Re: [DSE-Dev] I've created secilc package, please sponsor

2014-05-12 Thread Laurent Bigonville
Le Mon, 12 May 2014 01:58:21 +0300, Victor Porton por...@narod.ru a écrit : 12.05.2014, 01:50, Laurent Bigonville bi...@debian.org: Le Mon, 12 May 2014 00:22:59 +0300, Victor Porton por...@narod.ru a écrit :  I also added (untested) code to automatically reload the policy on  

[DSE-Dev] On structure and installation of CIL modules

2014-05-12 Thread Victor Porton
I propose to split all CIL packages (not necessarily corresponding 1-1 to Debian packages) into two categories: 1. base policies; 2. additional modules. Installation of a base policy would create /etc/selinux/POLICY dir. Installation of additional modules would not create this dir. Each

Re: [DSE-Dev] Should I file a bug report?

2014-05-12 Thread Mika Pflüger
Hi, Victor Porton por...@narod.ru wrote: Binary policies should not be in /etc/ but in /var/ Could you elaborate why? Binary policy only changes due to administrator action, not when just running things. I'd usually expect data in /var to change during normal operation, and stuff in /etc only