Research Menu

.
Skip Search Box

SELinux Mailing List

Re: gentoo diff for arpwatch

From: James Carter <jwcart2_at_epoch.ncsc.mil>
Date: Fri, 19 Nov 2004 14:47:34 -0500


Merged with some changes.

I moved the following rules and put an "ifdef(`arpwatch.te'" around them:

"allow system_mail_t" rules to mta.te
"allow qmail_inject_t" rules to qmail.te
"allow allow postfix_local_t" rule to postfix.te

I also moved the "allow initrc_t" rules to initrc.te and put "ifdef(`distro_gentoo" and "ifdef(`arpwatch.te'" around them.

On Mon, 2004-11-15 at 10:51, petre rodan wrote:
> Hi,
>
> attached you'll find a +15 -5 patch to the arpwatch policy
>
> both /var/lib/arpwatch and /var/arpwatch are used by gentoo.
> etc_t is used when arpwatch_t reads nsswitch.conf, usr_t is needed to read the ethercodes file.
>
> the distro_gentoo block is needed because init creates ethX.dat files before the daemon is started.
>
> bye,
> peter

-- 
James Carter <jwcart2@epoch.ncsc.mil>
National Security Agency

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 19 Nov 2004 - 14:44:55 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service