diff --git a/toolkit/perfsonar-toolkit/selinux/perfsonar-toolkit.te b/toolkit/perfsonar-toolkit/selinux/perfsonar-toolkit.te index 4b5105ec..3eb0da6e 100644 --- a/toolkit/perfsonar-toolkit/selinux/perfsonar-toolkit.te +++ b/toolkit/perfsonar-toolkit/selinux/perfsonar-toolkit.te @@ -29,7 +29,7 @@ require { type systemd_unit_file_t; class dbus { send_msg }; class dir { ioctl read write getattr lock search open add_name remove_name }; - class file { getattr open read unlink ioctl lock execute execute_no_trans create write }; + class file { getattr open read unlink ioctl lock execute execute_no_trans create write rename }; class lnk_file { read getattr }; class system { status }; class rawip_socket { create }; @@ -101,5 +101,5 @@ allow httpd_t sysctl_net_t:file { getattr ioctl open read }; #misc allow httpd_t httpd_sys_content_t:dir { ioctl read write getattr lock search open add_name remove_name }; -allow httpd_t httpd_sys_content_t:file { create getattr ioctl open read write }; +allow httpd_t httpd_sys_content_t:file { create getattr ioctl open read write rename unlink }; allow httpd_t self:netlink_generic_socket create; \ No newline at end of file