mirror of
https://github.com/flatcar/scripts.git
synced 2025-08-24 16:01:09 +02:00
Merge pull request #1995 from mjg59/selinux-character-nodes
sec-policy/selinux-virt: Grant more permissions on chr_files
This commit is contained in:
commit
8d59ca5df6
@ -27,7 +27,7 @@ diff -u contrib.orig/virt.te contrib/virt.te
|
|||||||
+term_use_generic_ptys(svirt_lxc_net_t)
|
+term_use_generic_ptys(svirt_lxc_net_t)
|
||||||
+term_setattr_generic_ptys(svirt_lxc_net_t)
|
+term_setattr_generic_ptys(svirt_lxc_net_t)
|
||||||
+allow svirt_lxc_net_t tmpfs_t:chr_file { read write open };
|
+allow svirt_lxc_net_t tmpfs_t:chr_file { read write open };
|
||||||
+allow svirt_lxc_net_t svirt_lxc_file_t:chr_file { setattr };
|
+allow svirt_lxc_net_t svirt_lxc_file_t:chr_file { manage_file_perm };
|
||||||
+allow svirt_lxc_net_t self:capability sys_chroot;
|
+allow svirt_lxc_net_t self:capability sys_chroot;
|
||||||
+allow svirt_lxc_net_t self:process getpgid;
|
+allow svirt_lxc_net_t self:process getpgid;
|
||||||
+allow svirt_lxc_net_t svirt_lxc_file_t:file { entrypoint mounton };
|
+allow svirt_lxc_net_t svirt_lxc_file_t:file { entrypoint mounton };
|
||||||
|
Loading…
x
Reference in New Issue
Block a user