From: Antoine Tenart <antoine.tenart@bootlin.com>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH 12/15] package/refpolicy: allow to provide a custom refpolicy
Date: Fri, 31 Jul 2020 12:10:37 +0200 [thread overview]
Message-ID: <20200731101040.1723047-13-antoine.tenart@bootlin.com> (raw)
In-Reply-To: <20200731101040.1723047-1-antoine.tenart@bootlin.com>
Add support for the user to provide a fully custom refpolicy. When this
is used, modules aren't disabled anymore and packages do not select
refpolicy available modules either. The custom refpolicy must define
the full policy explicitly, and must be a fork of the original
refpolicy, to have the same build system.
This is added to allow users to fully control an SELinux policy, by
providing a complete custom policy.
Signed-off-by: Antoine Tenart <antoine.tenart@bootlin.com>
---
package/refpolicy/Config.in | 39 ++++++++++++++++++++++++++++++++++
package/refpolicy/refpolicy.mk | 18 +++++++++++++---
2 files changed, 54 insertions(+), 3 deletions(-)
diff --git a/package/refpolicy/Config.in b/package/refpolicy/Config.in
index 73274920000a..5e1fa0e93c6a 100644
--- a/package/refpolicy/Config.in
+++ b/package/refpolicy/Config.in
@@ -28,6 +28,41 @@ config BR2_PACKAGE_REFPOLICY
if BR2_PACKAGE_REFPOLICY
+choice
+ prompt "Refpolicy version"
+ default BR2_PACKAGE_REFPOLICY_UPSTREAM_VERSION
+
+config BR2_PACKAGE_REFPOLICY_UPSTREAM_VERSION
+ bool "Upstream version"
+ help
+ Use the refpolicy as provided by Buildroot.
+
+config BR2_PACKAGE_REFPOLICY_CUSTOM_GIT
+ bool "Custom git repository"
+ help
+ Allows to get the refpolicy from a custom git repository.
+
+ The custom refpolicy must define the full policy explicitly, and must
+ be a fork of the original refpolicy, to have the same build system.
+ When this is selected, only the custom policy definition are taken
+ into account and all the modules of the policy are built into the
+ binary policy.
+
+endchoice
+
+if BR2_PACKAGE_REFPOLICY_CUSTOM_GIT
+
+config BR2_PACKAGE_REFPOLICY_CUSTOM_REPO_URL
+ string "URL of custom repository"
+
+config BR2_PACKAGE_REFPOLICY_CUSTOM_REPO_VERSION
+ string "Custom repository version"
+ help
+ Revision to use in the typical format used by Git.
+ E.g. a sha id, tag, branch...
+
+endif
+
choice
prompt "SELinux default state"
default BR2_PACKAGE_REFPOLICY_POLICY_STATE_PERMISSIVE
@@ -54,6 +89,8 @@ config BR2_PACKAGE_REFPOLICY_POLICY_STATE
default "enforcing" if BR2_PACKAGE_REFPOLICY_POLICY_STATE_ENFORCING
default "disabled" if BR2_PACKAGE_REFPOLICY_POLICY_STATE_DISABLED
+if BR2_PACKAGE_REFPOLICY_UPSTREAM_VERSION
+
config BR2_REFPOLICY_EXTRA_MODULES_DIRS
string "Extra modules directories"
help
@@ -71,5 +108,7 @@ config BR2_REFPOLICY_EXTRA_MODULES
endif
+endif
+
comment "refpolicy needs a toolchain w/ threads"
depends on !BR2_TOOLCHAIN_HAS_THREADS
diff --git a/package/refpolicy/refpolicy.mk b/package/refpolicy/refpolicy.mk
index de1fe9217a80..74d2733f7d10 100644
--- a/package/refpolicy/refpolicy.mk
+++ b/package/refpolicy/refpolicy.mk
@@ -4,9 +4,6 @@
#
################################################################################
-REFPOLICY_VERSION = 2.20200229
-REFPOLICY_SOURCE = refpolicy-$(REFPOLICY_VERSION).tar.bz2
-REFPOLICY_SITE = https://github.com/SELinuxProject/refpolicy/releases/download/RELEASE_2_20200229
REFPOLICY_LICENSE = GPL-2.0
REFPOLICY_LICENSE_FILES = COPYING
REFPOLICY_INSTALL_STAGING = YES
@@ -18,6 +15,17 @@ REFPOLICY_DEPENDENCIES = \
host-setools \
host-gawk
+ifeq ($(BR2_PACKAGE_REFPOLICY_CUSTOM_GIT),y)
+REFPOLICY_VERSION = $(call qstrip,$(BR2_PACKAGE_REFPOLICY_CUSTOM_REPO_VERSION))
+REFPOLICY_SITE = $(call qstrip,$(BR2_PACKAGE_REFPOLICY_CUSTOM_REPO_URL))
+REFPOLICY_SITE_METHOD = git
+BR_NO_CHECK_HASH_FOR += $(REFPOLICY_SOURCE)
+else
+REFPOLICY_VERSION = 2.20200229
+REFPOLICY_SOURCE = refpolicy-$(REFPOLICY_VERSION).tar.bz2
+REFPOLICY_SITE = https://github.com/SELinuxProject/refpolicy/releases/download/RELEASE_2_20200229
+endif
+
# Cannot use multiple threads to build the reference policy
REFPOLICY_MAKE = \
PYTHON=$(HOST_DIR)/usr/bin/python3 \
@@ -29,6 +37,8 @@ REFPOLICY_POLICY_VERSION = $(BR2_PACKAGE_LIBSEPOL_POLICY_VERSION)
REFPOLICY_POLICY_STATE = \
$(call qstrip,$(BR2_PACKAGE_REFPOLICY_POLICY_STATE))
+ifeq ($(BR2_PACKAGE_REFPOLICY_UPSTREAM_VERSION),y)
+
REFPOLICY_MODULES = \
application \
authlogin \
@@ -77,6 +87,8 @@ define REFPOLICY_CONFIGURE_MODULES
)
endef
+endif # BR2_PACKAGE_REFPOLICY_UPSTREAM_VERSION = y
+
ifeq ($(BR2_INIT_SYSTEMD),y)
define REFPOLICY_CONFIGURE_SYSTEMD
$(SED) "/SYSTEMD/c\SYSTEMD = y" $(@D)/build.conf
--
2.26.2
next prev parent reply other threads:[~2020-07-31 10:10 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-07-31 10:10 [Buildroot] [PATCH 00/15] Improve SELinux support Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 01/15] package/e2fsprogs: set xattrs for the root dir as well Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 02/15] fs/common.mk: set SELinux file security contexts Antoine Tenart
2020-09-04 12:58 ` Thomas Petazzoni
2020-07-31 10:10 ` [Buildroot] [PATCH 03/15] fs/common.mk: move down ROOTFS_REPRODUCIBLE for consistency Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 04/15] package/refpolicy: smaller monolithic policy Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 05/15] package/refpolicy: allow packages to select SELinux modules Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 06/15] package/systemd: " Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 07/15] package/dbus: select SELinux module Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 08/15] package/util-linux: " Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 09/15] package/e2fsprogs: " Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 10/15] package/refpolicy: allow providing user defined modules Antoine Tenart
2020-09-04 13:05 ` Thomas Petazzoni
2020-09-04 15:00 ` Antoine Tenart
2020-09-04 15:10 ` Thomas Petazzoni
2020-09-04 15:28 ` Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 11/15] package/refpolicy: allow selecting additional modules Antoine Tenart
2020-07-31 10:10 ` Antoine Tenart [this message]
2020-07-31 10:10 ` [Buildroot] [PATCH 13/15] package/refpolicy: allow packages to provide their own SELinux modules Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 14/15] package/refpolicy: fix the configure, build and install steps Antoine Tenart
2020-09-04 13:07 ` Thomas Petazzoni
2020-07-31 10:10 ` [Buildroot] [PATCH 15/15] docs/manual: add a section about SELinux Antoine Tenart
2020-07-31 12:15 ` Matthew Weber
2020-07-31 12:52 ` Antoine Tenart
2020-07-31 13:15 ` Thomas Petazzoni
2020-07-31 13:19 ` Matthew Weber
2020-07-31 13:22 ` Antoine Tenart
2020-09-04 13:09 ` Thomas Petazzoni
2020-07-31 17:08 ` [Buildroot] [PATCH 00/15] Improve SELinux support Adam Duskett
2020-07-31 20:48 ` Adam Duskett
2020-08-01 8:12 ` Antoine Tenart
2020-08-01 8:05 ` Antoine Tenart
2020-09-04 12:56 ` Thomas Petazzoni
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200731101040.1723047-13-antoine.tenart@bootlin.com \
--to=antoine.tenart@bootlin.com \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox