52dc8d8a26
Make conmon run in a separate domain and allow podman types to transition to it. Signed-off-by: Kenton Groombridge <me@concord.sh>
3 lines
141 B
Plaintext
3 lines
141 B
Plaintext
/usr/bin/podman -- gen_context(system_u:object_r:podman_exec_t,s0)
|
|
/usr/bin/conmon -- gen_context(system_u:object_r:podman_conmon_exec_t,s0)
|