diff options
| author | Max Chernoff <git@maxchernoff.ca> | 2025-05-24 01:16:57 -0600 |
|---|---|---|
| committer | Stefano Brivio <sbrivio@redhat.com> | 2025-06-04 12:24:01 +0200 |
| commit | 7aeda16a781848df3dc897da477e6a9bb8a84e67 (patch) | |
| tree | 18730a636718199b854d17a1b50ddeb27e22ad1f /doc | |
| parent | 3262c9b088288902f28b5d09f61220fae5376082 (diff) | |
| download | passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.tar passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.tar.gz passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.tar.bz2 passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.tar.lz passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.tar.xz passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.tar.zst passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.zip | |
selinux: Transition to pasta_t in containers
Currently, pasta runs in the container_runtime_exec_t context when
running in a container. This is not ideal since it means that pasta runs
with more privileges than strictly necessary. This commit updates the
SELinux policy to have pasta transition to the pasta_t context when
started from the container_runtime_t context, adds the appropriate
labels to $XDG_RUNTIME_DIR/netns and
$XDG_RUNTIME_DIR/containers/networks/rootless-netns, and grants the
necessary permissions to the pasta_t context.
Link: https://bugs.passt.top/show_bug.cgi?id=81
Link: https://github.com/containers/podman/discussions/26100#discussioncomment-13088518
Signed-off-by: Max Chernoff <git@maxchernoff.ca>
Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
Diffstat (limited to 'doc')
0 files changed, 0 insertions, 0 deletions
