diff --git a/roles/collectd/base/files/selinux/fi-collectd.mod b/roles/collectd/base/files/selinux/fi-collectd.mod index 591c3685b8..3cb62bcb63 100644 Binary files a/roles/collectd/base/files/selinux/fi-collectd.mod and b/roles/collectd/base/files/selinux/fi-collectd.mod differ diff --git a/roles/collectd/base/files/selinux/fi-collectd.pp b/roles/collectd/base/files/selinux/fi-collectd.pp index c61021eb18..a3425f2358 100644 Binary files a/roles/collectd/base/files/selinux/fi-collectd.pp and b/roles/collectd/base/files/selinux/fi-collectd.pp differ diff --git a/roles/collectd/base/files/selinux/fi-collectd.te b/roles/collectd/base/files/selinux/fi-collectd.te index 248c2a3218..8184719164 100644 --- a/roles/collectd/base/files/selinux/fi-collectd.te +++ b/roles/collectd/base/files/selinux/fi-collectd.te @@ -1,4 +1,4 @@ -module fi-collectd 1.11.2; +module fi-collectd 1.11.3; require { type shell_exec_t; @@ -51,3 +51,4 @@ allow collectd_t self:capability chown; # Allow the CGI to request a flush of the RRDs through collectd's unix socket #============= collectd_script_t ============== allow collectd_script_t collectd_var_run_t:sock_file write; +allow collectd_script_t collectd_t:unix_stream_socket connectto;