Gentoo Archives: gentoo-dev

From: "Anthony G. Basile" <blueness@g.o>
To: Gentoo Development <gentoo-dev@l.g.o>
Subject: [gentoo-dev] Adding a new selinux profile to default/linux/{amd64,x86}/10.0
Date: Wed, 07 Dec 2011 14:08:40
Hi everyone,

Some time ago the selinux team restructured the selinux profiles and
made a features/selinux which could be stacked on the hardened profiles
for x86/amd64.  At that time I also tested and found that it stacked
fine on default/linux/{amd64,x86}/10.0.  I'm emailing the list to see if
there's any reason why we shouldn't add
default/linux/{amd64,x86}/10.0/selinux.  Currently I prefer adding it
directly to 10.0 rather than 10.0/server because the status of the later
is uncertain.  Selinux on the desktops is not being strongly supported
so its not appropriate there either, leaving only 10.0/selinux.  If
added eselect profile list would show

  [1]   default/linux/amd64/10.0
  [2]   default/linux/amd64/10.0/selinux
  [3]   default/linux/amd64/10.0/desktop
  [4]   default/linux/amd64/10.0/desktop/gnome
  [5]   default/linux/amd64/10.0/desktop/kde
  [6]   default/linux/amd64/10.0/developer
  [7]   default/linux/amd64/10.0/no-multilib
  [8]   default/linux/amd64/10.0/server
  [9]   hardened/linux/amd64 *
  [10]   hardened/linux/amd64/selinux
  [11]  hardened/linux/amd64/no-multilib
  [12]  hardened/linux/amd64/no-multilib/selinux

Any objections?

Anthony G. Basile, Ph.D.
Gentoo Linux Developer [Hardened]
E-Mail    : blueness@g.o
GnuPG FP  : 8040 5A4D 8709 21B1 1A88  33CE 979C AF40 D045 5535
GnuPG ID  : D0455535