When I compile and install this policy
---------------------------------------------------------------
# cat /tmp/container.te
policy_module(container, 1.0)
virt_sandbox_domain_template(container)
----------------------------------------------------------------
I end up with mknod capability.
sesearch -A -s container_t -t container_t -c capability
Found 1 semantic av rules:
allow container_t container_t : capability mknod ;
But I didn't add mknod to the policy.
grep mknod tmp/container.tmp
class capability { chown dac_override dac_read_search fowner fsetid
kill setgid setuid setpcap linux_immutable net_bind_service
net_broadcast net_admin net_raw ipc_lock ipc_owner sys_module sys_rawio
sys_chroot sys_ptrace sys_pacct sys_admin sys_boot sys_nice sys_resource
sys_time sys_tty_config mknod lease audit_write audit_control setfcap };
Any ideas?
_______________________________________________
Selinux mailing list
Selinux@xxxxxxxxxxxxx
To unsubscribe, send email to Selinux-leave@xxxxxxxxxxxxx.
To get help, send an email containing "help" to Selinux-request@xxxxxxxxxxxxx.