All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] Refpolicy interface annotation guidelines
@ 2017-05-05 13:39 Christian Göttsche
  2017-05-06 16:35 ` Chris PeBenito
  0 siblings, 1 reply; 2+ messages in thread
From: Christian Göttsche @ 2017-05-05 13:39 UTC (permalink / raw)
  To: refpolicy

What are the guidelines whether and how to use (setools?) interface
annotations, like infoflow[1] or rolecap[2]?


[1]: https://github.com/TresysTechnology/refpolicy/blob/master/policy/modules/system/application.if#L108
[2]: https://github.com/TresysTechnology/refpolicy-contrib/blob/master/vnstatd.if#L170

^ permalink raw reply	[flat|nested] 2+ messages in thread

* [refpolicy] Refpolicy interface annotation guidelines
  2017-05-05 13:39 [refpolicy] Refpolicy interface annotation guidelines Christian Göttsche
@ 2017-05-06 16:35 ` Chris PeBenito
  0 siblings, 0 replies; 2+ messages in thread
From: Chris PeBenito @ 2017-05-06 16:35 UTC (permalink / raw)
  To: refpolicy

On 05/05/2017 09:39 AM, Christian G?ttsche via refpolicy wrote:
> What are the guidelines whether and how to use (setools?) interface
> annotations, like infoflow[1] or rolecap[2]?

For a long time, these tags have been intended for tools to leverage.  I 
think the old SLIDE tool was the only one that attempted to use it. 
SETools doesn't use it since it doesn't look at policy sources and has 
no knowledge of refpolicy interfaces.  I'm not explicitly looking for 
them, so it may be time to give up on the idea.


> [1]: https://github.com/TresysTechnology/refpolicy/blob/master/policy/modules/system/application.if#L108
> [2]: https://github.com/TresysTechnology/refpolicy-contrib/blob/master/vnstatd.if#L170



-- 
Chris PeBenito

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2017-05-06 16:35 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-05-05 13:39 [refpolicy] Refpolicy interface annotation guidelines Christian Göttsche
2017-05-06 16:35 ` Chris PeBenito

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.