[DSE-Dev] Bug#1030804: refpolicy: more rigorous validation

Christian Göttsche cgzones at googlemail.com
Tue Feb 7 15:57:21 GMT 2023


Package: refpolicy
Version: 2:2.20221101-4
Tags: patch

Dear Maintainer,

attached are three patches to be more rigorous about policy building.

Patch 1: Drop duplicate declaration of file context for /var/log/rspamd(/.*)?
Patch 2: Build policy and verify file contexts within autopkgtest
Patch 3: Validate the policy at build time

Best regards,
       Christian Göttsche
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-d-patches-drop-addition-of-existent-file-context.patch
Type: text/x-patch
Size: 2010 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/selinux-devel/attachments/20230207/13f5331a/attachment.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0002-d-tests-simulate-policy-building.patch
Type: text/x-patch
Size: 1804 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/selinux-devel/attachments/20230207/13f5331a/attachment-0001.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0003-d-rules-validate-build-policy.patch
Type: text/x-patch
Size: 1413 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/selinux-devel/attachments/20230207/13f5331a/attachment-0002.bin>


More information about the SELinux-devel mailing list