Ver Fonte

unconfined_additional: rewrite amavis and jabber transition rules

Helmut Pozimski há 3 anos atrás
pai
commit
5e77267dfd
1 ficheiros alterados com 9 adições e 3 exclusões
  1. 9 3
      unconfined_additional.te

+ 9 - 3
unconfined_additional.te

@@ -1,4 +1,4 @@
-policy_module(unconfined_additional, 0.0.5)
+policy_module(unconfined_additional, 0.0.7)
 
 require {
   type unconfined_t;
@@ -12,6 +12,12 @@ require {
   type phpfpm_t;
   type phpfpm_initrc_exec_t;
   type phpfpm_unit_t;
+  type amavis_t;
+  type amavis_initrc_exec_t;
+  type amavis_unit_t;
+  type jabberd_t;
+  type jabberd_initrc_exec_t;
+  type jabber_unit_t;
   role unconfined_r;
 }
 
@@ -21,8 +27,8 @@ allow unconfined_t self:process execmem;
 init_startstop_service(unconfined_t, unconfined_r, atop_t, atop_initrc_exec_t, atop_unit_t)
 init_startstop_service(unconfined_t, unconfined_r, spamd_t, spamd_initrc_exec_t, spamd_unit_t)
 init_startstop_service(unconfined_t, unconfined_r, phpfpm_t, phpfpm_initrc_exec_t, phpfpm_unit_t)
-jabber_admin(unconfined_t, unconfined_r)
-amavis_admin(unconfined_t, unconfined_r)
+init_startstop_service(unconfined_t, unconfined_r, amavis_t, amavis_initrc_exec_t, amavis_unit_t)
+init_startstop_service(unconfined_t, unconfined_r, jabberd_t, jabberd_initrc_exec_t, jabber_unit_t)
 logging_admin_audit(unconfined_t, unconfined_r)
 dovecot_admin(unconfined_t, unconfined_r)
 openvpn_admin(unconfined_t, unconfined_r)