selinux-policy/www/html/status.html

485 lines
12 KiB
HTML
Raw Normal View History

2005-06-15 01:14:09 +00:00
<h1>Status</h1>
2006-03-07 14:47:21 +00:00
<strong>Current Version: 20060307</strong>
2005-12-06 21:28:21 +00:00
<p>
See <a href="index.php?page=download">download</a> for download
information. Details of this release are part of the <a href="html/Changelog.txt">changelog</a>.
2006-03-07 14:47:21 +00:00
This release focused on improving the consistency of interface names
in an effort to stabilize the Reference Policy interfaces.
Currently both strict and targeted policies can
2006-01-17 20:40:13 +00:00
be built. MLS policies can be built, but the policy is still undergoing
testing on running systems.
2005-12-06 21:28:21 +00:00
</p>
2005-08-02 15:19:49 +00:00
<p>&nbsp;</p>
<h2>Status and Tasks</h2>
2005-06-15 18:28:01 +00:00
<table border="1" cellspacing="0" cellpadding="3">
2005-06-15 17:32:40 +00:00
<tr>
2005-06-15 18:28:01 +00:00
<th class="title" colspan="3">Reference Policy Status</th>
</tr>
<tr>
<td class="header">Task/Component</td><td class="header">Status</td><td class="header">Description</td>
2005-06-15 17:32:40 +00:00
</tr>
<tr>
<td>Policy Structure</td>
<td>Complete</td>
<td>The policy is converted over to new Reference Policy structure</td>
</tr>
<tr>
<td>TE Policy</td>
<td>Conversion Ongoing</td>
<td>Conversion of old policy to Reference Policy modules is ongoing</td>
2005-07-05 18:59:08 +00:00
</tr>
2005-06-15 17:32:40 +00:00
<tr>
<td>Loadable Policy Modules</td>
<td>Major improvements</td>
<td>Infrastructure is in place to support both source policy and
2006-03-07 14:47:21 +00:00
loadable policy modules. Makefile support completed.</td>
2005-06-15 17:32:40 +00:00
</tr>
2005-07-05 18:59:08 +00:00
<tr>
2005-06-15 17:32:40 +00:00
<td>Documentation Infrastructure</td>
2005-09-07 14:45:49 +00:00
<td>Interfaces, templates, Booleans, and tunables complete</td>
<td>Tools to create webpages from the module interface and
template documentation is complete. Global Booleans and
tunables are supported. Booleans and tunables local to
policies are planned.</td>
2005-06-15 17:32:40 +00:00
</tr>
<tr>
<td>Policy Documentation</td>
<td>Ongoing</td>
2005-09-07 14:45:49 +00:00
<td>Most modules are documented.</td>
2005-06-15 17:32:40 +00:00
</tr>
<tr>
<td>Unused Modules</td>
<td>Complete</td>
<td>Modules can be disabled by using modules.conf.</td>
</tr>
<tr>
<td>MLS Infrastructure</td>
<td>Minor improvements</td>
<td>MLS infrastructure added to support easy conversion between
MLS and non-MLS policy. Policy is compilable, but
2006-03-07 14:47:21 +00:00
only lightly tested.</td>
2005-06-15 17:32:40 +00:00
</tr>
2005-09-22 18:40:05 +00:00
<tr>
<td>MCS Support</td>
<td>Minor improvements</td>
<td>MLS infrastructure has been extended to support MCS
categories in users and all contexts. MCS constraints
2005-12-06 21:28:21 +00:00
have been added. Policy has been tested in the
targeted-mcs policy configuration.</td>
2005-09-22 18:40:05 +00:00
</tr>
2005-06-15 17:32:40 +00:00
<tr>
<td>Network Infrastructure</td>
<td>Minor improvements</td>
<td>All network ports, nodes, and interfaces moved to
corenetwork module, interfaces generated automatically.
Plan to add more infrastructure for configuration of
ports, nodes, and interfaces.</td>
</tr>
<tr>
<td>User domains and roles</td>
<td>Minor improvements</td>
<td>Some infrastructure added to support per-user domain policy,
e.g., to create types and policy for ssh,
for each user. Plan to add infrastructure to easily
configure userdomains and roles.</td>
</tr>
<tr>
<td>Labeling</td>
<td>Minor improvements</td>
<td>All labeling moved to modules, consistent with Reference
2005-09-07 14:45:49 +00:00
Policy structure. Levels can be added to the labels
without changes to the policy.</td>
2005-06-15 17:32:40 +00:00
</tr>
<tr>
<td>Tunables</td>
<td>Minor improvements</td>
2005-09-07 14:45:49 +00:00
<td>Tunables are documented and included in the webpage policy
documentation.</td>
2005-06-15 17:32:40 +00:00
</tr>
<tr>
<td>Users</td>
<td>Unchanged</td>
2005-09-07 14:45:49 +00:00
<td>Assignment of users to roles.</td>
2005-06-15 17:32:40 +00:00
</tr>
<tr>
<td>Constraints</td>
<td>Unchanged</td>
2005-09-07 14:45:49 +00:00
<td>Plan to split up into relevant modules when loadable modules
support this. There are ordering problems with source
policies.</td>
2005-06-15 17:32:40 +00:00
</tr>
<tr>
<td>Flask</td>
<td>Unchanged</td>
<td>Headers for the policy, describing object classes, and
2005-09-07 14:45:49 +00:00
their permissions. No planned changes.</td>
2005-06-15 17:32:40 +00:00
</tr>
</table>
2005-08-02 15:19:49 +00:00
<p>&nbsp;</p>
2006-03-07 14:47:21 +00:00
<!--
2005-08-02 15:19:49 +00:00
<h2>Roadmap</h2>
<table cellpadding="3" cellspacing="0" border="1">
<tbody>
<tr>
<th colspan="3" class="title">Reference Policy Roadmap</th>
</tr>
<tr>
<td class="header">Version</td>
<td class="header">Date</td>
<td class="header">Description</td>
</tr>
<tr>
<td>0.1</td>
<td>June 2005</td>
<td>Initial public release, basic policy restructuring, some infrastructure, few modules, and minimal documentation.</td>
</tr>
<tr>
<td>0.2</td>
<td>July 2005</td>
<td>Restructuring complete, additional modules, and improved infrastructure.</td>
</tr>
<tr>
<td>0.3</td>
<td>August 2005</td>
<td>Additional modules, documentation, and base module configuration support.</td>
</tr>
<tr>
<td>0.4</td>
<td>September 2005</td>
<td>Additional modules, documentation, and tested loadable module support.</td>
</tr>
<tr>
<td>0.5</td>
<td>October 2005</td>
<td>Additional modules, documentation, targeted policy, and tested MLS support</td>
</tr>
<tr>
<td>0.6</td>
<td>December 2005</td>
<td>Additional modules, documentation, and module variations</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
2006-03-07 14:47:21 +00:00
-->
2005-07-01 16:39:31 +00:00
<h2>Policy Conversion</h2>
<p>
This phase of reference policy development involves the conversion of policies
2005-09-22 18:40:05 +00:00
from the example strict policy. Please use the current NSA example policy
in <a href="http://cvs.sourceforge.net/viewcvs.py/selinux/nsa/selinux-usr/policy/">
NSA SourceForge CVS</a>.
2005-09-13 22:06:10 +00:00
We ask that modules that are in the targeted policy be given the first priority,
and then modules in the strict policy but not in targeted policy given second priority.
2005-09-13 21:49:35 +00:00
For those who wish to contribute, here is a listing of modules which need to be
converted:
2005-09-13 20:54:56 +00:00
</p>
<table cellpadding="3" cellspacing="0" border="1">
<tbody>
<tr>
<th colspan="3" class="title">Policy Module Status</th>
</tr>
<tr>
<td class="header">Module Name</td>
<td class="header">Previous Policy Files</td>
<td class="header">Assigned To</td>
</tr>
<tr>
2005-09-13 21:49:35 +00:00
<td>asterisk</td>
<td>asterisk.te asterisk.fc</td>
<td></td>
</tr>
<tr>
<td>audio-entropy</td>
<td>audio-entropyd.te audio-entropyd.fc</td>
<td></td>
</tr>
<tr>
<td>authbind</td>
<td>authbind.te authbind.fc</td>
<td></td>
</tr>
<tr>
<td>backup</td>
<td>backup.te backup.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>bonobo +</td>
2005-09-13 20:54:56 +00:00
<td>bonobo.te bonobo.fc bonobo_macros.te</td>
<td></td>
</tr>
<tr>
2005-09-13 21:49:35 +00:00
<td>calamaris</td>
<td>calabaris.te calamaris.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>cipe</td>
<td>ciped.te ciped.fc</td>
<td></td>
</tr>
<tr>
<td>courier</td>
<td>courier.te courier.fc</td>
<td></td>
</tr>
<tr>
<td>dante</td>
<td>dante.te dante.fc</td>
<td></td>
</tr>
<tr>
<td>dcc</td>
<td>dcc.te dcc.fc</td>
<td></td>
</tr>
<tr>
<td>ddclient</td>
<td>ddclient.te ddclient.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>dnsmasq</td>
<td>dnsmasq.te dnsmasq.fc</td>
<td></td>
</tr>
<tr>
<td>dpkg</td>
<td>dpkg.te dpkg.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>ethereal +</td>
2005-09-13 20:54:56 +00:00
<td>ethereal.te ethereal.fc ethereal_macros.te</td>
2006-02-16 22:21:22 +00:00
<td>Tresys</td>
2005-09-13 20:54:56 +00:00
</tr>
<tr>
2005-09-13 21:49:35 +00:00
<td>evolution +</td>
<td>evolution.te evolution.fc evolution_macros.te</td>
2006-02-16 22:21:22 +00:00
<td>Tresys</td>
2005-09-13 21:49:35 +00:00
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>fontconfig +</td>
2005-09-13 20:54:56 +00:00
<td>fontconfig.te fontconfig.fc</td>
2006-02-01 21:05:25 +00:00
<td>Tresys</td>
2005-09-13 20:54:56 +00:00
</tr>
<tr>
2005-09-13 21:49:35 +00:00
<td>gatekeeper</td>
<td>gatekeeper.te gatekeeper.fc</td>
<td></td>
</tr>
<tr>
<td>gconf +</td>
2005-09-13 20:54:56 +00:00
<td>gconf.te gconf.fc gconf_macros.te</td>
2006-02-01 21:05:25 +00:00
<td>Tresys</td>
2005-09-13 20:54:56 +00:00
</tr>
<tr>
2005-09-13 21:49:35 +00:00
<td>games +</td>
2005-09-13 20:54:56 +00:00
<td>games.te games.fc games_domain.te</td>
<td></td>
</tr>
<tr>
2005-09-13 21:49:35 +00:00
<td>gift</td>
<td>gift.te gift.fc gift_macros.te</td>
<td></td>
</tr>
<tr>
<td>gnome +</td>
2005-09-13 20:54:56 +00:00
<td>gnome.te gnome.fc gnome_macros.te gnome_vfs.te gnome_vfs.fc gnome_vfs_macros.te gnome-pty-helper.te gnome-pty-helper.fc gph_macros.te</td>
2006-02-01 21:05:25 +00:00
<td>Tresys</td>
2005-09-13 20:54:56 +00:00
</tr>
<tr>
2005-09-13 21:49:35 +00:00
<td>imazesrv</td>
<td>imazesrv.te imazesrv.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>ircd</td>
<td>ircd.te ircd.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>jabber</td>
<td>jabberd.te jabberd.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>lcd</td>
<td>lcd.te lcd.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>lrr</td>
<td>lrrd.te lrrd.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>monop</td>
<td>monopd.te monopd.fc</td>
<td></td>
</tr>
2006-02-16 22:21:22 +00:00
<tr>
<td>mozilla +</td>
<td>mozilla.te mozilla.fc mozilla_macros.te</td>
<td>Tresys</td>
</tr>
2005-09-13 21:49:35 +00:00
<tr>
<td>mplayer +</td>
2005-09-13 20:54:56 +00:00
<td>mplayer.te mplayer.fc mplayer_macros.te</td>
2006-01-30 15:32:59 +00:00
<td>Tresys</td>
2005-09-13 20:54:56 +00:00
</tr>
<tr>
2005-09-13 21:49:35 +00:00
<td>nagios</td>
<td>nagios.te nagios.fc nrpe.te nrpe.fc</td>
<td></td>
</tr>
<tr>
<td>nessus</td>
<td>nessusd.te nessusd.fc</td>
<td></td>
</tr>
<tr>
<td>nsd</td>
<td>nsd.te nsd.fc</td>
<td></td>
</tr>
<tr>
<td>nx</td>
<td>nx_server.te nx_server.fc</td>
<td></td>
</tr>
<tr>
<td>oav-update</td>
<td>oav-update.te oav-update.fc</td>
<td></td>
</tr>
<tr>
<td>openca</td>
<td>openca-ca.te openca-ca.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>orbit +</td>
2005-09-13 20:54:56 +00:00
<td>orbit.te orbit.fc orbit_macros.te</td>
<td></td>
</tr>
<tr>
2005-09-13 21:49:35 +00:00
<td>perdition</td>
<td>perdition.te perdition.fc</td>
<td></td>
</tr>
<tr>
<td>portslave</td>
<td>portslave.te portslave.fc</td>
<td></td>
</tr>
<tr>
<td>pxe</td>
<td>pxe.te pxe.fc</td>
<td></td>
</tr>
<tr>
<td>pyzor</td>
2005-09-13 22:01:53 +00:00
<td>pyzor.te pyzor.fc pyzor_macros.te</td>
2005-09-13 21:49:35 +00:00
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>razor</td>
2005-09-13 22:01:53 +00:00
<td>razor.te razor.fc razor_macros.te</td>
2005-09-13 21:49:35 +00:00
<td></td>
</tr>
<tr>
<td>resmgr</td>
<td>resmgrd.te resmgrd.fc</td>
<td></td>
</tr>
2005-09-13 22:01:53 +00:00
<tr>
<td>rhgb +</td>
<td>rhgb.te rhgb.fc rhgb_macros.te</td>
2006-02-16 22:21:22 +00:00
<td>Tresys</td>
2005-09-13 22:01:53 +00:00
</tr>
2005-09-13 21:49:35 +00:00
<tr>
<td>rssh</td>
2005-09-13 22:01:53 +00:00
<td>rssh.te rssh.fc rssh_macros.te</td>
2005-09-13 21:49:35 +00:00
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>scannerdaemon</td>
<td>scannerdaemon.te scannerdaemon.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>snort</td>
<td>snort.te snort.fc</td>
<td></td>
</tr>
<tr>
2006-01-17 20:40:13 +00:00
<td>sound-server +</td>
<td>sound-server.te sound-server.fc</td>
<td></td>
2005-09-13 20:54:56 +00:00
</tr>
<tr>
2005-09-13 21:49:35 +00:00
<td>speedtouch</td>
<td>speedmgmt.te speedmgmt.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>sxid</td>
<td>sxid.te sxid.fc</td>
<td></td>
</tr>
<tr>
<td>transproxy</td>
<td>transproxy.te transproxy.fc</td>
<td></td>
</tr>
<tr>
<td>tripwire</td>
<td>tripwire.te tripwire.fc</td>
<td></td>
</tr>
<tr>
<td>uptimed</td>
<td>uptimed.te uptimed.fc</td>
<td></td>
</tr>
2005-09-13 20:54:56 +00:00
<tr>
2005-09-13 21:49:35 +00:00
<td>uwimap</td>
<td>uwimapd.te uwimapd.fc</td>
<td></td>
</tr>
<tr>
<td>vmware +</td>
2005-09-13 20:54:56 +00:00
<td>vmware.te vmware.fc vmware_macros.te</td>
2006-02-01 21:05:25 +00:00
<td>Tresys</td>
2005-09-13 20:54:56 +00:00
</tr>
2005-09-13 21:49:35 +00:00
<tr>
<td>watchdog</td>
<td>watchdog.te watchdog.fc</td>
2005-09-13 20:54:56 +00:00
<td></td>
</tr>
<tr>
2005-09-13 21:49:35 +00:00
<td>xprint</td>
<td>xprint.te xprint.fc</td>
<td></td>
</tr>
<tr>
<td>yam</td>
<td>yam.te yam.fc</td>
<td></td>
</tr>
<tr>
<td colspan="3">(*) Modules in the Fedora targeted policy</td>
</tr>
<tr>
<td colspan="3">(+) Modules in the Fedora strict policy</td>
</tr>
2005-09-13 20:54:56 +00:00
</tbody>
</table>
2005-12-06 21:28:21 +00:00
2005-06-15 20:23:26 +00:00
<h2>Testing Status</h2>
<p>
2006-03-07 14:47:21 +00:00
Reference policy is now included in the Fedora Core 5 distribution.
2005-06-15 20:23:26 +00:00
</p>