Commit Graph

97 Commits

Author SHA1 Message Date
Daniel J Walsh
0ced217ba7
Allow all container domains to be entered from container_file_t 2019-05-12 06:50:58 -04:00
Daniel J Walsh
5c4855c313
Allow containers to read rpm cache and rpm databse 2019-05-03 15:32:13 -04:00
Daniel J Walsh
3cdf9de46f
Allow containers running as spc_t to create unlabeled_t kernel keyrings 2019-04-23 11:44:55 -04:00
Daniel J Walsh
bd9b0f5853
Allow containers running as spc_t to create unlabeled_t kernel keyrings 2019-04-23 11:44:39 -04:00
Daniel J Walsh
920a724abf
Fix labeling on /var/lib/containers/storage/overlay-layers,images to be sharable.
Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
2019-04-23 11:43:50 -04:00
Daniel J Walsh
e2b52d2d49
Allow iptables to append to container_file_t 2019-04-15 09:14:34 -04:00
Daniel J Walsh
7bfa450762
Allow containers to read/write sysctl_kernel_ns_last_pid_t
Allow containers to manage fusefs sockets and named pipes
2019-04-12 12:48:55 -04:00
Daniel J Walsh
9a2cedceeb
Allow containers to create fusefs sockets and named pipes 2019-04-01 17:47:51 -04:00
Daniel J Walsh
e0dcd250c0
Allow init_t to manage container content
Allow container domains to create fifo_files on fusefs file systems
Add boolean to allow containers to use ceph file systems
2019-03-28 08:00:26 -04:00
Daniel J Walsh
81c6f71fc4
Allow container runtimes to create unlabeled keyrings 2019-03-26 08:15:18 -04:00
Daniel J Walsh
4b3e8ccdf7
Allow containers to mount and umount fuse file systems. This will allow us
to use buidlah within a user namespace separated container.
2019-03-20 15:41:00 -04:00
Daniel J Walsh
c650254748
Allow all container domains to have container file types entrypoint
Add new release to fix issues with udica
Allow container_runtime_t to dyntransition to container domains
2019-03-09 08:38:21 -05:00
Daniel J Walsh
7ef0bf8d6f
Allow unconfined user and services to dyntrans to container domains, needed for CRIU
Allow containers exectue hugetlb files.
2019-03-01 09:00:53 -05:00
Daniel J Walsh
cdbdbb8ff6
More allow rules to allow containers to run within containers 2019-02-28 14:51:59 -05:00
Daniel J Walsh
9481eed87d
More allow rules to allow containers to run within containers 2019-02-28 08:15:40 -05:00
Lokesh Mandvekar (Bot)
0a83311798 container-selinux-2:2.82-2.git5e1f62f
- bump to 2.82
- autobuilt 5e1f62f

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2019-02-26 05:15:09 +00:00
Daniel J Walsh
a2d2cf7715
Allow containers to mounton cgroup and container_file_t 2019-02-25 10:08:25 -05:00
Daniel J Walsh
9c1bcaed9f
Allow confined users to use containers 2019-02-10 07:36:32 -07:00
Lokesh Mandvekar (Bot)
e791d82a98 container-selinux-2:2.80-3.git21c2be6
- bump to 2.80
- autobuilt 21c2be6

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2019-02-08 05:02:18 +00:00
Daniel J Walsh
2ae0570400
Add new labels for paths for containerd 2019-02-07 10:02:09 -07:00
Daniel J Walsh
ff7f910564
Don't allow containers to talk to contianer runtime sockets 2019-01-22 15:05:39 +01:00
Daniel J Walsh
d4eda46462
Fix labeling on /var/lib/registries 2019-01-11 11:05:46 -05:00
Lokesh Mandvekar (Bot)
3899d72021 container-selinux-2:2.77-2.git2c57a17
- bump to 2.77
- autobuilt 2c57a17

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2019-01-11 04:55:44 +00:00
Daniel J Walsh
5e8d437aba
Fix labeling for images in docker daemon user namespace 2019-01-10 15:17:44 -05:00
Daniel J Walsh
22b5b2899f
Allow container-runtime to setattr on fifo_file handed into container runtime. 2018-12-17 15:47:41 -05:00
Daniel J Walsh
6065af86d3
Allow container-runtime to setattr on fifo_file handed into container runtime. 2018-12-17 14:23:41 -05:00
Lokesh Mandvekar (Bot)
fbbda7e411 container-selinux-2:2.752.75-1.dev.git99e2cfd1
- bump to 2.75
- autobuilt 99e2cfd

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2018-11-13 04:05:43 +00:00
Daniel J Walsh
60e901fa33
Allow containers to sendto dgram socket of container runtimes
Needed to run container runtimes in notify socket unit files.
2018-11-12 15:48:53 -05:00
Daniel J Walsh
20e37ffd79
Allow containers to use fuse file systems by default 2018-10-30 08:34:06 -04:00
Daniel J Walsh
5df1d6fc43
Allow containers to setexec themselves 2018-10-19 17:45:33 -04:00
Daniel J Walsh
88328244ed
Define spc_t as a container_domain, so that container_runtime will transition
to spc_t even when setup with nosuid.
2018-09-13 09:33:50 -04:00
Daniel J Walsh
1c6b7ec5b2
Allow unconfined_r to transition to system_r over container_runtime_exec_t 2018-08-22 18:20:47 -07:00
Daniel J Walsh
e6bf4b2eb8
Allow unconfined_t to transition to container_runtime_t over container_runtime_exec_t 2018-08-22 07:30:54 -07:00
Daniel J Walsh
4ed36528d0
dontaudit attempts to write to sysctl_kernel_t 2018-07-25 17:35:22 -04:00
Lokesh Mandvekar (Bot)
08b0e73601 container-selinux-2:2.68-2.gitc139a3d
- autobuilt c139a3d

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2018-07-18 02:04:23 +00:00
Daniel J Walsh
be54b1d5ac
Add labels for /var/lib/origin directory
Add container_file_t as a customizable_type

Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
2018-07-16 12:21:16 -04:00
Lokesh Mandvekar (Bot)
814ce627ca container-selinux-2:2.67-2.git042f7cf
- autobuilt 042f7cf

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2018-07-09 15:15:01 +00:00
Lokesh Mandvekar (Bot)
da11a8106d container-selinux-2:2.67-1.git0407867
- bump to 2.67
- autobuilt 0407867

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2018-07-07 04:53:53 +00:00
Daniel J Walsh
37cbbf8e2c
Allow container runtimes to dbus chat with systemd-resolved 2018-06-30 07:25:56 -04:00
Lokesh Mandvekar (Bot)
ee88cda7eb container-selinux-2:2.64-1.gitdfaf8fd
- bump to 2.64
- autobuilt dfaf8fd

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2018-06-12 04:41:04 +00:00
Daniel J Walsh
781a8d1c0d
Add new type to handle containers running with a non priv user in a userns
allow containers to map all sockets
2018-06-11 08:55:28 -04:00
Daniel J Walsh
3cc70f6448 Allow containers to create all socket classes 2018-06-03 06:14:48 -04:00
Daniel J Walsh
71d8662692 Allow containers to create icmp packets 2018-05-30 11:10:00 -04:00
Lokesh Mandvekar (Bot)
c2346462ef container-selinux-2:2.62-1.git1ecf953
- bump to 2.62
- autobuilt 1ecf953

Signed-off-by: Lokesh Mandvekar (Bot) <lsm5+bot@fedoraproject.org>
2018-05-25 18:35:07 +00:00
Daniel J Walsh
25c4cb361a Allow spc_t to load kernel modules from inside of container 2018-05-21 17:13:15 -04:00
Daniel J Walsh
59df2c8753 Allow containers to list cgroup directories 2018-05-21 13:19:17 -04:00
Daniel J Walsh
2be9204393 Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t. 2018-05-21 12:49:37 -04:00
Daniel J Walsh
1f65dab452 Add labels to allow podman to be run from a systemd unit file 2018-05-18 11:53:51 -04:00
Daniel J Walsh
c46266a878 Dontaudit attempts by containers to write to /proc/self 2018-03-15 07:14:36 -04:00
Daniel J Walsh
37b78d28ce Add rules for container domains to make writing custom policy easier
Allow shell_exec_t as a container_runtime_t entrypoint
2018-03-14 09:39:06 -04:00