phpfpm_additional.if 918 B

123456789101112131415161718192021222324252627282930313233343536373839
  1. ## <summary>PHP-fpm policy interfaces.</summary>
  2. ########################################
  3. ## <summary>
  4. ## Do not audit attempts to read and
  5. ## write phpfpm unix domain stream sockets.
  6. ## </summary>
  7. ## <param name="domain">
  8. ## <summary>
  9. ## Domain to not audit.
  10. ## </summary>
  11. ## </param>
  12. #
  13. interface(`phpfpm_dontaudit_rw_stream_sockets',`
  14. gen_require(`
  15. type phpfpm_t;
  16. ')
  17. dontaudit $1 phpfpm_t:unix_stream_socket { read write };
  18. ')
  19. ########################################
  20. ## <summary>
  21. ## Do not audit attempts to read and
  22. ## write phpfpm TCP sockets.
  23. ## </summary>
  24. ## <param name="domain">
  25. ## <summary>
  26. ## Domain to not audit.
  27. ## </summary>
  28. ## </param>
  29. #
  30. interface(`phpfpm_dontaudit_rw_tcp_sockets',`
  31. gen_require(`
  32. type phpfpm_t;
  33. ')
  34. dontaudit $1 phpfpm_t:tcp_socket { read write };
  35. ')