4 ms·
Exactly. If you isolate this as an programmer's concern then you can skip the administrative effort and assume that the application configures itself properly r
by batou 11y ago
Exactly. If you isolate this as an programmer's concern then you can skip the administrative effort and assume that the application configures itself properly rather than relies on someone to experiment with producing a sandbox for it to run in. The latter is error prone hence why things like SELinux have permissive and enforcing modes. SELinux turns your job into a reverse engineering one which isn't fun.
I'm slightly bitter that I've become a bit of an SELinux expert over the years. I shouldn't have to be one, hell the tech shouldn't even need to exist in 2015.