policycoreutils: add option to build audit2allow
authorAdam Duskett <Aduskett@gmail.com>
Thu, 2 Feb 2017 22:45:05 +0000 (17:45 -0500)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Sun, 9 Apr 2017 13:33:54 +0000 (15:33 +0200)
commit005a5f33f25821af1edae15c7811c4ad305d3f0d
treef81e29b0909ee73443a019bbfa48ebbb63b6148c
parenteb77bd3dabe1fc2d0fa9ef0f8967e25eb550c9fb
policycoreutils: add option to build audit2allow

This python utility scans the logs for messages logged when the system
denied permission for operations, and  generates  a snippet of policy
rules which, if loaded into policy, might have allowed  those operations
to succeed.  However, this utility only generates Type Enforcement (TE)
allow rules.

Signed-off-by: Adam Duskett <Adamduskett@outlook.com>
Reviewed-by: Matt Weber <matthew.weber@rockwellcollins.com>
[Thomas: adjust Config.in to propagate the dependencies of sepolgen,
checkpolicy and python3.]
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/policycoreutils/Config.in
package/policycoreutils/policycoreutils.mk