From Debian package 0.2.20100524-11 * Allow perdition to authenticate with mysql, read directories of type perdition_etc_t, connect to the pop ports Index: policy/modules/services/perdition.te =================================================================== --- policy/modules/services/perdition.te.orig +++ policy/modules/services/perdition.te @@ -28,6 +28,7 @@ allow perdition_t self:udp_socket create_socket_perms; allow perdition_t perdition_etc_t:file read_file_perms; +allow perdition_t perdition_etc_t:dir r_dir_perms; files_search_etc(perdition_t) manage_files_pattern(perdition_t, perdition_var_run_t, perdition_var_run_t) @@ -47,6 +48,7 @@ corenet_udp_sendrecv_all_ports(perdition_t) corenet_tcp_bind_generic_node(perdition_t) corenet_tcp_bind_pop_port(perdition_t) +corenet_tcp_connect_pop_port(perdition_t) corenet_sendrecv_pop_server_packets(perdition_t) dev_read_sysfs(perdition_t) @@ -74,3 +76,7 @@ optional_policy(` udev_read_db(perdition_t) ') +optional_policy(` + mysql_tcp_connect(perdition_t) + mysql_stream_connect(perdition_t) +')