/usr/sbin/mcelog -- gen_context(system_u:object_r:mcelog_exec_t,s0)
-/var/run/mcelog-client -s gen_context(system_u:object_r:mcelog_var_run_t,s0)
+/var/log/mcelog.* -- gen_context(system_u:object_r:mcelog_log_t,s0)
+/var/run/mcelog-client -s gen_context(system_u:object_r:mcelog_var_run_t,s0)
type mcelog_var_run_t;
files_pid_file(mcelog_var_run_t)
+type mcelog_log_t;
+logging_log_file(mcelog_log_t)
+
########################################
#
# mcelog local policy
allow mcelog_t self:capability sys_admin;
+manage_files_pattern(mcelog_t, mcelog_log_t, mcelog_log_t)
+manage_dirs_pattern(mcelog_t, mcelog_log_t, mcelog_log_t)
+logging_log_filetrans(mcelog_t, mcelog_log_t, { file dir })
+
manage_files_pattern(mcelog_t, mcelog_var_run_t, mcelog_var_run_t)
manage_dirs_pattern(mcelog_t, mcelog_var_run_t, mcelog_var_run_t)
manage_sock_files_pattern(mcelog_t, mcelog_var_run_t, mcelog_var_run_t)
/var/spool/fcron/new\.systab -- gen_context(system_u:object_r:system_cron_spool_t,s0)
/var/lib/glpi/files(/.*)? gen_context(system_u:object_r:cron_var_lib_t,s0)
-
-/var/log/mcelog.* -- gen_context(system_u:object_r:cron_log_t,s0)