241731e Add labels for crio rename

Authored and Committed by dwalsh 7 years ago
    Add labels for crio rename
    Break container_t rules out to use a separate container_domain
    Allow containers to be able to set namespaced SYCTLS
    Allow sandbox containers manage fuse files.
    Fixes to make container_runtimes work on MLS machines
    Bump version to allow handling of container_file_t filesystems
    Allow containers to mount, remount and umount container_file_t file systems
    Fixes to handle cap_userns
    Give container_t access to XFRM sockets
    Allow spc_t to dbus chat with init system
    Allow spc_t to dbus chat with init system
    Add rules to allow container runtimes to run with unconfined disabled
    Add rules to support cgroup file systems mounted into container.
    Fix typebounds entrypoint problems
    Fix typebounds problems
    Add typebounds statement for container_t from container_runtime_t
    We should only label runc not runc*
    
        
file modified
+1 -0
file modified
+21 -2
file modified
+1 -2