From 88340b904ae88118c8bf8c823724482f18921931 Mon Sep 17 00:00:00 2001 From: Dominick Grift Date: Wed, 24 Feb 2010 13:00:42 +0100 Subject: [PATCH] Various amavis fixes. Create amavis_initrc_domtrans. Call amavis_initrc_domtrans from amavis_admin. Remove obsolete require. Allow domains to search bin to enable run amavis executable. Signed-off-by: Dominick Grift --- policy/modules/services/amavis.if | 22 ++++++++++++++++++++-- 1 file changed, 20 insertions(+), 2 deletions(-) diff --git a/policy/modules/services/amavis.if b/policy/modules/services/amavis.if index db18f31c..22523cdc 100644 --- a/policy/modules/services/amavis.if +++ b/policy/modules/services/amavis.if @@ -18,9 +18,28 @@ interface(`amavis_domtrans',` type amavis_t, amavis_exec_t; ') + corecmd_search_bin($1) domtrans_pattern($1, amavis_exec_t, amavis_t) ') +######################################## +## +## Execute amavis server in the amavis domain. +## +## +## +## The type of the process performing this action. +## +## +# +interface(`amavis_initrc_domtrans',` + gen_require(` + type afs_initrc_exec_t; + ') + + init_labeled_script_domtrans($1, amavis_initrc_exec_t) +') + ######################################## ## ## Read amavis spool files. @@ -209,13 +228,12 @@ interface(`amavis_admin',` type amavis_t, amavis_tmp_t, amavis_var_log_t; type amavis_spool_t, amavis_var_lib_t, amavis_var_run_t; type amavis_etc_t, amavis_quarantine_t; - type amavis_initrc_exec_t; ') allow $1 amavis_t:process { ptrace signal_perms }; ps_process_pattern($1, amavis_t) - init_labeled_script_domtrans($1, amavis_initrc_exec_t) + amavis_initrc_domtrans($1) domain_system_change_exemption($1) role_transition $2 amavis_initrc_exec_t system_r; allow $2 system_r;