{"thread":{"id":"15055","subject":"SeLinux integration","startedAt":"2008-08-17T10:44:22Z","lastAt":"2008-08-18T14:29:47Z","messageCount":7,"participants":["Jens Neuhalfen","Christian Jaeger","Björn Steinbrink","Petr Baudis","David P. Quigley"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"87429","messageId":"6341D084-1A83-4C0F-8C45-943916612D48@gmx.de","threadId":"15055","inReplyTo":null,"subject":"SeLinux integration","fromName":"Jens Neuhalfen","fromEmail":"jensneuhalfen@gmx.de","sentAt":"2008-08-17T10:44:22Z","receivedAt":"2008-08-17T10:44:22Z","isPatch":false,"sender":{"key":"jensneuhalfen@gmx.de","avatar":null},"body":"Hi,\n\nI  wrote an SeLinux policy and an init.d script  for the git-daemon  \nand now seek for comments and improvements.\n\nThe scripts were tested on my Centos 5.2 box  and an older version had  \nbeen tested on FC 9.\n\n  Features:\n    * multiple configuration files for the init.d script\n    * selinux support for git daemon\n    * seboolean (git_daemon_update_repository) that forces git-daemon  \ninto strict read-only mode when set to false\n\nTODO\n  * The policy and the accompanying init.d script still lack  \ndocumentation\n  * see selinux/BUGS and initd/BUGS\n\nFeel free to pull from my repository and comment. If the everything is  \n'good' I will send patches to the list, so that SeLinux support can be  \nintegrated into the main repository.\n\n\n  git://www.neuhalfen.name/git-selinux.git\n\n\nJens\n"},{"id":"87520","messageId":"48A93696.6010500@jaeger.mine.nu","threadId":"15055","inReplyTo":"6341D084-1A83-4C0F-8C45-943916612D48@gmx.de","subject":"Re: SeLinux integration","fromName":"Christian Jaeger","fromEmail":"christian@jaeger.mine.nu","sentAt":"2008-08-18T08:45:10Z","receivedAt":"2008-08-18T08:45:10Z","isPatch":false,"sender":{"key":"christian@jaeger.mine.nu","avatar":null},"body":"Jens Neuhalfen wrote:\n> git://www.neuhalfen.name/git-selinux.git\n\nI'm just an end user, too, so this isn't representing any official \nstatement, but imho you should clean up your history before you publish \nit (and also, I think it would be a good idea to mention that your git \nrepo is really including the upstream git so that people know they \nshould use the --reference option to git clone to reuse the contents of \na local upstream git to avoid pulling everything from your server):\n\n- remove commits that don't make sense like your \"XXX\" file\n- generally look over your history again and rework it so that it makes \nsense for a receiver (which is not necessarily the historic events of \nhow you wrote it)\n- follow the common commit message format (one line subject, the rest in \nthe body and line wrapped)\n- probably there's no reason to merge your history with historic events \nof the upstream git, so you should rebase your history onto some point \nof upstream.\n\nYou can do this by running\n\ngit branch last_upstream 053fd0c1c3da20474c4ff175c56ea4c1d6eeda11\ngit rebase --interactive last_upstream\n\n(or alternatively (with the advantage that you can open and edit all \npatches at the same time, but the disadvantage that editing diffs is \nmore difficult to get right than editing files in snapshots), by first \ncreating patch files by running:\n\ngit format-patch master...last_upstream\n\nthen editing the patch files (and remove those which don't make sense) \nand then switch to the upstream branch and run \"git-am --3way 00*patch\", \nor replace 00*patch with the patch files in the order you want them \napplied).\n\nChristian.\n"},{"id":"87533","messageId":"1219060960.13808.20.camel@desktop.local.neuhalfen.name","threadId":"15055","inReplyTo":"48A93696.6010500@jaeger.mine.nu","subject":"Re: SeLinux integration","fromName":"Jens Neuhalfen","fromEmail":"jensneuhalfen@gmx.de","sentAt":"2008-08-18T12:02:39Z","receivedAt":"2008-08-18T12:02:39Z","isPatch":false,"sender":{"key":"jensneuhalfen@gmx.de","avatar":null},"body":"> Jens Neuhalfen wrote:\n> > git://www.neuhalfen.name/git-selinux.git\n> \n\n\nHi Christian,\n\n> I'm just an end user, too, so this isn't representing any official \n...\n\nfirst, thank you for your taking your time! I am relatively new to git (I've been poking git for three or four weeks now), so your advice on how-to (and how-not-to) is much appreciated.\n\nThe repository is my current development repository which, naturally (?), is based on the 'blessed' repository. My understanding of git was, that anyone with a copy of the blessed git repository can 'pull' from my repository and gets my branches with git transmitting just my changes over the net. Then he/she/it can switch to 'my' branch and test the policy/init-script.\n\nDid I get something wrong there? I thought that this is a/the normal way of using git. \n\nYou are right with the commits and their rather terse messages, though the code are not ready for release or an integration review. The plan was: Get some feedback on the current state, refine the code and then send the patches to the list. \n\nChristian, have you been able to test the policy? I am very curious, how it works on other machines (say, gentoo) or with other setups (strict-policy is completely untested, although I don't think that anyone really uses it).\n\nJens\n\n\n> Christian.\n"},{"id":"87535","messageId":"48A96F51.6090404@jaeger.mine.nu","threadId":"15055","inReplyTo":"1219060960.13808.20.camel@desktop.local.neuhalfen.name","subject":"Re: SeLinux integration","fromName":"Christian Jaeger","fromEmail":"christian@jaeger.mine.nu","sentAt":"2008-08-18T12:47:13Z","receivedAt":"2008-08-18T12:47:13Z","isPatch":false,"sender":{"key":"christian@jaeger.mine.nu","avatar":null},"body":"Jens Neuhalfen wrote:\n> The repository is my current development repository which, naturally (?), is based on the 'blessed' repository. My understanding of git was, that anyone with a copy of the blessed git repository can 'pull' from my repository and gets my branches with git transmitting just my changes over the net. Then he/she/it can switch to 'my' branch and test the policy/init-script.\n>\n> Did I get something wrong there? I thought that this is a/the normal way of using git. \n>   \n\nWell I'm sure you could use it this way; but check for yourself, if you \nstart gitk on your repository, one has to first figure out where to find \nyou work, i.e. one has to follow the right parent in your commits to see \nall of them; it's certainly possible but I guess not very inviting for \npeople who just want to *look* at your work (as opposed to simply try it \nout). I'll readily admit that I just wanted to look, not try it out. But \nmaybe I'm not the only one with this as his/her primary aim.\n\n> You are right with the commits and their rather terse messages, though the code are not ready for release or an integration review. The plan was: Get some feedback on the current state, refine the code and then send the patches to the list. \n>   \n\nOk, maybe how you're doing it is just fine, I'll leave it to others to \njudge. But still you should be aware that it's common practice with Git \nto first clean up private history before publishing it. The history can \nexplain the code much better than is possible by just looking at the \nlatest committed version, and since with Git it is possible to rework \nthe history as long at it is private, people frequently do it, so that \nthe readers can get most out of it. (This is more akin to patch sets, \nwhere each patch does a certain thing -- versus work steps, which \ndocuments how you created the changes. The latter documentation is \nreally only of interest for you, for others it's the intended changes \nwhich matter. So you could \"git branch my_selinux_prepublish_1\" to keep \nthe latter history in case you want to look at it again later, then do \nthe history cleanup as I've suggested and publish that instead. And \ncontinue to work on that reworked branch, actually.)\n\n> Christian, have you been able to test the policy? I am very curious, how it works on other machines (say, gentoo) or with other setups (strict-policy is completely untested, although I don't think that anyone really uses it).\n\nI don't have any SELinux setup here. I'm playing with the thought of \nlooking into it, that's why the subject of your mail has catched my \nattention.\n\nThanks,\nChristian.\n"},{"id":"87536","messageId":"20080818130454.GA908@atjola.homenet","threadId":"15055","inReplyTo":"48A96F51.6090404@jaeger.mine.nu","subject":"Re: SeLinux integration","fromName":"Björn Steinbrink","fromEmail":"b.steinbrink@gmx.de","sentAt":"2008-08-18T13:04:54Z","receivedAt":"2008-08-18T13:04:54Z","isPatch":false,"sender":{"key":"b.steinbrink@gmx.de","avatar":"https://avatars.githubusercontent.com/u/230962?v=4"},"body":"On 2008.08.18 14:47:13 +0200, Christian Jaeger wrote:\n> Jens Neuhalfen wrote:\n>> The repository is my current development repository which, naturally\n>> (?), is based on the 'blessed' repository. My understanding of git\n>> was, that anyone with a copy of the blessed git repository can 'pull'\n>> from my repository and gets my branches with git transmitting just my\n>> changes over the net. Then he/she/it can switch to 'my' branch and\n>> test the policy/init-script.\n>>\n>> Did I get something wrong there? I thought that this is a/the normal \n>> way of using git.   \n>\n> Well I'm sure you could use it this way; but check for yourself, if you  \n> start gitk on your repository, one has to first figure out where to find  \n> you work, i.e. one has to follow the right parent in your commits to see  \n> all of them; it's certainly possible but I guess not very inviting for  \n> people who just want to *look* at your work (as opposed to simply try it  \n> out). I'll readily admit that I just wanted to look, not try it out. But  \n> maybe I'm not the only one with this as his/her primary aim.\n\nWell, instead of using --reference, I would just add a \"selinux\" remote\nto my existing git.git repo, fetch the stuff and then:\n\ngitk origin/master..selinux/master\n\nIt's still not \"pretty\", but quite usable. And as far as I'm concerned,\nit's kinda obvious that the git-selinux repo is based on the git.git\nrepo, so I wouldn't say that you're required to mention that explicitly.\n\nBjörn\n"},{"id":"87537","messageId":"20080818133200.GF10544@machine.or.cz","threadId":"15055","inReplyTo":"6341D084-1A83-4C0F-8C45-943916612D48@gmx.de","subject":"Re: SeLinux integration","fromName":"Petr Baudis","fromEmail":"pasky@suse.cz","sentAt":"2008-08-18T13:32:00Z","receivedAt":"2008-08-18T13:32:00Z","isPatch":false,"sender":{"key":"pasky@ucw.cz","avatar":"https://avatars.githubusercontent.com/u/18439?v=4"},"body":"  Hi,\n\nOn Sun, Aug 17, 2008 at 12:44:22PM +0200, Jens Neuhalfen wrote:\n>  git://www.neuhalfen.name/git-selinux.git\n\n  for the mildly curious ones, your friendly gitweb provider service\noffers\n\n\thttp://repo.or.cz/w/git/selinux.git\n\n\t\t\t\tPetr \"Pasky\" Baudis\n"},{"id":"87542","messageId":"1219069787.2609.86.camel@moss-terrapins.epoch.ncsc.mil","threadId":"15055","inReplyTo":"6341D084-1A83-4C0F-8C45-943916612D48@gmx.de","subject":"Re: SeLinux integration","fromName":"David P. Quigley","fromEmail":"dpquigl@tycho.nsa.gov","sentAt":"2008-08-18T14:29:47Z","receivedAt":"2008-08-18T14:29:47Z","isPatch":false,"sender":{"key":"dpquigl@tycho.nsa.gov","avatar":null},"body":"On Sun, 2008-08-17 at 12:44 +0200, Jens Neuhalfen wrote:\n> Hi,\n> \n> I  wrote an SeLinux policy and an init.d script  for the git-daemon  \n> and now seek for comments and improvements.\n> \n> The scripts were tested on my Centos 5.2 box  and an older version had  \n> been tested on FC 9.\n> \n>   Features:\n>     * multiple configuration files for the init.d script\n>     * selinux support for git daemon\n>     * seboolean (git_daemon_update_repository) that forces git-daemon  \n> into strict read-only mode when set to false\n> \n> TODO\n>   * The policy and the accompanying init.d script still lack  \n> documentation\n>   * see selinux/BUGS and initd/BUGS\n> \n> Feel free to pull from my repository and comment. If the everything is  \n> 'good' I will send patches to the list, so that SeLinux support can be  \n> integrated into the main repository.\n> \n> \n>   git://www.neuhalfen.name/git-selinux.git\n> \n> \n> Jens\n> \n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n\nHello,\n   It is great to see people other than the core policy developers\nworking on SELinux policy. One thing I would suggest is to post your\npolicy to the new reference policy mailing list for SELinux. This way\npeople such as Chris PeBenito and Dan Walsh can look over it and give\nsuggestions as well. You can find the list at the link below [1]. \n\n[1]http://oss.tresys.com/mailman/listinfo/refpolicy\n\nDave\n"}]}