All of lore.kernel.org
 help / color / mirror / Atom feed
* [Buildroot] SELinux and buildroot
@ 2019-06-02 14:40 jonsmirl at gmail.com
  2019-06-03 13:20 ` Matthew Weber
  0 siblings, 1 reply; 2+ messages in thread
From: jonsmirl at gmail.com @ 2019-06-02 14:40 UTC (permalink / raw)
  To: buildroot

Is there an example of a basic buildroot system properly locked down
with selinux policies around somewhere that I can use as a guide?

-- 
Jon Smirl
jonsmirl at gmail.com

^ permalink raw reply	[flat|nested] 2+ messages in thread

* [Buildroot] SELinux and buildroot
  2019-06-02 14:40 [Buildroot] SELinux and buildroot jonsmirl at gmail.com
@ 2019-06-03 13:20 ` Matthew Weber
  0 siblings, 0 replies; 2+ messages in thread
From: Matthew Weber @ 2019-06-03 13:20 UTC (permalink / raw)
  To: buildroot

Jon,


On Sun, Jun 2, 2019 at 9:41 AM jonsmirl at gmail.com <jonsmirl@gmail.com> wrote:
>
> Is there an example of a basic buildroot system properly locked down
> with selinux policies around somewhere that I can use as a guide?
>

I believe Thomas was working on a runtime test that captured a working
basic busybox configuration.  I've also CC'd Adam as he was supporting
IRC discussion on this topic last week.

Note, there were some patches as part of the original SELinux support
to Buildroot, however those are quite old and wouldn't apply to the
current refpolicy.  I believe the kernel and rootfilesystem config
also wouldn't be terribly beneficial.  Here are the links to those
patchsets.

Really old refpolicy changes we had to make for an embedded target.
Good example of what might need to be touched.
http://patchwork.ozlabs.org/patch/427128/

Example target defconfig and filesystem adjustments
http://patchwork.ozlabs.org/patch/641331/
http://patchwork.ozlabs.org/patch/641333/

Good luck!
Matt

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2019-06-03 13:20 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-06-02 14:40 [Buildroot] SELinux and buildroot jonsmirl at gmail.com
2019-06-03 13:20 ` Matthew Weber

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.