selinux-refpolicy/policy/modules
Nicolas Iooss 3a7e30c22d Allow journald to read the kernel ring buffer and to use /dev/kmsg
audit.log shows that journald needs to read the kernel read buffer:

    avc:  denied  { syslog_read } for  pid=147 comm="systemd-journal" scontext=system_u:system_r:syslogd_t tcontext=system_u:system_r:kernel_t tclass=system permissive=1

Moreover journald uses RW access to /dev/kmsg, according to its code:
http://cgit.freedesktop.org/systemd/systemd/tree/src/journal/journald-kmsg.c?id=v215#n394
2014-09-12 09:52:18 -04:00
..
admin Module version bump for ping rawip socket fix from Luis Ressel. 2014-08-18 10:30:28 -04:00
apps Move modules to contrib submodule. 2011-09-09 10:10:03 -04:00
contrib@ee5a05b5f3 Update contrib. 2014-08-19 08:55:37 -04:00
kernel Allow journald to read the kernel ring buffer and to use /dev/kmsg 2014-09-12 09:52:18 -04:00
roles Module version bump for deprecated interface usage removal from Nicolas Iooss. 2014-05-27 09:23:29 -04:00
services Module version bump for postgres fc revisions from Luis Ressel. 2014-08-20 14:38:30 -04:00
system Allow journald to read the kernel ring buffer and to use /dev/kmsg 2014-09-12 09:52:18 -04:00