selinux-refpolicy/policy/support
Russell Coker 3e39efffdf
patches for nspawn policy (#721)
* patches to nspawn policy.

Allow it netlink operations and creating udp sockets

Allow remounting and reading sysfs

Allow stat cgroup filesystem

Make it create fifos and sock_files in the right context

Allow mounting the selinux fs

Signed-off-by: Russell Coker <russell@coker.com.au>

* Use the new mounton_dir_perms and mounton_file_perms macros

Signed-off-by: Russell Coker <russell@coker.com.au>

* Corrected macro name

Signed-off-by: Russell Coker <russell@coker.com.au>

* Fixed description of files_mounton_kernel_symbol_table

Signed-off-by: Russell Coker <russell@coker.com.au>

* systemd: Move lines in nspawn.

No rule changes.

Signed-off-by: Chris PeBenito <pebenito@ieee.org>

---------

Signed-off-by: Russell Coker <russell@coker.com.au>
Signed-off-by: Chris PeBenito <pebenito@ieee.org>
Co-authored-by: Chris PeBenito <pebenito@ieee.org>
2023-10-09 09:32:38 -04:00
..
file_patterns.spt
ipc_patterns.spt
loadable_module.spt Drop module versioning. 2022-01-06 09:19:13 -05:00
misc_macros.spt
misc_patterns.spt systemd: Add systemd-homed and systemd-userdbd. 2022-02-01 09:07:28 -05:00
mls_mcs_macros.spt
obj_perm_sets.spt patches for nspawn policy (#721) 2023-10-09 09:32:38 -04:00