mirror of
https://github.com/linuxkit/linuxkit.git
synced 2025-10-04 05:32:31 +00:00
In the riddler change I changed "command" in the yaml to "args" but did not change the files. In fact we basically used the default command everywhere so this did not actually break. Remove the unnecessary "command" lines to simplify yaml. Revert the command to args change for now as I think I prefer command, but its easier to switch now. Need to think if the entrypoint/command distinction matters before finalizing. Signed-off-by: Justin Cormack <justin.cormack@docker.com>
selinux
The ultimate goal here is to use SELinux as our default LSM in Moby. To this end, here are the compiler flags and userspace packages necessary to do the basics.
TODO
All the necessary binaries exist, so the next steps are:
- label the filesystem with a default label
- have a policy that contains containerd
- label each container's files seprately, and contain them each with a policy
- policies for other system daemons