2013-11-03 14:11:12

by Mira Ressel

[permalink] [raw]
Subject: [refpolicy] [PATCH] Allow initrc_t to create /var/run/opendkim

On Gentoo, /var/run/opendkim is created by the init system, therefore
init_daemon_run_dir() is required, otherwise the directory would get a
wrong label.
---
policy/modules/contrib/dkim.te | 2 ++
1 file changed, 2 insertions(+)

diff --git a/policy/modules/contrib/dkim.te b/policy/modules/contrib/dkim.te
index 1c3545d..2383e24 100644
--- a/policy/modules/contrib/dkim.te
+++ b/policy/modules/contrib/dkim.te
@@ -31,3 +31,5 @@ dev_read_urand(dkim_milter_t)
files_search_spool(dkim_milter_t)

mta_read_config(dkim_milter_t)
+
+init_daemon_run_dir(dkim_milter_data_t, "opendkim")
--
1.8.4.2


2013-11-03 16:08:22

by dominick.grift

[permalink] [raw]
Subject: [refpolicy] [PATCH] Allow initrc_t to create /var/run/opendkim

On Sun, 2013-11-03 at 15:11 +0100, Luis Ressel wrote:
> On Gentoo, /var/run/opendkim is created by the init system, therefore
> init_daemon_run_dir() is required, otherwise the directory would get a
> wrong label.

Thank you! This was merged

> ---
> policy/modules/contrib/dkim.te | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/policy/modules/contrib/dkim.te b/policy/modules/contrib/dkim.te
> index 1c3545d..2383e24 100644
> --- a/policy/modules/contrib/dkim.te
> +++ b/policy/modules/contrib/dkim.te
> @@ -31,3 +31,5 @@ dev_read_urand(dkim_milter_t)
> files_search_spool(dkim_milter_t)
>
> mta_read_config(dkim_milter_t)
> +
> +init_daemon_run_dir(dkim_milter_data_t, "opendkim")