selinux/mls/policy/policy.33
/etc/selinux/mls/setrans.conf
/etc/selinux/mls/seusers
/usr/share/selinux/mls
/usr/share/selinux/mls/base.lst
/usr/share/selinux/mls/modules-base.lst
/usr/share/selinux/mls/modules-contrib.lst
/usr/share/selinux/mls/nonbasemodules.lst
/var/lib/selinux/mls
/var/lib/selinux/mls/active
/var/lib/selinux/mls/active/commit_num
/var/lib/selinux/mls/active/file_contexts
/var/lib/selinux/mls/active/file_contexts.homedirs
/var/lib/selinux/mls/active/homedir_template
/var/lib/selinux/mls/active/modules
/var/lib/selinux/mls/active/modules/100/accountsd
/var/lib/selinux/mls/active/modules/100/accountsd/cil
/var/lib/selinux/mls/active/modules/100/accountsd/hll
/var/lib/selinux/mls/active/modules/100/accountsd/lang_ext
/var/lib/selinux/mls/active/modules/100/acct
/var/lib/selinux/mls/active/modules/100/acct/cil
/var/lib/selinux/mls/active/modules/100/acct/hll
/var/lib/selinux/mls/active/modules/100/acct/lang_ext
/var/lib/selinux/mls/active/modules/100/afs
/var/lib/selinux/mls/active/modules/100/afs/cil
/var/lib/selinux/mls/active/modules/100/afs/hll
/var/lib/selinux/mls/active/modules/100/afs/lang_ext
/var/lib/selinux/mls/active/modules/100/aide
/var/lib/selinux/mls/active/modules/100/aide/cil
/var/lib/selinux/mls/active/modules/100/aide/hll
/var/lib/selinux/mls/active/modules/100/aide/lang_ext
/var/lib/selinux/mls/active/modules/100/alsa
/var/lib/selinux/mls/active/modules/100/alsa/cil
/var/lib/selinux/mls/active/modules/100/alsa/hll
/var/lib/selinux/mls/active/modules/100/alsa/lang_ext
/var/lib/selinux/mls/active/modules/100/amanda
/var/lib/selinux/mls/active/modules/100/amanda/cil
/var/lib/selinux/mls/active/modules/100/amanda/hll
/var/lib/selinux/mls/active/modules/100/amanda/lang_ext
/var/lib/selinux/mls/active/modules/100/amtu
/var/lib/selinux/mls/active/modules/100/amtu/cil
/var/lib/selinux/mls/active/modules/100/amtu/hll
/var/lib/selinux/mls/active/modules/100/amtu/lang_ext
/var/lib/selinux/mls/active/modules/100/anaconda
/var/lib/selinux/mls/active/modules/100/anaconda/cil
/var/lib/selinux/mls/active/modules/100/anaconda/hll
/var/lib/selinux/mls/active/modules/100/anaconda/lang_ext
/var/lib/selinux/mls/active/modules/100/antivirus
/var/lib/selinux/mls/active/modules/100/antivirus/cil
/var/lib/selinux/mls/active/modules/100/antivirus/hll
/var/lib/selinux/mls/active/modules/100/antivirus/lang_ext
/var/lib/selinux/mls/active/modules/100/apache
/var/lib/selinux/mls/active/modules/100/apache/cil
/var/lib/selinux/mls/active/modules/100/apache/hll
/var/lib/selinux/mls/active/modules/100/apache/lang_ext
/var/lib/selinux/mls/active/modules/100/apcupsd
/var/lib/selinux/mls/active/modules/100/apcupsd/cil
/var/lib/selinux/mls/active/modules/100/apcupsd/hll
/var/lib/selinux/mls/active/modules/100/apcupsd/lang_ext
/var/lib/selinux/mls/active/modules/100/apm
/var/lib/selinux/mls/active/modules/100/apm/cil
/var/lib/selinux/mls/active/modules/100/apm/hll
/var/lib/selinux/mls/active/modules/100/apm/lang_ext
/var/lib/selinux/mls/active/modules/100/application
/var/lib/selinux/mls/active/modules/100/application/cil
/var/lib/selinux/mls/active/modules/100/application/hll
/var/lib/selinux/mls/active/modules/100/application/lang_ext
/var/lib/selinux/mls/active/modules/100/arpwatch
/var/lib/selinux/mls/active/modules/100/arpwatch/cil
/var/lib/selinux/mls/active/modules/100/arpwatch/hll
/var/lib/selinux/mls/active/modules/100/arpwatch/lang_ext
/var/lib/selinux/mls/active/modules/100/auditadm
/var/lib/selinux/mls/active/modules/100/auditadm/cil
/var/lib/selinux/mls/active/modules/100/auditadm/hll
/var/lib/selinux/mls/active/modules/100/auditadm/lang_ext
/var/lib/selinux/mls/active/modules/100/authlogin
/var/lib/selinux/mls/active/modules/100/authlogin/cil
/var/lib/selinux/mls/active/modules/100/authlogin/hll
/var/lib/selinux/mls/active/modules/100/authlogin/lang_ext
/var/lib/selinux/mls/active/modules/100/automount
/var/lib/selinux/mls/active/modules/100/automount/cil
/var/lib/selinux/mls/active/modules/100/automount/hll
/var/lib/selinux/mls/active/modules/100/automount/lang_ext
/var/lib/selinux/mls/active/modules/100/avahi
/var/lib/selinux/mls/active/modules/100/avahi/cil
/var/lib/selinux/mls/active/modules/100/avahi/hll
/var/lib/selinux/mls/active/modules/100/avahi/lang_ext
/var/lib/selinux/mls/active/modules/100/awstats
/var/lib/selinux/mls/active/modules/100/awstats/cil
/var/lib/selinux/mls/active/modules/100/awstats/hll
/var/lib/selinux/mls/active/modules/100/awstats/lang_ext
/var/lib/selinux/mls/active/modules/100/base
/var/lib/selinux/mls/active/modules/100/base/cil
/var/lib/selinux/mls/active/modules/100/base/hll
/var/lib/selinux/mls/active/modules/100/base/lang_ext
/var/lib/selinux/mls/active/modules/100/bind
/var/lib/selinux/mls/active/modules/100/bind/cil
/var/lib/selinux/mls/active/modules/100/bind/hll
/var/lib/selinux/mls/active/modules/100/bind/lang_ext
/var/lib/selinux/mls/active/modules/100/bitlbee
/var/lib/selinux/mls/active/modules/100/bitlbee/cil
/var/lib/selinux/mls/active/modules/100/bitlbee/hll
/var/lib/selinux/mls/active/modules/100/bitlbee/lang_ext
/var/lib/selinux/mls/active/modules/100/bluetooth
/var/lib/selinux/mls/active/modules/100/bluetooth/cil
/var/lib/selinux/mls/active/modules/100/bluetooth/hll
/var/lib/selinux/mls/active/modules/100/bluetooth/lang_ext
/var/lib/selinux/mls/active/modules/100/boinc
/var/lib/selinux/mls/active/modules/100/boinc/cil
/var/lib/selinux/mls/active/modules/100/boinc/hll
/var/lib/selinux/mls/active/modules/100/boinc/lang_ext
/var/lib/selinux/mls/active/modules/100/bootloader
/var/lib/selinux/mls/active/modules/100/bootloader/cil
/var/lib/selinux/mls/active/modules/100/bootloader/hll
/var/lib/selinux/mls/active/modules/100/bootloader/lang_ext
/var/lib/selinux/mls/active/modules/100/brctl
/var/lib/selinux/mls/active/modules/100/brctl/cil
/var/lib/selinux/mls/active/modules/100/brctl/hll
/var/lib/selinux/mls/active/modules/100/brctl/lang_ext
/var/lib/selinux/mls/active/modules/100/bugzilla
/var/lib/selinux/mls/active/modules/100/bugzilla/cil
/var/lib/selinux/mls/active/modules/100/bugzilla/hll
/var/lib/selinux/mls/active/modules/100/bugzilla/lang_ext
/var/lib/selinux/mls/active/modules/100/cachefilesd
/var/lib/selinux/mls/active/modules/100/cachefilesd/cil
/var/lib/selinux/mls/active/modules/100/cachefilesd/hll
/var/lib/selinux/mls/active/modules/100/cachefilesd/lang_ext
/var/lib/selinux/mls/active/modules/100/calamaris
/var/lib/selinux/mls/active/modules/100/calamaris/cil
/var/lib/selinux/mls/active/modules/100/calamaris/hll
/var/lib/selinux/mls/active/modules/100/calamaris/lang_ext
/var/lib/selinux/mls/active/modules/100/canna
/var/lib/selinux/mls/active/modules/100/canna/cil
/var/lib/selinux/mls/active/modules/100/canna/hll
/var/lib/selinux/mls/active/modules/100/canna/lang_ext
/var/lib/selinux/mls/active/modules/100/ccs
/var/lib/selinux/mls/active/modules/100/ccs/cil
/var/lib/selinux/mls/active/modules/100/ccs/hll
/var/lib/selinux/mls/active/modules/100/ccs/lang_ext
/var/lib/selinux/mls/active/modules/100/cdrecord
/var/lib/selinux/mls/active/modules/100/cdrecord/cil
/var/lib/selinux/mls/active/modules/100/cdrecord/hll
/var/lib/selinux/mls/active/modules/100/cdrecord/lang_ext
/var/lib/selinux/mls/active/modules/100/certmaster
/var/lib/selinux/mls/active/modules/100/certmaster/cil
/var/lib/selinux/mls/active/modules/100/certmaster/hll
/var/lib/selinux/mls/active/modules/100/certmaster/lang_ext
/var/lib/selinux/mls/active/modules/100/certmonger
/var/lib/selinux/mls/active/modules/100/certmonger/cil
/var/lib/selinux/mls/active/modules/100/certmonger/hll
/var/lib/selinux/mls/active/modules/100/certmonger/lang_ext
/var/lib/selinux/mls/active/modules/100/certwatch
/var/lib/selinux/mls/active/modules/100/certwatch/cil
/var/lib/selinux/mls/active/modules/100/certwatch/hll
/var/lib/selinux/mls/active/modules/100/certwatch/lang_ext
/var/lib/selinux/mls/active/modules/100/cgroup
/var/lib/selinux/mls/active/modules/100/cgroup/cil
/var/lib/selinux/mls/active/modules/100/cgroup/hll
/var/lib/selinux/mls/active/modules/100/cgroup/lang_ext
/var/lib/selinux/mls/active/modules/100/chrome
/var/lib/selinux/mls/active/modules/100/chrome/cil
/var/lib/selinux/mls/active/modules/100/chrome/hll
/var/lib/selinux/mls/active/modules/100/chrome/lang_ext
/var/lib/selinux/mls/active/modules/100/chronyd
/var/lib/selinux/mls/active/modules/100/chronyd/cil
/var/lib/selinux/mls/active/modules/100/chronyd/hll
/var/lib/selinux/mls/active/modules/100/chronyd/lang_ext
/var/lib/selinux/mls/active/modules/100/cipe
/var/lib/selinux/mls/active/modules/100/cipe/cil
/var/lib/selinux/mls/active/modules/100/cipe/hll
/var/lib/selinux/mls/active/modules/100/cipe/lang_ext
/var/lib/selinux/mls/active/modules/100/clock
/var/lib/selinux/mls/active/modules/100/clock/cil
/var/lib/selinux/mls/active/modules/100/clock/hll
/var/lib/selinux/mls/active/modules/100/clock/lang_ext
/var/lib/selinux/mls/active/modules/100/clogd
/var/lib/selinux/mls/active/modules/100/clogd/cil
/var/lib/selinux/mls/active/modules/100/clogd/hll
/var/lib/selinux/mls/active/modules/100/clogd/lang_ext
/var/lib/selinux/mls/active/modules/100/cmirrord
/var/lib/selinux/mls/active/modules/100/cmirrord/cil
/var/lib/selinux/mls/active/modules/100/cmirrord/hll
/var/lib/selinux/mls/active/modules/100/cmirrord/lang_ext
/var/lib/selinux/mls/active/modules/100/colord
/var/lib/selinux/mls/active/modules/100/colord/cil
/var/lib/selinux/mls/active/modules/100/colord/hll
/var/lib/selinux/mls/active/modules/100/colord/lang_ext
/var/lib/selinux/mls/active/modules/100/comsat
/var/lib/selinux/mls/active/modules/100/comsat/cil
/var/lib/selinux/mls/active/modules/100/comsat/hll
/var/lib/selinux/mls/active/modules/100/comsat/lang_ext
/var/lib/selinux/mls/active/modules/100/courier
/var/lib/selinux/mls/active/modules/100/courier/cil
/var/lib/selinux/mls/active/modules/100/courier/hll
/var/lib/selinux/mls/active/modules/100/courier/lang_ext
/var/lib/selinux/mls/active/modules/100/cpucontrol
/var/lib/selinux/mls/active/modules/100/cpucontrol/cil
/var/lib/selinux/mls/active/modules/100/cpucontrol/hll
/var/lib/selinux/mls/active/modules/100/cpucontrol/lang_ext
/var/lib/selinux/mls/active/modules/100/cpufreqselector
/var/lib/selinux/mls/active/modules/100/cpufreqselector/cil
/var/lib/selinux/mls/active/modules/100/cpufreqselector/hll
/var/lib/selinux/mls/active/modules/100/cpufreqselector/lang_ext
/var/lib/selinux/mls/active/modules/100/cron
/var/lib/selinux/mls/active/modules/100/cron/cil
/var/lib/selinux/mls/active/modules/100/cron/hll
/var/lib/selinux/mls/active/modules/100/cron/lang_ext
/var/lib/selinux/mls/active/modules/100/cups
/var/lib/selinux/mls/active/modules/100/cups/cil
/var/lib/selinux/mls/active/modules/100/cups/hll
/var/lib/selinux/mls/active/modules/100/cups/lang_ext
/var/lib/selinux/mls/active/modules/100/cvs
/var/lib/selinux/mls/active/modules/100/cvs/cil
/var/lib/selinux/mls/active/modules/100/cvs/hll
/var/lib/selinux/mls/active/modules/100/cvs/lang_ext
/var/lib/selinux/mls/active/modules/100/cyphesis
/var/lib/selinux/mls/active/modules/100/cyphesis/cil
/var/lib/selinux/mls/active/modules/100/cyphesis/hll
/var/lib/selinux/mls/active/modules/100/cyphesis/lang_ext
/var/lib/selinux/mls/active/modules/100/cyrus
/var/lib/selinux/mls/active/modules/100/cyrus/cil
/var/lib/selinux/mls/active/modules/100/cyrus/hll
/var/lib/selinux/mls/active/modules/100/cyrus/lang_ext
/var/lib/selinux/mls/active/modules/100/daemontools
/var/lib/selinux/mls/active/modules/100/daemontools/cil
/var/lib/selinux/mls/active/modules/100/daemontools/hll
/var/lib/selinux/mls/active/modules/100/daemontools/lang_ext
/var/lib/selinux/mls/active/modules/100/dbadm
/var/lib/selinux/mls/active/modules/100/dbadm/cil
/var/lib/selinux/mls/active/modules/100/dbadm/hll
/var/lib/selinux/mls/active/modules/100/dbadm/lang_ext
/var/lib/selinux/mls/active/modules/100/dbskk
/var/lib/selinux/mls/active/modules/100/dbskk/cil
/var/lib/selinux/mls/active/modules/100/dbskk/hll
/var/lib/selinux/mls/active/modules/100/dbskk/lang_ext
/var/lib/selinux/mls/active/modules/100/dbus
/var/lib/selinux/mls/active/modules/100/dbus/cil
/var/lib/selinux/mls/active/modules/100/dbus/hll
/var/lib/selinux/mls/active/modules/100/dbus/lang_ext
/var/lib/selinux/mls/active/modules/100/dcc
/var/lib/selinux/mls/active/modules/100/dcc/cil
/var/lib/selinux/mls/active/modules/100/dcc/hll
/var/lib/selinux/mls/active/modules/100/dcc/lang_ext
/var/lib/selinux/mls/active/modules/100/devicekit
/var/lib/selinux/mls/active/modules/100/devicekit/cil
/var/lib/selinux/mls/active/modules/100/devicekit/hll
/var/lib/selinux/mls/active/modules/100/devicekit/lang_ext
/var/lib/selinux/mls/active/modules/100/dhcp
/var/lib/selinux/mls/active/modules/100/dhcp/cil
/var/lib/selinux/mls/active/modules/100/dhcp/hll
/var/lib/selinux/mls/active/modules/100/dhcp/lang_ext
/var/lib/selinux/mls/active/modules/100/dictd
/var/lib/selinux/mls/active/modules/100/dictd/cil
/var/lib/selinux/mls/active/modules/100/dictd/hll
/var/lib/selinux/mls/active/modules/100/dictd/lang_ext
/var/lib/selinux/mls/active/modules/100/dmesg
/var/lib/selinux/mls/active/modules/100/dmesg/cil
/var/lib/selinux/mls/active/modules/100/dmesg/hll
/var/lib/selinux/mls/active/modules/100/dmesg/lang_ext
/var/lib/selinux/mls/active/modules/100/dmidecode
/var/lib/selinux/mls/active/modules/100/dmidecode/cil
/var/lib/selinux/mls/active/modules/100/dmidecode/hll
/var/lib/selinux/mls/active/modules/100/dmidecode/lang_ext
/var/lib/selinux/mls/active/modules/100/dnsmasq
/var/lib/selinux/mls/active/modules/100/dnsmasq/cil
/var/lib/selinux/mls/active/modules/100/dnsmasq/hll
/var/lib/selinux/mls/active/modules/100/dnsmasq/lang_ext
/var/lib/selinux/mls/active/modules/100/dnssec
/var/lib/selinux/mls/active/modules/100/dnssec/cil
/var/lib/selinux/mls/active/modules/100/dnssec/hll
/var/lib/selinux/mls/active/modules/100/dnssec/lang_ext
/var/lib/selinux/mls/active/modules/100/dovecot
/var/lib/selinux/mls/active/modules/100/dovecot/cil
/var/lib/selinux/mls/active/modules/100/dovecot/hll
/var/lib/selinux/mls/active/modules/100/dovecot/lang_ext
/var/lib/selinux/mls/active/modules/100/entropyd
/var/lib/selinux/mls/active/modules/100/entropyd/cil
/var/lib/selinux/mls/active/modules/100/entropyd/hll
/var/lib/selinux/mls/active/modules/100/entropyd/lang_ext
/var/lib/selinux/mls/active/modules/100/exim
/var/lib/selinux/mls/active/modules/100/exim/cil
/var/lib/selinux/mls/active/modules/100/exim/hll
/var/lib/selinux/mls/active/modules/100/exim/lang_ext
/var/lib/selinux/mls/active/modules/100/fail2ban
/var/lib/selinux/mls/active/modules/100/fail2ban/cil
/var/lib/selinux/mls/active/modules/100/fail2ban/hll
/var/lib/selinux/mls/active/modules/100/fail2ban/lang_ext
/var/lib/selinux/mls/active/modules/100/fetchmail
/var/lib/selinux/mls/active/modules/100/fetchmail/cil
/var/lib/selinux/mls/active/modules/100/fetchmail/hll
/var/lib/selinux/mls/active/modules/100/fetchmail/lang_ext
/var/lib/selinux/mls/active/modules/100/finger
/var/lib/selinux/mls/active/modules/100/finger/cil
/var/lib/selinux/mls/active/modules/100/finger/hll
/var/lib/selinux/mls/active/modules/100/finger/lang_ext
/var/lib/selinux/mls/active/modules/100/firewalld
/var/lib/selinux/mls/active/modules/100/firewalld/cil
/var/lib/selinux/mls/active/modules/100/firewalld/hll
/var/lib/selinux/mls/active/modules/100/firewalld/lang_ext
/var/lib/selinux/mls/active/modules/100/firewallgui
/var/lib/selinux/mls/active/modules/100/firewallgui/cil
/var/lib/selinux/mls/active/modules/100/firewallgui/hll
/var/lib/selinux/mls/active/modules/100/firewallgui/lang_ext
/var/lib/selinux/mls/active/modules/100/firstboot
/var/lib/selinux/mls/active/modules/100/firstboot/cil
/var/lib/selinux/mls/active/modules/100/firstboot/hll
/var/lib/selinux/mls/active/modules/100/firstboot/lang_ext
/var/lib/selinux/mls/active/modules/100/fprintd
/var/lib/selinux/mls/active/modules/100/fprintd/cil
/var/lib/selinux/mls/active/modules/100/fprintd/hll
/var/lib/selinux/mls/active/modules/100/fprintd/lang_ext
/var/lib/selinux/mls/active/modules/100/fstools
/var/lib/selinux/mls/active/modules/100/fstools/cil
/var/lib/selinux/mls/active/modules/100/fstools/hll
/var/lib/selinux/mls/active/modules/100/fstools/lang_ext
/var/lib/selinux/mls/active/modules/100/ftp
/var/lib/selinux/mls/active/modules/100/ftp/cil
/var/lib/selinux/mls/active/modules/100/ftp/hll
/var/lib/selinux/mls/active/modules/100/ftp/lang_ext
/var/lib/selinux/mls/active/modules/100/games
/var/lib/selinux/mls/active/modules/100/games/cil
/var/lib/selinux/mls/active/modules/100/games/hll
/var/lib/selinux/mls/active/modules/100/games/lang_ext
/var/lib/selinux/mls/active/modules/100/getty
/var/lib/selinux/mls/active/modules/100/getty/cil
/var/lib/selinux/mls/active/modules/100/getty/hll
/var/lib/selinux/mls/active/modules/100/getty/lang_ext
/var/lib/selinux/mls/active/modules/100/git
/var/lib/selinux/mls/active/modules/100/git/cil
/var/lib/selinux/mls/active/modules/100/git/hll
/var/lib/selinux/mls/active/modules/100/git/lang_ext
/var/lib/selinux/mls/active/modules/100/gitosis
/var/lib/selinux/mls/active/modules/100/gitosis/cil
/var/lib/selinux/mls/active/modules/100/gitosis/hll
/var/lib/selinux/mls/active/modules/100/gitosis/lang_ext
/var/lib/selinux/mls/active/modules/100/glance
/var/lib/selinux/mls/active/modules/100/glance/cil
/var/lib/selinux/mls/active/modules/100/glance/hll
/var/lib/selinux/mls/active/modules/100/glance/lang_ext
/var/lib/selinux/mls/active/modules/100/gnome
/var/lib/selinux/mls/active/modules/100/gnome/cil
/var/lib/selinux/mls/active/modules/100/gnome/hll
/var/lib/selinux/mls/active/modules/100/gnome/lang_ext
/var/lib/selinux/mls/active/modules/100/gpg
/var/lib/selinux/mls/active/modules/100/gpg/cil
/var/lib/selinux/mls/active/modules/100/gpg/hll
/var/lib/selinux/mls/active/modules/100/gpg/lang_ext
/var/lib/selinux/mls/active/modules/100/gpm
/var/lib/selinux/mls/active/modules/100/gpm/cil
/var/lib/selinux/mls/active/modules/100/gpm/hll
/var/lib/selinux/mls/active/modules/100/gpm/lang_ext
/var/lib/selinux/mls/active/modules/100/gpsd
/var/lib/selinux/mls/active/modules/100/gpsd/cil
/var/lib/selinux/mls/active/modules/100/gpsd/hll
/var/lib/selinux/mls/active/modules/100/gpsd/lang_ext
/var/lib/selinux/mls/active/modules/100/gssproxy
/var/lib/selinux/mls/active/modules/100/gssproxy/cil
/var/lib/selinux/mls/active/modules/100/gssproxy/hll
/var/lib/selinux/mls/active/modules/100/gssproxy/lang_ext
/var/lib/selinux/mls/active/modules/100/guest
/var/lib/selinux/mls/active/modules/100/guest/cil
/var/lib/selinux/mls/active/modules/100/guest/hll
/var/lib/selinux/mls/active/modules/100/guest/lang_ext
/var/lib/selinux/mls/active/modules/100/hostname
/var/lib/selinux/mls/active/modules/100/hostname/cil
/var/lib/selinux/mls/active/modules/100/hostname/hll
/var/lib/selinux/mls/active/modules/100/hostname/lang_ext
/var/lib/selinux/mls/active/modules/100/inetd
/var/lib/selinux/mls/active/modules/100/inetd/cil
/var/lib/selinux/mls/active/modules/100/inetd/hll
/var/lib/selinux/mls/active/modules/100/inetd/lang_ext
/var/lib/selinux/mls/active/modules/100/init
/var/lib/selinux/mls/active/modules/100/init/cil
/var/lib/selinux/mls/active/modules/100/init/hll
/var/lib/selinux/mls/active/modules/100/init/lang_ext
/var/lib/selinux/mls/active/modules/100/inn
/var/lib/selinux/mls/active/modules/100/inn/cil
/var/lib/selinux/mls/active/modules/100/inn/hll
/var/lib/selinux/mls/active/modules/100/inn/lang_ext
/var/lib/selinux/mls/active/modules/100/ipsec
/var/lib/selinux/mls/active/modules/100/ipsec/cil
/var/lib/selinux/mls/active/modules/100/ipsec/hll
/var/lib/selinux/mls/active/modules/100/ipsec/lang_ext
/var/lib/selinux/mls/active/modules/100/iptables
/var/lib/selinux/mls/active/modules/100/iptables/cil
/var/lib/selinux/mls/active/modules/100/iptables/hll
/var/lib/selinux/mls/active/modules/100/iptables/lang_ext
/var/lib/selinux/mls/active/modules/100/irc
/var/lib/selinux/mls/active/modules/100/irc/cil
/var/lib/selinux/mls/active/modules/100/irc/hll
/var/lib/selinux/mls/active/modules/100/irc/lang_ext
/var/lib/selinux/mls/active/modules/100/irqbalance
/var/lib/selinux/mls/active/modules/100/irqbalance/cil
/var/lib/selinux/mls/active/modules/100/irqbalance/hll
/var/lib/selinux/mls/active/modules/100/irqbalance/lang_ext
/var/lib/selinux/mls/active/modules/100/iscsi
/var/lib/selinux/mls/active/modules/100/iscsi/cil
/var/lib/selinux/mls/active/modules/100/iscsi/hll
/var/lib/selinux/mls/active/modules/100/iscsi/lang_ext
/var/lib/selinux/mls/active/modules/100/jabber
/var/lib/selinux/mls/active/modules/100/jabber/cil
/var/lib/selinux/mls/active/modules/100/jabber/hll
/var/lib/selinux/mls/active/modules/100/jabber/lang_ext
/var/lib/selinux/mls/active/modules/100/kdump
/var/lib/selinux/mls/active/modules/100/kdump/cil
/var/lib/selinux/mls/active/modules/100/kdump/hll
/var/lib/selinux/mls/active/modules/100/kdump/lang_ext
/var/lib/selinux/mls/active/modules/100/kdumpgui
/var/lib/selinux/mls/active/modules/100/kdumpgui/cil
/var/lib/selinux/mls/active/modules/100/kdumpgui/hll
/var/lib/selinux/mls/active/modules/100/kdumpgui/lang_ext
/var/lib/selinux/mls/active/modules/100/kerberos
/var/lib/selinux/mls/active/modules/100/kerberos/cil
/var/lib/selinux/mls/active/modules/100/kerberos/hll
/var/lib/selinux/mls/active/modules/100/kerberos/lang_ext
/var/lib/selinux/mls/active/modules/100/kismet
/var/lib/selinux/mls/active/modules/100/kismet/cil
/var/lib/selinux/mls/active/modules/100/kismet/hll
/var/lib/selinux/mls/active/modules/100/kismet/lang_ext
/var/lib/selinux/mls/active/modules/100/ksmtuned
/var/lib/selinux/mls/active/modules/100/ksmtuned/cil
/var/lib/selinux/mls/active/modules/100/ksmtuned/hll
/var/lib/selinux/mls/active/modules/100/ksmtuned/lang_ext
/var/lib/selinux/mls/active/modules/100/ktalk
/var/lib/selinux/mls/active/modules/100/ktalk/cil
/var/lib/selinux/mls/active/modules/100/ktalk/hll
/var/lib/selinux/mls/active/modules/100/ktalk/lang_ext
/var/lib/selinux/mls/active/modules/100/ldap
/var/lib/selinux/mls/active/modules/100/ldap/cil
/var/lib/selinux/mls/active/modules/100/ldap/hll
/var/lib/selinux/mls/active/modules/100/ldap/lang_ext
/var/lib/selinux/mls/active/modules/100/libraries
/var/lib/selinux/mls/active/modules/100/libraries/cil
/var/lib/selinux/mls/active/modules/100/libraries/hll
/var/lib/selinux/mls/active/modules/100/libraries/lang_ext
/var/lib/selinux/mls/active/modules/100/lircd
/var/lib/selinux/mls/active/modules/100/lircd/cil
/var/lib/selinux/mls/active/modules/100/lircd/hll
/var/lib/selinux/mls/active/modules/100/lircd/lang_ext
/var/lib/selinux/mls/active/modules/100/loadkeys
/var/lib/selinux/mls/active/modules/100/loadkeys/cil
/var/lib/selinux/mls/active/modules/100/loadkeys/hll
/var/lib/selinux/mls/active/modules/100/loadkeys/lang_ext
/var/lib/selinux/mls/active/modules/100/locallogin
/var/lib/selinux/mls/active/modules/100/locallogin/cil
/var/lib/selinux/mls/active/modules/100/locallogin/hll
/var/lib/selinux/mls/active/modules/100/locallogin/lang_ext
/var/lib/selinux/mls/active/modules/100/lockdev
/var/lib/selinux/mls/active/modules/100/lockdev/cil
/var/lib/selinux/mls/active/modules/100/lockdev/hll
/var/lib/selinux/mls/active/modules/100/lockdev/lang_ext
/var/lib/selinux/mls/active/modules/100/logadm
/var/lib/selinux/mls/active/modules/100/logadm/cil
/var/lib/selinux/mls/active/modules/100/logadm/hll
/var/lib/selinux/mls/active/modules/100/logadm/lang_ext
/var/lib/selinux/mls/active/modules/100/logging
/var/lib/selinux/mls/active/modules/100/logging/cil
/var/lib/selinux/mls/active/modules/100/logging/hll
/var/lib/selinux/mls/active/modules/100/logging/lang_ext
/var/lib/selinux/mls/active/modules/100/logrotate
/var/lib/selinux/mls/active/modules/100/logrotate/cil
/var/lib/selinux/mls/active/modules/100/logrotate/hll
/var/lib/selinux/mls/active/modules/100/logrotate/lang_ext
/var/lib/selinux/mls/active/modules/100/logwatch
/var/lib/selinux/mls/active/modules/100/logwatch/cil
/var/lib/selinux/mls/active/modules/100/logwatch/hll
/var/lib/selinux/mls/active/modules/100/logwatch/lang_ext
/var/lib/selinux/mls/active/modules/100/lpd
/var/lib/selinux/mls/active/modules/100/lpd/cil
/var/lib/selinux/mls/active/modules/100/lpd/hll
/var/lib/selinux/mls/active/modules/100/lpd/lang_ext
/var/lib/selinux/mls/active/modules/100/lsm
/var/lib/selinux/mls/active/modules/100/lsm/cil
/var/lib/selinux/mls/active/modules/100/lsm/hll
/var/lib/selinux/mls/active/modules/100/lsm/lang_ext
/var/lib/selinux/mls/active/modules/100/lvm
/var/lib/selinux/mls/active/modules/100/lvm/cil
/var/lib/selinux/mls/active/modules/100/lvm/hll
/var/lib/selinux/mls/active/modules/100/lvm/lang_ext
/var/lib/selinux/mls/active/modules/100/mailman
/var/lib/selinux/mls/active/modules/100/mailman/cil
/var/lib/selinux/mls/active/modules/100/mailman/hll
/var/lib/selinux/mls/active/modules/100/mailman/lang_ext
/var/lib/selinux/mls/active/modules/100/mandb
/var/lib/selinux/mls/active/modules/100/mandb/cil
/var/lib/selinux/mls/active/modules/100/mandb/hll
/var/lib/selinux/mls/active/modules/100/mandb/lang_ext
/var/lib/selinux/mls/active/modules/100/mcelog
/var/lib/selinux/mls/active/modules/100/mcelog/cil
/var/lib/selinux/mls/active/modules/100/mcelog/hll
/var/lib/selinux/mls/active/modules/100/mcelog/lang_ext
/var/lib/selinux/mls/active/modules/100/memcached
/var/lib/selinux/mls/active/modules/100/memcached/cil
/var/lib/selinux/mls/active/modules/100/memcached/hll
/var/lib/selinux/mls/active/modules/100/memcached/lang_ext
/var/lib/selinux/mls/active/modules/100/milter
/var/lib/selinux/mls/active/modules/100/milter/cil
/var/lib/selinux/mls/active/modules/100/milter/hll
/var/lib/selinux/mls/active/modules/100/milter/lang_ext
/var/lib/selinux/mls/active/modules/100/miscfiles
/var/lib/selinux/mls/active/modules/100/miscfiles/cil
/var/lib/selinux/mls/active/modules/100/miscfiles/hll
/var/lib/selinux/mls/active/modules/100/miscfiles/lang_ext
/var/lib/selinux/mls/active/modules/100/modemmanager
/var/lib/selinux/mls/active/modules/100/modemmanager/cil
/var/lib/selinux/mls/active/modules/100/modemmanager/hll
/var/lib/selinux/mls/active/modules/100/modemmanager/lang_ext
/var/lib/selinux/mls/active/modules/100/modutils
/var/lib/selinux/mls/active/modules/100/modutils/cil
/var/lib/selinux/mls/active/modules/100/modutils/hll
/var/lib/selinux/mls/active/modules/100/modutils/lang_ext
/var/lib/selinux/mls/active/modules/100/mojomojo
/var/lib/selinux/mls/active/modules/100/mojomojo/cil
/var/lib/selinux/mls/active/modules/100/mojomojo/hll
/var/lib/selinux/mls/active/modules/100/mojomojo/lang_ext
/var/lib/selinux/mls/active/modules/100/mount
/var/lib/selinux/mls/active/modules/100/mount/cil
/var/lib/selinux/mls/active/modules/100/mount/hll
/var/lib/selinux/mls/active/modules/100/mount/lang_ext
/var/lib/selinux/mls/active/modules/100/mozilla
/var/lib/selinux/mls/active/modules/100/mozilla/cil
/var/lib/selinux/mls/active/modules/100/mozilla/hll
/var/lib/selinux/mls/active/modules/100/mozilla/lang_ext
/var/lib/selinux/mls/active/modules/100/mplayer
/var/lib/selinux/mls/active/modules/100/mplayer/cil
/var/lib/selinux/mls/active/modules/100/mplayer/hll
/var/lib/selinux/mls/active/modules/100/mplayer/lang_ext
/var/lib/selinux/mls/active/modules/100/mrtg
/var/lib/selinux/mls/active/modules/100/mrtg/cil
/var/lib/selinux/mls/active/modules/100/mrtg/hll
/var/lib/selinux/mls/active/modules/100/mrtg/lang_ext
/var/lib/selinux/mls/active/modules/100/mta
/var/lib/selinux/mls/active/modules/100/mta/cil
/var/lib/selinux/mls/active/modules/100/mta/hll
/var/lib/selinux/mls/active/modules/100/mta/lang_ext
/var/lib/selinux/mls/active/modules/100/munin
/var/lib/selinux/mls/active/modules/100/munin/cil
/var/lib/selinux/mls/active/modules/100/munin/hll
/var/lib/selinux/mls/active/modules/100/munin/lang_ext
/var/lib/selinux/mls/active/modules/100/mysql
/var/lib/selinux/mls/active/modules/100/mysql/cil
/var/lib/selinux/mls/active/modules/100/mysql/hll
/var/lib/selinux/mls/active/modules/100/mysql/lang_ext
/var/lib/selinux/mls/active/modules/100/nagios
/var/lib/selinux/mls/active/modules/100/nagios/cil
/var/lib/selinux/mls/active/modules/100/nagios/hll
/var/lib/selinux/mls/active/modules/100/nagios/lang_ext
/var/lib/selinux/mls/active/modules/100/namespace
/var/lib/selinux/mls/active/modules/100/namespace/cil
/var/lib/selinux/mls/active/modules/100/namespace/hll
/var/lib/selinux/mls/active/modules/100/namespace/lang_ext
/var/lib/selinux/mls/active/modules/100/ncftool
/var/lib/selinux/mls/active/modules/100/ncftool/cil
/var/lib/selinux/mls/active/modules/100/ncftool/hll
/var/lib/selinux/mls/active/modules/100/ncftool/lang_ext
/var/lib/selinux/mls/active/modules/100/netlabel
/var/lib/selinux/mls/active/modules/100/netlabel/cil
/var/lib/selinux/mls/active/modules/100/netlabel/hll
/var/lib/selinux/mls/active/modules/100/netlabel/lang_ext
/var/lib/selinux/mls/active/modules/100/netutils
/var/lib/selinux/mls/active/modules/100/netutils/cil
/var/lib/selinux/mls/active/modules/100/netutils/hll
/var/lib/selinux/mls/active/modules/100/netutils/lang_ext
/var/lib/selinux/mls/active/modules/100/networkmanager
/var/lib/selinux/mls/active/modules/100/networkmanager/cil
/var/lib/selinux/mls/active/modules/100/networkmanager/hll
/var/lib/selinux/mls/active/modules/100/networkmanager/lang_ext
/var/lib/selinux/mls/active/modules/100/nis
/var/lib/selinux/mls/active/modules/100/nis/cil
/var/lib/selinux/mls/active/modules/100/nis/hll
/var/lib/selinux/mls/active/modules/100/nis/lang_ext
/var/lib/selinux/mls/active/modules/100/nscd
/var/lib/selinux/mls/active/modules/100/nscd/cil
/var/lib/selinux/mls/active/modules/100/nscd/hll
/var/lib/selinux/mls/active/modules/100/nscd/lang_ext
/var/lib/selinux/mls/active/modules/100/nslcd
/var/lib/selinux/mls/active/modules/100/nslcd/cil
/var/lib/selinux/mls/active/modules/100/nslcd/hll
/var/lib/selinux/mls/active/modules/100/nslcd/lang_ext
/var/lib/selinux/mls/active/modules/100/ntop
/var/lib/selinux/mls/active/modules/100/ntop/cil
/var/lib/selinux/mls/active/modules/100/ntop/hll
/var/lib/selinux/mls/active/modules/100/ntop/lang_ext
/var/lib/selinux/mls/active/modules/100/ntp
/var/lib/selinux/mls/active/modules/100/ntp/cil
/var/lib/selinux/mls/active/modules/100/ntp/hll
/var/lib/selinux/mls/active/modules/100/ntp/lang_ext
/var/lib/selinux/mls/active/modules/100/nx
/var/lib/selinux/mls/active/modules/100/nx/cil
/var/lib/selinux/mls/active/modules/100/nx/hll
/var/lib/selinux/mls/active/modules/100/nx/lang_ext
/var/lib/selinux/mls/active/modules/100/oddjob
/var/lib/selinux/mls/active/modules/100/oddjob/cil
/var/lib/selinux/mls/active/modules/100/oddjob/hll
/var/lib/selinux/mls/active/modules/100/oddjob/lang_ext
/var/lib/selinux/mls/active/modules/100/openct
/var/lib/selinux/mls/active/modules/100/openct/cil
/var/lib/selinux/mls/active/modules/100/openct/hll
/var/lib/selinux/mls/active/modules/100/openct/lang_ext
/var/lib/selinux/mls/active/modules/100/openvpn
/var/lib/selinux/mls/active/modules/100/openvpn/cil
/var/lib/selinux/mls/active/modules/100/openvpn/hll
/var/lib/selinux/mls/active/modules/100/openvpn/lang_ext
/var/lib/selinux/mls/active/modules/100/openvswitch
/var/lib/selinux/mls/active/modules/100/openvswitch/cil
/var/lib/selinux/mls/active/modules/100/openvswitch/hll
/var/lib/selinux/mls/active/modules/100/openvswitch/lang_ext
/var/lib/selinux/mls/active/modules/100/pads
/var/lib/selinux/mls/active/modules/100/pads/cil
/var/lib/selinux/mls/active/modules/100/pads/hll
/var/lib/selinux/mls/active/modules/100/pads/lang_ext
/var/lib/selinux/mls/active/modules/100/pcmcia
/var/lib/selinux/mls/active/modules/100/pcmcia/cil
/var/lib/selinux/mls/active/modules/100/pcmcia/hll
/var/lib/selinux/mls/active/modules/100/pcmcia/lang_ext
/var/lib/selinux/mls/active/modules/100/pcscd
/var/lib/selinux/mls/active/modules/100/pcscd/cil
/var/lib/selinux/mls/active/modules/100/pcscd/hll
/var/lib/selinux/mls/active/modules/100/pcscd/lang_ext
/var/lib/selinux/mls/active/modules/100/pegasus
/var/lib/selinux/mls/active/modules/100/pegasus/cil
/var/lib/selinux/mls/active/modules/100/pegasus/hll
/var/lib/selinux/mls/active/modules/100/pegasus/lang_ext
/var/lib/selinux/mls/active/modules/100/pingd
/var/lib/selinux/mls/active/modules/100/pingd/cil
/var/lib/selinux/mls/active/modules/100/pingd/hll
/var/lib/selinux/mls/active/modules/100/pingd/lang_ext
/var/lib/selinux/mls/active/modules/100/piranha
/var/lib/selinux/mls/active/modules/100/piranha/cil
/var/lib/selinux/mls/active/modules/100/piranha/hll
/var/lib/selinux/mls/active/modules/100/piranha/lang_ext
/var/lib/selinux/mls/active/modules/100/plymouthd
/var/lib/selinux/mls/active/modules/100/plymouthd/cil
/var/lib/selinux/mls/active/modules/100/plymouthd/hll
/var/lib/selinux/mls/active/modules/100/plymouthd/lang_ext
/var/lib/selinux/mls/active/modules/100/podsleuth
/var/lib/selinux/mls/active/modules/100/podsleuth/cil
/var/lib/selinux/mls/active/modules/100/podsleuth/hll
/var/lib/selinux/mls/active/modules/100/podsleuth/lang_ext
/var/lib/selinux/mls/active/modules/100/policykit
/var/lib/selinux/mls/active/modules/100/policykit/cil
/var/lib/selinux/mls/active/modules/100/policykit/hll
/var/lib/selinux/mls/active/modules/100/policykit/lang_ext
/var/lib/selinux/mls/active/modules/100/polipo
/var/lib/selinux/mls/active/modules/100/polipo/cil
/var/lib/selinux/mls/active/modules/100/polipo/hll
/var/lib/selinux/mls/active/modules/100/polipo/lang_ext
/var/lib/selinux/mls/active/modules/100/portmap
/var/lib/selinux/mls/active/modules/100/portmap/cil
/var/lib/selinux/mls/active/modules/100/portmap/hll
/var/lib/selinux/mls/active/modules/100/portmap/lang_ext
/var/lib/selinux/mls/active/modules/100/portreserve
/var/lib/selinux/mls/active/modules/100/portreserve/cil
/var/lib/selinux/mls/active/modules/100/portreserve/hll
/var/lib/selinux/mls/active/modules/100/portreserve/lang_ext
/var/lib/selinux/mls/active/modules/100/postfix
/var/lib/selinux/mls/active/modules/100/postfix/cil
/var/lib/selinux/mls/active/modules/100/postfix/hll
/var/lib/selinux/mls/active/modules/100/postfix/lang_ext
/var/lib/selinux/mls/active/modules/100/postgresql
/var/lib/selinux/mls/active/modules/100/postgresql/cil
/var/lib/selinux/mls/active/modules/100/postgresql/hll
/var/lib/selinux/mls/active/modules/100/postgresql/lang_ext
/var/lib/selinux/mls/active/modules/100/postgrey
/var/lib/selinux/mls/active/modules/100/postgrey/cil
/var/lib/selinux/mls/active/modules/100/postgrey/hll
/var/lib/selinux/mls/active/modules/100/postgrey/lang_ext
/var/lib/selinux/mls/active/modules/100/ppp
/var/lib/selinux/mls/active/modules/100/ppp/cil
/var/lib/selinux/mls/active/modules/100/ppp/hll
/var/lib/selinux/mls/active/modules/100/ppp/lang_ext
/var/lib/selinux/mls/active/modules/100/prelink
/var/lib/selinux/mls/active/modules/100/prelink/cil
/var/lib/selinux/mls/active/modules/100/prelink/hll
/var/lib/selinux/mls/active/modules/100/prelink/lang_ext
/var/lib/selinux/mls/active/modules/100/prelude
/var/lib/selinux/mls/active/modules/100/prelude/cil
/var/lib/selinux/mls/active/modules/100/prelude/hll
/var/lib/selinux/mls/active/modules/100/prelude/lang_ext
/var/lib/selinux/mls/active/modules/100/privoxy
/var/lib/selinux/mls/active/modules/100/privoxy/cil
/var/lib/selinux/mls/active/modules/100/privoxy/hll
/var/lib/selinux/mls/active/modules/100/privoxy/lang_ext
/var/lib/selinux/mls/active/modules/100/procmail
/var/lib/selinux/mls/active/modules/100/procmail/cil
/var/lib/selinux/mls/active/modules/100/procmail/hll
/var/lib/selinux/mls/active/modules/100/procmail/lang_ext
/var/lib/selinux/mls/active/modules/100/prosody
/var/lib/selinux/mls/active/modules/100/prosody/cil
/var/lib/selinux/mls/active/modules/100/prosody/hll
/var/lib/selinux/mls/active/modules/100/prosody/lang_ext
/var/lib/selinux/mls/active/modules/100/psad
/var/lib/selinux/mls/active/modules/100/psad/cil
/var/lib/selinux/mls/active/modules/100/psad/hll
/var/lib/selinux/mls/active/modules/100/psad/lang_ext
/var/lib/selinux/mls/active/modules/100/ptchown
/var/lib/selinux/mls/active/modules/100/ptchown/cil
/var/lib/selinux/mls/active/modules/100/ptchown/hll
/var/lib/selinux/mls/active/modules/100/ptchown/lang_ext
/var/lib/selinux/mls/active/modules/100/publicfile
/var/lib/selinux/mls/active/modules/100/publicfile/cil
/var/lib/selinux/mls/active/modules/100/publicfile/hll
/var/lib/selinux/mls/active/modules/100/publicfile/lang_ext
/var/lib/selinux/mls/active/modules/100/pulseaudio
/var/lib/selinux/mls/active/modules/100/pulseaudio/cil
/var/lib/selinux/mls/active/modules/100/pulseaudio/hll
/var/lib/selinux/mls/active/modules/100/pulseaudio/lang_ext
/var/lib/selinux/mls/active/modules/100/qmail
/var/lib/selinux/mls/active/modules/100/qmail/cil
/var/lib/selinux/mls/active/modules/100/qmail/hll
/var/lib/selinux/mls/active/modules/100/qmail/lang_ext
/var/lib/selinux/mls/active/modules/100/qpid
/var/lib/selinux/mls/active/modules/100/qpid/cil
/var/lib/selinux/mls/active/modules/100/qpid/hll
/var/lib/selinux/mls/active/modules/100/qpid/lang_ext
/var/lib/selinux/mls/active/modules/100/quota
/var/lib/selinux/mls/active/modules/100/quota/cil
/var/lib/selinux/mls/active/modules/100/quota/hll
/var/lib/selinux/mls/active/modules/100/quota/lang_ext
/var/lib/selinux/mls/active/modules/100/radius
/var/lib/selinux/mls/active/modules/100/radius/cil
/var/lib/selinux/mls/active/modules/100/radius/hll
/var/lib/selinux/mls/active/modules/100/radius/lang_ext
/var/lib/selinux/mls/active/modules/100/radvd
/var/lib/selinux/mls/active/modules/100/radvd/cil
/var/lib/selinux/mls/active/modules/100/radvd/hll
/var/lib/selinux/mls/active/modules/100/radvd/lang_ext
/var/lib/selinux/mls/active/modules/100/raid
/var/lib/selinux/mls/active/modules/100/raid/cil
/var/lib/selinux/mls/active/modules/100/raid/hll
/var/lib/selinux/mls/active/modules/100/raid/lang_ext
/var/lib/selinux/mls/active/modules/100/rdisc
/var/lib/selinux/mls/active/modules/100/rdisc/cil
/var/lib/selinux/mls/active/modules/100/rdisc/hll
/var/lib/selinux/mls/active/modules/100/rdisc/lang_ext
/var/lib/selinux/mls/active/modules/100/readahead
/var/lib/selinux/mls/active/modules/100/readahead/cil
/var/lib/selinux/mls/active/modules/100/readahead/hll
/var/lib/selinux/mls/active/modules/100/readahead/lang_ext
/var/lib/selinux/mls/active/modules/100/remotelogin
/var/lib/selinux/mls/active/modules/100/remotelogin/cil
/var/lib/selinux/mls/active/modules/100/remotelogin/hll
/var/lib/selinux/mls/active/modules/100/remotelogin/lang_ext
/var/lib/selinux/mls/active/modules/100/rhcs
/var/lib/selinux/mls/active/modules/100/rhcs/cil
/var/lib/selinux/mls/active/modules/100/rhcs/hll
/var/lib/selinux/mls/active/modules/100/rhcs/lang_ext
/var/lib/selinux/mls/active/modules/100/rhgb
/var/lib/selinux/mls/active/modules/100/rhgb/cil
/var/lib/selinux/mls/active/modules/100/rhgb/hll
/var/lib/selinux/mls/active/modules/100/rhgb/lang_ext
/var/lib/selinux/mls/active/modules/100/ricci
/var/lib/selinux/mls/active/modules/100/ricci/cil
/var/lib/selinux/mls/active/modules/100/ricci/hll
/var/lib/selinux/mls/active/modules/100/ricci/lang_ext
/var/lib/selinux/mls/active/modules/100/rlogin
/var/lib/selinux/mls/active/modules/100/rlogin/cil
/var/lib/selinux/mls/active/modules/100/rlogin/hll
/var/lib/selinux/mls/active/modules/100/rlogin/lang_ext
/var/lib/selinux/mls/active/modules/100/roundup
/var/lib/selinux/mls/active/modules/100/roundup/cil
/var/lib/selinux/mls/active/modules/100/roundup/hll
/var/lib/selinux/mls/active/modules/100/roundup/lang_ext
/var/lib/selinux/mls/active/modules/100/rpc
/var/lib/selinux/mls/active/modules/100/rpc/cil
/var/lib/selinux/mls/active/modules/100/rpc/hll
/var/lib/selinux/mls/active/modules/100/rpc/lang_ext
/var/lib/selinux/mls/active/modules/100/rpcbind
/var/lib/selinux/mls/active/modules/100/rpcbind/cil
/var/lib/selinux/mls/active/modules/100/rpcbind/hll
/var/lib/selinux/mls/active/modules/100/rpcbind/lang_ext
/var/lib/selinux/mls/active/modules/100/rpm
/var/lib/selinux/mls/active/modules/100/rpm/cil
/var/lib/selinux/mls/active/modules/100/rpm/hll
/var/lib/selinux/mls/active/modules/100/rpm/lang_ext
/var/lib/selinux/mls/active/modules/100/rshd
/var/lib/selinux/mls/active/modules/100/rshd/cil
/var/lib/selinux/mls/active/modules/100/rshd/hll
/var/lib/selinux/mls/active/modules/100/rshd/lang_ext
/var/lib/selinux/mls/active/modules/100/rsync
/var/lib/selinux/mls/active/modules/100/rsync/cil
/var/lib/selinux/mls/active/modules/100/rsync/hll
/var/lib/selinux/mls/active/modules/100/rsync/lang_ext
/var/lib/selinux/mls/active/modules/100/rtkit
/var/lib/selinux/mls/active/modules/100/rtkit/cil
/var/lib/selinux/mls/active/modules/100/rtkit/hll
/var/lib/selinux/mls/active/modules/100/rtkit/lang_ext
/var/lib/selinux/mls/active/modules/100/rwho
/var/lib/selinux/mls/active/modules/100/rwho/cil
/var/lib/selinux/mls/active/modules/100/rwho/hll
/var/lib/selinux/mls/active/modules/100/rwho/lang_ext
/var/lib/selinux/mls/active/modules/100/samba
/var/lib/selinux/mls/active/modules/100/samba/cil
/var/lib/selinux/mls/active/modules/100/samba/hll
/var/lib/selinux/mls/active/modules/100/samba/lang_ext
/var/lib/selinux/mls/active/modules/100/sambagui
/var/lib/selinux/mls/active/modules/100/sambagui/cil
/var/lib/selinux/mls/active/modules/100/sambagui/hll
/var/lib/selinux/mls/active/modules/100/sambagui/lang_ext
/var/lib/selinux/mls/active/modules/100/sasl
/var/lib/selinux/mls/active/modules/100/sasl/cil
/var/lib/selinux/mls/active/modules/100/sasl/hll
/var/lib/selinux/mls/active/modules/100/sasl/lang_ext
/var/lib/selinux/mls/active/modules/100/screen
/var/lib/selinux/mls/active/modules/100/screen/cil
/var/lib/selinux/mls/active/modules/100/screen/hll
/var/lib/selinux/mls/active/modules/100/screen/lang_ext
/var/lib/selinux/mls/active/modules/100/secadm
/var/lib/selinux/mls/active/modules/100/secadm/cil
/var/lib/selinux/mls/active/modules/100/secadm/hll
/var/lib/selinux/mls/active/modules/100/secadm/lang_ext
/var/lib/selinux/mls/active/modules/100/selinuxutil
/var/lib/selinux/mls/active/modules/100/selinuxutil/cil
/var/lib/selinux/mls/active/modules/100/selinuxutil/hll
/var/lib/selinux/mls/active/modules/100/selinuxutil/lang_ext
/var/lib/selinux/mls/active/modules/100/sendmail
/var/lib/selinux/mls/active/modules/100/sendmail/cil
/var/lib/selinux/mls/active/modules/100/sendmail/hll
/var/lib/selinux/mls/active/modules/100/sendmail/lang_ext
/var/lib/selinux/mls/active/modules/100/setrans
/var/lib/selinux/mls/active/modules/100/setrans/cil
/var/lib/selinux/mls/active/modules/100/setrans/hll
/var/lib/selinux/mls/active/modules/100/setrans/lang_ext
/var/lib/selinux/mls/active/modules/100/setroubleshoot
/var/lib/selinux/mls/active/modules/100/setroubleshoot/cil
/var/lib/selinux/mls/active/modules/100/setroubleshoot/hll
/var/lib/selinux/mls/active/modules/100/setroubleshoot/lang_ext
/var/lib/selinux/mls/active/modules/100/seunshare
/var/lib/selinux/mls/active/modules/100/seunshare/cil
/var/lib/selinux/mls/active/modules/100/seunshare/hll
/var/lib/selinux/mls/active/modules/100/seunshare/lang_ext
/var/lib/selinux/mls/active/modules/100/shorewall
/var/lib/selinux/mls/active/modules/100/shorewall/cil
/var/lib/selinux/mls/active/modules/100/shorewall/hll
/var/lib/selinux/mls/active/modules/100/shorewall/lang_ext
/var/lib/selinux/mls/active/modules/100/slocate
/var/lib/selinux/mls/active/modules/100/slocate/cil
/var/lib/selinux/mls/active/modules/100/slocate/hll
/var/lib/selinux/mls/active/modules/100/slocate/lang_ext
/var/lib/selinux/mls/active/modules/100/smartmon
/var/lib/selinux/mls/active/modules/100/smartmon/cil
/var/lib/selinux/mls/active/modules/100/smartmon/hll
/var/lib/selinux/mls/active/modules/100/smartmon/lang_ext
/var/lib/selinux/mls/active/modules/100/snmp
/var/lib/selinux/mls/active/modules/100/snmp/cil
/var/lib/selinux/mls/active/modules/100/snmp/hll
/var/lib/selinux/mls/active/modules/100/snmp/lang_ext
/var/lib/selinux/mls/active/modules/100/snort
/var/lib/selinux/mls/active/modules/100/snort/cil
/var/lib/selinux/mls/active/modules/100/snort/hll
/var/lib/selinux/mls/active/modules/100/snort/lang_ext
/var/lib/selinux/mls/active/modules/100/sosreport
/var/lib/selinux/mls/active/modules/100/sosreport/cil
/var/lib/selinux/mls/active/modules/100/sosreport/hll
/var/lib/selinux/mls/active/modules/100/sosreport/lang_ext
/var/lib/selinux/mls/active/modules/100/soundserver
/var/lib/selinux/mls/active/modules/100/soundserver/cil
/var/lib/selinux/mls/active/modules/100/soundserver/hll
/var/lib/selinux/mls/active/modules/100/soundserver/lang_ext
/var/lib/selinux/mls/active/modules/100/spamassassin
/var/lib/selinux/mls/active/modules/100/spamassassin/cil
/var/lib/selinux/mls/active/modules/100/spamassassin/hll
/var/lib/selinux/mls/active/modules/100/spamassassin/lang_ext
/var/lib/selinux/mls/active/modules/100/squid
/var/lib/selinux/mls/active/modules/100/squid/cil
/var/lib/selinux/mls/active/modules/100/squid/hll
/var/lib/selinux/mls/active/modules/100/squid/lang_ext
/var/lib/selinux/mls/active/modules/100/ssh
/var/lib/selinux/mls/active/modules/100/ssh/cil
/var/lib/selinux/mls/active/modules/100/ssh/hll
/var/lib/selinux/mls/active/modules/100/ssh/lang_ext
/var/lib/selinux/mls/active/modules/100/sssd
/var/lib/selinux/mls/active/modules/100/sssd/cil
/var/lib/selinux/mls/active/modules/100/sssd/hll
/var/lib/selinux/mls/active/modules/100/sssd/lang_ext
/var/lib/selinux/mls/active/modules/100/staff
/var/lib/selinux/mls/active/modules/100/staff/cil
/var/lib/selinux/mls/active/modules/100/staff/hll
/var/lib/selinux/mls/active/modules/100/staff/lang_ext
/var/lib/selinux/mls/active/modules/100/stunnel
/var/lib/selinux/mls/active/modules/100/stunnel/cil
/var/lib/selinux/mls/active/modules/100/stunnel/hll
/var/lib/selinux/mls/active/modules/100/stunnel/lang_ext
/var/lib/selinux/mls/active/modules/100/su
/var/lib/selinux/mls/active/modules/100/su/cil
/var/lib/selinux/mls/active/modules/100/su/hll
/var/lib/selinux/mls/active/modules/100/su/lang_ext
/var/lib/selinux/mls/active/modules/100/sudo
/var/lib/selinux/mls/active/modules/100/sudo/cil
/var/lib/selinux/mls/active/modules/100/sudo/hll
/var/lib/selinux/mls/active/modules/100/sudo/lang_ext
/var/lib/selinux/mls/active/modules/100/sysadm
/var/lib/selinux/mls/active/modules/100/sysadm/cil
/var/lib/selinux/mls/active/modules/100/sysadm/hll
/var/lib/selinux/mls/active/modules/100/sysadm/lang_ext
/var/lib/selinux/mls/active/modules/100/sysadm_secadm
/var/lib/selinux/mls/active/modules/100/sysadm_secadm/cil
/var/lib/selinux/mls/active/modules/100/sysadm_secadm/hll
/var/lib/selinux/mls/active/modules/100/sysadm_secadm/lang_ext
/var/lib/selinux/mls/active/modules/100/sysnetwork
/var/lib/selinux/mls/active/modules/100/sysnetwork/cil
/var/lib/selinux/mls/active/modules/100/sysnetwork/hll
/var/lib/selinux/mls/active/modules/100/sysnetwork/lang_ext
/var/lib/selinux/mls/active/modules/100/sysstat
/var/lib/selinux/mls/active/modules/100/sysstat/cil
/var/lib/selinux/mls/active/modules/100/sysstat/hll
/var/lib/selinux/mls/active/modules/100/sysstat/lang_ext
/var/lib/selinux/mls/active/modules/100/systemd
/var/lib/selinux/mls/active/modules/100/systemd/cil
/var/lib/selinux/mls/active/modules/100/systemd/hll
/var/lib/selinux/mls/active/modules/100/systemd/lang_ext
/var/lib/selinux/mls/active/modules/100/tcpd
/var/lib/selinux/mls/active/modules/100/tcpd/cil
/var/lib/selinux/mls/active/modules/100/tcpd/hll
/var/lib/selinux/mls/active/modules/100/tcpd/lang_ext
/var/lib/selinux/mls/active/modules/100/tcsd
/var/lib/selinux/mls/active/modules/100/tcsd/cil
/var/lib/selinux/mls/active/modules/100/tcsd/hll
/var/lib/selinux/mls/active/modules/100/tcsd/lang_ext
/var/lib/selinux/mls/active/modules/100/telepathy
/var/lib/selinux/mls/active/modules/100/telepathy/cil
/var/lib/selinux/mls/active/modules/100/telepathy/hll
/var/lib/selinux/mls/active/modules/100/telepathy/lang_ext
/var/lib/selinux/mls/active/modules/100/telnet
/var/lib/selinux/mls/active/modules/100/telnet/cil
/var/lib/selinux/mls/active/modules/100/telnet/hll
/var/lib/selinux/mls/active/modules/100/telnet/lang_ext
/var/lib/selinux/mls/active/modules/100/tftp
/var/lib/selinux/mls/active/modules/100/tftp/cil
/var/lib/selinux/mls/active/modules/100/tftp/hll
/var/lib/selinux/mls/active/modules/100/tftp/lang_ext
/var/lib/selinux/mls/active/modules/100/tgtd
/var/lib/selinux/mls/active/modules/100/tgtd/cil
/var/lib/selinux/mls/active/modules/100/tgtd/hll
/var/lib/selinux/mls/active/modules/100/tgtd/lang_ext
/var/lib/selinux/mls/active/modules/100/thumb
/var/lib/selinux/mls/active/modules/100/thumb/cil
/var/lib/selinux/mls/active/modules/100/thumb/hll
/var/lib/selinux/mls/active/modules/100/thumb/lang_ext
/var/lib/selinux/mls/active/modules/100/tmpreaper
/var/lib/selinux/mls/active/modules/100/tmpreaper/cil
/var/lib/selinux/mls/active/modules/100/tmpreaper/hll
/var/lib/selinux/mls/active/modules/100/tmpreaper/lang_ext
/var/lib/selinux/mls/active/modules/100/tor
/var/lib/selinux/mls/active/modules/100/tor/cil
/var/lib/selinux/mls/active/modules/100/tor/hll
/var/lib/selinux/mls/active/modules/100/tor/lang_ext
/var/lib/selinux/mls/active/modules/100/tuned
/var/lib/selinux/mls/active/modules/100/tuned/cil
/var/lib/selinux/mls/active/modules/100/tuned/hll
/var/lib/selinux/mls/active/modules/100/tuned/lang_ext
/var/lib/selinux/mls/active/modules/100/tvtime
/var/lib/selinux/mls/active/modules/100/tvtime/cil
/var/lib/selinux/mls/active/modules/100/tvtime/hll
/var/lib/selinux/mls/active/modules/100/tvtime/lang_ext
/var/lib/selinux/mls/active/modules/100/udev
/var/lib/selinux/mls/active/modules/100/udev/cil
/var/lib/selinux/mls/active/modules/100/udev/hll
/var/lib/selinux/mls/active/modules/100/udev/lang_ext
/var/lib/selinux/mls/active/modules/100/ulogd
/var/lib/selinux/mls/active/modules/100/ulogd/cil
/var/lib/selinux/mls/active/modules/100/ulogd/hll
/var/lib/selinux/mls/active/modules/100/ulogd/lang_ext
/var/lib/selinux/mls/active/modules/100/uml
/var/lib/selinux/mls/active/modules/100/uml/cil
/var/lib/selinux/mls/active/modules/100/uml/hll
/var/lib/selinux/mls/active/modules/100/uml/lang_ext
/var/lib/selinux/mls/active/modules/100/unlabelednet
/var/lib/selinux/mls/active/modules/100/unlabelednet/cil
/var/lib/selinux/mls/active/modules/100/unlabelednet/hll
/var/lib/selinux/mls/active/modules/100/unlabelednet/lang_ext
/var/lib/selinux/mls/active/modules/100/unprivuser
/var/lib/selinux/mls/active/modules/100/unprivuser/cil
/var/lib/selinux/mls/active/modules/100/unprivuser/hll
/var/lib/selinux/mls/active/modules/100/unprivuser/lang_ext
/var/lib/selinux/mls/active/modules/100/updfstab
/var/lib/selinux/mls/active/modules/100/updfstab/cil
/var/lib/selinux/mls/active/modules/100/updfstab/hll
/var/lib/selinux/mls/active/modules/100/updfstab/lang_ext
/var/lib/selinux/mls/active/modules/100/usbmodules
/var/lib/selinux/mls/active/modules/100/usbmodules/cil
/var/lib/selinux/mls/active/modules/100/usbmodules/hll
/var/lib/selinux/mls/active/modules/100/usbmodules/lang_ext
/var/lib/selinux/mls/active/modules/100/userdomain
/var/lib/selinux/mls/active/modules/100/userdomain/cil
/var/lib/selinux/mls/active/modules/100/userdomain/hll
/var/lib/selinux/mls/active/modules/100/userdomain/lang_ext
/var/lib/selinux/mls/active/modules/100/userhelper
/var/lib/selinux/mls/active/modules/100/userhelper/cil
/var/lib/selinux/mls/active/modules/100/userhelper/hll
/var/lib/selinux/mls/active/modules/100/userhelper/lang_ext
/var/lib/selinux/mls/active/modules/100/usermanage
/var/lib/selinux/mls/active/modules/100/usermanage/cil
/var/lib/selinux/mls/active/modules/100/usermanage/hll
/var/lib/selinux/mls/active/modules/100/usermanage/lang_ext
/var/lib/selinux/mls/active/modules/100/usernetctl
/var/lib/selinux/mls/active/modules/100/usernetctl/cil
/var/lib/selinux/mls/active/modules/100/usernetctl/hll
/var/lib/selinux/mls/active/modules/100/usernetctl/lang_ext
/var/lib/selinux/mls/active/modules/100/uucp
/var/lib/selinux/mls/active/modules/100/uucp/cil
/var/lib/selinux/mls/active/modules/100/uucp/hll
/var/lib/selinux/mls/active/modules/100/uucp/lang_ext
/var/lib/selinux/mls/active/modules/100/virt
/var/lib/selinux/mls/active/modules/100/virt/cil
/var/lib/selinux/mls/active/modules/100/virt/hll
/var/lib/selinux/mls/active/modules/100/virt/lang_ext
/var/lib/selinux/mls/active/modules/100/vmware
/var/lib/selinux/mls/active/modules/100/vmware/cil
/var/lib/selinux/mls/active/modules/100/vmware/hll
/var/lib/selinux/mls/active/modules/100/vmware/lang_ext
/var/lib/selinux/mls/active/modules/100/vpn
/var/lib/selinux/mls/active/modules/100/vpn/cil
/var/lib/selinux/mls/active/modules/100/vpn/hll
/var/lib/selinux/mls/active/modules/100/vpn/lang_ext
/var/lib/selinux/mls/active/modules/100/w3c
/var/lib/selinux/mls/active/modules/100/w3c/cil
/var/lib/selinux/mls/active/modules/100/w3c/hll
/var/lib/selinux/mls/active/modules/100/w3c/lang_ext
/var/lib/selinux/mls/active/modules/100/webadm
/var/lib/selinux/mls/active/modules/100/webadm/cil
/var/lib/selinux/mls/active/modules/100/webadm/hll
/var/lib/selinux/mls/active/modules/100/webadm/lang_ext
/var/lib/selinux/mls/active/modules/100/webalizer
/var/lib/selinux/mls/active/modules/100/webalizer/cil
/var/lib/selinux/mls/active/modules/100/webalizer/hll
/var/lib/selinux/mls/active/modules/100/webalizer/lang_ext
/var/lib/selinux/mls/active/modules/100/wine
/var/lib/selinux/mls/active/modules/100/wine/cil
/var/lib/selinux/mls/active/modules/100/wine/hll
/var/lib/selinux/mls/active/modules/100/wine/lang_ext
/var/lib/selinux/mls/active/modules/100/wireshark
/var/lib/selinux/mls/active/modules/100/wireshark/cil
/var/lib/selinux/mls/active/modules/100/wireshark/hll
/var/lib/selinux/mls/active/modules/100/wireshark/lang_ext
/var/lib/selinux/mls/active/modules/100/wm
/var/lib/selinux/mls/active/modules/100/wm/cil
/var/lib/selinux/mls/active/modules/100/wm/hll
/var/lib/selinux/mls/active/modules/100/wm/lang_ext
/var/lib/selinux/mls/active/modules/100/xen
/var/lib/selinux/mls/active/modules/100/xen/cil
/var/lib/selinux/mls/active/modules/100/xen/hll
/var/lib/selinux/mls/active/modules/100/xen/lang_ext
/var/lib/selinux/mls/active/modules/100/xguest
/var/lib/selinux/mls/active/modules/100/xguest/cil
/var/lib/selinux/mls/active/modules/100/xguest/hll
/var/lib/selinux/mls/active/modules/100/xguest/lang_ext
/var/lib/selinux/mls/active/modules/100/xserver
/var/lib/selinux/mls/active/modules/100/xserver/cil
/var/lib/selinux/mls/active/modules/100/xserver/hll
/var/lib/selinux/mls/active/modules/100/xserver/lang_ext
/var/lib/selinux/mls/active/modules/100/zabbix
/var/lib/selinux/mls/active/modules/100/zabbix/cil
/var/lib/selinux/mls/active/modules/100/zabbix/hll
/var/lib/selinux/mls/active/modules/100/zabbix/lang_ext
/var/lib/selinux/mls/active/modules/100/zebra
/var/lib/selinux/mls/active/modules/100/zebra/cil
/var/lib/selinux/mls/active/modules/100/zebra/hll
/var/lib/selinux/mls/active/modules/100/zebra/lang_ext
/var/lib/selinux/mls/active/modules/100/zosremote
/var/lib/selinux/mls/active/modules/100/zosremote/cil
/var/lib/selinux/mls/active/modules/100/zosremote/hll
/var/lib/selinux/mls/active/modules/100/zosremote/lang_ext
/var/lib/selinux/mls/active/modules/400/extra_varrun
/var/lib/selinux/mls/active/modules_checksum
/var/lib/selinux/mls/active/policy.kern
/var/lib/selinux/mls/active/policy.linked
/var/lib/selinux/mls/active/seusers
/var/lib/selinux/mls/active/seusers.linked
/var/lib/selinux/mls/active/users_extra
/var/lib/selinux/mls/active/users_extra.linked
/var/lib/selinux/mls/semanage.read.LOCK
/var/lib/selinux/mls/semanage.trans.LOCK


Generated by rpm2html 1.8.1

Fabrice Bellet, Sun Apr 14 23:56:26 2024