Drop `CAP_MAC_ADMIN` from the default capabilities which is needed to write and read(!) unknown SELinux labels. Adjust the stages that need to read or write SELinux labels accordingly. |
||
|---|---|---|
| .. | ||
| org.osbuild.error | ||
| org.osbuild.noop | ||
| org.osbuild.oci-archive | ||
| org.osbuild.ostree.commit | ||
| org.osbuild.qemu | ||
| org.osbuild.rawfs | ||
| org.osbuild.tar | ||