> Quoting Greg KH (
greg@kroah.com):
> > On Fri, Mar 07, 2008 at 11:35:42AM -0600, Serge E. Hallyn wrote:
> > > > Do you really want to run other LSMs within a containerd kernel? Is
> > > > that a requirement? It would seem to run counter to the main goal of
> > > > containers to me.
> > >
> > > Until user namespaces are complete, selinux seems the only good solution
> > > to offer isolation.
> >
> > Great, use that instead :)
>
> That can't work as is since you can't specify major:minor in policy.