diff --git a/policy-rawhide-contrib.patch b/policy-rawhide-contrib.patch index 94d21eb0..c8e9d8b3 100644 --- a/policy-rawhide-contrib.patch +++ b/policy-rawhide-contrib.patch @@ -22509,7 +22509,7 @@ index 0000000..d856375 +') diff --git a/docker.te b/docker.te new file mode 100644 -index 0000000..c5b0dcd +index 0000000..f156949 --- /dev/null +++ b/docker.te @@ -0,0 +1,145 @@ @@ -22610,8 +22610,8 @@ index 0000000..c5b0dcd + +allow docker_t self:capability { sys_admin sys_boot dac_override setpcap sys_ptrace }; +allow docker_t self:process { setpgid setsched signal_perms }; -+allow docker_t self:netlink_route_socket nlmsg_write; -+allow docker_t self:netlink_audit_socket create_netlink_perms; ++allow docker_t self:netlink_route_socket rw_netlink_socket_perms;; ++allow docker_t self:netlink_audit_socket create_netlink_socket_perms; +allow docker_t self:unix_dgram_socket create_socket_perms; +allow docker_t self:unix_stream_socket { create_stream_socket_perms connectto }; +