phpfpm_additional.te 1.1 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647
  1. policy_module(phpfpm_additional, 0.0.7)
  2. require {
  3. type phpfpm_t;
  4. type etc_t;
  5. type httpd_sys_content_t;
  6. type phpfpm_tmp_t;
  7. type usr_t;
  8. type httpd_sys_ra_content_t;
  9. }
  10. type phpfpm_initrc_exec_t;
  11. init_script_file(phpfpm_initrc_exec_t)
  12. type phpfpm_unit_t;
  13. init_unit_file(phpfpm_unit_t)
  14. allow phpfpm_t self:process sigkill;
  15. allow phpfpm_t phpfpm_tmp_t:lnk_file { create unlink };
  16. miscfiles_read_all_certs(phpfpm_t)
  17. miscfiles_read_fonts(phpfpm_t)
  18. corecmd_exec_shell(phpfpm_t)
  19. corenet_tcp_connect_pop_port(phpfpm_t)
  20. corenet_tcp_connect_http_port(phpfpm_t)
  21. corenet_tcp_connect_sieve_port(phpfpm_t)
  22. corenet_tcp_connect_smtp_port(phpfpm_t)
  23. files_tmp_filetrans(phpfpm_t, phpfpm_tmp_t, lnk_file)
  24. apache_manage_sys_content(phpfpm_t)
  25. manage_dirs_pattern(phpfpm_t, httpd_sys_ra_content_t, httpd_sys_ra_content_t)
  26. fs_mmap_rw_hugetlbfs_files(phpfpm_t)
  27. allow phpfpm_t etc_t:file map;
  28. allow phpfpm_t httpd_sys_content_t:file map;
  29. allow phpfpm_t phpfpm_tmp_t:file map;
  30. allow phpfpm_t usr_t:file map;
  31. mta_sendmail_exec(phpfpm_t)
  32. mta_send_mail(phpfpm_t)
  33. mta_signal_system_mail(phpfpm_t)
  34. logging_send_syslog_msg(phpfpm_t)