Skip to content

Commit 5d98341

Browse files
authored
Merge pull request #303 from rhatdan/main
Allow container domains to communicate with spc_t unix_stream_sockets
2 parents a8e389d + 0e7f166 commit 5d98341

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

container.te

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
policy_module(container, 2.230.0)
1+
policy_module(container, 2.231.0)
22

33
gen_require(`
44
class passwd rootok;
@@ -1087,6 +1087,7 @@ allow container_net_domain self:rawip_socket create_stream_socket_perms;
10871087
allow container_net_domain self:netlink_kobject_uevent_socket create_socket_perms;
10881088
allow container_net_domain self:netlink_xfrm_socket create_netlink_socket_perms;
10891089

1090+
allow container_domain spc_t:unix_stream_socket { read write };
10901091
kernel_unlabeled_domtrans(container_runtime_domain, spc_t)
10911092
kernel_unlabeled_entry_type(spc_t)
10921093
allow container_runtime_domain unlabeled_t:key manage_key_perms;

0 commit comments

Comments
 (0)