|
|
@ -1,4 +1,4 @@ |
|
|
|
module zabbix-server 1.3; |
|
|
|
module zabbix-server 1.4; |
|
|
|
|
|
|
|
|
|
|
|
require { |
|
|
|
require { |
|
|
|
type devlog_t; |
|
|
|
type devlog_t; |
|
|
@ -12,7 +12,7 @@ require { |
|
|
|
class capability { sys_resource audit_write }; |
|
|
|
class capability { sys_resource audit_write }; |
|
|
|
class file { execute read create ioctl execute_no_trans write getattr unlink open }; |
|
|
|
class file { execute read create ioctl execute_no_trans write getattr unlink open }; |
|
|
|
class netlink_audit_socket { nlmsg_relay create }; |
|
|
|
class netlink_audit_socket { nlmsg_relay create }; |
|
|
|
class sock_file { create write}; |
|
|
|
class sock_file { create write unlink }; |
|
|
|
class unix_dgram_socket { create connect sendto }; |
|
|
|
class unix_dgram_socket { create connect sendto }; |
|
|
|
class dir { write remove_name add_name }; |
|
|
|
class dir { write remove_name add_name }; |
|
|
|
class key write; |
|
|
|
class key write; |
|
|
@ -31,4 +31,4 @@ allow zabbix_t syslogd_t:unix_dgram_socket sendto; |
|
|
|
allow zabbix_t zabbix_var_lib_t:dir { write remove_name add_name }; |
|
|
|
allow zabbix_t zabbix_var_lib_t:dir { write remove_name add_name }; |
|
|
|
allow zabbix_t zabbix_var_lib_t:file { execute read create getattr execute_no_trans write ioctl unlink open }; |
|
|
|
allow zabbix_t zabbix_var_lib_t:file { execute read create getattr execute_no_trans write ioctl unlink open }; |
|
|
|
allow zabbix_t self:unix_stream_socket connectto; |
|
|
|
allow zabbix_t self:unix_stream_socket connectto; |
|
|
|
allow zabbix_t zabbix_var_run_t:sock_file create; |
|
|
|
allow zabbix_t zabbix_var_run_t:sock_file { create write unlink }; |
|
|
|