From 507a1492ae93134dda636eda8b3780b655e394fb Mon Sep 17 00:00:00 2001 From: Ralph Bean Date: Fri, 18 Jul 2014 19:46:33 +0000 Subject: [PATCH] Also, this. --- .../base/files/selinux/fi-collectd.mod | Bin 1425 -> 1439 bytes .../base/files/selinux/fi-collectd.pp | Bin 1441 -> 1455 bytes .../base/files/selinux/fi-collectd.te | 6 +++--- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/roles/collectd/base/files/selinux/fi-collectd.mod b/roles/collectd/base/files/selinux/fi-collectd.mod index a5bf03c63894b634821e834097f7af2b73b980f5..e37ce5c8674af964558be4a8f57f028e15640053 100644 GIT binary patch delta 127 zcmbQpJ)e7m1Eb+Y$0}A<1_lP!i3dbIK#Y{c9ufcm delta 109 zcmZ3_y^woC0HeXgz$#W21_lO}i5EnzK#Y{cn+a diff --git a/roles/collectd/base/files/selinux/fi-collectd.te b/roles/collectd/base/files/selinux/fi-collectd.te index 5c01df0df8..afc648d56f 100644 --- a/roles/collectd/base/files/selinux/fi-collectd.te +++ b/roles/collectd/base/files/selinux/fi-collectd.te @@ -1,11 +1,11 @@ -module fi-collectd 1.0; +module fi-collectd 1.1; require { type configfs_t; type pstorefs_t; type collectd_t; - class capability { dac_read_search sys_ptrace setgid dac_override }; + class capability { setuid dac_read_search sys_ptrace setgid dac_override }; class file read; class dir getattr; } @@ -13,4 +13,4 @@ require { #============= collectd_t ============== allow collectd_t configfs_t:dir getattr; allow collectd_t pstorefs_t:dir getattr; -allow collectd_t self:capability { dac_read_search sys_ptrace setgid dac_override }; +allow collectd_t self:capability { setuid dac_read_search sys_ptrace setgid dac_override };