summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChris PeBenito <pebenito@gentoo.org>2008-05-25 23:50:07 +0000
committerChris PeBenito <pebenito@gentoo.org>2008-05-25 23:50:07 +0000
commit70cfe26dcccb0b42241537d0c34909d668096be1 (patch)
tree91b8b6c34631bed46b9c334f07a54af513d112c9 /sec-policy/selinux-base-policy
parentnet-libs/gtk-vnc: bump to 0.3.6, bugfix release (diff)
downloadhistorical-70cfe26dcccb0b42241537d0c34909d668096be1.tar.gz
historical-70cfe26dcccb0b42241537d0c34909d668096be1.tar.bz2
historical-70cfe26dcccb0b42241537d0c34909d668096be1.zip
sec-policy: bump selinux policy
Package-Manager: portage-2.1.5
Diffstat (limited to 'sec-policy/selinux-base-policy')
-rw-r--r--sec-policy/selinux-base-policy/ChangeLog8
-rw-r--r--sec-policy/selinux-base-policy/files/modules.conf.strict.2008052548
-rw-r--r--sec-policy/selinux-base-policy/files/modules.conf.targeted.2008052549
-rw-r--r--sec-policy/selinux-base-policy/selinux-base-policy-20070329.ebuild26
-rw-r--r--sec-policy/selinux-base-policy/selinux-base-policy-20080525.ebuild117
5 files changed, 234 insertions, 14 deletions
diff --git a/sec-policy/selinux-base-policy/ChangeLog b/sec-policy/selinux-base-policy/ChangeLog
index a6a6c6cbab4d..11a9e358113b 100644
--- a/sec-policy/selinux-base-policy/ChangeLog
+++ b/sec-policy/selinux-base-policy/ChangeLog
@@ -1,6 +1,12 @@
# ChangeLog for sec-policy/selinux-base-policy
# Copyright 2000-2008 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-base-policy/ChangeLog,v 1.61 2008/03/16 04:06:54 pebenito Exp $
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-base-policy/ChangeLog,v 1.62 2008/05/25 23:49:52 pebenito Exp $
+
+*selinux-base-policy-20080525 (25 May 2008)
+
+ 25 May 2008; Chris PeBenito <pebenito@gentoo.org>
+ +selinux-base-policy-20080525.ebuild:
+ New SVN snapshot.
16 Mar 2008; Chris PeBenito <pebenito@gentoo.org>
-selinux-base-policy-20051022-r1.ebuild,
diff --git a/sec-policy/selinux-base-policy/files/modules.conf.strict.20080525 b/sec-policy/selinux-base-policy/files/modules.conf.strict.20080525
new file mode 100644
index 000000000000..11642a928318
--- /dev/null
+++ b/sec-policy/selinux-base-policy/files/modules.conf.strict.20080525
@@ -0,0 +1,48 @@
+application = base
+authlogin = base
+bootloader = base
+clock = base
+consoletype = base
+corecommands = base
+corenetwork = base
+cron = base
+devices = base
+dmesg = base
+domain = base
+files = base
+filesystem = base
+fstools = base
+getty = base
+hostname = base
+hotplug = base
+init = base
+iptables = base
+kernel = base
+libraries = base
+locallogin = base
+logging = base
+lvm = base
+miscfiles = base
+mcs = base
+mls = base
+modutils = base
+mount = base
+mta = base
+netutils = base
+nscd = base
+portage = base
+raid = base
+rsync = base
+selinux = base
+selinuxutil = base
+ssh = base
+staff = base
+storage = base
+su = base
+sysadm = base
+sysnetwork = base
+terminal = base
+udev = base
+userdomain = base
+usermanage = base
+unprivuser = base
diff --git a/sec-policy/selinux-base-policy/files/modules.conf.targeted.20080525 b/sec-policy/selinux-base-policy/files/modules.conf.targeted.20080525
new file mode 100644
index 000000000000..55a9b4a873b2
--- /dev/null
+++ b/sec-policy/selinux-base-policy/files/modules.conf.targeted.20080525
@@ -0,0 +1,49 @@
+application = base
+authlogin = base
+bootloader = base
+clock = base
+consoletype = base
+corecommands = base
+corenetwork = base
+cron = base
+devices = base
+dmesg = base
+domain = base
+files = base
+filesystem = base
+fstools = base
+getty = base
+hostname = base
+hotplug = base
+init = base
+iptables = base
+kernel = base
+libraries = base
+locallogin = base
+logging = base
+lvm = base
+miscfiles = base
+mcs = base
+mls = base
+modutils = base
+mount = base
+mta = base
+netutils = base
+nscd = base
+portage = base
+raid = base
+rsync = base
+selinux = base
+selinuxutil = base
+ssh = base
+staff = base
+storage = base
+su = base
+sysadm = base
+sysnetwork = base
+terminal = base
+udev = base
+unconfined = base
+userdomain = base
+usermanage = base
+unprivuser = base
diff --git a/sec-policy/selinux-base-policy/selinux-base-policy-20070329.ebuild b/sec-policy/selinux-base-policy/selinux-base-policy-20070329.ebuild
index 4b3bae76f8b8..90ed154e8eb6 100644
--- a/sec-policy/selinux-base-policy/selinux-base-policy-20070329.ebuild
+++ b/sec-policy/selinux-base-policy/selinux-base-policy-20070329.ebuild
@@ -1,6 +1,6 @@
# Copyright 1999-2007 Gentoo Foundation
# Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-base-policy/selinux-base-policy-20070329.ebuild,v 1.3 2007/06/04 00:26:41 pebenito Exp $
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-base-policy/selinux-base-policy-20070329.ebuild,v 1.4 2008/05/25 23:49:52 pebenito Exp $
IUSE=""
@@ -27,12 +27,12 @@ src_unpack() {
unpack ${A}
- cd ${S}/refpolicy
- epatch ${FILESDIR}/${PN}-${PV}.diff
+ cd "${S}/refpolicy"
+ epatch "${FILESDIR}/${PN}-${PV}.diff"
for i in ${POLICY_TYPES}; do
- mkdir -p ${S}/${i}/policy
- cp ${FILESDIR}/modules.conf.${i} ${S}/${i}/policy/modules.conf
+ mkdir -p "${S}/${i}/policy"
+ cp "${FILESDIR}/modules.conf.${i}" "${S}/${i}/policy/modules.conf"
done
}
@@ -40,17 +40,17 @@ src_compile() {
local OPTS="MONOLITHIC=n DISTRO=gentoo QUIET=y"
[ -z "${POLICY_TYPES}" ] && local POLICY_TYPES="strict targeted"
- cd ${S}/refpolicy
+ cd "${S}/refpolicy"
make ${OPTS} generate || die "Failed to create generated module files"
make ${OPTS} xml || die "XML generation failed."
for i in ${POLICY_TYPES}; do
-# make ${OPTS} TYPE=${i} NAME=${i} LOCAL_ROOT=${S}/${i} conf \
+# make ${OPTS} TYPE=${i} NAME=${i} LOCAL_ROOT="${S}/${i}" conf \
# || die "${i} modules.conf update failed"
- make ${OPTS} TYPE=${i} NAME=${i} LOCAL_ROOT=${S}/${i} base \
+ make ${OPTS} TYPE=${i} NAME=${i} LOCAL_ROOT="${S}/${i}" base \
|| die "${i} compile failed"
done
}
@@ -59,18 +59,18 @@ src_install() {
local OPTS="MONOLITHIC=n DISTRO=gentoo QUIET=y DESTDIR=${D}"
[ -z "${POLICY_TYPES}" ] && local POLICY_TYPES="strict targeted"
- cd ${S}/refpolicy
+ cd "${S}/refpolicy"
for i in ${POLICY_TYPES}; do
- make ${OPTS} TYPE=${i} NAME=${i} LOCAL_ROOT=${S}/${i} install \
+ make ${OPTS} TYPE=${i} NAME=${i} LOCAL_ROOT="${S}/${i}" install \
|| die "${i} install failed."
make ${OPTS} TYPE=${i} NAME=${i} install-headers \
|| die "${i} headers install failed."
- echo "run_init_t" > ${D}/etc/selinux/${i}/contexts/run_init_type
+ echo "run_init_t" > "${D}/etc/selinux/${i}/contexts/run_init_type"
- echo "textrel_shlib_t" >> ${D}/etc/selinux/${i}/contexts/customizable_types
+ echo "textrel_shlib_t" >> "${D}/etc/selinux/${i}/contexts/customizable_types"
# libsemanage won't make this on its own
keepdir /etc/selinux/${i}/policy
@@ -79,7 +79,7 @@ src_install() {
dodoc doc/Makefile.example doc/example.{te,fc,if}
insinto /etc/selinux
- doins ${FILESDIR}/config
+ doins "${FILESDIR}/config"
}
pkg_postinst() {
diff --git a/sec-policy/selinux-base-policy/selinux-base-policy-20080525.ebuild b/sec-policy/selinux-base-policy/selinux-base-policy-20080525.ebuild
new file mode 100644
index 000000000000..40718e81e840
--- /dev/null
+++ b/sec-policy/selinux-base-policy/selinux-base-policy-20080525.ebuild
@@ -0,0 +1,117 @@
+# Copyright 1999-2008 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/sec-policy/selinux-base-policy/selinux-base-policy-20080525.ebuild,v 1.1 2008/05/25 23:49:52 pebenito Exp $
+
+IUSE=""
+
+inherit eutils
+
+DESCRIPTION="Gentoo base policy for SELinux"
+HOMEPAGE="http://www.gentoo.org/proj/en/hardened/selinux/"
+SRC_URI="http://oss.tresys.com/files/refpolicy/refpolicy-${PV}.tar.bz2"
+LICENSE="GPL-2"
+SLOT="0"
+
+#KEYWORDS="~x86 ~ppc ~sparc ~amd64 ~mips ~alpha"
+KEYWORDS="~alpha ~amd64 ~mips ~ppc ~sparc ~x86"
+
+RDEPEND=">=sys-apps/policycoreutils-1.30.30"
+DEPEND="${RDEPEND}
+ sys-devel/m4
+ >=sys-apps/checkpolicy-1.30.12"
+
+S=${WORKDIR}/
+
+src_unpack() {
+ [ -z "${POLICY_TYPES}" ] && local POLICY_TYPES="strict targeted"
+ MOD_CONF_VER="20080525"
+
+ unpack ${A}
+
+# cd "${S}/refpolicy"
+# epatch ${FILESDIR}/${PN}-${PV}.diff
+
+ for i in ${POLICY_TYPES}; do
+ cp -a "${S}/refpolicy" "${S}/${i}"
+
+ cp "${FILESDIR}/modules.conf.${i}.${MOD_CONF_VER}" \
+ "${S}/${i}/policy/modules.conf" \
+ || die "failed to set up modules.conf"
+ sed -i -e '/^QUIET/s/n/y/' -e '/^MONOLITHIC/s/y/n/' \
+ -e "/^NAME/s/refpolicy/$i/" "${S}/${i}/build.conf" \
+ || die "build.conf setup failed."
+
+ echo "DISTRO = gentoo" >> "${S}/${i}/build.conf"
+
+ if [ "${i}" == "targeted" ]; then
+ sed -i -e '/root/d' -e 's/user_u/unconfined_u/' \
+ "${S}/${i}/config/appconfig-standard/seusers" \
+ || die "targeted seusers setup failed."
+
+ # add compat
+ sed -i -e '/user_u/s/user_r/user_r system_r/' "${S}/${i}/policy/users" \
+ || die "targeted user compat failed."
+ fi
+ done
+}
+
+src_compile() {
+ [ -z "${POLICY_TYPES}" ] && local POLICY_TYPES="strict targeted"
+
+ for i in ${POLICY_TYPES}; do
+ cd "${S}/${i}"
+
+ make base || die "${i} compile failed"
+ done
+}
+
+src_install() {
+ [ -z "${POLICY_TYPES}" ] && local POLICY_TYPES="strict targeted"
+
+ for i in ${POLICY_TYPES}; do
+ cd "${S}/${i}"
+
+ make DESTDIR="${D}" install \
+ || die "${i} install failed."
+
+ make DESTDIR="${D}" install-headers \
+ || die "${i} headers install failed."
+
+ echo "run_init_t" > "${D}/etc/selinux/${i}/contexts/run_init_type"
+
+ echo "textrel_shlib_t" >> "${D}/etc/selinux/${i}/contexts/customizable_types"
+
+ # libsemanage won't make this on its own
+ keepdir "/etc/selinux/${i}/policy"
+ done
+
+ dodoc doc/Makefile.example doc/example.{te,fc,if}
+
+ insinto /etc/selinux
+ doins "${FILESDIR}/config"
+}
+
+pkg_postinst() {
+ [ -z "${POLICY_TYPES}" ] && local POLICY_TYPES="strict targeted"
+
+ if has "loadpolicy" $FEATURES ; then
+ for i in ${POLICY_TYPES}; do
+ einfo "Inserting base module into ${i} module store."
+
+ cd "/usr/share/selinux/${i}"
+ semodule -s "${i}" -b base.pp
+ done
+ else
+ echo
+ echo
+ eerror "Policy has not been loaded. It is strongly suggested"
+ eerror "that the policy be loaded before continuing!!"
+ echo
+ einfo "Automatic policy loading can be enabled by adding"
+ einfo "\"loadpolicy\" to the FEATURES in make.conf."
+ echo
+ echo
+ ebeep 4
+ epause 4
+ fi
+}