type=AVC msg=audit(1312230830.140:46): avc: denied { read } for pid=1711 comm="nrpe" name="nrpe.cfg" dev=vda3 ino=6958 scontext=system_u:system_r:nrpe_t tcontext=system_u:object_r:nrpe_etc_t tclass=file Reproducible: Always
type=SYSCALL msg=audit(1312230830.140:46): arch=c000003e syscall=2 success=no exit=-13 a0=4ca00b9e040 a1=0 a2=1b6 a3=0 items=0 ppid=1710 pid=1711 auid=4294967295 uid=103 gid=110 euid=103 suid=103 fsuid=103 egid=110 sgid=110 fsgid=110 tty=(none) ses=4294967295 comm="nrpe" exe="/usr/bin/nrpe" subj=system_u:system_r:nrpe_t key=(null)
Should be available in hardened-dev overlay, selinux-nagios-2.20110726-r1
working now, but I get the following for the check-disk plugin type=AVC msg=audit(1313311496.131:89): avc: denied { getattr } for pid=3430 comm="check_disk" path="/var" dev=dm-3 ino=2 scontext=system_u:system_r:nagios_checkdisk_plugin_t tcontext=system_u:object_r:var_t tclass=dir type=SYSCALL msg=audit(1313311496.131:89): arch=c000003e syscall=4 success=no exit=-13 a0=7e75c8394a25 a1=9d9dcc6fd60 a2=9d9dcc6fd60 a3=4 items=0 ppid=3429 pid=3430 auid=0 uid=103 gid=110 euid=103 suid=103 fsuid=103 egid=110 sgid=110 fsgid=110 tty=(none) ses=1 comm="check_disk" exe="/usr/lib64/nagios/plugins/check_disk" subj=system_u:system_r:nagios_checkdisk_plugin_t key=(null) type=AVC msg=audit(1313311511.189:90): avc: denied { read } for pid=3434 comm="check_disk" name="mtab" dev=vda3 ino=7304 scontext=system_u:system_r:nagios_checkdisk_plugin_t tcontext=system_u:object_r:etc_t tclass=file type=SYSCALL msg=audit(1313311511.189:90): arch=c000003e syscall=2 success=no exit=-13 a0=4a49fd08260 a1=0 a2=1b6 a3=0 items=0 ppid=3433 pid=3434 auid=0 uid=103 gid=110 euid=103 suid=103 fsuid=103 egid=110 sgid=110 fsgid=110 tty=(none) ses=1 comm="check_disk" exe="/usr/lib64/nagios/plugins/check_disk" subj=system_u:system_r:nagios_checkdisk_plugin_t key=(null) type=AVC msg=audit(1313311511.189:91): avc: denied { read } for pid=3434 comm="check_disk" name="mtab" dev=vda3 ino=7304 scontext=system_u:system_r:nagios_checkdisk_plugin_t tcontext=system_u:object_r:etc_t tclass=file type=SYSCALL msg=audit(1313311511.189:91): arch=c000003e syscall=2 success=no exit=-13 a0=4a49fd08260 a1=0 a2=1b6 a3=0 items=0 ppid=3433 pid=3434 auid=0 uid=103 gid=110 euid=103 suid=103 fsuid=103 egid=110 sgid=110 fsgid=110 tty=(none) ses=1 comm="check_disk" exe="/usr/lib64/nagios/plugins/check_disk" subj=system_u:system_r:nagios_checkdisk_plugin_t key=(null)
Opening bug 379199 for the nrpe plugin issue