Skip to content

Commit

Permalink
Security: Run tendrl in SELinux enabled
Browse files Browse the repository at this point in the history
tendrl-bug-id: Tendrl#241

Signed-off-by: Timothy Asir J <[email protected]>
  • Loading branch information
TimothyAsirJeyasing committed Sep 7, 2017
1 parent b8745d9 commit 4f3735e
Showing 1 changed file with 2 additions and 5 deletions.
7 changes: 2 additions & 5 deletions specs/enable-selinux.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -121,13 +121,10 @@ allow tendrl_t self:fifo_file rw_fifo_file_perms;
allow tendrl_t self:unix_stream_socket create_stream_socket_perms;
allow tendrl_t self:tcp_socket { accept listen };
- - -
optional_policy(`
          unconfined_domain(tendrl_t)
')

==== Tendrl commons impact:

SELinux policy files will be added in to this tendrl-commons module.
SELinux policy files will be added to tendrl-commons module.
This will be used for every nodes participating in the tendrl.

Sample tendrl AVCs:
Expand Down Expand Up @@ -184,7 +181,7 @@ Primary assignee:
tjeyasin

=== Work Items:

https://github.com/Tendrl/node-agent/issues/604


== Dependencies:
Expand Down

0 comments on commit 4f3735e

Please sign in to comment.