diff --git a/policy/modules/system/logging.if b/policy/modules/system/logging.if index c33c23079..341763730 100644 --- a/policy/modules/system/logging.if +++ b/policy/modules/system/logging.if @@ -306,7 +306,7 @@ interface(`logging_signal_dispatcher',` # interface(`logging_dispatcher_domain',` gen_require(` - type audisp_t; + type audisp_t, auditd_t; role system_r; ') @@ -315,6 +315,8 @@ interface(`logging_dispatcher_domain',` role system_r types $1; + allow auditd_t $2:file getattr; + domtrans_pattern(audisp_t, $2, $1) allow audisp_t $1:process { sigkill sigstop signull signal };