Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/services/
Date: Sat, 09 Apr 2022 19:28:54
Message-Id: 1649532510.bd72a9299a732f01958ce28f616be3313eb13536.perfinion@gentoo
1 commit: bd72a9299a732f01958ce28f616be3313eb13536
2 Author: Kenton Groombridge <me <AT> concord <DOT> sh>
3 AuthorDate: Thu Mar 31 18:22:01 2022 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Sat Apr 9 19:28:30 2022 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=bd72a929
7
8 podman: fix role associations
9
10 Add conmon to the system role and make podman/conmon user domains user
11 applications.
12
13 Signed-off-by: Kenton Groombridge <me <AT> concord.sh>
14 Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org>
15
16 policy/modules/services/podman.te | 5 +++--
17 1 file changed, 3 insertions(+), 2 deletions(-)
18
19 diff --git a/policy/modules/services/podman.te b/policy/modules/services/podman.te
20 index 316db505..e5158720 100644
21 --- a/policy/modules/services/podman.te
22 +++ b/policy/modules/services/podman.te
23 @@ -18,15 +18,16 @@ mls_trusted_object(podman_t)
24
25 container_engine_domain_template(podman_user)
26 container_user_engine(podman_user_t)
27 -application_domain(podman_user_t, podman_exec_t)
28 +userdom_user_application_domain(podman_user_t, podman_exec_t)
29 mls_trusted_object(podman_user_t)
30
31 type podman_conmon_t;
32 type podman_conmon_exec_t;
33 application_domain(podman_conmon_t, podman_conmon_exec_t)
34 +role system_r types podman_conmon_t;
35
36 type podman_conmon_user_t;
37 -application_domain(podman_conmon_user_t, podman_conmon_exec_t)
38 +userdom_user_application_domain(podman_conmon_user_t, podman_conmon_exec_t)
39
40 ########################################
41 #