diff --git a/repos/aimee-os/sec-policy/selinux-aimee-os/files/aimee-os.te b/repos/aimee-os/sec-policy/selinux-aimee-os/files/aimee-os.te index 2b7e1c0..822ecb8 100644 --- a/repos/aimee-os/sec-policy/selinux-aimee-os/files/aimee-os.te +++ b/repos/aimee-os/sec-policy/selinux-aimee-os/files/aimee-os.te @@ -238,3 +238,12 @@ gen_require(` type sysadm_t; ') init_use_fds(sysadm_t) + +# Allow podman to relabel any file (to container_file_t) +optional_policy(` + gen_require(` + type podman_t; + ') + files_relabel_non_security_dirs(podman_t) + files_relabel_non_security_files(podman_t) +')