Browse Source

logrotate_additional: add policy module

Helmut Pozimski 3 years ago
parent
commit
03fd23cb60
1 changed files with 13 additions and 0 deletions
  1. 13 0
      logrotate_additional.te

+ 13 - 0
logrotate_additional.te

@@ -0,0 +1,13 @@
+policy_module(logrotate_additional, 0.0.1)
+
+require {
+  type logrotate_t;
+  type syslogd_t;
+  type initrc_state_t;
+}
+
+init_read_script_status_files(logrotate_t)
+allow logrotate_t initrc_state_t:lnk_file { getattr read };
+allow logrotate_t initrc_state_t:dir read;
+
+allow logrotate_t syslogd_t:process signull;