瀏覽代碼

apache: allow writing to httpd_sys_content_dir again

Helmut Pozimski 7 年之前
父節點
當前提交
04de692d0d
共有 1 個文件被更改,包括 4 次插入1 次删除
  1. 4 1
      policy/modules/apache.te

+ 4 - 1
policy/modules/apache.te

@@ -1,4 +1,4 @@
-policy_module(apache, 2.11.1)
+policy_module(apache, 2.11.2)
 
 ########################################
 #
@@ -394,6 +394,9 @@ allow httpd_t self:unix_dgram_socket sendto;
 allow httpd_t self:unix_stream_socket { accept connectto listen };
 allow httpd_t self:tcp_socket { accept listen };
 
+allow httpd_t httpd_sys_content_t:dir { write remove_name add_name };
+allow httpd_t httpd_sys_content_t:file { write create unlink };
+
 manage_dirs_pattern(httpd_t, httpd_cache_t, httpd_cache_t)
 manage_files_pattern(httpd_t, httpd_cache_t, httpd_cache_t)
 manage_lnk_files_pattern(httpd_t, httpd_cache_t, httpd_cache_t)