From: sven.vermeulen@siphos.be (Sven Vermeulen) Date: Fri, 19 Oct 2012 20:51:24 +0200 Subject: [refpolicy] [PATCH 2/3] Introduce logging_search_all_log_dirs interface In-Reply-To: <1350672685-14472-1-git-send-email-sven.vermeulen@siphos.be> References: <1350672685-14472-1-git-send-email-sven.vermeulen@siphos.be> Message-ID: <1350672685-14472-3-git-send-email-sven.vermeulen@siphos.be> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Support the logging_search_all_log_dirs interface for applications such as fail2ban-client, who scan through log directories. Signed-off-by: Sven Vermeulen --- policy/modules/system/logging.if | 19 +++++++++++++++++++ 1 files changed, 19 insertions(+), 0 deletions(-) diff --git a/policy/modules/system/logging.if b/policy/modules/system/logging.if index be20dca..6957993 100644 --- a/policy/modules/system/logging.if +++ b/policy/modules/system/logging.if @@ -686,6 +686,25 @@ interface(`logging_rw_generic_log_dirs',` ####################################### ## +## Search through all log dirs. +## +## +## +## Domain allowed access. +## +## +## +# +interface(`logging_search_all_log_dirs',` + gen_require(` + attribute logfile; + ') + + allow $1 logfile:dir search_dir_perms; +') + +####################################### +## ## Set attributes on all log dirs. ## ## -- 1.7.8.6