Skip to content

Releases: SELinuxProject/setools

4.7.1

Choose a tag to compare

@pebenito pebenito released this 28 Jul 17:50
4.7.1
b284eb6
  • Add initial prompts to MCP server.
  • Add file_contexts querying class.
  • Change MCP server to use standalone FastMCP package. The FastMCP server in
    the mcp package is a legacy version. FastMCP depends on the mcp package, so
    this change is not expected to be problematic for users or distros.
Name SHA-256 SUM
setools-4.7.1.tar.bz2 9b414eae7f17aa6ca53248d11d74fad01582a21985c78a483fa1240e70bd3b6a

4.7.0

Choose a tag to compare

@pebenito pebenito released this 23 Jun 19:12
4.7.0
8b182f0

Notable Changes

  • Add MCP server to provide LLMs the ability to analyze policy.
  • The source distribution is now a Python sdist and can be installed
    using pip.

Notes

  • Since the source distribution is Python sdist, the policyrep C extension is already cythonized. Cython is not needed unless you want to regenerate the C code. However, because of the generated code, the source distribution is much larger.
Name SHA-256 SUM
setools-4.7.0.tar.bz2 149ada9f39bb2f11b2e8ae292230a6f9f9f3069dd25bc30c30fd42a8d6f8cc90

4.6.0

Choose a tag to compare

@pebenito pebenito released this 08 Sep 19:12
4.6.0
dfb95f3

User Visible Changes

  • Add seinfo option to see roles allowed for a specified type.
  • Add sechecker module for asserting kernel modules are read-only.
  • Add support for the nlmsg extended permission.

Under The Hood Changes

  • Significant code quality and unit testing improvements.
  • Drop methods marked for deprecation.

Packaging Changes

  • Refactor packaging to use pyproject.toml.
Name SHA-256 SUM
setools-4.6.0.tar.bz2 97319aabaf9d4237841ee60dcc9b2f291e73a761f317fd13e293ea2367d5806c

4.5.1

Choose a tag to compare

@pebenito pebenito released this 01 May 17:57
659ec47
  • Correct annotations of NetworkX types to make it optional again.
  • Fix packaging issue for apol's style sheet (apol.css).
Name SHA-256 SUM
setools-4.5.1.tar.bz2 25e47d00bbffd6046f55409c9ba3b08d9b1d5788cc159ea247d9e0ced8e482e7

4.5.0

Choose a tag to compare

@pebenito pebenito released this 21 Mar 12:59

User Visible Changes

  • Add graphical results for information flow analysis and domain
    transition analysis, available in apol, sedta, and seinfoflow.
  • Add tooltips, What's This?, and detail popups in apol to help
    cross-referencing query and analysis results along with
    context-sensitive help.

Under The Hood Changes

  • Rework apol to fully generate the UI programmatically.
  • Update apol to PyQt6
  • Replace deprecated uses of pkg_resources and distutils.
  • Begin adding unit tests for apol UI.

Updated Dependencies

SETools now higher minimum versions of the following dependencies:

  • Python 3.10
  • NetworkX 2.6
  • PyQt6
  • Cython 0.29.14

New Dependencies

  • pygraphviz (for seinfoflow, sedta, apol)
  • pytest (if running unit tests)
Name SHA-256 SUM
setools-4.5.0.tar.bz2 68469ae9bd114b42bba4cb41795577ca1e4f50e3e4234817f13ff1a8bbd9ce77

4.4.4

Choose a tag to compare

@pebenito pebenito released this 07 Dec 16:07
a04b015
  • Update for compiling with libsepol 3.6.
  • Update apol to use fully specified PyQt enums.
  • Correct minor code lint issues.
Name SHA-256 SUM
setools-4.4.4.tar.bz2 3c5fa76a674fe3f6890d900df59b9d142e4b63c9ffbde653904f90ed6e666ef9

4.4.3

Choose a tag to compare

@pebenito pebenito released this 27 Jul 19:05
d3dbddb
  • Fix compilation with Cython 3.0.0.
  • Improve man pages.
  • Remove neverallow options in sediff.
  • Add -r option to seinfoflow to get flows into the source type.
  • Reject a rule with no permissions as invalid policy.
Name SHA-256 SUM
setools-4.4.3.tar.bz2 2f751599dbed0d628fb268a3302dd8c578829f302bd28e8c08e182aef7fd5cb8

4.4.2

Choose a tag to compare

@pebenito pebenito released this 19 Apr 13:16
d8d0dcc
  • Make NetworkX optional. sedta and seinfoflow tools, along with the
    equivalent analyses in apol require NetworkX.
  • Change unit test runner to pytest as setuptools' test command is
    deprecated.
  • Remove neverallow options in sesearch and apol. These are not usable
    since they are removed in the final binary policy.
  • Unit tests and CI tests improvements.
Name SHA-256 SUM
setools-4.4.2.tar.bz2 f23e3c8635aa289096ca0218ca6f4568a4346e088bc46f374cb0917b7fb66f05

4.4.1

Choose a tag to compare

@pebenito pebenito released this 06 Feb 14:03
bec5c81
  • Replace deprecated NetworkX function use in information flow and domain
    transition analysis. This function was removed in NetworkX 3.0.
  • Fix bug in apol copy and cut functions when copying from a tree view.
  • Fix bug with extended permission set construction when a range includes
    0x0.
  • Add sesearch -Sp option for permission subset match.
  • Fix error in man page description for sesearch -ep option.
  • Improve output stability in constraint, common, class, role, and user
    queries.
  • Updated permission map.
  • Fix bug in sechecker parsing of multiline values.
  • Other code cleanups not visible to users.
Name SHA-256 SUM
setools-4.4.1.tar.bz2 fcd161e55504aa4c361921833bf9d4cd58475c98746cfdacadd192a68788ae45

4.4.0

Choose a tag to compare

@pebenito pebenito released this 05 Mar 19:26

This SETools requires Python 3.6+ and libsepol 3.2+

User Visible Changes

  • Added support for old Boolean name substitution in seinfo and sesearch.
  • Added sechecker tool which is a configuration file driven analysis tool.

Development Related Changes

  • Updated policy representation to handle policydb version 33, compressed
    filename transitions.
  • Changed apol tab registry to use metaclasses rather than having a multiple static
    dictionaries in the code.
  • Fixed bug in queries where checks that permissions were part of the specified
    object class would incorrectly raise exceptions when the object class
    criteria is a regex.
  • Added type annotations to the code and added static type checking for
    continuous integration tests.
  • Reduced aggressiveness of default compiler flags. Since the C code is generated
    by Cython, there typically isn't anything SETools can do when Cython causes
    compiler warnings.
Name SHA-256 SUM
setools-4.4.0.tar.bz2 f3786677e40b7f16a226f48f233dcf835e700739614a7dbed2ff61cc9607814e