4f9ed7
diff -up container-selinux-2.161.1/container.te.orig container-selinux-2.161.1/container.te
4f9ed7
--- container-selinux-2.161.1/container.te.orig	2021-05-06 14:55:57.952216763 +0200
4f9ed7
+++ container-selinux-2.161.1/container.te	2021-05-06 14:56:02.027287991 +0200
4f9ed7
@@ -114,7 +114,7 @@ mls_trusted_object(container_runtime_t)
4f9ed7
 #
4f9ed7
 allow container_runtime_domain self:capability { chown kill fowner fsetid mknod net_admin net_bind_service net_raw setfcap sys_resource };
4f9ed7
 allow container_runtime_domain self:tun_socket { create_socket_perms relabelto };
4f9ed7
-allow container_runtime_domain self:lockdown { confidentiality integrity };
4f9ed7
+#allow container_runtime_domain self:lockdown { confidentiality integrity };
4f9ed7
 allow container_runtime_domain self:process ~setcurrent;
4f9ed7
 allow container_runtime_domain self:passwd rootok;
4f9ed7
 allow container_runtime_domain self:fd use;