All of lore.kernel.org
 help / color / mirror / Atom feed
From: Stephen Smalley <sds@tycho.nsa.gov>
To: selinux@tycho.nsa.gov
Subject: Updated SELinux Release
Date: Wed, 07 Sep 2005 12:23:21 -0400	[thread overview]
Message-ID: <1126110201.14896.80.camel@moss-spartans.epoch.ncsc.mil> (raw)
In-Reply-To: <1119466630.13181.175.camel@moss-spartans.epoch.ncsc.mil>

An updated SELinux release is available from the NSA SELinux web site;
see http://www.nsa.gov/selinux/news.cfm#R050907.

This SELinux release is based on Linux 2.6.13.  The 2.6.13 kernel
includes the execstack and execheap permission checks contributed by
Lorenzo and the support for default labeling of the MLS field by James
Morris.  The SELinux kernel patch for 2.6.13 includes support for atomic
security labeling of new inodes (for ext2, ext3, tmpfs only at present),
a generic VFS fallback for getting and setting security attributes on
filesystems that do not natively support EAs, and memory optimizations
for the policy's avtab.  Several of these changes have already been
upstreamed into Linus' git tree while others remain pending in the -mm
patchset.

In userspace, a number of enhancements to the libraries and utilities
have been merged.  These enhancements include the support for the new
binary policy version with the optimized avtab, a number of improvements
in abstraction and organization within libsepol by Ivan Gyurdiev, the
loadable policy module support by Tresys Technology (affecting libsepol,
checkpolicy, policycoreutils and adding libsemanage), and the context
translation support in libselinux based on work by Trusted Computer
Solutions and Red Hat.  Numerous bug fixes have also been merged, many
submitted by Serge Hallyn of IBM based on bugs discovered using the
Coverity tool.

With regard to the new binary policy version, checkpolicy -c 19 can be
used to generate the prior binary policy version for kernels that do not
yet have the necessary support.  As usual, both the SELinux module and
checkpolicy/libsepol provide backward compatibility for older binary
policy versions.

With regard to the policy module support, selinux-doc/README.MODULES has
some basic documentation of the module support, but further
documentation and man pages will be needed.  Note that libsemanage is
currently only available as a static library and limited to managing
policy modules (due to its origins as libsemod); it will be expanded in
the future to provide a more complete policy management API and to
provide a shared library with a stable API/ABI.

In this release, we have also stopped carrying copies of setools, slat,
and polgen on nsa.gov itself, but continue to provide links to the
respective Tresys Technology and MITRE SELinux sites where the latest
versions can always be obtained.  This avoids having stale copies around
on nsa.gov and ensures that people always acquire the latest version.

-- 
Stephen Smalley
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2005-09-07 16:28 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-03-09 21:02 Updated SELinux Release Stephen Smalley
2005-06-22 18:57 ` Stephen Smalley
2005-09-07 16:23   ` Stephen Smalley [this message]
2005-12-07 20:28     ` ANN: " Stephen Smalley
  -- strict thread matches above, loose matches on Subject: below --
2005-01-07 20:59 Stephen Smalley
2004-11-03 15:39 Stephen Smalley
2004-11-03 18:19 ` Karl MacMillan
2004-11-03 19:21 ` Dhruv Gami
2004-11-04  2:15   ` Colin Walters
2004-11-04  7:02     ` Manoj Srivastava
2004-11-04 13:15       ` Luke Kenneth Casson Leighton
2004-11-05  4:06         ` Colin Walters
2004-11-05 10:28           ` Luke Kenneth Casson Leighton
2004-11-05 15:11             ` Colin Walters
2004-11-05 15:51               ` Stephen Smalley
2004-11-05 15:57               ` Luke Kenneth Casson Leighton
2004-11-05 21:01                 ` Colin Walters
2005-01-03 12:53                 ` Russell Coker
2005-01-03 14:47                   ` Lorenzo Hernández García-Hierro
2004-11-05 12:29           ` Stephen Smalley
2004-11-04 14:35       ` Stephen Smalley
2004-11-04 15:38       ` James Morris
2004-11-04 15:47         ` Stephen Smalley
2004-11-04 14:24   ` Stephen Smalley
2004-11-04  0:59 ` Manoj Srivastava
2004-11-04  3:37   ` Colin Walters
2004-11-04  6:57     ` Manoj Srivastava
2004-11-04 13:38     ` Stephen Smalley
2004-11-04 18:25       ` Christopher J. PeBenito
2004-11-04 18:25         ` Stephen Smalley
2004-11-04 13:33   ` Stephen Smalley
2004-08-19 19:01 Updated SELinux release Stephen Smalley

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1126110201.14896.80.camel@moss-spartans.epoch.ncsc.mil \
    --to=sds@tycho.nsa.gov \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.