allow syslog-ng to setrlimit

syslog-ng wants to increase the number of permissible open files from 256 to 4096 on unix/linux systems.

Signed-off-by: Chris Richards <gizmo@giz-works.com>
Signed-off-by: Chris PeBenito <pebenito@gentoo.org>
This commit is contained in:
Chris Richards 2010-04-16 06:29:10 +00:00 committed by Chris PeBenito
parent 5c3274d7bf
commit 8c38fba0f0

View File

@ -342,7 +342,8 @@ optional_policy(`
allow syslogd_t self:capability { dac_override sys_resource sys_tty_config net_admin sys_admin chown fsetid };
dontaudit syslogd_t self:capability sys_tty_config;
# setpgid for metalog
allow syslogd_t self:process { signal_perms setpgid };
# setrlimit for syslog-ng
allow syslogd_t self:process { signal_perms setpgid setrlimit };
# receive messages to be logged
allow syslogd_t self:unix_dgram_socket create_socket_perms;
allow syslogd_t self:unix_stream_socket create_stream_socket_perms;