All of lore.kernel.org
 help / color / mirror / Atom feed
* X policy classes
@ 2004-05-14  6:19 Joshua Brindle
  2004-05-14 12:05 ` Stephen Smalley
  0 siblings, 1 reply; 9+ messages in thread
From: Joshua Brindle @ 2004-05-14  6:19 UTC (permalink / raw)
  To: SELinux

We noticed today that the SE-X policy classes have been merged into the 
sf.net cvs policy. Is there an ETA on when those will be merged into the 
kernel headers?

The reason I ask is because we added the pax class in Gentoo policy and 
kernels, now the ordering becomes an issue because with our current 
kernels (with pax support included) the policy flask/access_vectors 
ordering would have to have pax and then X classes but that would 
prevent a user from using a vanilla kernel which has the X classes in 
the headers.

We'll probably go ahead and add the X classes to our kernel headers and 
pax below them so that both vanilla and gentoo kernels would be able to 
load the same policy but we'll need to make changes to our policy and 
would like to know when we can expect the headers to be changed.

Another idea might be to add the pax class to the standard access_vector 
  file but I'm not sure how receptive that would be since afaik we are 
the only ones using it.

Joshua Brindle


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2004-05-26 15:50 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-05-14  6:19 X policy classes Joshua Brindle
2004-05-14 12:05 ` Stephen Smalley
2004-05-14 17:26   ` Joshua Brindle
2004-05-14 17:47     ` Stephen Smalley
2004-05-14 19:00       ` Chris PeBenito
2004-05-14 19:08         ` Stephen Smalley
2004-05-26 15:35           ` Stephen Smalley
2004-05-26 15:50             ` Stephen Smalley
2004-05-14 19:01       ` Joshua Brindle

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.