fix(profile): modernise fuse-overlayfs.

fix  #726
This commit is contained in:
Alexandre Pujol 2025-05-01 20:15:24 +02:00
parent 5edde91d44
commit 87e82b1505
No known key found for this signature in database
GPG key ID: C5469996F0DF68EC

View file

@ -10,14 +10,21 @@ include <tunables/global>
profile fuse-overlayfs @{exec_path} {
include <abstractions/base>
capability sys_admin,
capability chown,
capability dac_override,
capability dac_read_search,
capability chown,
capability fowner,
capability setfcap,
capability setuid,
capability sys_admin,
mount fstype=fuse.* options=(rw,nodev,noatime) @{user_share_dirs}/containers/storage/overlay/**/merged/ -> **,
mount fstype=fuse.overlayfs options=(rw,nodev,noatime) fuse-overlayfs -> @{user_share_dirs}/containers/storage/overlay/**/merged/,
@{exec_path} mr,
mount fstype=fuse.* options=(rw,nodev,noatime) @{user_share_dirs}/containers/storage/overlay/**/merged/ -> **,
@{bin}/mount rix,
@{bin}/umount rix,
owner @{user_share_dirs}/containers/storage/overlay/{,**} rwl,