2 policy_module(abrt, 1.0.0)
4 ########################################
11 init_daemon_domain(abrt_t, abrt_exec_t)
13 type abrt_initrc_exec_t;
14 init_script_file(abrt_initrc_exec_t)
18 files_config_file(abrt_etc_t)
22 logging_log_file(abrt_var_log_t)
26 files_tmp_file(abrt_tmp_t)
29 type abrt_var_cache_t;
30 files_type(abrt_var_cache_t)
34 files_pid_file(abrt_var_run_t)
36 ########################################
41 allow abrt_t self:capability { setuid setgid sys_nice dac_override };
42 allow abrt_t self:process { signal signull setsched getsched };
44 allow abrt_t self:fifo_file rw_fifo_file_perms;
45 allow abrt_t self:tcp_socket create_stream_socket_perms;
46 allow abrt_t self:udp_socket create_socket_perms;
47 allow abrt_t self:unix_dgram_socket create_socket_perms;
48 allow abrt_t self:netlink_route_socket r_netlink_socket_perms;
51 rw_files_pattern(abrt_t, abrt_etc_t, abrt_etc_t)
54 manage_files_pattern(abrt_t, abrt_var_log_t, abrt_var_log_t)
55 logging_log_filetrans(abrt_t, abrt_var_log_t, file)
58 manage_dirs_pattern(abrt_t, abrt_tmp_t, abrt_tmp_t)
59 manage_files_pattern(abrt_t, abrt_tmp_t, abrt_tmp_t)
60 files_tmp_filetrans(abrt_t, abrt_tmp_t, { file dir })
62 # abrt var/cache files
63 manage_files_pattern(abrt_t, abrt_var_cache_t, abrt_var_cache_t)
64 manage_dirs_pattern(abrt_t, abrt_var_cache_t, abrt_var_cache_t)
65 files_var_filetrans(abrt_t, abrt_var_cache_t, { file dir })
68 manage_files_pattern(abrt_t, abrt_var_run_t, abrt_var_run_t)
69 manage_dirs_pattern(abrt_t, abrt_var_run_t, abrt_var_run_t)
70 files_pid_filetrans(abrt_t, abrt_var_run_t, { file dir })
72 kernel_read_ring_buffer(abrt_t)
73 kernel_read_system_state(abrt_t)
74 kernel_rw_kernel_sysctl(abrt_t)
76 corecmd_exec_bin(abrt_t)
77 corecmd_exec_shell(abrt_t)
79 corenet_tcp_connect_http_port(abrt_t)
81 dev_read_urand(abrt_t)
83 files_getattr_all_files(abrt_t)
84 files_read_etc_files(abrt_t)
85 files_read_usr_files(abrt_t)
87 fs_list_inotifyfs(abrt_t)
88 fs_getattr_all_fs(abrt_t)
89 fs_getattr_all_dirs(abrt_t)
91 sysnet_read_config(abrt_t)
93 logging_read_generic_logs(abrt_t)
94 logging_send_syslog_msg(abrt_t)
96 miscfiles_read_certs(abrt_t)
97 miscfiles_read_localization(abrt_t)
99 # to run bugzilla plugin
100 # read ~/.abrt/Bugzilla.conf
101 userdom_read_user_home_content_files(abrt_t)
104 dbus_connect_system_bus(abrt_t)
105 dbus_system_bus_client(abrt_t)
108 # to install debuginfo packages
110 rpm_manage_db(abrt_t)
114 # to run mailx plugin
116 sendmail_domtrans(abrt_t)