Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Posted Feb 26, 2020 23:54 UTC (Wed) by TheJH (subscriber, #101155)In reply to: Impedance matching for BPF and LSM by Cyberax
Parent article: Impedance matching for BPF and LSM
Posted Feb 26, 2020 23:55 UTC (Wed)
by Cyberax (✭ supporter ✭, #52523)
[Link] (17 responses)
Posted Feb 27, 2020 5:11 UTC (Thu)
by re:fi.64 (subscriber, #132628)
[Link]
Even then, RHEL uses SELinux by default and has widespread use in enterprise.
Posted Feb 27, 2020 10:47 UTC (Thu)
by beagnach (guest, #32987)
[Link] (15 responses)
Posted Feb 27, 2020 18:01 UTC (Thu)
by Cyberax (✭ supporter ✭, #52523)
[Link] (14 responses)
So as a result, Android now looks almost nothing like Unix.
Posted Feb 27, 2020 18:20 UTC (Thu)
by rahulsundaram (subscriber, #21946)
[Link] (12 responses)
You would have to discount Android, Chrome OS, RHEL/CentOS, Fedora, CoreOS and several others
There are more mobile/tablet/chromebook users using their devices for all sorts of things. I think that would qualify as general purpose anyway
Posted Feb 27, 2020 19:33 UTC (Thu)
by Cyberax (✭ supporter ✭, #52523)
[Link] (11 responses)
Posted Feb 27, 2020 19:50 UTC (Thu)
by pizza (subscriber, #46)
[Link] (3 responses)
(If anything, "general purpose UNIX-like Linux" is the actual niche use case these days..)
Posted Feb 27, 2020 19:53 UTC (Thu)
by Cyberax (✭ supporter ✭, #52523)
[Link] (2 responses)
It's no wonder that SELinux can work within these environments.
SELinux still fails within environments that require flexibility or extensibility.
Posted Feb 29, 2020 12:31 UTC (Sat)
by cpitrat (subscriber, #116459)
[Link]
Posted Feb 29, 2020 20:45 UTC (Sat)
by zlynx (guest, #2285)
[Link]
Only with administrators who can't be bothered to learn how it works.
This reminds me of PHP web developers who can't be bothered to learn Unix file permissions and mark everything chmod 777.
Posted Feb 27, 2020 20:13 UTC (Thu)
by SEJeff (guest, #51588)
[Link] (6 responses)
Posted Feb 27, 2020 20:18 UTC (Thu)
by Cyberax (✭ supporter ✭, #52523)
[Link] (5 responses)
Many RedHat forks (Amazon Linux, Scientific Linux) also pretty much ignore SELinux and barely test it.
Posted Feb 27, 2020 20:39 UTC (Thu)
by mohg (guest, #114025)
[Link] (1 responses)
As a binary rebuild of RHEL, Scientifix Linux supports whatever the equivalent RHEL does.
Posted Feb 27, 2020 20:46 UTC (Thu)
by Cyberax (✭ supporter ✭, #52523)
[Link]
However, plenty of software doesn't support it. Like SUN (RIP) Grid Engine forks, or good old Hadoop.
Posted Feb 27, 2020 20:59 UTC (Thu)
by rahulsundaram (subscriber, #21946)
[Link]
I have worked in multiple large enterprises which had SELinux in enforcing mode. I am not sure what this argument is about
Posted Feb 29, 2020 2:14 UTC (Sat)
by Rudd-O (guest, #61155)
[Link]
Perhaps the "niche" is only on your mind, brah.
Posted Mar 3, 2020 17:45 UTC (Tue)
by frostsnow (subscriber, #114957)
[Link]
Posted Feb 27, 2020 22:34 UTC (Thu)
by beagnach (guest, #32987)
[Link]
Again... "niche" and billions just don't seem to fit together. If you're wanting to contrast with "general purpose" why not just use the term "special purpose"?
Sorry to be nit-picky but I find your use of that term in this context quite jarring.
Posted Feb 27, 2020 17:04 UTC (Thu)
by theonewolf (guest, #118690)
[Link]
That makes it being used in Microsoft Azure (OpenShift offering) and other places where OpenShift is being deployed (AWS, on premise).
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
("niche" does not mean "
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
I have no idea in what sense it could be said to "pretty much ignore SELinux".
Impedance matching for BPF and LSM
> I have no idea in what sense it could be said to "pretty much ignore SELinux".
The problem is that SL doesn't do anything with SELinux. If you use it as a RHEL rebuild it works just as RHEL.
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
