Re: How is the upstream SELinux refpolicy tied into Fedora?

David Sommerseth <[email protected]> Fri, 31 Mar 2023 15:16:14 +0000
Newsgroups gmane.linux.redhat.fedora.selinux
Message-ID <[email protected]>
On 31/03/2023 17:08, Petr Lautrbach wrote:
> David Sommerseth <[email protected]> writes:
> 
>> On 31/03/2023 16:36, Neal Gompa wrote:
>>> On Fri, Mar 31, 2023 at 9:58 AM David Sommerseth <[email protected]> wrote:
>>>>
>>>>
>>>> Hi,
>>>>
>>>> I had an upstream SELinux pull-request merged in autumn 2020 [1].  But I
>>>> still don't see this SELinux boolean flag (renamed [2] to
>>>> "dbus_pass_tuntap_fd") present in Fedora 38.  So I wonder how the
>>>> SELinux refpolicy is consumed into Fedora's SELinux policies ... when
>>>> can I expect to see this in Fedora and RHEL SELinux policies?
>>>>
> 
> The best way is to create a bug with a request to backport a patch or
> create a PR on github.com/fedora-selinux/selinux-policy

Alright, I'll wrap up a patch and pull-req for fedora-selinux too.

But for OpenVPN 3 Linux I do have an additional policy for a few of the 
D-Bus services as well.  Would it make sense to just keep them in the 
openvpn3-linux project, or should I try to get them to some more 
widespread SELinux reference policies?

Considering the discoveries of today, I'm kind a wondering if it's best 
to keep it how it is.  That way I can ensure it's available on all 
distributions with SELinux support more easily.  But I'm open to think 
differently.

[...snip...]

>> Maybe not the right place to ask ... but what is the purpose and goal of
>> the SELinux refpolicy project if several of the larger Linux
>> distributions doesn't pay attention to it?
>>
>> I kinda would expect that lots of the SELinux policy details in Fedora
>> would be pretty much the same challenges in other distributions as well.
>>
> 
> AFAIK refpolicy was more conservative while fedora-selinux was more
> focused on usability on desktop. They're still somehow compatible, they
> use same build process and backports from or to fedora-selinux still happen
> from time to time, but fedora-selinux is not considered as fork anymore.

Okay, good to know.  Is fedora-selinux specific to Fedora/RHEL only, or 
does other distributions also use this as their refpolicy?


-- 
kind regards,

David Sommerseth
OpenVPN Inc

_______________________________________________
selinux mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
signature.asc (application/pgp-signature, 855 B)
-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wsFzBAEBCAAnBQJkJvk9CZBTlzn2TPwK3RYhBIIvMc1tEJTA+m/9n1OXOfZM
/ArdAAAY4hAAgLDwiju4xOMrDhOn5LsoNO4AJiDKsQ/GCMffTWtIKleQzzit
bbGNoinC2kuDQjJymFP/zdi014VJEsRg45jZ/EGYbJWsS52mUnExcgx17Zhh
HxtvAMx5xtdC3z5hV8IhwsI4S336CAYZ/+ImtDvWI6ZN9/63J7JLTy8olOPN
nWHtob0JiH1gmVKp7YxPspeVh5RgGkW0R7U5BEb+M0g3lIinhexv5q7aU4yR
Acggr5rCcVYI3q6QNS9pME//IbEKL1FK8m2ZCtC6f2XMPsh8g7Elf+La0Xag
IXQVir16JFcaA5ZjGe3q2s88f72PxvV7KPXQwEmjBVEW/95xF3LeDrDXQF1Q
iG3/hYt3zrySAGD4CWqc0W3kdxwhI+2ATJdq5NEn2TK/5367hZwkTosA7GMf
woXQSbAv2rhXIp+UA3zS4Qu1TQniUioGcEZyDYj6AL1SV/o5enI4T3z94ST+
YHZSE0q/6OqR3sCU6uURk0mz4SU163Lj//asch9ElaeSgkkcRTDDwF3bKly1
Zgjpq9XfDGNY8pmatiTly23TuSSPl/eikpzMj7yNyPS5AOJqbpVAy2rYzgIE
YuQMUiHaMJmyZbSuN191WqMkMo6lH55KenQ8g/EK1tRTpRtCatGEF4r2fzt8
p6kg90iYn89A1suITvlaJ/7aHl5gHaIrk7s=
=X/gl
-----END PGP SIGNATURE-----