Skip to content

Commit 0ef4703

Browse files
committed
Add rules for kvm containers to use vfio_device
This is needed for the more advanced uses of virtiofsd. Signed-off-by: Daniel J Walsh <[email protected]>
1 parent e80cdf3 commit 0ef4703

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

container.te

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
policy_module(container, 2.149.0)
1+
policy_module(container, 2.150.0)
22
gen_require(`
33
class passwd rootok;
44
')
@@ -754,7 +754,7 @@ allow container_domain self:sem create_sem_perms;
754754
allow container_domain self:shm create_shm_perms;
755755
allow container_domain self:socket create_socket_perms;
756756
allow container_domain self:tcp_socket create_socket_perms;
757-
allow container_domain self:tun_socket { create_socket_perms relabelfrom relabelto };
757+
allow container_domain self:tun_socket { create_socket_perms relabelfrom relabelto attach_queue };
758758
allow container_domain self:udp_socket create_socket_perms;
759759
allow container_domain self:unix_dgram_socket create_socket_perms;
760760
allow container_domain self:unix_stream_socket create_stream_socket_perms;
@@ -1149,6 +1149,7 @@ allow container_kvm_t container_runtime_t:unix_stream_socket rw_stream_socket_pe
11491149
container_stream_connect(container_kvm_t)
11501150

11511151
dev_rw_inherited_vhost(container_kvm_t)
1152+
dev_rw_vfio_dev(container_kvm_t)
11521153

11531154
corenet_rw_inherited_tun_tap_dev(container_kvm_t)
11541155
corecmd_exec_shell(container_kvm_t)

0 commit comments

Comments
 (0)