All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] Question: and the policy grows...
@ 2011-03-17 13:50 Guido Trentalancia
  2011-03-17 14:25 ` Daniel J Walsh
  0 siblings, 1 reply; 46+ messages in thread
From: Guido Trentalancia @ 2011-03-17 13:50 UTC (permalink / raw)
  To: refpolicy

Hello everybody !

I have a question which I believe is quite interesting.

I often get on and off the list because of a lack of time, but I have
noticed that most (if not all) of the patches that have been submitted
to refpolicy in the last period of time, including a few patches that I
have submitted, were intended to improve usability and were going to add
new permissions to this or that policy module (it's always diff +).

So, the policy grows... and becomes weaker (less tight and secure),
although hopefully more usable.

If this trends continues the policy will just become weaker and weaker
with time and this might not always be backed by an increased usability.

I would even expect that some of the permissions added long time ago and
still present in the policy are no longer needed by more recent versions
of the same packages. And usually backwards compatibility (for very old
package versions) is not something which should be guaranteed forever...

So my question is: who is going to take care of periodically trimming
down the permissions in refpolicy that are no longer needed (keep the
policy tight) ? But more importantly how is this going to be done
technically (the methodology) ?

Thanks for your time !

Regards,

Guido

^ permalink raw reply	[flat|nested] 46+ messages in thread

end of thread, other threads:[~2011-03-19 14:40 UTC | newest]

Thread overview: 46+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-03-17 13:50 [refpolicy] Question: and the policy grows Guido Trentalancia
2011-03-17 14:25 ` Daniel J Walsh
2011-03-17 16:04   ` Guido Trentalancia
2011-03-17 16:44     ` Daniel J Walsh
2011-03-17 17:54       ` Christopher J. PeBenito
2011-03-17 18:34         ` Daniel J Walsh
2011-03-17 19:49           ` Daniel J Walsh
2011-03-18 13:30           ` Christopher J. PeBenito
2011-03-17 20:15         ` Guido Trentalancia
2011-03-18 13:35           ` Christopher J. PeBenito
2011-03-18 15:25             ` Guido Trentalancia
2011-03-17 19:40       ` Guido Trentalancia
2011-03-17 19:55         ` Daniel J Walsh
2011-03-17 20:27           ` Guido Trentalancia
2011-03-18 13:38             ` Christopher J. PeBenito
2011-03-17 20:24         ` Sven Vermeulen
2011-03-17 21:08           ` Guido Trentalancia
2011-03-17 21:34             ` Sven Vermeulen
2011-03-17 23:04               ` Guido Trentalancia
2011-03-18 13:52               ` Christopher J. PeBenito
2011-03-18 15:20                 ` Guido Trentalancia
2011-03-17 23:08           ` Mark Montague
2011-03-18  6:06             ` Sven Vermeulen
2011-03-18 10:19               ` Dominick Grift
2011-03-18 12:31               ` Guido Trentalancia
2011-03-17 22:56         ` Mark Montague
2011-03-18 10:12           ` Dominick Grift
2011-03-18 13:37           ` Stephen Smalley
2011-03-18 15:37           ` Dominick Grift
2011-03-17 23:24         ` SE Linux use - was: " Russell Coker
2011-03-18  0:33           ` Guido Trentalancia
2011-03-18  2:11           ` Jason Axelson
2011-03-18 13:23           ` James Carter
2011-03-18 14:33             ` Russell Coker
2011-03-18 14:57               ` Christopher J. PeBenito
2011-03-18 15:48                 ` Guido Trentalancia
2011-03-18 23:40                 ` Russell Coker
2011-03-18 15:45               ` Guido Trentalancia
2011-03-18 23:52                 ` Russell Coker
2011-03-19 14:37                   ` Guido Trentalancia
2011-03-18 14:08           ` Christopher J. PeBenito
2011-03-18 13:45         ` [refpolicy] " Christopher J. PeBenito
2011-03-18 15:09           ` Guido Trentalancia
2011-03-18 17:14           ` [refpolicy] dual mailing list (was Question: and the policy grows...) Guido Trentalancia
2011-03-18 18:40             ` Daniel J Walsh
2011-03-18 19:13               ` Guido Trentalancia

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.