diff --git a/roles/collectd/base/files/selinux/fi-collectd.mod b/roles/collectd/base/files/selinux/fi-collectd.mod index 5592941a2c..596ce3bdf5 100644 Binary files a/roles/collectd/base/files/selinux/fi-collectd.mod and b/roles/collectd/base/files/selinux/fi-collectd.mod differ diff --git a/roles/collectd/base/files/selinux/fi-collectd.pp b/roles/collectd/base/files/selinux/fi-collectd.pp index cc266245e4..c1fbadb199 100644 Binary files a/roles/collectd/base/files/selinux/fi-collectd.pp and b/roles/collectd/base/files/selinux/fi-collectd.pp differ diff --git a/roles/collectd/base/files/selinux/fi-collectd.te b/roles/collectd/base/files/selinux/fi-collectd.te index 82c1f13a11..94846dc864 100644 --- a/roles/collectd/base/files/selinux/fi-collectd.te +++ b/roles/collectd/base/files/selinux/fi-collectd.te @@ -1,4 +1,4 @@ -module fi-collectd 1.11.0; +module fi-collectd 1.11.1; require { type shell_exec_t; @@ -22,7 +22,7 @@ require { class lnk_file read; class sock_file { read write getattr }; class unix_stream_socket connectto; - class netlink_generic_socket create; + class netlink_generic_socket { create bind }; } #============= collectd_t ============== @@ -41,4 +41,4 @@ allow collectd_t var_run_t:sock_file { read write getattr }; allow collectd_t anon_inodefs_t:file { write read }; allow collectd_t initrc_t:unix_stream_socket connectto; allow collectd_t proc_net_t:lnk_file read; -allow collectd_t self:netlink_generic_socket create; +allow collectd_t self:netlink_generic_socket { create bind };