selinux/kernel
Ondrej Mosnacek 08dcaa3534 kernel/selinux-testsuite: patch the policy for restraint
When this test in run via restraint (e.g. on Beaker), it inherits some
file descriptors originating from it, labeled unconfined_service_t. This
leads to a huge amount of denials when test programs are exectuted.

To work around this, add a rule to the policy that allows the test
domains to inherit these descriptors from unconfined_service_t.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2021-09-22 22:41:55 +02:00
..
avc_tracepoint kernel/avc_tracepoint: disable restraint's AVC check 2021-04-29 08:14:28 +02:00
genfs_fallback Fix invalid FMF syntax 2021-04-06 15:25:20 +02:00
labeled-cephfs Make all relevancy expressions use comparison operators 2020-12-15 12:38:32 +01:00
netlabel_many_ifaces kernel/netlabel_many_ifaces: fix relevancy for RHEL 2021-04-16 20:51:37 +02:00
selinux-testsuite kernel/selinux-testsuite: patch the policy for restraint 2021-09-22 22:41:55 +02:00
setsebool-deadlock Fix invalid FMF syntax 2021-04-06 15:25:20 +02:00
synflood kernel/synflood: disable on s390x 2021-02-24 16:39:59 +01:00
wrong-rules-after-setsebool Add a minimal test for the recent setsebool kernel regression 2021-04-27 11:00:42 +02:00