Dominick Grift d4e8941
policy_module(ulogd, 1.2.1)
1ec3d1a
1ec3d1a
########################################
1ec3d1a
#
1ec3d1a
# Declarations
1ec3d1a
#
1ec3d1a
1ec3d1a
type ulogd_t;
1ec3d1a
type ulogd_exec_t;
1ec3d1a
init_daemon_domain(ulogd_t, ulogd_exec_t)
1ec3d1a
1ec3d1a
type ulogd_etc_t;
1ec3d1a
files_config_file(ulogd_etc_t)
1ec3d1a
1ec3d1a
type ulogd_initrc_exec_t;
1ec3d1a
init_script_file(ulogd_initrc_exec_t)
1ec3d1a
1ec3d1a
type ulogd_modules_t;
1ec3d1a
files_type(ulogd_modules_t)
1ec3d1a
1ec3d1a
type ulogd_var_log_t;
1ec3d1a
logging_log_file(ulogd_var_log_t)
1ec3d1a
1ec3d1a
########################################
1ec3d1a
#
Dominick Grift d4e8941
# Local policy
1ec3d1a
#
1ec3d1a
1ec3d1a
allow ulogd_t self:capability { net_admin sys_nice };
1ec3d1a
allow ulogd_t self:process { setsched };
1ec3d1a
allow ulogd_t self:netlink_nflog_socket create_socket_perms;
1ec3d1a
allow ulogd_t self:netlink_route_socket r_netlink_socket_perms;
1ec3d1a
allow ulogd_t self:netlink_socket create_socket_perms;
1ec3d1a
allow ulogd_t self:tcp_socket { create_stream_socket_perms connect };
1ec3d1a
allow ulogd_t self:udp_socket create_socket_perms;
1ec3d1a
1ec3d1a
read_files_pattern(ulogd_t, ulogd_etc_t, ulogd_etc_t)
1ec3d1a
1ec3d1a
list_dirs_pattern(ulogd_t, ulogd_modules_t, ulogd_modules_t)
1ec3d1a
mmap_files_pattern(ulogd_t, ulogd_modules_t, ulogd_modules_t)
1ec3d1a
Dominick Grift d4e8941
append_files_pattern(ulogd_t, ulogd_var_log_t, ulogd_var_log_t)
Dominick Grift d4e8941
create_files_pattern(ulogd_t, ulogd_var_log_t, ulogd_var_log_t)
Dominick Grift d4e8941
setattr_files_pattern(ulogd_t, ulogd_var_log_t, ulogd_var_log_t)
1ec3d1a
logging_log_filetrans(ulogd_t, ulogd_var_log_t, file)
1ec3d1a
1ec3d1a
1ec3d1a
Dominick Grift d4e8941
sysnet_dns_name_resolve(ulogd_t)
1ec3d1a
Dominick Grift d4e8941
optional_policy(`
1ec3d1a
	mysql_stream_connect(ulogd_t)
1ec3d1a
	mysql_tcp_connect(ulogd_t)
1ec3d1a
')
1ec3d1a
1ec3d1a
optional_policy(`
1ec3d1a
	postgresql_stream_connect(ulogd_t)
1ec3d1a
	postgresql_tcp_connect(ulogd_t)
1ec3d1a
')