diff options
author | Chris PeBenito <pebenito@gentoo.org> | 2003-05-22 20:20:23 +0000 |
---|---|---|
committer | Chris PeBenito <pebenito@gentoo.org> | 2003-05-22 20:20:23 +0000 |
commit | 88c123aa7fbd09dbd4ce34e2963e65acfb954e35 (patch) | |
tree | f0a731d7897a45786ef9cec18c70439c3665acea /sys-apps | |
parent | cleanup (diff) | |
download | historical-88c123aa7fbd09dbd4ce34e2963e65acfb954e35.tar.gz historical-88c123aa7fbd09dbd4ce34e2963e65acfb954e35.tar.bz2 historical-88c123aa7fbd09dbd4ce34e2963e65acfb954e35.zip |
Dep fix, /etc/security files moved to selinux-base-policy, new rlpkg script
Diffstat (limited to 'sys-apps')
-rw-r--r-- | sys-apps/selinux-small/ChangeLog | 11 | ||||
-rw-r--r-- | sys-apps/selinux-small/Manifest | 4 | ||||
-rw-r--r-- | sys-apps/selinux-small/files/digest-selinux-small-2003040709-r2 | 2 | ||||
-rw-r--r-- | sys-apps/selinux-small/selinux-small-2003040709-r2.ebuild | 145 |
4 files changed, 160 insertions, 2 deletions
diff --git a/sys-apps/selinux-small/ChangeLog b/sys-apps/selinux-small/ChangeLog index a9fc04671fe9..291547b5fac7 100644 --- a/sys-apps/selinux-small/ChangeLog +++ b/sys-apps/selinux-small/ChangeLog @@ -1,6 +1,15 @@ # ChangeLog for sys-apps/selinux-small # Copyright 2000-2003 Gentoo Technologies, Inc.; Distributed under the GPL v2 -# $Header: /var/cvsroot/gentoo-x86/sys-apps/selinux-small/ChangeLog,v 1.15 2003/05/14 19:13:15 pebenito Exp $ +# $Header: /var/cvsroot/gentoo-x86/sys-apps/selinux-small/ChangeLog,v 1.16 2003/05/22 20:20:18 pebenito Exp $ + +*selinux-small-2003040709-r2 (22 May 2003) + + 22 May 2003; Chris PeBenito <pebenito@gentoo.org> + selinux-small-2003040709-r2.ebuild: + Changed pam dep to shadow, so /etc/pam.d files are created correctly (shadow + depends on pam). Moved /etc/security files to selinux-base-policy since they + need to be modified based on the base policy. Added initial version of rlpkg + which will relabel a package based on its CONTENTS in the portage db. *selinux-small-2003040709-r1 (14 May 2003) diff --git a/sys-apps/selinux-small/Manifest b/sys-apps/selinux-small/Manifest index ec443c233621..c08843b3c2a5 100644 --- a/sys-apps/selinux-small/Manifest +++ b/sys-apps/selinux-small/Manifest @@ -1,9 +1,11 @@ -MD5 66f378585e11a8229bc89202d00f09fb ChangeLog 3319 +MD5 a8ba9ae8b41a56076a735967f8c2b86d ChangeLog 3763 MD5 5f53b492ab89de7607a70d08f844228e selinux-small-2003011510-r4.ebuild 4212 MD5 6ed2547809a991a94a1cfd1aa19cd875 selinux-small-2003040709-r1.ebuild 4482 +MD5 88e690e85a9a8d58d49c45d20ed9b32a selinux-small-2003040709-r2.ebuild 4466 MD5 4487057dc383a5e8f1b0424242308452 files/rlpkg 1788 MD5 e5ffaa323b22754b51eaa94f04bcf5dd files/digest-selinux-small-2003011510-r4 151 MD5 0986e11cde481cc9d4f8061654dedead files/digest-selinux-small-2003040709-r1 151 MD5 5b8ae6c77d50a559c31fb144faf6843e files/selinux-small-2003011510-bison.diff 553 MD5 5b8ae6c77d50a559c31fb144faf6843e files/selinux-small-2003040709-bison.diff 553 MD5 3809db44913b783d2b8bb31c8361aa92 files/selinux-small-2003040709-setfiles.diff 2623 +MD5 0986e11cde481cc9d4f8061654dedead files/digest-selinux-small-2003040709-r2 151 diff --git a/sys-apps/selinux-small/files/digest-selinux-small-2003040709-r2 b/sys-apps/selinux-small/files/digest-selinux-small-2003040709-r2 new file mode 100644 index 000000000000..be96298ad944 --- /dev/null +++ b/sys-apps/selinux-small/files/digest-selinux-small-2003040709-r2 @@ -0,0 +1,2 @@ +MD5 f2a8e506d952ceb4a30970a646e9a227 selinux-small-2003040709.tgz 571597 +MD5 98d24820cf82cce8d826b88ff2617eb6 selinux-small_2003040709-5.diff.gz 62300 diff --git a/sys-apps/selinux-small/selinux-small-2003040709-r2.ebuild b/sys-apps/selinux-small/selinux-small-2003040709-r2.ebuild new file mode 100644 index 000000000000..336fedefb225 --- /dev/null +++ b/sys-apps/selinux-small/selinux-small-2003040709-r2.ebuild @@ -0,0 +1,145 @@ +# Copyright 1999-2002 Gentoo Technologies, Inc. +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/sys-apps/selinux-small/selinux-small-2003040709-r2.ebuild,v 1.1 2003/05/22 20:20:18 pebenito Exp $ + +DESCRIPTION="SELinux libraries and policy compiler" +HOMEPAGE="http://www.nsa.gov/selinux" +SRC_URI="http://www.nsa.gov/selinux/archives/${P}.tgz + http://www.coker.com.au/selinux/selinux-small/selinux-small_${PV}-5.diff.gz" + +LICENSE="GPL-1" +SLOT="0" +S="${WORKDIR}/selinux" + +# to easily specify that libsecure is in the workdir, and we want to use pam +LIBSECURE="-I${S}/libsecure/include -L${S}/libsecure/src -DUSE_PAM" + +KEYWORDS="~x86 ~ppc ~alpha ~sparc" +IUSE="selinux" +DEPEND="<sys-libs/glibc-2.3.2 + sys-devel/flex + sys-apps/shadow + || ( + >=sys-kernel/selinux-sources-2.4.20-r1 + >=sys-kernel/hardened-sources-2.4.20-r1 + )" + +RDEPEND="<sys-libs/glibc-2.3.2 + || ( + >=sys-kernel/selinux-sources-2.4.20-r1 + >=sys-kernel/hardened-sources-2.4.20-r1 + ) + dev-tcltk/expect + >=sys-apps/selinux-base-policy-20030522" + +pkg_setup() { + use selinux || eend 1 "You must have selinux in USE." + + if [ ! -f /usr/src/linux/security/selinux/ss/ebitmap.c ]; then + eerror "The /usr/src/linux symlink appears to be incorrect. It must" + eerror "be pointing to a selinux-sources or hardened-sources kernel" + eerror "for selinux-small to compile. If the symlink is correct, the" + eerror "kernel sources may be damaged or incomplete, and will need to" + eend 1 "be remerged. Please fix and retry." + fi +} + +src_compile() { + ln -s /usr/src/linux ${WORKDIR}/lsm-2.4 + + cd ${S} + + epatch ${WORKDIR}/selinux-small_${PV}-5.diff + epatch ${FILESDIR}/${P}-bison.diff + + cd ${S}/setfiles + epatch ${FILESDIR}/${P}-setfiles.diff + + einfo "Compiling checkpolicy" + cd ${S}/module + make all LSMVER=-2.4 || die "Checkpolicy compilation failed" + + einfo "Compiling libsecure" + cd ${S}/libsecure + make SE_INC=/usr/include/linux/flask \ + EXTRA_CFLAGS="${CFLAGS}" \ + || die "libsecure compile failed." + cd ${S}/devfsd + mv devfsd-conflet selinux-small + make CFLAGS="${CFLAGS} ${LIBSECURE}" \ + LDFLAGS="-L${S}/libsecure/src" \ + || die "devfsd compile failed." + + einfo "Compiling utilities" + cd ${S}/setfiles + make CFLAGS="${CFLAGS} ${LIBSECURE}" \ + LDFLAGS="-L${S}/libsecure/src" setfiles \ + || die "setfiles compile failed." + cd ${S}/utils/newrole + make CFLAGS="${CFLAGS} ${LIBSECURE} -lcrypt" \ + || die "newrole compile failed." + cd ${S}/utils/run_init + make CFLAGS="${CFLAGS} ${LIBSECURE} -lcrypt" \ + || die "run_init compile failed." + cd ${S}/utils/spasswd + make CFLAGS="${CFLAGS} ${LIBSECURE}" \ + LDFLAGS="-L${S}/libsecure/src -lcrypt" \ + || die "spasswd compile failed." +} + +src_install() { + # install policy stuff + dosbin ${S}/module/checkpolicy/checkpolicy + dosbin ${S}/setfiles/setfiles + + insinto /usr/include + doins ${S}/libsecure/include/*.h + + insinto /etc/devfs.d + doins ${S}/devfsd/selinux-small + + dolib.a ${S}/libsecure/src/libsecure.a + dobin ${S}/libsecure/test/{avc_enforcing,avc_toggle,context_to_sid,sid_to_context,list_sids,chsid,lchsid,chsidfs,get_user_sids} + dosbin ${S}/libsecure/test/load_policy + dobin ${S}/utils/spasswd/{sadminpasswd,schfn,schsh,spasswd,suseradd,suserdel,svipw} + dobin ${S}/utils/run_init/run_init + dosbin ${S}/utils/run_init/open_init_pty + dobin ${S}/utils/newrole/newrole + dosbin ${FILESDIR}/rlpkg + + doman ${S}/setfiles/setfiles.8 + doman ${S}/libsecure/man/man[12]/* + doman ${S}/utils/newrole/newrole.1 + doman ${S}/utils/run_init/run_init.8 + + exeinto /lib/devfsd + doexe ${S}/devfsd/devfsd-se.so + + # install pam stuff + dodir /etc/pam.d + sed "/pam_rootok.so/d" /etc/pam.d/su > ${D}/etc/pam.d/newrole + cp ${D}/etc/pam.d/newrole ${D}/etc/pam.d/run_init +} + +pkg_postinst() { + einfo + einfo "To recompile the policy and relabel the filesystem simply run:" + einfo "ebuild /var/db/pkg/${CATEGORY}/${PF}/${PF}.ebuild config" + einfo +} + +pkg_config() { + cd /etc/security/selinux/src/policy + + einfo "Compiling policy" + make policy || die "Policy compile failed (see above error messages)" + + einfo "Installing policy" + make install || die "Policy install failed (see above error messages)" + + einfo "Loading policy" + make load || die "Policy loading failed (see above error messages)" + + einfo "Relabeling filesystems -- This will take a very long time!" + make relabel || die "Relabeling failed (see above error messages)" +} |