Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <sven.vermeulen@××××××.be>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Cleanup of sec-policy (old ebuilds)
Date: Sun, 27 Feb 2011 13:25:02
Message-Id: 20110227132326.GA10007@siphos.be
1 Hi all,
2
3 The current sec-policy category contains many old ebuilds for old and
4 obsoleted SELinux policies. In my opinion, it would be better if we purge
5 them so that only those based on the 20101213 refpolicy remain (and for
6 those, only a limited set).
7
8 My general idea on purging ebuilds is to drop all stable ebuilds except the
9 latest stable, and to drop all ~arch ebuilds except the last two or so.
10
11 I know the current stable ones might not even function well, but dropping
12 all stables might result in dependencies being broken for existing users
13 (even if they run in permissive mode, it would cause Portage to fail
14 installing master packages that depend on a SELinux policy...
15
16 I don't mind drafting a script or patch that does this, but if a developer
17 sais he doesn't need a patch it'll save me quite some time :-) Also, if you
18 just prefer a list of ebuilds to keep (for each package) that's fine too,
19 but in that case don't forget to clean the files/ folder too.
20
21 Wkr,
22 Sven Vermeulen

Replies

Subject Author
Re: [gentoo-hardened] Cleanup of sec-policy (old ebuilds) "Anthony G. Basile" <blueness@g.o>