All of lore.kernel.org
 help / color / mirror / Atom feed
From: Daniel J Walsh <dwalsh@redhat.com>
To: "Christopher J. PeBenito" <cpebenito@tresys.com>
Cc: Paul Moore <paul.moore@hp.com>,
	Stephen Smalley <sds@tycho.nsa.gov>,
	SE Linux <selinux@tycho.nsa.gov>
Subject: Re: I have spit out my current diffs in policy on fedoraproject.org
Date: Fri, 01 Feb 2008 16:08:56 -0500	[thread overview]
Message-ID: <47A38A68.8070001@redhat.com> (raw)
In-Reply-To: <1201894768.21440.10.camel@gorn.columbia.tresys.com>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Christopher J. PeBenito wrote:
> On Fri, 2008-02-01 at 11:07 -0500, Paul Moore wrote:
>> On Friday 01 February 2008 10:05:27 am Stephen Smalley wrote:
>>> On Fri, 2008-02-01 at 10:01 -0500, Daniel J Walsh wrote:
>>>> -----BEGIN PGP SIGNED MESSAGE-----
>>>> Hash: SHA1
>>>>
>>>> http://people.fedoraproject.org/~dwalsh/Policy/
>>>>
>>>> Patch is now up to 28000 lines.
>>>>
>>>> {snip}
>>>>
>>>> Going forward this is going to get more difficult.  I think we need
>>>> more people with the ability to update the reference policy.  Even
>>>> if they just cherry pick through the differences in my patches and
>>>> upstream.  I don't believe one person can keep up with the volume
>>>> of changes.
>>> Maybe create a fedora branch of refpolicy?
>> Does this actually solve the problem, or just move the patch problem 
>> from outside refpolicy SVN into a branch within refpolicy?  The changes 
>> still need to get merged into the trunk and I'm not sure a branch helps 
>> that any (maybe it does, I guess it all depends on how Chris works).
> 
> That doesn't help me; on many things I need more information on the
> change, so a patch format works.  Some of the problems are that the
> patches are divided by module, not by changeset.  Its better than one
> big mega patch, but still suboptimal, especially if a changeset crosses
> modules.  I still suggest using quilt.
> 
> I'd suggest using trac's bug system on the refpolicy site so we can have
> tracking of patches without flooding the mail list, however I'm sure Dan
> isn't interesting in entering in 147 bugs (unless there is a nice
> command line tool that can do this that I don't know of).
> 

The problem is something like  quilt works if you sit down and do one
massive change to policy, like removing the role separation on homedirs.
 But I get 10 Bugzilla's a day that I make changes to in the same pool.
 Then back port these fixes into F7, F8 and RHEL5.  I am also adding
additional policy components all the time.  A lot of times while I am
fixing an AVC Bugzilla, I will notice that the policy really needs a
higher level function like auth_use_nsswitch(), I make the change while
I am in there.

So it would be tough to change the way  I am working.  What we really
could use is some volunteers review and  package up changes in a way
that Chris would like to see them.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkejimgACgkQrlYvE4MpobOFQQCg3u0coLduGjwDnjAv2A/AT9l3
wNoAnjqZzuCDItJGpz3EADqMRdO38RE9
=OWij
-----END PGP SIGNATURE-----

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

      reply	other threads:[~2008-02-01 21:08 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-02-01 15:01 I have spit out my current diffs in policy on fedoraproject.org Daniel J Walsh
2008-02-01 15:05 ` Stephen Smalley
2008-02-01 16:07   ` Paul Moore
2008-02-01 19:39     ` Christopher J. PeBenito
2008-02-01 21:08       ` Daniel J Walsh [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=47A38A68.8070001@redhat.com \
    --to=dwalsh@redhat.com \
    --cc=cpebenito@tresys.com \
    --cc=paul.moore@hp.com \
    --cc=sds@tycho.nsa.gov \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.