Skip to content

Commit 887d683

Browse files
committed
Allow container_logread_t to read logfile sym links
Signed-off-by: Daniel J Walsh <[email protected]>
1 parent ce3c132 commit 887d683

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

container.te

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
policy_module(container, 2.168.0)
1+
policy_module(container, 2.169.0)
22

33
gen_require(`
44
class passwd rootok;
@@ -1113,6 +1113,8 @@ tunable_policy(`virt_sandbox_use_sys_admin',`
11131113
container_domain_template(container_logreader)
11141114
typeattribute container_logreader_t container_net_domain;
11151115
logging_read_all_logs(container_logreader_t)
1116+
# Remove once https://github.com/fedora-selinux/selinux-policy/pull/898 merges
1117+
allow container_logreader_t logfile:lnk_file read_lnk_file_perms;
11161118
logging_read_audit_log(container_logreader_t)
11171119
logging_list_logs(container_logreader_t)
11181120

0 commit comments

Comments
 (0)