SELinux Tools (setools), version 1.0.1
by Tresys Technology, LLC
(selinux@tresys.com, www.tresys.com/selinux)

October 30, 2003

BUILDING AND INSTALLING NOTES AND WARNINGS

NOTE: If you are upgrading from a previous version of setools you must 
make sure you remove /usr/local/selinux/bin from your path.  The 
setools set is now installed to /usr/bin to match the rest of SE Linux.

We have built and used this package on Linux (Red Hat 7.x and Red Hat 
9.x) using several versions of SELinux.  The tar file will create a 
directory with the following subdirectories:

apol            The policy analysis tool
awish           Our customized version of the Tk wish interpreter
libapol         The main policy (policy.conf) analysis library
libseuser       The seuser support library
sepct           The policy configuration/editing tool (sepcut)
seuser          The user management tool and shell scripts
packages	External packages required by setools
	
Before building you will need to ensure that you have Tcl/Tk 8.3 or 
higher installed with BWidgets.  Generally, Red Hat Linux has 
appropriate versions of Tcl and Tk.  Usually the BWidgets package IS 
NOT installed by default. If you do not have BWidgets installed it
is available in the packages subdirectory. It can be installed by
going to the packages subdirectory and typing "make install". If you
have BWidgets installed make certain that it is a compatible version.
See BWIDGETS VERSIONS below for more information.

Given that you have Tcl/Tk with BWidgets installed, below are the 
build instructions.  You have the option of installing either apol, 
sepcut, seuser, or all.  apol can run on any Linux box (doesn't 
require SELinux).  It is just an analysis tool and many might just 
want to use it on their regular Linux box (we do).  Likewise sepcut 
can run on any system with Tcl/Tk and BWidgets; it's a straight Tcl/Tk 
application without any special C library required.

Seuser and its shell scripts on the other hand, are examples of 
operational policy management tools; they expect and require an SELinux 
system.

NOTE: If you're using MLS aspects of a policy, apol and the other 
tools are specifically not currently designed to address those 
aspects. However, you may have success using apol with MLS-enabled 
policies if you compile with the -DCONFIG_SECURITY_SELINUX_MLS flag in 
the Makefile. We have conducted very little testing with MLS enabled. 
Even with this flag set during compile time, apol still ignores all 
the MLS aspects of a policy, but should be able to parse such 
policies.

BUILDING AND INSTALL

Short version: make all; su root; make install  Long version follows:

0. Review the ./setools/Makefile, and ensure that the TCL_INCLUDE and 
TCL_LIBINC variables are set appropriately for your installation of 
Tcl/Tk.
   
1. If you are installing seuser and have a version of SELinux based
on an LSM kernel earlier than 2.4.19 (prior to August 2002 or so): 

	a. Check that you have the policy management changes to your 
	installed policy. Starting with the 2.4.19 LSM kernel based 
	SELinux, you do NOT need to install the policy patch; skip 
	ahead to Step 2.

	The changes to the policy necessary for pre-2.4.19 LSM kernels 
	are based on a patch we posted for the SELinux main 
	distribution.  See ./setools/policy/polpatch/readme.txt for 
	further instructions on determining whether you need the patch 
	and if so how to apply it.

	b. After you have applied the patch for the policy, make sure 
	the policy sources are installed. The patched policy make 
	file (./selinux/policy/Makefile) should have an 
	"install-src" target that will do this for you.

2. Build and install tools:  If you want to install all tools, just 
type "make install" to build and install everything.  Type "make" to 
see options to build individual pieces, for example to install just 
seuser, sepcut, or apol.

NOTE: If you installed seuser ("make install" or "make install-
seuser"), then the makefile also attempted to install the seuser 
policy.  If this failed, you either are not using an SELinux machine, 
the policy management patch isn't installed (see Step 1), or the 
policy source directory is not installed in the conventional location 
(use make install-src in the policy source directory from the SELinux 
distribution). Email us; we'll try to help (selinux@tresys.com)!

Most errors result from improperly installed Tcl/Tk, BWidgets, or the 
above libapol files.  
   
Send comments/questions to selinux@tresys.com.

BWIDGETS VERSIONS

The BWidgets package can be found at 
http://sourceforge.net/projects/tcllib. There are some 
incompatibilities with different versions of Tcl/Tk and BWidgets that 
can cause critical runtime errors. You will not be able to run any of 
the tools if you are using incompatible versions of Tcl/Tk and 
BWidgets. Correct versions of BWidgets for the Tcl/Tk version you are 
using are:

	- Tcl/Tk 8.3 - BWidget-1.4.1
	- Tcl/Tk 8.4 or greater - any

NOTE: You may run the tools using a pre-1.4.1 BWidgets package, 
however, you may experience problems. These tools have been tested 
using BWidgets 1.4.1 and 1.6.0. See TESTING INFORMATION in KNOWN-BUGS for
more  information on what platforms and configurations these tools have
been tested against.

Once you  have downloaded the correct version of BWidgets, then you 
can install it in your TCL directory. For instance, if you have 
Tcl installed in the /usr/lib directory, then you should install the 
BWidgets directory to /usr/lib/tcl8.3/.
