Re: [lxc-devel] [PATCH] provide an example SELinux policy for older releases

2014-07-24 Thread Dwight Engen
On Thu, 24 Jul 2014 20:21:41 + Serge Hallyn wrote: > Quoting Dwight Engen (dwight.en...@oracle.com): > > The virtd_lxc_t type provided by the default RHEL/CentOS/Oracle 6.5 > > policy is an unconfined_domain(), so it doesn't really enforce > > anything. This change will provide a link in the

Re: [lxc-devel] [PATCH] provide an example SELinux policy for older releases

2014-07-24 Thread Serge Hallyn
Quoting Dwight Engen (dwight.en...@oracle.com): > The virtd_lxc_t type provided by the default RHEL/CentOS/Oracle 6.5 > policy is an unconfined_domain(), so it doesn't really enforce anything. > This change will provide a link in the documentation to an example > policy that does confine containers

[lxc-devel] [PATCH] provide an example SELinux policy for older releases

2014-07-24 Thread Dwight Engen
The virtd_lxc_t type provided by the default RHEL/CentOS/Oracle 6.5 policy is an unconfined_domain(), so it doesn't really enforce anything. This change will provide a link in the documentation to an example policy that does confine containers. On more recent distributions with new enough policy,