Skip to content

fix: allow initrc_t to relabel to userns-privileged types#1224

Merged
RoyalOughtness merged 1 commit intosecureblue:livefrom
HastD:userns-relabel-initrc
Aug 4, 2025
Merged

fix: allow initrc_t to relabel to userns-privileged types#1224
RoyalOughtness merged 1 commit intosecureblue:livefrom
HastD:userns-relabel-initrc

Conversation

@HastD
Copy link
Copy Markdown
Collaborator

@HastD HastD commented Aug 3, 2025

This is necessary, for example, to allow system services to take btrfs snapshots of the root filesystem. This shouldn't have security implications as root access is already needed to execute something as initrc_t.

This is necessary, for example, to allow system services to take btrfs
snapshots of the root filesystem. This shouldn't have security
implications as root access is already needed to execute something as
initrc_t.

Signed-off-by: Daniel Hast <[email protected]>
@HastD HastD requested a review from RoyalOughtness as a code owner August 3, 2025 23:44
@RoyalOughtness RoyalOughtness merged commit 6218cdd into secureblue:live Aug 4, 2025
18 of 19 checks passed
@HastD HastD deleted the userns-relabel-initrc branch August 4, 2025 17:32
RoyalOughtness pushed a commit to RoyalOughtness/secureblue-dev that referenced this pull request Aug 4, 2025
…#1224)

This is necessary, for example, to allow system services to take btrfs
snapshots of the root filesystem. This shouldn't have security
implications as root access is already needed to execute something as
initrc_t.

Signed-off-by: Daniel Hast <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants