Daniel J Walsh
Daniel J Walsh
If we can get someone to mentor, this seems like a great GSoC project (Not me, I don't rust. :^)
How can I do (roleallow unconfined_r container_user_r) Using traditional container.te rules?
What version of podman are you attempting this with?
Could you try again to make sure it is 4.7.2 or better yet 4.8.*
What are the latest AVC messages you are seeing?
Dontaudit rules are hiding the denial. sudo semodule -DB Now you should see the AVCs sudo semodule -B To run the dontaudit rules back on.
Interested in opening a PR for this?
I am fine with this, but we need community to work on it. If you want to implement this and it is simply a CLI change, I would be all...
Yes it is planned for the future.