From Debian package 0.2.20100524-5 0077-courier-policy-adjustments-Label-courier-socket-file.patch (part of) * Label courier socket files as courier_var_run_t Labelling of sockets was done upstream in 2aa70bc0 (2011-03-09) Label of authdaemond was merged upstream in contrib 11388469 (2011-11-16) Index: policy/modules/contrib/courier.te =================================================================== --- policy/modules/contrib/courier.te.orig +++ policy/modules/contrib/courier.te @@ -24,6 +24,7 @@ type courier_var_run_t; files_pid_file(courier_var_run_t) +files_pid_filetrans(courier_authdaemon_t, courier_var_run_t, { file sock_file }) type courier_exec_t; mta_agent_executable(courier_exec_t) @@ -33,6 +34,7 @@ courier_domain_template(sqwebmail) typealias courier_sqwebmail_exec_t alias sqwebmail_cron_exec_t; +files_pid_filetrans(courier_sqwebmail_t, courier_var_run_t, { file sock_file }) manage_files_pattern(courier_sqwebmail_t, courier_sqwebmail_cache_t, courier_sqwebmail_cache_t)