[PATCH] Fix redefinition of XATTR_NAME_SELINUX

2016-09-21 Thread william . c . roberts
From: William Roberts When the Kernel UAPI header is present, this error occurs: external/selinux/libselinux/src/policy.h:7:9: warning: 'XATTR_NAME_SELINUX' macro redefined [-Wmacro-redefined] \#define XATTR_NAME_SELINUX "security.selinux" ^

[PATCH v2 1/1] genhomedircon: remove hardcoded refpolicy strings

2016-09-21 Thread Gary Tierney
Removes the "system_u" and "s0" string literals from refpolicy and replaces the seuser and range in each homedir, uid, and username context specification for every user. Signed-off-by: Gary Tierney --- libsemanage/src/genhomedircon.c | 87

[PATCH v2 0/1] genhomedircon: remove hardcoded refpolicy strings

2016-09-21 Thread Gary Tierney
Second iteration of my previous genhomedircon patch. The issue with context specifications as "<>" is fixed and libselinux calls are replaced with their respective libsepol calls. I've filed a new BZ for Fedora's system_u login here: https://bugzilla.redhat.com/show_bug.cgi?id=1378204 Gary

Re: unlocked stdio

2016-09-21 Thread William Roberts
Another thing I noticed rectifying the Android tree is that the selinux/Android.mk upstream is empty, but the secondary levels are present, any reason that hasn't been pushed? On Wed, Sep 21, 2016 at 2:53 PM, William Roberts wrote: > On Wed, Sep 21, 2016 at 2:48 PM,

Re: unlocked stdio

2016-09-21 Thread William Roberts
On Wed, Sep 21, 2016 at 2:48 PM, William Roberts wrote: > On Sep 21, 2016 13:16, "Stephen Smalley" wrote: >> >> On 09/21/2016 04:11 PM, William Roberts wrote: >> > On Sep 21, 2016 13:06, "Stephen Smalley" > >

Re: unlocked stdio

2016-09-21 Thread William Roberts
On Sep 21, 2016 13:16, "Stephen Smalley" wrote: > > On 09/21/2016 04:11 PM, William Roberts wrote: > > On Sep 21, 2016 13:06, "Stephen Smalley" > > wrote: > >> > >> On 09/21/2016 03:57 PM, Roberts, William C wrote: > >> >

Re: unlocked stdio

2016-09-21 Thread Stephen Smalley
On 09/21/2016 04:11 PM, William Roberts wrote: > On Sep 21, 2016 13:06, "Stephen Smalley" > wrote: >> >> On 09/21/2016 03:57 PM, Roberts, William C wrote: >> > Correction, it’s just fgets_unlocked, it appears to support the others. >> >> Seems like

unlocked stdio

2016-09-21 Thread Roberts, William C
What was the purpose of using unlocked stdio in libselinux? Bionic doesn't support it, is it really necessary? Bill ___ Selinux mailing list Selinux@tycho.nsa.gov To unsubscribe, send email to selinux-le...@tycho.nsa.gov. To get help, send an email

RE: unlocked stdio

2016-09-21 Thread Roberts, William C
Correction, it's just fgets_unlocked, it appears to support the others. From: Roberts, William C Sent: Wednesday, September 21, 2016 12:53 PM To: 'seandroid-l...@tycho.nsa.gov' ; 'selinux@tycho.nsa.gov' ; 's...@tycho.nsa.gov'

Re: selinux 2.6-rc1 release planned 9/30

2016-09-21 Thread Stephen Smalley
On 09/21/2016 11:52 AM, Stephen Smalley wrote: > On 09/21/2016 11:40 AM, William Roberts wrote: >> I'd like to see the -r flip change in by then, so no official release >> is cut with that behavior. >> >> Also, I was looking at the help output for -r, and its quite >> confusing, I cant tell if -r

Re: [PATCH] sandbox: do not run xmodmap in a new X session

2016-09-21 Thread Stephen Smalley
On 09/21/2016 12:00 PM, Petr Lautrbach wrote: > On 09/21/2016 05:39 PM, Petr Lautrbach wrote: >> xmodmap causes Xephyr X server to reset itself when it's run before wm >> and even right after wm. It causes termination of the server as we use >> -terminate. The -terminate option seems be important

Re: [PATCH v2] sandbox: Use GObject introspection binding instead of pygtk2

2016-09-21 Thread Stephen Smalley
On 09/19/2016 02:01 PM, Laurent Bigonville wrote: > From: Petr Lautrbach > > sandbox command is also now using GTK 3.0 > > This patch comes from Fedora patch set > > Signed-off-by: Laurent Bigonville Thanks, applied. > --- >

Re: selinux 2.6-rc1 release planned 9/30

2016-09-21 Thread Stephen Smalley
On 09/21/2016 11:40 AM, William Roberts wrote: > I'd like to see the -r flip change in by then, so no official release > is cut with that behavior. > > Also, I was looking at the help output for -r, and its quite > confusing, I cant tell if -r includes or omits, verbatim output: > > -r

Re: selinux 2.6-rc1 release planned 9/30

2016-09-21 Thread William Roberts
I'd like to see the -r flip change in by then, so no official release is cut with that behavior. Also, I was looking at the help output for -r, and its quite confusing, I cant tell if -r includes or omits, verbatim output: -r Include precompiled regular expressions in the output.

selinux 2.6-rc1 release planned 9/30

2016-09-21 Thread Stephen Smalley
Hi, We plan to cut a 2.6-rc1 release on 9/30. If you have any patches that you want included in 2.6, please post them to the list before then. Thanks. ___ Selinux mailing list Selinux@tycho.nsa.gov To unsubscribe, send email to