Re: container and staff_t
Kenton Groombridge <[email protected]> Sat, 30 Aug 2025 14:22:24 -0400
| Newsgroups | org.kernel.vger.selinux-refpolicy |
|---|---|
| Message-ID | <x7p6j522rntl7xqdtosjefb2amgjbi3yyzuvqty4mdalye33pq@a5jwkoyyuryh> |
On 25/08/29 08:20PM, Russell Coker wrote: > grep -R container_user_role policy/ > policy/modules/roles/staff.te: container_user_role(staff, staff_t, > staff_application_exec_domain, staff_r) > policy/modules/services/container.if:template(`container_user_role',` > > Why is staff_t the only domain for container_user_role() ? > When the container policy was originally written, it was only tested with staff_t and unconfined_t at the time. The other roles (mostly user_t) should probably also be allowed to use it but I would personally rather it be a tunable for each given the amount of attack surface that unprivilged containers can still expose. If we did that, staff_t should probably be tunable as well. --- Kenton Groombridge
signature.asc
(application/pgp-signature, 963 B)
-----BEGIN PGP SIGNATURE----- iQKTBAABCgB9FiEEP+u3AkfbrORB/inCFt7v5V9Ft54FAmizQVtfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDNG RUJCNzAyNDdEQkFDRTQ0MUZFMjlDMjE2REVFRkU1NUY0NUI3OUUACgkQFt7v5V9F t578lg//WdyreiZJTiXvDJEIk20Kd62H68pSiEAM1pzV1x9xGNbil1q3KF1NH5zR sYVU1K8L39dat5NmJul+l4foSFGsozO6jIR3xNw/W3s7ZNiqI4zjE61GrKy6awec RUHL86lYpP+CiEU06LnGYZs5FOQjo1j6GDyccvER7TNRExxsnDbMf08Qr2gikmdQ 6SeFx1gxOxA5Ejxd2SZh7J4ZqlHpHmg8n0PQGO/x5owxlJE7ci2biVS3f8WnuP/W oozbY0fAI2mUogTX4C5TtHvQJl63ofJ7Dtl4scqWA+lFgIa5KhhJp4VRawzz6cJx PGnyNxLJo9ccbNh4E3EimoYPsRuDLe9tpp7i25Py6gPq0BHRcMQK9LI/1dFvy9Zd +APa34uaO19A7KxYvJ8c4ypSQWo+1xyi3MRlHCOlU0/gMj/CE2vx+fvqLkptmU99 qJfdlD9123Igftg2FKpE+L+wGGMWbZ6DkmVrLkwqoIePYfoOUV70IOgnyszn55m7 S6CLCnUrcfe0W960xBX/Nx1Qa31j6qb6Qjo8YH5yVLSLITHU0pHrJPtbB/or0xWb D63N7rPSwVNJaubjbhFq/Cia/7CbMi29D3a0n5J6cp1V1hatEaX/+Sz4P1/3Ua48 yoEHdOmQPWJSDisyuMZztqy3YXi/A92TzznuKfDGi5rzLF1rzA0= =Jnox -----END PGP SIGNATURE-----