From mboxrd@z Thu Jan 1 00:00:00 1970 From: ng0 Subject: Re: Shadow -> 4.4 Date: Fri, 17 Feb 2017 09:58:45 +0000 Message-ID: <20170217095845.kklrv2gifklx5ghv@wasp> References: <20170119200636.2767-1-contact.ng0@cryptolab.net> <20170120051657.GA27443@jasmine> <87o9z2vvte.fsf@wasp.i-did-not-set--mail-host-address--so-tickle-me> <20170211184723.GA8411@jasmine> <20170211194807.wxxsq4z3jqyrsv5t@wasp> <20170211202822.GA11831@jasmine> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:40720) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cefHe-0003BP-Ai for guix-devel@gnu.org; Fri, 17 Feb 2017 04:56:59 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cefHZ-00008x-Ok for guix-devel@gnu.org; Fri, 17 Feb 2017 04:56:58 -0500 Received: from latitanza.investici.org ([82.94.249.234]:39713) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cefHZ-00007a-EU for guix-devel@gnu.org; Fri, 17 Feb 2017 04:56:53 -0500 Content-Disposition: inline In-Reply-To: <20170211202822.GA11831@jasmine> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Leo Famulari Cc: guix-devel@gnu.org On 17-02-11 15:28:22, Leo Famulari wrote: > On Sat, Feb 11, 2017 at 07:48:07PM +0000, ng0 wrote: > > Are there any reasons _against_ configuring 'shadow' with SELinux > > support? > > I'm not that familiar with SELinux, so I can't say one way or the other. > There were some scattered discussions about SELinux in GuixSD at FOSDEM, > but I'm not sure if we drew any conclusions or not. > The SELinux function is based on/originated in a patch from Gentoo. Gentoo does not default to SELinux in sys-apps/shadow, it's only when you set your whole system up to use selinux. It adds the dependencies on the packages "libselinux" and "libsemanage". I think we should add it once there is a consent on how to SELinux in GuixSD. -- ng0 -- https://www.inventati.org/patternsinthechaos/