3 ms·
SELinux is pretty inflexible and incompatible with multi-user systems that deploy stuff without privileges - it assumes you can have global policy that applies
by catern 5y ago
SELinux is pretty inflexible and incompatible with multi-user systems that deploy stuff without privileges - it assumes you can have global policy that applies to everything, which doesn't work well with containers, or browsers, or even just running things out of your home directory.
Hence, kernel devs would like to increase adoption of something that's a little better designed - not SELinux.
- totony 5y ago>SELinux is pretty inflexible and incompatible with multi-user systems that deploy stuff without privileges IMO that's not true -- Android has done a pretty good job at it.