From: dwalsh@redhat.com (Daniel J Walsh) Date: Tue, 24 Mar 2009 09:46:54 -0400 Subject: [refpolicy] services_mta.patch Message-ID: <49C8E44E.5030300@redhat.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com http://people.fedoraproject.org/~dwalsh/SELinux/F11/services_mta.patch Lots of fixes for mta interfaces system_mail_t needs fowner and uses fifo files Mailers are always reading /tmp files Mailers user inodify and inodefs I allow system mail to be appended to all logs since confined domains are constantly redirecting stdout/stderr to log files system_mail can be sent from apache_bugzill dirs Gets executed from cron with redirection to cron pipes add courier/exim mail If you are a mailserver_delivery you need to write to users homedirs. (nfs, cifs)