Message ID | 153754740781.17872.7869536526927736855.stgit@warthog.procyon.org.uk (mailing list archive) |
---|---|
Headers | show
Return-Path: <selinux-bounces@tycho.nsa.gov> Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id 8814015A6 for <patchwork-selinux@patchwork.kernel.org>; Fri, 21 Sep 2018 17:59:48 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 7270B2E085 for <patchwork-selinux@patchwork.kernel.org>; Fri, 21 Sep 2018 17:59:48 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 657BE2E0B9; Fri, 21 Sep 2018 17:59:48 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.2 required=2.0 tests=BAYES_00,MAILING_LIST_MULTI, RCVD_IN_DNSWL_MED autolearn=ham version=3.3.1 Received: from uhil19pa11.eemsg.mail.mil (uhil19pa11.eemsg.mail.mil [214.24.21.84]) (using TLSv1.2 with cipher DHE-RSA-AES256-SHA256 (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id 96A4A2E085 for <patchwork-selinux@patchwork.kernel.org>; Fri, 21 Sep 2018 17:59:46 +0000 (UTC) X-EEMSG-check-008: 338739294|UHIL19PA11_EEMSG_MP9.csd.disa.mil Received: from emsm-gh1-uea10.ncsc.mil ([214.29.60.2]) by uhil19pa11.eemsg.mail.mil with ESMTP/TLS/DHE-RSA-AES256-SHA256; 21 Sep 2018 17:59:44 +0000 X-IronPort-AV: E=Sophos;i="5.54,285,1534809600"; d="scan'208";a="16110510" IronPort-PHdr: 9a23:Vb2G0h9c/ENmef9uRHKM819IXTAuvvDOBiVQ1KB60e0QIJqq85mqBkHD//Il1AaPAd2Eraocw8Pt8InYEVQa5piAtH1QOLdtbDQizfssogo7HcSeAlf6JvO5JwYzHcBFSUM3tyrjaRsdF8nxfUDdrWOv5jAOBBr/KRB1JuPoEYLOksi7ze+/94HRbglSmDaxfa55IQmrownWqsQYm5ZpJLwryhvOrHtIeuBWyn1tKFmOgRvy5dq+8YB6/ShItP0v68BPUaPhf6QlVrNYFygpM3o05MLwqxbOSxaE62YGXWUXlhpIBBXF7A3/U5zsvCb2qvZx1S+HNsDtU7s6RSqt4LtqSB/wiScIKTg58H3MisdtiK5XuQ+tqwBjz4LRZoyaOuB+fqfAdt0EQ2RPUNtaWyhYDo68aocCCfcKM+RFoInnv1YArQWwCwevCuzhxTBHnGL43bU43ug8HwzJwAMuEMwVsHnPsNX6L70fXfypwKTSzzjOae5d1zfn6IjPdxAsuf+CUqhuccrQ1EYkCgHLjlKeqIP7OzOV0v8NuHWc4uV9VeKvjGAmpB91ojir3cchkZPJiZwIxVDE7yp53Jw5KsG/SE5+eNOpFoZbuS+dN4tzWMwiQmdotT45yrIYo567ejYFyJA9yx7YcfyHfJCE7QzsVemLJDd4nHZld6ylixmu9kigz+vxXdS33lZStidJj9bBu38X2xHT98SLUOVx80i/1TqVygzf8v9ILVwwmKbBNpIszKA8moAOvUnAECL6glv6gayQe0454Oan8f7nba/jppKEMo90jRzxPbo2l8ykBOQ4LhAOX2+G+eSgzLHj/VP2QLFNjvAujqnWqoraJcUGpq6iGQNVzoYi5Aq/DzehytgYm2UILElZdx6diojpOlXOLOj5Dfe5nVusjC9my+3JM7DuGJnALmXPnK3/cbty9UJQ0hc/wcha551OC7EBJPzzWlX2tNzdFhI5KBK7w+LmCNV7y4MfVnuDDbSeMKPPt1+H+vwgI/KXaY8JuDfyN/gl5/n0gX8/gl8SZ7Ol3ZQQaHCmBvhmOVmWYWLwgtcdFmcHpgg+TOvsiFKYTT5TZ2y9X6Qn6zE5D4KmC4LDSZq2gLydwii7BIZWanpBClCWHnfib5+EVOsUaCKOPs9hlSQJVbqjS4A7yR6utxT6y71hLurV5C0Vrpzj1Nxo5+zcjh4y6Dp0D9iA022XSGF0hGwITScs3K9juUx91kuD0a9gjv1WFNxT4/ZJXRkgNZPHwex1Fc39WgXbftiTUFamWNKmATMvQd0t398CeUF9G8+tjhrbxSqlH6cVl6CXBJwz6q/TwmT+J8N6y3bAyKktkkIrQtVROm28h65+9g/TB4jTn0WfiamqabwW3DTR+2eb0WqOoEZYXRZuXqXdR38ffErWrc/i60PaVbCuE7UnMhBZyc6GMKRFdsPmgU9BRPf5N9TUe3ixlHuoBRaU2rOMa5Lne2YH0yXeD0gEjhse/XWcOgg9ASehvnjSDDt0FVLge0ns6/VxqGunTk8oyAGHd1du2Kev+h4Um/OcUege0agYtycksTl0G0y9393OAdqauwVhZLlcYc864FpfyW3WrQh9MYK7L6B+hl8edB96v1jy2BV2FIpAl9QqrHIwwwZoL6KXzk9BfSuC3Z/sIr3XNnXy/Be3Zq7Mx17Rzc2b+qgK6PU3sVnjuh+mFlY6+XV9z9ZVy2ec5onNDAcKSpLxXFw39x9hp7HGeSQ9/IXU1XpiMKmxqDDC3cglBO07xRa8Z91fKr+LFBfuE80GAMijMOIrlEKtbhIYIu9S7rU0Mti4d/SYwq6kJ/tgnDe8gWRA+oB93VqG9zBgRe7Qw5YF3/aY0xOBVzf9iFehtt74mZtfaD4IAGW/0y/kCJRWZq1ocoYBEX2uLNGvxtVim57tXGZV+0O/B1wcws+kYgadb1v43QJMz0sXumCnlTG+zzNqjzEjtrCf0zDWw+T+aBoHPXZGRHdjjVjwPYi0iMoaUFK0YAgpkxul40n6yrNfpKR+KWncW11Ify/sI2FlSKuwuaKIY9RT55MwrSVXTOO8bEieSr78uBsazzrvH3BAyzA/djGqvIj5nhNhhWKGNHZzrXzZecBsyhfE/tDcQ+Be3iYeTililTbXHkS8P8Wu/diMjZfDteS+V2a/WZ1JbSbryo2BuTCg5W13HRK/hOq/mtr9EQg1ySX7zcVlVT3UrBbgZYnmz6e6PvxhfklzH1L86NR1Godlkos2mp4QxWIWhpKP/XoIiW3zK8lU2bribHoRQj4G28bV7xL42E1nMH2J35j2VnOBwsR/fdm3eX4W2jkj4MBQE6eY9qdEnSxoolqisQ3ef/Z9njAHyfsh9nEWmecJtxQxzi+FGLAdAVFYPTDwlxSP992+sqNXa3u0fLiu0kpxgNChAKuEog5CRHbzYo0iEjNo7sVjLFLM12X+6pn+d9nNadIerQGbkxbcj+lVMZ4xmOAFhSx9NWL6p30lxPYxjQZy0pGioIiHN2Jt8bq3AhFCMD31e8QT+jT2gKZQgMmZwoevHo97FTUTRpvoSvCoHywOuvT7LQqOFyc8qniDE7rFAQCf8Ftmr27IE52zMnGYPn0ZzdF8SxmBOExQmhobUS48npEnCgCq39Duf11h5j8P/FL4rAVDyv5wPRnlTmjfvBuoaiszSJWHIhpW9B9N6FrOMcOE6OJzAyZY/oa6oQOXNmObYh5EDWYTWkyLH1rjJKWh5cHc8+iEAeqzN+PObquVpuNAUfeIxI6v0ox98jaNKMqAIGdtA+c82kpZUnBzA97ZlCkXSywLiyLNaNaWqwyn9SFwqsC/8e/rWB705YeVELtdL8lg9wqtgaidM+6QhSB5KStX154X2XDJyKIf3EMJiy10eTiiC6gAtTXKTKLWgKNXCAQbayxrPstS8608xhVNOdLcit7tzbF4j/E1C1BDVVH6h86me9cFI2CnO1PBHkqLM66GJTLTycHtfay8UaFQjPlTtxCouzabE0/iPiyElzntVhCvLf9DgTqePBxfpIG9aAhiBXLkTNL8ZR2xKMV3giEuwb0omnPKMnYRMTt8ckNJsLKd9iZYgvJxG2xP8HVlMfWEmyae7+ndNJkaq/1rDTpol+hC+nQ116NV7D1YRPxygCbSqMBhrEuikuSUyTpnVwFOqipRi4KNpkViOqTZ+oNGWXna4BIH9X+QBAgSp9t5Ft3vvLhdysLRm6LoNjhN6cjU8tccB8XPM82HMWAhPgfuGD7aFAsFVyCkNGHFi0xbjv6S6mWfroImpZj0hJoOVrhbWUQoGfMdDERlGsENL4lzXjMlirOUltAH5WC5rBXLQ8VapJ/HXOqIAfrzMDaZkaVEZxwQzLzlN4sTKIz71FF5alRhhovKAVDQXddDoy16cAA7vFhN8GJ/Tm0v20PpcAWt72EPFfSshB45lhN+Yfgx9Dfr+1o3Il3KpDEun0k3mNTlhiuccDH3LKetR41WDDD0t0cpOJPhXwl1dRGynVBjNDrcXLJekb9gdWFtiA/BtppCAuJTTapBYBAM3/6XfOko3U5aqiq52U9N/fHFBod6lAs2bZ6sqGpN2x5ibN4wIqzQOKpJz1hLi62Tvy+p1vo+zxQEK0YL7mySZDYCuFYUObk+Oyqo4uts5BSYlDtHeWgDS+Qlrepv9kI9PeSAyCTg3KRYJ0+qNuyQNaWZt3HOlc6VWF8w0F0Hl1Vd97hszcgja1aUV1wozLaJDBsGK8zCJBpPYMVP6njcYzyOsf7XzpJvP4SxDOfoTfWBtKwMmEKrAB4pH5gQ7sQGBpSs31zYLcbjLL4B1xot4R/mK0ibA/tSeRKEijEHr9u4zJ9t0olXPisdDnllMSWr+rbXoRcngOCFXNc3fngaXowENnYtWMOigiBXom5OASWw3O8C1AeC6Dr8qTjKAznnc9pvfvGUag1wCNuu4zUw77C2iULL8pXZP2z6L85tusXI6ewBvJuHF+lUQqNjs0jCn4lYRnqqU2HLEd60KJjwa5UsbdLuBXagV1yzkTQ1QNntPNy1NKiHnRnoRZpIsImcxD0iO9WxGS0eGxdxouED5bhzZQ4Ybpo6fxHnqRoxO7a4IAeC3dWkW3ytJidOT/lD0eW6YKRazy82Ye+gy3svUI06z+ix8U4CX5wLgAvRxfC/aIlaVijzB2FSex7VqSo/iWdhKv44wv0jzxPQrVkcLzeLefRzZ2xeotE8A0meIXZtB2o5Rl+cjJbD7RW207AU4SRdg85e0fdZv3jmop/ffDWsVbS3qZXStiotdsQmr7F0MYP4OMeGso3RniDHRpnKrgKFSDK6F+ZdmtVIIiJYR+dHlHo4NsMYoopO91AxVtsgKLNSEqUsoK6laSZ8By4I0SAZT5+A3CAFguqk1bvajA2fcJI+PxwFq5VPmd4dUzZ3Yi8Hv6+iWZ7Wm3WDSmgRLwcZ9R5M6x4Ylo9sYuDl55LFTINRxDFLovJ7SC/LG4J0+Fv8T2GZnUL3SO69k+Cz2wJd0u7s2MEBWBFjEUhd2/pWlkwwJbFvMKkQopTFvSKUdU7hp2Ltz/amJENNxsLKcV34EJDFunD4UiEG/n0UX4BPwmnFFZsOiwp5dLorpFJULY+9dEbx+yAoyoZ0E7S2Ts2k21ElrXMaSCiwCNpBF/tqsFTJVz15e5qrsonqO41OQm9M/52Qs01Zn1twPC6505VcN9pA4joLXDhRvzqRose9SMpe1sBoFZMMJMlwu2vlEqNeJJeRu2E2uqDoynLB5zA8qkm1yyuuFKKjUuJZ+3EeGh8zKGSAq0kvCO8s/XnO8lzXtVB05ehbDKCVjUptuDZ9AoxOBjFR2HCnNVtzVn5Gs/5eKKvPbcxRWPwyZQKrOxwiFP4pw02J8ltynXfieSBysRFa+y/FVQkuSSYVmqvtmSEZqsy/Oz8VUZRIbTs7byfCNg2UhztavApFZEFsQJAZBcxJ+7cF0otI5sDCU1qjKTkZXBx+MQI1yfxflUpYvUWZfyDdCBCkdffJsh15Z8eettWpLOjj/AdaloznrP04978dSHG8ng2tW9/epZfmttKWrkuOaLv4M+qkbH/HTTjDkRewhbM+AJnR5STTMQ1bK55hyXo/epXhDGHGPBtcK6IcPUpbWrhwac9areBCe89kZKEJ9LdpBhKcQxPiGJeirPdYIVnOQjTeNT+O8vSloYLU77zSV/TvZtCWy3bAWaJ3MY9w6SPnFLfyzY9e5k321+9v9kN7TFjLKCWBo8rhJwwV/smid03ivpIzETPQHphwjGLnxltceMoPXy2q7JMYxYtY6HfxU+13yFT8vfZJ97Z69Yk4/axmxd2zJafIJvRQqVVnDQSMBgV26pUtB3BySHtQYu8KJvbeZ6YZjcHyq+DvDaMX9RmV9vdFZtvAOk7OhNOwCiyGSRxDhgcOsyQWLgyG1/6Kg6V0U9qqpfDl2kIx5FizNgYGw6px5YiY+qqJqujXbwHSzbQdQajlWMfzrrUqu0OP6vwpj6YOdXZpYwK7EOgcWMkdxn3jzawwziIjDdnDH7T+9/5HTX45mSjgm59lFVUMBvwUBaaL/ZhZnmoglOzWKNsWcrxFmmaIEhKkCaENyXqq6yuRPWlkjQrD0xXuTmOp7F75tzV0QS3SwNf/ikBVTKW4BV9OXyq1Pk91qC+APAjyu9Xroqk68EY2MmjgtNKMimShIq9XENPjK9ycOyU0o0gXjJIpTNy1xY8bAca9IMsW8Hxma/ve7GWrkzNOo6hZnIfe58CV9e/RHXa+k62bpbKNxCpbyngjp10/7M6vNu3W7d2QX/uoz3oRTzt4uwbZUB66tqfbr0sNNUKW30nFno0KPtdE3Xg3zUzm6+0jT8g19ApADIrAYOkCpT/rMjvu3Vmfe843VjWZ0zZPHFL1Fll4GK4m1G3svMLJkWrQ9EApR4lxcUznnh93D4QjJEIz6VgX3DAMEQwQZhCaFr2oA1rqLZccX0gZdRuHxKS6ersw3UBrw7Ov+vXcbepnCqoJK/ZSkw+OnF9AGp4Mtq0eWr18cUdH9KHLvgjiF5TnX//+mHoyK/K1TM5a8cQCunos+Am/QQSv6YtZ47Ydlp+IarZOYYLQs8Bk80dn+TkPezRCgBh7iBO4X/4TpOTn4tXAq5qo7eCuVKcxSOkN8Rg7GXh+hYPqgF8/udHXy/tcSorNhIT68QBNIH2KuIHB3hl+M+UOKIWrfLB++HUBPSQeIWwBPcaOYfkm/yBtKCnT50BFAs4UftwXIszNmRxPh03yXLFT8dbbGkOGC4htas8k9W33yCo68ZEkSObv9Ce2JYzD71FKJ/5DlCJslNbYq+gPz/vSDywX4XeCZhhwxSOCzIKNBOjs8uWWz9HUTEgGHi8wU4dSPjaC/hanRuWtnpXzTgyU8tPzgI45dE+ISHy+gqAFsqdUEeFekSj63zleFoXwh/2Lqdqs7HVYukdAEIZp4h3PAL9fMYljORTkismrQVBxByXneMHOdxohpPSZy/wJ4+V/K0v+f5EULggDy7Lg5npfVhFuR6LuvlaFQeIRY8NrSPTArn9L8o9gM6sPM0KGpJz2rzdHtEw2ABU3Z7AutDBacFfBnBFNUabupLEAkhccUcJ+uUJUHWKwOWQ+5yfIVKhMiKmRCecV8imITqEVUkVnKCV+QxSv1JVpYbupkuhNsnlakSNlvPgqzztmSQO5uSL2u60N2TMg+Le/tDgap3xFT+OenDnMCVVCyvQKkKgdB2zl6Vymb3kJdJHy76V/JcT86Ykh5GwyYRc5cC0FWuSvEDr9j76OAoyTsNJcgwONuMrObb+vNyQSMKoyyQ77TXhnzgfehApo8HcMQji47t8kIYK9Odw/xiqpAmjWb1AM7blMsMTvtF4HVuw2aUluwG97yMiIWjUNRNDTG2YylgUkcmtEcJdf5hIbFKQlmSiIsbdc/gEVYTbUFYKl9pPWncjWxXluBettk3zXvKqtlJ4s0WMjn9Jy8z7Iv24dMfHbAOF2BX2m+o5ByOC2R/Kyv+QDU8MyxLSmT/IGNtKL42a62Jx2HESiw+JNTBKCLOYfy+KDAG+eQmqCVLHOKjDRxWxrO1Pu5RSuMlw8YdtLqEl4KObZm5pAjFe8CuFJfQys/nTj5TR/d+4Xchk5/oKueghMSe8VNI3+beQtwfhrDlwKYjeJGCZtEOa5vBarm5QzIHRv50j2IKzt/wnqPcHUG0wCFojX/fsTseeiSDenPnlthAZ3IFEy7/3WQlgxsfBRd5KKtcLdi9RyzagOcPI+VE91ocYdz7pq8pLcy8KWaVfUx5f2K8vSp62UA/rAwkAuYUlAX7YZaB+z7II/bbtbE6bLE+5htA8HTbM/XIRnN2r18/RsKxhvdwfKeLmuqsz6/6SRa5dUrmOQ5VU1f0K+8xEGw+a/GBRydIvix22nJpc2S3pNrsY4DBxgEcoHF5YaoganCoLSk6a+hg== X-IPAS-Result: A2B6AAAyMKVb/wHyM5BbHQEBBQEHBQGBUYFZBScDZSNcKINziBVfi02BaIEdlVcUgVsWGAsIAYQ7AwIZgy8hNBgBAwEBAQEBAQIBbBwMgjUkAYJmAiAEDRogBgUDAwkCJAIiBAICAgEBLRUBHgsFGASCNUyCAQMMowt7M4oKgQuJZReBQT+BEjOBYUmDN4FJARIBBAMCQoJVgjUiAogkISmFDY4wTwmGQ4l9gUVKhlg1hgyGdoF3gwuJCYFCOGRxMxoIGxU7gmwJghwXg0aFFIU/bgF6AQEUinMBDRcHgh8BAQ Received: from tarius.tycho.ncsc.mil ([144.51.242.1]) by EMSM-GH1-UEA10.NCSC.MIL with ESMTP; 21 Sep 2018 17:59:42 +0000 Received: from prometheus.infosec.tycho.ncsc.mil (prometheus.infosec.tycho.ncsc.mil [192.168.25.40]) by tarius.tycho.ncsc.mil (8.14.4/8.14.4) with ESMTP id w8LHx7wN020507; Fri, 21 Sep 2018 13:59:21 -0400 Received: from tarius.tycho.ncsc.mil (tarius.infosec.tycho.ncsc.mil [144.51.242.1]) by prometheus.infosec.tycho.ncsc.mil (8.15.2/8.15.2) with ESMTP id w8LGUT4j017512 for <selinux@prometheus.infosec.tycho.ncsc.mil>; Fri, 21 Sep 2018 12:30:29 -0400 Received: from goalie.tycho.ncsc.mil (goalie.infosec.tycho.ncsc.mil [144.51.242.250]) by tarius.tycho.ncsc.mil (8.14.4/8.14.4) with ESMTP id w8LGUNLR009855; Fri, 21 Sep 2018 12:30:24 -0400 X-IronPort-Anti-Spam-Filtered: true X-IronPort-Anti-Spam-Result: A1A4AACEG6Vbl3sWGNZaHQEBBQEHBQGBUYFZBSdofyiDc4gVX401gR2VVxSBZgsjCYRAg0ghNBgBAwEBAQEBAQIUAQEBAQEIFgZMhW4ETQU1AiYCSYJ/SwGCAQMMowZ7M4oMgQuJZReBQT+BEjOBYUmDN4FhAwJCglWCNSICiCQhKYUNjjBPCYZDiX2BRUqGWDWGDIZ2gXeDC4kJgUKCDTMaCBsVO4JsCYIcDgmDRoUUhT9uAYEQin8BJAeCHwEB X-IPAS-Result: A1A4AACEG6Vbl3sWGNZaHQEBBQEHBQGBUYFZBSdofyiDc4gVX401gR2VVxSBZgsjCYRAg0ghNBgBAwEBAQEBAQIUAQEBAQEIFgZMhW4ETQU1AiYCSYJ/SwGCAQMMowZ7M4oMgQuJZReBQT+BEjOBYUmDN4FhAwJCglWCNSICiCQhKYUNjjBPCYZDiX2BRUqGWDWGDIZ2gXeDC4kJgUKCDTMaCBsVO4JsCYIcDgmDRoUUhT9uAYEQin8BJAeCHwEB X-IronPort-AV: E=Sophos;i="5.54,285,1534824000"; d="scan'208";a="375409" Received: from emsm-gh1-uea11.ncsc.mil ([214.29.60.35]) by goalie.tycho.ncsc.mil with ESMTP; 21 Sep 2018 12:30:22 -0400 X-IronPort-Anti-Spam-Filtered: true X-IronPort-Anti-Spam-Result: A0AsAAD4G6Vbl3sWGNZaHQEBBQEHBQGBUYFZBSdofyiDc4gVX401gR2VVxSBZgsjCYRAg0ghNBgBAwEBAQEBAQIBEwEBAQEBCBYGTAyCNSQBgwgETQU1AiYCSYJ/SwGCAQMMowZ7M4oMgQuJZReBQT+BEjOBYUmDN4FhAwJCglWCNSICiCQhKYUNjjBPCYZDiX2BRUqGWDWGDIZ2gXeDC4kJgUKCDTMaCBsVO4JsCYIcDgmDRoUUhT9uAYEQin8BJAeCHwEB X-IPAS-Result: A0AsAAD4G6Vbl3sWGNZaHQEBBQEHBQGBUYFZBSdofyiDc4gVX401gR2VVxSBZgsjCYRAg0ghNBgBAwEBAQEBAQIBEwEBAQEBCBYGTAyCNSQBgwgETQU1AiYCSYJ/SwGCAQMMowZ7M4oMgQuJZReBQT+BEjOBYUmDN4FhAwJCglWCNSICiCQhKYUNjjBPCYZDiX2BRUqGWDWGDIZ2gXeDC4kJgUKCDTMaCBsVO4JsCYIcDgmDRoUUhT9uAYEQin8BJAeCHwEB X-IronPort-AV: E=Sophos;i="5.54,285,1534809600"; d="scan'208";a="18528133" X-IronPort-Outbreak-Status: No, level 0, Unknown - Unknown Received: from usat3cpa13.eemsg.mail.mil ([214.24.22.123]) by emsm-gh1-uea11.NCSC.MIL with ESMTP; 21 Sep 2018 16:30:21 +0000 X-EEMSG-check-005: 0 X-EEMSG-check-006: 000-001;2097b830-d883-4600-8963-ccc3d18eeaa4 Authentication-Results: USAT3CPA04.eemsg.mail.mil; dkim=none (message not signed) header.i=none; spf=None smtp.pra=dhowells@redhat.com; spf=Pass smtp.mailfrom=dhowells@redhat.com; spf=Pass smtp.helo=postmaster@mx1.redhat.com; dmarc=pass (p=none dis=none) d=redhat.com X-EEMSG-check-008: 325835597|USAT3CPA04_EEMSG_MP20.csd.disa.mil X-EEMSG-check-001: false X-EEMSG-SBRS: 3.5 X-EEMSG-ORIG-IP: 209.132.183.28 X-EEMSG-check-002: true X-IronPort-Anti-Spam-Filtered: true X-IronPort-Anti-Spam-Result: A0AzAACEG6Vbhxy3hNFaHQEBBQEHBQGBUYFZBYEPfyiDc4gVX401gR2VVxSBZgsTEAgBhDwCAoNIGgYBBDAYAQMBAQEBAQEBAQETAQEBCA0JCCkjDII1JAGDCAQLAUEFNQImAkmCf0sBggEPowZ7M4oMgQuJZReBQT+BEjOBYUmDN4FhAwJCglWCNSICiCQhKYUNjjBPCYZDiX2BRUqGWDWGDIZ2gXeDC4kJgUKCDTMaCBsVO4JsCYIcDgmDRoUUhT8+MAGBDgEBin8BJAeCHwEB X-IPAS-Result: A0AzAACEG6Vbhxy3hNFaHQEBBQEHBQGBUYFZBYEPfyiDc4gVX401gR2VVxSBZgsTEAgBhDwCAoNIGgYBBDAYAQMBAQEBAQEBAQETAQEBCA0JCCkjDII1JAGDCAQLAUEFNQImAkmCf0sBggEPowZ7M4oMgQuJZReBQT+BEjOBYUmDN4FhAwJCglWCNSICiCQhKYUNjjBPCYZDiX2BRUqGWDWGDIZ2gXeDC4kJgUKCDTMaCBsVO4JsCYIcDgmDRoUUhT8+MAGBDgEBin8BJAeCHwEB Received: from mx1.redhat.com ([209.132.183.28]) by USAT3CPA04.eemsg.mail.mil with ESMTP/TLS/DHE-RSA-AES256-SHA256; 21 Sep 2018 16:30:15 +0000 Received: from smtp.corp.redhat.com (int-mx03.intmail.prod.int.phx2.redhat.com [10.5.11.13]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 8612B9FDDB; Fri, 21 Sep 2018 16:30:14 +0000 (UTC) Received: from warthog.procyon.org.uk (ovpn-123-84.rdu2.redhat.com [10.10.123.84]) by smtp.corp.redhat.com (Postfix) with ESMTP id 294CE84D05; Fri, 21 Sep 2018 16:30:08 +0000 (UTC) X-EEMSG-check-009: 444-444 From: David Howells <dhowells@redhat.com> To: viro@zeniv.linux.org.uk Date: Fri, 21 Sep 2018 17:30:08 +0100 Message-ID: <153754740781.17872.7869536526927736855.stgit@warthog.procyon.org.uk> User-Agent: StGit/unknown-version MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.13 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.39]); Fri, 21 Sep 2018 16:30:15 +0000 (UTC) X-MIME-Autoconverted: from quoted-printable to 8bit by prometheus.infosec.tycho.ncsc.mil id w8LGUT4j017512 X-Mailman-Approved-At: Fri, 21 Sep 2018 13:59:05 -0400 Subject: [PATCH 00/34] VFS: Introduce filesystem context [ver #12] X-BeenThere: selinux@tycho.nsa.gov X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Security-Enhanced Linux \(SELinux\) mailing list" <selinux.tycho.nsa.gov> List-Post: <mailto:selinux@tycho.nsa.gov> List-Help: <mailto:selinux-request@tycho.nsa.gov?subject=help> Cc: Eric Biggers <ebiggers@google.com>, Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>, linux-kernel@vger.kernel.org, dhowells@redhat.com, selinux@tycho.nsa.gov, tomoyo-dev-en@lists.sourceforge.jp, Stephen Smalley <sds@tycho.nsa.gov>, fenghua.yu@intel.com, mszeredi@redhat.com, apparmor@lists.ubuntu.com, cgroups@vger.kernel.org, John Johansen <john.johansen@canonical.com>, linux-api@vger.kernel.org, Greg Kroah-Hartman <gregkh@linuxfoundation.org>, "Eric W. Biederman" <ebiederm@redhat.com>, linux-security-module@vger.kernel.org, Li Zefan <lizefan@huawei.com>, Johannes Weiner <hannes@cmpxchg.org>, linux-fsdevel@vger.kernel.org, Tejun Heo <tj@kernel.org>, torvalds@linux-foundation.org Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Errors-To: selinux-bounces@tycho.nsa.gov Sender: "Selinux" <selinux-bounces@tycho.nsa.gov> X-Virus-Scanned: ClamAV using ClamSMTP |
Series |
VFS: Introduce filesystem context [ver #12]
|
expand
|
David, I have been going through these and it is a wonderful proof of concept patchset. There are a couple significant problems with it however. - Many patches do more than one thing that could benefit from being broken up into more patches so that there is only one logical change per patch. I have attempted a little of that and have found several significant bugs. - There are many unnecessary changes in this patchset that just add noise and make it difficult to review. - There are many typos and thinkos in this patchset that while not hard to correct keep this from being anywhere close to being ready for prime time. - Some of the bugs I have encountered. * proc that isn't pid_ns_prepare_proc does not set fc->user_ns to match the pid namespace. * mqueue does not set fc->user_ns to match the ipc namespace. * The cpuset filesystem always fails to mount * Non-converted filesystems don't have the old security hooks and only have a bit blob so don't call into the new security hooks either. * The changes to implement the new security hooks at least for selinux are riddled with typos, and thinkos. I was hoping to get into the semantic questions but I can't get there until I get a good solid baseline patch to work with. I have been able to hoist the permission check out of sget_fc for converted filesystems. So progress is being made. That absolutely requires fc->user_ns to be set properly before vfs_get_tree. Something that still needs to be fixed. I have also observed that by not allowing unconverted filesystems to mount using the new api. The compatbitility code can be significantly simplified, and the who data_size problem goes away. I am going to be travelling for the next couple of days so I don't expect I will be able to answer questions in a timely manner. In the hopes that it might help below is my work in progress git tree where I have cleaned up some of these issues. https://git.kernel.org/pub/scm/linux/kernel/git/ebiederm/user-namespace.git new-mount-api-testing Eric