All of lore.kernel.org
 help / color / mirror / Atom feed
* Questions regarding loadable policy modules
@ 2007-02-07 21:58 Dave Quigley
  2007-02-09 16:41 ` Christopher J. PeBenito
  0 siblings, 1 reply; 3+ messages in thread
From: Dave Quigley @ 2007-02-07 21:58 UTC (permalink / raw)
  To: selinux

Hello,
    I have a few questions about loadable policy modules in SELinux.
It has been mentioned before that certain policy language constructs
can't be used within a loadable policy module. Is there a list
somewhere for what these are? Also, I am looking through the reference
policy and I am trying to understand how the build process treats
policy marked with module in modules.conf. I have read through the
section on the reference policy in SELinux by Example and it mainly
describes a Monolithic policy build. The main question I have about
using a modular policy is what in the system is responsible for making
sure the proper modules are loaded if you use this method? My final
question is what exactly are the semantics and implementation details
of the policy_module keyword and what ramifications are there for
having your policy consist of many policy modules. I know each file in
the reference policy has a policy_module macro at the beginning but I
am talking about on a much finer granularity that currently exists.
Does the policy_module keyword provide some sort of isolation for a
module?

Dave Quigley

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2007-02-09 18:20 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2007-02-07 21:58 Questions regarding loadable policy modules Dave Quigley
2007-02-09 16:41 ` Christopher J. PeBenito
2007-02-09 18:20   ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.