Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/services/
Date: Sun, 30 Jan 2022 01:22:59
Message-Id: 1643505306.1841ac553d3131121749274fe165af7af8d6865d.perfinion@gentoo
1 commit: 1841ac553d3131121749274fe165af7af8d6865d
2 Author: Kenton Groombridge <me <AT> concord <DOT> sh>
3 AuthorDate: Fri Jan 21 19:03:38 2022 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Sun Jan 30 01:15:06 2022 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=1841ac55
7
8 docker: call rootlesskit access in docker access
9
10 Signed-off-by: Kenton Groombridge <me <AT> concord.sh>
11 Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org>
12
13 policy/modules/services/docker.if | 4 ++++
14 1 file changed, 4 insertions(+)
15
16 diff --git a/policy/modules/services/docker.if b/policy/modules/services/docker.if
17 index 6460ed6e..c3ac8174 100644
18 --- a/policy/modules/services/docker.if
19 +++ b/policy/modules/services/docker.if
20 @@ -178,6 +178,8 @@ template(`docker_user_role',`
21 docker_run_user_daemon($3, $4)
22 docker_run_user_cli($3, $4)
23
24 + rootlesskit_role($1, $2, $3, $4)
25 +
26 ifdef(`init_systemd',`
27 systemd_user_daemon_domain($1, dockerd_exec_t, dockerd_user_t)
28 systemd_user_send_systemd_notify($1, dockerd_user_t)
29 @@ -226,4 +228,6 @@ interface(`docker_signal_user_daemon',`
30 #
31 interface(`docker_admin',`
32 docker_run_cli($1, $2)
33 +
34 + rootlesskit_run($1, $2)
35 ')