From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Fri, 20 Apr 2012 16:37:06 -0400 Subject: [refpolicy] [PATCH 1/5] Allow asterisk to chown its own /var/run/asterisk directory In-Reply-To: <20120326184910.GB24792@siphos.be> References: <20120326184827.GA24792@siphos.be> <20120326184910.GB24792@siphos.be> Message-ID: <4F91C8F2.40305@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 03/26/12 14:49, Sven Vermeulen wrote: > During startup, asterisk verifies the ownership of its run-directory and, if not set correctly, changes it accordingly. > > Signed-off-by: Sven Vermeulen > --- > asterisk.te | 2 +- > 1 files changed, 1 insertions(+), 1 deletions(-) > > diff --git a/asterisk.te b/asterisk.te > index 22d7cdf..c702879 100644 > --- a/asterisk.te > +++ b/asterisk.te > @@ -40,7 +40,7 @@ files_pid_file(asterisk_var_run_t) > # > > # dac_override for /var/run/asterisk > -allow asterisk_t self:capability { dac_override setgid setuid sys_nice net_admin }; > +allow asterisk_t self:capability { dac_override setgid setuid sys_nice net_admin chown }; > dontaudit asterisk_t self:capability sys_tty_config; > allow asterisk_t self:process { getsched setsched signal_perms getcap setcap }; > allow asterisk_t self:fifo_file rw_fifo_file_perms; Merged. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com