Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Policy(ies) for KDE Plasma Desktop #92

Open
PseudoDistant opened this issue Oct 23, 2021 · 4 comments
Open

Policy(ies) for KDE Plasma Desktop #92

PseudoDistant opened this issue Oct 23, 2021 · 4 comments

Comments

@PseudoDistant
Copy link

I'm still kind of new to SELinux.
I've used it before on Fedora and Debian, but always with GNOME.
I'm finally trying to get it enforced on my daily driver, but I run Plasma.
How would I get Plasma running on Arch with SELinux enforced?
(It's running, but in permissive.)

@fishilico
Copy link
Member

Hello,
I do not use Plasma nor know what would be specific about it. I guess that the SELinux policy might miss some process domains and file context rules for this environment. If this is what your question is about, some good places to ask questions (and submit pull requests) would be https://github.com/SELinuxProject/refpolicy and the [email protected] mailing list (http://vger.kernel.org/vger-lists.html#selinux-refpolicy).

This project tries to stay as close as possible to the upstream projects, and the upstream of the policy which is installed by selinux-refpolicy-arch is https://github.com/SELinuxProject/refpolicy.

@Lunarequest
Copy link

I've been looking at the avc denial logs on kde plasma and it looks like there is little work done for selinux support on the upstream policy since many binaries such as kwin_wayland are blocked from using /dev/dri/card0 which breaks kwin and kills the plasma session. I've personally not written any SELinux policies so, if someone could point towards how to fix these issue I would love to fix and upstream them!

@freedom1b2830
Copy link

@Lunarequest Let's unite in writing policy

@Lunarequest
Copy link

I've not thought about using selinux in a while. @freedom1b2830 feel free to reach out through my email luna.dragon [@] suse.com or matrix nullrequest:matrix.org

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants