All of lore.kernel.org
 help / color / mirror / Atom feed
From: Stephen Smalley <sds@tycho.nsa.gov>
To: Bhargava Shastry <bshas3@gmail.com>
Cc: Eric Paris <eparis@parisplace.org>,
	SELinux@tycho.nsa.gov, James Morris <jmorris@namei.org>
Subject: Re: SELinux on Android
Date: Tue, 22 Nov 2011 14:29:53 -0500	[thread overview]
Message-ID: <1321990193.4161.63.camel@moss-pluto> (raw)
In-Reply-To: <CAGGozWRoHG9TW0xEy7c3ji1ksfXeHt_Nb+53=j3hpZSp0fWmDw@mail.gmail.com>

On Tue, 2011-11-22 at 20:25 +0100, Bhargava Shastry wrote:
> Thanks for pointing out. I am getting myself acquainted with SELinux
> policy semantics to be able to start from scratch. I have one question
> though and the answer to this would make my task of creating an
> Android specific policy much smoother. 
> I had previously loaded an Ubuntu SELinux policy on Android and it
> seemed to label all the filesystems correctly (except yaffs). I would
> like to diff a very basic policy (i.e., mdp output) with the default
> ubuntu policy so that I would get an idea of how filesystems are being
> labeled and how transitions are handled among other things; basically
> to learn from a delta between the two files. To do this, I need
> sources for Ubuntu-SELinux policy (in order to compile a
> policy.conf) . I have somehow not been able to locate the source for
> the policy binary that ubuntu uses (I looked in the /etc/selinux dir
> to no avail). Any ideas as to where I can find them? Alternatively, is
> there a tool to reverse engineer policy.conf from the policy binary
> (e.g. policy.24)?

You need the source package.  selinux-policy-src?

setools has a variety of tools that allow you to inspect a policy, even
a binary one.  seinfo, sesearch, apol, etc.

-- 
Stephen Smalley
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2011-11-22 19:29 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-11-04 10:16 SELinux on Android Bhargava Shastry
2011-11-04 10:54 ` Russell Coker
2011-11-04 12:32 ` Stephen Smalley
2011-11-04 16:25   ` Bhargava Shastry
2011-11-04 16:59     ` Stephen Smalley
2011-11-10 10:33       ` Bhargava Shastry
2011-11-10 12:48         ` Russell Coker
2011-11-10 13:11           ` Eric Paris
2011-11-10 13:12         ` Stephen Smalley
2011-11-10 13:26           ` Bhargava Shastry
2011-11-10 16:26             ` Stephen Smalley
2011-11-11 11:33               ` Bhargava Shastry
2011-11-16 18:15                 ` Bhargava Shastry
2011-11-16 18:35                   ` Eric Paris
2011-11-17 10:15                     ` Bhargava Shastry
2011-11-17 13:39                       ` Stephen Smalley
2011-11-21 15:45                         ` Bhargava Shastry
2011-11-21 15:51                           ` Stephen Smalley
2011-11-21 18:18                             ` Bhargava Shastry
2011-11-21 18:32                               ` Stephen Smalley
2011-11-22 19:25                                 ` Bhargava Shastry
2011-11-22 19:29                                   ` Stephen Smalley [this message]
2011-11-22 22:03                                   ` Russell Coker
2011-12-01 18:42                                     ` Bhargava Shastry
2011-12-01 19:04                                       ` Stephen Smalley
2011-12-02 10:37                                         ` Bhargava Shastry
2011-11-17 13:37                   ` Stephen Smalley

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1321990193.4161.63.camel@moss-pluto \
    --to=sds@tycho.nsa.gov \
    --cc=SELinux@tycho.nsa.gov \
    --cc=bshas3@gmail.com \
    --cc=eparis@parisplace.org \
    --cc=jmorris@namei.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.