瀏覽代碼

Merge pull request #21381 from mlaventure/selinux-pcp_pmcd

Give selinux pcp_pmcd_t type access to /var/lib/docker
Michael Crosby 9 年之前
父節點
當前提交
55304e2e55
共有 1 個文件被更改,包括 7 次插入0 次删除
  1. 7 0
      contrib/docker-engine-selinux/docker.te

+ 7 - 0
contrib/docker-engine-selinux/docker.te

@@ -405,3 +405,10 @@ optional_policy(`
 
 
      dontaudit svirt_sandbox_domain domain:key {search link};
      dontaudit svirt_sandbox_domain domain:key {search link};
 ')
 ')
+
+optional_policy(`
+	gen_require(`
+		type pcp_pmcd_t;
+	')
+	docker_manage_lib_files(pcp_pmcd_t)
+')