From 8c38fba0f018ca93ba436aeace2e62afeeefa778 Mon Sep 17 00:00:00 2001 From: Chris Richards Date: Apr 24 2010 12:02:23 +0000 Subject: allow syslog-ng to setrlimit syslog-ng wants to increase the number of permissible open files from 256 to 4096 on unix/linux systems. Signed-off-by: Chris Richards Signed-off-by: Chris PeBenito --- diff --git a/policy/modules/system/logging.te b/policy/modules/system/logging.te index 1b05b64..5004241 100644 --- a/policy/modules/system/logging.te +++ b/policy/modules/system/logging.te @@ -342,7 +342,8 @@ optional_policy(` allow syslogd_t self:capability { dac_override sys_resource sys_tty_config net_admin sys_admin chown fsetid }; dontaudit syslogd_t self:capability sys_tty_config; # setpgid for metalog -allow syslogd_t self:process { signal_perms setpgid }; +# setrlimit for syslog-ng +allow syslogd_t self:process { signal_perms setpgid setrlimit }; # receive messages to be logged allow syslogd_t self:unix_dgram_socket create_socket_perms; allow syslogd_t self:unix_stream_socket create_stream_socket_perms;