aboutgitcodebugslistschat
path: root/doc
diff options
context:
space:
mode:
authorMax Chernoff <git@maxchernoff.ca>2025-05-24 01:16:57 -0600
committerStefano Brivio <sbrivio@redhat.com>2025-06-04 12:24:01 +0200
commit7aeda16a781848df3dc897da477e6a9bb8a84e67 (patch)
tree18730a636718199b854d17a1b50ddeb27e22ad1f /doc
parent3262c9b088288902f28b5d09f61220fae5376082 (diff)
downloadpasst-7aeda16a781848df3dc897da477e6a9bb8a84e67.tar
passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.tar.gz
passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.tar.bz2
passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.tar.lz
passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.tar.xz
passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.tar.zst
passt-7aeda16a781848df3dc897da477e6a9bb8a84e67.zip
selinux: Transition to pasta_t in containers
Currently, pasta runs in the container_runtime_exec_t context when running in a container. This is not ideal since it means that pasta runs with more privileges than strictly necessary. This commit updates the SELinux policy to have pasta transition to the pasta_t context when started from the container_runtime_t context, adds the appropriate labels to $XDG_RUNTIME_DIR/netns and $XDG_RUNTIME_DIR/containers/networks/rootless-netns, and grants the necessary permissions to the pasta_t context. Link: https://bugs.passt.top/show_bug.cgi?id=81 Link: https://github.com/containers/podman/discussions/26100#discussioncomment-13088518 Signed-off-by: Max Chernoff <git@maxchernoff.ca> Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
Diffstat (limited to 'doc')
0 files changed, 0 insertions, 0 deletions