Skip to content

Commit 20dc668

Browse files
authored
Merge pull request #218 from rhatdan/main
Allow avirt_sandbox_domain to manage container_file_t types
2 parents 6ab4d5b + 9e5afed commit 20dc668

File tree

1 file changed

+9
-1
lines changed

1 file changed

+9
-1
lines changed

container.te

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
policy_module(container, 2.204.0)
1+
policy_module(container, 2.205.0)
22

33
gen_require(`
44
class passwd rootok;
@@ -1414,3 +1414,11 @@ optional_policy(`
14141414
allow syslogd_t container_runtime_tmpfs_t:file { read write };
14151415
logging_send_syslog_msg(container_runtime_t)
14161416
')
1417+
1418+
1419+
manage_dirs_pattern(svirt_sandbox_domain, container_file_t, container_file_t)
1420+
manage_files_pattern(svirt_sandbox_domain, container_file_t, container_file_t)
1421+
manage_lnk_files_pattern(svirt_sandbox_domain, container_file_t, container_file_t)
1422+
manage_chr_files_pattern(svirt_sandbox_domain, container_file_t, container_file_t)
1423+
manage_blk_files_pattern(svirt_sandbox_domain, container_file_t, container_file_t)
1424+
manage_sock_files_pattern(svirt_sandbox_domain, container_file_t, container_file_t)

0 commit comments

Comments
 (0)