aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKenton Groombridge <concord@gentoo.org>2024-08-09 15:45:47 -0400
committerJason Zaman <perfinion@gentoo.org>2024-09-21 15:28:29 -0700
commit19a28130109650c10a226b67121d6697c2d53907 (patch)
tree3c8f0a327d8f90bbde3ffcea9a9dceb63524c1cf
parentMakefile: drop duplicate quotes (diff)
downloadhardened-refpolicy-19a28130109650c10a226b67121d6697c2d53907.tar.gz
hardened-refpolicy-19a28130109650c10a226b67121d6697c2d53907.tar.bz2
hardened-refpolicy-19a28130109650c10a226b67121d6697c2d53907.zip
testing: add container_kvm_t to net admin exempt list
Signed-off-by: Kenton Groombridge <concord@gentoo.org> Signed-off-by: Jason Zaman <perfinion@gentoo.org>
-rw-r--r--testing/sechecker.ini1
1 files changed, 1 insertions, 0 deletions
diff --git a/testing/sechecker.ini b/testing/sechecker.ini
index b873b94ec..f5f85ce3e 100644
--- a/testing/sechecker.ini
+++ b/testing/sechecker.ini
@@ -241,6 +241,7 @@ exempt_source = arpwatch_t
chronyd_t # Conditional access (chronyd_hwtimestamp)
condor_startd_t
container_engine_t
+ container_kvm_t # Modify interfaces and routes for VM networking
container_t # Conditional access (container_use_host_all_caps)
crio_t
ctdbd_t