phpfpm_additional.te 688 B

1234567891011121314151617181920212223242526272829
  1. policy_module(phpfpm_additional, 0.0.2)
  2. require {
  3. type phpfpm_t;
  4. type etc_t;
  5. type httpd_sys_content_t;
  6. type phpfpm_tmp_t;
  7. type usr_t;
  8. }
  9. allow phpfpm_t self:process sigkill;
  10. miscfiles_read_all_certs(phpfpm_t)
  11. miscfiles_read_fonts(phpfpm_t)
  12. corenet_tcp_connect_pop_port(phpfpm_t)
  13. corenet_tcp_connect_http_port(phpfpm_t)
  14. corenet_tcp_connect_sieve_port(phpfpm_t)
  15. corenet_tcp_connect_smtp_port(phpfpm_t)
  16. files_tmp_filetrans(phpfpm_t, phpfpm_tmp_t, lnk_file)
  17. apache_manage_sys_content(phpfpm_t)
  18. fs_mmap_rw_hugetlbfs_files(phpfpm_t)
  19. allow phpfpm_t etc_t:file map;
  20. allow phpfpm_t httpd_sys_content_t:file map;
  21. allow phpfpm_t phpfpm_tmp_t:file map;
  22. allow phpfpm_t usr_t:file map;