Skip to content

Conversation

@pjbgf
Copy link
Member

@pjbgf pjbgf commented Nov 3, 2025

In order for qubesome to work in environments where SELinux is enforced the container execution needs to opt-out from SELinux. For profiles, it is likely that this will be reverse once we ship a qubesome-specific SELinux policy. For general workloads that is less likely.

This changes will also ensure that mtls data storage errors does not cause a hard failure.

pjbgf added 2 commits November 3, 2025 22:21
In order for qubesome to work in environments where SELinux
is enabled and enforced the container execution needs to opt-out
from SELinux.

For profiles, it is likely that this will be reverse once we ship
a qubesome-specific SELinux policy. For general workloads that is
less likely.

Signed-off-by: Paulo Gomes <pjbgf@linux.com>
The mtls data storage is largely a convenience feature which enables things
such as mime handling. This change ensures that a profile can still be started
regardless of it.

Signed-off-by: Paulo Gomes <pjbgf@linux.com>
@pjbgf pjbgf merged commit 934455f into main Nov 3, 2025
5 checks passed
@pjbgf pjbgf deleted the selinux branch November 3, 2025 22:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants