From: dwalsh@redhat.com (Daniel J Walsh) Date: Thu, 21 May 2009 10:58:33 -0400 Subject: [refpolicy] apps_gpg.patch Message-ID: <4A156C19.50902@redhat.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com http://people.fedoraproject.org/~dwalsh/SELinux/F11/apps_gpg.patch gpg sends signals executed from firefox/thunderbird, which leak filedescripors like a sieve. Needs getcap Creates files in /tmp uses getpw calls Needs to manager users files in /tmp and the homedir. It signs, them, encrypts them ...