Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1578019

Re: [PATCH] security: selinux: allow per-file labeling for cgroupfs

Path csiph.com!aioe.org!bofh.it!news.nic.it!robomod
From Paul Moore <paul@paul-moore.com>
Newsgroups linux.kernel
Subject Re: [PATCH] security: selinux: allow per-file labeling for cgroupfs
Date Fri, 10 Feb 2017 00:10:01 +0100
Message-ID <t960F-3Z2-1@gated-at.bofh.it> (permalink)
References <t8Zsd-8j1-11@gated-at.bofh.it> <t8ZBT-8mq-11@gated-at.bofh.it> <t92zM-1JF-17@gated-at.bofh.it> <t92zM-1JF-15@gated-at.bofh.it> <t960F-3Z2-3@gated-at.bofh.it>
X-Original-To Antonio Murdaca <amurdaca@redhat.com>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=mtlJ6tOOiM0xOUIWSfGsr5C7j0T/qElGOGw0OcnqemI=; b=Pgc7mIVd8t6R29UrrsqsqKsLs2kXjsfZqSNqusEs5tsZJ81TJfcVOsccAqtX2QW/vc R1qVpwt3z6KwfzZqZq2sZq/hPwzVFhmPI2mRcqJfbv/4REA3HuZ5QyY5/vfXam6SV0IM yOSVL6wKrSMZmcvodplXJI7R8GXIEKHnizn15NbfNlTW6J7LQM9dqPbqmV4gsnTvnEGU LwZ7oHZuIlwvLDkqgeRndfLxhG2XP2GazS2bF+bJYyTcrYgmk8nG4LjzXyu8sKbupBl3 m7kO+1RnanZya4YD9hvBFh4AKTLom+SutbS4nOWHmSFw7efYiAdEHbN+Adq1qNkxuCJ+ 12eQ==
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=mtlJ6tOOiM0xOUIWSfGsr5C7j0T/qElGOGw0OcnqemI=; b=UQwpfoXO2M9+YqQr8b3vnmduzrHfjpNwxTysno/q97I657vrIcHQRZozs3j/plsnhG Qx9tGHDRkllNjS4fAcFgLN4lAbx3nCTbVzCpJz8qJ6gxoLs8Lga8SIEponvjAm6uUczT Y+90pXIiUGhjuZQ/w+X0MQZmU1crvVsPan1w8PXY7rQZaZOLB+iC/kAcTwRGsg7CcV6B QmFz0iKsKHnpWG2ogHGiViY74LLhEzE52QO/LsuGEfoiZyKJglrhfBpdtldGyhj0kyxe Agi9pMtSPE11xufe/KYlS/FWQrP7qi5PosDYOl4EXhYVmg18N6vbXsZBoDsAFQkTsrac b8zw==
X-Gm-Message-State AMke39m3yAa6QL9KjBOB332yYXGHKfooSwH3WxOwANgQgWGwfiDiDBgj8GhzMQwgbUlwKqbfWXLOx20JMAfdRA==
X-Received by 10.159.32.38 with SMTP id 35mr3085039uam.12.1486681498485; Thu, 09 Feb 2017 15:04:58 -0800 (PST)
MIME-Version 1.0
X-Originating-IP [108.49.102.27]
Content-Type text/plain; charset=UTF-8
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 42
Organization linux.* mail to news gateway
X-Original-Cc selinux@tycho.nsa.gov, Antonio Murdaca <runcom@redhat.com>, Vivek Goyal <vgoyal@redhat.com>, linux-kernel@vger.kernel.org, cgroups@vger.kernel.org
X-Original-Date Thu, 9 Feb 2017 18:04:57 -0500
X-Original-Message-ID <CAHC9VhTMxN5sqk+BL6f4-V7o3ez=7fMHBWFRAvj+j5iD+VkiMA@mail.gmail.com>
X-Original-References <20170209160242.23405-1-amurdaca@redhat.com> <CAHC9VhRFxDuRJHYEuRs7kc4ivgaT=-SxdU-o5Lq7H-O+5JJRxQ@mail.gmail.com> <CALKLTGTc7U7ohxd44MHOuzVomW-oUsumqUqr0MKaUohw1NpSsg@mail.gmail.com> <CAHC9VhSj4ztDZwxfcuugaD5-OJrBVaJ=TQS=t4=jfL0+ZdbdYQ@mail.gmail.com> <CALKLTGTjpBYd5-M9RiO-Q4H_SokEiPJYptbxktg_aPccws59Jw@mail.gmail.com>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1578019

Show key headers only | View raw


On Thu, Feb 9, 2017 at 5:32 PM, Antonio Murdaca <amurdaca@redhat.com> wrote:
>
>
> On Feb 9, 2017 20:23, "Paul Moore" <paul@paul-moore.com> wrote:
>
> On Thu, Feb 9, 2017 at 12:39 PM, Antonio Murdaca <amurdaca@redhat.com>
> wrote:
>> On Feb 9, 2017 17:14, "Paul Moore" <paul@paul-moore.com> wrote:
>> On Thu, Feb 9, 2017 at 11:02 AM, Antonio Murdaca <amurdaca@redhat.com>
>> wrote:
>>> From: Antonio Murdaca <runcom@redhat.com>
>>>
>>> This patch allows genfscon per-file labeling for cgroupfs. For instance,
>>> this allows to label the "release_agent" file within each
>>> cgroup mount and limit writes to it.
>>>
>>> Signed-off-by: Antonio Murdaca <amurdaca@redhat.com>
>>> ---
>>>  security/selinux/hooks.c | 2 ++
>>>  1 file changed, 2 insertions(+)
>>
>> This was already merged ... ?
>>
>>
>> This is adding cgroup and cgroup2 to the other whitelist (afaict).
>
> Yes, my apologies, I read this patch too quickly and confused it with
> the previous cgroups patch.
>
> Just to set expectations, this patch is too late for the upcoming
> merge window, we can consider it in a few weeks once the merge window
> has closed.  This should give you some time to do some further testing
> (hint, hint).
>
>
> Sure, I'm going to test this and add tests in selinux-testsuite as well

Great, thank you.

-- 
paul moore
www.paul-moore.com

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH] security: selinux: allow per-file labeling for cgroupfs Antonio Murdaca <amurdaca@redhat.com> - 2017-02-09 17:10 +0100
  Re: [PATCH] security: selinux: allow per-file labeling for cgroupfs Paul Moore <paul@paul-moore.com> - 2017-02-09 17:20 +0100
    Re: [PATCH] security: selinux: allow per-file labeling for cgroupfs Paul Moore <paul@paul-moore.com> - 2017-02-09 20:30 +0100
      Re: [PATCH] security: selinux: allow per-file labeling for cgroupfs Paul Moore <paul@paul-moore.com> - 2017-02-10 00:10 +0100
        Re: [PATCH] security: selinux: allow per-file labeling for cgroupfs Daniel J Walsh <dwalsh@redhat.com> - 2017-02-11 00:10 +0100

csiph-web