From: sven.vermeulen@siphos.be (Sven Vermeulen) Date: Tue, 22 Nov 2011 20:29:25 +0100 Subject: [refpolicy] [PATCH 1/1] Nagios monitoring needs to read mdstat Message-ID: <20111122192925.GA6106@siphos.be> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com In order to succesfully monitor RAID states, the nrpe agent (running in the nrpe_t domain) needs read access to /proc/mdstat. Signed-off-by: Sven Vermeulen --- nagios.te | 3 ++- 1 files changed, 2 insertions(+), 1 deletions(-) diff --git a/nagios.te b/nagios.te index 07017da..6b2c0dd 100644 --- a/nagios.te +++ b/nagios.te @@ -193,8 +193,9 @@ files_search_etc(nrpe_t) manage_files_pattern(nrpe_t, nrpe_var_run_t, nrpe_var_run_t) files_pid_filetrans(nrpe_t, nrpe_var_run_t, file) -kernel_read_system_state(nrpe_t) kernel_read_kernel_sysctls(nrpe_t) +kernel_read_software_raid_state(nrpe_t) +kernel_read_system_state(nrpe_t) corecmd_exec_bin(nrpe_t) corecmd_exec_shell(nrpe_t) -- 1.7.3.4