1 |
commit: 9a6e04ea1f7da6812ea463bd509862a77f0da623 |
2 |
Author: Kenton Groombridge <me <AT> concord <DOT> sh> |
3 |
AuthorDate: Sun Jan 30 23:09:12 2022 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Mon Jan 31 17:55:20 2022 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=9a6e04ea |
7 |
|
8 |
docker: add missing call to init_daemon_domain() |
9 |
|
10 |
Signed-off-by: Kenton Groombridge <me <AT> concord.sh> |
11 |
Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org> |
12 |
|
13 |
policy/modules/services/docker.te | 1 + |
14 |
1 file changed, 1 insertion(+) |
15 |
|
16 |
diff --git a/policy/modules/services/docker.te b/policy/modules/services/docker.te |
17 |
index bb5eeb49..7a657e15 100644 |
18 |
--- a/policy/modules/services/docker.te |
19 |
+++ b/policy/modules/services/docker.te |
20 |
@@ -10,6 +10,7 @@ container_system_engine(dockerd_t) |
21 |
type dockerd_exec_t; |
22 |
container_engine_executable_file(dockerd_exec_t) |
23 |
application_domain(dockerd_t, dockerd_exec_t) |
24 |
+init_daemon_domain(dockerd_t, dockerd_exec_t) |
25 |
ifdef(`enable_mls',` |
26 |
init_ranged_daemon_domain(dockerd_t, dockerd_exec_t, s0 - mls_systemhigh) |
27 |
') |