1 |
commit: bd72a9299a732f01958ce28f616be3313eb13536 |
2 |
Author: Kenton Groombridge <me <AT> concord <DOT> sh> |
3 |
AuthorDate: Thu Mar 31 18:22:01 2022 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Sat Apr 9 19:28:30 2022 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=bd72a929 |
7 |
|
8 |
podman: fix role associations |
9 |
|
10 |
Add conmon to the system role and make podman/conmon user domains user |
11 |
applications. |
12 |
|
13 |
Signed-off-by: Kenton Groombridge <me <AT> concord.sh> |
14 |
Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org> |
15 |
|
16 |
policy/modules/services/podman.te | 5 +++-- |
17 |
1 file changed, 3 insertions(+), 2 deletions(-) |
18 |
|
19 |
diff --git a/policy/modules/services/podman.te b/policy/modules/services/podman.te |
20 |
index 316db505..e5158720 100644 |
21 |
--- a/policy/modules/services/podman.te |
22 |
+++ b/policy/modules/services/podman.te |
23 |
@@ -18,15 +18,16 @@ mls_trusted_object(podman_t) |
24 |
|
25 |
container_engine_domain_template(podman_user) |
26 |
container_user_engine(podman_user_t) |
27 |
-application_domain(podman_user_t, podman_exec_t) |
28 |
+userdom_user_application_domain(podman_user_t, podman_exec_t) |
29 |
mls_trusted_object(podman_user_t) |
30 |
|
31 |
type podman_conmon_t; |
32 |
type podman_conmon_exec_t; |
33 |
application_domain(podman_conmon_t, podman_conmon_exec_t) |
34 |
+role system_r types podman_conmon_t; |
35 |
|
36 |
type podman_conmon_user_t; |
37 |
-application_domain(podman_conmon_user_t, podman_conmon_exec_t) |
38 |
+userdom_user_application_domain(podman_conmon_user_t, podman_conmon_exec_t) |
39 |
|
40 |
######################################## |
41 |
# |