All of lore.kernel.org
 help / color / mirror / Atom feed
* SELinux and systemd integration
@ 2023-06-14 19:33 Paul Moore
  2023-06-16  5:43 ` Petr Lautrbach
  0 siblings, 1 reply; 5+ messages in thread
From: Paul Moore @ 2023-06-14 19:33 UTC (permalink / raw)
  To: Christian Göttsche, selinux, selinux-refpolicy; +Cc: Lennart Poettering

Hello all,

Amongst Christian's various other SELinux contributions, over the past
several years Christian has been working on improving the SELinux
integration in systemd.  One of the things that Christian has been
working on is revamping the SELinux permissions that systemd uses for
unitfile operations, both to resolve problems and generally improve
the mapping of permissions to systemd operations.  As this work has
been languishing for several years, I would like to see if we can get
things "unstuck" by proposing two things:

1. I've provided links to the systemd GH PRs below, but I think it
might be helpful if Christian could provide a quick summary of the new
permissions, how they map to systemd operations, and how they map to
the existing SELinux/systemd permissions with a focus on helping
policy developers migrate existing SELinux policies.

2. Given the significance of systemd to modern Linux distributions, I
think it might be a good idea if we selected a SELinux "liaison" for
the systemd project.  This person, or group of people, would work with
the systemd folks to keep the SELinux integration in good working
order, review systemd code as necessary, and help represent the
SELinux project within systemd.

How does that sound to everyone?  If we are in agreement on #2, and
assuming he would be willing to help out, I would like to nominate
Christian as our SELinux liaison to systemd; any objections?  Anyone
else interested in helping out?

For reference, Christian's systemd PRs on GH:
* https://github.com/systemd/systemd/pull/10023
* https://github.com/systemd/systemd/pull/20387

--
paul-moore.com

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2023-06-19 21:58 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-06-14 19:33 SELinux and systemd integration Paul Moore
2023-06-16  5:43 ` Petr Lautrbach
2023-06-17 18:08   ` Christian Göttsche
2023-06-19 21:58     ` Paul Moore
2023-06-19 21:54   ` Paul Moore

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.