Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nginx.te: Allow access to dac_override. #12

Open
wants to merge 1 commit into
base: next
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion policy/modules/contrib/nginx.te
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,7 @@ files_runtime_file(nginx_runtime_t)
allow nginx_t self:fifo_file rw_inherited_fifo_file_perms;
allow nginx_t self:unix_stream_socket create_stream_socket_perms;
allow nginx_t self:tcp_socket { listen accept };
allow nginx_t self:capability { setuid net_bind_service setgid chown };
allow nginx_t self:capability { dac_override setuid net_bind_service setgid chown };

# conf files
list_dirs_pattern(nginx_t, nginx_conf_t, nginx_conf_t)
Expand Down