Request for SELinux Policy Placeholder in meta-swupdate

35 views
Skip to first unread message

Gargi Misra

unread,
Sep 30, 2026, 2:53:24 AM (8 days ago) Sep 30
to swup...@googlegroups.com

Hello SWUpdate Maintainers,

 

We are currently integrating SWUpdate on Qualcomm Linux platforms where SELinux is enabled and enforced as part of our security architecture.

 

As part of this effort, we are developing the SELinux policy required for SWUpdate and its associated components. While reviewing the available Yocto layers, we noticed that meta-swupdate does not currently provide any SELinux policy support.

 

We would like to understand whether there would be interest in hosting SWUpdate-related SELinux policy within the meta-swupdate layer itself.

 

For reference, the meta-updater layer contains SELinux policy support for OSTree under its SELinux dynamic layer: meta-updater/dynamic-layers/selinux/recipes-security/refpolicy at master · uptane/meta-updater. Having the policy maintained close to the corresponding functionality provides a natural location for updates, enables policy evolution alongside feature development, and avoids downstream layers having to carry SWUpdate-specific policy separately.

 

Our intention is to keep SWUpdate-specific SELinux policy together with the SWUpdate layer so that:

 

  • SWUpdate domains, types, file contexts, and associated rules are maintained alongside the software they are intended to protect.
  • Policy updates can evolve together with SWUpdate functionality.
  • Downstream users do not need to re-create or duplicate the same SWUpdate policy structure.
  • SELinux-enabled deployments have a common baseline policy available as a starting point.

 

We are currently working through the SELinux enablement and policy development for SWUpdate on Qualcomm platforms, and before investing further effort, we wanted to get feedback from the maintainers on whether such an approach would be acceptable for meta-swupdate.

 

Has there been any prior discussion around SELinux support in meta-swupdate? If there is interest, we would be happy to discuss potential implementation approaches and contribute patches for review.

 

Thank you for your time and feedback.

 

Best regards,

Gargi Misra

Qualcomm Technologies, Inc.

 

Stefano Babic

unread,
Sep 30, 2026, 3:35:03 AM (8 days ago) Sep 30
to Gargi Misra, swup...@googlegroups.com
Hi Gargi,

On 9/30/26 07:48, 'Gargi Misra' via swupdate wrote:
> Hello SWUpdate Maintainers,
>
> We are currently integrating SWUpdate on Qualcomm Linux platforms where
> SELinux is enabled and enforced as part of our security architecture.
>
> As part of this effort, we are developing the SELinux policy required
> for SWUpdate and its associated components. While reviewing the
> available Yocto layers, we noticed that meta-swupdate does not currently
> provide any SELinux policy support.
>

There was not request so far.

> We would like to understand whether there would be interest in hosting
> SWUpdate-related SELinux policy within the meta-swupdate layer itself.
>
> For reference, the meta-updater layer contains SELinux policy support
> for OSTree under its SELinux dynamic layer: meta-updater/dynamic-layers/
> selinux/recipes-security/refpolicy at master · uptane/meta-updater
> <https://github.com/uptane/meta-updater/tree/master/dynamic-layers/
> selinux/recipes-security/refpolicy>.

This is the correct way to do - using dynamic layers, additional
features (and .bbappend) can be safely added without breaking builds if
a feature / layer is not requested.

To add selinux to meta-swupdate, I agree this is the path to do it.

> Having the policy maintained close
> to the corresponding functionality provides a natural location for
> updates, enables policy evolution alongside feature development, and
> avoids downstream layers having to carry SWUpdate-specific policy
> separately.

Sure.

>
> Our intention is to keep SWUpdate-specific SELinux policy together with
> the SWUpdate layer so that:
>
> * SWUpdate domains, types, file contexts, and associated rules are
> maintained alongside the software they are intended to protect.
> * Policy updates can evolve together with SWUpdate functionality.
> * Downstream users do not need to re-create or duplicate the same
> SWUpdate policy structure.
> * SELinux-enabled deployments have a common baseline policy available
> as a starting point.
>
> We are currently working through the SELinux enablement and policy
> development for SWUpdate on Qualcomm platforms, and before investing
> further effort, we wanted to get feedback from the maintainers on
> whether such an approach would be acceptable for meta-swupdate.

It is fine and I agree the method used in meta-updater, and it is ok for
me to add BBFILES_DYNAMIC into layer.conf.

>
> Has there been any prior discussion around SELinux support in meta-
> swupdate?

No, I haven't received any request in this direction.

> If there is interest, we would be happy to discuss potential
> implementation approaches and contribute patches for review.
>

Please do it.

Best regards,
Stefano Babic

> Thank you for your time and feedback.
>
> Best regards,
>
> Gargi Misra
>
> Qualcomm Technologies, Inc.
>
> --
> You received this message because you are subscribed to the Google
> Groups "swupdate" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to swupdate+u...@googlegroups.com
> <mailto:swupdate+u...@googlegroups.com>.
> To view this discussion visit https://groups.google.com/d/msgid/
> swupdate/
> LV3PR02MB106444BC321A8DB4870380D80F18B2%40LV3PR02MB10644.namprd02.prod.outlook.com <https://groups.google.com/d/msgid/swupdate/LV3PR02MB106444BC321A8DB4870380D80F18B2%40LV3PR02MB10644.namprd02.prod.outlook.com?utm_medium=email&utm_source=footer>.

--
_______________________________________________________________________
Nabla Software Engineering GmbH
Hirschstr. 111A | 86156 Augsburg | Tel: +49 821 45592596
Geschäftsführer : Stefano Babic | HRB 40522 Augsburg
E-Mail: sba...@nabladev.com

ayoub...@googlemail.com

unread,
Sep 30, 2026, 12:44:17 PM (7 days ago) Sep 30
to swupdate

Hi,

You’ll probably need first to add SELinux support to SWUpdate through libselinux so that suricatta and mongoose/Websocket can run in separate SELinux contexts from the core process.

Best,
Ayoub

ayoub...@googlemail.com

unread,
Oct 1, 2026, 7:42:50 AM (7 days ago) Oct 1
to swupdate

I have an old patch in my drawer that adds SELinux support for child processes. 

It needs to be reworked for master and tested. 

I’ll send it soon.

Reply all
Reply to author
Forward
0 new messages