The postmarketOS and Alpine Linux Conference

SELinux for postmarketOS
2026-09-27 , 5053.1 (Großer B-IT Raum)

A practical look at SELinux and mandatory access control and the challenges of bringing it to Alpine Linux and postmarketOS.


The devices we carry in our pockets are the devices with our most sensitive data. As such, operating systems like Android have undertaken serious efforts to harden themselves against attackers. At the heart of Android's hardening efforts is SELinux, an implementation of mandatory access control (MAC).

In this presentation, we will explain what MAC is and showcase the benefits of SELinux. We will briefly compare it to AppArmor and then look into the history of MAC in postmarketOS and the technical challenges that come with integrating SELinux into Alpine Linux and postmarketOS.

Thanks to the work done by members of the postmarketOS SELinux effort, we will even showcase a demo at the end!

I'm Aelin (she/her), a postmarketOS team member mostly hacking on kernels and U-Boot. I have particular interests in security hardening, UEFI boot and exotic CPU architectures.

This speaker also appears in:

Computer science student at RWTH Aachen and a developer for both Alpine Linux and postmarketOS. Maintainer of various Alpine packages including LLVM, the GNOME stack and the stable Linux kernel. Also responsible for GNOME/Phosh UI integration in postmarketOS and the coordination between Alpine and pmOS. https://achill.org/

This speaker also appears in: