Re: [Xen-devel] [PATCH v2] flask: change default state to enforcing

2016-04-08 Thread Konrad Rzeszutek Wilk
On Wed, Apr 06, 2016 at 03:35:59PM -0400, Daniel De Graaf wrote: > The previous default of "permissive" is meant for developing or > debugging a disaggregated system. However, this default makes it too > easy to accidentally boot a machine in this state, which does not place > any restrictions on

[Xen-devel] [PATCH v2] flask: change default state to enforcing

2016-04-06 Thread Daniel De Graaf
The previous default of "permissive" is meant for developing or debugging a disaggregated system. However, this default makes it too easy to accidentally boot a machine in this state, which does not place any restrictions on guests. This is not suitable for normal systems because any guest can pe