Skip to content

[RFE] new package: sec-policy/selinux-container #479

@tormath1

Description

@tormath1

Current situation

For SELinux, we currently use the following policies with custom patches:

  • sec-policy/selinux-virt
  • sec-policy/selinux-unconfined
  • sec-policy/selinux-base

In the SELinux effort, it would be nice to port the following policy: https://github.com/containers/container-selinux to the OS to be aligned with an upstream reference and contribute to it.

Impact

  • no need to maintain custom patches
  • up-to-date with an official containers SELinux policy
  • contribute to the containers/container-selinux

Implementation options

It seems there is no ebuild for this policy - we could contribute to the upstream ::gentoo to provide it then add it to ::portage-stable.

Additional information

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions