From: Daniel J Walsh <dwalsh@redhat.com>
To: SE Linux <selinux@tycho.nsa.gov>
Subject: We need to do a better job of merging policy into Refpolicy
Date: Fri, 23 May 2008 11:54:53 -0400 [thread overview]
Message-ID: <4836E8CD.2030806@redhat.com> (raw)
Chris has done a brilliant job up to this point but I see my differences
between the upstream growing astronomically. This is causing other
distributions to not be able to take advantage of SELinux use in Fedora
and similarly it is getting harder for me to merge in upstream changes.
Currently the patch that I am applying to Refpolicy is huge
# wc policy-20080509.patch
38260 95488 1171253 policy-20080509.patch
And I don't see how we can get this merged without huge amounts of
effort by me or Chris and neither of us have the time.
I think we need a way for third parties to come in an peruse the diffs
and apply the no brainer changes to policy.
We need the ability for a couple of acks to get minor changes in,
without Chris having to look at each change.
Most of my changes to policy come about via bugzilla's so I fix a
problem reported by an AVC and update policy. I have come up with a
system of hundreds/thousands of small changes, but it does not make
merging upstream easy.
I also have made some grand sweeping changes in the same pool that Chris
does not currently agree with or is moving in a slightly different
direction (Roles Based Home Dirs)
So I guess I am saying help.
Can we setup a system of policy Triages, which can look at the policy
patches and apply small obvious changes?
Dan
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
reply other threads:[~2008-05-23 15:54 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4836E8CD.2030806@redhat.com \
--to=dwalsh@redhat.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.