1
# ------------------------------------------------------------------
3
# Copyright (C) 2002-2005 Novell/SUSE
5
# This program is free software; you can redistribute it and/or
6
# modify it under the terms of version 2 of the GNU General Public
7
# License published by the Free Software Foundation.
9
# ------------------------------------------------------------------
12
#include <tunables/global>
15
#include <abstractions/base>
16
#include <abstractions/nameservice>
17
#include <abstractions/web-data>
19
# needed to change max file descriptors
20
capability sys_resource,
23
capability net_bind_service,
25
# changing the uid/gid on startup
30
/etc/lighttpd/*.conf r,
31
/etc/lighttpd/conf.d/*.conf r,
32
/etc/lighttpd/auth.d/* r,
33
/etc/lighttpd/vhosts.d r,
34
/etc/lighttpd/vhosts.d/* r,
35
/usr/sbin/lighttpd mix,
37
/usr/lib/lighttpd/*.so mr,
38
/usr/lib64/lighttpd/*.so mr,
40
/etc/ssl/private/*.pem r,
41
# home dir. e.g. used for sockets.
43
/var/lib/lighttpd/** rwl,
45
/var/cache/lighttpd/ r,
46
/var/cache/lighttpd/** rwl,
48
/var/run/lighttpd.pid rwl,
50
/var/log/lighttpd/*.log rw,