diff options
Diffstat (limited to 'contrib')
| -rw-r--r-- | contrib/selinux/passt.te | 7 | ||||
| -rw-r--r-- | contrib/selinux/pasta.te | 2 |
2 files changed, 6 insertions, 3 deletions
diff --git a/contrib/selinux/passt.te b/contrib/selinux/passt.te index 6995df8..e540473 100644 --- a/contrib/selinux/passt.te +++ b/contrib/selinux/passt.te @@ -23,6 +23,7 @@ require { type user_home_t; type tmpfs_t; type root_t; + type nsfs_t; # Workaround: passt --vhost-user needs to map guest memory, but # libvirt doesn't maintain its own policy, which makes updates @@ -61,7 +62,7 @@ require { type sysctl_net_t; class capability { sys_tty_config setuid setgid }; - class cap_userns { setpcap sys_admin sys_ptrace }; + class cap_userns { setpcap setgid setuid sys_admin sys_ptrace }; class user_namespace create; } @@ -104,11 +105,13 @@ allow syslogd_t self:cap_userns sys_ptrace; allow passt_t self:process setcap; allow passt_t self:capability { sys_tty_config setpcap net_bind_service setuid setgid}; -allow passt_t self:cap_userns { setpcap sys_admin sys_ptrace }; +allow passt_t self:cap_userns { setgid setuid setpcap sys_admin sys_ptrace }; allow passt_t self:user_namespace create; auth_read_passwd(passt_t) +allow passt_t nsfs_t:file { open read }; + allow passt_t proc_net_t:file read; allow passt_t tmp_t:sock_file { create unlink write }; allow passt_t self:netlink_route_socket { bind create nlmsg_read read write setopt }; diff --git a/contrib/selinux/pasta.te b/contrib/selinux/pasta.te index 9394f97..d0c9c32 100644 --- a/contrib/selinux/pasta.te +++ b/contrib/selinux/pasta.te @@ -87,7 +87,7 @@ require { type init_t; class capability { sys_tty_config setuid setgid }; - class cap_userns { setpcap sys_admin sys_ptrace net_bind_service net_admin }; + class cap_userns { setpcap sys_admin sys_ptrace net_bind_service net_admin setgid setuid }; class user_namespace create; # Container requires |
