]> git.ipfire.org Git - people/stevee/selinux-policy.git/commitdiff
Fix JIT usage for freshclam.
authorChris PeBenito <cpebenito@tresys.com>
Tue, 13 Jul 2010 12:39:54 +0000 (08:39 -0400)
committerChris PeBenito <cpebenito@tresys.com>
Tue, 13 Jul 2010 12:39:54 +0000 (08:39 -0400)
http://marc.info/?l=selinux&m=127893898208934&w=2

Changelog
policy/modules/services/clamav.te

index 34cf320c022ce56f653ed9e8da7b76cd6040b832..7f59676773e39ee0c29a157787b4ef245c7234d2 100644 (file)
--- a/Changelog
+++ b/Changelog
@@ -1,3 +1,4 @@
+- Add JIT usage for freshclam.
 - Remove ethereal module since the application was renamed to wireshark.
 - Remove duplicate/redundant rules, from Russell Coker.
 - Increased default number of categories to 1024, from Russell Coker.
index 33621bbdffa3f0e4e0f426a9f599f01a3857fabb..8c36027740cbd31ceac802c85402a636e9ec5341 100644 (file)
@@ -1,4 +1,4 @@
-policy_module(clamav, 1.8.0)
+policy_module(clamav, 1.8.1)
 
 ## <desc>
 ## <p>
@@ -145,6 +145,12 @@ optional_policy(`
        exim_read_spool_files(clamd_t)
 ')
 
+tunable_policy(`clamd_use_jit',`
+       allow clamd_t self:process execmem;
+', `
+       dontaudit clamd_t self:process execmem;
+')
+
 ########################################
 #
 # Freshclam local policy
@@ -205,6 +211,12 @@ optional_policy(`
        cron_system_entry(freshclam_t, freshclam_exec_t)
 ')
 
+tunable_policy(`clamd_use_jit',`
+       allow freshclam_t self:process execmem;
+', `
+       dontaudit freshclam_t self:process execmem;
+')
+
 ########################################
 #
 # clamscam local policy
@@ -254,12 +266,6 @@ clamav_stream_connect(clamscan_t)
 
 mta_send_mail(clamscan_t)
 
-tunable_policy(`clamd_use_jit',`
-       allow clamd_t self:process execmem;
-', `
-       dontaudit clamd_t self:process execmem;
-')
-
 optional_policy(`
        amavis_read_spool_files(clamscan_t)
 ')