SELinux on Void (experimental)
I have been working to get SELinux running under Void Linux for quite some time and I wanted to share my progress with you. Do note that this is still very experimental and should NOT be tested on a system that you rely on.
Where it's at currently:
- SELinux enabled kernel (7.1-selinux)
- Userspace tooling packaged (checkpolicy, libsemanage, policycureutils etc.)
- SELinux reference policy is loading up successfully via a runit stage-1 hook
The main limitation is that its currently permissive-only. Also the reference policy has no runit-specific domains yet.
if anyone finds this interesting and wants to help, send me a DM.