Skip to content

Commit 21972d6

Browse files
authored
Update ee-logrotate.te
1 parent 291677d commit 21972d6

File tree

1 file changed

+2
-6
lines changed

1 file changed

+2
-6
lines changed

logrotate/selinux-policy/ee-logrotate.te

Lines changed: 2 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -4,16 +4,12 @@ require {
44
type logrotate_t;
55
type container_runtime_exec_t;
66
type usr_t;
7-
class file { read open getattr append execute execute_no_trans };
7+
class file { read open getattr append execute execute_no_trans map };
88
}
99

1010
#============= logrotate_t ==============
1111

12-
# 1. Quyền đọc docker inspect
1312
allow logrotate_t container_runtime_exec_t:file { read open getattr };
14-
15-
# 2. Quyền thực thi docker compose
1613
allow logrotate_t container_runtime_exec_t:file { execute execute_no_trans };
17-
18-
# 3. Quyền ghi append vào log file (giữ nguyên usr_t)
14+
allow logrotate_t container_runtime_exec_t:file map;
1915
allow logrotate_t usr_t:file append;

0 commit comments

Comments
 (0)