You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
With a BTRFS filesystem, machinectl can clone a systemd-nspawn container quickly and efficiently.
It also attempts to clone and/or remove any *.nspawn configuration files in /etc/systemd/nspawn or /run/systemd/nspawn, which fails with the current F40 selinux-policy.
The audit2allow rules suggest allowing the systemd_machined_t source context edit access to the etc_t target type. This is not really what we should do.
Requesting that a new type systemd_nspawn_conf_t be created for /etc/systemd/nspwan and /run/systemd/nspawn. Then systemd_machined_t can be allowed to manage those spaces with the appropriate interfaces.
The text was updated successfully, but these errors were encountered:
amessina
changed the title
Allow systemd's machinectl to clone and/or remove systemd-nspawn/brfs instances in /var/lib/machines
Allow systemd's machinectl to clone and/or remove systemd-nspawn/btrfs instances in /var/lib/machines
Jun 21, 2024
With a BTRFS filesystem, machinectl can clone a systemd-nspawn container quickly and efficiently.
It also attempts to clone and/or remove any *.nspawn configuration files in /etc/systemd/nspawn or /run/systemd/nspawn, which fails with the current F40 selinux-policy.
The audit2allow rules suggest allowing the systemd_machined_t source context edit access to the etc_t target type. This is not really what we should do.
Requesting that a new type
systemd_nspawn_conf_t
be created for /etc/systemd/nspwan and /run/systemd/nspawn. Then systemd_machined_t can be allowed to manage those spaces with the appropriate interfaces.The text was updated successfully, but these errors were encountered: