Research Menu

.
Skip Search Box

SELinux Mailing List

RE: Libsemanage dependency on version of Linux...

From: Hasan Rezaul-CHR010 <CHR010_at_motorola.com>
Date: Thu, 12 Jul 2007 15:48:11 -0400


Thanks Stephen,

So given the fact that I must use Linux Kernel 2.6.14 :

Are you saying that its okay for us to upgrade SELinux libs FROM the versions listed below TO the versions listed below while continuing to use Linux Kernel 2.6.14 ? In other words, the newer versions of the SELinux-related libs DON'T depend on the version of the Linux kernel ? I would like to upgrade the libs as described below, but I fear that the new libs versions may not work correctly with Linux 2.6.14.

Please confirm...

libsemanage-1.6.17-1     =>  libsemanage-1.10.4
checkpolicy-1.33.1-2     =>  checkpolicy-1.34.3-x
libsepol-1.15.3-1        =>  libsepol-1.16.3-x
libselinux-1.33.4-2      =>  libselinux-1.34.10-x
policycoreutils-1.34.1-4 => policycoreutils-1.34.10-x

Thanks,

  • Rezaul.

-----Original Message-----
From: Stephen Smalley [mailto:sds@tycho.nsa.gov] Sent: Thursday, July 12, 2007 2:40 PM
To: Hasan Rezaul-CHR010
Cc: SE Linux
Subject: Re: Libsemanage dependency on version of Linux...

On Thu, 2007-07-12 at 15:03 -0400, Hasan Rezaul-CHR010 wrote:
> Hi All,
>
> I currently am running on Linux 2.6.14, and I have
> libsemanage-1.6.17-1
>
> After discussing with Stephen Smalley, I learned that in order for
> semanage to NOT create a "/previous" directory, I need to upgrade my
> libsemanage library to version 1.9.2 or higher.
>
> My question is: is libsemanage version 1.9.2 dependent on a Linux
> version newer than Linux 2.6.14 ???
>
> What is the latest version of libsemanage that is supported in Linux
> version 2.6.14 ?
>
> Also, what are the latest versions of the following other libs
> supported by Linux 2.6.14 : ?
>
> checkpolicy
> libsepol
> libselinux
> Policycoreutils

Hi,

You should generally upgrade all of the core SELinux userland components together to be safe, but newer versions of the SELinux core userland should work fine on older kernels (at least for the stable branch).

You may wish to set the policy-version in your /etc/selinux/semanage.conf file though to make sure that it is generating the right policy version for your kernel (as reported by cat /selinux/policyvers), especially if you are using an older SysVinit that doesn't use the newer policy loading logic with automatic downgrading.

-- 
Stephen Smalley
National Security Agency



--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 12 Jul 2007 - 15:48:19 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service