Hello SWUpdate Maintainers,
We are currently integrating SWUpdate on Qualcomm Linux platforms where SELinux is enabled and enforced as part of our security architecture.
As part of this effort, we are developing the SELinux policy required for SWUpdate and its associated components. While reviewing the available Yocto layers, we noticed that meta-swupdate does not currently provide any SELinux policy support.
We would like to understand whether there would be interest in hosting SWUpdate-related SELinux policy within the meta-swupdate layer itself.
For reference, the meta-updater layer contains SELinux policy support for OSTree under its SELinux dynamic layer: meta-updater/dynamic-layers/selinux/recipes-security/refpolicy at master · uptane/meta-updater. Having the policy maintained close to the corresponding functionality provides a natural location for updates, enables policy evolution alongside feature development, and avoids downstream layers having to carry SWUpdate-specific policy separately.
Our intention is to keep SWUpdate-specific SELinux policy together with the SWUpdate layer so that:
We are currently working through the SELinux enablement and policy development for SWUpdate on Qualcomm platforms, and before investing further effort, we wanted to get feedback from the maintainers on whether such an approach would be acceptable for meta-swupdate.
Has there been any prior discussion around SELinux support in meta-swupdate? If there is interest, we would be happy to discuss potential implementation approaches and contribute patches for review.
Thank you for your time and feedback.
Best regards,
Gargi Misra
Qualcomm Technologies, Inc.
Hi,
You’ll probably need first to add SELinux support to SWUpdate through libselinux so that suricatta and mongoose/Websocket can run in separate SELinux contexts from the core process.
Best,
Ayoub
I have an old patch in my drawer that adds SELinux support for child processes.
It needs to be reworked for master and tested.
I’ll send it soon.