From 44cc7d7a4b5686e695337d733f0716a2d3e27107 Mon Sep 17 00:00:00 2001 From: kalebskeithley Date: Wed, 8 Jul 2020 15:20:30 -0400 Subject: [PATCH] selinux: allow ceph_t amqp_port_t:tcp_socket allow ceph_t amqp_port_t:tcp_socket name_connect; allow ceph_t soundd_port_t:tcp_socket name_connect; Required for running RabbitMQ (soundd_port_t) for running RabbitMQ on port 8000 Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=1854083 Signed-off-by: Kaleb S. KEITHLEY (cherry picked from commit 05c523185b2d5ddd9e10f425c7e1f1ee1e409ba2) --- selinux/ceph.te | 2 ++ 1 file changed, 2 insertions(+) diff --git a/selinux/ceph.te b/selinux/ceph.te index 81b4d006753..a5b9f5329fa 100644 --- a/selinux/ceph.te +++ b/selinux/ceph.te @@ -87,6 +87,8 @@ corenet_tcp_sendrecv_cyphesis_port(ceph_t) allow ceph_t commplex_main_port_t:tcp_socket name_connect; allow ceph_t http_cache_port_t:tcp_socket name_connect; +allow ceph_t amqp_port_t:tcp_socket name_connect; +allow ceph_t soundd_port_t:tcp_socket name_connect; corecmd_exec_bin(ceph_t) corecmd_exec_shell(ceph_t) -- 2.47.3