Research Menu

.
Skip Search Box

SELinux Mailing List

Re: [RFC & PATCH] inherited type definition.

From: Stephen Smalley <sds_at_tycho.nsa.gov>
Date: Mon, 18 Apr 2005 08:25:45 -0400


On Sat, 2005-04-16 at 16:31 +0900, KaiGai Kohei wrote:
> How is the current status of inheritable-type patch ?
> Can I think that we can use such statements checkpolicy-1.24 or later ?
> Please, don't forget. :-)
>
> I modified the latest patch against to checkpolicy-1.23.1 on Fedora's CVS.
> Since there is only one FAILED hunk on checkpolicy.c:518, I modified this.

Hi,

Thanks for updating the patch. However, from the discussions on the list, I haven't seen any clear indication that this new language feature:
a) solves a real problem in a superior manner to the use of macros, and b) is being demanded by people who are presently developing policy.

I'm willing to be convinced otherwise, but I just haven't seen the evidence for it yet. Have you considered working on a template feature for the language instead, as that clearly would be beneficial?

-- 
Stephen Smalley <sds@tycho.nsa.gov>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Mon 18 Apr 2005 - 08:38:47 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service