From 70924e6a89354d7e76220cea5e89abb5cc76fd29 Mon Sep 17 00:00:00 2001 From: Ralph Bean Date: Wed, 1 Oct 2014 20:09:53 +0000 Subject: [PATCH] Let collectd run bash scripts. --- roles/collectd/base/files/selinux/fi-collectd.te | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/roles/collectd/base/files/selinux/fi-collectd.te b/roles/collectd/base/files/selinux/fi-collectd.te index 14526f9e52..b92934f184 100644 --- a/roles/collectd/base/files/selinux/fi-collectd.te +++ b/roles/collectd/base/files/selinux/fi-collectd.te @@ -1,5 +1,5 @@ -module fi-collectd 1.6; +module fi-collectd 1.7; require { type var_run_t; @@ -22,3 +22,4 @@ allow collectd_t init_t:unix_stream_socket connectto; allow collectd_t pstorefs_t:dir getattr; allow collectd_t self:capability { setuid dac_read_search sys_ptrace setgid dac_override }; allow collectd_t var_run_t:sock_file { read write getattr }; +allow collectd_t shell_exec_t:file execute;