-
Notifications
You must be signed in to change notification settings - Fork 197
ENT-13666: Added RHEL 10 specific SELinux policy #6035
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
5b842a5 to
79bf50f
Compare
Ticket: ENT-13666 Signed-off-by: Ihor Aleksandrychiev <ihor.aleksandrychiev@northern.tech>
79bf50f to
8d52ad9
Compare
|
with this fix: |
| allow cfengine_apachectl_t user_devpts_t:chr_file getattr; | ||
|
|
||
| #============= cfengine_execd_t ============== | ||
| allow cfengine_execd_t http_port_t:tcp_socket name_connect; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Any clue why cf-execd (and cf-serverd below) want to be able to connect to HTTP? Something new in pre-eval?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
yeah, would be good to reference masterfiles. Maybe it is us trying to query the aws api in inventory!?
| @@ -0,0 +1,69 @@ | |||
| require { | |||
| type cfengine_reactor_t; | |||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I am suspicious about all the requires. I remember this biting us in the past. Look at other policies for hints on using macros for many includes instead.
| } | ||
|
|
||
| #============= cfengine_apachectl_t ============== | ||
| allow cfengine_apachectl_t devpts_t:dir { getattr search }; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Would be interesting to compare this to a standard apache httpd policy.
| allow cfengine_apachectl_t user_devpts_t:chr_file getattr; | ||
|
|
||
| #============= cfengine_execd_t ============== | ||
| allow cfengine_execd_t http_port_t:tcp_socket name_connect; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
yeah, would be good to reference masterfiles. Maybe it is us trying to query the aws api in inventory!?
Ticket: ENT-13666