Skip to content

set lock permissions to /proc/meminfo for /usr/share/dotnet/dotnet #14340

Answered by imma-cx
imma-cx asked this question in Q&A
Discussion options

You must be logged in to vote

When I run the container without using udica and without container-selinux, only with container_t I get the following message.

type=AVC msg=audit(1653485153.165:992): avc: denied { write } for pid=19776 comm="dotnet" name="Scans" dev="nvme0n1p2" ino=28181155 scontext=system_u:system_r:container_t:s0:c89,c560 tcontext=system_u:object_r:user_home_t:s0 tclass=dir permissive=0

I was able to overcome the issue with the volumes mount and the port for communication with ActiveMQ by using Udica.
I'm just having issues with the 'dotnet' permission for path="/dev/zero" and path="/proc/meminfo".
Can this be done using only udica?
Or using only container-selinux?

Replies: 4 comments 8 replies

Comment options

You must be logged in to vote
2 replies
@rhatdan
Comment options

@rhatdan
Comment options

Comment options

You must be logged in to vote
2 replies
@rhatdan
Comment options

@rhatdan
Comment options

Comment options

You must be logged in to vote
4 replies
@rhatdan
Comment options

@imma-cx
Comment options

@rhatdan
Comment options

@imma-cx
Comment options

Answer selected by imma-cx
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants