[DSE-Dev] Bug#805492: refpolicy: Fix the maintainer script to support the new policy store

Laurent Bigonville bigon at debian.org
Wed Nov 18 18:32:29 UTC 2015

Source: refpolicy
Version: 2:2.20140421-9
Severity: serious


With the userspace 2.4, the policy store has moved from
/etc/selinux/<policy_name> to /var/lib/selinux/<policy_name> (the format
of the store has also changed).

The semanage-utils package contains a script to do that, we should see
if we are using it (it uses python) or if we are doing the migration

The maintainer script should also be updated to use the new location to
install the modules after the initial migration. Should we use semodule
again? We should also install these modules with the correct priority.


Laurent Bigonville

-- System Information:
Debian Release: stretch/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.2.0-1-amd64 (SMP w/8 CPU cores)
Locale: LANG=fr_BE.utf8, LC_CTYPE=fr_BE.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

More information about the SELinux-devel mailing list