All of lore.kernel.org
 help / color / mirror / Atom feed
* 2.4-based SELinux
@ 2004-02-10 15:44 Stephen Smalley
  2004-02-10 18:40 ` Miguel Bolanos
  2004-02-10 20:32 ` Andreas Schuldei
  0 siblings, 2 replies; 5+ messages in thread
From: Stephen Smalley @ 2004-02-10 15:44 UTC (permalink / raw)
  To: selinux

Hi,

In the last nsa.gov release of SELinux, the 2.4-based SELinux (the back
port of the 2.6-based SELinux) began to lag behind the 2.6-based
SELinux, e.g. the new signal and resource limit inheritance controls and
the restored network access controls were only implemented for the
2.6-based SELinux.  The gulf between the two versions has grown further
since that release, as all new development has only been done for the
2.6-based SELinux (e.g. port-based controls, getpeercon support, mount
context options, conditional policy extensions) and we have reached the
point where compatibility is once again an issue, although you can still
uncomment the POLICYCOMPAT definition in the policy Makefile to build
the older policy format.

While the 2.4 back port served a useful purpose for a time in allowing
people to start migrating to the new SELinux API and to using extended
attributes for file security contexts without immediately jumping to
2.6, there seems to be little reason to continue maintaining it for much
longer, and we are really only maintaining it for newer base kernels at
present.  Hence, I expect that a final snapshot of it will be migrated
to the historical versions page in the future.  If you have concerns
with this, let us know, although we really don't plan on continuing to
maintain it ourselves.  Someone else could certainly seek to maintain
it, but I'm not sure that it would be worthwhile, as Fedora Core 2
appears to only be 2.6-based.

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2004-02-13 15:44 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-02-10 15:44 2.4-based SELinux Stephen Smalley
2004-02-10 18:40 ` Miguel Bolanos
2004-02-13 15:44   ` Stephen Smalley
2004-02-10 20:32 ` Andreas Schuldei
2004-02-10 20:41   ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.