mls constraints changed by evaluator consoletype/hostname need to ignore open fds from xen. Xen leaks them and uses them to communicate. Maybe someday they will fix this. firstboot needs to dbus chat with hal apt runs as rpm on Red Hat platforms userad d and groupadd need to transition to nscd mozilla fixes for strict policy qemu-ifup should be bin_t xfs now supports xattrs Added new access to kernel:key xen wants to getattr on devpts filesystem Fixes for amavis Apache should not ignore access to sysadm home dirs avahi needs access to certs for encryption bluetooth running on ypbind systems Fixes for crontab in strict/mls policies Fixes for newversion of cupsd that is SELinux aware user dbus needs to talk to hal in strict policy ldap has a socket ntp needs net_bind_service Fixes for postfix Samba needs to be able to create a log directory setroubleshoot has been cleaned up to be one process. spam wants to read postfix config squid needs to be able to setrlimit, and sys_resource xserver in strict policy needs additional privs libavutil changed its name login programs need self:key {search write }. Should this be moved to auth_pgm? Audit is being changed to use a socket. Avahi has its own localtime mount wants to check if selinux in enforcing mode semanage_t needs to be able to read files created by secadm_t uncofined_execmem_t needs to be chating We need to coordinat the changes to userdomain.