Re: [PATCH] README.md: Further elaboration on minimum policy versions

Thiébaud Weksteen <[email protected]>
Newsgroups org.kernel.vger.selinux
Message-ID <CA+zpnLcjJcEAUJJcHT9euu266WE++dFmC7-ukGisPTfa4nb04w@mail.gmail.com>
On Fri, Aug 14, 2026 at 6:01 AM Stephen Smalley
<[email protected]> wrote:
>
> Provide further elaboration on minimum policy versions and
> considerations when updating them.
>
> Signed-off-by: Stephen Smalley <[email protected]>
> ---
>  README.md | 59 +++++++++++++++++++++++++++++++++++++++++++++----------
>  1 file changed, 49 insertions(+), 10 deletions(-)
>
> diff --git a/README.md b/README.md
> index bfd32b89..a2427bb4 100644
> --- a/README.md
> +++ b/README.md
> @@ -25,8 +25,9 @@ for more information.
>
>  Minimum Supported Kernel Version
>  --------------------------------
> -Linux v3.0 (for /sys/fs/selinux mount point directory) for libselinux
> -and anything that uses libselinux to access selinuxfs.
> +The minimum supported kernel version is Linux v3.0 (for the
> +/sys/fs/selinux mount point directory) for libselinux and anything
> +that uses libselinux to access selinuxfs.
>
>  Note that the policy build toolchain (e.g. libsepol, checkpolicy,
>  checkmodule, secilc, semodule_package/expand/link) does not link with
> @@ -35,18 +36,56 @@ Linux kernel version. The policy build toolchain has in the past
>  successfully been built and run on non-Linux platforms as well
>  (e.g. macOS), although this is not officially supported.
>
> -Minimum Supported Policy Version
> ---------------------------------
> -Kernel policy version 24 (boundary) for the SELinux and Xen
> -targets. Support for this policy version first shipped in libsepol
> +Minimum Supported Policy Versions
> +---------------------------------
> +The minimum kernel policy version is 24 (boundary) for the SELinux and
> +Xen targets. Support for this policy version first shipped in libsepol
>  2.0.34 (userspace release 20090403), Linux v2.6.28, and Xen
>  4.0.0. libsepol dropped support for kernel policy versions older than
>  24 starting with libsepol 3.12.
>
> -Modular policy version 10 (boundary alias). Support for this modular
> -policy version first shipped in libsepol 2.0.35 (userspace release
> -20090403). libsepol dropped support for modular policies older than 10
> -starting with libsepol 3.12
> +The minimum modular policy version is 10 (boundary alias). Support for
> +this modular policy version first shipped in libsepol 2.0.35
> +(userspace release 20090403). libsepol dropped support for modular
> +policies older than 10 starting with libsepol 3.12
> +
> +These minimum policy versions in libsepol affect:
> +1. The policy build toolchain. For example, checkpolicy, checkmodule,
> +and secilc cannot generate a policy with a version less than the
> +minimum.
> +2. libselinux and its users. For example, libselinux cannot downgrade a
> +policy file to a version less than the minimum, and libsemanage cannot
> +read a binary policy module that was compiled with a version less than
> +the minimum.
> +3. SELinux policy analysis tools. For example, setools cannot read a
> +policy with a version less the minimum.
> +4. The Xen hypervisor, which compiles its XSM/Flask policies using
> +checkpolicy, and only currently supports kernel policy versions 24 and
> +30 for the Xen target. Xen does not use binary policy modules so it is
> +unaffected by changes to the minimum modular policy version.
> +5. Android, which has remained on kernel policy version 30 since
> +moving to it since it has not needed any of the newer policy version

nit: double "since" here. Maybe something like:

Android, which is on kernel policy version 30. There has not been any
need for newer policy version features yet.

Link to our build configuration, if that helps:
https://cs.android.com/android/platform/superproject/+/android-latest-release:system/sepolicy/build/soong/policy.go;l=31

> +features yet. Android does not use binary policy modules so it is
> +unaffected by changes to the minimum modular policy version.

Acked-by: Thiébaud Weksteen <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.