Explorar o código

apache: allow writing to httpd_sys_content_dir again

Helmut Pozimski %!s(int64=7) %!d(string=hai) anos
pai
achega
04de692d0d
Modificáronse 1 ficheiros con 4 adicións e 1 borrados
  1. 4 1
      policy/modules/apache.te

+ 4 - 1
policy/modules/apache.te

@@ -1,4 +1,4 @@
-policy_module(apache, 2.11.1)
+policy_module(apache, 2.11.2)
 
 ########################################
 #
@@ -394,6 +394,9 @@ allow httpd_t self:unix_dgram_socket sendto;
 allow httpd_t self:unix_stream_socket { accept connectto listen };
 allow httpd_t self:tcp_socket { accept listen };
 
+allow httpd_t httpd_sys_content_t:dir { write remove_name add_name };
+allow httpd_t httpd_sys_content_t:file { write create unlink };
+
 manage_dirs_pattern(httpd_t, httpd_cache_t, httpd_cache_t)
 manage_files_pattern(httpd_t, httpd_cache_t, httpd_cache_t)
 manage_lnk_files_pattern(httpd_t, httpd_cache_t, httpd_cache_t)