rancher / rke2-selinux

RKE2 selinux + RPM packaging for selinux
Apache License 2.0
21 stars 21 forks source link

el7: restorecon on containerd binaries in /usr/local/bin/ does not set them to container_runtime_exec_t #22

Open dweomer opened 3 years ago

dweomer commented 3 years ago

Because container-selinux in el7 is ancient we should add these fcontext entries:

$ restorecon -Frv /usr/local/bin # centos/7
node-1: restorecon reset /usr/local/bin/containerd-shim-runc-v1 context unconfined_u:object_r:bin_t:s0->system_u:object_r:bin_t:s0
node-1: restorecon reset /usr/local/bin/containerd-shim-runc-v2 context unconfined_u:object_r:bin_t:s0->system_u:object_r:bin_t:s0
node-1: restorecon reset /usr/local/bin/containerd-shim context unconfined_u:object_r:bin_t:s0->system_u:object_r:bin_t:s0
node-1: restorecon reset /usr/local/bin/ctr context unconfined_u:object_r:bin_t:s0->system_u:object_r:bin_t:s0
node-1: restorecon reset /usr/local/bin/containerd context unconfined_u:object_r:bin_t:s0->system_u:object_r:bin_t:s0