diff --git a/policy-20080710.patch b/policy-20080710.patch index 3e5372e..2f8809d 100644 --- a/policy-20080710.patch +++ b/policy-20080710.patch @@ -27399,7 +27399,7 @@ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/send +') diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/sendmail.te serefpolicy-3.5.13/policy/modules/services/sendmail.te --- nsaserefpolicy/policy/modules/services/sendmail.te 2008-10-17 14:49:13.000000000 +0200 -+++ serefpolicy-3.5.13/policy/modules/services/sendmail.te 2009-04-14 11:07:49.000000000 +0200 ++++ serefpolicy-3.5.13/policy/modules/services/sendmail.te 2009-04-14 12:30:20.000000000 +0200 @@ -20,13 +20,17 @@ mta_mailserver_delivery(sendmail_t) mta_mailserver_sender(sendmail_t) @@ -27498,7 +27498,7 @@ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/send +') + +optional_policy(` -+ fail2ban_read_lib_files(daemon) ++ fail2ban_read_lib_files(sendmail_t) +') + +optional_policy(` @@ -27506,7 +27506,7 @@ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/send +') + +optional_policy(` -+ milter_stream_connect_all(sendmail_t) ++ milter_stream_connect_all(sendmail_t) +') + +optional_policy(` diff --git a/selinux-policy.spec b/selinux-policy.spec index 9acccb1..8dc8d02 100644 --- a/selinux-policy.spec +++ b/selinux-policy.spec @@ -462,6 +462,7 @@ exit 0 %changelog * Tue Apr 14 2009 Miroslav Grepl 3.5.13-56 - Fix fail2ban policy +- Allow sendmail to read fail2ban_var_lib_t * Tue Apr 7 2009 Miroslav Grepl 3.5.13-55 - Allow swat_t domtrans to smbd_t