Skip to content

Commit a023e9e

Browse files
authored
Merge pull request #300 from rhatdan/main
Add buildah as a container_runtime_exec_t label
2 parents eac5792 + db3b662 commit a023e9e

File tree

2 files changed

+7
-6
lines changed

2 files changed

+7
-6
lines changed

container.fc

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -13,14 +13,15 @@
1313
/usr/local/s?bin/kubenswrapper.* -- gen_context(system_u:object_r:kubelet_exec_t,s0)
1414
/usr/s?bin/kubensenter.* -- gen_context(system_u:object_r:kubelet_exec_t,s0)
1515
/usr/local/s?bin/kubensenter.* -- gen_context(system_u:object_r:kubelet_exec_t,s0)
16-
/usr/local/s?bin/docker.* -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
16+
/usr/local/s?bin/docker.* -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
1717
/usr/s?bin/containerd.* -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
18-
/usr/local/s?bin/containerd.* -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
18+
/usr/local/s?bin/containerd.* -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
19+
/usr/s?bin/buildah -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
1920
/usr/s?bin/buildkitd.* -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
20-
/usr/local/s?bin/buildkitd.* -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
21+
/usr/local/s?bin/buildkitd.* -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
2122

22-
/usr/s?bin/lxc-.* -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
23-
/usr/s?bin/lxd-.* -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
23+
/usr/s?bin/lxc-.* -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
24+
/usr/s?bin/lxd-.* -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
2425
/usr/s?bin/lxc -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
2526
/usr/s?bin/lxd -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
2627
/usr/s?bin/fuidshift -- gen_context(system_u:object_r:container_runtime_exec_t,s0)

container.te

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
policy_module(container, 2.229.0)
1+
policy_module(container, 2.229.1)
22

33
gen_require(`
44
class passwd rootok;

0 commit comments

Comments
 (0)