diff options
author | Laurent Bigonville <bigon@bigon.be> | 2016-02-19 16:43:10 +0100 |
---|---|---|
committer | Jason Zaman <jason@perfinion.com> | 2016-03-12 01:15:38 +0800 |
commit | 32348d254dbfba60ae8671f958bc302281cce8c6 (patch) | |
tree | fcffc47f6f4d47220a12817d3e750eb304a012a2 /config | |
parent | Module version bump for iptables/firewalld patch from Laurent Bigonville. (diff) | |
download | hardened-refpolicy-32348d254dbfba60ae8671f958bc302281cce8c6.tar.gz hardened-refpolicy-32348d254dbfba60ae8671f958bc302281cce8c6.tar.bz2 hardened-refpolicy-32348d254dbfba60ae8671f958bc302281cce8c6.zip |
Add lxc_contexts config file
selinux_lxc_contexts_path() function in upstream libselinux points to
this config file. It is ATM used by libvirt.
The file from Fedora also contains sandbox_lxc_process and
sandbox_kvm_process parameters, but I cannot find where they are used,
keep them out of the file for the time being.
Diffstat (limited to 'config')
-rw-r--r-- | config/appconfig-mcs/lxc_contexts | 3 | ||||
-rw-r--r-- | config/appconfig-mls/lxc_contexts | 3 | ||||
-rw-r--r-- | config/appconfig-standard/lxc_contexts | 3 |
3 files changed, 9 insertions, 0 deletions
diff --git a/config/appconfig-mcs/lxc_contexts b/config/appconfig-mcs/lxc_contexts new file mode 100644 index 00000000..bf3fcc1a --- /dev/null +++ b/config/appconfig-mcs/lxc_contexts @@ -0,0 +1,3 @@ +process = "system_u:system_r:svirt_lxc_net_t:s0" +content = "system_u:object_r:virt_var_lib_t:s0" +file = "system_u:object_r:svirt_lxc_file_t:s0" diff --git a/config/appconfig-mls/lxc_contexts b/config/appconfig-mls/lxc_contexts new file mode 100644 index 00000000..bf3fcc1a --- /dev/null +++ b/config/appconfig-mls/lxc_contexts @@ -0,0 +1,3 @@ +process = "system_u:system_r:svirt_lxc_net_t:s0" +content = "system_u:object_r:virt_var_lib_t:s0" +file = "system_u:object_r:svirt_lxc_file_t:s0" diff --git a/config/appconfig-standard/lxc_contexts b/config/appconfig-standard/lxc_contexts new file mode 100644 index 00000000..b386c6ad --- /dev/null +++ b/config/appconfig-standard/lxc_contexts @@ -0,0 +1,3 @@ +process = "system_u:system_r:svirt_lxc_net_t" +content = "system_u:object_r:virt_var_lib_t" +file = "system_u:object_r:svirt_lxc_file_t" |