Skip to content

Commit b7d69e4

Browse files
committed
Move /var/run fc entries to /run
/var/run is a symlink to /run in microos. Currently the selinux-policy package has a rule for file contexts from /run/<file> to use the same file context specified in /var/run/<file>. The upcoming main selinux-policy package update will change the direction of that "forwarding", so /var/run will follow the rules in /run. This way, the file context entries will match the actual filesystem path. All existing file context entries in custom modules based on the /var/run path need to change to /run, otherwise there is no rule for /var/run entries to "be forwarded to" in /run. Signed-off-by: Cathy Hu <[email protected]>
1 parent a370547 commit b7d69e4

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

policy/microos/k3s.fc

+2-2
Original file line numberDiff line numberDiff line change
@@ -23,5 +23,5 @@
2323
/var/lib/rancher/k3s/data/[^/]*/bin/runc -- gen_context(system_u:object_r:container_runtime_exec_t,s0)
2424
/var/lib/rancher/k3s/data/[^/]*/etc(/.*)? gen_context(system_u:object_r:container_config_t,s0)
2525
/var/lib/rancher/k3s/storage(/.*)? gen_context(system_u:object_r:container_file_t,s0)
26-
/var/run/k3s(/.*)? gen_context(system_u:object_r:container_var_run_t,s0)
27-
/var/run/k3s/containerd/[^/]*/sandboxes/[^/]*/shm(/.*)? gen_context(system_u:object_r:container_runtime_tmpfs_t,s0)
26+
/run/k3s(/.*)? gen_context(system_u:object_r:container_var_run_t,s0)
27+
/run/k3s/containerd/[^/]*/sandboxes/[^/]*/shm(/.*)? gen_context(system_u:object_r:container_runtime_tmpfs_t,s0)

0 commit comments

Comments
 (0)