Research Menu

.
Skip Search Box

SELinux Mailing List

Re: gentoo policy for dante

From: petre rodan <kaiowas_at_gentoo.org>
Date: Sun, 28 Nov 2004 11:51:08 +0200

Hi Daniel,

Daniel J Walsh wrote:
> Small change on previous patch.
>
> Please ignore previous patch and use this one.
 >
> --- nsapolicy/domains/program/unused/postgresql.te 2004-11-20 22:29:09.000000000 -0500
> +++ policy-1.19.4/domains/program/unused/postgresql.te 2004-11-21 00:17:07.933617789 -0500
> @@ -110,6 +110,14 @@
> dontaudit postgresql_t selinux_config_t:dir { search };
> allow postgresql_t mail_spool_t:dir { search };
> rw_dir_create_file(postgresql_t, var_lock_t)
> +can_exec(postgresql_t, { shell_exec_t bin_t } )
> +ifdef(`httpd.te', `
> +#
> +# Allow httpd to work with postgresql
> +#
> +allow httpd_t postgresql_tmp_t:sock_file rw_file_perms;
> +can_unix_connect(httpd_t, posgresql_t)
> +')

shouldn't this be an ifdef on apache.te instead of httpd.te?

bye,
peter

-- 
petre rodan
<kaiowas@gentoo.org>
Developer,
Hardened Gentoo Linux

-- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.

Received on Sun 28 Nov 2004 - 04:20:51 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service