1
# $Id: usr.sbin.lighttpd 90 2006-08-04 19:13:59Z seth_arnold $
2
# ------------------------------------------------------------------
4
# Copyright (C) 2002-2005 Novell/SUSE
6
# This program is free software; you can redistribute it and/or
7
# modify it under the terms of version 2 of the GNU General Public
8
# License published by the Free Software Foundation.
10
# ------------------------------------------------------------------
13
#include <tunables/global>
16
#include <abstractions/base>
17
#include <abstractions/nameservice>
18
#include <abstractions/web-data>
20
# needed to change max file descriptors
21
capability sys_resource,
24
capability net_bind_service,
26
# changing the uid/gid on startup
30
/proc/sys/kernel/ngroups_max r,
33
/etc/lighttpd/*.conf r,
34
/etc/lighttpd/conf.d/*.conf r,
35
/etc/lighttpd/auth.d/* r,
36
/etc/lighttpd/vhosts.d r,
37
/etc/lighttpd/vhosts.d/* r,
38
/usr/sbin/lighttpd mix,
40
/usr/lib/lighttpd/*.so mr,
41
/usr/lib64/lighttpd/*.so mr,
43
/etc/ssl/private/*.pem r,
44
# home dir. e.g. used for sockets.
46
/var/lib/lighttpd/** rwl,
48
/var/cache/lighttpd/ r,
49
/var/cache/lighttpd/** rwl,
51
/var/run/lighttpd.pid rwl,
53
/var/log/lighttpd/*.log rw,