module nagios_hostname 1.0; require { type nagios_t; type hostname_exec_t; class file { read getattr open execute execute_no_trans }; } #============= nagios_t ============== allow nagios_t hostname_exec_t:file { read getattr open execute execute_no_trans };