-
Notifications
You must be signed in to change notification settings - Fork 344
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
typebounds should support specifying an attribute for the child #24
Comments
This is becoming more critical. In container-selinux I would need something like
|
In the interim, could you add something like: |
Yes except container_runtime_exec_t is defined external to the base policy. We are shipping container-selinux totally separate. |
That's why I put it in an optional? |
Right. My point was that we would need an update for both packages. Not something easily done in RHEL. But it would fix it for Fedora for now. |
At present we can only specify an individual type as the child in a typebounds statement.
This makes it difficult to specify that many types are bounded a single parent type.
Update libsepol/checkpolicy to support specifying an attribute for the child type, and either
update the policy file and kernel to also support this (i.e. new policy version) or have libsepol expand
the rules at build time.
The text was updated successfully, but these errors were encountered: