From: Dan <dtdevore64@yahoo.com>
To: James Carter <jwcart2@tycho.nsa.gov>, selinux@tycho.nsa.gov
Subject: Re: Does it matter where .cil modules are build.
Date: Fri, 31 Jul 2015 16:26:22 -0400 [thread overview]
Message-ID: <55BBD9EE.7030508@yahoo.com> (raw)
In-Reply-To: <55BB827C.5020204@tycho.nsa.gov>
Yeah I'm just looking to build selinux policies to confine applications,
etc, with the cil language and nothing else, so when you say the policy
store is that the /var/lib/selinux/targeted/active/modules/400 directory?
On 07/31/2015 10:13 AM, James Carter wrote:
> On 07/31/2015 12:56 AM, Dan wrote:
>> Hello everyone,
>>
>> I have been reading up on the cil documentation and am starting
>> to get the
>> hang of it and have successfully built my first module. I have a a
>> module called
>> test.cil. Now my only question on is where exactly would I put this
>> module to
>> build it or does it not matter where you stick them at? I know when
>> you take the
>> .pp packages and convert them to .cil they get stored in
>> /var/lib/selinux/targeted/active/modules/400, but I'm just using the
>> secilc
>> compiler and nothing else to build policy.
>>
>
> If you are using the CIL compiler to build the whole policy, then it
> doesn't matter where the files are located. Just specify all of the
> files that are part of the policy on the command line for secilc.
>
> Do note that the CIL compiler does not build modules, it builds the
> complete policy, so if you are only building a module than it should
> go into the policy store. You should also use the policy store if you
> want to use the management functions of semanage.
>
next prev parent reply other threads:[~2015-07-31 20:29 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-07-31 4:56 Does it matter where .cil modules are build Dan
2015-07-31 14:13 ` James Carter
2015-07-31 20:26 ` Dan [this message]
2015-08-03 6:21 ` Miroslav Grepl
2015-08-04 0:08 ` Dan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=55BBD9EE.7030508@yahoo.com \
--to=dtdevore64@yahoo.com \
--cc=jwcart2@tycho.nsa.gov \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.