We're going to want the ability for processes to have unique categories, to enforce separation of container processes. Gentoo's SELinux policy supports both Multi-Category Security and Multi-Level Security modes, although the latter does not seem to work out of the box. |
||
---|---|---|
.. | ||
host/etc/portage | ||
target/etc/portage |