<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SE Linux Policy Packaging for a Distribution</title>
	<atom:link href="http://etbe.coker.com.au/2008/08/18/se-linux-policy-packaging-distribution/feed/" rel="self" type="application/rss+xml" />
	<link>http://etbe.coker.com.au/2008/08/18/se-linux-policy-packaging-distribution/</link>
	<description>Linux, politics, and other interesting things</description>
	<lastBuildDate>Thu, 09 Feb 2012 01:09:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Ownership of the Local SE Linux Policy &#124; etbe - Russell Coker</title>
		<link>http://etbe.coker.com.au/2008/08/18/se-linux-policy-packaging-distribution/comment-page-1/#comment-15380</link>
		<dc:creator>Ownership of the Local SE Linux Policy &#124; etbe - Russell Coker</dc:creator>
		<pubDate>Tue, 19 Aug 2008 12:16:47 +0000</pubDate>
		<guid isPermaLink="false">http://etbe.coker.com.au/?p=712#comment-15380</guid>
		<description>[...] Comments etbe on SE Linux Policy Packaging for a DistributionMatthew W. S. Bell on SE Linux Policy Packaging for a DistributionScott Kitterman on SE Linux Policy [...]</description>
		<content:encoded><![CDATA[<p>[...] Comments etbe on SE Linux Policy Packaging for a DistributionMatthew W. S. Bell on SE Linux Policy Packaging for a DistributionScott Kitterman on SE Linux Policy [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: etbe</title>
		<link>http://etbe.coker.com.au/2008/08/18/se-linux-policy-packaging-distribution/comment-page-1/#comment-15379</link>
		<dc:creator>etbe</dc:creator>
		<pubDate>Tue, 19 Aug 2008 10:44:19 +0000</pubDate>
		<guid isPermaLink="false">http://etbe.coker.com.au/?p=712#comment-15379</guid>
		<description>Matthew: I&#039;m not sure if you are saying that my suggestion for working around the problem was bad or Michael&#039;s request for having it work on such a machine was a bad idea.

http://doc.coker.com.au/papers/porting-se-linux-hand-held-devices/

For reference in the past I&#039;ve got SE Linux working on a machine with 64M of storage (see the above URL).  I did this by building the policy on another machine and copying the image to the target machine.  I think that is the best way to deal with really small machines.

The issue is what areas I can spend time working on.  I can&#039;t fix all bugs or tune the system for the desires of all users.

Incidentally I run a bunch of Xen virtual machines with small amounts of storage.  The machine which hosts my blog has 3G of disk space assigned to it of which 1.4G is free.  A router would need significantly less storage space (unless you want to have a Squid cache on the CF).</description>
		<content:encoded><![CDATA[<p>Matthew: I&#8217;m not sure if you are saying that my suggestion for working around the problem was bad or Michael&#8217;s request for having it work on such a machine was a bad idea.</p>
<p><a href="http://doc.coker.com.au/papers/porting-se-linux-hand-held-devices/" rel="nofollow">http://doc.coker.com.au/papers/porting-se-linux-hand-held-devices/</a></p>
<p>For reference in the past I&#8217;ve got SE Linux working on a machine with 64M of storage (see the above URL).  I did this by building the policy on another machine and copying the image to the target machine.  I think that is the best way to deal with really small machines.</p>
<p>The issue is what areas I can spend time working on.  I can&#8217;t fix all bugs or tune the system for the desires of all users.</p>
<p>Incidentally I run a bunch of Xen virtual machines with small amounts of storage.  The machine which hosts my blog has 3G of disk space assigned to it of which 1.4G is free.  A router would need significantly less storage space (unless you want to have a Squid cache on the CF).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matthew W. S. Bell</title>
		<link>http://etbe.coker.com.au/2008/08/18/se-linux-policy-packaging-distribution/comment-page-1/#comment-15375</link>
		<dc:creator>Matthew W. S. Bell</dc:creator>
		<pubDate>Tue, 19 Aug 2008 02:02:54 +0000</pubDate>
		<guid isPermaLink="false">http://etbe.coker.com.au/?p=712#comment-15375</guid>
		<description>@etbe: WRT embedded systems: that&#039;s a really stupid argument, isn&#039;t it? (So bad I thought about adding an expletive.) Yes, you could run a whole load of custom scripts to set up a common environment, but that would completely obliterate the point of a having distribution. Muppet.</description>
		<content:encoded><![CDATA[<p>@etbe: WRT embedded systems: that&#8217;s a really stupid argument, isn&#8217;t it? (So bad I thought about adding an expletive.) Yes, you could run a whole load of custom scripts to set up a common environment, but that would completely obliterate the point of a having distribution. Muppet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Kitterman</title>
		<link>http://etbe.coker.com.au/2008/08/18/se-linux-policy-packaging-distribution/comment-page-1/#comment-15374</link>
		<dc:creator>Scott Kitterman</dc:creator>
		<pubDate>Tue, 19 Aug 2008 01:05:12 +0000</pubDate>
		<guid isPermaLink="false">http://etbe.coker.com.au/?p=712#comment-15374</guid>
		<description>I think that&#039;s not an unreasonable characterization.</description>
		<content:encoded><![CDATA[<p>I think that&#8217;s not an unreasonable characterization.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: etbe</title>
		<link>http://etbe.coker.com.au/2008/08/18/se-linux-policy-packaging-distribution/comment-page-1/#comment-15373</link>
		<dc:creator>etbe</dc:creator>
		<pubDate>Mon, 18 Aug 2008 23:20:10 +0000</pubDate>
		<guid isPermaLink="false">http://etbe.coker.com.au/?p=712#comment-15373</guid>
		<description>Caleb: The postinst in the Debian packages does this.  Look for the population of %map at about line 65.

Also I disagree with your claim about security and will cover it in my next post.

Anon: That would never work, I&#039;ll cover it in my next post.

Scott: I&#039;ve updated the post to describe Caleb as a contributer.  Is that correct?</description>
		<content:encoded><![CDATA[<p>Caleb: The postinst in the Debian packages does this.  Look for the population of %map at about line 65.</p>
<p>Also I disagree with your claim about security and will cover it in my next post.</p>
<p>Anon: That would never work, I&#8217;ll cover it in my next post.</p>
<p>Scott: I&#8217;ve updated the post to describe Caleb as a contributer.  Is that correct?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Kitterman</title>
		<link>http://etbe.coker.com.au/2008/08/18/se-linux-policy-packaging-distribution/comment-page-1/#comment-15371</link>
		<dc:creator>Scott Kitterman</dc:creator>
		<pubDate>Mon, 18 Aug 2008 15:44:14 +0000</pubDate>
		<guid isPermaLink="false">http://etbe.coker.com.au/?p=712#comment-15371</guid>
		<description>Caleb Case is not an Ubuntu developer.  He did some SE Linux package work that was sponsored into Ubuntu during a period with SE Linux in Debian was dormant, but since then we&#039;ve rebased everything on Debian&#039;s packages.</description>
		<content:encoded><![CDATA[<p>Caleb Case is not an Ubuntu developer.  He did some SE Linux package work that was sponsored into Ubuntu during a period with SE Linux in Debian was dormant, but since then we&#8217;ve rebased everything on Debian&#8217;s packages.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

