"Christopher J. PeBenito" writes: > On 9/3/26 5:10 AM, Sam James wrote: >> "Christopher J. PeBenito" writes: >> >>> Back when refpolicy started, every system carried the policy sources >>> and built its own policy locally. Given that world, *make* was the >>> obvious choice — ubiquitous, lightweight, and well understood. The >>> downside is a set of Makefiles that’s hard to read and even harder to >>> maintain. >>> >>> Fast‑forward to today, and no one is building full policies on‑device >>> anymore. Outside of a few local modules, the main policy is built by >>> the distro. With that in mind, I’d like to move the main policy build >>> to a modern system (the headers‑based builds would stay on make). >>> >>> I’ve been experimenting with *meson/ninja*, and so far the results >>> look good. I’d appreciate feedback on two points: >>> >>> 1. >>> >>> *Concerns about making this change* >> >> We'd lose the ability to quickly run make for a single policy being >> developed before it moves into proper packaging, I think, but we could >> keep simple Makefiles around for that case. > > When you say single policy, do you mean a full build of > standard/MLS/MCS or an individual policy module like "make > modulename.pp"? > Ah, sorry, I meant "make modulename.pp" when working on something new. > >>> 2. >>> >>> *Which build system we should adopt (I'm definitely not attached to >>> meson)* >> Meson is usually the nicest to deal with as a distribution maintainer. >> >> I'm also a Meson contributor. I think Rahul was interested in adding >> SELinux policy support natively into Meson too. >> > Can you clarify what that means? It seems like a very specialized feature. Not needing custom_targets to build policy files, so benefitting from proper typing and native Meson objects for it. Meson already has them for various languages and it welcomes more of them. I think he had some specific benefits in mind but I'd have to ask him what they were again. sam