Allow getsched for syslog-ng

Recent syslog-ng implementation uses a threading library that requires the getsched permission.

See also https://bugs.gentoo.org/show_bug.cgi?id=405425

Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
This commit is contained in:
Sven Vermeulen 2012-05-01 10:13:14 +02:00 committed by Chris PeBenito
parent b72101a116
commit 1c5de3ddf5
1 changed files with 2 additions and 1 deletions

View File

@ -358,7 +358,8 @@ allow syslogd_t self:capability { dac_override sys_resource sys_tty_config net_a
dontaudit syslogd_t self:capability sys_tty_config;
# setpgid for metalog
# setrlimit for syslog-ng
allow syslogd_t self:process { signal_perms setpgid setrlimit };
# getsched for syslog-ng
allow syslogd_t self:process { signal_perms setpgid setrlimit getsched };
# receive messages to be logged
allow syslogd_t self:unix_dgram_socket create_socket_perms;
allow syslogd_t self:unix_stream_socket create_stream_socket_perms;