Research Menu

.
Skip Search Box

SELinux Mailing List

Re: [patch] tighten fetchmail policy

From: James Carter <jwcart2_at_epoch.ncsc.mil>
Date: Fri, 01 Apr 2005 15:34:36 -0500


Merged, except for this little bit.
Better to use r_file_perms and allow the lock permission, unless there is a good reason not to allow lock.

On Tue, 2005-03-29 at 19:46 -0600, Greg Norris wrote:
>
> # file access
> -allow fetchmail_t etc_t:file r_file_perms;
> -allow fetchmail_t fetchmail_etc_t:file r_file_perms;
> +allow fetchmail_t etc_t:file { read getattr ioctl };
> +allow fetchmail_t fetchmail_etc_t:file { read getattr ioctl };
> allow fetchmail_t mail_spool_t:dir search;
> file_type_auto_trans(fetchmail_t, mail_spool_t,
> fetchmail_uidl_cache_t, file)
>
>

-- 
James Carter <jwcart2@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 1 Apr 2005 - 15:35:05 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service