Re: [CentOS-devel] Making the redhat selinux-policy repository publicly available
Zdenek Pytela <[email protected]> Mon, 15 Apr 2024 16:39:06 +0200
| Newsgroups | gmane.linux.redhat.fedora.selinux,gmane.linux.centos.devel |
|---|---|
| Message-ID | <CAO4UijA_Ah6uLiL+yAkQspJUZr-MdXv1NBJq9BeuAH9XkBeibw@mail.gmail.com> |
--===============4813560287030257304== Content-Type: multipart/alternative; boundary="00000000000017fef00616239627" --00000000000017fef00616239627 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Fri, Jul 14, 2023 at 11:48=E2=80=AFAM Daan De Meyer <daan.j.demeyer@gmai= l.com> wrote: > > To get just the latest repository content, steps described by Troy > should work. Additionally, most of the upstream work is done in Fedora an= d > anyway every new commit should go to Fedora first, RHEL content is mostly= a > subset of Fedora, there are very few differences. > > Yes, but the differences might be crucial so it'd be great if we could > look at the repository containing the actual policy used in centos as > well. > I did not oppose the arguments, just commented on the current state and what was possible that time. Anyway, the change eventually happened and there is the c9s branch in the fedora-selinux/selinux-policy repository now. Thanks everybody for your patience. https://github.com/fedora-selinux/selinux-policy/tree/c9s > > Cheers, > > Daan > > On Wed, 12 Jul 2023 at 16:16, Zdenek Pytela <[email protected]> wrote: > > > > > > > > On Tue, Jul 11, 2023 at 10:37=E2=80=AFPM Troy Dawson <[email protected]= m> wrote: > >> > >> On Tue, Jul 11, 2023 at 12:50=E2=80=AFPM Neal Gompa <[email protected]= m> wrote: > >>> > >>> On Tue, Jul 11, 2023 at 9:31=E2=80=AFAM Troy Dawson <[email protected]= om> > wrote: > >>> > > >>> > On Tue, Jul 11, 2023 at 4:28=E2=80=AFAM Daan De Meyer < > [email protected]> wrote: > >>> >> > >>> >> Hi, > >>> >> > >>> >> It seems that the selinux-policy rpm is built from > >>> >> [email protected]:SELinux/selinux-policy.git which seems > to be > >>> >> a redhat internal repository. More specifically, if I try to > checkout > >>> >> the commit listed in the selinux-policy spec > >>> >> ( > https://gitlab.com/redhat/centos-stream/rpms/selinux-policy/-/blob/c9s/se= linux-policy.spec#L3 > ) > >>> >> in the fedora-selinux repository cloned from github, I get an erro= r > >>> >> saying that the commit does not exist. It would be great if the > >>> >> repository containing this commit was publicly available and open > for > >>> >> external contributors just like all the other packages in CentOS > >>> >> Stream. Is it possible to make this happen? > >>> > > >>> > > >>> > I'm not the selinux-policy maintainer, so I can't comment on where > they work on the selinux-policy source code. > >>> > > >>> > But this is how I get the sources, if that is what you are > ultimately looking for. > >>> > > >>> > centpkg clone selinux-policy > >>> > cd selinux-policy > >>> > centpkg sources > >>> > or if you want to know where they really are > >>> > centpkg -v sources > >>> > This shows it to be coming from > >>> > > https://sources.stream.centos.org/sources/rpms/selinux-policy/selinux-pol= icy-66a4b6e.tar.gz/sha512/797e746ccd271fe531a91b2639aed06447fb2720267dadba2= 25989d81634b1fb7b2a4e78262612a41b6073f6e0eca358b8c274adc33630cd3f0db1390cd5= 7767/selinux-policy-66a4b6e.tar.gz > >>> > > >>> > The sources information is found in the sources file > >>> > > https://gitlab.com/redhat/centos-stream/rpms/selinux-policy/-/blob/c9s/so= urces > >>> > > >>> > I know this isn't exactly what you asked for, but I hope it still > helps. > >>> > > >>> > >>> I think the idea is that having the Git repository in a public > >>> location would allow the CentOS Hyperscale SIG to contribute to the > >>> SELinux policy in a meaningful way. > >> > >> > >> Ah, ok. That makes sense. > >> As I said, I'm not the maintainer so I don't know why it's where it > is. So I'll step out of the conversation. > > > > > > Hi, > > > > I am one of the selinux-policy maintainers. Currently, repository for > Fedora is at github.com and RHEL sources are in an internal repo. We have > already discussed moving centos stream sources to some of the public > repositories, but it did not happen. Currently we are discussing it again= , > there are a few options how to do so. > > > > To get just the latest repository content, steps described by Troy > should work. Additionally, most of the upstream work is done in Fedora an= d > anyway every new commit should go to Fedora first, RHEL content is mostly= a > subset of Fedora, there are very few differences. > > > > -- > > > > Zdenek Pytela > > Security SELinux team > > _______________________________________________ > > selinux mailing list -- [email protected] > > To unsubscribe send an email to [email protected] > > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > > List Archives: > https://lists.fedoraproject.org/archives/list/[email protected]= .org > > Do not reply to spam, report it: > https://pagure.io/fedora-infrastructure/new_issue > > --=20 Zdenek Pytela Security SELinux team --00000000000017fef00616239627 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote">= <div dir=3D"ltr" class=3D"gmail_attr">On Fri, Jul 14, 2023 at 11:48=E2=80= =AFAM Daan De Meyer <<a href=3D"mailto:[email protected]">daan.j.= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quote"= style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);p= adding-left:1ex">> To get just the latest repository content, steps desc= ribed by Troy should work. Additionally, most of the upstream work is done = in Fedora and anyway every new commit should go to Fedora first, RHEL conte= nt is mostly a subset of Fedora, there are very few differences.<br> <br> Yes, but the differences might be crucial so it'd be great if we could<= br> look at the repository containing the actual policy used in centos as<br> well.<br></blockquote><div>I did not oppose the arguments, just commented o= n the current state and what was possible that time.</div><div><br></div><d= iv>Anyway, the change eventually happened and there is the c9s branch in t= he fedora-selinux/selinux-policy repository now.</div><div>Thanks everybody= for your patience.</div><div><br></div><div><a href=3D"https://github.com/= fedora-selinux/selinux-policy/tree/c9s">https://github.com/fedora-selinux/s= elinux-policy/tree/c9s</a></div><div><br></div><div>=C2=A0<br></div><blockq= uote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1p= x solid rgb(204,204,204);padding-left:1ex"> <br> Cheers,<br> <br> Daan<br> <br> On Wed, 12 Jul 2023 at 16:16, Zdenek Pytela <<a href=3D"mailto:zpytela@r= edhat.com" target=3D"_blank">[email protected]</a>> wrote:<br> ><br> ><br> ><br> > On Tue, Jul 11, 2023 at 10:37=E2=80=AFPM Troy Dawson <<a href=3D"ma= ilto:[email protected]" target=3D"_blank">[email protected]</a>> wrote= :<br> >><br> >> On Tue, Jul 11, 2023 at 12:50=E2=80=AFPM Neal Gompa <<a href=3D= "mailto:[email protected]" target=3D"_blank">[email protected]</a>> wr= ote:<br> >>><br> >>> On Tue, Jul 11, 2023 at 9:31=E2=80=AFAM Troy Dawson <<a hre= f=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>>= ; wrote:<br> >>> ><br> >>> > On Tue, Jul 11, 2023 at 4:28=E2=80=AFAM Daan De Meyer <= ;<a href=3D"mailto:[email protected]" target=3D"_blank">daan.j.demey= [email protected]</a>> wrote:<br> >>> >><br> >>> >> Hi,<br> >>> >><br> >>> >> It seems that the selinux-policy rpm is built from<br= > >>> >> [email protected]:SELinux/selinux-policy.git = which seems to be<br> >>> >> a redhat internal repository. More specifically, if I= try to checkout<br> >>> >> the commit listed in the selinux-policy spec<br> >>> >> (<a href=3D"https://gitlab.com/redhat/centos-stream/r= pms/selinux-policy/-/blob/c9s/selinux-policy.spec#L3" rel=3D"noreferrer" ta= rget=3D"_blank">https://gitlab.com/redhat/centos-stream/rpms/selinux-policy= /-/blob/c9s/selinux-policy.spec#L3</a>)<br> >>> >> in the fedora-selinux repository cloned from github, = I get an error<br> >>> >> saying that the commit does not exist. It would be gr= eat if the<br> >>> >> repository containing this commit was publicly availa= ble and open for<br> >>> >> external contributors just like all the other package= s in CentOS<br> >>> >> Stream. Is it possible to make this happen?<br> >>> ><br> >>> ><br> >>> > I'm not the selinux-policy maintainer, so I can't= comment on where they work on the selinux-policy source code.<br> >>> ><br> >>> > But this is how I get the sources, if that is what you ar= e ultimately looking for.<br> >>> ><br> >>> >=C2=A0 =C2=A0centpkg clone selinux-policy<br> >>> >=C2=A0 =C2=A0cd selinux-policy<br> >>> >=C2=A0 =C2=A0centpkg sources<br> >>> > or if you want to know where they really are<br> >>> >=C2=A0 =C2=A0centpkg -v sources<br> >>> > This shows it to be coming from<br> >>> > <a href=3D"https://sources.stream.centos.org/sources/rpms= /selinux-policy/selinux-policy-66a4b6e.tar.gz/sha512/797e746ccd271fe531a91b= 2639aed06447fb2720267dadba225989d81634b1fb7b2a4e78262612a41b6073f6e0eca358b= 8c274adc33630cd3f0db1390cd57767/selinux-policy-66a4b6e.tar.gz" rel=3D"noref= errer" target=3D"_blank">https://sources.stream.centos.org/sources/rpms/sel= inux-policy/selinux-policy-66a4b6e.tar.gz/sha512/797e746ccd271fe531a91b2639= aed06447fb2720267dadba225989d81634b1fb7b2a4e78262612a41b6073f6e0eca358b8c27= 4adc33630cd3f0db1390cd57767/selinux-policy-66a4b6e.tar.gz</a><br> >>> ><br> >>> > The sources information is found in the sources file<br> >>> > <a href=3D"https://gitlab.com/redhat/centos-stream/rpms/s= elinux-policy/-/blob/c9s/sources" rel=3D"noreferrer" target=3D"_blank">http= s://gitlab.com/redhat/centos-stream/rpms/selinux-policy/-/blob/c9s/sources<= /a><br> >>> ><br> >>> > I know this isn't exactly what you asked for, but I h= ope it still helps.<br> >>> ><br> >>><br> >>> I think the idea is that having the Git repository in a public= <br> >>> location would allow the CentOS Hyperscale SIG to contribute t= o the<br> >>> SELinux policy in a meaningful way.<br> >><br> >><br> >> Ah, ok.=C2=A0 That makes sense.<br> >> As I said, I'm not the maintainer so I don't know why it&#= 39;s where it is.=C2=A0 So I'll step out of the conversation.<br> ><br> ><br> > Hi,<br> ><br> > I am one of the selinux-policy maintainers. Currently, repository for = Fedora is at <a href=3D"http://github.com" rel=3D"noreferrer" target=3D"_bl= ank">github.com</a> and RHEL sources are in an internal repo. We have alrea= dy discussed moving centos stream sources to some of the public repositorie= s, but it did not happen. Currently we are discussing it again, there are a= few options how to do so.<br> ><br> > To get just the latest repository content, steps described by Troy sho= uld work. Additionally, most of the upstream work is done in Fedora and any= way every new commit should go to Fedora first, RHEL content is mostly a su= bset of Fedora, there are very few differences.<br> ><br> > --<br> ><br> > Zdenek Pytela<br> > Security SELinux team<br> > _______________________________________________<br> > selinux mailing list -- <a href=3D"mailto:[email protected].= org" target=3D"_blank">[email protected]</a><br> > To unsubscribe send an email to <a href=3D"mailto:selinux-leave@lists.= fedoraproject.org" target=3D"_blank">[email protected]<= /a><br> > Fedora Code of Conduct: <a href=3D"https://docs.fedoraproject.org/en-U= S/project/code-of-conduct/" rel=3D"noreferrer" target=3D"_blank">https://do= cs.fedoraproject.org/en-US/project/code-of-conduct/</a><br> > List Guidelines: <a href=3D"https://fedoraproject.org/wiki/Mailing_lis= t_guidelines" rel=3D"noreferrer" target=3D"_blank">https://fedoraproject.or= g/wiki/Mailing_list_guidelines</a><br> > List Archives: <a href=3D"https://lists.fedoraproject.org/archives/lis= t/[email protected]" rel=3D"noreferrer" target=3D"_blank">htt= ps://lists.fedoraproject.org/archives/list/[email protected]<= /a><br> > Do not reply to spam, report it: <a href=3D"https://pagure.io/fedora-i= nfrastructure/new_issue" rel=3D"noreferrer" target=3D"_blank">https://pagur= e.io/fedora-infrastructure/new_issue</a><br> <br> </blockquote></div><br clear=3D"all"><br><span class=3D"gmail_signature_pre= fix">-- </span><br><div dir=3D"ltr" class=3D"gmail_signature"><div dir=3D"l= tr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div>= <div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><br> Zdenek Pytela</div><div dir=3D"ltr">Security SELinux team</div></div></div>= </div></div></div></div></div></div></div></div></div></div></div></div> --00000000000017fef00616239627-- --===============4813560287030257304== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline LS0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc2VsaW51 eCBtYWlsaW5nIGxpc3QgLS0gc2VsaW51eEBsaXN0cy5mZWRvcmFwcm9qZWN0Lm9yZwpUbyB1bnN1 YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRvIHNlbGludXgtbGVhdmVAbGlzdHMuZmVkb3JhcHJvamVj dC5vcmcKRmVkb3JhIENvZGUgb2YgQ29uZHVjdDogaHR0cHM6Ly9kb2NzLmZlZG9yYXByb2plY3Qu b3JnL2VuLVVTL3Byb2plY3QvY29kZS1vZi1jb25kdWN0LwpMaXN0IEd1aWRlbGluZXM6IGh0dHBz Oi8vZmVkb3JhcHJvamVjdC5vcmcvd2lraS9NYWlsaW5nX2xpc3RfZ3VpZGVsaW5lcwpMaXN0IEFy Y2hpdmVzOiBodHRwczovL2xpc3RzLmZlZG9yYXByb2plY3Qub3JnL2FyY2hpdmVzL2xpc3Qvc2Vs aW51eEBsaXN0cy5mZWRvcmFwcm9qZWN0Lm9yZwpEbyBub3QgcmVwbHkgdG8gc3BhbSwgcmVwb3J0 IGl0OiBodHRwczovL3BhZ3VyZS5pby9mZWRvcmEtaW5mcmFzdHJ1Y3R1cmUvbmV3X2lzc3VlCg== --===============4813560287030257304==--