From: Philip Tricca <flihp@twobit.us>
To: Stephen Smalley <sds@tycho.nsa.gov>
Cc: yocto@yoctoproject.org
Subject: Re: [meta-selinux][PATCH 1/2] refpolicy: Replace 2.2014120 with release 2.20151208.
Date: Mon, 28 Mar 2016 18:45:21 -0700 [thread overview]
Message-ID: <56F9DE31.10406@twobit.us> (raw)
In-Reply-To: <56F1A078.1090609@tycho.nsa.gov>
On 03/22/2016 12:43 PM, Stephen Smalley wrote:
> On 03/21/2016 12:26 AM, Philip Tricca wrote:
>> This was mostly straight forward. Had to refresh a single patch:
>> poky-policy-fix-new-SELINUXMNT-in-sys.patch
>
> Can we drop that one? Doesn't upstream already include rules for the
> change from /selinux to /sys/fs/selinux, since that has been the default
> for Linux 3.0 and later?
I'm trying to make as few changes as possible with this though you're
likely right. These are also marked as specific to Poky and I've been
testing only the minimal oe-selinux.conf. The patches aren't applied
using any logic that looks at the distro so I'm not even sure how
specific they are to poky even.
> Also, refpolicy-update-for_systemd.patch seems suspect, given that
> upstream refpolicy already includes systemd support (but you need to
> build with SYSTEMD=y, which can be done now via POLICY_SYSTEMD=y in your
> local.conf or elsewhere). The only bit I see in that patch that isn't
> already in refpolicy is
> allow devpts device_t:filesystem associate;
> which ought to be rewritten as
> dev_associate(devpts_t)
> and upstreamed to refpolicy terminal.te if needed.
>
> I assume that is from creating the /dvv/pts mount point and
> automatically trying to label it according to file_contexts, but the
> type in file_contexts is really for the devpts mount, not the mount point.
Long story short it looks like these patch queues need a scrub. This is
useful information though to get the task started. I'll merge this as it
is and take on the patch scrub on next.
Philip
next prev parent reply other threads:[~2016-03-29 1:45 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-03-21 4:26 [meta-selinux][PATCH 0/2] policy upgrade and cleanup Philip Tricca
2016-03-21 4:26 ` [meta-selinux][PATCH 1/2] refpolicy: Replace 2.2014120 with release 2.20151208 Philip Tricca
2016-03-22 19:43 ` Stephen Smalley
2016-03-29 1:45 ` Philip Tricca [this message]
2016-03-21 4:26 ` [meta-selinux][PATCH 2/2] refpolicy: Remove 2.20140311 release Philip Tricca
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=56F9DE31.10406@twobit.us \
--to=flihp@twobit.us \
--cc=sds@tycho.nsa.gov \
--cc=yocto@yoctoproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.