diff --git a/glusterd.te b/glusterd.te index 48811e2..d2a1ba9 100644 --- a/glusterd.te +++ b/glusterd.te @@ -59,7 +59,7 @@ files_type(glusterd_brick_t) # Local policy # -allow glusterd_t self:capability { sys_admin sys_resource sys_ptrace dac_override chown dac_read_search fowner fsetid kill setgid setuid net_admin mknod net_raw }; +allow glusterd_t self:capability { sys_admin sys_resource sys_ptrace dac_override chown dac_read_search fowner fsetid ipc_lock kill setgid setuid net_admin mknod net_raw }; allow glusterd_t self:capability2 block_suspend; allow glusterd_t self:process { getcap setcap setrlimit signal_perms setsched getsched setfscreate}; @@ -155,6 +155,7 @@ corenet_tcp_connect_all_ports(glusterd_t) dev_read_sysfs(glusterd_t) dev_read_urand(glusterd_t) dev_read_rand(glusterd_t) +dev_rw_infiniband_dev(glusterd_t) domain_read_all_domains_state(glusterd_t) domain_getattr_all_sockets(glusterd_t) @@ -164,6 +165,7 @@ domain_use_interactive_fds(glusterd_t) fs_mount_all_fs(glusterd_t) fs_unmount_all_fs(glusterd_t) fs_getattr_all_fs(glusterd_t) +fs_getattr_all_dirs(glusterd_t) files_mounton_non_security(glusterd_t)