We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 291677d commit 21972d6Copy full SHA for 21972d6
logrotate/selinux-policy/ee-logrotate.te
@@ -4,16 +4,12 @@ require {
4
type logrotate_t;
5
type container_runtime_exec_t;
6
type usr_t;
7
- class file { read open getattr append execute execute_no_trans };
+ class file { read open getattr append execute execute_no_trans map };
8
}
9
10
#============= logrotate_t ==============
11
12
-# 1. Quyền đọc docker inspect
13
allow logrotate_t container_runtime_exec_t:file { read open getattr };
14
-
15
-# 2. Quyền thực thi docker compose
16
allow logrotate_t container_runtime_exec_t:file { execute execute_no_trans };
17
18
-# 3. Quyền ghi append vào log file (giữ nguyên usr_t)
+allow logrotate_t container_runtime_exec_t:file map;
19
allow logrotate_t usr_t:file append;
0 commit comments