--- "Eric W. Biederman" <ebiederm@xmission.com> wrote:
How would you run PREEMPT_RT in one container, and PREEMPT_DESKTOP
in another? How would you run SMP in one and UP in the other?
One aspect that SELinux and Smack share is that they only really
provide security if all processes involved are under their control,
just like the preemption behavior.
This is not necessarily true of all possible LSMs. In that case it may
be practicle to have different behavior for different containers.
Casey Schaufler
casey@schaufler-ca.com
-