mirror of
https://github.com/flatcar/scripts.git
synced 2025-08-24 16:01:09 +02:00
sec-policy/selinux-virt: Grant more permissions on chr_files
apt seems to use character device nodes for a couple of things, so give the full set of permissions for them when operating in the container's own context.
This commit is contained in:
parent
ea43677d10
commit
e7a2a92b66
@ -27,7 +27,7 @@ diff -u contrib.orig/virt.te contrib/virt.te
|
||||
+term_use_generic_ptys(svirt_lxc_net_t)
|
||||
+term_setattr_generic_ptys(svirt_lxc_net_t)
|
||||
+allow svirt_lxc_net_t tmpfs_t:chr_file { read write open };
|
||||
+allow svirt_lxc_net_t svirt_lxc_file_t:chr_file { setattr };
|
||||
+allow svirt_lxc_net_t svirt_lxc_file_t:chr_file { manage_file_perm };
|
||||
+allow svirt_lxc_net_t self:capability sys_chroot;
|
||||
+allow svirt_lxc_net_t self:process getpgid;
|
||||
+allow svirt_lxc_net_t svirt_lxc_file_t:file { entrypoint mounton };
|
||||
|
Loading…
x
Reference in New Issue
Block a user