[PATCH] NEWS: strongly suggest that <backend type='passt'/> not yet be used in production

Laine Stump laine at redhat.com
Tue Feb 28 21:08:07 UTC 2023


Based on Stefano's suggestion that the NEWS should not seem to
encourage disabling SELinux or AppArmor (which is a valid point) this
replaces the "you need to disable SELinux/AppArmor" note with a
"please do not use in production because that will require disabling
SELinux/AppArmor".

Signed-off-by: Laine Stump <laine at redhat.com>
---

If this change seems okay, anyone who ACKs please push it so that it's
in place before Jiri cuts the release (I may not yet be awake at that
time of day).

 NEWS.rst | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/NEWS.rst b/NEWS.rst
index af7a3b2c76..b9fe73a747 100644
--- a/NEWS.rst
+++ b/NEWS.rst
@@ -78,8 +78,10 @@ v9.1.0 (unreleased)
     start the guest; this led to a running guest with no network
     connectivity.
 
-    (NB: On systems that use them, it is still necessary to disable
-    SELinux/AppArmor to start passt.)
+    (NB: Please do not use <backend type='passt'/> on production
+    systems with Linux Security Modules as it currently requires
+    setting SELinux to permissive mode or disabling selected AppArmor
+    profiles)
 
 
 v9.0.0 (2023-01-16)
-- 
2.39.2



More information about the libvir-list mailing list