2014-05-07 22:27:00 +00:00
|
|
|
/usr/sbin/mosquitto {
|
|
|
|
#include <abstractions/base>
|
|
|
|
#include <abstractions/nameservice>
|
|
|
|
|
|
|
|
/usr/sbin/mosquitto r,
|
|
|
|
/etc/mosquitto/mosquitto.conf r,
|
|
|
|
/etc/mosquitto/ca_certificates/* r,
|
2014-07-28 08:22:20 +00:00
|
|
|
/etc/mosquitto/certs/* r,
|
2014-05-07 22:27:00 +00:00
|
|
|
/etc/mosquitto/conf.d/* r,
|
|
|
|
/var/lib/mosquitto/ r,
|
|
|
|
/var/lib/mosquitto/mosquitto.db rwk,
|
2020-12-27 23:05:53 +00:00
|
|
|
/var/lib/mosquitto/mosquitto.db.new rwk,
|
2014-05-07 22:27:00 +00:00
|
|
|
/var/run/mosquitto.pid rw,
|
|
|
|
|
|
|
|
network inet stream,
|
|
|
|
network inet6 stream,
|
|
|
|
network inet dgram,
|
|
|
|
network inet6 dgram,
|
|
|
|
|
|
|
|
# For drop privileges
|
|
|
|
capability setgid,
|
|
|
|
capability setuid,
|
|
|
|
|
|
|
|
# For tcp-wrappers
|
|
|
|
/lib{,32,64}/libwrap.so* rm,
|
|
|
|
/etc/hosts.allow r,
|
|
|
|
/etc/hosts.deny r,
|
|
|
|
}
|