From: dE <de.techno@gmail.com>
To: selinux@tycho.nsa.gov
Subject: Re: No chance of using SELinux on rootfs without security namespace?
Date: Tue, 29 Apr 2014 09:51:06 +0530 [thread overview]
Message-ID: <535F28B2.5020803@gmail.com> (raw)
In-Reply-To: <CAB9W1A1qJqeg3x67x9te70tpEOSoQkvcFwjTzq=8dfLzeKsvew@mail.gmail.com>
On 04/28/14 19:42, Stephen Smalley wrote:
> It would be difficult at best, unless you are only using it for a
> minimalist root and everything else is on some other filesystem type.
> Without xattrs, you do not have per-file security labels and therefore
> cannot set up automatic domain transitions on any of the executables
> in that filesystem or otherwise distinguish any of those files in the
> policy. Lack of xattr support in a native Linux filesystem is a
> significant drawback these days; xattrs are used not only for SELinux
> but also for ACLs, file capabilities, and various application purposes
> (user. namespace). reiser4 isn't in mainline AFAIK.
>
> On Mon, Apr 28, 2014 at 1:06 AM, dE <de.techno@gmail.com> wrote:
>> I just realized -- my rootfs doesn't support xattr (reiser4).
>>
>> Is there any chance I can use SELinux?
>> _______________________________________________
>> Selinux mailing list
>> Selinux@tycho.nsa.gov
>> To unsubscribe, send email to Selinux-leave@tycho.nsa.gov.
>> To get help, send an email containing "help" to
>> Selinux-request@tycho.nsa.gov.
Thanks for clarifying that.
I'll try out SELinux in that fedora VM.
prev parent reply other threads:[~2014-04-29 4:23 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-04-28 8:06 No chance of using SELinux on rootfs without security namespace? dE
2014-04-28 14:12 ` Stephen Smalley
2014-04-29 4:21 ` dE [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=535F28B2.5020803@gmail.com \
--to=de.techno@gmail.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.