summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChris PeBenito <pebenito@gentoo.org>2003-05-22 20:20:23 +0000
committerChris PeBenito <pebenito@gentoo.org>2003-05-22 20:20:23 +0000
commitd70baec05a44d530189380b29fce7afd66e2ad4f (patch)
treee174fd6847d2831ab870da99d354500f67a46882 /sys-apps
parentcleanup (diff)
downloadgentoo-2-d70baec05a44d530189380b29fce7afd66e2ad4f.tar.gz
gentoo-2-d70baec05a44d530189380b29fce7afd66e2ad4f.tar.bz2
gentoo-2-d70baec05a44d530189380b29fce7afd66e2ad4f.zip
Dep fix, /etc/security files moved to selinux-base-policy, new rlpkg script
Diffstat (limited to 'sys-apps')
-rw-r--r--sys-apps/selinux-small/ChangeLog11
-rw-r--r--sys-apps/selinux-small/Manifest4
-rw-r--r--sys-apps/selinux-small/files/digest-selinux-small-2003040709-r22
-rw-r--r--sys-apps/selinux-small/selinux-small-2003040709-r2.ebuild145
4 files changed, 160 insertions, 2 deletions
diff --git a/sys-apps/selinux-small/ChangeLog b/sys-apps/selinux-small/ChangeLog
index a9fc04671fe9..291547b5fac7 100644
--- a/sys-apps/selinux-small/ChangeLog
+++ b/sys-apps/selinux-small/ChangeLog
@@ -1,6 +1,15 @@
# ChangeLog for sys-apps/selinux-small
# Copyright 2000-2003 Gentoo Technologies, Inc.; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/sys-apps/selinux-small/ChangeLog,v 1.15 2003/05/14 19:13:15 pebenito Exp $
+# $Header: /var/cvsroot/gentoo-x86/sys-apps/selinux-small/ChangeLog,v 1.16 2003/05/22 20:20:18 pebenito Exp $
+
+*selinux-small-2003040709-r2 (22 May 2003)
+
+ 22 May 2003; Chris PeBenito <pebenito@gentoo.org>
+ selinux-small-2003040709-r2.ebuild:
+ Changed pam dep to shadow, so /etc/pam.d files are created correctly (shadow
+ depends on pam). Moved /etc/security files to selinux-base-policy since they
+ need to be modified based on the base policy. Added initial version of rlpkg
+ which will relabel a package based on its CONTENTS in the portage db.
*selinux-small-2003040709-r1 (14 May 2003)
diff --git a/sys-apps/selinux-small/Manifest b/sys-apps/selinux-small/Manifest
index ec443c233621..c08843b3c2a5 100644
--- a/sys-apps/selinux-small/Manifest
+++ b/sys-apps/selinux-small/Manifest
@@ -1,9 +1,11 @@
-MD5 66f378585e11a8229bc89202d00f09fb ChangeLog 3319
+MD5 a8ba9ae8b41a56076a735967f8c2b86d ChangeLog 3763
MD5 5f53b492ab89de7607a70d08f844228e selinux-small-2003011510-r4.ebuild 4212
MD5 6ed2547809a991a94a1cfd1aa19cd875 selinux-small-2003040709-r1.ebuild 4482
+MD5 88e690e85a9a8d58d49c45d20ed9b32a selinux-small-2003040709-r2.ebuild 4466
MD5 4487057dc383a5e8f1b0424242308452 files/rlpkg 1788
MD5 e5ffaa323b22754b51eaa94f04bcf5dd files/digest-selinux-small-2003011510-r4 151
MD5 0986e11cde481cc9d4f8061654dedead files/digest-selinux-small-2003040709-r1 151
MD5 5b8ae6c77d50a559c31fb144faf6843e files/selinux-small-2003011510-bison.diff 553
MD5 5b8ae6c77d50a559c31fb144faf6843e files/selinux-small-2003040709-bison.diff 553
MD5 3809db44913b783d2b8bb31c8361aa92 files/selinux-small-2003040709-setfiles.diff 2623
+MD5 0986e11cde481cc9d4f8061654dedead files/digest-selinux-small-2003040709-r2 151
diff --git a/sys-apps/selinux-small/files/digest-selinux-small-2003040709-r2 b/sys-apps/selinux-small/files/digest-selinux-small-2003040709-r2
new file mode 100644
index 000000000000..be96298ad944
--- /dev/null
+++ b/sys-apps/selinux-small/files/digest-selinux-small-2003040709-r2
@@ -0,0 +1,2 @@
+MD5 f2a8e506d952ceb4a30970a646e9a227 selinux-small-2003040709.tgz 571597
+MD5 98d24820cf82cce8d826b88ff2617eb6 selinux-small_2003040709-5.diff.gz 62300
diff --git a/sys-apps/selinux-small/selinux-small-2003040709-r2.ebuild b/sys-apps/selinux-small/selinux-small-2003040709-r2.ebuild
new file mode 100644
index 000000000000..336fedefb225
--- /dev/null
+++ b/sys-apps/selinux-small/selinux-small-2003040709-r2.ebuild
@@ -0,0 +1,145 @@
+# Copyright 1999-2002 Gentoo Technologies, Inc.
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/sys-apps/selinux-small/selinux-small-2003040709-r2.ebuild,v 1.1 2003/05/22 20:20:18 pebenito Exp $
+
+DESCRIPTION="SELinux libraries and policy compiler"
+HOMEPAGE="http://www.nsa.gov/selinux"
+SRC_URI="http://www.nsa.gov/selinux/archives/${P}.tgz
+ http://www.coker.com.au/selinux/selinux-small/selinux-small_${PV}-5.diff.gz"
+
+LICENSE="GPL-1"
+SLOT="0"
+S="${WORKDIR}/selinux"
+
+# to easily specify that libsecure is in the workdir, and we want to use pam
+LIBSECURE="-I${S}/libsecure/include -L${S}/libsecure/src -DUSE_PAM"
+
+KEYWORDS="~x86 ~ppc ~alpha ~sparc"
+IUSE="selinux"
+DEPEND="<sys-libs/glibc-2.3.2
+ sys-devel/flex
+ sys-apps/shadow
+ || (
+ >=sys-kernel/selinux-sources-2.4.20-r1
+ >=sys-kernel/hardened-sources-2.4.20-r1
+ )"
+
+RDEPEND="<sys-libs/glibc-2.3.2
+ || (
+ >=sys-kernel/selinux-sources-2.4.20-r1
+ >=sys-kernel/hardened-sources-2.4.20-r1
+ )
+ dev-tcltk/expect
+ >=sys-apps/selinux-base-policy-20030522"
+
+pkg_setup() {
+ use selinux || eend 1 "You must have selinux in USE."
+
+ if [ ! -f /usr/src/linux/security/selinux/ss/ebitmap.c ]; then
+ eerror "The /usr/src/linux symlink appears to be incorrect. It must"
+ eerror "be pointing to a selinux-sources or hardened-sources kernel"
+ eerror "for selinux-small to compile. If the symlink is correct, the"
+ eerror "kernel sources may be damaged or incomplete, and will need to"
+ eend 1 "be remerged. Please fix and retry."
+ fi
+}
+
+src_compile() {
+ ln -s /usr/src/linux ${WORKDIR}/lsm-2.4
+
+ cd ${S}
+
+ epatch ${WORKDIR}/selinux-small_${PV}-5.diff
+ epatch ${FILESDIR}/${P}-bison.diff
+
+ cd ${S}/setfiles
+ epatch ${FILESDIR}/${P}-setfiles.diff
+
+ einfo "Compiling checkpolicy"
+ cd ${S}/module
+ make all LSMVER=-2.4 || die "Checkpolicy compilation failed"
+
+ einfo "Compiling libsecure"
+ cd ${S}/libsecure
+ make SE_INC=/usr/include/linux/flask \
+ EXTRA_CFLAGS="${CFLAGS}" \
+ || die "libsecure compile failed."
+ cd ${S}/devfsd
+ mv devfsd-conflet selinux-small
+ make CFLAGS="${CFLAGS} ${LIBSECURE}" \
+ LDFLAGS="-L${S}/libsecure/src" \
+ || die "devfsd compile failed."
+
+ einfo "Compiling utilities"
+ cd ${S}/setfiles
+ make CFLAGS="${CFLAGS} ${LIBSECURE}" \
+ LDFLAGS="-L${S}/libsecure/src" setfiles \
+ || die "setfiles compile failed."
+ cd ${S}/utils/newrole
+ make CFLAGS="${CFLAGS} ${LIBSECURE} -lcrypt" \
+ || die "newrole compile failed."
+ cd ${S}/utils/run_init
+ make CFLAGS="${CFLAGS} ${LIBSECURE} -lcrypt" \
+ || die "run_init compile failed."
+ cd ${S}/utils/spasswd
+ make CFLAGS="${CFLAGS} ${LIBSECURE}" \
+ LDFLAGS="-L${S}/libsecure/src -lcrypt" \
+ || die "spasswd compile failed."
+}
+
+src_install() {
+ # install policy stuff
+ dosbin ${S}/module/checkpolicy/checkpolicy
+ dosbin ${S}/setfiles/setfiles
+
+ insinto /usr/include
+ doins ${S}/libsecure/include/*.h
+
+ insinto /etc/devfs.d
+ doins ${S}/devfsd/selinux-small
+
+ dolib.a ${S}/libsecure/src/libsecure.a
+ dobin ${S}/libsecure/test/{avc_enforcing,avc_toggle,context_to_sid,sid_to_context,list_sids,chsid,lchsid,chsidfs,get_user_sids}
+ dosbin ${S}/libsecure/test/load_policy
+ dobin ${S}/utils/spasswd/{sadminpasswd,schfn,schsh,spasswd,suseradd,suserdel,svipw}
+ dobin ${S}/utils/run_init/run_init
+ dosbin ${S}/utils/run_init/open_init_pty
+ dobin ${S}/utils/newrole/newrole
+ dosbin ${FILESDIR}/rlpkg
+
+ doman ${S}/setfiles/setfiles.8
+ doman ${S}/libsecure/man/man[12]/*
+ doman ${S}/utils/newrole/newrole.1
+ doman ${S}/utils/run_init/run_init.8
+
+ exeinto /lib/devfsd
+ doexe ${S}/devfsd/devfsd-se.so
+
+ # install pam stuff
+ dodir /etc/pam.d
+ sed "/pam_rootok.so/d" /etc/pam.d/su > ${D}/etc/pam.d/newrole
+ cp ${D}/etc/pam.d/newrole ${D}/etc/pam.d/run_init
+}
+
+pkg_postinst() {
+ einfo
+ einfo "To recompile the policy and relabel the filesystem simply run:"
+ einfo "ebuild /var/db/pkg/${CATEGORY}/${PF}/${PF}.ebuild config"
+ einfo
+}
+
+pkg_config() {
+ cd /etc/security/selinux/src/policy
+
+ einfo "Compiling policy"
+ make policy || die "Policy compile failed (see above error messages)"
+
+ einfo "Installing policy"
+ make install || die "Policy install failed (see above error messages)"
+
+ einfo "Loading policy"
+ make load || die "Policy loading failed (see above error messages)"
+
+ einfo "Relabeling filesystems -- This will take a very long time!"
+ make relabel || die "Relabeling failed (see above error messages)"
+}