Skip to content

Commit 8ed2899

Browse files
committed
Add support to new user_namespace access check
Signed-off-by: Daniel J Walsh <[email protected]>
1 parent 7293dae commit 8ed2899

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

container.te

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
policy_module(container, 2.199.0)
1+
policy_module(container, 2.200.0)
22

33
gen_require(`
44
class passwd rootok;
@@ -819,6 +819,7 @@ allow container_domain container_runtime_domain:fd use;
819819
allow container_runtime_domain container_domain:fd use;
820820
allow container_domain self:socket_class_set { create_socket_perms map accept };
821821
allow container_domain self:lnk_file setattr;
822+
allow container_domain self:user_namespace create;
822823

823824
dontaudit container_domain self:capability fsetid;
824825
allow container_domain self:association sendto;

0 commit comments

Comments
 (0)