Skip to content

Commit

Permalink
Merge pull request #38 from andypitcher/expand-watch-permission
Browse files Browse the repository at this point in the history
Add file watch permission from rke_logreader_t to container_var_lib_t
  • Loading branch information
andypitcher authored Dec 19, 2023
2 parents 4b6a0f4 + 7b54f40 commit 1946e04
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 2 deletions.
2 changes: 1 addition & 1 deletion policy/centos8/rancher.te
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ allow rke_logreader_t container_log_t:dir { open read search };
allow rke_logreader_t container_log_t:lnk_file { getattr read };
allow rke_logreader_t container_log_t:file { getattr open read watch };
allow rke_logreader_t container_var_lib_t:dir search;
allow rke_logreader_t container_var_lib_t:file { getattr open read };
allow rke_logreader_t container_var_lib_t:file { getattr open read watch };
allow rke_logreader_t container_var_lib_t:lnk_file { getattr read };
allow rke_logreader_t syslogd_var_run_t:dir read;
allow rke_logreader_t syslogd_var_run_t:file { getattr map open read };
Expand Down
2 changes: 1 addition & 1 deletion policy/centos9/rancher.te
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ allow rke_logreader_t container_log_t:dir { open read search };
allow rke_logreader_t container_log_t:lnk_file { getattr read };
allow rke_logreader_t container_log_t:file { getattr open read watch };
allow rke_logreader_t container_var_lib_t:dir search;
allow rke_logreader_t container_var_lib_t:file { getattr open read };
allow rke_logreader_t container_var_lib_t:file { getattr open read watch };
allow rke_logreader_t container_var_lib_t:lnk_file { getattr read };
allow rke_logreader_t syslogd_var_run_t:dir read;
allow rke_logreader_t syslogd_var_run_t:file { getattr map open read };
Expand Down

0 comments on commit 1946e04

Please sign in to comment.