From: Steve Lawrence <slawrence@tresys.com>
To: Richard Haines <richard_c_haines@btinternet.com>,
<selinux@tycho.nsa.gov>, <setools-bugs@tresys.com>,
<brindle@quarksecurity.com>
Subject: Re: [PATCH] setools: Update to load v29 policy source files.
Date: Fri, 25 Apr 2014 15:20:42 -0400 [thread overview]
Message-ID: <535AB58A.1050500@tresys.com> (raw)
In-Reply-To: <1397573043-21748-1-git-send-email-richard_c_haines@btinternet.com>
On 04/15/2014 10:44 AM, Richard Haines wrote:
> This uses the policy build files from checkpolicy-2.1.12-5.fc20 that
> are then modified to be used in setools for source policy expansion.
> The files have comments /* Required for SETools libqpol */ added to
> allow for easier patching next time.
>
> This patch should now enable all policy features up to policy version 29.
>
> There are #defines in policy.c infer_policy_version() to determine the
> max version the policy should support when being built, however they
> have not been fully tested.
>
> The source policy expansion has been tested using apol on Fedora 20.
>
> There is one bug where filename type_transition rules are added twice.
> This is a problem in libsepol (expand.c copy_and_expand_avrule_block())
> that adds these rules again - have a fix for this - probably.
>
> There are two bug fixes:
> 1) Add range field to default_range.
> 2) Toggle apol "Policy Source" tab correctly.
>
> This patch MUST be applied on top of the four patches available from:
> http://marc.info/?l=selinux&m=139696911602613&w=2
>
> or (the preferred approach), a fully patched version of setools is
> available from: https://github.com/QuarkSecurity/setools
>
> With RPMs at: https://quarksecurity.com/files/RPMS/
>
> Signed-off-by: Richard Haines <richard_c_haines@btinternet.com>
Applied.
Thanks!
- Steve
next prev parent reply other threads:[~2014-04-25 19:21 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-04-15 14:44 [PATCH] setools: Update to load v29 policy source files Richard Haines
2014-04-15 14:48 ` Joshua Brindle
2014-04-25 19:20 ` Steve Lawrence [this message]
2014-04-25 19:22 ` Joshua Brindle
2014-04-29 13:21 ` Christopher J. PeBenito
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=535AB58A.1050500@tresys.com \
--to=slawrence@tresys.com \
--cc=brindle@quarksecurity.com \
--cc=richard_c_haines@btinternet.com \
--cc=selinux@tycho.nsa.gov \
--cc=setools-bugs@tresys.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.