]> git.ipfire.org Git - people/stevee/selinux-policy.git/commitdiff
Turn on allow_postfix_local_write_mail_spool
authorMiroslav Grepl <mgrepl@redhat.com>
Thu, 18 Nov 2010 15:37:42 +0000 (16:37 +0100)
committerMiroslav Grepl <mgrepl@redhat.com>
Thu, 18 Nov 2010 15:37:42 +0000 (16:37 +0100)
policy/modules/services/abrt.te
policy/modules/services/dirsrv-admin.te
policy/modules/services/lircd.if
policy/modules/services/postfix.te

index 21950f3a5f61f4065e23bb0fee5aa1bb4004631b..5fdea83bd4a1e3e82756b0685147f78b93f15792 100644 (file)
@@ -67,6 +67,7 @@ allow abrt_t self:unix_dgram_socket create_socket_perms;
 allow abrt_t self:netlink_route_socket r_netlink_socket_perms;
 
 # abrt etc files
+list_dirs_pattern(abrt_t, abrt_etc_t, abrt_etc_t)
 rw_files_pattern(abrt_t, abrt_etc_t, abrt_etc_t)
 
 # log file
index a7eee5f4e710544b8e4853d4d1e400c02cee1e42..c88f61160553b8713e6600d2637f8ef95fc4085c 100644 (file)
@@ -36,6 +36,8 @@ corecmd_shell_entry_type(dirsrvadmin_t)
 
 files_exec_etc_files(dirsrvadmin_t)
 
+libs_exec_ld_so(dirsrvadmin_t)
+
 logging_search_logs(dirsrvadmin_t)
 
 miscfiles_read_localization(dirsrvadmin_t)
index 056d48104d9281f220a74d6d9bd729f3fc621b93..b9a332759d8e1766d48b2084e3649a3a0c4653f5 100644 (file)
@@ -57,7 +57,7 @@ interface(`lircd_stream_connect',`
 #
 interface(`lircd_admin',`
        gen_require(`
-               type lircd_t, lircd_var_run_t, lircd_etc_t;
+               type lircd_t, lircd_var_run_t;
                type lircd_initrc_exec_t;
        ')
 
@@ -69,9 +69,6 @@ interface(`lircd_admin',`
        role_transition $2 lircd_initrc_exec_t system_r;
        allow $2 system_r;
 
-       files_list_etc($1)
-       admin_pattern($1, lircd_etc_t)
-
        files_list_pids($1)
        admin_pattern($1, lircd_var_run_t)
 ')
index 628fcdaaaa8d256ba4a1bdd75e4385a4d75cfc4c..cffba217f484014f3e74281376a06e55246ef6a3 100644 (file)
@@ -10,7 +10,7 @@ policy_module(postfix, 1.12.0)
 ##     Allow postfix_local domain full write access to mail_spool directories
 ##     </p>
 ## </desc>
-gen_tunable(allow_postfix_local_write_mail_spool, false)
+gen_tunable(allow_postfix_local_write_mail_spool, true)
 
 attribute postfix_spool_type;
 attribute postfix_user_domains;