2015-08-19 05:16:30

by mgrepl

[permalink] [raw]
Subject: [refpolicy] Policy source files in CIL

Hi all,
is there a future plan to re-write policies in CIL? I apologize if I
missed a thread about it.

Regards,
Miroslav

--
Miroslav Grepl
Senior Software Engineer, SELinux Solutions
Red Hat, Inc.


2015-08-19 12:41:02

by cpebenito

[permalink] [raw]
Subject: [refpolicy] Policy source files in CIL

On 8/19/2015 1:16 AM, Miroslav Grepl wrote:
> Hi all,
> is there a future plan to re-write policies in CIL? I apologize if I
> missed a thread about it.

There is no plan to rewrite refpolicy in CIL. Ideally, a refpolicy
high-level language and compiler will be created. There is a
prototype[1], but it compiles the current m4-structured language. In
the long run, it would be better to morph the language slightly to have
proper constructs, eliminating the m4-isms we have now.

[1] https://bitbucket.org/jwcarter/fpp

--
Chris PeBenito
Tresys Technology, LLC
http://www.tresys.com | oss.tresys.com