Compare commits
No commits in common. "rawhide" and "f35" have entirely different histories.
11 changed files with 1036 additions and 562 deletions
|
|
@ -1 +0,0 @@
|
|||
1
|
||||
44
.gitignore
vendored
44
.gitignore
vendored
|
|
@ -80,47 +80,3 @@ zabbix-1.8.2.tar.gz
|
|||
/zabbix-5.0.18.tar.gz
|
||||
/zabbix-5.0.19.tar.gz
|
||||
/zabbix-5.0.21.tar.gz
|
||||
/zabbix-6.0.2.tar.gz
|
||||
/zabbix-6.0.3.tar.gz
|
||||
/zabbix-6.0.4.tar.gz
|
||||
/zabbix-6.0.5.tar.gz
|
||||
/zabbix-6.0.6.tar.gz
|
||||
/zabbix-6.0.8.tar.gz
|
||||
/zabbix-6.0.12.tar.gz
|
||||
/zabbix-6.0.13.tar.gz
|
||||
/zabbix-6.0.14.tar.gz
|
||||
/zabbix-6.0.15.tar.gz
|
||||
/zabbix-6.0.16.tar.gz
|
||||
/zabbix-6.0.17.tar.gz
|
||||
/zabbix-6.0.18.tar.gz
|
||||
/zabbix-6.0.19.tar.gz
|
||||
/zabbix-6.0.20.tar.gz
|
||||
/zabbix-6.0.22.tar.gz
|
||||
/zabbix-6.0.25.tar.gz
|
||||
/zabbix-6.0.27.tar.gz
|
||||
/zabbix-6.0.29.tar.gz
|
||||
/zabbix-6.0.30.tar.gz
|
||||
/zabbix-6.0.33.tar.gz
|
||||
/zabbix-7.0.2.tar.gz
|
||||
/zabbix-7.0.3.tar.gz
|
||||
/zabbix-7.0.4.tar.gz
|
||||
/zabbix-7.0.5.tar.gz
|
||||
/zabbix-7.0.6.tar.gz
|
||||
/zabbix-7.2.0.tar.gz
|
||||
/zabbix-7.2.2.tar.gz
|
||||
/zabbix-7.2.5.tar.gz
|
||||
/zabbix-7.2.9.tar.gz
|
||||
/zabbix-7.2.10.tar.gz
|
||||
/zabbix-7.2.11.tar.gz
|
||||
/zabbix-7.4.1.tar.gz
|
||||
/zabbix-7.4.2.tar.gz
|
||||
/zabbix-7.4.3.tar.gz
|
||||
/zabbix-7.4.4.tar.gz
|
||||
/zabbix-7.4.5.tar.gz
|
||||
/zabbix-7.4.6.tar.gz
|
||||
/zabbix-7.4.7.tar.gz
|
||||
/zabbix-7.4.8.tar.gz
|
||||
/zabbix-7.4.9.tar.gz
|
||||
/zabbix-7.4.12.tar.gz
|
||||
/zabbix-7.4.13.tar.gz
|
||||
/zabbix-7.4.14.tar.gz
|
||||
|
|
|
|||
|
|
@ -1,22 +0,0 @@
|
|||
summary: DSP test suite
|
||||
discover:
|
||||
- name: DSP_test
|
||||
how: fmf
|
||||
url: https://github.com/fedora-selinux/DSP_test.git
|
||||
ref: main
|
||||
|
||||
execute:
|
||||
how: tmt
|
||||
|
||||
environment:
|
||||
trigger: FedoraCI
|
||||
# DSP_test specific variables:
|
||||
TEST_RPM: "zabbix-selinux"
|
||||
TEST_POLICY: "zabbix"
|
||||
|
||||
prepare:
|
||||
how: install
|
||||
package:
|
||||
- zabbix-selinux
|
||||
- autoconf
|
||||
- automake
|
||||
2
sources
2
sources
|
|
@ -1 +1 @@
|
|||
SHA512 (zabbix-7.4.14.tar.gz) = 98b26bfcd3b1803b23d85af70094fe875d138263cabbc4f6fa5c63ea9b07c4bedaa86eeed79ede74919f55515d6c17408391ea999ed204948320dc8ec29bbdc6
|
||||
SHA512 (zabbix-5.0.21.tar.gz) = 1c448fa5c2d8323c30793a923597c64e4aede3c3f0185bb0462e52677e955e8d75954d336baebe4226691cc186f2840402c8b2b1fe318c227c45541030b3bac3
|
||||
|
|
|
|||
37
tests/tests-DSP.yml
Normal file
37
tests/tests-DSP.yml
Normal file
|
|
@ -0,0 +1,37 @@
|
|||
- hosts: localhost
|
||||
|
||||
roles:
|
||||
- role: standard-test-beakerlib
|
||||
tags:
|
||||
- classic
|
||||
repositories:
|
||||
- repo: https://pagure.io/DSP_test.git
|
||||
dest: DSP_test
|
||||
version: master
|
||||
|
||||
tests:
|
||||
- DSP_test
|
||||
environment:
|
||||
# RPM package containing the policy module
|
||||
TEST_RPM: zabbix-selinux
|
||||
# policy module name
|
||||
TEST_POLICY: zabbix
|
||||
# policy sources will be extracted from corresponding .src.rpm
|
||||
# policy tar filename regexp (e.g. "usbguard-selinux*.tar.gz")
|
||||
# or empty string if policy sources are not inside a tar archive
|
||||
POLICY_TAR: ''
|
||||
# path to policy sources (in of the tar archive) -- <POLICY_TAR>/<POLICY_PATH>/<TEST_POLICY>.(te|if|fc)
|
||||
# or path in the src.rpm if there is no tar archive -- <src.rpm>/<POLICY_PATH>/<TEST_POLICY>.(te|if|fc)
|
||||
# can contain wildcards (e.g. for versions etc.)
|
||||
POLICY_PATH: .
|
||||
|
||||
required_packages:
|
||||
- policycoreutils
|
||||
- selinux-policy
|
||||
- selinux-policy-targeted
|
||||
- setools-console
|
||||
- libselinux-utils
|
||||
- rpm
|
||||
- tar
|
||||
- git
|
||||
- zabbix-selinux
|
||||
|
|
@ -1,21 +1,19 @@
|
|||
diff --git a/ui/include/classes/core/CConfigFile.php b/ui/include/classes/core/CConfigFile.php
|
||||
index d7ad93a..88b7d5f 100644
|
||||
--- a/ui/include/classes/core/CConfigFile.php
|
||||
+++ b/ui/include/classes/core/CConfigFile.php
|
||||
@@ -20,7 +20,7 @@ class CConfigFile {
|
||||
diff -up zabbix-5.0.6/ui/include/classes/core/CConfigFile.php.config zabbix-5.0.6/ui/include/classes/core/CConfigFile.php
|
||||
--- zabbix-5.0.6/ui/include/classes/core/CConfigFile.php.config 2020-11-30 04:16:17.000000000 -0700
|
||||
+++ zabbix-5.0.6/ui/include/classes/core/CConfigFile.php 2020-12-13 14:45:24.690966761 -0700
|
||||
@@ -24,7 +24,7 @@ class CConfigFile {
|
||||
const CONFIG_NOT_FOUND = 1;
|
||||
const CONFIG_ERROR = 2;
|
||||
const CONFIG_VAULT_ERROR = 3;
|
||||
|
||||
- const CONFIG_FILE_PATH = '/conf/zabbix.conf.php';
|
||||
+ const CONFIG_FILE_PATH = '/etc/zabbix/web/zabbix.conf.php';
|
||||
|
||||
private static $supported_db_types = [
|
||||
ZBX_DB_MYSQL => true,
|
||||
diff --git a/ui/include/classes/core/ZBase.php b/ui/include/classes/core/ZBase.php
|
||||
index 51b2165..e57e5a8 100644
|
||||
--- a/ui/include/classes/core/ZBase.php
|
||||
+++ b/ui/include/classes/core/ZBase.php
|
||||
@@ -392,7 +392,7 @@ class ZBase {
|
||||
diff -up zabbix-5.0.6/ui/include/classes/core/ZBase.php.config zabbix-5.0.6/ui/include/classes/core/ZBase.php
|
||||
--- zabbix-5.0.6/ui/include/classes/core/ZBase.php.config 2020-11-30 04:16:17.000000000 -0700
|
||||
+++ zabbix-5.0.6/ui/include/classes/core/ZBase.php 2020-12-13 14:45:24.691966769 -0700
|
||||
@@ -322,7 +322,7 @@ class ZBase {
|
||||
* @throws Exception
|
||||
*/
|
||||
protected function setMaintenanceMode() {
|
||||
|
|
@ -24,24 +22,23 @@ index 51b2165..e57e5a8 100644
|
|||
|
||||
if (defined('ZBX_DENY_GUI_ACCESS')) {
|
||||
if (!isset($ZBX_GUI_ACCESS_IP_RANGE) || !in_array(CWebUser::getIp(), $ZBX_GUI_ACCESS_IP_RANGE)) {
|
||||
@@ -405,7 +405,7 @@ class ZBase {
|
||||
@@ -335,7 +335,7 @@ class ZBase {
|
||||
* Load zabbix config file.
|
||||
*/
|
||||
protected function loadConfigFile(): void {
|
||||
- $configFile = $this->root_dir.CConfigFile::CONFIG_FILE_PATH;
|
||||
protected function loadConfigFile() {
|
||||
- $configFile = $this->getRootDir().CConfigFile::CONFIG_FILE_PATH;
|
||||
+ $configFile = CConfigFile::CONFIG_FILE_PATH;
|
||||
|
||||
$config = new CConfigFile($configFile);
|
||||
|
||||
diff --git a/ui/include/classes/setup/CSetupWizard.php b/ui/include/classes/setup/CSetupWizard.php
|
||||
index 8574868..79d0c72 100644
|
||||
--- a/ui/include/classes/setup/CSetupWizard.php
|
||||
+++ b/ui/include/classes/setup/CSetupWizard.php
|
||||
@@ -328,7 +328,7 @@ class CSetupWizard extends CForm {
|
||||
$this->config = $config->load();
|
||||
}
|
||||
diff -up zabbix-5.0.6/ui/include/classes/setup/CSetupWizard.php.config zabbix-5.0.6/ui/include/classes/setup/CSetupWizard.php
|
||||
--- zabbix-5.0.6/ui/include/classes/setup/CSetupWizard.php.config 2020-11-30 04:16:17.000000000 -0700
|
||||
+++ zabbix-5.0.6/ui/include/classes/setup/CSetupWizard.php 2020-12-13 14:45:50.510168641 -0700
|
||||
@@ -678,7 +678,7 @@ class CSetupWizard extends CForm {
|
||||
// make zabbix.conf.php downloadable
|
||||
header('Content-Type: application/x-httpd-php');
|
||||
header('Content-Disposition: attachment; filename="'.basename(CConfigFile::CONFIG_FILE_PATH).'"');
|
||||
- $config = new CConfigFile(APP::getRootDir().CConfigFile::CONFIG_FILE_PATH);
|
||||
- $config = new CConfigFile(APP::getInstance()->getRootDir().CConfigFile::CONFIG_FILE_PATH);
|
||||
+ $config = new CConfigFile(CConfigFile::CONFIG_FILE_PATH);
|
||||
$config->config = [
|
||||
'DB' => [
|
||||
|
|
|
|||
|
|
@ -1,17 +0,0 @@
|
|||
sscanf needs <stdio.h> for the prototype. Submitted upstream here:
|
||||
|
||||
<https://support.zabbix.com/browse/ZBX-21946>
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index 0588004f9f89cdd5..bbc60e3a28369f9f 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -952,6 +952,7 @@ dnl FreeBSD 4.x does not support %llu
|
||||
AC_MSG_CHECKING(for long long format)
|
||||
AC_RUN_IFELSE([AC_LANG_SOURCE([[
|
||||
#include <sys/types.h>
|
||||
+#include <stdio.h>
|
||||
int main()
|
||||
{
|
||||
uint64_t i;
|
||||
|
||||
|
|
@ -1,21 +1,7 @@
|
|||
diff --git a/src/go/pkg/tls/tls.go b/src/go/pkg/tls/tls.go
|
||||
index b7ddff4..063eb02 100644
|
||||
--- a/src/go/pkg/tls/tls.go
|
||||
+++ b/src/go/pkg/tls/tls.go
|
||||
@@ -406,6 +406,8 @@ static void *tls_new_context(const char *ca_file, const char *crl_file, const ch
|
||||
#endif
|
||||
if (NULL != cipher)
|
||||
ciphers = cipher;
|
||||
+ else
|
||||
+ ciphers = "PROFILE=SYSTEM";
|
||||
|
||||
if (1 != SSL_CTX_set_cipher_list(ctx, ciphers))
|
||||
goto out;
|
||||
diff --git a/src/libs/zbxcomms/tls_openssl.c b/src/libs/zbxcomms/tls_openssl.c
|
||||
index 40394a3..b2eb0f0 100644
|
||||
--- a/src/libs/zbxcomms/tls_openssl.c
|
||||
+++ b/src/libs/zbxcomms/tls_openssl.c
|
||||
@@ -1212,7 +1212,7 @@ void zbx_tls_init_child(const zbx_config_tls_t *config_tls, zbx_get_program_type
|
||||
diff -up zabbix-5.0.2/src/libs/zbxcrypto/tls.c.crypto-policy zabbix-5.0.2/src/libs/zbxcrypto/tls.c
|
||||
--- zabbix-5.0.2/src/libs/zbxcrypto/tls.c.crypto-policy 2020-07-06 03:54:32.000000000 -0600
|
||||
+++ zabbix-5.0.2/src/libs/zbxcrypto/tls.c 2020-07-18 21:22:13.125099598 -0600
|
||||
@@ -2932,7 +2932,7 @@ void zbx_tls_init_child(void)
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
|
|
@ -24,7 +10,7 @@ index 40394a3..b2eb0f0 100644
|
|||
{
|
||||
zbx_snprintf_alloc(&error, &error_alloc, &error_offset, "cannot set list of certificate"
|
||||
" ciphersuites:");
|
||||
@@ -1302,7 +1302,7 @@ void zbx_tls_init_child(const zbx_config_tls_t *config_tls, zbx_get_program_type
|
||||
@@ -3014,7 +3014,7 @@ void zbx_tls_init_child(void)
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
|
|
@ -33,7 +19,7 @@ index 40394a3..b2eb0f0 100644
|
|||
{
|
||||
zbx_snprintf_alloc(&error, &error_alloc, &error_offset, "cannot set list of PSK ciphersuites:");
|
||||
goto out;
|
||||
@@ -1360,7 +1360,7 @@ void zbx_tls_init_child(const zbx_config_tls_t *config_tls, zbx_get_program_type
|
||||
@@ -3070,7 +3070,7 @@ void zbx_tls_init_child(void)
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
|
|
|
|||
File diff suppressed because it is too large
Load diff
325
zabbix.spec
325
zabbix.spec
|
|
@ -16,34 +16,13 @@
|
|||
|
||||
Name: zabbix
|
||||
Epoch: 1
|
||||
Version: 7.4.14
|
||||
Version: 5.0.21
|
||||
Release: 1%{?dist}
|
||||
Summary: Open-source monitoring solution for your IT infrastructure
|
||||
|
||||
# TODO - Note additional licenses in src/go when we start building with go
|
||||
# src/libs/zbxembed/duktape.c: MIT License
|
||||
# src/libs/zbxembed/duktape.h: MIT License
|
||||
# src/libs/zbxgetopt/getopt.c: GNU General Public License v2.0 or later
|
||||
# src/libs/zbxhash/md5.c: zlib License
|
||||
# ui/vendor/composer/LICENSE: MIT License
|
||||
# ui/js/vendors/D3/LICENSE: ISC License
|
||||
# ui/js/vendors/Leaflet/LICENSE: BSD 2-Clause License
|
||||
# ui/js/vendors/Leaflet.markercluster/LICENSE: MIT License
|
||||
# ui/js/vendors/jQueryUI/LICENSE: MIT License
|
||||
# ui/js/vendors/qrcode/LICENSE: MIT License
|
||||
# ui/vendor/duosecurity/duo_universal_php/LICENSE: BSD 3-Clause License
|
||||
# ui/vendor/firebase/php-jwt/LICENSE: BSD 3-Clause License
|
||||
# ui/vendor/onelogin/php-saml/LICENSE: MIT License
|
||||
# ui/vendor/paragonie/constant_time_encoding/LICENSE.txt: MIT License
|
||||
# ui/vendor/pragmarx/google2fa/LICENSE.md: MIT License
|
||||
# ui/vendor/symfony/deprecation-contracts/LICENSE: MIT License
|
||||
# ui/vendor/symfony/polyfill-ctype/LICENSE: MIT License
|
||||
# ui/vendor/symfony/yaml/LICENSE: MIT License
|
||||
# ui/assets/styles/vendors/Leaflet/LICENSE: BSD 2-Clause License
|
||||
# ui/vendor/paragonie/constant_time_encoding/src/*.php: MIT License
|
||||
License: AGPL-3.0-only AND MIT AND GPL-2.0-or-later AND Zlib AND BSD-3-Clause AND BSD-2-Clause AND ISC
|
||||
License: GPLv2+
|
||||
URL: https://www.zabbix.com
|
||||
Source0: https://cdn.zabbix.com/zabbix/sources/stable/7.4/zabbix-%{version}.tar.gz
|
||||
Source0: https://cdn.zabbix.com/zabbix/sources/stable/5.0/zabbix-%{version}.tar.gz
|
||||
Source1: %{srcname}-web.conf
|
||||
Source2: %{srcname}-php-fpm.conf
|
||||
Source5: %{srcname}-logrotate.in
|
||||
|
|
@ -70,14 +49,15 @@ Patch0: %{srcname}-config.patch
|
|||
Patch1: %{srcname}-out-of-tree.patch
|
||||
# Enforce Fedora Crypto Policy
|
||||
Patch2: %{srcname}-crypto-policy.patch
|
||||
# Add <stdio> to sscanf check
|
||||
# https://support.zabbix.com/browse/ZBX-21946
|
||||
Patch3: %{srcname}-configure-sscanf.patch
|
||||
|
||||
# Patch1 patches automake files so we need to autoreconf
|
||||
BuildRequires: make
|
||||
BuildRequires: libtool
|
||||
BuildRequires: make
|
||||
%if 0%{?fedora} || 0%{?rhel} >= 8
|
||||
BuildRequires: mariadb-connector-c-devel
|
||||
%else
|
||||
BuildRequires: mysql-devel
|
||||
%endif
|
||||
BuildRequires: libpq-devel
|
||||
BuildRequires: sqlite-devel
|
||||
BuildRequires: net-snmp-devel
|
||||
|
|
@ -90,7 +70,7 @@ BuildRequires: OpenIPMI-devel
|
|||
BuildRequires: libssh2-devel
|
||||
BuildRequires: libxml2-devel
|
||||
BuildRequires: libevent-devel
|
||||
BuildRequires: pcre2-devel
|
||||
BuildRequires: pcre-devel
|
||||
BuildRequires: gcc
|
||||
# For Agent 2 - has missing deps
|
||||
%if %{with go}
|
||||
|
|
@ -126,7 +106,13 @@ Provides: bundled(md5-deutsch)
|
|||
# Could alternatively be conditional on Fedora/EL
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname} = %{version}-%{release}
|
||||
Conflicts: %{srcname} < 6.0
|
||||
Conflicts: %{srcname} < 3.0
|
||||
Conflicts: %{srcname}20
|
||||
Conflicts: %{srcname}22
|
||||
%else
|
||||
Obsoletes: %{srcname}-docs < 1.8.15-2
|
||||
Obsoletes: %{srcname}-web-sqlite3 < 2.0.3-3
|
||||
Obsoletes: %{srcname}-server-sqlite3 < 2.0.3-3
|
||||
%endif
|
||||
|
||||
%description
|
||||
|
|
@ -176,11 +162,10 @@ Requires: %{name} = %{?epoch:%{epoch}:}%{version}-%{release}
|
|||
Requires: %{name}-server-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: fping
|
||||
Requires: traceroute
|
||||
Requires(pre): shadow-utils
|
||||
Requires(post): systemd
|
||||
Requires(preun): systemd
|
||||
Requires(postun): systemd
|
||||
Provides: user(zabbixsrv)
|
||||
Provides: group(zabbixsrv)
|
||||
|
||||
%description server
|
||||
Zabbix server common files
|
||||
|
|
@ -191,6 +176,7 @@ Requires: %{name} = %{?epoch:%{epoch}:}%{version}-%{release}
|
|||
Requires: %{name}-dbfiles-mysql
|
||||
Requires: %{name}-server = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires(post): %{_sbindir}/update-alternatives
|
||||
Requires(preun): %{_sbindir}/alternatives
|
||||
Requires(postun): %{_sbindir}/update-alternatives
|
||||
Provides: %{name}-server-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
|
||||
|
|
@ -203,6 +189,7 @@ Requires: %{name} = %{?epoch:%{epoch}:}%{version}-%{release}
|
|||
Requires: %{name}-server = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: %{name}-dbfiles-pgsql
|
||||
Requires(post): %{_sbindir}/update-alternatives
|
||||
Requires(preun): %{_sbindir}/alternatives
|
||||
Requires(postun): %{_sbindir}/update-alternatives
|
||||
Provides: %{name}-server-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
|
||||
|
|
@ -212,6 +199,7 @@ Zabbix server compiled to use PostgreSQL
|
|||
%package agent
|
||||
Summary: Zabbix agent
|
||||
Requires: %{name} = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires(pre): shadow-utils
|
||||
Requires(post): systemd
|
||||
Requires(preun): systemd
|
||||
Requires(postun): systemd
|
||||
|
|
@ -224,6 +212,7 @@ Summary: Zabbix proxy common files
|
|||
BuildArch: noarch
|
||||
Requires: %{name} = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: %{name}-proxy-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires(pre): shadow-utils
|
||||
Requires(post): systemd
|
||||
Requires(preun): systemd
|
||||
Requires(postun): systemd
|
||||
|
|
@ -238,6 +227,7 @@ Requires: %{name}-proxy = %{?epoch:%{epoch}:}%{version}-%{release}
|
|||
Requires: %{name}-dbfiles-mysql
|
||||
Provides: %{name}-proxy-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires(post): %{_sbindir}/update-alternatives
|
||||
Requires(preun): %{_sbindir}/alternatives
|
||||
Requires(postun): %{_sbindir}/update-alternatives
|
||||
|
||||
%description proxy-mysql
|
||||
|
|
@ -249,6 +239,7 @@ Requires: %{name}-proxy = %{?epoch:%{epoch}:}%{version}-%{release}
|
|||
Requires: %{name}-dbfiles-pgsql
|
||||
Provides: %{name}-proxy-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires(post): %{_sbindir}/update-alternatives
|
||||
Requires(preun): %{_sbindir}/alternatives
|
||||
Requires(postun): %{_sbindir}/update-alternatives
|
||||
|
||||
%description proxy-pgsql
|
||||
|
|
@ -260,6 +251,7 @@ Requires: %{name}-proxy = %{?epoch:%{epoch}:}%{version}-%{release}
|
|||
Requires: %{name}-dbfiles-sqlite3
|
||||
Provides: %{name}-proxy-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires(post): %{_sbindir}/update-alternatives
|
||||
Requires(preun): %{_sbindir}/alternatives
|
||||
Requires(postun): %{_sbindir}/update-alternatives
|
||||
|
||||
%description proxy-sqlite3
|
||||
|
|
@ -276,9 +268,9 @@ Requires: php-json
|
|||
Requires: php-ldap
|
||||
Requires: php-mbstring
|
||||
Requires: php-xml
|
||||
# jquery 3.6.0 and jquery-ui 1.13.2 in the sources
|
||||
Requires: js-jquery >= 3.6.0
|
||||
Provides: bundled(js-jquery-ui) = 1.13.2
|
||||
# jquery 3.3.1 and jquery-ui 1.12.1 in the sources
|
||||
Requires: js-jquery >= 3.3.1
|
||||
Provides: bundled(js-jquery-ui) = 1.12.1
|
||||
# prototype 1.6.1 in the sources, Fedora package is dead
|
||||
#Requires: prototype
|
||||
Requires: dejavu-sans-fonts
|
||||
|
|
@ -294,6 +286,7 @@ BuildArch: noarch
|
|||
Requires: %{name}-web = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: php-mysqli
|
||||
Provides: %{name}-web-database = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Obsoletes: %{name}-web <= 1.5.3-0.1
|
||||
|
||||
%description web-mysql
|
||||
Zabbix web frontend for MySQL
|
||||
|
|
@ -337,7 +330,10 @@ Custom SELinux policy module
|
|||
|
||||
|
||||
%prep
|
||||
%autosetup -p1
|
||||
%setup0 -q -n %{srcname}-%{version}%{?prerelease:.%{prerelease}}
|
||||
%patch0 -p1 -b .config
|
||||
%patch1 -p1 -b .out-of-tree
|
||||
%patch2 -p1 -b .crypto-policy
|
||||
autoreconf
|
||||
|
||||
# Remove bundled java libs
|
||||
|
|
@ -394,11 +390,6 @@ sed -i \
|
|||
# Install README file
|
||||
install -m 0644 -p %{SOURCE16} .
|
||||
|
||||
# Create a sysusers.d config file
|
||||
cat >zabbix.sysusers.conf <<EOF
|
||||
u zabbix - 'Zabbix Monitoring System' %{_sharedstatedir}/zabbix -
|
||||
EOF
|
||||
|
||||
|
||||
%build
|
||||
|
||||
|
|
@ -414,7 +405,7 @@ common_flags="
|
|||
--with-ssh2
|
||||
--with-libxml2
|
||||
--with-libevent
|
||||
--with-libpcre2
|
||||
--with-libpcre
|
||||
--with-openssl
|
||||
"
|
||||
# Setup out of tree builds
|
||||
|
|
@ -553,11 +544,8 @@ cp -p database/sqlite3/schema.sql $RPM_BUILD_ROOT%{_datadir}/%{srcname}-sqlite3
|
|||
|
||||
%if 0%{?with_selinux}
|
||||
install -D -m 0644 %{name}.pp.bz2 %{buildroot}%{_datadir}/selinux/packages/%{selinuxtype}/%{name}.pp.bz2
|
||||
install -D -p -m 0644 selinux/%{name}.if %{buildroot}%{_datadir}/selinux/devel/include/distributed/%{name}.if
|
||||
%endif
|
||||
|
||||
install -m0644 -D zabbix.sysusers.conf %{buildroot}%{_sysusersdir}/zabbix.conf
|
||||
|
||||
|
||||
%post server
|
||||
%systemd_post zabbix-server.service
|
||||
|
|
@ -572,25 +560,13 @@ fi
|
|||
%post server-mysql
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_server \
|
||||
%{srcname}-server %{_sbindir}/%{srcname}_server_mysql 10 \
|
||||
--slave %{_unitdir}/zabbix-server.service %{srcname}-server.service \
|
||||
%{_unitdir}/zabbix-server-mysql.service
|
||||
# This needs to be run twice to rename from old slave name in zabbix < 6.0.33-2
|
||||
# due to a bug in alternatives. Remove in F45
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_server \
|
||||
%{srcname}-server %{_sbindir}/%{srcname}_server_mysql 10 \
|
||||
--slave %{_unitdir}/zabbix-server.service %{srcname}-server.service \
|
||||
--slave %{_unitdir}/zabbix-server.service %{srcname}-server-systemd \
|
||||
%{_unitdir}/zabbix-server-mysql.service
|
||||
|
||||
%post server-pgsql
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_server \
|
||||
%{srcname}-server %{_sbindir}/%{srcname}_server_pgsql 10 \
|
||||
--slave %{_unitdir}/zabbix-server.service %{srcname}-server.service \
|
||||
%{_unitdir}/zabbix-server-pgsql.service
|
||||
# This needs to be run twice to rename from old slave name in zabbix < 6.0.33-2
|
||||
# due to a bug in alternatives. Remove in F45
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_server \
|
||||
%{srcname}-server %{_sbindir}/%{srcname}_server_pgsql 10 \
|
||||
--slave %{_unitdir}/zabbix-server.service %{srcname}-server.service \
|
||||
--slave %{_unitdir}/zabbix-server.service %{srcname}-server-systemd \
|
||||
%{_unitdir}/zabbix-server-pgsql.service
|
||||
|
||||
%post proxy
|
||||
|
|
@ -606,37 +582,19 @@ fi
|
|||
%post proxy-mysql
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_proxy \
|
||||
%{srcname}-proxy %{_sbindir}/%{srcname}_proxy_mysql 10 \
|
||||
--slave %{_unitdir}/zabbix-proxy.service %{srcname}-proxy.service \
|
||||
%{_unitdir}/zabbix-proxy-mysql.service
|
||||
# This needs to be run twice to rename from old slave name in zabbix < 6.0.33-2
|
||||
# due to a bug in alternatives. Remove in F45
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_proxy \
|
||||
%{srcname}-proxy %{_sbindir}/%{srcname}_proxy_mysql 10 \
|
||||
--slave %{_unitdir}/zabbix-proxy.service %{srcname}-proxy.service \
|
||||
--slave %{_unitdir}/zabbix-proxy.service %{srcname}-proxy-systemd \
|
||||
%{_unitdir}/zabbix-proxy-mysql.service
|
||||
|
||||
%post proxy-pgsql
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_proxy \
|
||||
%{srcname}-proxy %{_sbindir}/%{srcname}_proxy_pgsql 10 \
|
||||
--slave %{_unitdir}/zabbix-proxy.service %{srcname}-proxy.service \
|
||||
%{_unitdir}/zabbix-proxy-pgsql.service
|
||||
# This needs to be run twice to rename from old slave name in zabbix < 6.0.33-2
|
||||
# due to a bug in alternatives. Remove in F45
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_proxy \
|
||||
%{srcname}-proxy %{_sbindir}/%{srcname}_proxy_pgsql 10 \
|
||||
--slave %{_unitdir}/zabbix-proxy.service %{srcname}-proxy.service \
|
||||
--slave %{_unitdir}/zabbix-proxy.service %{srcname}-proxy-systemd \
|
||||
%{_unitdir}/zabbix-proxy-pgsql.service
|
||||
|
||||
%post proxy-sqlite3
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_proxy \
|
||||
%{srcname}-proxy %{_sbindir}/%{srcname}_proxy_sqlite3 10 \
|
||||
--slave %{_unitdir}/zabbix-proxy.service %{srcname}-proxy.service \
|
||||
%{_unitdir}/zabbix-proxy-sqlite3.service
|
||||
# This needs to be run twice to rename from old slave name in zabbix < 6.0.33-2
|
||||
# due to a bug in alternatives. Remove in F45
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_proxy \
|
||||
%{srcname}-proxy %{_sbindir}/%{srcname}_proxy_sqlite3 10 \
|
||||
--slave %{_unitdir}/zabbix-proxy.service %{srcname}-proxy.service \
|
||||
--slave %{_unitdir}/zabbix-proxy.service %{srcname}-proxy-systemd \
|
||||
%{_unitdir}/zabbix-proxy-sqlite3.service
|
||||
|
||||
%if 0%{?with_selinux}
|
||||
|
|
@ -657,6 +615,12 @@ fi
|
|||
%selinux_relabel_post -s %{selinuxtype}
|
||||
%endif
|
||||
|
||||
%pre agent
|
||||
getent group zabbix > /dev/null || groupadd -r zabbix
|
||||
getent passwd zabbix > /dev/null || \
|
||||
useradd -r -g zabbix -d %{_sharedstatedir}/zabbix -s /sbin/nologin \
|
||||
-c "Zabbix Monitoring System" zabbix
|
||||
:
|
||||
|
||||
%post agent
|
||||
%systemd_post zabbix-agent.service
|
||||
|
|
@ -782,8 +746,7 @@ fi
|
|||
%if 0%{?with_selinux}
|
||||
%files selinux
|
||||
%{_datadir}/selinux/packages/%{selinuxtype}/%{name}.pp.*
|
||||
%{_datadir}/selinux/devel/include/distributed/%{name}.if
|
||||
%ghost %verify(not md5 size mode mtime) %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{name}
|
||||
%ghost %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{name}
|
||||
%endif
|
||||
|
||||
%files agent
|
||||
|
|
@ -797,7 +760,6 @@ fi
|
|||
%{_unitdir}/zabbix-agent.service
|
||||
%{_sbindir}/zabbix_agentd
|
||||
%{_mandir}/man8/zabbix_agentd.8*
|
||||
%{_sysusersdir}/zabbix.conf
|
||||
|
||||
%files proxy
|
||||
%doc misc/snmptrap/zabbix_trap_receiver.pl
|
||||
|
|
@ -839,203 +801,6 @@ fi
|
|||
%files web-pgsql
|
||||
|
||||
%changelog
|
||||
* Tue Aug 25 2026 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.14-1
|
||||
- 7.4.14
|
||||
|
||||
* Thu Aug 20 2026 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.13-1
|
||||
- 7.4.13
|
||||
|
||||
* Fri Jul 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1:7.4.12-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
|
||||
|
||||
* Thu Jul 09 2026 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.12-1
|
||||
- 7.4.12
|
||||
|
||||
* Sat Jun 13 2026 Yaakov Selkowitz <yselkowi@redhat.com> - 1:7.4.9-3
|
||||
- Rebuilt for openssl 4.0
|
||||
|
||||
* Mon Apr 13 2026 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.9-2
|
||||
- Openssl rebuild
|
||||
|
||||
* Thu Apr 09 2026 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.9-1
|
||||
- 7.4.9
|
||||
|
||||
* Fri Mar 13 2026 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.8-1
|
||||
- 7.4.8
|
||||
|
||||
* Fri Feb 13 2026 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.7-1
|
||||
- 7.4.7
|
||||
|
||||
* Fri Jan 23 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 1:7.4.6-3
|
||||
- Rebuilt for net-snmp 5.9.5.2
|
||||
|
||||
* Sat Jan 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1:7.4.6-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
|
||||
|
||||
* Thu Dec 18 2025 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.6-1
|
||||
- 7.4.6
|
||||
|
||||
* Mon Nov 03 2025 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.5-1
|
||||
- 7.4.5
|
||||
|
||||
* Wed Oct 29 2025 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.4-1
|
||||
- 7.4.4
|
||||
|
||||
* Wed Oct 01 2025 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.3-1
|
||||
- 7.4.3
|
||||
|
||||
* Mon Aug 25 2025 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.2-1
|
||||
- 7.4.2
|
||||
|
||||
* Thu Jul 31 2025 Gwyn Ciesla <gwync@protonmail.com> - 1:7.4.1-1
|
||||
- 7.4.1
|
||||
|
||||
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1:7.2.11-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
|
||||
|
||||
* Tue Jul 22 2025 Gwyn Ciesla <gwync@protonmail.com> - 1:7.2.11-1
|
||||
- 7.2.11
|
||||
|
||||
* Fri Jun 27 2025 Gwyn Ciesla <gwync@protonmail.com> - 1:7.2.10-1
|
||||
- 7.2.10
|
||||
|
||||
* Fri Jun 20 2025 Gwyn Ciesla <gwync@protonmail.com> - 1:7.2.9-1
|
||||
- 7.2.9
|
||||
|
||||
* Wed Apr 09 2025 Gwyn Ciesla <gwync@protonmail.com> - 1:7.2.5-2
|
||||
- Add user/group provides to -server to fix FTI
|
||||
|
||||
* Wed Apr 02 2025 Orion Poplawski <orion@nwra.com> - 1:7.2.5-1
|
||||
- Update to 7.2.5 (CVE-2024-36469, CVE-2024-42325, CVE-2024-45700)
|
||||
|
||||
* Tue Feb 11 2025 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> - 1:7.2.2-3
|
||||
- Add sysusers.d config file to allow rpm to create users/groups automatically
|
||||
|
||||
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1:7.2.2-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
|
||||
|
||||
* Mon Jan 06 2025 Orion Poplawski <orion@nwra.com> - 1:7.2.2-1
|
||||
- Update to 7.2.2
|
||||
|
||||
* Thu Dec 12 2024 Orion Poplawski <orion@nwra.com> - 1:7.2.0-1
|
||||
- Update to 7.2.0
|
||||
|
||||
* Sat Nov 30 2024 Orion Poplawski <orion@nwra.com> - 1:7.0.6-1
|
||||
- Update to 7.0.6
|
||||
|
||||
* Tue Oct 22 2024 Orion Poplawski <orion@nwra.com> - 1:7.0.5-1
|
||||
- Update to 7.0.5
|
||||
|
||||
* Mon Oct 07 2024 Orion Poplawski <orion@nwra.com> - 1:7.0.4-2
|
||||
- Fix typo in crypto policy patch that broke SSL connections
|
||||
|
||||
* Thu Sep 26 2024 Orion Poplawski <orion@nwra.com> - 1:7.0.4-1
|
||||
- Update to 7.0.4
|
||||
|
||||
* Sat Aug 24 2024 Orion Poplawski <orion@nwra.com> - 1:7.0.3-1
|
||||
- Update to 7.0.3
|
||||
- License changed upstream to AGPL-3.0-only, note other licenses in source
|
||||
|
||||
* Mon Aug 19 2024 Orion Poplawski <orion@nwra.com> - 1:6.0.33-2
|
||||
- Use alternatives name that systemd likes for units (bz#2305855)
|
||||
|
||||
* Thu Aug 15 2024 Gwyn Ciesla <gwync@protonmail.com> - 1:6.0.33-1
|
||||
- 6.0.33
|
||||
|
||||
* Mon Jul 29 2024 Miroslav Suchý <msuchy@redhat.com> - 1:6.0.30-3
|
||||
- convert license to SPDX
|
||||
|
||||
* Sat Jul 20 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1:6.0.30-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
|
||||
|
||||
* Tue May 21 2024 Gwyn Ciesla <gwync@protonmail.com> - 1:6.0.30-1
|
||||
- 6.0.30
|
||||
|
||||
* Fri May 03 2024 Orion Poplawski <orion@nwra.com> - 1:6.0.29-1
|
||||
- Update to 6.0.29
|
||||
- Hopefully really get the zabbix_run_sudo SELinux boolean working for
|
||||
zabbix-agent and allow it to run lvm when enabled
|
||||
|
||||
* Wed Feb 28 2024 Morten Stevens <mstevens@fedoraproject.org> - 1:6.0.27-1
|
||||
- Update to 6.0.27
|
||||
|
||||
* Sat Jan 27 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1:6.0.25-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
|
||||
|
||||
* Thu Jan 04 2024 Orion Poplawski <orion@nwra.com> - 1:6.0.25-1
|
||||
- Update to 6.0.25
|
||||
|
||||
* Fri Dec 01 2023 Gwyn Ciesla <gwync@protonmail.com> - 1:6.0.22-3
|
||||
- Patch for libxml2 2.12.x
|
||||
|
||||
* Sat Oct 28 2023 Orion Poplawski <orion@nwra.com> - 1:6.0.22-2
|
||||
- Add dontaudit SELinux rules for spurious AVC denial messages (bz#2170630)
|
||||
|
||||
* Wed Oct 04 2023 Morten Stevens <mstevens@fedoraproject.org> - 1:6.0.22-1
|
||||
- Update to 6.0.22
|
||||
|
||||
* Mon Aug 07 2023 Morten Stevens <mstevens@fedoraproject.org> - 1:6.0.20-1
|
||||
- Update to 6.0.20
|
||||
|
||||
* Sat Jul 22 2023 Fedora Release Engineering <releng@fedoraproject.org> - 1:6.0.19-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
|
||||
|
||||
* Thu Jul 06 2023 Morten Stevens <mstevens@fedoraproject.org> - 1:6.0.19-1
|
||||
- Update to 6.0.19
|
||||
|
||||
* Thu Jun 15 2023 Morten Stevens <mstevens@fedoraproject.org> - 1:6.0.18-1
|
||||
- Update to 6.0.18
|
||||
|
||||
* Tue Apr 25 2023 Morten Stevens <mstevens@fedoraproject.org> - 1:6.0.17-1
|
||||
- Update to 6.0.17
|
||||
|
||||
* Tue Apr 11 2023 Morten Stevens <mstevens@fedoraproject.org> - 1:6.0.16-1
|
||||
- Update to 6.0.16
|
||||
|
||||
* Tue Apr 04 2023 Morten Stevens <mstevens@fedoraproject.org> - 1:6.0.15-1
|
||||
- Update to 6.0.15
|
||||
|
||||
* Tue Mar 21 2023 Morten Stevens <mstevens@fedoraproject.org> - 1:6.0.14-1
|
||||
- Update to 6.0.14
|
||||
|
||||
* Wed Mar 01 2023 Gwyn Ciesla <gwync@protonmail.com> - 1:6.0.13-2
|
||||
- migrated to SPDX license
|
||||
|
||||
* Thu Feb 16 2023 Orion Poplawski <orion@nwra.com> - 1:6.0.13-1
|
||||
- Update to 6.0.13
|
||||
- Add policy to allow zabbix scripts to run chronyc as chronyc_t (bz#2160180)
|
||||
- Add policy to allow zabbix agent to run rpm read-only
|
||||
|
||||
* Sun Jan 22 2023 Orion Poplawski <orion@nwra.com> - 1:6.0.12-1
|
||||
- Update to 6.0.12
|
||||
|
||||
* Sat Jan 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 1:6.0.8-3
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
|
||||
|
||||
* Thu Nov 17 2022 Florian Weimer <fweimer@redhat.com> - 1:6.0.8-2
|
||||
- Include <stdio.h> in configure for sscanf prototype
|
||||
|
||||
* Wed Sep 14 2022 Gwyn Ciesla <gwync@protonmail.com> - 1:6.0.8-1
|
||||
- 6.0.8
|
||||
|
||||
* Fri Jul 22 2022 Gwyn Ciesla <gwync@protonmail.com> -1:6.0.6-2
|
||||
- Move to pcre2
|
||||
|
||||
* Fri Jul 08 2022 Orion Poplawski <orion@nwra.com> - 1:6.0.6-1
|
||||
- Update to 6.0.6
|
||||
|
||||
* Tue May 31 2022 Gwyn Ciesla <gwync@protonmail.com> - 1:6.0.5-1
|
||||
- 6.0.5
|
||||
|
||||
* Mon May 09 2022 Orion Poplawski <orion@cora.nwra.com> - 1:6.0.4-1
|
||||
- Update to 6.0.4
|
||||
|
||||
* Mon Apr 04 2022 Gwyn Ciesla <gwync@protonmail.com> - 1:6.0.3-1
|
||||
- 6.0.3
|
||||
|
||||
* Wed Mar 23 2022 Orion Poplawski <orion@nwra.com> - 1:6.0.2-1
|
||||
- Update to 6.0.2
|
||||
|
||||
* Fri Mar 11 2022 Gwyn Ciesla <gwync@protonmail.com> - 1:5.0.21-1
|
||||
- 5.0.21
|
||||
|
||||
|
|
|
|||
41
zabbix.te
41
zabbix.te
|
|
@ -1,4 +1,4 @@
|
|||
policy_module(zabbix, 1.7.0)
|
||||
policy_module(zabbix, 1.6.0)
|
||||
|
||||
########################################
|
||||
#
|
||||
|
|
@ -284,53 +284,22 @@ zabbix_tcp_connect(zabbix_agent_t)
|
|||
|
||||
zabbix_script_domtrans(zabbix_agent_t)
|
||||
|
||||
# These are triggered by vfs.dev.discovery enumerating everyting in /dev
|
||||
gen_require(`
|
||||
type devlog_t;
|
||||
')
|
||||
dontaudit zabbix_agent_t devlog_t:sock_file getattr;
|
||||
init_dontaudit_getattr_initctl(zabbix_agent_t)
|
||||
kernel_dontaudit_getattr_core_if(zabbix_agent_t)
|
||||
|
||||
gen_require(`
|
||||
type kernel_t, sudo_log_t;
|
||||
')
|
||||
tunable_policy(`zabbix_run_sudo',`
|
||||
allow zabbix_agent_t self:capability { chown dac_read_search setgid setuid sys_resource };
|
||||
allow zabbix_agent_t self:capability { setgid setuid sys_resource };
|
||||
allow zabbix_agent_t self:process { setrlimit setsched };
|
||||
allow zabbix_agent_t self:key write;
|
||||
allow zabbix_agent_t self:passwd { passwd rootok };
|
||||
|
||||
allow zabbix_agent_t sudo_log_t:dir { add_name create setattr write };
|
||||
allow zabbix_agent_t sudo_log_t:file { create open read setattr write };
|
||||
|
||||
allow zabbix_agent_t devlog_t:sock_file write;
|
||||
allow zabbix_agent_t kernel_t:unix_dgram_socket sendto;
|
||||
allow zabbix_agent_t self:unix_dgram_socket { connect create };
|
||||
|
||||
auth_domtrans_chkpwd(zabbix_agent_t)
|
||||
auth_rw_lastlog(zabbix_agent_t)
|
||||
auth_rw_faillog(zabbix_agent_t)
|
||||
|
||||
logging_send_audit_msgs(zabbix_agent_t)
|
||||
auth_exec_chkpwd(zabbix_agent_t)
|
||||
|
||||
selinux_compute_access_vector(zabbix_agent_t)
|
||||
|
||||
sssd_read_config(zabbix_agent_t)
|
||||
|
||||
systemd_write_inherited_logind_sessions_pipes(zabbix_agent_t)
|
||||
systemd_dbus_chat_logind(zabbix_agent_t)
|
||||
|
||||
xserver_exec_xauth(zabbix_agent_t)
|
||||
|
||||
# Conceivably this could be under a separate boolean, but the reason to allow sudo
|
||||
# is to allow check like this
|
||||
lvm_domtrans(zabbix_agent_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
rpm_exec(zabbix_agent_t)
|
||||
rpm_read_db(zabbix_agent_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
|
|
@ -361,10 +330,6 @@ allow zabbix_t zabbix_script_t:process signal;
|
|||
|
||||
init_domtrans_script(zabbix_script_t)
|
||||
|
||||
optional_policy(`
|
||||
chronyd_domtrans_chronyc(zabbix_script_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
mta_send_mail(zabbix_script_t)
|
||||
')
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue