## System log analyzer and reporter. ######################################## ## ## Read logwatch temporary files. ## ## ## ## Domain allowed access. ## ## # interface(`logwatch_read_tmp_files',` gen_require(` type logwatch_tmp_t; ') files_search_tmp($1) allow $1 logwatch_tmp_t:file read_file_perms; ') ######################################## ## ## Search logwatch cache directories. ## ## ## ## Domain allowed access. ## ## # interface(`logwatch_search_cache_dir',` gen_require(` type logwatch_cache_t; ') files_search_var($1) allow $1 logwatch_cache_t:dir search_dir_perms; ') ####################################### ## ## Dontaudit read and write an leaked file descriptors ## ## ## ## Domain to not audit. ## ## # interface(`logwatch_dontaudit_leaks',` gen_require(` type logwatch_t; ') dontaudit $1 logwatch_t:fifo_file { read write }; ') ######################################## ## ## Create, read, write, and delete ## svirt cache files. ## ## ## ## Domain allowed access. ## ## # interface(`logwatch_manage_cache',` gen_require(` type logwatch_cache_t; ') files_search_var($1) manage_files_pattern($1, logwatch_cache_t, logwatch_cache_t) manage_dirs_pattern($1, logwatch_cache_t, logwatch_cache_t) ')