在 2017/12/28 22:57, Stephen Smalley 写道:
Thank you very much for your reply. Yes, we encounter this issue in our implementation. We have an intertion in our design that we can divide the policy into several parts to load separately. So after the red-hat linux bringing up, which has loaded the system policy db released by redhat, we begin to load the policy released by our product , and meanwhile someone want to start a docker container, and the runc get an ENOMEM error like i mentioned above. Should we merge all the policy into the system policy db and just load once? -- Best Regards Li Kun |