All of lore.kernel.org
 help / color / mirror / Atom feed
* FCGlob
@ 2007-04-17 10:07 Russell Coker
  2007-04-17 11:23 ` FCGlob John D. Ramsdell
  2007-04-17 19:07 ` FCGlob James Athey
  0 siblings, 2 replies; 11+ messages in thread
From: Russell Coker @ 2007-04-17 10:07 UTC (permalink / raw)
  To: SE-Linux

http://selinux-symposium.org/2007/papers/06-fcglob.pdf

I've just read the above paper.  It seems apparent that this is generally the 
right approach.

Page 3 states that a down-side is "the tree would be a binary file and not 
human readable any more".  Why would this be so?  Currently we compile a set 
of plain text .fc files into a plain text file that is not directly 
accessible to the sys-admin (everyone on this list knows how to get it - but 
it's not a documented interface) and there is also a semanage option to 
display the same data.

It seems to me that having .fc files with FCGlob data which are human readable 
and then compiling them into a binary form will not be any different.  
The .fc files shipped as part of policy modules will still need to be 
plain-text (the tree structure depends on nodes from other .fc files), and 
the semanage command can still do much the same tasks.

Why would it be desirable to compile FCGlob to regular expressions?  Once the 
performance benefits are proven we might as well go full-speed ahead.

As for regex's that have no clear meaning, the only thing to do is to remove 
them and wait for the original policy author to complain.  There are many 
regular expressions that never matched anything and probably many more that 
match old versions of software.

-- 
russell@coker.com.au
http://etbe.blogspot.com/          My Blog

http://www.coker.com.au/sponsorship.html Sponsoring Free Software development

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2007-04-20 13:32 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-04-17 10:07 FCGlob Russell Coker
2007-04-17 11:23 ` FCGlob John D. Ramsdell
2007-04-17 12:54   ` FCGlob (does someone have the time to generate a special purpose machine) Zwartsenberg, Remmolt
2007-04-17 14:19     ` John D. Ramsdell
2007-04-17 16:08   ` FCGlob Christopher Ashworth
2007-04-17 17:51     ` FCGlob John D. Ramsdell
2007-04-17 18:42       ` FCGlob James Antill
2007-04-17 18:10     ` FCGlob John D. Ramsdell
2007-04-17 19:07 ` FCGlob James Athey
2007-04-18  0:35   ` FCGlob Russell Coker
2007-04-20 13:32   ` FCGlob John D. Ramsdell

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.