diff --git a/INSTALL/misplogrotate.te b/INSTALL/misplogrotate.te index 921989772..80b2eb945 100644 --- a/INSTALL/misplogrotate.te +++ b/INSTALL/misplogrotate.te @@ -7,10 +7,10 @@ require { type httpd_sys_content_t; type httpd_sys_rw_content_t; class dir { ioctl read getattr lock search open remove_name }; - class file { unlink write }; + class file { unlink write rename }; } #============= logrotate_t ============== allow logrotate_t httpd_sys_content_t:dir { ioctl read getattr lock search open }; allow logrotate_t httpd_sys_rw_content_t:dir { ioctl read getattr lock search open }; allow httpd_t httpd_log_t:dir remove_name; -allow { httpd_t httpd_sys_script_t } httpd_log_t:file { unlink write }; +allow { httpd_t httpd_sys_script_t } httpd_log_t:file { unlink write rename };