Skip to content

Commit 45ea0fe

Browse files
committed
Adjusted CFEngine SELinux policy to allow cf-execd to run ps command with policy version 33
Apparently, ps command running with SELinux kernel policy version 33 requires self:cap_userns sys_ptrace. Ticket: ENT-12446 Changelog: title
1 parent e8e1c84 commit 45ea0fe

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

misc/selinux/cfengine-enterprise.te.all

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -229,6 +229,7 @@ allow cfengine_execd_t cfengine_reactor_exec_t:file getattr;
229229
allow cfengine_execd_t cfengine_var_lib_t:sock_file { create unlink getattr setattr };
230230

231231
allow cfengine_execd_t self:capability sys_ptrace;
232+
allow cfengine_execd_t self:cap_userns sys_ptrace;
232233

233234
allow cfengine_execd_t crontab_exec_t:file getattr;
234235
allow cfengine_execd_t dmidecode_exec_t:file getattr;

0 commit comments

Comments
 (0)