blob: 1eaf9ef5846b03dbd0b7bc3948a85bb7a1934e04 [file] [log] [blame]
Bjoern Johanssonca5bfb12018-03-19 11:14:30 -07001# Network namespace creation
2type createns, domain;
3type createns_exec, exec_type, vendor_file_type, file_type;
4
5init_daemon_domain(createns)
6
7allow createns self:capability { sys_admin net_raw setuid setgid };
8allow createns varrun_file:dir { add_name search write };
9allow createns varrun_file:file { create mounton open read write };
10
11#Allow createns itself to be run by init in its own domain
12domain_auto_trans(goldfish_setup, createns_exec, createns);
13allow createns goldfish_setup:fd use;
14