~ubuntu-branches/ubuntu/wily/apparmor/wily

« back to all changes in this revision

Viewing changes to profiles/apparmor.d/sbin.syslog-ng

  • Committer: Bazaar Package Importer
  • Author(s): Kees Cook
  • Date: 2011-04-27 10:38:07 UTC
  • mfrom: (5.1.118 natty)
  • Revision ID: james.westby@ubuntu.com-20110427103807-ym3rhwys6o84ith0
Tags: 2.6.1-2
debian/copyright: clarify for some full organization names.

Show diffs side-by-side

added added

removed removed

Lines of Context:
 
1
# ------------------------------------------------------------------
 
2
#
 
3
#    Copyright (C) 2006-2009 Novell/SUSE
 
4
#    Copyright (C) 2006 Christian Boltz
 
5
#    Copyright (C) 2010 Canonical Ltd.
 
6
#
 
7
#    This program is free software; you can redistribute it and/or
 
8
#    modify it under the terms of version 2 of the GNU General Public
 
9
#    License published by the Free Software Foundation.
 
10
#
 
11
# ------------------------------------------------------------------
 
12
 
 
13
#include <tunables/global>
 
14
 
 
15
#define this to be where syslog-ng is chrooted
 
16
@{CHROOT_BASE}=""
 
17
 
 
18
/sbin/syslog-ng {
 
19
  #include <abstractions/base>
 
20
  #include <abstractions/consoles>
 
21
  #include <abstractions/nameservice>
 
22
 
 
23
  capability chown,
 
24
  capability dac_override,
 
25
  capability fsetid,
 
26
  capability fowner,
 
27
  capability sys_tty_config,
 
28
 
 
29
  /dev/log w,
 
30
  /dev/syslog w,
 
31
  /dev/tty10 rw,
 
32
  /dev/xconsole rw,
 
33
  /etc/syslog-ng/* r,
 
34
  @{PROC}/kmsg r,
 
35
  /etc/hosts.deny r,
 
36
  /etc/hosts.allow r,
 
37
  /sbin/syslog-ng mr,
 
38
  # chrooted applications
 
39
  @{CHROOT_BASE}/var/lib/*/dev/log w,
 
40
  @{CHROOT_BASE}/var/lib/syslog-ng/syslog-ng.persist rw,
 
41
  @{CHROOT_BASE}/var/log/** w,
 
42
  @{CHROOT_BASE}/var/run/syslog-ng.pid krw,
 
43
 
 
44
  # Site-specific additions and overrides. See local/README for details.
 
45
  #include <local/sbin.syslog-ng>
 
46
}