Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-2.5 required=3.0 tests=HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,SPF_PASS,USER_AGENT_MUTT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 34581C43441 for ; Mon, 12 Nov 2018 06:55:07 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id EF78E216FD for ; Mon, 12 Nov 2018 06:55:06 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org EF78E216FD Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=suse.cz Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=selinux-refpolicy-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1731833AbeKLQrA (ORCPT ); Mon, 12 Nov 2018 11:47:00 -0500 Received: from mx2.suse.de ([195.135.220.15]:34578 "EHLO mx1.suse.de" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1731784AbeKLQq7 (ORCPT ); Mon, 12 Nov 2018 11:46:59 -0500 X-Virus-Scanned: by amavisd-new at test-mx.suse.de Received: from relay2.suse.de (unknown [195.135.220.254]) by mx1.suse.de (Postfix) with ESMTP id 14502ADC3; Mon, 12 Nov 2018 06:55:05 +0000 (UTC) Date: Mon, 12 Nov 2018 07:55:03 +0100 From: Petr Vorel To: Chris PeBenito Cc: selinux-refpolicy@vger.kernel.org, Dan Walsh Subject: Re: [PATCH 1/2] dnsmasq: Require log files to have .log suffix Message-ID: <20181112065503.GA16658@dell5510> Reply-To: Petr Vorel References: <20181107205736.21748-1-pvorel@suse.cz> <5137d6d9-5bdb-a21d-97c9-2e6c8a61c2a6@ieee.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <5137d6d9-5bdb-a21d-97c9-2e6c8a61c2a6@ieee.org> User-Agent: Mutt/1.10.1 (2018-07-13) Sender: selinux-refpolicy-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: selinux-refpolicy@vger.kernel.org Hi Chris, ... > > +++ b/policy/modules/services/dnsmasq.fc > > @@ -13,7 +13,7 @@ > > /var/lib/misc/dnsmasq\.leases -- gen_context(system_u:object_r:dnsmasq_lease_t,s0) > > /var/lib/dnsmasq(/.*)? gen_context(system_u:object_r:dnsmasq_lease_t,s0) > > -/var/log/dnsmasq.* -- gen_context(system_u:object_r:dnsmasq_var_log_t,s0) > > +/var/log/dnsmasq(.*)?\.log -- gen_context(system_u:object_r:dnsmasq_var_log_t,s0) > > /run/dnsmasq.* -- gen_context(system_u:object_r:dnsmasq_var_run_t,s0) > > /run/libvirt/network(/.*)? gen_context(system_u:object_r:dnsmasq_var_run_t,s0) > This would exclude rotated logs, e.g. something like dnsmasq.log.1 or > dnsmasq.log.1.gz, which would be undesirable. I didn't know dnsmasq need to open logs already handled by logrotate (I thought logrotate creates these). But I see apache has similar pattern. I added the patern in v2: /var/log/dnsmasq(.*)?\.log(\..+) Kind regards, Petr