commit: 9a6e04ea1f7da6812ea463bd509862a77f0da623
Author: Kenton Groombridge <me <AT> concord <DOT> sh>
AuthorDate: Sun Jan 30 23:09:12 2022 +0000
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
CommitDate: Mon Jan 31 17:55:20 2022 +0000
URL:
https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=9a6e04ea
docker: add missing call to init_daemon_domain()
Signed-off-by: Kenton Groombridge <me <AT> concord.sh>
Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org>
policy/modules/services/docker.te | 1 +
1 file changed, 1 insertion(+)
diff --git a/policy/modules/services/docker.te
b/policy/modules/services/docker.te
index bb5eeb49..7a657e15 100644
--- a/policy/modules/services/docker.te
+++ b/policy/modules/services/docker.te
@@ -10,6 +10,7 @@ container_system_engine(dockerd_t)
type dockerd_exec_t;
container_engine_executable_file(dockerd_exec_t)
application_domain(dockerd_t, dockerd_exec_t)
+init_daemon_domain(dockerd_t, dockerd_exec_t)
ifdef(`enable_mls',`
init_ranged_daemon_domain(dockerd_t, dockerd_exec_t, s0 -
mls_systemhigh)
')