diff --git a/roles/mirrormanager/mirrorlist_proxy/files/selinux/mirrorlist-logrotate.mod b/roles/mirrormanager/mirrorlist_proxy/files/selinux/mirrorlist-logrotate.mod index 49ca37b8d4..017ad3d338 100644 Binary files a/roles/mirrormanager/mirrorlist_proxy/files/selinux/mirrorlist-logrotate.mod and b/roles/mirrormanager/mirrorlist_proxy/files/selinux/mirrorlist-logrotate.mod differ diff --git a/roles/mirrormanager/mirrorlist_proxy/files/selinux/mirrorlist-logrotate.pp b/roles/mirrormanager/mirrorlist_proxy/files/selinux/mirrorlist-logrotate.pp index f4be1215e3..64e047ef03 100644 Binary files a/roles/mirrormanager/mirrorlist_proxy/files/selinux/mirrorlist-logrotate.pp and b/roles/mirrormanager/mirrorlist_proxy/files/selinux/mirrorlist-logrotate.pp differ diff --git a/roles/mirrormanager/mirrorlist_proxy/files/selinux/mirrorlist-logrotate.te b/roles/mirrormanager/mirrorlist_proxy/files/selinux/mirrorlist-logrotate.te index 1028deb976..f464c2cb47 100644 --- a/roles/mirrormanager/mirrorlist_proxy/files/selinux/mirrorlist-logrotate.te +++ b/roles/mirrormanager/mirrorlist_proxy/files/selinux/mirrorlist-logrotate.te @@ -3,10 +3,10 @@ module mirrorlist-logrotate 1.0; require { type logrotate_t; type svirt_sandbox_file_t; - class file { setattr create write }; + class file { setattr create write unlink }; class dir { write add_name remove_name }; } #============= logrotate_t ============== allow logrotate_t svirt_sandbox_file_t:dir { add_name remove_name write }; -allow logrotate_t svirt_sandbox_file_t:file { setattr create write }; +allow logrotate_t svirt_sandbox_file_t:file { setattr create write unlink };