All of lore.kernel.org
 help / color / mirror / Atom feed
* RFC policycoreutils packaging
@ 2013-09-14 13:54 Dominick Grift
  2013-09-16 12:07 ` Stephen Smalley
  0 siblings, 1 reply; 10+ messages in thread
From: Dominick Grift @ 2013-09-14 13:54 UTC (permalink / raw)
  To: selinux

We were discussing policycoreutils packaging and there are some things
unclear to me:

1. if one wants to run a monotlitic policy on a embedded system, then,
besides fixfiles and checkpolicy, which tools from policycoreutils are
needed?

1.a How are home dir contexts generated with monolithic policy (  or
should they be created manually ? ), i ask this because in Fedora the
genhomedircon is just a script that calls semodule, but i think semodule
does not work with monolithic policy. If true, how then is someone
expected to generate home dir contexts?

2. Does the sandbox utility only work ( or only work properly ) in
policy configurations that have the MCS security model enabled? If so
should one then depend on a policy model that has MCS enabled?

Fedora splits policycoreutils into the following components/packages:

policycoreutils
policycoreutils-devel
policycoreutils-gui
policycoreutils-newrole
policycoreutils-python
policycoreutils-restorecond
policycoreutils-sandbox

However i am considering whether it makes sense to additionally split
policycoreutils into policycoreutils, and policycoreutils-semodule. 

Because well monlithic configurations do not need semodule.

The problem here is that genhomedircon is basically a shell script that
runs semodule, thus i suspect that the genhomedircon script then needs
to also go into the policycoreutils-semodule package.

Then i get back to my first question, if semodule generates
homedircontexts, and cannot be used with monolithic policy, and if
genhomedircon is just a shell script that runs semodule, then how does
one take care of home dir contexts in a monolithic configuration?

Any hints, tips advice and comments are greatly appreciated.



--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2013-09-16 16:21 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-09-14 13:54 RFC policycoreutils packaging Dominick Grift
2013-09-16 12:07 ` Stephen Smalley
2013-09-16 12:32   ` Dominick Grift
2013-09-16 14:32     ` Daniel J Walsh
2013-09-16 14:54       ` Dominick Grift
2013-09-16 15:12         ` Daniel J Walsh
2013-09-16 15:27           ` Dominick Grift
2013-09-16 15:38             ` Dominick Grift
2013-09-16 16:21               ` Daniel J Walsh
2013-09-16 15:28         ` Christopher J. PeBenito

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.