From: Ralf Ertzinger Date: Sun, 17 Nov 2019 13:25:04 +0000 (+0000) Subject: Add httpd-unix-sock X-Git-Url: https://git.camperquake.de/gitweb.cgi?p=selinux.git;a=commitdiff_plain;h=d2b7c306571374f9aae2f6409f47f34301af490b Add httpd-unix-sock --- diff --git a/httpd-unix-sock/httpd-unix-sock.fc b/httpd-unix-sock/httpd-unix-sock.fc new file mode 100644 index 0000000..e69de29 diff --git a/httpd-unix-sock/httpd-unix-sock.if b/httpd-unix-sock/httpd-unix-sock.if new file mode 100644 index 0000000..3eb6a30 --- /dev/null +++ b/httpd-unix-sock/httpd-unix-sock.if @@ -0,0 +1 @@ +## diff --git a/httpd-unix-sock/httpd-unix-sock.te b/httpd-unix-sock/httpd-unix-sock.te new file mode 100644 index 0000000..ef11af9 --- /dev/null +++ b/httpd-unix-sock/httpd-unix-sock.te @@ -0,0 +1,10 @@ +policy_module(httpd-unix-sock, 0.0.1) + +require { + type httpd_t; + type unconfined_service_t; +} + +files_search_pids(httpd_t); +files_write_generic_pid_pipes(httpd_t); +allow httpd_t unconfined_service_t:unix_stream_socket { getattr connectto };