Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[RFE] new package: sec-policy/selinux-container #479

Closed
tormath1 opened this issue Aug 12, 2021 · 2 comments · Fixed by flatcar/scripts#917 · May be fixed by flatcar-archive/coreos-overlay#1993
Closed

[RFE] new package: sec-policy/selinux-container #479

tormath1 opened this issue Aug 12, 2021 · 2 comments · Fixed by flatcar/scripts#917 · May be fixed by flatcar-archive/coreos-overlay#1993
Labels
area/selinux Issues related to SELinux kind/feature A feature request

Comments

@tormath1
Copy link
Contributor

tormath1 commented Aug 12, 2021

Current situation

For SELinux, we currently use the following policies with custom patches:

  • sec-policy/selinux-virt
  • sec-policy/selinux-unconfined
  • sec-policy/selinux-base

In the SELinux effort, it would be nice to port the following policy: https://github.com/containers/container-selinux to the OS to be aligned with an upstream reference and contribute to it.

Impact

  • no need to maintain custom patches
  • up-to-date with an official containers SELinux policy
  • contribute to the containers/container-selinux

Implementation options

It seems there is no ebuild for this policy - we could contribute to the upstream ::gentoo to provide it then add it to ::portage-stable.

Additional information

@tormath1
Copy link
Contributor Author

containers SELinux module has been added to refpolicy.

@tormath1 tormath1 changed the title [RFE] new package: sec-policy/selinux-containers [RFE] new package: sec-policy/selinux-container Jan 31, 2022
@tormath1 tormath1 added the area/selinux Issues related to SELinux label Mar 29, 2022
@tormath1
Copy link
Contributor Author

sec-policy/selinux-container has been added upstream: https://github.com/gentoo/gentoo/tree/master/sec-policy/selinux-container

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/selinux Issues related to SELinux kind/feature A feature request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant