selinux-refpolicy/policy/modules/services/podman.fc
Kenton Groombridge 52dc8d8a26 container, podman: add policy for conmon
Make conmon run in a separate domain and allow podman types to
transition to it.

Signed-off-by: Kenton Groombridge <me@concord.sh>
2022-01-24 11:07:45 -05:00

3 lines
141 B
Plaintext

/usr/bin/podman -- gen_context(system_u:object_r:podman_exec_t,s0)
/usr/bin/conmon -- gen_context(system_u:object_r:podman_conmon_exec_t,s0)