Gentoo Archives: gentoo-commits

From: Sven Vermeulen <sven.vermeulen@××××××.be>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/contrib/
Date: Wed, 28 Nov 2012 20:22:48
Message-Id: 1354134010.bc58b454ba0adea0253ad906e38d3ad70df9629c.SwifT@gentoo
1 commit: bc58b454ba0adea0253ad906e38d3ad70df9629c
2 Author: Dominick Grift <dominick.grift <AT> gmail <DOT> com>
3 AuthorDate: Wed Nov 28 16:32:28 2012 +0000
4 Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
5 CommitDate: Wed Nov 28 20:20:10 2012 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=bc58b454
7
8 Changes to the spamassassin policy module
9
10 spamd_update creates spamd_var_lib_t directories and ignores DAC when
11 searching for directories
12
13 Signed-off-by: Dominick Grift <dominick.grift <AT> gmail.com>
14
15 ---
16 policy/modules/contrib/spamassassin.te | 6 +++---
17 1 files changed, 3 insertions(+), 3 deletions(-)
18
19 diff --git a/policy/modules/contrib/spamassassin.te b/policy/modules/contrib/spamassassin.te
20 index 435018e..4faa7e0 100644
21 --- a/policy/modules/contrib/spamassassin.te
22 +++ b/policy/modules/contrib/spamassassin.te
23 @@ -1,4 +1,4 @@
24 -policy_module(spamassassin, 2.5.7)
25 +policy_module(spamassassin, 2.5.8)
26
27 ########################################
28 #
29 @@ -477,7 +477,7 @@ optional_policy(`
30 # Update local policy
31 #
32
33 -dontaudit spamd_update_t self:capability dac_override;
34 +allow spamd_update_t self:capability dac_override;
35 allow spamd_update_t self:fifo_file manage_fifo_file_perms;
36 allow spamd_update_t self:unix_stream_socket create_stream_socket_perms;
37
38 @@ -485,7 +485,7 @@ manage_dirs_pattern(spamd_update_t, spamd_tmp_t, spamd_tmp_t)
39 manage_files_pattern(spamd_update_t, spamd_tmp_t, spamd_tmp_t)
40 files_tmp_filetrans(spamd_update_t, spamd_tmp_t, { file dir })
41
42 -allow spamd_update_t spamd_var_lib_t:dir list_dir_perms;
43 +manage_dirs_pattern(spamd_update_t, spamd_var_lib_t, spamd_var_lib_t)
44 manage_files_pattern(spamd_update_t, spamd_var_lib_t, spamd_var_lib_t)
45 manage_lnk_files_pattern(spamd_update_t, spamd_var_lib_t, spamd_var_lib_t)