1 |
commit: 1841ac553d3131121749274fe165af7af8d6865d |
2 |
Author: Kenton Groombridge <me <AT> concord <DOT> sh> |
3 |
AuthorDate: Fri Jan 21 19:03:38 2022 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Sun Jan 30 01:15:06 2022 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=1841ac55 |
7 |
|
8 |
docker: call rootlesskit access in docker access |
9 |
|
10 |
Signed-off-by: Kenton Groombridge <me <AT> concord.sh> |
11 |
Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org> |
12 |
|
13 |
policy/modules/services/docker.if | 4 ++++ |
14 |
1 file changed, 4 insertions(+) |
15 |
|
16 |
diff --git a/policy/modules/services/docker.if b/policy/modules/services/docker.if |
17 |
index 6460ed6e..c3ac8174 100644 |
18 |
--- a/policy/modules/services/docker.if |
19 |
+++ b/policy/modules/services/docker.if |
20 |
@@ -178,6 +178,8 @@ template(`docker_user_role',` |
21 |
docker_run_user_daemon($3, $4) |
22 |
docker_run_user_cli($3, $4) |
23 |
|
24 |
+ rootlesskit_role($1, $2, $3, $4) |
25 |
+ |
26 |
ifdef(`init_systemd',` |
27 |
systemd_user_daemon_domain($1, dockerd_exec_t, dockerd_user_t) |
28 |
systemd_user_send_systemd_notify($1, dockerd_user_t) |
29 |
@@ -226,4 +228,6 @@ interface(`docker_signal_user_daemon',` |
30 |
# |
31 |
interface(`docker_admin',` |
32 |
docker_run_cli($1, $2) |
33 |
+ |
34 |
+ rootlesskit_run($1, $2) |
35 |
') |