From: Joe MacDonald <Joe_MacDonald@mentor.com>
To: <xin.ouyang@windriver.com>, Mark Hatle <mark.hatle@windriver.com>
Cc: yocto@yoctoproject.org
Subject: Re: [meta-selinux] refpolicy update in master-next
Date: Fri, 19 Sep 2014 17:17:18 -0400 [thread overview]
Message-ID: <20140919211717.GB5036@mentor.com> (raw)
In-Reply-To: <541B3B4E.30300@windriver.com>
[-- Attachment #1: Type: text/plain, Size: 2917 bytes --]
[Re: [meta-selinux] refpolicy update in master-next] On 14.09.18 (Thu 15:06) Mark Hatle wrote:
> On 9/18/14, 2:57 PM, Joe MacDonald wrote:
> >Hey all,
> >
> >As we'd all discussed at different times in the past, we're well behind
> >the curve on a refpolicy update for meta-selinux. With the 1.7 release
> >of Yocto coming up, we thought it was important to update the policy
> >sooner rather than later, so I'm starting that work now.
> >
> >It's being done in master-next and currently the only recipe that has
> >been updated is the -mls one. Over the next few days I'll be updating
> >the others, then working through testing and trying to make sure they're
> >all sane. It would help me out immensely if you had time to kick the
> >tires as well on your favourite policy variant.
> >
> >Depending on how long this takes, the next step is updating the
> >userspace. Fortunately this time around, though, the current userspace
> >is still officially up to the task of managing the current policy, so a
> >full update isn't strictly required. It'd be a really nice thing to
> >have done, though. :-)
> >
>
> I spoke with Joe about this work this morning, and I think
> master-next is the right place to do this. So if you have immediate
> bug fixes, we'll try to apply them to both master and master-next.
> And then continue to use master-next to stage the policy changes (or
> anything else that requires a bit more 'soak' time) before merging.
>
> I'd like to try to get 'master' of meta-selinux fully synced and
> working with the 'master' of Poky around the time of Poky's release
> (within a week or so of the release at least).. then we can branch
> and let the master continue to flow with any "new" work. (It's a
> plan, I'm not sure if it'll happen or not.)
>
> If anyone has any concerns let me know.. otherwise I think this is the plan!
The plan proceeds! :-)
Anyway, so I've now updated all of the policies in refpolicy/ and I'm
starting in on the testing.
Pascal: Can you pay particular attention to refpolicy-minimum? The
straight forward-port of it failed to install the unconfined module
(obviously kind of important to r-min) due to some failure inside
prepare_policy_store(). I started debugging it, then saw that there was
a copy in the refpolicy-minimum recipe as well as one in
refpolicy_common.inc. Both of them need to be cleaned up, but they both
appeared to be doing the same thing in slightly different ways. Given
that, I turfed the one from refpolicy-minimum and it looks like the
unconfined.pp is installed properly using the version from
refpolicy_common. It wasn't clear looking at either the function or the
commit log why a duplicate version of the function was placed in
refpolicy-minimum, so please have a look to see why it was there and if
it's still needed.
Thanks.
--
-Joe MacDonald.
:wq
[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 501 bytes --]
next prev parent reply other threads:[~2014-09-19 21:17 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-09-18 19:57 [meta-selinux] refpolicy update in master-next Joe MacDonald
2014-09-18 20:06 ` Mark Hatle
2014-09-19 21:17 ` Joe MacDonald [this message]
2014-09-22 8:29 ` Pascal Ouyang
2014-09-22 13:35 ` Joe MacDonald
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140919211717.GB5036@mentor.com \
--to=joe_macdonald@mentor.com \
--cc=mark.hatle@windriver.com \
--cc=xin.ouyang@windriver.com \
--cc=yocto@yoctoproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.