Index: apparmor-profiles-2.3/apparmor.d/sbin.syslog-ng =================================================================== --- apparmor-profiles-2.3.orig/apparmor.d/sbin.syslog-ng +++ apparmor-profiles-2.3/apparmor.d/sbin.syslog-ng @@ -19,12 +19,14 @@ #include #include #include + #include capability chown, capability dac_override, capability fsetid, capability fowner, capability sys_tty_config, + capability sys_resource, /dev/log w, /dev/syslog w, @@ -35,11 +37,14 @@ /etc/hosts.deny r, /etc/hosts.allow r, /sbin/syslog-ng mr, + /usr/share/syslog-ng/** r, # chrooted applications @{CHROOT_BASE}/var/lib/*/dev/log w, - @{CHROOT_BASE}/var/lib/syslog-ng/syslog-ng.persist rw, + @{CHROOT_BASE}/var/lib/syslog-ng/syslog-ng.persist* rw, @{CHROOT_BASE}/var/log/** w, @{CHROOT_BASE}/var/run/syslog-ng.pid krw, + @{CHROOT_BASE}/var/run/syslog-ng.ctl rw, + /var/run/syslog-ng/additional-log-sockets.conf r, }