3 ms·
You can boot a system with a btrfs root file system without having the btrfs-progs installed. Good luck trying to use SELinux without having the policy install
by tytso 5y ago
You can boot a system with a btrfs root file system without having the btrfs-progs installed.
Good luck trying to use SELinux without having the policy installed; it's guaranteed to be non-functional. And given that the SELinux policy is distro-speicific, it's not like you can take a random Linux distribution, and enable SELinux and expect it to work. You enable SELinux on the boot command-line, but without the policy installed, it will be dead in the water. And configuring the SELinux policy is extremely non-trivial. It's several orders of magnitude more challenging than running, say, "mkfs.btrfs".
>That is exactly operating system does, which is the topic of discussion. Linux >OSs such as RHEL as an example.
If that's your definition of an OS, then there are plenty of Linux distributions --- aka, an "OS" by your definition --- that do *NOT* have SELinux built in, because they don't have an SELinux policy defined that will work with that distribution's system daemons.
Therefore, by your definition SELinux is not "built in" to all versions of Linux (specifically, "distributions"). Q.E.D.
- YATA0 5y ago>You can boot a system with a btrfs root file system without having the btrfs-progs installed. Wrong again! You can actually have Linux systems that do not support booting from btrfs, but have btrfs-progs installed. Or systems that have neither. >Good luck trying to use SELinux without having the policy installed They are installed and included in the Linux operating systems used by the US government, as I stated above. This is a non-point. > And given that the SELinux policy is distro-speicific, it's not like you can take a random Linux distribution, and enable SELinux and expect it to work. Wow, it's almost like it be nice if there were standards used by the government and other organizations looking to secure their operating systems. Maybe they can form an agency, I'll call it the Defense Information Systems Agency. They can make standards that secure and lockdown systems, and make sure SELinux is configured properly... We'll call these Security Technical Implementation Guides, STIGs for shor... Oh wait... > And configuring the SELinux policy is extremely non-trivial. It's several orders of magnitude more challenging than running, say, "mkfs.btrfs". Immaterial to the matter at hand. >If that's your definition of an OS A distribution is an operating system by definition. It's not my definition, it's the definition[0]. >that do NOT have SELinux built in, because they don't have an SELinux policy defined that will work with that distribution's system daemons. Still "built-in" to Linux. Whether or not it's enabled or complied in is an implementation detail, but it's still "built-in" to Linux operating systems, most definitely those used by the government for secure systems, which was the original point. Thanks for proving my point, Q.E.D. >Therefore, by your definition SELinux is not "built in" to all versions of Linux Using your illogic, there are BSDs that send your password through plaintext over the wire because they only have rlogin. They don't have SSH "built-in". SELinux is absolutely "built-in" to the Linux kernel and operating systems. Whether or not specific implementations of Linux have it compiled and enabled is besides the fact that it is built-in, not third-party. You're fractally wrong again. Take the L and stop while you're this far behind. [0] https://en.m.wikipedia.org/wiki/Linux_distribution https://en.m.wikipedia.org/wiki/Linux_distribution