Switch to "mcs" SELinux policy

We're going to want the ability for processes to have unique categories,
to enforce separation of container processes.  Gentoo's SELinux policy
supports both Multi-Category Security and Multi-Level Security modes,
although the latter does not seem to work out of the box.
This commit is contained in:
2023-03-12 21:34:15 -05:00
parent cb7e0a5819
commit e9b21b0ca0
3 changed files with 5 additions and 3 deletions

View File

@@ -0,0 +1,2 @@
USE="${USE} -unconfined"
POLICY_TYPES=mcs