Hello,
Petr Lautrbach wrote:
So in your system you already have something unconstrained what created the sock_file.
OK.
Does anyone know if an existing boolean covers the need for nginx to be able to open a unix domain socket file?
If not, I'd like to propose adding such a boolean, so I would submit a ticket in a relevant system. Would that system be https://github.com/SELinuxProject/refpolicy, or Red Hat's bugzilla, or yet another system?
--
Kind regards,
Troels Arvin
_______________________________________________ selinux mailing list -- selinux@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to selinux-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/selinux@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure