diff --git a/roles/collectd/base/files/selinux/fi-collectd.mod b/roles/collectd/base/files/selinux/fi-collectd.mod index 9247a19bf7..83b8da15db 100644 Binary files a/roles/collectd/base/files/selinux/fi-collectd.mod and b/roles/collectd/base/files/selinux/fi-collectd.mod differ diff --git a/roles/collectd/base/files/selinux/fi-collectd.pp b/roles/collectd/base/files/selinux/fi-collectd.pp index 67a5db1f6f..ea6ef6d380 100644 Binary files a/roles/collectd/base/files/selinux/fi-collectd.pp and b/roles/collectd/base/files/selinux/fi-collectd.pp differ diff --git a/roles/collectd/base/files/selinux/fi-collectd.te b/roles/collectd/base/files/selinux/fi-collectd.te index b3a7375621..51bc23d090 100644 --- a/roles/collectd/base/files/selinux/fi-collectd.te +++ b/roles/collectd/base/files/selinux/fi-collectd.te @@ -1,5 +1,5 @@ -module fi-collectd 1.2; +module fi-collectd 1.3; require { type bin_t; @@ -7,12 +7,12 @@ require { type pstorefs_t; type collectd_t; class capability { setuid dac_read_search sys_ptrace setgid dac_override }; - class file { read execute }; + class file { read execute execute_no_trans }; class dir getattr; } #============= collectd_t ============== -allow collectd_t bin_t:file execute; +allow collectd_t bin_t:file { execute execute_no_trans }; allow collectd_t configfs_t:dir getattr; allow collectd_t pstorefs_t:dir getattr; allow collectd_t self:capability { setuid dac_read_search sys_ptrace setgid dac_override };