Compare commits
14 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
802cd05a3f | ||
|
|
c6ab2b369a | ||
|
|
d440861715 | ||
|
|
43636de6ac | ||
|
|
9d2baf599a | ||
|
|
13ad086bf4 | ||
|
|
5db8a1fbc4 | ||
|
|
3e916a126f | ||
|
|
f3b1c8bd8e | ||
|
|
125e8b2742 | ||
|
|
21bcd94fce | ||
|
|
4ef5538812 | ||
|
|
e18fae44a1 | ||
|
|
be957d936d |
21 changed files with 3090 additions and 0 deletions
10
.gitignore
vendored
Normal file
10
.gitignore
vendored
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
/zabbix-6.0.8.tar.gz
|
||||
/zabbix-6.0.12.tar.gz
|
||||
/zabbix-6.0.13.tar.gz
|
||||
/zabbix-6.0.14.tar.gz
|
||||
/zabbix-6.0.15.tar.gz
|
||||
/zabbix-6.0.16.tar.gz
|
||||
/zabbix-6.0.19.tar.gz
|
||||
/zabbix-6.0.22.tar.gz
|
||||
/zabbix-6.0.25.tar.gz
|
||||
/zabbix-6.0.29.tar.gz
|
||||
1
sources
Normal file
1
sources
Normal file
|
|
@ -0,0 +1 @@
|
|||
SHA512 (zabbix-6.0.29.tar.gz) = 3189a534e250a02f7661340700d6c6d852eeae552db8a15f94e6d917aea84f7292660a22580d6fc59479498aedecdbf58b19c51b649266a9de229f0d0c35c3e0
|
||||
11
zabbix-agent.service
Normal file
11
zabbix-agent.service
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
[Unit]
|
||||
Description=Zabbix Monitor Agent
|
||||
After=syslog.target network.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
ExecStart=/usr/sbin/zabbix_agentd -f
|
||||
User=zabbix
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
45
zabbix-config.patch
Normal file
45
zabbix-config.patch
Normal file
|
|
@ -0,0 +1,45 @@
|
|||
diff -up zabbix-6.0.2/ui/include/classes/core/CConfigFile.php.config zabbix-6.0.2/ui/include/classes/core/CConfigFile.php
|
||||
--- zabbix-6.0.2/ui/include/classes/core/CConfigFile.php.config 2022-03-23 08:38:25.049013803 -0600
|
||||
+++ zabbix-6.0.2/ui/include/classes/core/CConfigFile.php 2022-03-23 08:39:25.001657019 -0600
|
||||
@@ -25,7 +25,7 @@ class CConfigFile {
|
||||
const CONFIG_ERROR = 2;
|
||||
const CONFIG_VAULT_ERROR = 3;
|
||||
|
||||
- const CONFIG_FILE_PATH = '/conf/zabbix.conf.php';
|
||||
+ const CONFIG_FILE_PATH = '/etc/zabbix/web/zabbix.conf.php';
|
||||
|
||||
private static $supported_db_types = [
|
||||
ZBX_DB_MYSQL => true,
|
||||
diff -up zabbix-6.0.2/ui/include/classes/core/ZBase.php.config zabbix-6.0.2/ui/include/classes/core/ZBase.php
|
||||
--- zabbix-6.0.2/ui/include/classes/core/ZBase.php.config 2022-03-14 03:57:00.000000000 -0600
|
||||
+++ zabbix-6.0.2/ui/include/classes/core/ZBase.php 2022-03-23 08:38:25.052013836 -0600
|
||||
@@ -368,7 +368,7 @@ class ZBase {
|
||||
* @throws Exception
|
||||
*/
|
||||
protected function setMaintenanceMode() {
|
||||
- require_once 'conf/maintenance.inc.php';
|
||||
+ require_once '/etc/zabbix/web/maintenance.inc.php';
|
||||
|
||||
if (defined('ZBX_DENY_GUI_ACCESS')) {
|
||||
if (!isset($ZBX_GUI_ACCESS_IP_RANGE) || !in_array(CWebUser::getIp(), $ZBX_GUI_ACCESS_IP_RANGE)) {
|
||||
@@ -381,7 +381,7 @@ class ZBase {
|
||||
* Load zabbix config file.
|
||||
*/
|
||||
protected function loadConfigFile() {
|
||||
- $configFile = $this->getRootDir().CConfigFile::CONFIG_FILE_PATH;
|
||||
+ $configFile = CConfigFile::CONFIG_FILE_PATH;
|
||||
$config = new CConfigFile($configFile);
|
||||
$this->config = $config->load();
|
||||
}
|
||||
diff -up zabbix-6.0.2/ui/include/classes/setup/CSetupWizard.php.config zabbix-6.0.2/ui/include/classes/setup/CSetupWizard.php
|
||||
--- zabbix-6.0.2/ui/include/classes/setup/CSetupWizard.php.config 2022-03-14 03:57:00.000000000 -0600
|
||||
+++ zabbix-6.0.2/ui/include/classes/setup/CSetupWizard.php 2022-03-23 08:38:25.054013857 -0600
|
||||
@@ -271,7 +271,7 @@ class CSetupWizard extends CForm {
|
||||
// make zabbix.conf.php downloadable
|
||||
header('Content-Type: application/x-httpd-php');
|
||||
header('Content-Disposition: attachment; filename="'.basename(CConfigFile::CONFIG_FILE_PATH).'"');
|
||||
- $config = new CConfigFile(APP::getInstance()->getRootDir().CConfigFile::CONFIG_FILE_PATH);
|
||||
+ $config = new CConfigFile(CConfigFile::CONFIG_FILE_PATH);
|
||||
$config->config = [
|
||||
'DB' => [
|
||||
'TYPE' => $this->getConfig('DB_TYPE'),
|
||||
30
zabbix-crypto-policy.patch
Normal file
30
zabbix-crypto-policy.patch
Normal file
|
|
@ -0,0 +1,30 @@
|
|||
diff -up zabbix-5.0.2/src/libs/zbxcrypto/tls.c.crypto-policy zabbix-5.0.2/src/libs/zbxcrypto/tls.c
|
||||
--- zabbix-5.0.2/src/libs/zbxcrypto/tls.c.crypto-policy 2020-07-06 03:54:32.000000000 -0600
|
||||
+++ zabbix-5.0.2/src/libs/zbxcrypto/tls.c 2020-07-18 21:22:13.125099598 -0600
|
||||
@@ -2932,7 +2932,7 @@ void zbx_tls_init_child(void)
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
- else if (1 != SSL_CTX_set_cipher_list(ctx_cert, ciphers))
|
||||
+ else if (1 != SSL_CTX_set_cipher_list(ctx_cert, "PROFILE=SYSTEM"))
|
||||
{
|
||||
zbx_snprintf_alloc(&error, &error_alloc, &error_offset, "cannot set list of certificate"
|
||||
" ciphersuites:");
|
||||
@@ -3014,7 +3014,7 @@ void zbx_tls_init_child(void)
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
- else if (1 != SSL_CTX_set_cipher_list(ctx_psk, ciphers))
|
||||
+ else if (1 != SSL_CTX_set_cipher_list(ctx_psk, "PROFILE=SYSTEM"))
|
||||
{
|
||||
zbx_snprintf_alloc(&error, &error_alloc, &error_offset, "cannot set list of PSK ciphersuites:");
|
||||
goto out;
|
||||
@@ -3070,7 +3070,7 @@ void zbx_tls_init_child(void)
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
- else if (1 != SSL_CTX_set_cipher_list(ctx_all, ciphers))
|
||||
+ else if (1 != SSL_CTX_set_cipher_list(ctx_all, "PROFILE=SYSTEM"))
|
||||
{
|
||||
zbx_snprintf_alloc(&error, &error_alloc, &error_offset, "cannot set list of all ciphersuites:");
|
||||
goto out;
|
||||
217
zabbix-fedora-epel.README
Normal file
217
zabbix-fedora-epel.README
Normal file
|
|
@ -0,0 +1,217 @@
|
|||
=Custom in Fedora/EPEL=
|
||||
|
||||
==Pinger files==
|
||||
|
||||
Since /tmp is not a good place to spool files, the pinger files shall now reside
|
||||
in /var/lib/zabbixsrv/tmp. This directory is automatically created and proxy and
|
||||
server configuration files are changed accordingly from 2.0.8 on.
|
||||
|
||||
|
||||
==Web configuration==
|
||||
|
||||
Web configuration resides in /etc/zabbix/web. The configuration file can be
|
||||
created manually or by walking through the frontend setup tool, as soon as your
|
||||
httpd configuration allows. The directory also contains maintenance.inc.php!
|
||||
|
||||
|
||||
==Log files==
|
||||
|
||||
Log files are located in /var/log/zabbix for the agent and /var/log/zabbixsrv.
|
||||
for server and proxy.
|
||||
|
||||
|
||||
==No htaccess files==
|
||||
|
||||
Fedora ships an Apache configuration file instead. This solutions performs
|
||||
better and is easier to maintain.
|
||||
|
||||
|
||||
==Two users and groups==
|
||||
|
||||
There's a certain security risk involved, running agent and proxy/server as the
|
||||
same user. This package therefore introduces an additional zabbixsrv user, used
|
||||
for proxy and server. Please check the permissions of your scripts and group
|
||||
memberships, if necessary.
|
||||
|
||||
|
||||
==Using the Alternatives system instead of conflicting sub-packages==
|
||||
|
||||
You can now install Zabbix proxies or servers compiled for different database
|
||||
back-ends on the same system. While this is not intended to happily switch back
|
||||
and forth, it allows you to:
|
||||
|
||||
- Stop the daemon
|
||||
- "Run alternatives --config zabbix-server" or
|
||||
"alternatives --config zabbix-proxy"
|
||||
- Make your choice
|
||||
- If you're using systemd, run systemctl reload
|
||||
- Adjust the configuration file
|
||||
- Start the daemon
|
||||
- In some cases you have to use "restart" instead of "start".
|
||||
The reason is not yet clear to me.
|
||||
|
||||
"Alternatives" considers the first installed implementation of server or proxy as
|
||||
default, respectively.
|
||||
|
||||
Don't forget to reconfigure the front-end when you switch the server to a
|
||||
different DB implementation!
|
||||
|
||||
|
||||
==How to run multiple instances of a Zabbix daemon with init scripts==
|
||||
|
||||
If you want to run multiple instances on the same host, do the following:
|
||||
|
||||
- Copy or symlink the init scripts
|
||||
- Create a file of the same name as the new init script in /etc/sysconfig
|
||||
- Define CFG_FILE="</path/to/daemon_config_file>" in this file
|
||||
- Create the file defined as CFG_FILE and adjust settings; in particular:
|
||||
- DB settings if you set up multiple instances of server and proxy daemons;
|
||||
IMPORTANT: Two daemons using the same database at the same time could act
|
||||
destructive!
|
||||
- PidFile
|
||||
- ListenPort and/or ListenIP, if you plan for simultaneous operation;
|
||||
Don't forget to review your firewall settings!
|
||||
- LogFile, if you don't use syslog
|
||||
- Optionally run the following to register the new instance as a service and
|
||||
start it up automatically:
|
||||
chkconfig --add <init_script_name>
|
||||
chkconfig <init_script_name> on
|
||||
- service <init_script_name> start
|
||||
|
||||
|
||||
==Configuration changes==
|
||||
|
||||
Zabbix 2.0 and later place configuration files directly in /etc. Symlinks preserve
|
||||
compatibility. maintenance.inc.php moved from /usr/share/zabbix/conf to
|
||||
/etc/zabbix/web. Be careful not to replace the symlinks with files by mistake,
|
||||
as the agent will not pick them up!
|
||||
|
||||
|
||||
==Media scripts and external scripts==
|
||||
|
||||
The directories for external scripts and media scripts have moved to
|
||||
/var/lib/zabbixsrv. Symlinks preserve compatibility.
|
||||
|
||||
/var/lib/zabbix is now intended for scripts run by the agent. Please move your
|
||||
server or proxy scripts to /var/lib/zabbixsrv. Be sure to check permissions and
|
||||
ownership.
|
||||
|
||||
|
||||
==No Java bridge==
|
||||
|
||||
The Zabbix Java bridge can not be included now, due to missing dependencies.
|
||||
|
||||
|
||||
=SELinux=
|
||||
|
||||
The settings necessary for you vary, depending on how you set up your system/s.
|
||||
Most of the time, the only adjustments necessary should be on the machine that
|
||||
holds the frontend:
|
||||
|
||||
#Allow to connect the frontend to a database by other means than sockets
|
||||
setsebool -P httpd_can_network_connect_db 1
|
||||
|
||||
#Allow the frontend to create a connection to the server listening port
|
||||
#That's the check the frontend uses to see whether the server is running.
|
||||
#This option effectively supersedes the previous
|
||||
setsebool -P httpd_can_network_connect 1
|
||||
|
||||
Using sebools is a somewhat coarse method of allowing things.
|
||||
A more fine-grained approach for the latter would be to grab an actual
|
||||
avc denial from the audit log, pipe it through audit2allow, put it in a
|
||||
module package and load that:
|
||||
|
||||
echo "avc: denied { name_connect } for pid=20619 comm="httpd" dest=10051 scontext=system_u:system_r:httpd_t:s0 tcontext=system_u:object_r:zabbix_port_t:s0 tclass=tcp_socket" | audit2allow -M zabbix_conn_httpd; sudo semodule -i zabbix_conn_httpd.pp
|
||||
|
||||
If you're using ping from the frontend:
|
||||
|
||||
echo "avc: denied { setpgid } for pid=31880 comm="zabbix_server_p" scontext=system_u:system_r:zabbix_t:s0 tcontext=system_u:system_r:zabbix_t:s0 tclass=process" | audit2allow -M zabbix_ping_frontend; sudo semodule -i zabbix_ping_frontend.pp
|
||||
|
||||
|
||||
=Additional packaging changes in Fedora/EPEL since 3.0=
|
||||
|
||||
==Configuration files contain the actual defaults==
|
||||
Previously, the defaults in the config file were replaced by settings that
|
||||
are suitable for Fedora. For non-mandatory settings, the daemon would default
|
||||
to the hardcoded setting though, which is confusing. To make this
|
||||
obvious, the original default settings are left in place and additional lines
|
||||
added instead.
|
||||
|
||||
==Daemons are running in the foreground mode==
|
||||
Systemd is more happy with this and it also solves the problem for the pidfile
|
||||
setting, described in BZ #1220392. It is related to the above-mentioned.
|
||||
|
||||
==Minimal PHP configuration==
|
||||
The httpd configuration contains the minimal settings necessary to operate
|
||||
the frontend. Please refer to the manual for details:
|
||||
https://www.zabbix.com/documentation/3.0/manual/installation/install
|
||||
|
||||
Make sure to review these settings!
|
||||
|
||||
|
||||
=Additional packaging changes in Fedora/EPEL since 2.0=
|
||||
|
||||
==Zabbix 2.2 conflicts 1.8 and 2.0==
|
||||
|
||||
Please see the below section for the reason!
|
||||
|
||||
|
||||
==Agent init script/unit file name==
|
||||
For the sake of consistency between distributions, the agent init script,
|
||||
respectively the systemd unit file, was renamed to zabbix-agentd -- mind the
|
||||
trailing "d"! Symlinks with the old names are in place. Keep in mind, if
|
||||
you created a configuration file in /etc/sysconfig, the sourced file must
|
||||
the name of the init script you invoke! Consequently, if you decide to use
|
||||
zabbix-agentd in the future, copy or symlink this file.
|
||||
|
||||
|
||||
==zabbixsrv now has its own user group==
|
||||
|
||||
zabbixsrv used to be a member of the zabbix user group. Completely fresh
|
||||
installations will create the zabbixsrv group and assign it as the primary
|
||||
group. If the user zabbixsrv already exists (upgrade from 2.0), the user group
|
||||
is replaced.
|
||||
|
||||
|
||||
==Log and lock file locations, group membership==
|
||||
|
||||
All logs used to be in /var/log/zabbix. With zabbixsrv having its own
|
||||
user group, the logs are now split between /var/log/zabbix for the agent and
|
||||
/var/log/zabbixsrv for server and proxy.
|
||||
|
||||
|
||||
=Additional packaging changes in Fedora/EPEL since 1.8=
|
||||
|
||||
==Zabbix 2.0 packages conflict Zabbix 1.8; 2.2 conflicts 1.8 and 2.0==
|
||||
|
||||
This measure was taken because this major version introduces various database
|
||||
schema changes. A silent update would render Zabbix non-operational and possibly
|
||||
break the database. Besides that, Zabbix 2.0/2.2 server only works with the
|
||||
respective major versions of servers and proxies. Distributed setups must
|
||||
therefore be updated at the same time to keep working.
|
||||
|
||||
http://www.zabbix.com/documentation/2.0/manual/appendix/compatibility
|
||||
http://www.zabbix.com/documentation/2.2/manual/appendix/compatibility
|
||||
|
||||
--------------------------------------------------------------------------------
|
||||
|
||||
=Guide for upgrading to 2.2 from 2.0=
|
||||
|
||||
https://www.zabbix.com/documentation/2.2/manual/installation/upgrade
|
||||
https://www.zabbix.com/documentation/2.2/manual/installation/upgrade_notes_220
|
||||
|
||||
Be sure to read the upgrades notes of the latest minor release too!
|
||||
|
||||
- Review all rpmnew and rpmsave files; merge where necessary
|
||||
- Review permissions, ownerships and group memberships for zabbixsrv
|
||||
- Migrate server and proxy logs to the new location, if you want
|
||||
- Back up the Zabbix database (really!)
|
||||
- Remove custom database changes, if any
|
||||
- Make sure the database user has sufficing permissions
|
||||
(ALTER TABLE, DROP INDEX, DROP TABLE, ...)
|
||||
- Start the server
|
||||
- Check the server log for progress and possible errors
|
||||
The schema conversion should finish within minutes or hours
|
||||
|
||||
|
||||
Volker Fröhlich volker27@gmx.at Jan 5 2013
|
||||
8
zabbix-logrotate.in
Normal file
8
zabbix-logrotate.in
Normal file
|
|
@ -0,0 +1,8 @@
|
|||
/var/log/USER/zabbix_COMPONENT.log {
|
||||
missingok
|
||||
monthly
|
||||
notifempty
|
||||
compress
|
||||
copytruncate
|
||||
su USER USER
|
||||
}
|
||||
1120
zabbix-out-of-tree.patch
Normal file
1120
zabbix-out-of-tree.patch
Normal file
File diff suppressed because it is too large
Load diff
24
zabbix-php-fpm.conf
Normal file
24
zabbix-php-fpm.conf
Normal file
|
|
@ -0,0 +1,24 @@
|
|||
[zabbix]
|
||||
user = apache
|
||||
group = apache
|
||||
|
||||
listen = /run/php-fpm/zabbix.sock
|
||||
listen.acl_users = apache,nginx
|
||||
listen.allowed_clients = 127.0.0.1
|
||||
|
||||
pm = dynamic
|
||||
pm.max_children = 50
|
||||
pm.start_servers = 5
|
||||
pm.min_spare_servers = 5
|
||||
pm.max_spare_servers = 35
|
||||
|
||||
php_value[session.save_handler] = files
|
||||
php_value[session.save_path] = /var/lib/php/session
|
||||
|
||||
php_value[max_execution_time] = 300
|
||||
php_value[memory_limit] = 128M
|
||||
php_value[post_max_size] = 16M
|
||||
php_value[upload_max_filesize] = 2M
|
||||
php_value[max_input_time] = 300
|
||||
php_value[max_input_vars] = 10000
|
||||
; php_value[date.timezone] = Europe/Riga
|
||||
11
zabbix-proxy-mysql.service
Normal file
11
zabbix-proxy-mysql.service
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
[Unit]
|
||||
Description=Zabbix MySQL Proxy
|
||||
After=syslog.target network.target mysqld.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
ExecStart=/usr/sbin/zabbix_proxy -f
|
||||
User=zabbixsrv
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
11
zabbix-proxy-pgsql.service
Normal file
11
zabbix-proxy-pgsql.service
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
[Unit]
|
||||
Description=Zabbix PostgreSQL Proxy
|
||||
After=syslog.target network.target postgresql.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
ExecStart=/usr/sbin/zabbix_proxy -f
|
||||
User=zabbixsrv
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
11
zabbix-proxy-sqlite3.service
Normal file
11
zabbix-proxy-sqlite3.service
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
[Unit]
|
||||
Description=Zabbix SQLite3 Proxy
|
||||
After=syslog.target network.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
ExecStart=/usr/sbin/zabbix_proxy -f
|
||||
User=zabbixsrv
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
11
zabbix-server-mysql.service
Normal file
11
zabbix-server-mysql.service
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
[Unit]
|
||||
Description=Zabbix Server with MySQL DB
|
||||
After=syslog.target network.target mysqld.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
ExecStart=/usr/sbin/zabbix_server -f
|
||||
User=zabbixsrv
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
11
zabbix-server-pgsql.service
Normal file
11
zabbix-server-pgsql.service
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
[Unit]
|
||||
Description=Zabbix Server with PostgreSQL DB
|
||||
After=syslog.target network.target postgresql.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
ExecStart=/usr/sbin/zabbix_server -f
|
||||
User=zabbixsrv
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
1
zabbix-tmpfiles-zabbix.conf
Normal file
1
zabbix-tmpfiles-zabbix.conf
Normal file
|
|
@ -0,0 +1 @@
|
|||
D /run/zabbix 0755 zabbix zabbix -
|
||||
1
zabbix-tmpfiles-zabbixsrv.conf
Normal file
1
zabbix-tmpfiles-zabbixsrv.conf
Normal file
|
|
@ -0,0 +1 @@
|
|||
D /run/zabbixsrv 0755 zabbixsrv zabbixsrv -
|
||||
35
zabbix-web.conf
Normal file
35
zabbix-web.conf
Normal file
|
|
@ -0,0 +1,35 @@
|
|||
#
|
||||
# Zabbix monitoring system php web frontend
|
||||
#
|
||||
|
||||
Alias /zabbix /usr/share/zabbix
|
||||
|
||||
<Directory "/usr/share/zabbix">
|
||||
Options FollowSymLinks
|
||||
AllowOverride None
|
||||
Require all granted
|
||||
|
||||
<IfModule dir_module>
|
||||
DirectoryIndex index.php
|
||||
</IfModule>
|
||||
|
||||
<FilesMatch \.(php|phar)$>
|
||||
SetHandler "proxy:unix:/run/php-fpm/zabbix.sock|fcgi://localhost"
|
||||
</FilesMatch>
|
||||
</Directory>
|
||||
|
||||
<Directory "/usr/share/zabbix/conf">
|
||||
Require all denied
|
||||
</Directory>
|
||||
|
||||
<Directory "/usr/share/zabbix/app">
|
||||
Require all denied
|
||||
</Directory>
|
||||
|
||||
<Directory "/usr/share/zabbix/include">
|
||||
Require all denied
|
||||
</Directory>
|
||||
|
||||
<Directory "/usr/share/zabbix/local">
|
||||
Require all denied
|
||||
</Directory>
|
||||
25
zabbix.fc
Normal file
25
zabbix.fc
Normal file
|
|
@ -0,0 +1,25 @@
|
|||
/etc/rc\.d/init\.d/(zabbix|zabbix-server) -- gen_context(system_u:object_r:zabbix_initrc_exec_t,s0)
|
||||
/etc/rc\.d/init\.d/zabbix-agentd -- gen_context(system_u:object_r:zabbix_agent_initrc_exec_t,s0)
|
||||
|
||||
/usr/bin/zabbix_server -- gen_context(system_u:object_r:zabbix_exec_t,s0)
|
||||
/usr/bin/zabbix_agentd -- gen_context(system_u:object_r:zabbix_agent_exec_t,s0)
|
||||
|
||||
/usr/sbin/zabbix_agentd -- gen_context(system_u:object_r:zabbix_agent_exec_t,s0)
|
||||
/usr/sbin/zabbix_server -- gen_context(system_u:object_r:zabbix_exec_t,s0)
|
||||
/usr/sbin/zabbix_server_mysql -- gen_context(system_u:object_r:zabbix_exec_t,s0)
|
||||
/usr/sbin/zabbix_server_pgsql -- gen_context(system_u:object_r:zabbix_exec_t,s0)
|
||||
/usr/sbin/zabbix_server_sqlite3 -- gen_context(system_u:object_r:zabbix_exec_t,s0)
|
||||
/usr/sbin/zabbix_proxy -- gen_context(system_u:object_r:zabbix_exec_t,s0)
|
||||
/usr/sbin/zabbix_proxy_mysql -- gen_context(system_u:object_r:zabbix_exec_t,s0)
|
||||
/usr/sbin/zabbix_proxy_pgsql -- gen_context(system_u:object_r:zabbix_exec_t,s0)
|
||||
/usr/sbin/zabbix_proxy_sqlite3 -- gen_context(system_u:object_r:zabbix_exec_t,s0)
|
||||
|
||||
/var/lib/zabbix(/.*)? gen_context(system_u:object_r:zabbix_var_lib_t,s0)
|
||||
|
||||
/var/lib/zabbixsrv(/.*)? gen_context(system_u:object_r:zabbix_var_lib_t,s0)
|
||||
/var/lib/zabbixsrv/.*scripts(/.*)? gen_context(system_u:object_r:zabbix_script_exec_t,s0)
|
||||
/var/lib/zabbixsrv/tmp(/.*)? gen_context(system_u:object_r:zabbix_tmp_t,s0)
|
||||
|
||||
/var/log/zabbix.* gen_context(system_u:object_r:zabbix_log_t,s0)
|
||||
|
||||
/var/run/zabbix(/.*)? gen_context(system_u:object_r:zabbix_var_run_t,s0)
|
||||
199
zabbix.if
Normal file
199
zabbix.if
Normal file
|
|
@ -0,0 +1,199 @@
|
|||
## <summary>Distributed infrastructure monitoring</summary>
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Execute a domain transition to run zabbix.
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed to transition.
|
||||
## </summary>
|
||||
## </param>
|
||||
#
|
||||
interface(`zabbix_domtrans',`
|
||||
gen_require(`
|
||||
type zabbix_t, zabbix_exec_t;
|
||||
')
|
||||
|
||||
domtrans_pattern($1, zabbix_exec_t, zabbix_t)
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Execute a domain transition to run zabbix_script.
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed to transition.
|
||||
## </summary>
|
||||
## </param>
|
||||
#
|
||||
interface(`zabbix_script_domtrans',`
|
||||
gen_require(`
|
||||
type zabbix_script_t, zabbix_script_exec_t;
|
||||
')
|
||||
|
||||
domtrans_pattern($1, zabbix_script_exec_t, zabbix_script_t)
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Allow connectivity to the zabbix server
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed access.
|
||||
## </summary>
|
||||
## </param>
|
||||
#
|
||||
interface(`zabbix_tcp_connect',`
|
||||
gen_require(`
|
||||
type zabbix_t;
|
||||
')
|
||||
|
||||
corenet_sendrecv_zabbix_agent_client_packets($1)
|
||||
corenet_tcp_connect_zabbix_port($1)
|
||||
corenet_tcp_recvfrom_labeled($1, zabbix_t)
|
||||
corenet_tcp_sendrecv_zabbix_port($1)
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Allow the specified domain to read zabbix's log files.
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed access.
|
||||
## </summary>
|
||||
## </param>
|
||||
## <rolecap/>
|
||||
#
|
||||
interface(`zabbix_read_log',`
|
||||
gen_require(`
|
||||
type zabbix_log_t;
|
||||
')
|
||||
|
||||
logging_search_logs($1)
|
||||
read_files_pattern($1, zabbix_log_t, zabbix_log_t)
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Allow the specified domain to read zabbix's tmp files.
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed access.
|
||||
## </summary>
|
||||
## </param>
|
||||
## <rolecap/>
|
||||
#
|
||||
interface(`zabbix_read_tmp',`
|
||||
gen_require(`
|
||||
type zabbix_tmp_t;
|
||||
')
|
||||
|
||||
files_search_tmp($1)
|
||||
read_files_pattern($1, zabbix_tmp_t, zabbix_tmp_t)
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Allow the specified domain to append
|
||||
## zabbix log files.
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed access.
|
||||
## </summary>
|
||||
## </param>
|
||||
#
|
||||
interface(`zabbix_append_log',`
|
||||
gen_require(`
|
||||
type zabbix_log_t;
|
||||
')
|
||||
|
||||
logging_search_logs($1)
|
||||
append_files_pattern($1, zabbix_log_t, zabbix_log_t)
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Read zabbix PID files.
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed access.
|
||||
## </summary>
|
||||
## </param>
|
||||
#
|
||||
interface(`zabbix_read_pid_files',`
|
||||
gen_require(`
|
||||
type zabbix_var_run_t;
|
||||
')
|
||||
|
||||
files_search_pids($1)
|
||||
allow $1 zabbix_var_run_t:file read_file_perms;
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Allow connectivity to a zabbix agent
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed access.
|
||||
## </summary>
|
||||
## </param>
|
||||
#
|
||||
interface(`zabbix_agent_tcp_connect',`
|
||||
gen_require(`
|
||||
type zabbix_t, zabbix_agent_t;
|
||||
')
|
||||
|
||||
corenet_sendrecv_zabbix_agent_client_packets($1)
|
||||
corenet_tcp_connect_zabbix_agent_port($1)
|
||||
corenet_tcp_recvfrom_labeled($1, zabbix_t)
|
||||
corenet_tcp_sendrecv_zabbix_agent_port($1)
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## All of the rules required to administrate
|
||||
## an zabbix environment
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed access.
|
||||
## </summary>
|
||||
## </param>
|
||||
## <param name="role">
|
||||
## <summary>
|
||||
## The role to be allowed to manage the zabbix domain.
|
||||
## </summary>
|
||||
## </param>
|
||||
## <rolecap/>
|
||||
#
|
||||
interface(`zabbix_admin',`
|
||||
gen_require(`
|
||||
type zabbix_t, zabbix_log_t, zabbix_var_run_t;
|
||||
type zabbix_initrc_exec_t;
|
||||
')
|
||||
|
||||
allow $1 zabbix_t:process signal_perms;
|
||||
ps_process_pattern($1, zabbix_t)
|
||||
tunable_policy(`deny_ptrace',`',`
|
||||
allow $1 zabbix_t:process ptrace;
|
||||
')
|
||||
|
||||
init_labeled_script_domtrans($1, zabbix_initrc_exec_t)
|
||||
domain_system_change_exemption($1)
|
||||
role_transition $2 zabbix_initrc_exec_t system_r;
|
||||
allow $2 system_r;
|
||||
|
||||
logging_list_logs($1)
|
||||
admin_pattern($1, zabbix_log_t)
|
||||
|
||||
files_list_pids($1)
|
||||
admin_pattern($1, zabbix_var_run_t)
|
||||
')
|
||||
374
zabbix.te
Normal file
374
zabbix.te
Normal file
|
|
@ -0,0 +1,374 @@
|
|||
policy_module(zabbix, 1.7.0)
|
||||
|
||||
########################################
|
||||
#
|
||||
# Declarations
|
||||
#
|
||||
|
||||
## <desc>
|
||||
## <p>
|
||||
## Determine whether zabbix can
|
||||
## connect to all TCP ports
|
||||
## </p>
|
||||
## </desc>
|
||||
gen_tunable(zabbix_can_network, false)
|
||||
|
||||
|
||||
## <desc>
|
||||
## <p>
|
||||
## Allow Zabbix to run su/sudo.
|
||||
## </p>
|
||||
## </desc>
|
||||
gen_tunable(zabbix_run_sudo, false)
|
||||
|
||||
gen_require(`
|
||||
class passwd rootok;
|
||||
class passwd passwd;
|
||||
')
|
||||
|
||||
attribute zabbix_domain;
|
||||
|
||||
type zabbix_t, zabbix_domain;
|
||||
type zabbix_exec_t;
|
||||
init_daemon_domain(zabbix_t, zabbix_exec_t)
|
||||
|
||||
type zabbix_initrc_exec_t;
|
||||
init_script_file(zabbix_initrc_exec_t)
|
||||
|
||||
type zabbix_agent_t, zabbix_domain;
|
||||
type zabbix_agent_exec_t;
|
||||
init_daemon_domain(zabbix_agent_t, zabbix_agent_exec_t)
|
||||
|
||||
type zabbix_agent_initrc_exec_t;
|
||||
init_script_file(zabbix_agent_initrc_exec_t)
|
||||
|
||||
type zabbixd_var_lib_t;
|
||||
files_type(zabbixd_var_lib_t)
|
||||
|
||||
type zabbix_log_t;
|
||||
logging_log_file(zabbix_log_t)
|
||||
|
||||
type zabbix_tmp_t;
|
||||
files_tmp_file(zabbix_tmp_t)
|
||||
|
||||
type zabbix_tmpfs_t;
|
||||
files_tmpfs_file(zabbix_tmpfs_t)
|
||||
|
||||
type zabbix_var_lib_t;
|
||||
files_type(zabbix_var_lib_t)
|
||||
|
||||
type zabbix_var_run_t;
|
||||
files_pid_file(zabbix_var_run_t)
|
||||
|
||||
type zabbix_script_t;
|
||||
type zabbix_script_exec_t;
|
||||
domain_type(zabbix_script_t)
|
||||
domain_entry_file(zabbix_script_t, zabbix_script_exec_t)
|
||||
application_executable_file(zabbix_script_exec_t)
|
||||
role system_r types zabbix_script_t;
|
||||
|
||||
########################################
|
||||
#
|
||||
# zabbix domain local policy
|
||||
#
|
||||
|
||||
allow zabbix_domain self:capability { setgid setuid };
|
||||
allow zabbix_domain self:process { getsched setpgid setsched signal_perms };
|
||||
allow zabbix_domain self:fifo_file rw_fifo_file_perms;
|
||||
allow zabbix_domain self:sem create_sem_perms;
|
||||
allow zabbix_domain self:shm create_shm_perms;
|
||||
allow zabbix_domain self:tcp_socket { accept listen };
|
||||
allow zabbix_domain self:unix_stream_socket create_stream_socket_perms;
|
||||
|
||||
kernel_read_all_sysctls(zabbix_domain)
|
||||
kernel_read_network_state(zabbix_domain)
|
||||
|
||||
corenet_tcp_sendrecv_generic_if(zabbix_domain)
|
||||
corenet_tcp_sendrecv_generic_node(zabbix_domain)
|
||||
corenet_tcp_bind_generic_node(zabbix_domain)
|
||||
|
||||
corecmd_exec_shell(zabbix_domain)
|
||||
corecmd_exec_bin(zabbix_domain)
|
||||
|
||||
dev_read_sysfs(zabbix_domain)
|
||||
dev_read_urand(zabbix_domain)
|
||||
|
||||
########################################
|
||||
#
|
||||
# Local policy
|
||||
#
|
||||
|
||||
allow zabbix_t self:capability { dac_read_search };
|
||||
allow zabbix_t self:process { setrlimit };
|
||||
allow zabbix_t self:unix_stream_socket connectto;
|
||||
|
||||
manage_dirs_pattern(zabbix_t, zabbix_var_lib_t, zabbix_var_lib_t)
|
||||
manage_files_pattern(zabbix_t, zabbix_var_lib_t, zabbix_var_lib_t)
|
||||
manage_lnk_files_pattern(zabbix_t, zabbix_var_lib_t, zabbix_var_lib_t)
|
||||
manage_sock_files_pattern(zabbix_t, zabbix_var_lib_t, zabbix_var_lib_t)
|
||||
files_var_lib_filetrans(zabbix_t, zabbix_var_lib_t, dir, "zabbixsrv")
|
||||
|
||||
manage_dirs_pattern(zabbix_t, zabbix_log_t, zabbix_log_t)
|
||||
manage_files_pattern(zabbix_t, zabbix_log_t, zabbix_log_t)
|
||||
manage_lnk_files_pattern(zabbix_t, zabbix_log_t, zabbix_log_t)
|
||||
logging_log_filetrans(zabbix_t, zabbix_log_t, { dir file })
|
||||
|
||||
manage_dirs_pattern(zabbix_t, zabbix_tmp_t, zabbix_tmp_t)
|
||||
manage_files_pattern(zabbix_t, zabbix_tmp_t, zabbix_tmp_t)
|
||||
manage_sock_files_pattern(zabbix_t, zabbix_tmp_t, zabbix_tmp_t)
|
||||
files_tmp_filetrans(zabbix_t, zabbix_tmp_t, { dir file sock_file })
|
||||
|
||||
rw_files_pattern(zabbix_t, zabbix_tmpfs_t, zabbix_tmpfs_t)
|
||||
fs_tmpfs_filetrans(zabbix_t, zabbix_tmpfs_t, file)
|
||||
|
||||
manage_dirs_pattern(zabbix_t, zabbix_var_run_t, zabbix_var_run_t)
|
||||
manage_files_pattern(zabbix_t, zabbix_var_run_t, zabbix_var_run_t)
|
||||
manage_sock_files_pattern(zabbix_t, zabbix_var_run_t, zabbix_var_run_t)
|
||||
files_pid_filetrans(zabbix_t, zabbix_var_run_t, { dir file sock_file })
|
||||
|
||||
kernel_read_system_state(zabbix_t)
|
||||
|
||||
corenet_all_recvfrom_unlabeled(zabbix_t)
|
||||
corenet_all_recvfrom_netlabel(zabbix_t)
|
||||
|
||||
corenet_sendrecv_ftp_client_packets(zabbix_t)
|
||||
corenet_tcp_connect_ftp_port(zabbix_t)
|
||||
corenet_tcp_sendrecv_ftp_port(zabbix_t)
|
||||
|
||||
corenet_sendrecv_http_client_packets(zabbix_t)
|
||||
corenet_tcp_connect_http_port(zabbix_t)
|
||||
corenet_tcp_sendrecv_http_port(zabbix_t)
|
||||
corenet_tcp_connect_smtp_port(zabbix_t)
|
||||
|
||||
corenet_sendrecv_zabbix_server_packets(zabbix_t)
|
||||
corenet_tcp_bind_zabbix_port(zabbix_t)
|
||||
corenet_tcp_sendrecv_zabbix_port(zabbix_t)
|
||||
|
||||
auth_use_nsswitch(zabbix_t)
|
||||
|
||||
zabbix_agent_tcp_connect(zabbix_t)
|
||||
|
||||
logging_send_syslog_msg(zabbix_t)
|
||||
|
||||
tunable_policy(`zabbix_can_network',`
|
||||
corenet_sendrecv_all_client_packets(zabbix_t)
|
||||
corenet_tcp_connect_all_ports(zabbix_t)
|
||||
corenet_tcp_sendrecv_all_ports(zabbix_t)
|
||||
')
|
||||
|
||||
tunable_policy(`zabbix_run_sudo',`
|
||||
allow zabbix_t self:capability { setgid setuid sys_resource };
|
||||
allow zabbix_t self:process { setrlimit setsched };
|
||||
allow zabbix_t self:key write;
|
||||
allow zabbix_t self:passwd { passwd rootok };
|
||||
|
||||
auth_rw_lastlog(zabbix_t)
|
||||
auth_rw_faillog(zabbix_t)
|
||||
auth_exec_chkpwd(zabbix_t)
|
||||
|
||||
selinux_compute_access_vector(zabbix_t)
|
||||
|
||||
systemd_write_inherited_logind_sessions_pipes(zabbix_t)
|
||||
systemd_dbus_chat_logind(zabbix_t)
|
||||
|
||||
xserver_exec_xauth(zabbix_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
tunable_policy(`zabbix_run_sudo',`
|
||||
sudo_exec(zabbix_t)
|
||||
su_exec(zabbix_t)
|
||||
')
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
mysql_stream_connect(zabbix_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
netutils_domtrans_ping(zabbix_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
postgresql_stream_connect(zabbix_t)
|
||||
postgresql_tcp_connect(zabbix_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
snmp_read_snmp_var_lib_files(zabbix_t)
|
||||
snmp_read_snmp_var_lib_dirs(zabbix_t)
|
||||
')
|
||||
|
||||
########################################
|
||||
#
|
||||
# Agent local policy
|
||||
#
|
||||
|
||||
allow zabbix_agent_t self:process { setrlimit };
|
||||
|
||||
manage_files_pattern(zabbix_agent_t, zabbix_log_t, zabbix_log_t)
|
||||
|
||||
rw_files_pattern(zabbix_agent_t, zabbix_tmpfs_t, zabbix_tmpfs_t)
|
||||
fs_tmpfs_filetrans(zabbix_agent_t, zabbix_tmpfs_t, file)
|
||||
|
||||
manage_files_pattern(zabbix_agent_t, zabbix_var_run_t, zabbix_var_run_t)
|
||||
files_pid_filetrans(zabbix_agent_t, zabbix_var_run_t, file)
|
||||
|
||||
kernel_read_system_state(zabbix_agent_t)
|
||||
kernel_read_network_state(zabbix_agent_t)
|
||||
|
||||
corenet_all_recvfrom_unlabeled(zabbix_agent_t)
|
||||
corenet_all_recvfrom_netlabel(zabbix_agent_t)
|
||||
|
||||
corecmd_read_all_executables(zabbix_agent_t)
|
||||
|
||||
corenet_sendrecv_zabbix_agent_server_packets(zabbix_agent_t)
|
||||
corenet_tcp_bind_zabbix_agent_port(zabbix_agent_t)
|
||||
corenet_tcp_sendrecv_zabbix_agent_port(zabbix_agent_t)
|
||||
|
||||
corenet_sendrecv_ssh_client_packets(zabbix_agent_t)
|
||||
corenet_tcp_connect_ssh_port(zabbix_agent_t)
|
||||
corenet_tcp_sendrecv_ssh_port(zabbix_agent_t)
|
||||
|
||||
corenet_sendrecv_ftp_client_packets(zabbix_agent_t)
|
||||
corenet_tcp_connect_ftp_port(zabbix_agent_t)
|
||||
corenet_tcp_sendrecv_ftp_port(zabbix_agent_t)
|
||||
|
||||
corenet_sendrecv_http_client_packets(zabbix_agent_t)
|
||||
corenet_tcp_connect_http_port(zabbix_agent_t)
|
||||
corenet_tcp_sendrecv_http_port(zabbix_agent_t)
|
||||
|
||||
corenet_sendrecv_innd_client_packets(zabbix_agent_t)
|
||||
corenet_tcp_connect_innd_port(zabbix_agent_t)
|
||||
corenet_tcp_sendrecv_innd_port(zabbix_agent_t)
|
||||
|
||||
corenet_sendrecv_pop_client_packets(zabbix_agent_t)
|
||||
corenet_tcp_connect_pop_port(zabbix_agent_t)
|
||||
corenet_tcp_sendrecv_pop_port(zabbix_agent_t)
|
||||
|
||||
corenet_sendrecv_postgresql_client_packets(zabbix_agent_t)
|
||||
corenet_tcp_connect_postgresql_port(zabbix_agent_t)
|
||||
corenet_tcp_sendrecv_postgresql_port(zabbix_agent_t)
|
||||
|
||||
corenet_sendrecv_smtp_client_packets(zabbix_agent_t)
|
||||
corenet_tcp_connect_smtp_port(zabbix_agent_t)
|
||||
corenet_tcp_sendrecv_smtp_port(zabbix_agent_t)
|
||||
|
||||
corenet_sendrecv_zabbix_client_packets(zabbix_agent_t)
|
||||
corenet_tcp_connect_zabbix_port(zabbix_agent_t)
|
||||
corenet_tcp_sendrecv_zabbix_port(zabbix_agent_t)
|
||||
|
||||
corenet_tcp_connect_redis_port(zabbix_agent_t)
|
||||
corenet_tcp_sendrecv_redis_port(zabbix_agent_t)
|
||||
|
||||
dev_getattr_all_blk_files(zabbix_agent_t)
|
||||
dev_getattr_all_chr_files(zabbix_agent_t)
|
||||
|
||||
domain_read_all_domains_state(zabbix_agent_t)
|
||||
|
||||
files_getattr_all_dirs(zabbix_agent_t)
|
||||
files_getattr_all_files(zabbix_agent_t)
|
||||
files_read_all_symlinks(zabbix_agent_t)
|
||||
|
||||
fs_getattr_all_fs(zabbix_agent_t)
|
||||
|
||||
auth_use_nsswitch(zabbix_agent_t)
|
||||
|
||||
init_read_utmp(zabbix_agent_t)
|
||||
|
||||
logging_search_logs(zabbix_agent_t)
|
||||
|
||||
sysnet_dns_name_resolve(zabbix_agent_t)
|
||||
|
||||
zabbix_tcp_connect(zabbix_agent_t)
|
||||
|
||||
zabbix_script_domtrans(zabbix_agent_t)
|
||||
|
||||
# These are triggered by vfs.dev.discovery enumerating everyting in /dev
|
||||
gen_require(`
|
||||
type devlog_t;
|
||||
')
|
||||
dontaudit zabbix_agent_t devlog_t:sock_file getattr;
|
||||
init_dontaudit_getattr_initctl(zabbix_agent_t)
|
||||
kernel_dontaudit_getattr_core_if(zabbix_agent_t)
|
||||
|
||||
gen_require(`
|
||||
type kernel_t, sudo_log_t;
|
||||
')
|
||||
tunable_policy(`zabbix_run_sudo',`
|
||||
allow zabbix_agent_t self:capability { chown dac_read_search setgid setuid sys_resource };
|
||||
allow zabbix_agent_t self:process { setrlimit setsched };
|
||||
allow zabbix_agent_t self:key write;
|
||||
allow zabbix_agent_t self:passwd { passwd rootok };
|
||||
|
||||
allow zabbix_agent_t sudo_log_t:dir { add_name create setattr write };
|
||||
allow zabbix_agent_t sudo_log_t:file { create open read setattr write };
|
||||
|
||||
allow zabbix_agent_t devlog_t:sock_file write;
|
||||
allow zabbix_agent_t kernel_t:unix_dgram_socket sendto;
|
||||
allow zabbix_agent_t self:unix_dgram_socket { connect create };
|
||||
|
||||
auth_domtrans_chkpwd(zabbix_agent_t)
|
||||
auth_rw_lastlog(zabbix_agent_t)
|
||||
auth_rw_faillog(zabbix_agent_t)
|
||||
|
||||
logging_send_audit_msgs(zabbix_agent_t)
|
||||
|
||||
selinux_compute_access_vector(zabbix_agent_t)
|
||||
|
||||
sssd_read_config(zabbix_agent_t)
|
||||
|
||||
systemd_write_inherited_logind_sessions_pipes(zabbix_agent_t)
|
||||
systemd_dbus_chat_logind(zabbix_agent_t)
|
||||
|
||||
xserver_exec_xauth(zabbix_agent_t)
|
||||
|
||||
# Conceivably this could be under a separate boolean, but the reason to allow sudo
|
||||
# is to allow check like this
|
||||
lvm_domtrans(zabbix_agent_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
rpm_exec(zabbix_agent_t)
|
||||
rpm_read_db(zabbix_agent_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
tunable_policy(`zabbix_run_sudo',`
|
||||
sudo_exec(zabbix_agent_t)
|
||||
su_exec(zabbix_agent_t)
|
||||
')
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
dmidecode_domtrans(zabbix_agent_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
hostname_exec(zabbix_agent_t)
|
||||
')
|
||||
|
||||
########################################
|
||||
#
|
||||
# zabbix_script_t local policy
|
||||
#
|
||||
|
||||
domtrans_pattern(zabbix_t, zabbix_script_exec_t, zabbix_script_t)
|
||||
|
||||
allow zabbix_t zabbix_script_exec_t:dir list_dir_perms;
|
||||
allow zabbix_t zabbix_script_exec_t:file ioctl;
|
||||
allow zabbix_t zabbix_script_t:process signal;
|
||||
|
||||
init_domtrans_script(zabbix_script_t)
|
||||
|
||||
optional_policy(`
|
||||
chronyd_domtrans_chronyc(zabbix_script_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
mta_send_mail(zabbix_script_t)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
unconfined_domain(zabbix_script_t)
|
||||
')
|
||||
934
zabbix6.0.spec
Normal file
934
zabbix6.0.spec
Normal file
|
|
@ -0,0 +1,934 @@
|
|||
# TODO, maybe sometime:
|
||||
# * Allow for nginx?
|
||||
# * Consider using systemd's ReadWriteDirectories
|
||||
|
||||
#TODO: systemctl reload seems to be necessary after switching with Alternatives
|
||||
#TODO: If the DB path for a Sqlite proxy is configured wrong, it requires systemctl restart. Start doesn't work.
|
||||
|
||||
%global srcname zabbix
|
||||
%global with_selinux 1
|
||||
%global selinuxtype targeted
|
||||
# go is needed for agent2, but there are missing deps
|
||||
%bcond_with go
|
||||
# Missing dependencies for the java connector
|
||||
%bcond_with java
|
||||
|
||||
%global majver 6.0
|
||||
#%%global prerelease rc2
|
||||
|
||||
Name: zabbix%{majver}
|
||||
Version: 6.0.29
|
||||
Release: 1%{?dist}
|
||||
Summary: Open-source monitoring solution for your IT infrastructure
|
||||
|
||||
License: GPLv2+
|
||||
URL: https://www.zabbix.com
|
||||
Source0: https://cdn.zabbix.com/zabbix/sources/stable/%{majver}/zabbix-%{version}.tar.gz
|
||||
Source1: %{srcname}-web.conf
|
||||
Source2: %{srcname}-php-fpm.conf
|
||||
Source5: %{srcname}-logrotate.in
|
||||
Source9: %{srcname}-tmpfiles-zabbix.conf
|
||||
# systemd units -- Alternatives switches between them (they state their dependencies)
|
||||
# https://support.zabbix.com/browse/ZBXNEXT-1593
|
||||
Source10: %{srcname}-agent.service
|
||||
Source11: %{srcname}-proxy-mysql.service
|
||||
Source12: %{srcname}-proxy-pgsql.service
|
||||
Source13: %{srcname}-proxy-sqlite3.service
|
||||
Source14: %{srcname}-server-mysql.service
|
||||
Source15: %{srcname}-server-pgsql.service
|
||||
Source16: %{srcname}-fedora-epel.README
|
||||
Source17: %{srcname}-tmpfiles-zabbixsrv.conf
|
||||
Source18: %{srcname}.te
|
||||
Source19: %{srcname}.if
|
||||
Source20: %{srcname}.fc
|
||||
|
||||
# This is not a symlink, because we don't want the webserver to possibly ever serve it.
|
||||
# local rules for config files
|
||||
Patch0: %{srcname}-config.patch
|
||||
# Allow out-of-tree builds
|
||||
# https://support.zabbix.com/browse/ZBXNEXT-6077
|
||||
Patch1: %{srcname}-out-of-tree.patch
|
||||
# Enforce Fedora Crypto Policy
|
||||
Patch2: %{srcname}-crypto-policy.patch
|
||||
|
||||
# Patch1 patches automake files so we need to autoreconf
|
||||
BuildRequires: libtool
|
||||
BuildRequires: make
|
||||
%if 0%{?fedora} || 0%{?rhel} >= 8
|
||||
BuildRequires: mariadb-connector-c-devel
|
||||
%else
|
||||
BuildRequires: mysql-devel
|
||||
%endif
|
||||
%if 0%{?el7}
|
||||
BuildRequires: postgresql-devel
|
||||
%else
|
||||
BuildRequires: libpq-devel
|
||||
%endif
|
||||
BuildRequires: sqlite-devel
|
||||
BuildRequires: net-snmp-devel
|
||||
BuildRequires: openldap-devel
|
||||
BuildRequires: openssl-devel
|
||||
BuildRequires: gnutls-devel
|
||||
BuildRequires: unixODBC-devel
|
||||
BuildRequires: curl-devel
|
||||
BuildRequires: OpenIPMI-devel
|
||||
BuildRequires: libssh2-devel
|
||||
BuildRequires: libxml2-devel
|
||||
BuildRequires: libevent-devel
|
||||
BuildRequires: pcre2-devel
|
||||
BuildRequires: gcc
|
||||
# For Agent 2 - has missing deps
|
||||
%if %{with go}
|
||||
BuildRequires: gcc-go
|
||||
#BuildRequires: golang(github.com/alimy/mc/v2)
|
||||
BuildRequires: golang(github.com/docker/go-connections)
|
||||
#BuildRequires: golang(github.com/dustin/gomemcached)
|
||||
BuildRequires: golang(github.com/fsnotify/fsnotify)
|
||||
BuildRequires: golang(github.com/go-ldap/ldap)
|
||||
#BuildRequires: golang(github.com/go-ole/go-ole)
|
||||
BuildRequires: golang(github.com/go-sql-driver/mysql)
|
||||
BuildRequires: golang(github.com/godbus/dbus)
|
||||
#BuildRequires: golang(github.com/jackc/pgx/v4)
|
||||
BuildRequires: golang(github.com/mattn/go-sqlite3)
|
||||
#BuildRequires: golang(github.com/mediocregopher/radix/v3)
|
||||
#BuildRequires: golang(github.com/natefinch/npipe)
|
||||
#BuildRequires: golang(github.com/testcontainers/testcontainers-go)
|
||||
#BuildRequires: golang(golang.org/x/sys)
|
||||
%endif
|
||||
BuildRequires: systemd
|
||||
# Needed to determine path to link to
|
||||
BuildRequires: dejavu-sans-fonts
|
||||
|
||||
Requires: logrotate
|
||||
|
||||
%if 0%{?with_selinux}
|
||||
# This ensures that the *-selinux package and all it’s dependencies are not pulled
|
||||
# into containers and other systems that do not use SELinux
|
||||
%if 0%{?el7}
|
||||
Requires: %{name}-selinux
|
||||
%else
|
||||
Requires: (%{name}-selinux if selinux-policy-%{selinuxtype})
|
||||
%endif
|
||||
%endif
|
||||
|
||||
Provides: bundled(md5-deutsch)
|
||||
# Could alternatively be conditional on Fedora/EL
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname} = %{version}-%{release}
|
||||
Obsoletes: %{srcname} = 6.0.6
|
||||
Conflicts: %{srcname} < %{majver}
|
||||
%endif
|
||||
|
||||
%description
|
||||
Zabbix is software that monitors numerous parameters of a network and the
|
||||
health and integrity of servers. Zabbix uses a flexible notification mechanism
|
||||
that allows users to configure e-mail based alerts for virtually any event.
|
||||
This allows a fast reaction to server problems. Zabbix offers excellent
|
||||
reporting and data visualization features based on the stored data.
|
||||
This makes Zabbix ideal for capacity planning.
|
||||
|
||||
Zabbix supports both polling and trapping. All Zabbix reports and statistics,
|
||||
as well as configuration parameters are accessed through a web-based front end.
|
||||
A web-based front end ensures that the status of your network and the health of
|
||||
your servers can be assessed from any location. Properly configured, Zabbix can
|
||||
play an important role in monitoring IT infrastructure. This is equally true
|
||||
for small organizations with a few servers and for large companies with a
|
||||
multitude of servers.
|
||||
|
||||
%package dbfiles-mysql
|
||||
Summary: Zabbix database schemas, images, data and patches
|
||||
BuildArch: noarch
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-dbfiles-mysql = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-dbfiles-mysql = 6.0.6
|
||||
Conflicts: %{srcname}-dbfiles-mysql < %{majver}
|
||||
%endif
|
||||
|
||||
%description dbfiles-mysql
|
||||
Zabbix database schemas, images, data and patches necessary for creating
|
||||
and/or updating MySQL databases
|
||||
|
||||
%package dbfiles-pgsql
|
||||
Summary: Zabbix database schemas, images, data and patches
|
||||
BuildArch: noarch
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-dbfiles-pgsql = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-dbfiles-pgsql = 6.0.6
|
||||
Conflicts: %{srcname}-dbfiles-pgsql < %{majver}
|
||||
%endif
|
||||
|
||||
%description dbfiles-pgsql
|
||||
Zabbix database schemas, images, data and patches necessary for creating
|
||||
and/or updating PostgreSQL databases
|
||||
|
||||
%package dbfiles-sqlite3
|
||||
Summary: Zabbix database schemas and patches
|
||||
BuildArch: noarch
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-dbfiles-sqlite3 = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-dbfiles-sqlite3 = 6.0.6
|
||||
Conflicts: %{srcname}-dbfiles-sqlite3 < %{majver}
|
||||
%endif
|
||||
|
||||
%description dbfiles-sqlite3
|
||||
Zabbix database schemas and patches necessary for creating
|
||||
and/or updating SQLite databases
|
||||
|
||||
%package server
|
||||
Summary: Zabbix server common files
|
||||
BuildArch: noarch
|
||||
Requires: %{name} = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: %{name}-server-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: fping
|
||||
Requires: traceroute
|
||||
Requires(pre): shadow-utils
|
||||
Requires(post): systemd
|
||||
Requires(preun): systemd
|
||||
Requires(postun): systemd
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-server = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-server = 6.0.6
|
||||
Conflicts: %{srcname}-server < %{majver}
|
||||
%endif
|
||||
|
||||
%description server
|
||||
Zabbix server common files
|
||||
|
||||
%package server-mysql
|
||||
Summary: Zabbix server compiled to use MySQL
|
||||
Requires: %{name} = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: %{name}-dbfiles-mysql
|
||||
Requires: %{name}-server = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires(posttrans): %{_sbindir}/update-alternatives
|
||||
Requires(postun): %{_sbindir}/update-alternatives
|
||||
Provides: %{name}-server-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-server-mysql = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-server-mysql = 6.0.6
|
||||
Conflicts: %{srcname}-server-mysql < %{majver}
|
||||
%endif
|
||||
|
||||
%description server-mysql
|
||||
Zabbix server compiled to use MySQL
|
||||
|
||||
%package server-pgsql
|
||||
Summary: Zabbix server compiled to use PostgreSQL
|
||||
Requires: %{name} = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: %{name}-server = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: %{name}-dbfiles-pgsql
|
||||
Requires(posttrans): %{_sbindir}/update-alternatives
|
||||
Requires(postun): %{_sbindir}/update-alternatives
|
||||
Provides: %{name}-server-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-server-pgsql = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-server-pgsql = 6.0.6
|
||||
Conflicts: %{srcname}-server-pgsql < %{majver}
|
||||
%endif
|
||||
|
||||
%description server-pgsql
|
||||
Zabbix server compiled to use PostgreSQL
|
||||
|
||||
%package agent
|
||||
Summary: Zabbix agent
|
||||
Requires: %{name} = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires(pre): shadow-utils
|
||||
Requires(post): systemd
|
||||
Requires(preun): systemd
|
||||
Requires(postun): systemd
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-agent = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-agent = 6.0.6
|
||||
Conflicts: %{srcname}-agent < %{majver}
|
||||
%endif
|
||||
|
||||
%description agent
|
||||
Zabbix agent, to be installed on monitored systems
|
||||
|
||||
%package proxy
|
||||
Summary: Zabbix proxy common files
|
||||
BuildArch: noarch
|
||||
Requires: %{name} = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: %{name}-proxy-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires(pre): shadow-utils
|
||||
Requires(post): systemd
|
||||
Requires(preun): systemd
|
||||
Requires(postun): systemd
|
||||
Requires: fping
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-proxy = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-proxy = 6.0.6
|
||||
Conflicts: %{srcname}-proxy < %{majver}
|
||||
%endif
|
||||
|
||||
%description proxy
|
||||
Zabbix proxy commmon files
|
||||
|
||||
%package proxy-mysql
|
||||
Summary: Zabbix proxy compiled to use MySQL
|
||||
Requires: %{name}-proxy = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: %{name}-dbfiles-mysql
|
||||
Provides: %{name}-proxy-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires(posttrans): %{_sbindir}/update-alternatives
|
||||
Requires(postun): %{_sbindir}/update-alternatives
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-proxy-mysql = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-proxy-mysql = 6.0.6
|
||||
Conflicts: %{srcname}-proxy-mysql < %{majver}
|
||||
%endif
|
||||
|
||||
%description proxy-mysql
|
||||
Zabbix proxy compiled to use MySQL
|
||||
|
||||
%package proxy-pgsql
|
||||
Summary: Zabbix proxy compiled to use PostgreSQL
|
||||
Requires: %{name}-proxy = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: %{name}-dbfiles-pgsql
|
||||
Provides: %{name}-proxy-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires(posttrans): %{_sbindir}/update-alternatives
|
||||
Requires(postun): %{_sbindir}/update-alternatives
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-proxy-pgsql = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-proxy-pgsql = 6.0.6
|
||||
Conflicts: %{srcname}-proxy-pgsql < %{majver}
|
||||
%endif
|
||||
|
||||
%description proxy-pgsql
|
||||
Zabbix proxy compiled to use PostgreSQL
|
||||
|
||||
%package proxy-sqlite3
|
||||
Summary: Zabbix proxy compiled to use SQLite
|
||||
Requires: %{name}-proxy = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: %{name}-dbfiles-sqlite3
|
||||
Provides: %{name}-proxy-implementation = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires(posttrans): %{_sbindir}/update-alternatives
|
||||
Requires(postun): %{_sbindir}/update-alternatives
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-proxy-sqlite3 = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-proxy-sqlite3 = 6.0.6
|
||||
Conflicts: %{srcname}-proxy-sqlite3 < %{majver}
|
||||
%endif
|
||||
|
||||
%description proxy-sqlite3
|
||||
Zabbix proxy compiled to use SQLite
|
||||
|
||||
%package web
|
||||
Summary: Zabbix Web Frontend
|
||||
BuildArch: noarch
|
||||
Requires: php-bcmath
|
||||
Requires: php-fpm
|
||||
Requires: php-gd
|
||||
Requires: php-gettext
|
||||
Requires: php-json
|
||||
Requires: php-ldap
|
||||
Requires: php-mbstring
|
||||
Requires: php-xml
|
||||
# jquery 3.6.0 and jquery-ui 1.12.1 in the sources
|
||||
%if 0%{?el7}
|
||||
Provides: bundled(js-jquery) = 3.6.0
|
||||
%else
|
||||
Requires: js-jquery >= 3.6.0
|
||||
%endif
|
||||
Provides: bundled(js-jquery-ui) = 1.12.1
|
||||
# prototype 1.6.1 in the sources, Fedora package is dead
|
||||
#Requires: prototype
|
||||
Requires: dejavu-sans-fonts
|
||||
Requires: %{name} = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: %{name}-web-database = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-web = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-web = 6.0.6
|
||||
Conflicts: %{srcname}-web < %{majver}
|
||||
%endif
|
||||
|
||||
%description web
|
||||
The php frontend to display the Zabbix web interface.
|
||||
|
||||
%package web-mysql
|
||||
Summary: Zabbix web frontend for MySQL
|
||||
BuildArch: noarch
|
||||
Requires: %{name}-web = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: php-mysqli
|
||||
Provides: %{name}-web-database = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-web-mysql = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-web-mysql = 6.0.6
|
||||
Conflicts: %{srcname}-web-mysql < %{majver}
|
||||
%endif
|
||||
|
||||
%description web-mysql
|
||||
Zabbix web frontend for MySQL
|
||||
|
||||
%package web-pgsql
|
||||
Summary: Zabbix web frontend for PostgreSQL
|
||||
BuildArch: noarch
|
||||
Requires: %{name}-web = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
Requires: php-pgsql
|
||||
Provides: %{name}-web-database = %{?epoch:%{epoch}:}%{version}-%{release}
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-web-pgsql = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-web-pgsql = 6.0.6
|
||||
Conflicts: %{srcname}-web-pgsql < %{majver}
|
||||
%endif
|
||||
|
||||
%description web-pgsql
|
||||
Zabbix web frontend for PostgreSQL
|
||||
|
||||
%if %{with java}
|
||||
%package -n java-%{srcname}
|
||||
Summary: Zabbix Java connector
|
||||
BuildArch: noarch
|
||||
BuildRequires: java-devel
|
||||
BuildRequires: osgi(org.junit)
|
||||
BuildRequires: osgi(slf4j.api)
|
||||
BuildRequires: osgi(logback)
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-java = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-java = 6.0.6
|
||||
Conflicts: %{srcname}-java < %{majver}
|
||||
%endif
|
||||
|
||||
%description -n java-%{srcname}
|
||||
Zabbix Java connector.
|
||||
%endif
|
||||
|
||||
%if 0%{?with_selinux}
|
||||
# SELinux subpackage
|
||||
%package selinux
|
||||
Summary: Zabbix SELinux policy
|
||||
BuildArch: noarch
|
||||
Requires: selinux-policy-%{selinuxtype}
|
||||
Requires(post): selinux-policy-%{selinuxtype}
|
||||
BuildRequires: selinux-policy-devel
|
||||
%{?selinux_requires}
|
||||
%if "x%{?srcname}" != "x%{name}"
|
||||
Provides: %{srcname}-selinux = %{version}-%{release}
|
||||
Obsoletes: %{srcname}-selinux = 6.0.6
|
||||
Conflicts: %{srcname}-selinux < %{majver}
|
||||
%endif
|
||||
|
||||
%description selinux
|
||||
Custom SELinux policy module
|
||||
%endif
|
||||
|
||||
|
||||
%prep
|
||||
%setup0 -q -n %{srcname}-%{version}%{?prerelease:.%{prerelease}}
|
||||
%patch0 -p1 -b .config
|
||||
%patch1 -p1 -b .out-of-tree
|
||||
# No crypto policies on EL7
|
||||
%if !0%{?el7}
|
||||
%patch2 -p1 -b .crypto-policy
|
||||
%endif
|
||||
autoreconf
|
||||
|
||||
# Remove bundled java libs
|
||||
find -name \*.jar -delete
|
||||
|
||||
# Remove prebuilt Windows binaries
|
||||
rm -rf bin
|
||||
|
||||
# Override creation of statically named directory for alertscripts and externalscripts
|
||||
# https://support.zabbix.com/browse/ZBX-6159
|
||||
sed -i '/CURL_SSL_.*_LOCATION\|SCRIPTS_PATH/s|\${datadir}/zabbix|/var/lib/zabbixsrv|' \
|
||||
configure
|
||||
|
||||
# Kill off .htaccess files, options set in SOURCE1
|
||||
find -name .htaccess -delete
|
||||
|
||||
# Fix path to traceroute utility (on all Linux targets)
|
||||
find database -name 'data.sql' -exec sed -i 's|/usr/bin/traceroute|/bin/traceroute|' {} \;
|
||||
|
||||
# Common
|
||||
# Settings with hard-coded defaults that are not suitable for Fedora
|
||||
# are explicitly set, leaving the comment with the default value in place.
|
||||
# Settings without hard-coded defaults are simply replaced -- be they
|
||||
# comments or explicit settings!
|
||||
|
||||
# Also replace the datadir placeholder that is not expanded, but effective
|
||||
sed -i \
|
||||
-e '\|^# LogFileSize=.*|a LogFileSize=0' \
|
||||
-e 's|^DBUser=root|DBUser=zabbix|' \
|
||||
-e 's|^# DBSocket=.*|DBSocket=%{_sharedstatedir}/mysql/mysql.sock|' \
|
||||
-e '\|^# ExternalScripts=|a ExternalScripts=%{_sharedstatedir}/zabbixsrv/externalscripts' \
|
||||
-e '\|^# AlertScriptsPath=|a AlertScriptsPath=%{_sharedstatedir}/zabbixsrv/alertscripts' \
|
||||
-e '\|^# TmpDir=\/tmp|a TmpDir=%{_sharedstatedir}/zabbixsrv/tmp' \
|
||||
-e 's|/usr/local||' \
|
||||
-e 's|\${datadir}|/usr/share|' \
|
||||
conf/zabbix_agentd.conf conf/zabbix_proxy.conf conf/zabbix_server.conf
|
||||
|
||||
# Specific
|
||||
sed -i \
|
||||
-e '\|^# PidFile=.*|a PidFile=%{_rundir}/zabbix/zabbix_agentd.pid' \
|
||||
-e 's|^LogFile=.*|LogFile=%{_localstatedir}/log/zabbix/zabbix_agentd.log|' \
|
||||
conf/zabbix_agentd.conf
|
||||
|
||||
sed -i \
|
||||
-e '\|^# PidFile=.*|a PidFile=%{_rundir}/zabbixsrv/zabbix_proxy.pid' \
|
||||
-e 's|^LogFile=.*|LogFile=%{_localstatedir}/log/zabbixsrv/zabbix_proxy.log|' \
|
||||
conf/zabbix_proxy.conf
|
||||
|
||||
sed -i \
|
||||
-e '\|^# PidFile=.*|a PidFile=%{_rundir}/zabbixsrv/zabbix_server.pid' \
|
||||
-e 's|^LogFile=.*|LogFile=%{_localstatedir}/log/zabbixsrv/zabbix_server.log|' \
|
||||
conf/zabbix_server.conf
|
||||
|
||||
# Install README file
|
||||
install -m 0644 -p %{SOURCE16} .
|
||||
|
||||
|
||||
%build
|
||||
|
||||
common_flags="
|
||||
--enable-dependency-tracking
|
||||
--enable-proxy
|
||||
--enable-ipv6
|
||||
--with-net-snmp
|
||||
--with-ldap
|
||||
--with-libcurl
|
||||
--with-openipmi
|
||||
--with-unixodbc
|
||||
--with-ssh2
|
||||
--with-libxml2
|
||||
--with-libevent
|
||||
--with-libpcre2
|
||||
--with-openssl
|
||||
"
|
||||
# Setup out of tree builds
|
||||
%global _configure ../configure
|
||||
|
||||
%if 0%{?el7}
|
||||
export CFLAGS="%{optflags} -std=gnu99"
|
||||
%endif
|
||||
|
||||
%if %{with java}
|
||||
export CLASSPATH=$(build-classpath junit slf4j-api logback-core logback-classic android-json)
|
||||
%endif
|
||||
|
||||
# Frontend doesn't work for SQLite, thus don't build server
|
||||
mkdir -p build-frontend
|
||||
cd build-frontend
|
||||
%configure $common_flags --enable-agent --with-sqlite3 %{?with_go:--enable-agent2} %{?with_java:--enable-java}
|
||||
%make_build
|
||||
cd -
|
||||
|
||||
mkdir -p build-server-mysql
|
||||
cd build-server-mysql
|
||||
%configure $common_flags --with-mysql --enable-server
|
||||
%make_build
|
||||
cd -
|
||||
|
||||
mkdir -p build-server-postgresql
|
||||
cd build-server-postgresql
|
||||
%configure $common_flags --with-postgresql --enable-server
|
||||
%make_build
|
||||
cd -
|
||||
|
||||
%if 0%{?with_selinux}
|
||||
# SELinux policy (originally from selinux-policy-contrib)
|
||||
# this policy module will override the production module
|
||||
mkdir selinux
|
||||
cp -p %{SOURCE18} selinux/
|
||||
cp -p %{SOURCE19} selinux/
|
||||
cp -p %{SOURCE20} selinux/
|
||||
|
||||
make -f %{_datadir}/selinux/devel/Makefile %{srcname}.pp
|
||||
bzip2 -9 %{srcname}.pp
|
||||
%endif
|
||||
|
||||
|
||||
%install
|
||||
# Install binaries
|
||||
%make_install -C build-frontend
|
||||
mv $RPM_BUILD_ROOT%{_sbindir}/zabbix_proxy{,_sqlite3}
|
||||
%make_install -C build-server-mysql
|
||||
mv $RPM_BUILD_ROOT%{_sbindir}/zabbix_proxy{,_mysql}
|
||||
mv $RPM_BUILD_ROOT%{_sbindir}/zabbix_server{,_mysql}
|
||||
%make_install -C build-server-postgresql
|
||||
mv $RPM_BUILD_ROOT%{_sbindir}/zabbix_proxy{,_pgsql}
|
||||
mv $RPM_BUILD_ROOT%{_sbindir}/zabbix_server{,_pgsql}
|
||||
|
||||
# Ghosted alternatives
|
||||
touch $RPM_BUILD_ROOT%{_sbindir}/zabbix_{proxy,server}
|
||||
|
||||
# Home directory for the agent;
|
||||
# The other home directory is created during installation
|
||||
mkdir -p $RPM_BUILD_ROOT%{_sharedstatedir}/zabbix
|
||||
|
||||
# Log directories
|
||||
mkdir -p $RPM_BUILD_ROOT%{_localstatedir}/log/zabbix
|
||||
mkdir -p $RPM_BUILD_ROOT%{_localstatedir}/log/zabbixsrv
|
||||
|
||||
# systemd tmpfiles
|
||||
mkdir -p $RPM_BUILD_ROOT%{_prefix}/lib/tmpfiles.d
|
||||
install -m 0644 -p %{SOURCE9} $RPM_BUILD_ROOT%{_prefix}/lib/tmpfiles.d/zabbix.conf
|
||||
install -m 0644 -p %{SOURCE17} $RPM_BUILD_ROOT%{_prefix}/lib/tmpfiles.d/zabbixsrv.conf
|
||||
mkdir -p $RPM_BUILD_ROOT%{_rundir}
|
||||
install -d -m 0755 $RPM_BUILD_ROOT%{_rundir}/zabbix/
|
||||
install -d -m 0755 $RPM_BUILD_ROOT%{_rundir}/zabbixsrv/
|
||||
|
||||
# Install the frontend after removing backup files from patching
|
||||
find ui -name '*.orig' -delete
|
||||
mkdir -p $RPM_BUILD_ROOT%{_datadir}/%{srcname}
|
||||
cp -a ui/* $RPM_BUILD_ROOT%{_datadir}/%{srcname}/
|
||||
|
||||
# Prepare ghosted config file
|
||||
mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/%{srcname}/web
|
||||
touch $RPM_BUILD_ROOT%{_sysconfdir}/%{srcname}/web/zabbix.conf.php
|
||||
|
||||
# Replace bundled font
|
||||
[ -d %{_fontbasedir}/dejavu ] &&
|
||||
ln -sf ../../../fonts/dejavu/DejaVuSans.ttf $RPM_BUILD_ROOT%{_datadir}/%{srcname}/assets/fonts/
|
||||
[ -d %{_fontbasedir}/dejavu-sans-fonts ] &&
|
||||
ln -sf ../../../fonts/dejavu-sans-fonts/DejaVuSans.ttf $RPM_BUILD_ROOT%{_datadir}/%{srcname}/assets/fonts/
|
||||
|
||||
# Replace JS libraries
|
||||
# There is no jquery-ui package yet
|
||||
%if !0%{?el7}
|
||||
ln -sf ../../../javascript/jquery/3/jquery.min.js $RPM_BUILD_ROOT%{_datadir}/%{srcname}/js/vendors/jquery.js
|
||||
%endif
|
||||
#ln -sf ../../../javascript/jquery-ui/1/jquery-ui.min.js $RPM_BUILD_ROOT%{_datadir}/%{srcname}/js/vendors/jquery-ui.js
|
||||
|
||||
# This file is used to switch the frontend to maintenance mode
|
||||
mv $RPM_BUILD_ROOT%{_datadir}/%{srcname}/conf/maintenance.inc.php $RPM_BUILD_ROOT%{_sysconfdir}/%{srcname}/web/maintenance.inc.php || :
|
||||
|
||||
# Drop Apache config file in place
|
||||
mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/httpd/conf.d
|
||||
install -m 0644 -p %{SOURCE1} $RPM_BUILD_ROOT%{_sysconfdir}/httpd/conf.d/%{srcname}.conf
|
||||
|
||||
# Drop php-fpm config file in place
|
||||
mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/php-fpm.d
|
||||
install -m 0644 -p %{SOURCE2} $RPM_BUILD_ROOT%{_sysconfdir}/php-fpm.d/%{srcname}.conf
|
||||
|
||||
# Install log rotation
|
||||
mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d
|
||||
sed -e 's|COMPONENT|agentd|g; s|USER|zabbix|g' %{SOURCE5} > \
|
||||
$RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d/zabbix-agent
|
||||
sed -e 's|COMPONENT|server|g; s|USER|zabbixsrv|g' %{SOURCE5} > \
|
||||
$RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d/zabbix-server
|
||||
sed -e 's|COMPONENT|proxy|g; s|USER|zabbixsrv|g' %{SOURCE5} > \
|
||||
$RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d/zabbix-proxy
|
||||
|
||||
# Install different systemd units because of the requirements for DBMS daemons
|
||||
mkdir -p $RPM_BUILD_ROOT%{_unitdir}
|
||||
install -m 0644 -p %{SOURCE10} $RPM_BUILD_ROOT%{_unitdir}/zabbix-agent.service
|
||||
install -m 0644 -p %{SOURCE11} $RPM_BUILD_ROOT%{_unitdir}/zabbix-proxy-mysql.service
|
||||
install -m 0644 -p %{SOURCE12} $RPM_BUILD_ROOT%{_unitdir}/zabbix-proxy-pgsql.service
|
||||
install -m 0644 -p %{SOURCE13} $RPM_BUILD_ROOT%{_unitdir}/zabbix-proxy-sqlite3.service
|
||||
install -m 0644 -p %{SOURCE14} $RPM_BUILD_ROOT%{_unitdir}/zabbix-server-mysql.service
|
||||
install -m 0644 -p %{SOURCE15} $RPM_BUILD_ROOT%{_unitdir}/zabbix-server-pgsql.service
|
||||
|
||||
# Ghosted alternatives
|
||||
touch $RPM_BUILD_ROOT%{_unitdir}/zabbix-server.service
|
||||
touch $RPM_BUILD_ROOT%{_unitdir}/zabbix-proxy.service
|
||||
|
||||
# Directory for fping spooling files
|
||||
mkdir -p $RPM_BUILD_ROOT%{_sharedstatedir}/zabbixsrv/tmp
|
||||
|
||||
# Install sql files
|
||||
for db in postgresql mysql; do
|
||||
mkdir $RPM_BUILD_ROOT%{_datadir}/%{srcname}-$db
|
||||
cp -p database/$db/*.sql $RPM_BUILD_ROOT%{_datadir}/%{srcname}-$db
|
||||
done
|
||||
|
||||
install -dm 755 $RPM_BUILD_ROOT%{_datadir}/%{srcname}-sqlite3
|
||||
cp -p database/sqlite3/schema.sql $RPM_BUILD_ROOT%{_datadir}/%{srcname}-sqlite3
|
||||
|
||||
%if 0%{?with_selinux}
|
||||
install -D -m 0644 %{srcname}.pp.bz2 %{buildroot}%{_datadir}/selinux/packages/%{selinuxtype}/%{srcname}.pp.bz2
|
||||
install -D -p -m 0644 selinux/%{srcname}.if %{buildroot}%{_datadir}/selinux/devel/include/distributed/%{srcname}.if
|
||||
%endif
|
||||
|
||||
|
||||
%post server
|
||||
%systemd_post zabbix-server.service
|
||||
|
||||
if [ $1 -gt 1 ] ; then
|
||||
# Apply permissions also in *.rpmnew upgrades from old permissive ones
|
||||
chmod 0640 %{_sysconfdir}/zabbix_server.conf
|
||||
chown root:zabbixsrv %{_sysconfdir}/zabbix_server.conf
|
||||
fi
|
||||
:
|
||||
|
||||
%posttrans server-mysql
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_server \
|
||||
%{srcname}-server %{_sbindir}/%{srcname}_server_mysql 10 \
|
||||
--slave %{_unitdir}/zabbix-server.service %{srcname}-server-systemd \
|
||||
%{_unitdir}/zabbix-server-mysql.service
|
||||
|
||||
%posttrans server-pgsql
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_server \
|
||||
%{srcname}-server %{_sbindir}/%{srcname}_server_pgsql 10 \
|
||||
--slave %{_unitdir}/zabbix-server.service %{srcname}-server-systemd \
|
||||
%{_unitdir}/zabbix-server-pgsql.service
|
||||
|
||||
%post proxy
|
||||
%systemd_post zabbix-proxy.service
|
||||
|
||||
if [ $1 -gt 1 ] ; then
|
||||
# Apply permissions also in *.rpmnew upgrades from old permissive ones
|
||||
chmod 0640 %{_sysconfdir}/zabbix_proxy.conf
|
||||
chown root:zabbixsrv %{_sysconfdir}/zabbix_proxy.conf
|
||||
fi
|
||||
:
|
||||
|
||||
%posttrans proxy-mysql
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_proxy \
|
||||
%{srcname}-proxy %{_sbindir}/%{srcname}_proxy_mysql 10 \
|
||||
--slave %{_unitdir}/zabbix-proxy.service %{srcname}-proxy-systemd \
|
||||
%{_unitdir}/zabbix-proxy-mysql.service
|
||||
|
||||
%posttrans proxy-pgsql
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_proxy \
|
||||
%{srcname}-proxy %{_sbindir}/%{srcname}_proxy_pgsql 10 \
|
||||
--slave %{_unitdir}/zabbix-proxy.service %{srcname}-proxy-systemd \
|
||||
%{_unitdir}/zabbix-proxy-pgsql.service
|
||||
|
||||
%posttrans proxy-sqlite3
|
||||
%{_sbindir}/update-alternatives --install %{_sbindir}/%{srcname}_proxy \
|
||||
%{srcname}-proxy %{_sbindir}/%{srcname}_proxy_sqlite3 10 \
|
||||
--slave %{_unitdir}/zabbix-proxy.service %{srcname}-proxy-systemd \
|
||||
%{_unitdir}/zabbix-proxy-sqlite3.service
|
||||
|
||||
%if 0%{?with_selinux}
|
||||
# SELinux contexts are saved so that only affected files can be
|
||||
# relabeled after the policy module installation
|
||||
%pre selinux
|
||||
%selinux_relabel_pre -s %{selinuxtype}
|
||||
|
||||
%post selinux
|
||||
%selinux_modules_install -s %{selinuxtype} %{_datadir}/selinux/packages/%{selinuxtype}/%{srcname}.pp.bz2
|
||||
|
||||
%postun selinux
|
||||
if [ $1 -eq 0 ]; then
|
||||
%selinux_modules_uninstall -s %{selinuxtype} %{name}
|
||||
fi
|
||||
|
||||
%posttrans selinux
|
||||
%selinux_relabel_post -s %{selinuxtype}
|
||||
%endif
|
||||
|
||||
%pre agent
|
||||
getent group zabbix > /dev/null || groupadd -r zabbix
|
||||
getent passwd zabbix > /dev/null || \
|
||||
useradd -r -g zabbix -d %{_sharedstatedir}/zabbix -s /sbin/nologin \
|
||||
-c "Zabbix Monitoring System" zabbix
|
||||
:
|
||||
|
||||
%post agent
|
||||
%systemd_post zabbix-agent.service
|
||||
|
||||
%pre server
|
||||
getent group zabbixsrv > /dev/null || groupadd -r zabbixsrv
|
||||
# The zabbixsrv group is introduced by 2.2 packaging
|
||||
# The zabbixsrv user was a member of the zabbix group in 2.0
|
||||
if getent passwd zabbixsrv > /dev/null; then
|
||||
if [[ $(id -gn zabbixsrv) == "zabbix" ]]; then
|
||||
usermod -c "Zabbix Monitoring System -- Proxy or server" -g zabbixsrv zabbixsrv
|
||||
fi
|
||||
else
|
||||
useradd -r -g zabbixsrv -d %{_sharedstatedir}/zabbixsrv -s /sbin/nologin \
|
||||
-c "Zabbix Monitoring System -- Proxy or server" zabbixsrv
|
||||
fi
|
||||
:
|
||||
|
||||
%preun server
|
||||
%systemd_preun zabbix-server.service
|
||||
|
||||
%pre proxy
|
||||
getent group zabbixsrv > /dev/null || groupadd -r zabbixsrv
|
||||
# The zabbixsrv group is introduced by 2.2 packaging
|
||||
# The zabbixsrv user was a member of the zabbix group in 2.0
|
||||
if getent passwd zabbixsrv > /dev/null; then
|
||||
if [[ $(id -gn zabbixsrv) == "zabbix" ]]; then
|
||||
usermod -c "Zabbix Monitoring System -- Proxy or server" -g zabbixsrv zabbixsrv
|
||||
fi
|
||||
else
|
||||
useradd -r -g zabbixsrv -d %{_sharedstatedir}/zabbixsrv -s /sbin/nologin \
|
||||
-c "Zabbix Monitoring System -- Proxy or server" zabbixsrv
|
||||
fi
|
||||
:
|
||||
|
||||
%preun proxy
|
||||
%systemd_preun zabbix-proxy.service
|
||||
|
||||
%preun agent
|
||||
%systemd_preun zabbix-agent.service
|
||||
|
||||
%postun server
|
||||
%systemd_postun_with_restart zabbix-server.service
|
||||
|
||||
%postun server-mysql
|
||||
if [ $1 -eq 0 ] ; then
|
||||
%{_sbindir}/update-alternatives --remove %{srcname}-server %{_sbindir}/%{srcname}_server_mysql
|
||||
fi
|
||||
|
||||
%postun server-pgsql
|
||||
if [ $1 -eq 0 ] ; then
|
||||
%{_sbindir}/update-alternatives --remove %{srcname}-server %{_sbindir}/%{srcname}_server_pgsql
|
||||
fi
|
||||
|
||||
%postun proxy
|
||||
%systemd_postun_with_restart zabbix-proxy.service
|
||||
|
||||
%postun proxy-mysql
|
||||
if [ $1 -eq 0 ] ; then
|
||||
%{_sbindir}/update-alternatives --remove %{srcname}-proxy %{_sbindir}/%{srcname}_proxy_mysql
|
||||
fi
|
||||
|
||||
%postun proxy-pgsql
|
||||
if [ $1 -eq 0 ] ; then
|
||||
%{_sbindir}/update-alternatives --remove %{srcname}-proxy %{_sbindir}/%{srcname}_proxy_pgsql
|
||||
fi
|
||||
|
||||
%postun proxy-sqlite3
|
||||
if [ $1 -eq 0 ] ; then
|
||||
%{_sbindir}/update-alternatives --remove %{srcname}-proxy %{_sbindir}/%{srcname}_proxy_sqlite3
|
||||
fi
|
||||
|
||||
%postun agent
|
||||
%systemd_postun_with_restart zabbix-agent.service
|
||||
|
||||
|
||||
%files
|
||||
%license COPYING
|
||||
%doc AUTHORS ChangeLog NEWS README zabbix-fedora-epel.README
|
||||
%dir %{_sysconfdir}/%{srcname}
|
||||
%config(noreplace) %{_sysconfdir}/zabbix_agentd.conf
|
||||
%{_bindir}/zabbix_get
|
||||
%{_bindir}/zabbix_js
|
||||
%{_bindir}/zabbix_sender
|
||||
%{_mandir}/man1/zabbix_get.1*
|
||||
%{_mandir}/man1/zabbix_sender.1*
|
||||
|
||||
%files dbfiles-mysql
|
||||
%license COPYING
|
||||
%{_datadir}/%{srcname}-mysql/
|
||||
|
||||
%files dbfiles-pgsql
|
||||
%license COPYING
|
||||
%{_datadir}/%{srcname}-postgresql/
|
||||
|
||||
%files dbfiles-sqlite3
|
||||
%license COPYING
|
||||
%{_datadir}/%{srcname}-sqlite3/
|
||||
|
||||
%files server
|
||||
%doc misc/snmptrap/zabbix_trap_receiver.pl
|
||||
%attr(0755,zabbixsrv,zabbixsrv) %dir %{_rundir}/zabbixsrv/
|
||||
%{_prefix}/lib/tmpfiles.d/zabbixsrv.conf
|
||||
%attr(0640,root,zabbixsrv) %config(noreplace) %{_sysconfdir}/zabbix_server.conf
|
||||
%attr(0775,root,zabbixsrv) %dir %{_localstatedir}/log/zabbixsrv
|
||||
%config(noreplace) %{_sysconfdir}/logrotate.d/zabbix-server
|
||||
%ghost %{_sbindir}/zabbix_server
|
||||
%attr(0750,zabbixsrv,zabbixsrv) %dir %{_sharedstatedir}/zabbixsrv
|
||||
%attr(0750,zabbixsrv,zabbixsrv) %dir %{_sharedstatedir}/zabbixsrv/tmp
|
||||
%attr(0750,zabbixsrv,zabbixsrv) %dir %{_sharedstatedir}/zabbixsrv/alertscripts
|
||||
%attr(0750,zabbixsrv,zabbixsrv) %dir %{_sharedstatedir}/zabbixsrv/externalscripts
|
||||
%ghost %{_unitdir}/zabbix-server.service
|
||||
%{_mandir}/man8/zabbix_server.8*
|
||||
|
||||
%files server-mysql
|
||||
%{_sbindir}/zabbix_server_mysql
|
||||
%{_unitdir}/zabbix-server-mysql.service
|
||||
|
||||
%files server-pgsql
|
||||
%{_sbindir}/zabbix_server_pgsql
|
||||
%{_unitdir}/zabbix-server-pgsql.service
|
||||
|
||||
%if 0%{?with_selinux}
|
||||
%files selinux
|
||||
%{_datadir}/selinux/packages/%{selinuxtype}/%{srcname}.pp.*
|
||||
%{_datadir}/selinux/devel/include/distributed/%{srcname}.if
|
||||
%ghost %verify(not md5 size mode mtime) %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{name}
|
||||
%endif
|
||||
|
||||
%files agent
|
||||
%doc conf/zabbix_agentd/*.conf
|
||||
%attr(0755,zabbix,zabbix) %dir %{_rundir}/zabbix/
|
||||
%{_prefix}/lib/tmpfiles.d/zabbix.conf
|
||||
%attr(0775,root,zabbix) %dir %{_localstatedir}/log/zabbix
|
||||
%config(noreplace) %{_sysconfdir}/zabbix_agentd.conf
|
||||
%config(noreplace) %{_sysconfdir}/logrotate.d/zabbix-agent
|
||||
%attr(750,zabbix,zabbix) %dir %{_sharedstatedir}/zabbix
|
||||
%{_unitdir}/zabbix-agent.service
|
||||
%{_sbindir}/zabbix_agentd
|
||||
%{_mandir}/man8/zabbix_agentd.8*
|
||||
|
||||
%files proxy
|
||||
%doc misc/snmptrap/zabbix_trap_receiver.pl
|
||||
%attr(0755,zabbixsrv,zabbixsrv) %dir %{_rundir}/zabbixsrv/
|
||||
%{_prefix}/lib/tmpfiles.d/zabbixsrv.conf
|
||||
%attr(0640,root,zabbixsrv) %config(noreplace) %{_sysconfdir}/zabbix_proxy.conf
|
||||
%attr(0775,root,zabbixsrv) %dir %{_localstatedir}/log/zabbixsrv
|
||||
%config(noreplace) %{_sysconfdir}/logrotate.d/zabbix-proxy
|
||||
%ghost %{_sbindir}/zabbix_proxy
|
||||
%attr(0750,zabbixsrv,zabbixsrv) %dir %{_sharedstatedir}/zabbixsrv
|
||||
%attr(0750,zabbixsrv,zabbixsrv) %dir %{_sharedstatedir}/zabbixsrv/tmp
|
||||
%attr(0750,zabbixsrv,zabbixsrv) %dir %{_sharedstatedir}/zabbixsrv/alertscripts
|
||||
%attr(0750,zabbixsrv,zabbixsrv) %dir %{_sharedstatedir}/zabbixsrv/externalscripts
|
||||
%ghost %{_unitdir}/zabbix-proxy.service
|
||||
%{_mandir}/man8/zabbix_proxy.8*
|
||||
|
||||
%files proxy-mysql
|
||||
%{_sbindir}/zabbix_proxy_mysql
|
||||
%{_unitdir}/zabbix-proxy-mysql.service
|
||||
|
||||
%files proxy-pgsql
|
||||
%{_sbindir}/zabbix_proxy_pgsql
|
||||
%{_unitdir}/zabbix-proxy-pgsql.service
|
||||
|
||||
%files proxy-sqlite3
|
||||
%{_sbindir}/zabbix_proxy_sqlite3
|
||||
%{_unitdir}/zabbix-proxy-sqlite3.service
|
||||
|
||||
%files web
|
||||
%dir %attr(0750,apache,apache) %{_sysconfdir}/%{srcname}/web
|
||||
%ghost %attr(0644,apache,apache) %config(noreplace) %{_sysconfdir}/%{srcname}/web/zabbix.conf.php
|
||||
%attr(0644,apache,apache) %config(noreplace) %{_sysconfdir}/%{srcname}/web/maintenance.inc.php
|
||||
%config(noreplace) %{_sysconfdir}/httpd/conf.d/zabbix.conf
|
||||
%config(noreplace) %{_sysconfdir}/php-fpm.d/zabbix.conf
|
||||
%{_datadir}/%{srcname}/
|
||||
|
||||
%files web-mysql
|
||||
|
||||
%files web-pgsql
|
||||
|
||||
%changelog
|
||||
* Fri May 03 2024 Orion Poplawski <orion@nwra.com> - 6.0.29-1
|
||||
- Update to 6.0.29
|
||||
- Hopefully really get the zabbix_run_sudo SELinux boolean working for
|
||||
zabbix-agent and allow it to run lvm when enabled
|
||||
|
||||
* Thu Jan 04 2024 Orion Poplawski <orion@nwra.com> - 6.0.25-1
|
||||
- Update to 6.0.25
|
||||
- Drop crypto-policies patch on EL7 - not applicable
|
||||
|
||||
* Mon Oct 30 2023 Orion Poplawski <orion@nwra.com> - 6.0.22-2.1
|
||||
- Fix SELinux policy
|
||||
|
||||
* Mon Oct 30 2023 Orion Poplawski <orion@nwra.com> - 6.0.22-2
|
||||
- Add dontaudit SELinux rules for spurious AVC denial messages (bz#2170630)
|
||||
|
||||
* Mon Oct 30 2023 Orion Poplawski <orion@nwra.com> - 6.0.22-1
|
||||
- Update to 6.0.22
|
||||
|
||||
* Sun Jul 16 2023 Orion Poplawski <orion@nwra.com> - 6.0.19-1
|
||||
- Update to 6.0.19
|
||||
|
||||
* Tue Apr 11 2023 Orion Poplawski <orion@cora.nwra.com> - 6.0.16-1
|
||||
- Update to 6.0.16
|
||||
|
||||
* Wed Apr 05 2023 Orion Poplawski <orion@nwra.com> - 6.0.15-1
|
||||
- Update to 6.0.15
|
||||
|
||||
* Wed Mar 22 2023 Orion Poplawski <orion@nwra.com> - 6.0.14-1
|
||||
- Update to 6.0.14
|
||||
|
||||
* Fri Feb 17 2023 Orion Poplawski <orion@nwra.com> - 6.0.13-1
|
||||
- Update to 6.0.13
|
||||
- Add policy to allow zabbix scripts to run chronyc as chronyc_t (bz#2160180)
|
||||
- Add policy to allow zabbix agent to run rpm read-only
|
||||
- Fix up alternatives scripts to allow better upgrades from other zabbix packages
|
||||
|
||||
* Wed Sep 14 2022 Orion Poplawski <orion@nwra.com> - 6.0.8-1
|
||||
- Build for EPEL
|
||||
Loading…
Add table
Add a link
Reference in a new issue