From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Fri, 20 Apr 2012 16:37:14 -0400 Subject: [refpolicy] [PATCH 2/5] Allow asterisk to listen on its control socket In-Reply-To: <20120326184936.GC24792@siphos.be> References: <20120326184827.GA24792@siphos.be> <20120326184936.GC24792@siphos.be> Message-ID: <4F91C8FA.4070706@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 03/26/12 14:49, Sven Vermeulen wrote: > > Signed-off-by: Sven Vermeulen > --- > asterisk.te | 2 +- > 1 files changed, 1 insertions(+), 1 deletions(-) > > diff --git a/asterisk.te b/asterisk.te > index c702879..aac5a41 100644 > --- a/asterisk.te > +++ b/asterisk.te > @@ -46,7 +46,7 @@ allow asterisk_t self:process { getsched setsched signal_perms getcap setcap }; > allow asterisk_t self:fifo_file rw_fifo_file_perms; > allow asterisk_t self:sem create_sem_perms; > allow asterisk_t self:shm create_shm_perms; > -allow asterisk_t self:unix_stream_socket connectto; > +allow asterisk_t self:unix_stream_socket { connectto listen accept }; > allow asterisk_t self:tcp_socket create_stream_socket_perms; > allow asterisk_t self:udp_socket create_socket_perms; Merged. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com