Skip to content

Commit b032da2

Browse files
committed
Fix postgresql AVC denials
1 parent ca30a45 commit b032da2

File tree

1 file changed

+11
-0
lines changed

1 file changed

+11
-0
lines changed

grafana.te

+11
Original file line numberDiff line numberDiff line change
@@ -105,6 +105,17 @@ optional_policy(`
105105
allow grafana_t usr_t:file execute;
106106
')
107107

108+
optional_policy(`
109+
require {
110+
type postgresql_t;
111+
type postgresql_var_run_t;
112+
class unix_stream_socket { connectto };
113+
class sock_file { write };
114+
}
115+
allow grafana_t postgresql_t:unix_stream_socket connectto;
116+
allow grafana_t postgresql_var_run_t:sock_file write;
117+
')
118+
108119
manage_dirs_pattern(grafana_t, grafana_conf_t, grafana_conf_t)
109120
manage_files_pattern(grafana_t, grafana_conf_t, grafana_conf_t)
110121

0 commit comments

Comments
 (0)