File tree Expand file tree Collapse file tree 1 file changed +2
-0
lines changed Expand file tree Collapse file tree 1 file changed +2
-0
lines changed Original file line number Diff line number Diff line change @@ -1616,6 +1616,8 @@ allow container_domain container_ro_file_t:file { entrypoint execmod execute exe
1616
1616
allow container_domain container_var_lib_t:file entrypoint;
1617
1617
allow container_domain fusefs_t:file { append create entrypoint execmod execute execute_no_trans getattr ioctl link lock map mounton open read rename setattr unlink watch watch_reads write };
1618
1618
1619
+ allow install_t container_runtime_t:process2 { nnp_transition nosuid_transition };
1620
+
1619
1621
corecmd_entrypoint_all_executables(container_kvm_t)
1620
1622
allow svirt_sandbox_domain exec_type:file { entrypoint execute execute_no_trans getattr ioctl lock map open read };
1621
1623
allow svirt_sandbox_domain mountpoint:file entrypoint;
You can’t perform that action at this time.
0 commit comments