type sysfs_t;
type var_log_t;
type man_t;
+
class capability2 block_suspend;
class dir { open read search };
class file { execute execute_no_trans getattr open read write };
allow passenger_t self:tcp_socket listen;
allow passenger_t var_log_t:lnk_file read;
-# passenger_native_support.so
+# compiling and using passenger_native_support.so
+# (not needed for rOCCI-server package in Fedora/EPEL)
allow passenger_t passenger_var_run_t:file execute;
# not audited rules :-(