Skip to content

Commit c98794e

Browse files
committed
Allow container domains to be used by user roles
Signed-off-by: Daniel J Walsh <[email protected]>
1 parent db7dcc5 commit c98794e

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

container.te

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
policy_module(container, 2.171.0)
1+
policy_module(container, 2.172.0)
22

33
gen_require(`
44
class passwd rootok;
@@ -590,6 +590,7 @@ optional_policy(`
590590
gen_require(`
591591
role unconfined_r;
592592
')
593+
role unconfined_r types container_user_domain;
593594
unconfined_domain(container_runtime_t)
594595
unconfined_run_to(container_runtime_t, container_runtime_exec_t)
595596
role_transition unconfined_r container_runtime_exec_t system_r;

0 commit comments

Comments
 (0)