selinux-refpolicy/policy/modules
Russell Coker 3e39efffdf
patches for nspawn policy (#721)
* patches to nspawn policy.

Allow it netlink operations and creating udp sockets

Allow remounting and reading sysfs

Allow stat cgroup filesystem

Make it create fifos and sock_files in the right context

Allow mounting the selinux fs

Signed-off-by: Russell Coker <russell@coker.com.au>

* Use the new mounton_dir_perms and mounton_file_perms macros

Signed-off-by: Russell Coker <russell@coker.com.au>

* Corrected macro name

Signed-off-by: Russell Coker <russell@coker.com.au>

* Fixed description of files_mounton_kernel_symbol_table

Signed-off-by: Russell Coker <russell@coker.com.au>

* systemd: Move lines in nspawn.

No rule changes.

Signed-off-by: Chris PeBenito <pebenito@ieee.org>

---------

Signed-off-by: Russell Coker <russell@coker.com.au>
Signed-off-by: Chris PeBenito <pebenito@ieee.org>
Co-authored-by: Chris PeBenito <pebenito@ieee.org>
2023-10-09 09:32:38 -04:00
..
admin small network patches (#707) 2023-09-25 11:44:52 -04:00
apps Merge pull request #713 from gtrentalancia/openoffice_fixes_pr2 2023-10-02 08:57:04 -04:00
kernel patches for nspawn policy (#721) 2023-10-09 09:32:38 -04:00
roles init, sysadm: allow sysadm to manage systemd runtime units 2022-12-12 10:32:10 -05:00
services Separate label for /run/systemd/notify (#710) 2023-10-06 09:06:39 -04:00
system patches for nspawn policy (#721) 2023-10-09 09:32:38 -04:00