-
Notifications
You must be signed in to change notification settings - Fork 48
Open
Labels
area/selinuxIssues related to SELinuxIssues related to SELinuxarea/sysextsysext roadmapsysext roadmap
Description
The build_sysext tool is now used for the OEM and in the future the internal Docker/containerd systemd-sysext image.
For Docker and containerd we need to make sure that the files are correctly labeled for SELinux to work in enforcing mode.
There were attempts to do this with the torcx tar ball but they failed.
Note that the /usr image is also not completely labeled yet https://github.com/flatcar/scripts/blob/1f1a53140cf7b3cbb4d3e8961bce7a44af295ce4/build_library/build_image_util.sh#L775 and that enforcing mode is not expected to work until we update the policy and debug any remaining issues.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
area/selinuxIssues related to SELinuxIssues related to SELinuxarea/sysextsysext roadmapsysext roadmap
Type
Projects
Status
🪵Backlog