* [PATCH] libsepol: add include/sepol/cil symlink for in-tree builds
@ 2026-08-28 17:53 Stephen Smalley
2026-08-28 17:58 ` sashiko-bot
2026-08-28 20:13 ` Stephen Smalley
0 siblings, 2 replies; 3+ messages in thread
From: Stephen Smalley @ 2026-08-28 17:53 UTC (permalink / raw)
To: selinux; +Cc: jwcart2, plautrba, omosnace, jason, Stephen Smalley
secilc-fuzzer, secilc, libsemanage, and policycoreutils/semodule all
include <sepol/cil/cil.h>, which only exists in the installed header
layout. The source tree has libsepol/include/sepol and
libsepol/cil/include/cil, and the libsepol/include/Makefile installs
the latter to include/sepol/cil.
Add an include/sepol/cil symlink so that -Ilibsepol/include resolves
<sepol/cil/cil.h> against the source tree. This lets the standalone
libsepol/fuzz/Makefile build secilc-fuzzer without a system
libsepol-devel and against the source tree's header rather than the
system one, and more generally lets any in-tree consume of the CIL API
compile without a DESTDIR install first.
The install target is unaffected; it globs sepol/*.h which does not
match the symlink and copies cil/include/cil/*.h into $(INCDIR)/cil as
before.
Signed-off-by: Stephen Smalley <stephen.smalley.work@gmail.com>
---
libsepol/include/sepol/cil | 1 +
1 file changed, 1 insertion(+)
create mode 120000 libsepol/include/sepol/cil
diff --git a/libsepol/include/sepol/cil b/libsepol/include/sepol/cil
new file mode 120000
index 00000000..a1b89f59
--- /dev/null
+++ b/libsepol/include/sepol/cil
@@ -0,0 +1 @@
+../../cil/include/cil
\ No newline at end of file
--
2.55.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH] libsepol: add include/sepol/cil symlink for in-tree builds
2026-08-28 17:53 [PATCH] libsepol: add include/sepol/cil symlink for in-tree builds Stephen Smalley
@ 2026-08-28 17:58 ` sashiko-bot
2026-08-28 20:13 ` Stephen Smalley
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-08-28 17:58 UTC (permalink / raw)
Cc: selinux
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Invalid repository target. The patch is intended for the SELinux userspace repository (which contains `libsepol`, `secilc`, `libsemanage`) but was mistakenly applied to the Linux kernel tree.
--
commit 38dcb6e7783a077514cbc09a9dbfdbd6ef4f7c1a
Author: Stephen Smalley <stephen.smalley.work@gmail.com>
libsepol: add include/sepol/cil symlink for in-tree builds
This patch adds an include/sepol/cil symlink to allow in-tree builds of
SELinux userspace tools to resolve <sepol/cil/cil.h> without a DESTDIR
install.
> diff --git a/libsepol/include/sepol/cil b/libsepol/include/sepol/cil
> new file mode 120000
> index 0000000000000..a1b89f5916832
> --- /dev/null
> +++ b/libsepol/include/sepol/cil
> @@ -0,0 +1 @@
> +../../cil/include/cil
[Severity: High]
Is this patch intended for the selinux userspace repository?
Applying this patch creates a dangling symlink at the root of the kernel
tree, because the target ../../cil/include/cil does not exist in the Linux
kernel source. It appears this might have been mistakenly applied to the
kernel tree instead of the userspace repository containing libsepol,
secilc, and libsemanage.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260828175314.38256-1-stephen.smalley.work@gmail.com?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] libsepol: add include/sepol/cil symlink for in-tree builds
2026-08-28 17:53 [PATCH] libsepol: add include/sepol/cil symlink for in-tree builds Stephen Smalley
2026-08-28 17:58 ` sashiko-bot
@ 2026-08-28 20:13 ` Stephen Smalley
1 sibling, 0 replies; 3+ messages in thread
From: Stephen Smalley @ 2026-08-28 20:13 UTC (permalink / raw)
To: selinux; +Cc: jwcart2, plautrba, omosnace, jason
On Fri, Aug 28, 2026 at 1:53 PM Stephen Smalley
<stephen.smalley.work@gmail.com> wrote:
>
> secilc-fuzzer, secilc, libsemanage, and policycoreutils/semodule all
> include <sepol/cil/cil.h>, which only exists in the installed header
> layout. The source tree has libsepol/include/sepol and
> libsepol/cil/include/cil, and the libsepol/include/Makefile installs
> the latter to include/sepol/cil.
>
> Add an include/sepol/cil symlink so that -Ilibsepol/include resolves
> <sepol/cil/cil.h> against the source tree. This lets the standalone
> libsepol/fuzz/Makefile build secilc-fuzzer without a system
> libsepol-devel and against the source tree's header rather than the
> system one, and more generally lets any in-tree consume of the CIL API
> compile without a DESTDIR install first.
>
> The install target is unaffected; it globs sepol/*.h which does not
> match the symlink and copies cil/include/cil/*.h into $(INCDIR)/cil as
> before.
>
> Signed-off-by: Stephen Smalley <stephen.smalley.work@gmail.com>
This is now merged.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-28 20:13 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-28 17:53 [PATCH] libsepol: add include/sepol/cil symlink for in-tree builds Stephen Smalley
2026-08-28 17:58 ` sashiko-bot
2026-08-28 20:13 ` Stephen Smalley
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.