From: Casey Schaufler <casey@schaufler-ca.com>
To: Dave Quigley <dpquigl@davequigley.com>
Cc: bfields@fieldses.org, trond.myklebust@netapp.com,
sds@tycho.nsa.gov, linux-nfs@vger.kernel.org,
selinux@tycho.nsa.gov, linux-security-module@vger.kernel.org,
Casey Schaufler <casey@schaufler-ca.com>
Subject: Re: Labeled NFS [v5]
Date: Tue, 20 Nov 2012 16:32:23 -0800 [thread overview]
Message-ID: <50AC2117.801@schaufler-ca.com> (raw)
In-Reply-To: <50AC1A74.7080105@davequigley.com>
On 11/20/2012 4:04 PM, Dave Quigley wrote:
> On 11/20/2012 4:09 PM, Casey Schaufler wrote:
>> On 11/11/2012 10:15 PM, David Quigley wrote:
>>> The NFSv4 working group has finally accepted Labeled NFS as part of
>>> the NFSv4.2
>>> specification and it has been decided that a reposting of the
>>> Labeled NFS code
>>> for inclusion into mainline was a good idea. The patches have been
>>> rebased onto
>>> v3.7-rc2 and have been tested against the SELinux testsuite with the
>>> only
>>> failures being for features not supported by NFS.
>>
>> I'm trying to get the user space tools built so that I can
>> do Smack testing. The instructions on selinuxproject.org
>> seen out of date with regard to the packages required to
>> build the NFS tools. I have failed to build on Fedora 17
>> and Ubuntu 12.04. Any pointers beyond what's on the wiki?
>>
>> Thank you.
>>
>>
>> --
>> This message was distributed to subscribers of the selinux mailing list.
>> If you no longer wish to subscribe, send mail to
>> majordomo@tycho.nsa.gov with
>> the words "unsubscribe selinux" without quotes as the message.
>>
>>
>
> There are a bunch of libs that need to be installed for it to compile
> properly.
Yes, indeed!
> Unfortunately there are new dependencies which have been added since I
> updated the wiki last.
I found that to be the case as well.
> unfortunately don't remember what they are.
And they're not obvious.
> What I did to build it last time though was to apply the one patch
> onto the latest tag from the nfs-utils tree.
Sound simple enough if you're building the nfs-util tree on a daily basis
I suppose. Not something that I do regularly, alas.
> Unfortunately I don't have a clean vm on hand at the moment so I can't
> manually go through and list all the packages for you. A heavy handed
> approach that should still work is that I can give you my rpm list
> from my VM and then you can just make sure you have all the devel
> packages installed.
I'd be up for that.
> Another option would be to grab the nfs-utils srpm for fedora 17 and
> just add the patch into the spec file.
Yeah. Or not.
> That would work too and tell you the build dependencies you need. I
> could also just try to make that for you and put the RPM up but that
> wouldn't be for a few days at the earliest.
That, or I could give you the instructions on how to enable and test
Smack.
Thank you.
>
> Dave
>
WARNING: multiple messages have this Message-ID (diff)
From: Casey Schaufler <casey@schaufler-ca.com>
To: Dave Quigley <dpquigl@davequigley.com>
Cc: bfields@fieldses.org, trond.myklebust@netapp.com,
sds@tycho.nsa.gov, linux-nfs@vger.kernel.org,
selinux@tycho.nsa.gov, linux-security-module@vger.kernel.org,
Casey Schaufler <casey@schaufler-ca.com>
Subject: Re: Labeled NFS [v5]
Date: Tue, 20 Nov 2012 16:32:23 -0800 [thread overview]
Message-ID: <50AC2117.801@schaufler-ca.com> (raw)
In-Reply-To: <50AC1A74.7080105@davequigley.com>
On 11/20/2012 4:04 PM, Dave Quigley wrote:
> On 11/20/2012 4:09 PM, Casey Schaufler wrote:
>> On 11/11/2012 10:15 PM, David Quigley wrote:
>>> The NFSv4 working group has finally accepted Labeled NFS as part of
>>> the NFSv4.2
>>> specification and it has been decided that a reposting of the
>>> Labeled NFS code
>>> for inclusion into mainline was a good idea. The patches have been
>>> rebased onto
>>> v3.7-rc2 and have been tested against the SELinux testsuite with the
>>> only
>>> failures being for features not supported by NFS.
>>
>> I'm trying to get the user space tools built so that I can
>> do Smack testing. The instructions on selinuxproject.org
>> seen out of date with regard to the packages required to
>> build the NFS tools. I have failed to build on Fedora 17
>> and Ubuntu 12.04. Any pointers beyond what's on the wiki?
>>
>> Thank you.
>>
>>
>> --
>> This message was distributed to subscribers of the selinux mailing list.
>> If you no longer wish to subscribe, send mail to
>> majordomo@tycho.nsa.gov with
>> the words "unsubscribe selinux" without quotes as the message.
>>
>>
>
> There are a bunch of libs that need to be installed for it to compile
> properly.
Yes, indeed!
> Unfortunately there are new dependencies which have been added since I
> updated the wiki last.
I found that to be the case as well.
> unfortunately don't remember what they are.
And they're not obvious.
> What I did to build it last time though was to apply the one patch
> onto the latest tag from the nfs-utils tree.
Sound simple enough if you're building the nfs-util tree on a daily basis
I suppose. Not something that I do regularly, alas.
> Unfortunately I don't have a clean vm on hand at the moment so I can't
> manually go through and list all the packages for you. A heavy handed
> approach that should still work is that I can give you my rpm list
> from my VM and then you can just make sure you have all the devel
> packages installed.
I'd be up for that.
> Another option would be to grab the nfs-utils srpm for fedora 17 and
> just add the patch into the spec file.
Yeah. Or not.
> That would work too and tell you the build dependencies you need. I
> could also just try to make that for you and put the RPM up but that
> wouldn't be for a few days at the earliest.
That, or I could give you the instructions on how to enable and test
Smack.
Thank you.
>
> Dave
>
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2012-11-21 0:39 UTC|newest]
Thread overview: 154+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-11-12 6:15 Labeled NFS [v5] David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 6:15 ` [PATCH 01/13] Security: Add hook to calculate context based on a negative dentry David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 12:13 ` J. Bruce Fields
2012-11-12 14:52 ` Dave Quigley
2012-11-12 14:52 ` Dave Quigley
2012-11-12 6:15 ` [PATCH 02/13] Security: Add Hook to test if the particular xattr is part of a MAC model David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 12:15 ` J. Bruce Fields
2012-11-12 14:56 ` Dave Quigley
2012-11-12 14:56 ` Dave Quigley
2012-11-12 16:36 ` J. Bruce Fields
2012-11-12 19:36 ` David P. Quigley
2012-11-12 19:36 ` David P. Quigley
2012-11-12 21:43 ` J. Bruce Fields
2012-11-13 0:12 ` Dave Quigley
2012-11-13 0:12 ` Dave Quigley
2012-11-12 6:15 ` [PATCH 03/13] LSM: Add flags field to security_sb_set_mnt_opts for in kernel mount data David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 6:15 ` [PATCH 04/13] SELinux: Add new labeling type native labels David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 6:15 ` [PATCH 05/13] KConfig: Add KConfig entries for Labeled NFS David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 14:45 ` J. Bruce Fields
2012-11-12 14:57 ` Dave Quigley
2012-11-12 14:57 ` Dave Quigley
2012-11-12 6:15 ` [PATCH 06/13] NFSv4: Add label recommended attribute and NFSv4 flags David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 6:15 ` [PATCH 07/13] NFSv4: Introduce new label structure David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 15:13 ` J. Bruce Fields
2012-11-12 15:32 ` David P. Quigley
2012-11-12 15:32 ` David P. Quigley
2012-11-12 16:05 ` J. Bruce Fields
2012-11-12 16:53 ` David P. Quigley
2012-11-12 16:53 ` David P. Quigley
2012-11-12 17:50 ` J. Bruce Fields
2012-11-12 6:15 ` [PATCH 08/13] NFSv4: Extend fattr bitmaps to support all 3 words David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 6:15 ` [PATCH 09/13] NFS:Add labels to client function prototypes David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 6:15 ` [PATCH 10/13] NFS: Add label lifecycle management David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 15:33 ` J. Bruce Fields
2012-11-12 15:36 ` David P. Quigley
2012-11-12 15:36 ` David P. Quigley
2012-11-12 6:15 ` [PATCH 11/13] NFS: Client implementation of Labeled-NFS David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 6:15 ` [PATCH 12/13] NFS: Extend NFS xattr handlers to accept the security namespace David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 6:15 ` [PATCH 13/13] NFSD: Server implementation of MAC Labeling David Quigley
2012-11-12 6:15 ` David Quigley
2012-11-12 16:31 ` J. Bruce Fields
2012-11-12 15:23 ` Labeled NFS [v5] J. Bruce Fields
2012-11-12 15:34 ` David P. Quigley
2012-11-12 15:34 ` David P. Quigley
2012-11-12 16:09 ` J. Bruce Fields
2012-11-12 20:56 ` Steve Dickson
2012-11-13 1:39 ` Dave Quigley
2012-11-13 1:39 ` Dave Quigley
2012-11-13 12:55 ` Steve Dickson
2012-11-14 4:32 ` Dave Quigley
2012-11-14 4:32 ` Dave Quigley
2012-11-14 13:45 ` J. Bruce Fields
2012-11-14 13:50 ` David Quigley
2012-11-14 13:50 ` David Quigley
2012-11-14 13:59 ` J. Bruce Fields
2012-11-14 14:01 ` David Quigley
2012-11-14 14:01 ` David Quigley
2012-11-14 14:04 ` David Quigley
2012-11-14 14:04 ` David Quigley
2012-11-14 14:24 ` J. Bruce Fields
2012-11-14 14:30 ` David Quigley
2012-11-14 14:30 ` David Quigley
2012-11-15 16:00 ` Casey Schaufler
2012-11-15 16:00 ` Casey Schaufler
2012-11-15 20:28 ` David Quigley
2012-11-15 20:28 ` David Quigley
2012-11-16 3:34 ` Casey Schaufler
2012-11-16 3:34 ` Casey Schaufler
2012-11-16 3:43 ` David Quigley
2012-11-16 3:43 ` David Quigley
2012-11-16 4:58 ` Dave Quigley
2012-11-16 4:58 ` Dave Quigley
2012-11-16 4:59 ` Dave Quigley
2012-11-16 4:59 ` Dave Quigley
2012-11-14 13:56 ` David Quigley
2012-11-14 13:56 ` David Quigley
2012-11-12 16:33 ` J. Bruce Fields
2012-11-12 20:44 ` Dave Quigley
2012-11-12 20:44 ` Dave Quigley
2012-11-12 22:23 ` Casey Schaufler
2012-11-12 22:23 ` Casey Schaufler
2012-11-13 3:16 ` Dave Quigley
2012-11-13 3:16 ` Dave Quigley
2012-11-20 21:09 ` Casey Schaufler
2012-11-20 21:09 ` Casey Schaufler
2012-11-21 0:04 ` Dave Quigley
2012-11-21 0:04 ` Dave Quigley
2012-11-21 0:29 ` Dave Quigley
2012-11-21 0:29 ` Dave Quigley
2012-11-21 0:32 ` Casey Schaufler [this message]
2012-11-21 0:32 ` Casey Schaufler
2012-11-21 0:37 ` Dave Quigley
2012-11-21 0:37 ` Dave Quigley
2012-11-21 2:52 ` Casey Schaufler
2012-11-21 2:52 ` Casey Schaufler
2012-11-21 3:28 ` Dave Quigley
2012-11-21 3:28 ` Dave Quigley
2012-11-28 18:57 ` Casey Schaufler
2012-11-29 1:14 ` Dave Quigley
2012-11-29 1:14 ` Dave Quigley
2012-11-29 2:08 ` Casey Schaufler
2012-11-29 22:28 ` Casey Schaufler
2012-11-29 22:28 ` Casey Schaufler
2012-11-29 22:49 ` David Quigley
2012-11-29 22:49 ` David Quigley
2012-11-30 0:02 ` David Quigley
2012-11-30 0:02 ` David Quigley
2012-11-30 0:07 ` David Quigley
2012-11-30 0:07 ` David Quigley
2012-11-30 0:34 ` Casey Schaufler
2012-11-30 0:34 ` Casey Schaufler
2012-11-30 0:46 ` David Quigley
2012-11-30 0:46 ` David Quigley
2012-11-30 1:50 ` Casey Schaufler
2012-11-30 1:50 ` Casey Schaufler
2012-11-30 2:02 ` David Quigley
2012-11-30 2:02 ` David Quigley
2012-11-30 12:14 ` J. Bruce Fields
2012-11-30 12:57 ` David Quigley
2012-11-30 12:57 ` David Quigley
2012-11-30 13:17 ` David Quigley
2012-11-30 13:17 ` David Quigley
2012-11-30 13:28 ` Stephen Smalley
2012-11-30 13:28 ` Stephen Smalley
2012-11-30 13:35 ` David Quigley
2012-11-30 13:35 ` David Quigley
2012-11-30 13:50 ` Stephen Smalley
2012-11-30 13:50 ` Stephen Smalley
2012-11-30 14:02 ` David Quigley
2012-11-30 14:02 ` David Quigley
2012-11-30 16:21 ` Casey Schaufler
2012-11-30 16:21 ` Casey Schaufler
2012-11-30 16:28 ` David Quigley
2012-11-30 16:28 ` David Quigley
2012-12-03 18:27 ` Casey Schaufler
2012-12-03 18:27 ` Casey Schaufler
2012-11-30 16:55 ` J. Bruce Fields
2012-11-30 16:59 ` David Quigley
2012-11-30 16:59 ` David Quigley
2012-11-30 13:20 ` David Quigley
2012-11-30 13:20 ` David Quigley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=50AC2117.801@schaufler-ca.com \
--to=casey@schaufler-ca.com \
--cc=bfields@fieldses.org \
--cc=dpquigl@davequigley.com \
--cc=linux-nfs@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=sds@tycho.nsa.gov \
--cc=selinux@tycho.nsa.gov \
--cc=trond.myklebust@netapp.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.