Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow syslog append to public_content_rw_t #477

Merged
merged 3 commits into from Nov 20, 2020

Conversation

zpytela
Copy link
Contributor

@zpytela zpytela commented Nov 11, 2020

No description provided.

In customized configurations with rsyslog writing to files
with a non-standard path, the service is not allowed to search
the logfile parent directories. To enable export of the logs,
labeled public_content_rw_t, using http or ftp it also needs
append permissions to files with the public_content_rw_t type.

Since this commit, the rulesets described above are allowed conditionally
with turning on the logging_syslogd_append_public_content tunable
which is off by default.

Resolves: rhbz#1823672
@zpytela
Copy link
Contributor Author

zpytela commented Nov 20, 2020

Verified using a policy scratch build.

@zpytela zpytela merged commit 0625fa6 into fedora-selinux:rawhide Nov 20, 2020
@zpytela zpytela deleted the fb-syslog-append branch November 20, 2020 19:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant