File selinux/rocketgit.fc changed (mode: 100644) (index 12ca71b..157316e) |
6 |
6 |
/etc/rocketgit(/.*)? gen_context(system_u:object_r:rocketgit_conf_t,s0) |
/etc/rocketgit(/.*)? gen_context(system_u:object_r:rocketgit_conf_t,s0) |
7 |
7 |
|
|
8 |
8 |
/var/log/rocketgit(/.*)? gen_context(system_u:object_r:rocketgit_log_t,s0) |
/var/log/rocketgit(/.*)? gen_context(system_u:object_r:rocketgit_log_t,s0) |
9 |
|
/var/log/rocketgit-web(/.*)? gen_context(system_u:object_r:httpd_log_t,s0) |
|
10 |
9 |
|
|
11 |
10 |
/var/lib/rocketgit(/.*)? gen_context(system_u:object_r:rocketgit_var_t,s0) |
/var/lib/rocketgit(/.*)? gen_context(system_u:object_r:rocketgit_var_t,s0) |
12 |
11 |
/var/lib/rocketgit/locks(/.*)? gen_context(system_u:object_r:rocketgit_lock_t,s0) |
/var/lib/rocketgit/locks(/.*)? gen_context(system_u:object_r:rocketgit_lock_t,s0) |
File selinux/rocketgit.te.tmpl changed (mode: 100644) (index 954ee06..b6ce855) |
1 |
|
policy_module(rocketgit,1.0.104) |
|
|
1 |
|
policy_module(rocketgit,1.0.105) |
2 |
2 |
|
|
3 |
3 |
######################################## |
######################################## |
4 |
4 |
# |
# |
|
... |
... |
read_files_pattern(httpd_t, rocketgit_usr_t, rocketgit_usr_t) |
105 |
105 |
type rocketgit_log_t; |
type rocketgit_log_t; |
106 |
106 |
files_type(rocketgit_log_t) |
files_type(rocketgit_log_t) |
107 |
107 |
manage_files_pattern(rocketgit_t, rocketgit_log_t, rocketgit_log_t) |
manage_files_pattern(rocketgit_t, rocketgit_log_t, rocketgit_log_t) |
|
108 |
|
# Allow httpd(php-fpm) to create log files - note that it will run as |
|
109 |
|
# 'rocketgit' user. |
|
110 |
|
manage_files_pattern(httpd_t, rocketgit_log_t, rocketgit_log_t) |
108 |
111 |
logging_log_filetrans(rocketgit_t, rocketgit_log_t, file) |
logging_log_filetrans(rocketgit_t, rocketgit_log_t, file) |
109 |
112 |
# below line tries to allow httpd to create err-* files in /var/log/rocketgit-web |
# below line tries to allow httpd to create err-* files in /var/log/rocketgit-web |
110 |
113 |
#filetrans_pattern(httpd_t,dirtype?,rocketgit_log_t, file) |
#filetrans_pattern(httpd_t,dirtype?,rocketgit_log_t, file) |