Changes between Version 6 and Version 7 of RubyCASServer
- Timestamp:
- Feb 7, 2012 12:27:18 PM (13 years ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
RubyCASServer
v6 v7 124 124 125 125 require { 126 type unconfined_t;127 type automount_t;128 type rpcbind_t;126 type httpd_t; 127 type mysqld_port_t; 128 type passenger_t; 129 129 type passenger_tmp_t; 130 130 type var_log_t; 131 type httpd_t;132 type mysqld_port_t;133 type rpcd_t;134 type passenger_t;135 class sock_file { write getattr setattr create unlink };136 class tcp_socket { name_connect listen };137 131 class capability { sys_resource sys_ptrace }; 138 132 class dir { write getattr search add_name }; 139 133 class file { write getattr setattr read create open append }; 134 class sock_file { write getattr setattr create unlink }; 135 class tcp_socket { name_connect listen }; 140 136 } 141 137 … … 146 142 147 143 #============= passenger_t ============== 148 allow passenger_t automount_t:dir { getattr search };149 allow passenger_t automount_t:file { read open };150 allow passenger_t httpd_t:dir { getattr search };151 allow passenger_t httpd_t:file { read open };152 144 allow passenger_t mysqld_port_t:tcp_socket name_connect; 153 145 allow passenger_t passenger_tmp_t:sock_file { write create unlink getattr setattr }; 154 allow passenger_t rpcbind_t:dir { getattr search };155 allow passenger_t rpcbind_t:file { read open };156 allow passenger_t rpcd_t:dir { getattr search };157 allow passenger_t rpcd_t:file { read open };158 146 allow passenger_t self:capability { sys_resource sys_ptrace }; 159 allow passenger_t unconfined_t:dir { getattr search };160 allow passenger_t unconfined_t:file { read open };161 147 allow passenger_t var_log_t:file { getattr open append }; 162 148 }}}