Merge pull request #679 from gtrentalancia/audit_fixes_pr
Improve a previous syslog tunable policy change
This commit is contained in:
commit
ba922253f4
|
@ -408,8 +408,6 @@ allow syslogd_t self:unix_dgram_socket create_socket_perms;
|
|||
allow syslogd_t self:unix_stream_socket create_stream_socket_perms;
|
||||
allow syslogd_t self:unix_dgram_socket sendto;
|
||||
allow syslogd_t self:fifo_file rw_fifo_file_perms;
|
||||
allow syslogd_t self:udp_socket create_socket_perms;
|
||||
allow syslogd_t self:tcp_socket create_stream_socket_perms;
|
||||
|
||||
allow syslogd_t syslog_conf_t:file read_file_perms;
|
||||
allow syslogd_t syslog_conf_t:dir list_dir_perms;
|
||||
|
@ -588,6 +586,8 @@ ifdef(`distro_ubuntu',`
|
|||
|
||||
tunable_policy(`logging_syslog_can_network',`
|
||||
allow syslogd_t self:capability { net_admin };
|
||||
allow syslogd_t self:tcp_socket create_stream_socket_perms;
|
||||
allow syslogd_t self:udp_socket create_socket_perms;
|
||||
|
||||
corenet_all_recvfrom_netlabel(syslogd_t)
|
||||
corenet_udp_sendrecv_generic_if(syslogd_t)
|
||||
|
|
Loading…
Reference in New Issue