> Currently useradd/userdel make a SE Linux system unusable and unbootable, the > change I request fixes that. The base functionality of /bin/passwd works, > but it doesn't perform checks for SE Linux permission, so root:user_r:user_t > can change passwords for any user. This is also fixed by the change I > request. > > > PS You will also need to make it build-depend on libselinux1-dev.
Yep. That's the last point to sort as this package is not available on the Hurd as Nicolas François pointed on IRC (#shadow on freenode). I'm very seriously considering the suggested change and I'm now in the "only Manoj can make my mind change" mood...:-) We are about to upload a new release of shadow as soon as the current one will have reached testing, which should happen, from memory, in 1 day or two. I expect this new release to be built with libselinux1.