From: sven.vermeulen@siphos.be (Sven Vermeulen) Date: Tue, 1 May 2012 10:13:14 +0200 Subject: [refpolicy] [PATCH 1/1] Allow getsched for syslog-ng Message-ID: <20120501081313.GH32060@siphos.be> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Recent syslog-ng implementation uses a threading library that requires the getsched permission. See also https://bugs.gentoo.org/show_bug.cgi?id=405425 Signed-off-by: Sven Vermeulen --- policy/modules/system/logging.te | 3 ++- 1 files changed, 2 insertions(+), 1 deletions(-) diff --git a/policy/modules/system/logging.te b/policy/modules/system/logging.te index ebc216c..6bf2058 100644 --- a/policy/modules/system/logging.te +++ b/policy/modules/system/logging.te @@ -358,7 +358,8 @@ allow syslogd_t self:capability { dac_override sys_resource sys_tty_config net_a dontaudit syslogd_t self:capability sys_tty_config; # setpgid for metalog # setrlimit for syslog-ng -allow syslogd_t self:process { signal_perms setpgid setrlimit }; +# getsched for syslog-ng +allow syslogd_t self:process { signal_perms setpgid setrlimit getsched }; # receive messages to be logged allow syslogd_t self:unix_dgram_socket create_socket_perms; allow syslogd_t self:unix_stream_socket create_stream_socket_perms; -- 1.7.3.4