2008-09-11 19:48:50

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] MTA Changes

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

/bin/mail should be labeled sendmail_exec_t

Add attribute mailclient_exec_type. All mail clients should define
this, then a confined domain when executing file types with this
attribute will transition to system_mail_t.


Add attribute mailcontent_type, File types with this attribute can be
read by the system_mail_t.

Change mqueue_spool_t and mail_spool_t into mountpoints

system_mail_t needs additional prics.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkjJdiIACgkQrlYvE4MpobMn2ACdGd4FQ/eQfJj55KDI+9UkXsLw
NVQAoJ52vqt6HLCe9OtLfz+enE0h1QD5
=IJto
-----END PGP SIGNATURE-----
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: services_mta.patch
Url: http://oss.tresys.com/pipermail/refpolicy/attachments/20080911/3f8bfd2d/attachment.pl
-------------- next part --------------
A non-text attachment was scrubbed...
Name: services_mta.patch.sig
Type: application/octet-stream
Size: 72 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20080911/3f8bfd2d/attachment.obj