Hacker News new | ask | show | jobs
by poppafuze 99 days ago
hilarious they purposefully left out SELinux. try that in ramalama.
1 comments

Didn't leave it out. It was grouped with AppArmor in the table, which was imprecise. I'm splitting the row. SELinux labels are on the inode, so renames preserve the context. Copy resistance is policy-dependent (works for `sandbox_t`, not for `unconfined_t`). See my reply to `botanicalfriend` user above.