diff --git a/policy/modules/system/logging.te b/policy/modules/system/logging.te index 59b04c1a2..d7e857e85 100644 --- a/policy/modules/system/logging.te +++ b/policy/modules/system/logging.te @@ -361,7 +361,7 @@ dontaudit syslogd_t self:capability sys_tty_config; # setrlimit for syslog-ng # getsched for syslog-ng # setsched for rsyslog -allow syslogd_t self:process { signal_perms setpgid setrlimit getsched setsched }; +allow syslogd_t self:process { getcap setcap signal_perms setpgid setrlimit getsched setsched }; # receive messages to be logged allow syslogd_t self:unix_dgram_socket create_socket_perms; allow syslogd_t self:unix_stream_socket create_stream_socket_perms;