All of lore.kernel.org
 help / color / mirror / Atom feed
* policy under version control
@ 2003-11-29 13:26 Andreas Schuldei
  2003-11-29 15:05 ` Tom
  2003-12-01 15:13 ` Stephen Smalley
  0 siblings, 2 replies; 20+ messages in thread
From: Andreas Schuldei @ 2003-11-29 13:26 UTC (permalink / raw)
  To: Russell Coker, SELinux Mail List

I find it tiresom and uneffective to make changes to policy
without and easy way to feed my effords upstream. Actually i feel
selinux stands and falls with a smoothly working policy. this
needs attention and time of many, not just one.

i would therefor suggest to create a public readabel repository
against which one can update and also some scripts for mailing
back/submitting to the repository(?) the changes needed to make
the subsystems work.

some with some clue should go through this and apply those
patches. 

does it make sense to make this a inter-distribution-spanning
process, perhaps with manpower from the nsa? the nsa policy seems
to be not intended for use, right now and lacks relevance in that
regard.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 20+ messages in thread
* Re: policy under version control
@ 2003-12-03 15:36 Karl MacMillan
  2003-12-03 16:56 ` Serge E. Hallyn
  0 siblings, 1 reply; 20+ messages in thread
From: Karl MacMillan @ 2003-12-03 15:36 UTC (permalink / raw)
  To: SELinux List, tom

On Mon, 2003-12-01 at 14:28, Tom wrote:
> On Mon, Dec 01, 2003 at 10:13:35AM -0500, Stephen Smalley wrote:
> > There is already a sourceforge CVS tree, and patches can be posted to
> > the selinux list.
> 
> The problem I see with read-only CVS and a post-to-mailinglist approach 
> is that it's non-trivial to maintain various sets of the same policy.
> 
> It seems that in the long run we won't be able to do with a single
> default policy. We'll need a couple, or a modular approach. Something
> very much like Debian's tasksel or other tools for other distributions
> where you have 5-10 fields you can check what your machine is going to
> be, and the relevant policy is then assembled automatically.
> 
> 

We are working on some general mechanisms to address this problem. The
first is the ability to define booleans in policies that can be changed
at runtime. This will allow you to turn on and off TE rules based on the
values of the booleans. We posted some messages about this in the past
and we are going to release a working snapshot of this in the next few
days.

We are also working on binary policy modules, which more directly
address what you are wanting I think. This will allow you to create
small binary policy modules separately from a base policy. This is
primarily for the purpose of adding or removing policy components for
specific applications. The advantages of this system are that the
requirement for the policy source and checkpolicy is removed, there will
be language extensions to make the policy modules more loosely coupled
to the core policy (i.e. 1 module will potentially work with a variety
of base policies), and there will be provisions to handle labeling on
installation or removal of the policy modules. Hopefully we will be able
to post some more information about this in the near future (we are in
the design phase of this project).

Karl

-- 
Karl MacMillan
Tresys Technology
kmacmillan@tresys.com
http://www.tresys.com
(410) 290-1411 x134


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 20+ messages in thread

end of thread, other threads:[~2003-12-07 14:06 UTC | newest]

Thread overview: 20+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-11-29 13:26 policy under version control Andreas Schuldei
2003-11-29 15:05 ` Tom
2003-11-29 21:35   ` Russell Coker
2003-12-01 15:13 ` Stephen Smalley
2003-12-01 19:28   ` Tom
2003-12-01 22:53     ` Dale Amon
2003-12-02  3:30     ` Russell Coker
2003-12-02  7:08       ` Tom
2003-12-02  9:59         ` Brian May
2003-12-06 15:57           ` Colin Walters
2003-12-07 11:30           ` Tom
2003-12-07 13:41             ` Andreas Schuldei
2003-12-07 13:44               ` Russell Coker
2003-12-07 13:59                 ` Tom
2003-12-07 13:57               ` Tom
2003-12-02 14:58         ` Colin Walters
2003-12-02 18:52           ` Tom
2003-12-03 13:34             ` Tom
  -- strict thread matches above, loose matches on Subject: below --
2003-12-03 15:36 Karl MacMillan
2003-12-03 16:56 ` Serge E. Hallyn

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.