Skip to content

Commit 871e87e

Browse files
Merge pull request cfengine#5655 from craigcomstock/ENT-12446-3/master
SELinux: Allow cf-serverd to set its own limits
2 parents 84aba25 + c05f25b commit 871e87e

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

misc/selinux/cfengine-enterprise.te.all

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -341,6 +341,9 @@ allow cfengine_serverd_t unreserved_port_t:tcp_socket name_connect;
341341
allow cfengine_serverd_t cfengine_var_lib_t:sock_file { getattr write };
342342
allow cfengine_serverd_t cfengine_hub_t:unix_stream_socket connectto;
343343

344+
# allow cf-serverd to set its own limits, e.g. def.control_server_maxconnections
345+
allow cfengine_serverd_t self:capability sys_resource;
346+
344347
# TODO: this should not be needed
345348
allow cfengine_serverd_t ssh_port_t:tcp_socket name_connect;
346349
allow cfengine_serverd_t proc_xen_t:dir search;

0 commit comments

Comments
 (0)