From Debian package 0.2.20100524-8 * Label /var/lib/fetchmail as fetchmail_uidl_cache_t and allow fetchmail_t to search /var/lib and manage fetchmail_uidl_cache_t dirs Index: policy/modules/services/fetchmail.fc =================================================================== --- policy/modules/services/fetchmail.fc.orig +++ policy/modules/services/fetchmail.fc @@ -17,3 +17,4 @@ /var/run/fetchmail/.* -- gen_context(system_u:object_r:fetchmail_var_run_t,s0) /var/mail/\.fetchmail-UIDL-cache -- gen_context(system_u:object_r:fetchmail_uidl_cache_t,s0) +/var/lib/fetchmail(/.*)? gen_context(system_u:object_r:fetchmail_uidl_cache_t,s0) Index: policy/modules/services/fetchmail.te =================================================================== --- policy/modules/services/fetchmail.te.orig +++ policy/modules/services/fetchmail.te @@ -40,12 +40,14 @@ allow fetchmail_t fetchmail_etc_t:file read_file_perms; files_read_usr_files(fetchmail_t) +allow fetchmail_t fetchmail_uidl_cache_t:dir manage_dir_perms; allow fetchmail_t fetchmail_uidl_cache_t:file manage_file_perms; mta_spool_filetrans(fetchmail_t, fetchmail_uidl_cache_t, file) manage_dirs_pattern(fetchmail_t, fetchmail_var_run_t, fetchmail_var_run_t) manage_files_pattern(fetchmail_t, fetchmail_var_run_t, fetchmail_var_run_t) files_pid_filetrans(fetchmail_t, fetchmail_var_run_t, { dir file }) +files_search_var_lib(fetchmail_t) kernel_read_kernel_sysctls(fetchmail_t) kernel_list_proc(fetchmail_t)