> SELinux as a whole is binary: either it is on or off. You can't run a specific program as unconfined, generate a policy from the errors, and enable it after a while. You can make individual domains permissive with the…
I cringed when I read that one
> SELinux as a whole is binary: either it is on or off. You can't run a specific program as unconfined, generate a policy from the errors, and enable it after a while. You can make individual domains permissive with the…
I cringed when I read that one