## Pyzor is a distributed, collaborative spam detection and filtering network. ######################################## ## ## Role access for pyzor ## ## ## ## Role allowed access ## ## ## ## ## User domain for the role ## ## # interface(`pyzor_role',` gen_require(` type pyzor_t, pyzor_exec_t; type pyzor_home_t, pyzor_var_lib_t, pyzor_tmp_t; ') role $1 types pyzor_t; # Transition from the user domain to the derived domain. domtrans_pattern($2, pyzor_exec_t, pyzor_t) # allow ps to show pyzor and allow the user to kill it ps_process_pattern($2, pyzor_t) allow $2 pyzor_t:process signal; ') ######################################## ## ## Send generic signals to pyzor ## ## ## ## Domain allowed access. ## ## # interface(`pyzor_signal',` gen_require(` type pyzor_t; ') allow $1 pyzor_t:process signal; ') ######################################## ## ## Execute pyzor with a domain transition. ## ## ## ## Domain allowed to transition. ## ## # interface(`pyzor_domtrans',` gen_require(` type pyzor_exec_t, pyzor_t; ') files_search_usr($1) corecmd_search_bin($1) domtrans_pattern($1, pyzor_exec_t, pyzor_t) ') ######################################## ## ## Execute pyzor in the caller domain. ## ## ## ## Domain allowed access. ## ## # interface(`pyzor_exec',` gen_require(` type pyzor_exec_t; ') files_search_usr($1) corecmd_search_bin($1) can_exec($1, pyzor_exec_t) ')