[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Replacing aufs with overlayfs



Hi,

maximilian attems wrote (12 Mar 2015 20:52:04 GMT) :
> Apparmor is not critical, hence it is not a regression blocker.

Sure, I didn't expect this to be a blocker. Thanks, anyway, for making
it clear :)

> Better check how it affects Selinux while you'd care about security!

Sorry, I have no experience with SELinux, and have personally chosen
to work on improving AppArmor support on Debian a few years ago, so
I won't be the one who takes care of SELinux vs. overlayfs.

Now, it may be that the way SELinux works (labelling files) has less
chances to be affected by overlayfs than a path-based MAC such
as AppArmor.

Cheers,
-- 
intrigeri


Reply to: