1 |
commit: 6b7f2fdba7706b4859e2d63c4b8ef887b61d6bbd |
2 |
Author: Laurent Bigonville <bigon <AT> bigon <DOT> be> |
3 |
AuthorDate: Wed Dec 16 18:19:30 2015 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Sat Jan 30 17:02:52 2016 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=6b7f2fdb |
7 |
|
8 |
Allow syslogd_t to read sysctl_vm_overcommit_t |
9 |
|
10 |
policy/modules/system/logging.te | 3 ++- |
11 |
1 file changed, 2 insertions(+), 1 deletion(-) |
12 |
|
13 |
diff --git a/policy/modules/system/logging.te b/policy/modules/system/logging.te |
14 |
index 7b6b6fb..f2e4984 100644 |
15 |
--- a/policy/modules/system/logging.te |
16 |
+++ b/policy/modules/system/logging.te |
17 |
@@ -418,7 +418,8 @@ kernel_read_kernel_sysctls(syslogd_t) |
18 |
kernel_read_proc_symlinks(syslogd_t) |
19 |
# Allow access to /proc/kmsg for syslog-ng |
20 |
kernel_read_messages(syslogd_t) |
21 |
-kernel_read_vm_sysctls(syslogd_t) |
22 |
+# rsyslog |
23 |
+kernel_read_vm_overcommit_sysctl(syslogd_t) |
24 |
kernel_clear_ring_buffer(syslogd_t) |
25 |
kernel_change_ring_buffer_level(syslogd_t) |
26 |
# Read ring buffer for journald |