Lion sandboxing (was: RE: efence patch for darwin)

Jeff Johnson n3npq at mac.com
Tue Apr 26 05:40:44 PDT 2011


On Apr 26, 2011, at 5:04 AM, Russell Jones wrote:

>> But it *is* the 21st century and I most definitely am interested
>> in seeing Lion sandboxing, just like everyone else is waiting.
> 
> I wonder if it will be possible to convert SELinux and/or AppArmor profiles to the system Lion will use. Has there been any public indication of how Apple are planning to implement it?
> 

If it was "possible to convert" SELinux and/or AppArmor, it would have been done already imho.

This is isn't posible in the sense of "anything is possible".

This is a statement that there there has been no interest for years,
that Apple already has other security schemes, and that there would have
been signs (like @apple.com e-mail addresses) in various lists years
ago if SELinux/AppArmor  were "possible".

That is neither a good or bad thing that its impossible to convert.

73 de Jeff
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4645 bytes
Desc: not available
URL: <http://lists.macosforge.org/pipermail/macports-dev/attachments/20110426/3d0144f5/attachment.bin>


More information about the macports-dev mailing list