From: sven.vermeulen@siphos.be (Sven Vermeulen) Date: Mon, 21 Oct 2013 20:37:20 +0200 Subject: [refpolicy] [PATCH 1/1] Generalize syslog-ng pattern for syslogd_var_run_t Message-ID: <20131021183720.GA21511@siphos.be> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On Gentoo, /var/run/syslog-ng.ctl is a socket, and there's also /var/run/syslog-ng.pid, therefore the current pattern doesn't work. Signed-off-by: Luis Ressel Acked-by: Sven Vermeulen --- policy/modules/system/logging.fc | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/policy/modules/system/logging.fc b/policy/modules/system/logging.fc index b50c5fe..e9a6713 100644 --- a/policy/modules/system/logging.fc +++ b/policy/modules/system/logging.fc @@ -63,8 +63,7 @@ ifdef(`distro_redhat',` /var/run/log -s gen_context(system_u:object_r:devlog_t,s0) /var/run/metalog\.pid -- gen_context(system_u:object_r:syslogd_var_run_t,s0) /var/run/syslogd\.pid -- gen_context(system_u:object_r:syslogd_var_run_t,mls_systemhigh) -/var/run/syslog-ng.ctl -- gen_context(system_u:object_r:syslogd_var_run_t,s0) -/var/run/syslog-ng(/.*)? gen_context(system_u:object_r:syslogd_var_run_t,s0) +/var/run/syslog-ng(.*)? gen_context(system_u:object_r:syslogd_var_run_t,s0) /var/spool/audit(/.*)? gen_context(system_u:object_r:audit_spool_t,mls_systemhigh) /var/spool/bacula/log(/.*)? gen_context(system_u:object_r:var_log_t,s0) -- 1.8.1.5