All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Daniel H. Jones" <hotrats@us.ibm.com>
To: Yuichi Nakamura <himainu-ynakam@miomio.jp>
Cc: Stephen Smalley <sds@tycho.nsa.gov>,
	"Brian T. Sniffen" <bsniffen@mitre.org>,
	SELinux-dev@tresys.com, selinux@tycho.nsa.gov
Subject: Re: ANN: Virgil 0.1 released
Date: Fri, 16 Dec 2005 12:20:16 -0600	[thread overview]
Message-ID: <43A30560.60605@us.ibm.com> (raw)
In-Reply-To: <200512161745.jBGHjDBn004256@mms-r00.iijmio.jp>

Yuichi Nakamura wrote:
> Stephen Smalley  wrote:
> 
>>Could you briefly summarize how you view this tool and work as differing
>>from:
>>- the SELinux Policy Editor project (http://seedit.sf.net),
> 
> 
> I've tried virgil 0.1 and found difference.
> 
> Our tool(SELinux Policy Editor) is intended to simplify entire policy, 
> and its Simplified Poilcy Description(SPDL) language can describe 
> full policy that works.
> However, policy converted from SPDL can not be appended to 
> existing policy(sample policy, reference policy), because name of types 
> are completely different.
> 
> On the other hand, 
> It seems that Virgil is intended to generate policy piece, appendable to existing policy.
> 
> 
>>Naturally, your tool will need to deal with the transition to reference
>>policy and the use of binary/loadable policy modules.
> 
> I thinks so too.
> The tool will be more useful if it could generate policy module package
> directly appendable to existing policy.
> 
> ---
> Yuichi Nakamura
> Japan SELinux Users Group(JSELUG)
> SELinux Policy Editor:  http://seedit.sourceforge.net/
> 
> 

Yes. Thank you Yuichi. I think you have it exactly right. One of the 
primary goals of Virgil was to integrate new policy with existing 
policy. While the example conf files include policy for httpd, it is not 
my intent to replace the shipped policy. Web servers just make very 
useful examples.

-- 
Thanks,
Dan Jones
IBM Linux Technology Center, Security
512-838-1794 (T/L 678-1794)
hotrats@us.ibm.com


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2005-12-16 18:20 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-12-15 16:18 ANN: Virgil 0.1 released Daniel H. Jones
2005-12-16 14:56 ` Stephen Smalley
2005-12-16 17:45   ` Yuichi Nakamura
2005-12-16 18:20     ` Daniel H. Jones [this message]
2005-12-16 18:15   ` Daniel H. Jones

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=43A30560.60605@us.ibm.com \
    --to=hotrats@us.ibm.com \
    --cc=SELinux-dev@tresys.com \
    --cc=bsniffen@mitre.org \
    --cc=himainu-ynakam@miomio.jp \
    --cc=sds@tycho.nsa.gov \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.