File tree Expand file tree Collapse file tree 1 file changed +3
-2
lines changed Expand file tree Collapse file tree 1 file changed +3
-2
lines changed Original file line number Diff line number Diff line change 1
- policy_module(container, 2 .149 .0 )
1
+ policy_module(container, 2 .150 .0 )
2
2
gen_require(`
3
3
class passwd rootok;
4
4
')
@@ -754,7 +754,7 @@ allow container_domain self:sem create_sem_perms;
754
754
allow container_domain self:shm create_shm_perms;
755
755
allow container_domain self:socket create_socket_perms;
756
756
allow container_domain self:tcp_socket create_socket_perms;
757
- allow container_domain self:tun_socket { create_socket_perms relabelfrom relabelto };
757
+ allow container_domain self:tun_socket { create_socket_perms relabelfrom relabelto attach_queue };
758
758
allow container_domain self:udp_socket create_socket_perms;
759
759
allow container_domain self:unix_dgram_socket create_socket_perms;
760
760
allow container_domain self:unix_stream_socket create_stream_socket_perms;
@@ -1149,6 +1149,7 @@ allow container_kvm_t container_runtime_t:unix_stream_socket rw_stream_socket_pe
1149
1149
container_stream_connect(container_kvm_t)
1150
1150
1151
1151
dev_rw_inherited_vhost(container_kvm_t)
1152
+ dev_rw_vfio_dev(container_kvm_t)
1152
1153
1153
1154
corenet_rw_inherited_tun_tap_dev(container_kvm_t)
1154
1155
corecmd_exec_shell(container_kvm_t)
You can’t perform that action at this time.
0 commit comments