Re: F23 System Wide Change: SELinux policy store migration

2015-06-15 Thread Lennart Poettering
On Mon, 15.06.15 11:15, Petr Lautrbach (plaut...@redhat.com) wrote: Dne 13.6.2015 v 19:07 Lennart Poettering napsal(a): On Fri, 12.06.15 19:00, Miroslav Grepl (mgr...@redhat.com) wrote: On 06/12/2015 12:17 PM, Lennart Poettering wrote: On Thu, 11.06.15 06:51, Jan Kurik

Re: F23 System Wide Change: SELinux policy store migration

2015-06-15 Thread Petr Lautrbach
Dne 13.6.2015 v 19:07 Lennart Poettering napsal(a): On Fri, 12.06.15 19:00, Miroslav Grepl (mgr...@redhat.com) wrote: On 06/12/2015 12:17 PM, Lennart Poettering wrote: On Thu, 11.06.15 06:51, Jan Kurik (jku...@redhat.com) wrote: = Proposed System Wide Change: SELinux policy store migration

Re: F23 System Wide Change: SELinux policy store migration

2015-06-15 Thread Petr Lautrbach
Dne 15.6.2015 v 12:15 Lennart Poettering napsal(a): On Mon, 15.06.15 11:15, Petr Lautrbach (plaut...@redhat.com) wrote: Dne 13.6.2015 v 19:07 Lennart Poettering napsal(a): On Fri, 12.06.15 19:00, Miroslav Grepl (mgr...@redhat.com) wrote: On 06/12/2015 12:17 PM, Lennart Poettering wrote: On

Re: F23 System Wide Change: SELinux policy store migration

2015-06-15 Thread Daniel J Walsh
Could all of this be done with links? IE Could you install selinux-policy into /usr/share/selinux/TARGETED/base/*.pp /usr/share/selinux/TARGETED/custom/*.pp Then we reassemble these modules with custom modules in /var/lib/selinux/TARGETED/ supplied by administrators? On 06/15/2015 05:15 AM,

Re: F23 System Wide Change: SELinux policy store migration

2015-06-13 Thread Lennart Poettering
On Fri, 12.06.15 19:00, Miroslav Grepl (mgr...@redhat.com) wrote: On 06/12/2015 12:17 PM, Lennart Poettering wrote: On Thu, 11.06.15 06:51, Jan Kurik (jku...@redhat.com) wrote: = Proposed System Wide Change: SELinux policy store migration =

Re: F23 System Wide Change: SELinux policy store migration

2015-06-12 Thread Lennart Poettering
On Thu, 11.06.15 06:51, Jan Kurik (jku...@redhat.com) wrote: = Proposed System Wide Change: SELinux policy store migration = https://fedoraproject.org/wiki/Changes/SELinuxPolicyStoreMigration I cannot make sense of this with my limited selinux knowledge, could you please elaborate on this on

Re: F23 System Wide Change: SELinux policy store migration

2015-06-12 Thread Miroslav Grepl
On 06/12/2015 12:17 PM, Lennart Poettering wrote: On Thu, 11.06.15 06:51, Jan Kurik (jku...@redhat.com) wrote: = Proposed System Wide Change: SELinux policy store migration = https://fedoraproject.org/wiki/Changes/SELinuxPolicyStoreMigration I cannot make sense of this with my limited

Re: F23 System Wide Change: SELinux policy store migration

2015-06-11 Thread Petr Lautrbach
Dne 11.6.2015 v 14:42 Colin Walters napsal(a): On Thu, Jun 11, 2015, at 06:51 AM, Jan Kurik wrote: = Proposed System Wide Change: SELinux policy store migration = https://fedoraproject.org/wiki/Changes/SELinuxPolicyStoreMigration Change owner(s): * Petr Lautrbach plautrba at redhat dot com

Re: F23 System Wide Change: SELinux policy store migration

2015-06-11 Thread Miroslav Grepl
On 06/11/2015 03:26 PM, Matthew Miller wrote: On Thu, Jun 11, 2015 at 06:51:52AM -0400, Jan Kurik wrote: In the SELinux userspace project release 2015-02-02, the SELinux policy store was moved from /etc/selinux/store/modules/ to /var/lib/selinux/store/. The change page notes performance

Re: F23 System Wide Change: SELinux policy store migration

2015-06-11 Thread Matthew Miller
On Thu, Jun 11, 2015 at 06:51:52AM -0400, Jan Kurik wrote: In the SELinux userspace project release 2015-02-02, the SELinux policy store was moved from /etc/selinux/store/modules/ to /var/lib/selinux/store/. The change page notes performance improvements. Can these be quantified? At the very

Re: F23 System Wide Change: SELinux policy store migration

2015-06-11 Thread Colin Walters
On Thu, Jun 11, 2015, at 06:51 AM, Jan Kurik wrote: = Proposed System Wide Change: SELinux policy store migration = https://fedoraproject.org/wiki/Changes/SELinuxPolicyStoreMigration Change owner(s): * Petr Lautrbach plautrba at redhat dot com * Miroslav Grepl mgrepl at redhat dot com