From f13da83f992d0b2ac5f65654ad07286ce0f98399 Mon Sep 17 00:00:00 2001 From: Don Miner Date: Wed, 26 Oct 2005 18:31:09 +0000 Subject: [PATCH] Added search and getattr permissions to etc_mail_t dir for system_mail_t so that the sendmail process would be able to start through init --- refpolicy/policy/modules/services/mta.te | 1 + 1 file changed, 1 insertion(+) diff --git a/refpolicy/policy/modules/services/mta.te b/refpolicy/policy/modules/services/mta.te index 9e82279a..7d78871a 100644 --- a/refpolicy/policy/modules/services/mta.te +++ b/refpolicy/policy/modules/services/mta.te @@ -50,6 +50,7 @@ allow system_mail_t self:capability { setuid setgid chown }; allow system_mail_t self:process { signal_perms setrlimit }; allow system_mail_t self:tcp_socket create_socket_perms; +allow system_mail_t etc_mail_t:dir { getattr search }; allow system_mail_t etc_mail_t:file r_file_perms; # re-exec itself