From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Wed, 8 Feb 2012 15:37:49 -0500 Subject: [refpolicy] [PATCH 1/1] Nagios monitoring needs to read mdstat In-Reply-To: <20111122192925.GA6106@siphos.be> References: <20111122192925.GA6106@siphos.be> Message-ID: <4F32DD1D.1070609@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 11/22/11 14:29, Sven Vermeulen wrote: > In order to succesfully monitor RAID states, the nrpe agent (running in > the nrpe_t domain) needs read access to /proc/mdstat. Merged. > Signed-off-by: Sven Vermeulen > --- > nagios.te | 3 ++- > 1 files changed, 2 insertions(+), 1 deletions(-) > > diff --git a/nagios.te b/nagios.te > index 07017da..6b2c0dd 100644 > --- a/nagios.te > +++ b/nagios.te > @@ -193,8 +193,9 @@ files_search_etc(nrpe_t) > manage_files_pattern(nrpe_t, nrpe_var_run_t, nrpe_var_run_t) > files_pid_filetrans(nrpe_t, nrpe_var_run_t, file) > > -kernel_read_system_state(nrpe_t) > kernel_read_kernel_sysctls(nrpe_t) > +kernel_read_software_raid_state(nrpe_t) > +kernel_read_system_state(nrpe_t) > > corecmd_exec_bin(nrpe_t) > corecmd_exec_shell(nrpe_t) -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com