Quoting Daniel J Walsh (dwalsh at redhat.com): > Interesting idea, although I have never used containers. > > Rather then specifying unconfined_t and staff_t I think it would be > better to define an attribute Thanks Dan, I'll apply these and test in the next few days. -serge