fc5: several troubles at my first attempt

Chad Sellers csellers at tresys.com
Wed Mar 15 18:54:10 UTC 2006


Stephen Smalley wrote:
> On Wed, 2006-03-15 at 12:55 -0500, Stephen Smalley wrote:
>> I believe that the (highly modular) strict policy is known to be broken
>> in fc5/rawhide because of the file contexts ordering issue, which
>> requires further changes to libsemanage.  Right, Dan?  So only -targeted
>> or -mls are in a working state.  Possibly that -strict policy shouldn't
>> be included in fc5 since it is known to be broken?
> 
> Another option btw would be to put everything into the base module for
> -strict as is being done for -targeted and -mls already, right?  That
> would at least provide a working -strict policy for fc5.
> 
Yes, that's an option, though I'd lean against it. To my knowledge, we
still haven't come up with a good method for splitting things out into
their own modules. So, throwing everything into base now would make it
difficult to split them out later. I'd lean toward not including strict
on the CD and putting it in repos once it's working, but I'm not sure
how permissible that is (I'm guessing we have to have the package in FC5
in order to make updates to it).

Chad

-- 

----------------------
Chad Sellers
Tresys Technology, LLC
csellers at tresys.com
http://www.tresys.com




More information about the fedora-selinux-list mailing list