Post a Comment
You've really got to admire this lady who is not only a brilliant filesystem developer, but has the guts to publically see the truth and tell it like it is, despite it being a violation of political correctness:
Oh, and she's a Red Hat employee! And I must say I agree completely.
Edited 2009-07-16 00:57 UTC
That's spot on. SELinux works pretty much out of the box in the last couple of releases. Keeping policy in sync with development versions however is a more tricky problem and on development machines, it is going to not so smooth yet especially so if you are working on a new filesystem like she does. Ideally, policy modules should be part of the packages instead of being in a separate central package. Atleast for user space, that would eventually be the right architecture.
Have a look at this:
http://kerneltrap.org/search/node/hammer
(the site hasn't been updated in quiet a while, but it has good articles)



