Skip to content

Commit 1677bc4

Browse files
committed
Allow containers to read nsfs file systems
Signed-off-by: Daniel J Walsh <[email protected]>
1 parent 5d3c461 commit 1677bc4

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

container.te

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
policy_module(container, 2.151.0)
1+
policy_module(container, 2.152.0)
22
gen_require(`
33
class passwd rootok;
44
')
@@ -830,6 +830,7 @@ fs_manage_hugetlbfs_files(container_domain)
830830
fs_exec_hugetlbfs_files(container_domain)
831831
fs_dontaudit_getattr_all_dirs(container_domain)
832832
fs_dontaudit_getattr_all_files(container_domain)
833+
fs_read_nsfs_files(container_domain)
833834

834835
term_use_all_inherited_terms(container_domain)
835836

0 commit comments

Comments
 (0)