Ticket #42: exim-missing-perms.patch

File exim-missing-perms.patch, 0.9 kB (added by aqua, 1 year ago)

Adds missing entropy access, dontaudit on proc_t, TCP authorizations

  • exim.te

    old new  
    6565manage_files_pattern(exim_t, exim_var_run_t, exim_var_run_t) 
    6666files_pid_filetrans(exim_t, exim_var_run_t, { file dir }) 
    6767 
     68dev_read_rand(exim_t) 
     69dev_read_urand(exim_t) 
     70 
    6871kernel_read_kernel_sysctls(exim_t) 
    6972 
     73kernel_dontaudit_read_system_state(exim_t) 
     74 
    7075corecmd_search_bin(exim_t) 
    7176 
    7277corenet_all_recvfrom_unlabeled(exim_t) 
    7378corenet_tcp_sendrecv_all_if(exim_t) 
    7479corenet_tcp_sendrecv_all_nodes(exim_t) 
    7580corenet_tcp_sendrecv_all_ports(exim_t) 
     81corenet_tcp_sendrecv_smtp_port(exim_t) 
     82corenet_tcp_sendrecv_auth_port(exim_t) 
    7683corenet_tcp_bind_all_nodes(exim_t) 
    7784corenet_tcp_bind_smtp_port(exim_t) 
    7885corenet_tcp_bind_amavisd_send_port(exim_t) 
    7986corenet_tcp_connect_auth_port(exim_t) 
     87corenet_tcp_connect_smtp_port(exim_t) 
    8088corenet_tcp_connect_inetd_child_port(exim_t) 
    8189 
    8290# Init script handling