--- /usr/src/se/policy/file_contexts/program/sendmail.fc 2004-02-25 17:05:05.000000000 +1100 +++ /tmp/sendmail.fc 2004-10-02 02:28:23.000000000 +1000 @@ -3,3 +3,5 @@ /var/spool/(client)?mqueue(/.*)? system_u:object_r:mqueue_spool_t /var/log/sendmail\.st -- system_u:object_r:sendmail_log_t /var/log/mail(/.*)? system_u:object_r:sendmail_log_t +/var/run/sendmail.pid -- system_u:object_r:sendmail_var_run_t +/var/run/sm-client.pid -- system_u:object_r:sendmail_var_run_t --- /usr/src/se/policy/domains/program/unused/sendmail.te 2004-09-11 16:21:45.000000000 +1000 +++ domains/program/unused/sendmail.te 2004-10-02 02:31:38.000000000 +1000 @@ -65,11 +65,6 @@ # Read /usr/lib/sasl2/.* allow sendmail_t lib_t:file { getattr read }; -# /usr/sbin/sendmail asks for w access to utmp, but it will operate -# correctly without it. Do not audit write and lock denials to utmp. -allow sendmail_t initrc_var_run_t:file { getattr read }; -dontaudit sendmail_t initrc_var_run_t:file { lock write }; - # When sendmail runs as user_mail_domain, it needs some extra permissions # to update /etc/mail/statistics. allow user_mail_domain etc_mail_t:file rw_file_perms;