From Debian package 0.2.20100524-5 * Allow dkim_milter_t to read proc_t files and create /tmp files Index: policy/modules/services/dkim.te =================================================================== --- policy/modules/services/dkim.te.orig +++ policy/modules/services/dkim.te @@ -11,12 +11,18 @@ type dkim_milter_private_key_t; files_type(dkim_milter_private_key_t) +type dkim_milter_tmp_t; +files_tmp_file(dkim_milter_tmp_t) +ubac_constrained(dkim_milter_tmp_t) +files_tmp_filetrans(dkim_milter_t, dkim_milter_tmp_t, file) + ######################################## # # Local policy # allow dkim_milter_t self:capability { setgid setuid }; +kernel_read_system_state(dkim_milter_t) read_files_pattern(dkim_milter_t, dkim_milter_private_key_t, dkim_milter_private_key_t)