Skip to content

Commit 735aaf4

Browse files
committed
Allow syslogd_t to use tmpfs files created by container runtime
Signed-off-by: Daniel J Walsh <[email protected]>
1 parent 88f904d commit 735aaf4

File tree

1 file changed

+10
-1
lines changed

1 file changed

+10
-1
lines changed

container.te

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
policy_module(container, 2.193.0)
1+
policy_module(container, 2.194.0)
22

33
gen_require(`
44
class passwd rootok;
@@ -1377,3 +1377,12 @@ dev_rw_sysfs(container_device_plugin_init_t)
13771377
manage_dirs_pattern(container_device_plugin_init_t, kubernetes_file_t, kubernetes_file_t)
13781378
manage_files_pattern(container_device_plugin_init_t, kubernetes_file_t, kubernetes_file_t)
13791379
manage_lnk_files_pattern(container_device_plugin_init_t, kubernetes_file_t, kubernetes_file_t)
1380+
1381+
optional_policy(`
1382+
gen_require(`
1383+
type syslogd_t;
1384+
')
1385+
1386+
allow syslogd_t container_runtime_tmpfs_t:file { read write };
1387+
logging_send_syslog_msg(container_runtime_t)
1388+
')

0 commit comments

Comments
 (0)