Skip to content

Commit c9f0cb6

Browse files
authored
Merge pull request #126 from rhatdan/master
Allow unconfined domains to talk to unlabled sockets
2 parents d89a599 + 9e769d3 commit c9f0cb6

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

container.te

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
policy_module(container, 2.159.0)
1+
policy_module(container, 2.160.0)
22
gen_require(`
33
class passwd rootok;
44
')
@@ -648,6 +648,7 @@ allow container_runtime_domain spc_t:process { setsched signal_perms };
648648
ps_process_pattern(container_runtime_domain, spc_t)
649649
allow container_runtime_domain spc_t:socket_class_set { relabelto relabelfrom };
650650
allow spc_t unlabeled_t:key manage_key_perms;
651+
allow spc_t unlabeled_t:socket_class_set create_socket_perms;
651652

652653
init_dbus_chat(spc_t)
653654

0 commit comments

Comments
 (0)