Skip to content

Commit 7e20e1c

Browse files
authored
Merge pull request #7 from superseb/rke1_oel_tcp_accept
Add tcp_socket accept for Oracle Linux
2 parents 7f7157f + ba1f8f7 commit 7e20e1c

2 files changed

Lines changed: 2 additions & 2 deletions

File tree

policy/centos7/rancher.te

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ manage_dirs_pattern(rke_container_t, container_var_lib_t, container_var_lib_t)
6060
manage_files_pattern(rke_container_t, container_var_lib_t, container_var_lib_t)
6161
manage_dirs_pattern(rke_container_t, container_var_run_t, container_var_run_t)
6262
manage_files_pattern(rke_container_t, container_var_run_t, container_var_run_t)
63-
allow rke_container_t self:tcp_socket listen;
63+
allow rke_container_t self:tcp_socket { accept listen };
6464
allow rke_container_t container_var_lib_t:dir { relabelfrom relabelto };
6565
allow rke_container_t container_var_lib_t:file { relabelfrom relabelto };
6666
allow rke_container_t rke_opt_t:dir { relabelfrom relabelto };

policy/centos8/rancher.te

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ manage_dirs_pattern(rke_container_t, container_var_lib_t, container_var_lib_t)
5858
manage_files_pattern(rke_container_t, container_var_lib_t, container_var_lib_t)
5959
manage_dirs_pattern(rke_container_t, container_var_run_t, container_var_run_t)
6060
manage_files_pattern(rke_container_t, container_var_run_t, container_var_run_t)
61-
allow rke_container_t self:tcp_socket listen;
61+
allow rke_container_t self:tcp_socket { accept listen };
6262
allow rke_container_t container_var_lib_t:file map;
6363
allow rke_container_t rke_opt_t:file map;
6464
allow rke_container_t container_var_lib_t:dir { relabelfrom relabelto };

0 commit comments

Comments
 (0)