From: Lorenzo Hernandez Garcia-Hierro <lorenzo@gnu.org>
To: Stephen Smalley <sds@epoch.ncsc.mil>
Cc: selinux@tycho.nsa.gov
Subject: Re: SELinux port for 2.4.28 (and incoming backport from 2.6) released.
Date: Mon, 06 Dec 2004 16:20:28 +0100 [thread overview]
Message-ID: <1102346428.11450.2.camel@localhost> (raw)
In-Reply-To: <1102342918.23475.70.camel@moss-spartans.epoch.ncsc.mil>
[-- Attachment #1: Type: text/plain, Size: 1166 bytes --]
Hi Stephen,
El lun, 06-12-2004 a las 09:21 -0500, Stephen Smalley escribió:
> On Sat, 2004-12-04 at 15:38, Lorenzo Hernandez Garcia-Hierro wrote:
> > I've not tested it yet, but hopefully works.
>
> For that kernel, you'll have to pass the -c 15 option to checkpolicy to
> tell it to build a version 15 policy, as the 2.4-based SELinux doesn't
> support newer policy versions. Specifically, the 2.4-based SELinux was
> never updated for the conditional policy support (policy booleans), ipv6
> support, and fine-grained netlink classes. See
> http://marc.theaimsgroup.com/?l=selinux&m=107643944721568&w=2.
Yes, the conditional policy (v16) could be ported to it, as i have the
diff of the first release (2.6) that came with it, anyway, other stuff
could be hard to backport.
It would be great to have somewhere a SCM to see real diffs and the
evolution of the 2.6 brand, and the old 2.4 one, to compare what things
need to be backported and how to do it.
I will take a look in it later.
Cheers,
--
Lorenzo Hernández García-Hierro [1024D/6F2B2DEC]
Hardened Debian head developer & project manager.
http://www.debian-hardened.org
[-- Attachment #2: Esta parte del mensaje está firmada digitalmente --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
next prev parent reply other threads:[~2004-12-06 15:20 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-12-04 20:38 SELinux port for 2.4.28 (and incoming backport from 2.6) released Lorenzo Hernandez Garcia-Hierro
2004-12-06 14:21 ` Stephen Smalley
2004-12-06 15:20 ` Lorenzo Hernandez Garcia-Hierro [this message]
2004-12-06 18:07 ` Stephen Smalley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1102346428.11450.2.camel@localhost \
--to=lorenzo@gnu.org \
--cc=sds@epoch.ncsc.mil \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.