From 977bb115b7ae60aaa7910904965dc3cf9f7cd581 Mon Sep 17 00:00:00 2001 From: Eric Renfro Date: Mon, 9 Nov 2015 02:50:17 -0500 Subject: [PATCH] Tuned tcp_socket per audit2allow seperation --- mlogc.te | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/mlogc.te b/mlogc.te index 6760742..2d36337 100644 --- a/mlogc.te +++ b/mlogc.te @@ -1,5 +1,5 @@ -policy_module(mlogc,1.0.40) +policy_module(mlogc,1.0.41) ######################################## # @@ -104,7 +104,11 @@ allow httpd_t mlogc_log_t:file { write create open }; #============= mlogc_t ============== -allow mlogc_t http_port_t:tcp_socket { create connect name_connect getopt getattr setopt }; +allow mlogc_t http_port_t:tcp_socket name_connect; +allow mlogc_t self:tcp_socket { write read }; +allow mlogc_t self:tcp_socket { connect getopt getattr create setopt }; + +#allow mlogc_t http_port_t:tcp_socket { create connect name_connect getopt getattr setopt }; #allow mlogc_t cert_t:dir { write getattr }; #allow mlogc_t cert_t:file { read write getattr open lock };