Merge pull request #679 from gtrentalancia/audit_fixes_pr

Improve a previous syslog tunable policy change
This commit is contained in:
Chris PeBenito 2023-09-14 10:49:38 -04:00 committed by GitHub
commit ba922253f4
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 2 deletions

View File

@ -408,8 +408,6 @@ allow syslogd_t self:unix_dgram_socket create_socket_perms;
allow syslogd_t self:unix_stream_socket create_stream_socket_perms;
allow syslogd_t self:unix_dgram_socket sendto;
allow syslogd_t self:fifo_file rw_fifo_file_perms;
allow syslogd_t self:udp_socket create_socket_perms;
allow syslogd_t self:tcp_socket create_stream_socket_perms;
allow syslogd_t syslog_conf_t:file read_file_perms;
allow syslogd_t syslog_conf_t:dir list_dir_perms;
@ -588,6 +586,8 @@ ifdef(`distro_ubuntu',`
tunable_policy(`logging_syslog_can_network',`
allow syslogd_t self:capability { net_admin };
allow syslogd_t self:tcp_socket create_stream_socket_perms;
allow syslogd_t self:udp_socket create_socket_perms;
corenet_all_recvfrom_netlabel(syslogd_t)
corenet_udp_sendrecv_generic_if(syslogd_t)