Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-34205

Unknown toplevel directories are labeled default_t

    • sst_bootc
    • False
    • Hide

      None

      Show
      None

      Creating arbitrary new toplevel directories (e.g. `/app` or `aimodel`) will result in the default SELinux label `default_t`. Most domains are denied access to this.

      We should either:

      • Change the SELinux policy to make the generic fallback case be usr_t
      • We could do just this in the bootc container stack (perhaps preferable to start); but implementing that is a bit ugly

            walters@redhat.com Colin Walters
            walters@redhat.com Colin Walters
            Colin Walters Colin Walters
            Wei Shi Wei Shi
            Gabriela Necasova Gabriela Necasova
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated: