diff --git a/cils/comiclib.cil b/cils/comiclib.cil index 7863747..e2ead8d 100644 --- a/cils/comiclib.cil +++ b/cils/comiclib.cil @@ -1,7 +1,8 @@ (block comiclib (blockinherit container) - (allow process user_home_t ( dir ( watch getattr ioctl lock open read search ))) (allow process user_home_t ( file ( watch getattr ioctl lock open read ))) + + (dontaudit process node_t ( tcp_socket ( node_bind ) ) ) ) diff --git a/cils/container_wireguard.cil b/cils/container_wireguard.cil index b9c6e00..ca18544 100644 --- a/cils/container_wireguard.cil +++ b/cils/container_wireguard.cil @@ -4,4 +4,5 @@ (allow process container_wireguard.process ( netlink_route_socket ( nlmsg_write ))) + (dontaudit process cgroup_t (dir (write) )) )