From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Fri, 4 May 2012 08:44:47 -0400 Subject: [refpolicy] [PATCH v2 1/2] Adding dontaudit on mta In-Reply-To: <20120421161713.GC28496@siphos.be> References: <20120421161615.GB28496@siphos.be> <20120421161713.GC28496@siphos.be> Message-ID: <4FA3CF3F.6000007@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 04/21/12 12:17, Sven Vermeulen wrote: > > Signed-off-by: Sven Vermeulen > --- > mta.if | 2 ++ > 1 files changed, 2 insertions(+), 0 deletions(-) > > diff --git a/mta.if b/mta.if > index 343cee3..4e2a5ba 100644 > --- a/mta.if > +++ b/mta.if > @@ -362,6 +362,8 @@ interface(`mta_send_mail',` > allow mta_user_agent $1:fd use; > allow mta_user_agent $1:process sigchld; > allow mta_user_agent $1:fifo_file rw_fifo_file_perms; > + > + dontaudit mta_user_agent $1:unix_stream_socket rw_socket_perms; > ') > > ######################################## Merged. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com