ENT-13666: Added RHEL 10 specific SELinux policy#6035
Open
aleksandrychev wants to merge 1 commit intocfengine:masterfrom
Open
ENT-13666: Added RHEL 10 specific SELinux policy#6035aleksandrychev wants to merge 1 commit intocfengine:masterfrom
aleksandrychev wants to merge 1 commit intocfengine:masterfrom
Conversation
79bf50f to
8d52ad9
Compare
Contributor
Author
|
with this fix: |
vpodzime
reviewed
Feb 10, 2026
| @@ -0,0 +1,69 @@ | |||
| require { | |||
| type cfengine_reactor_t; | |||
Contributor
There was a problem hiding this comment.
I am suspicious about all the requires. I remember this biting us in the past. Look at other policies for hints on using macros for many includes instead.
| } | ||
|
|
||
| #============= cfengine_apachectl_t ============== | ||
| allow cfengine_apachectl_t devpts_t:dir { getattr search }; |
Contributor
There was a problem hiding this comment.
Would be interesting to compare this to a standard apache httpd policy.
Contributor
Author
There was a problem hiding this comment.
devpts_t:dir { getattr search } — needed for ps to access terminal info, apachectl runs ps to check whether httpd processes are running.
8d52ad9 to
8b1eaf9
Compare
Ticket: ENT-13666 Signed-off-by: Ihor Aleksandrychiev <ihor.aleksandrychiev@northern.tech>
8b1eaf9 to
345d080
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ticket: ENT-13666