diff --git a/repos/aimee-os/sec-policy/selinux-aimee-os/files/aimee-os.te b/repos/aimee-os/sec-policy/selinux-aimee-os/files/aimee-os.te index 23f47a5..abe887b 100644 --- a/repos/aimee-os/sec-policy/selinux-aimee-os/files/aimee-os.te +++ b/repos/aimee-os/sec-policy/selinux-aimee-os/files/aimee-os.te @@ -247,3 +247,13 @@ optional_policy(` files_relabel_non_security_dirs(podman_t) files_relabel_non_security_files(podman_t) ') + +# Allow podman to mount /dev/log in containers +optional_policy(` + gen_require(` + type podman_t, container_t; + type devlog_t; + ') + allow podman_t devlog_t:sock_file mounton; + logging_send_syslog_msg(container_t) +')