Skip to content

Commit dc44e14

Browse files
committed
Fix avc denials
1 parent 8861616 commit dc44e14

File tree

1 file changed

+16
-0
lines changed

1 file changed

+16
-0
lines changed

grafana.te

+16
Original file line numberDiff line numberDiff line change
@@ -87,6 +87,22 @@ allow grafana_t grafana_port_t:tcp_socket { name_bind name_connect };
8787

8888
allow grafana_t self:unix_stream_socket connectto;
8989

90+
optional_policy(`
91+
require {
92+
type smtp_port_t;
93+
class tcp_socket { name_connect };
94+
}
95+
allow grafana_t smtp_port_t:tcp_socket name_connect;
96+
')
97+
98+
optional_policy(`
99+
require {
100+
type usr_t;
101+
class file { execute };
102+
}
103+
allow grafana_t usr_t:file execute;
104+
')
105+
90106
manage_dirs_pattern(grafana_t, grafana_conf_t, grafana_conf_t)
91107
manage_files_pattern(grafana_t, grafana_conf_t, grafana_conf_t)
92108

0 commit comments

Comments
 (0)