SELinux Tools (setools), version 1.0.1
by Tresys Technology, LLC
(selinux@tresys.com, www.tresys.com/selinux)

October 30, 2003


OVERVIEW

This file describes the SELinux tools (setools) developed by Tresys. 
See the change log for details on the changes in this version. 

The tools and libraries in this release include:

1. apol: The GUI-based policy analysis tool.

2. sepcut: A basic GUI-based policy configuration, browsing, 
   editing, and testing tool. This tool is intended to provide a 
   complete, single user interface for viewing the source files of a 
   policy, configuring policy program modules, editing policy files, and 
   making and testing the policy.

3. seuser: A GUI and command line user manager tool for SELinux.  This 
   is a tool that actually manages a portion of a running policy (i.e., 
   user accounts).  

4. seuser scripts: A set of shell scripts: seuseradd, seusermod, and 
   seuserdel.  These scripts combine the functions of the associated user
   management commands (useradd etc.) with the seuser tool, to provide a 
   single interface to effectively manage all users in an SELinux system.

5. awish: A version of the Tcl/Tk wish interpreter that includes the 
   setools libraries.  We use this to test our GUIs (apol and seuser have the 
   interpreter compiled within them).  One could conceivably write one's own 
   GUI tools using Tcl/Tk as extended via awish.

6. libapol: The main policy.conf analysis library, which is the core 
   library for all of our tools.

7. libseuser: The primary logic used for seuser.

Apol, sepcut, seuser, and the seuser* shell scripts are the primary 
tools in this package.  The other tool (awish) and the two libraries 
can serve as building blocks for the development of additional tools. 
All of these tools and libraries are early generation, with little 
maturity, and should be used with care.  

See the help files for apol, sepcut, and seuser for specific help on using 
these tools.

These tools will likely have bugs (see KNOWN-BUGS for those of which 
we are aware).  Please report any new bugs or comments to selinux@tresys.com. 
Thank you.


THIS RELEASE

See the change log for a summary and history of all changes to setools.


COPYING

The intent is to allow free use of this source code under the GNU General 
Public License (see COPYING).  The following files are used directly from 
NSA's SELinux distribution (see http://www.nsa.gov/selinux/src-
disclaim.html): (libapol/*, queue.h, queue.c, and apolicy_scan.l (aka 
policy_scan.l).

Portions of libapol/apolicy_parse.y were also taken directly from NSA's 
distribution.  All other source code is copyright protected and freely 
distributed under the GNU GPL (see COPYING).  Absolutely no warranty is 
provided or implied (see COPYING).
