From: Paul Moore <[email protected]>
To: [email protected], [email protected],
[email protected], [email protected],
[email protected], Jens Axboe <[email protected]>,
Pavel Begunkov <[email protected]>,
Kumar Kartikeya Dwivedi <[email protected]>
Subject: Re: [PATCH v4 0/8] Add LSM access controls and auditing to io_uring
Date: Sun, 19 Sep 2021 22:44:50 -0400 [thread overview]
Message-ID: <CAHC9VhSn3pvUgUo5_T=TfiBXw3=f6Pn6GaAUVS=jfg-Kfr_ZEw@mail.gmail.com> (raw)
In-Reply-To: <163172413301.88001.16054830862146685573.stgit@olly>
On Wed, Sep 15, 2021 at 12:49 PM Paul Moore <[email protected]> wrote:
>
> A quick update to the v3 patchset with a small change to the audit
> record format (remove the audit login ID on io_uring records) and
> a subject line fix on the Smack patch. I also caught a few minor
> things in the code comments and fixed those up. All told, nothing
> significant but I really dislike merging patches that haven't hit
> the list so here ya go ...
>
> As a reminder, I'm planning to merge these in the selinux/next tree
> later this week and it would be *really* nice to get some ACKs from
> the io_uring folks; this patchset is implementing the ideas we all
> agreed to back in the v1 patchset so there shouldn't be anything
> surprising in here.
>
> For reference the v3 patchset can be found here:
> https://lore.kernel.org/linux-security-module/163159032713.470089.11728103630366176255.stgit@olly/T/#t
>
> Those who would prefer to fetch these patches directly from git can
> do so using the tree/branch below:
> git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux.git
> (checkout branch "working-io_uring")
>
> ---
>
> Casey Schaufler (1):
> Smack: Brutalist io_uring support
>
> Paul Moore (7):
> audit: prepare audit_context for use in calling contexts beyond syscalls
> audit,io_uring,io-wq: add some basic audit support to io_uring
> audit: add filtering for io_uring records
> fs: add anon_inode_getfile_secure() similar to anon_inode_getfd_secure()
> io_uring: convert io_uring to the secure anon inode interface
> lsm,io_uring: add LSM hooks to io_uring
> selinux: add support for the io_uring access controls
>
>
> fs/anon_inodes.c | 29 ++
> fs/io-wq.c | 4 +
> fs/io_uring.c | 69 +++-
> include/linux/anon_inodes.h | 4 +
> include/linux/audit.h | 26 ++
> include/linux/lsm_hook_defs.h | 5 +
> include/linux/lsm_hooks.h | 13 +
> include/linux/security.h | 16 +
> include/uapi/linux/audit.h | 4 +-
> kernel/audit.h | 7 +-
> kernel/audit_tree.c | 3 +-
> kernel/audit_watch.c | 3 +-
> kernel/auditfilter.c | 15 +-
> kernel/auditsc.c | 469 ++++++++++++++++++++++------
> security/security.c | 12 +
> security/selinux/hooks.c | 34 ++
> security/selinux/include/classmap.h | 2 +
> security/smack/smack_lsm.c | 46 +++
> 18 files changed, 646 insertions(+), 115 deletions(-)
With no serious objections or outstanding comments, I just merged
these patches into selinux/next. If anyone has any follow-on patches
please base them against selinux/next, thanks.
--
paul moore
www.paul-moore.com
prev parent reply other threads:[~2021-09-20 2:45 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-09-15 16:49 [PATCH v4 0/8] Add LSM access controls and auditing to io_uring Paul Moore
2021-09-15 16:49 ` [PATCH v4 1/8] audit: prepare audit_context for use in calling contexts beyond syscalls Paul Moore
2021-09-15 16:49 ` [PATCH v4 2/8] audit,io_uring,io-wq: add some basic audit support to io_uring Paul Moore
2021-09-16 13:33 ` Richard Guy Briggs
2021-09-16 14:02 ` Paul Moore
2021-09-16 14:19 ` Richard Guy Briggs
2021-09-16 14:47 ` Paul Moore
2021-09-15 16:49 ` [PATCH v4 3/8] audit: add filtering for io_uring records Paul Moore
2021-09-15 21:48 ` Richard Guy Briggs
2021-09-15 16:49 ` [PATCH v4 4/8] fs: add anon_inode_getfile_secure() similar to anon_inode_getfd_secure() Paul Moore
2021-09-15 16:49 ` [PATCH v4 5/8] io_uring: convert io_uring to the secure anon inode interface Paul Moore
2021-09-15 16:49 ` [PATCH v4 6/8] lsm,io_uring: add LSM hooks to io_uring Paul Moore
2021-09-15 16:50 ` [PATCH v4 7/8] selinux: add support for the io_uring access controls Paul Moore
2021-09-15 16:50 ` [PATCH v4 8/8] Smack: Brutalist io_uring support Paul Moore
2021-09-20 2:44 ` Paul Moore [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='CAHC9VhSn3pvUgUo5_T=TfiBXw3=f6Pn6GaAUVS=jfg-Kfr_ZEw@mail.gmail.com' \
[email protected] \
[email protected] \
[email protected] \
[email protected] \
[email protected] \
[email protected] \
[email protected] \
[email protected] \
[email protected] \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox