Skip to content

Commit d72cbcb

Browse files
Merge pull request #416 from ca-hu/account-utils-set-uidmap
Introduce container_write_proc_files interface (bsc#1253469)
2 parents efdee4d + c6349ab commit d72cbcb

File tree

1 file changed

+19
-0
lines changed

1 file changed

+19
-0
lines changed

container.if

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -87,6 +87,25 @@ interface(`container_read_state',`
8787
ps_process_pattern($1, container_runtime_t)
8888
')
8989

90+
########################################
91+
## <summary>
92+
## Write to /proc/PID of container runtime.
93+
## This is needed e.g. to set uid_map or gid_map
94+
## </summary>
95+
## <param name="domain">
96+
## <summary>
97+
## Domain allowed access.
98+
## </summary>
99+
## </param>
100+
#
101+
interface(`container_write_proc_files',`
102+
gen_require(`
103+
type container_runtime_t;
104+
')
105+
106+
allow $1 container_runtime_t:file { open write };
107+
')
108+
90109
########################################
91110
## <summary>
92111
## Search container lib directories.

0 commit comments

Comments
 (0)