container: allow containers to getcap
Signed-off-by: Kenton Groombridge <concord@gentoo.org>
This commit is contained in:
parent
7876e51510
commit
472e0442e7
|
@ -286,7 +286,7 @@ corenet_port(container_port_t)
|
|||
dontaudit container_domain self:capability fsetid;
|
||||
dontaudit container_domain self:capability2 block_suspend;
|
||||
allow container_domain self:cap_userns { chown dac_override dac_read_search fowner kill setgid setuid };
|
||||
allow container_domain self:process { execstack execmem getattr getsched getsession setsched setcap setpgid signal_perms };
|
||||
allow container_domain self:process { execstack execmem getattr getcap getsched getsession setsched setcap setpgid signal_perms };
|
||||
allow container_domain self:dir rw_dir_perms;
|
||||
allow container_domain self:file create_file_perms;
|
||||
allow container_domain self:fifo_file manage_fifo_file_perms;
|
||||
|
|
Loading…
Reference in New Issue