Skip to content

Commit 1f16bed

Browse files
RoyalOughtnesssecureblue-bot
authored andcommitted
fix: remove other container-selinux refs (#26)
1 parent f56dabd commit 1f16bed

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

cil/userns_deny_unconfined_relabels.cil

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
;; SPDX-License-Identifier: Apache-2.0 OR MIT
44

55
(typeattribute userns_privileged_file_type)
6-
(typeattributeset userns_privileged_file_type (colord_exec_t devicekit_power_exec_t docker_exec_t file_manager_exec_type flatpak_exec_t kubelet_exec_t systemsettings_exec_t trivalent_exec_t trivalent_script_exec_t))
6+
(typeattributeset userns_privileged_file_type (colord_exec_t devicekit_power_exec_t file_manager_exec_type flatpak_exec_t systemsettings_exec_t trivalent_exec_t trivalent_script_exec_t))
77

88
(typeattribute userns_relabel_allowed)
99
(typeattributeset userns_relabel_allowed (init_t initrc_t install_t kernel_t))
@@ -16,4 +16,4 @@
1616
(deny userns_relabel_restricted userns_privileged_file_type (dir (relabelfrom relabelto)))
1717
(deny userns_relabel_restricted userns_privileged_file_type (fifo_file (relabelfrom relabelto)))
1818
(deny userns_relabel_restricted userns_privileged_file_type (file (relabelfrom relabelto)))
19-
(deny userns_relabel_restricted userns_privileged_file_type (lnk_file (relabelfrom relabelto)))
19+
(deny userns_relabel_restricted userns_privileged_file_type (lnk_file (relabelfrom relabelto)))

0 commit comments

Comments
 (0)