| Commit message (Expand) | Author | Age | Files | Lines |
* | container: allow reading generic certs | Kenton Groombridge | 2024-09-21 | 1 | -0/+1 |
* | various: rules required for DV manipulation in kubevirt | Kenton Groombridge | 2024-09-21 | 1 | -0/+3 |
* | container: add container_kvm_t and supporting kubevirt rules | Kenton Groombridge | 2024-09-21 | 1 | -1/+33 |
* | container: allow spc various rules for kubevirt | Kenton Groombridge | 2024-09-21 | 1 | -2/+11 |
* | container, kubernetes: add supporting rules for kubevirt and multus | Kenton Groombridge | 2024-09-21 | 1 | -0/+9 |
* | container: allow super privileged containers to manage BPF dirs | Kenton Groombridge | 2024-09-21 | 1 | -1/+1 |
* | container: allow containers to execute tmpfs files | Kenton Groombridge | 2024-09-21 | 1 | -0/+1 |
* | Reorder perms and classes | freedom1b2830 | 2024-09-21 | 1 | -18/+18 |
* | container, crio, kubernetes: minor fixes | Kenton Groombridge | 2024-05-14 | 1 | -0/+1 |
* | container: allow containers to getcap | Kenton Groombridge | 2024-05-14 | 1 | -1/+1 |
* | container: allow system container engines to mmap runtime files | Kenton Groombridge | 2024-05-14 | 1 | -1/+1 |
* | Container: Minor fixes from interactive container use. | Chris PeBenito | 2024-03-01 | 1 | -1/+6 |
* | container: allow spc to map kubernetes runtime files | Kenton Groombridge | 2024-03-01 | 1 | -0/+1 |
* | container, kubernetes: allow kubernetes to use fuse-overlayfs | Kenton Groombridge | 2024-03-01 | 1 | -0/+2 |
* | container, kubernetes: add support for rook-ceph | Kenton Groombridge | 2024-03-01 | 1 | -3/+55 |
* | container, kubernetes: add support for cilium | Kenton Groombridge | 2024-03-01 | 1 | -2/+29 |
* | container: various fixes | Kenton Groombridge | 2024-03-01 | 1 | -1/+15 |
* | container: allow watching FUSEFS dirs and files | Kenton Groombridge | 2024-03-01 | 1 | -0/+2 |
* | container: rework capabilities | Kenton Groombridge | 2023-10-06 | 1 | -4/+84 |
* | container: fix cilium denial | Mathieu Tortuyaux | 2023-10-06 | 1 | -0/+1 |
* | container: fixes for podman run --log-driver=passthrough | Kenton Groombridge | 2023-03-31 | 1 | -0/+3 |
* | container: fixes for podman 4.4.0 | Kenton Groombridge | 2023-03-31 | 1 | -0/+7 |
* | container: Allow user namespace creation for all container engines. | Chris PeBenito | 2023-03-31 | 1 | -0/+1 |
* | container: add missing filetrans and filecon for containerd/docker | Kenton Groombridge | 2023-02-13 | 1 | -1/+1 |
* | container: add rules required for metallb BGP speakers | Kenton Groombridge | 2022-12-13 | 1 | -0/+4 |
* | container: add tunable to allow spc to use tun-tap devices | Kenton Groombridge | 2022-12-13 | 1 | -0/+11 |
* | container, miscfiles: transition to s0 for public content created by containers | Kenton Groombridge | 2022-12-13 | 1 | -0/+4 |
* | various: allow using glusterfs as backing storage for k8s | Kenton Groombridge | 2022-12-13 | 1 | -2/+7 |
* | container, kubernetes: add rules for device plugins running as spc | Kenton Groombridge | 2022-12-13 | 1 | -1/+5 |
* | container: add tunable to use dri devices | Kenton Groombridge | 2022-12-13 | 1 | -3/+14 |
* | container, kubernetes: add private type for generic container devices | Kenton Groombridge | 2022-12-13 | 1 | -0/+5 |
* | container: add tunable to allow containers to use huge pages | Kenton Groombridge | 2022-12-13 | 1 | -0/+11 |
* | container, kernel: add tunable to allow spc to create NFS servers | Kenton Groombridge | 2022-12-13 | 1 | -0/+19 |
* | various: fixes for kubernetes | Kenton Groombridge | 2022-12-13 | 1 | -14/+65 |
* | various: fixes for kubernetes | Kenton Groombridge | 2022-12-13 | 1 | -1/+73 |
* | container: add type for container plugins | Kenton Groombridge | 2022-12-13 | 1 | -0/+6 |
* | container: Add missing UDP node bind access on container engines. | Chris PeBenito | 2022-12-13 | 1 | -0/+1 |
* | container: Boolean for ecryptfs | Pat Riehecky | 2022-09-03 | 1 | -0/+14 |
* | container: Getattr generic device nodes. | Chris PeBenito | 2022-09-03 | 1 | -0/+2 |
* | container: Allow container engines to connect to http cache ports. | Chris PeBenito | 2022-09-03 | 1 | -0/+1 |
* | container, docker: Fixes for containerd and kubernetes testing. | Chris PeBenito | 2022-09-03 | 1 | -0/+3 |
* | container: add separate type for container engine units | Kenton Groombridge | 2022-09-03 | 1 | -0/+3 |
* | container: allow container engines to manage tmp symlinks | Kenton Groombridge | 2022-09-03 | 1 | -0/+2 |
* | container: allow containers to manipulate own fds | Kenton Groombridge | 2022-09-03 | 1 | -0/+3 |
* | container: also allow containers to watch public content | Kenton Groombridge | 2022-09-03 | 1 | -0/+2 |
* | container: add missing capabilities | Kenton Groombridge | 2022-04-09 | 1 | -2/+2 |
* | container: add tunables to allow containers to access public content | Kenton Groombridge | 2022-04-09 | 1 | -0/+30 |
* | container: allow generic containers to read the vm_overcommit sysctl | Kenton Groombridge | 2022-04-09 | 1 | -0/+2 |
* | container, podman: allow containers to interact with conmon | Kenton Groombridge | 2022-04-09 | 1 | -0/+5 |
* | container: allow containers to getsession | Kenton Groombridge | 2022-01-29 | 1 | -1/+1 |