diff for duplicates of <1500062619.3583.71.camel@linux.vnet.ibm.com> diff --git a/a/1.txt b/N1/1.txt index 120dcf4..9751d3e 100644 --- a/a/1.txt +++ b/N1/1.txt @@ -1,11 +1,11 @@ On Fri, 2017-07-14 at 11:52 -0700, James Bottomley wrote: > On Fri, 2017-07-14 at 14:48 -0400, Mimi Zohar wrote: -> > The concern is with a shared filesystems. In that case, for IMA it -> > would make sense to support a native and a namespace xattr. If due +> > The concern is with a shared filesystems. ?In that case, for IMA it +> > would make sense to support a native and a namespace xattr. ?If due > > to xattr space limitations we have to limit the number of xattrs, > > then we should limit it to two - a native and a namespace version, > > with a "uid=" tag - first namespace gets permission to write the -> > namespace xattr. Again, like in the layered case, if the namespace +> > namespace xattr. ?Again, like in the layered case, if the namespace > > xattr doesn't exist, fall back to using the native xattr. > > Just on this point: if we're really concerned about the need on shared @@ -18,12 +18,12 @@ On Fri, 2017-07-14 at 11:52 -0700, James Bottomley wrote: > (like NFS) as well as containerised bind mounts. Writing security.ima requires being root with CAP_SYS_ADMIN -privileges. I wouldn't want to give root within the namespace +privileges. ?I wouldn't want to give root within the namespace permission to over write or just extend the native security.ima. Mimi -_______________________________________________ -Containers mailing list -Containers@lists.linux-foundation.org -https://lists.linuxfoundation.org/mailman/listinfo/containers +-- +To unsubscribe from this list: send the line "unsubscribe linux-security-module" in +the body of a message to majordomo at vger.kernel.org +More majordomo info at http://vger.kernel.org/majordomo-info.html diff --git a/a/content_digest b/N1/content_digest index a8de4e3..0da77ce 100644 --- a/a/content_digest +++ b/N1/content_digest @@ -11,31 +11,20 @@ "ref\020170714173556.GA19669@mail.hallyn.com\0" "ref\01500058090.3583.28.camel@linux.vnet.ibm.com\0" "ref\01500058362.2853.28.camel@HansenPartnership.com\0" - "ref\01500058362.2853.28.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org\0" - "From\0Mimi Zohar <zohar-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>\0" - "Subject\0Re: [PATCH v2] xattr: Enable security.capability in user namespaces\0" + "From\0zohar@linux.vnet.ibm.com (Mimi Zohar)\0" + "Subject\0[PATCH v2] xattr: Enable security.capability in user namespaces\0" "Date\0Fri, 14 Jul 2017 16:03:39 -0400\0" - "To\0James Bottomley <James.Bottomley-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>" - Serge E. Hallyn <serge-A9i7LUbDfNHQT0dZR+AlfA@public.gmane.org> - Stefan Berger <stefanb-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org> - " Mimi Zohar <zohar-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>\0" - "Cc\0containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org" - linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org - linux-security-module-u79uwXL29TY76Z2rM5mHXA@public.gmane.org - Eric W. Biederman <ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org> - casey-iSGtlc1asvQWG2LlvL+J4A@public.gmane.org - Theodore Ts'o <tytso-3s7WtUTddSA@public.gmane.org> - " lkp-JC7UmRfGjtg@public.gmane.org\0" + "To\0linux-security-module@vger.kernel.org\0" "\00:1\0" "b\0" "On Fri, 2017-07-14 at 11:52 -0700, James Bottomley wrote:\n" "> On Fri, 2017-07-14 at 14:48 -0400, Mimi Zohar wrote:\n" - "> > The concern is with a shared filesystems. \302\240In that case, for IMA it\n" - "> > would make sense to support a native and a namespace xattr. \302\240If due\n" + "> > The concern is with a shared filesystems. ?In that case, for IMA it\n" + "> > would make sense to support a native and a namespace xattr. ?If due\n" "> > to xattr space limitations we have to limit the number of xattrs,\n" "> > then we should limit it to two - a native and a namespace version,\n" "> > with a \"uid=\" tag - first namespace gets permission to write the\n" - "> > namespace xattr. \302\240Again, like in the layered case, if the namespace\n" + "> > namespace xattr. ?Again, like in the layered case, if the namespace\n" "> > xattr doesn't exist, fall back to using the native xattr.\n" "> \n" "> Just on this point: if we're really concerned about the need on shared\n" @@ -48,14 +37,14 @@ "> (like NFS) as well as containerised bind mounts.\n" "\n" "Writing security.ima requires being root with CAP_SYS_ADMIN\n" - "privileges. \302\240I wouldn't want to give root within the namespace\n" + "privileges. ?I wouldn't want to give root within the namespace\n" "permission to over write or just extend the native security.ima.\n" "\n" "Mimi\n" "\n" - "_______________________________________________\n" - "Containers mailing list\n" - "Containers@lists.linux-foundation.org\n" - https://lists.linuxfoundation.org/mailman/listinfo/containers + "--\n" + "To unsubscribe from this list: send the line \"unsubscribe linux-security-module\" in\n" + "the body of a message to majordomo at vger.kernel.org\n" + More majordomo info at http://vger.kernel.org/majordomo-info.html -1e166eba0de5de059947503da501ea3213cb547b207bf9dd553549b22d293752 +591a13577bd9fcf3cb800931c7bcc798855ee9192f5495141f559c59d727b444
diff --git a/a/1.txt b/N2/1.txt index 120dcf4..f99c39f 100644 --- a/a/1.txt +++ b/N2/1.txt @@ -22,8 +22,3 @@ privileges. I wouldn't want to give root within the namespace permission to over write or just extend the native security.ima. Mimi - -_______________________________________________ -Containers mailing list -Containers@lists.linux-foundation.org -https://lists.linuxfoundation.org/mailman/listinfo/containers diff --git a/a/content_digest b/N2/content_digest index a8de4e3..d7b9bc6 100644 --- a/a/content_digest +++ b/N2/content_digest @@ -1,32 +1,9 @@ - "ref\087y3rscz9j.fsf@xmission.com\0" - "ref\020170713164012.brj2flnkaaks2oci@thunk.org\0" - "ref\087k23cb6os.fsf@xmission.com\0" - "ref\0847ccb2a-30c0-a94c-df6f-091c8901eaa0@linux.vnet.ibm.com\0" - "ref\087bmoo8bxb.fsf@xmission.com\0" - "ref\09a3010e5-ca2b-5e7a-656b-fcc14f7bec4e@linux.vnet.ibm.com\0" - "ref\087h8yf7szd.fsf@xmission.com\0" - "ref\065dbe654-0d99-03fa-c838-5a726b462826@linux.vnet.ibm.com\0" - "ref\020170714133437.GA16737@mail.hallyn.com\0" - "ref\0596f808b-e21d-8296-5fef-23c1ce7ab778@linux.vnet.ibm.com\0" - "ref\020170714173556.GA19669@mail.hallyn.com\0" - "ref\01500058090.3583.28.camel@linux.vnet.ibm.com\0" "ref\01500058362.2853.28.camel@HansenPartnership.com\0" - "ref\01500058362.2853.28.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org\0" - "From\0Mimi Zohar <zohar-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>\0" + "From\0Mimi Zohar <zohar@linux.vnet.ibm.com>\0" "Subject\0Re: [PATCH v2] xattr: Enable security.capability in user namespaces\0" "Date\0Fri, 14 Jul 2017 16:03:39 -0400\0" - "To\0James Bottomley <James.Bottomley-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>" - Serge E. Hallyn <serge-A9i7LUbDfNHQT0dZR+AlfA@public.gmane.org> - Stefan Berger <stefanb-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org> - " Mimi Zohar <zohar-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>\0" - "Cc\0containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org" - linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org - linux-security-module-u79uwXL29TY76Z2rM5mHXA@public.gmane.org - Eric W. Biederman <ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org> - casey-iSGtlc1asvQWG2LlvL+J4A@public.gmane.org - Theodore Ts'o <tytso-3s7WtUTddSA@public.gmane.org> - " lkp-JC7UmRfGjtg@public.gmane.org\0" - "\00:1\0" + "To\0lkp@lists.01.org\0" + "\01:1\0" "b\0" "On Fri, 2017-07-14 at 11:52 -0700, James Bottomley wrote:\n" "> On Fri, 2017-07-14 at 14:48 -0400, Mimi Zohar wrote:\n" @@ -51,11 +28,6 @@ "privileges. \302\240I wouldn't want to give root within the namespace\n" "permission to over write or just extend the native security.ima.\n" "\n" - "Mimi\n" - "\n" - "_______________________________________________\n" - "Containers mailing list\n" - "Containers@lists.linux-foundation.org\n" - https://lists.linuxfoundation.org/mailman/listinfo/containers + Mimi -1e166eba0de5de059947503da501ea3213cb547b207bf9dd553549b22d293752 +d3fe8536320236116535ea9400aa44b685c62b0bf0736f3b6e9ee018797ea393
diff --git a/a/1.txt b/N3/1.txt index 120dcf4..f99c39f 100644 --- a/a/1.txt +++ b/N3/1.txt @@ -22,8 +22,3 @@ privileges. I wouldn't want to give root within the namespace permission to over write or just extend the native security.ima. Mimi - -_______________________________________________ -Containers mailing list -Containers@lists.linux-foundation.org -https://lists.linuxfoundation.org/mailman/listinfo/containers diff --git a/a/content_digest b/N3/content_digest index a8de4e3..6630ce0 100644 --- a/a/content_digest +++ b/N3/content_digest @@ -11,21 +11,24 @@ "ref\020170714173556.GA19669@mail.hallyn.com\0" "ref\01500058090.3583.28.camel@linux.vnet.ibm.com\0" "ref\01500058362.2853.28.camel@HansenPartnership.com\0" - "ref\01500058362.2853.28.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org\0" - "From\0Mimi Zohar <zohar-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>\0" + "From\0Mimi Zohar <zohar@linux.vnet.ibm.com>\0" "Subject\0Re: [PATCH v2] xattr: Enable security.capability in user namespaces\0" "Date\0Fri, 14 Jul 2017 16:03:39 -0400\0" - "To\0James Bottomley <James.Bottomley-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>" - Serge E. Hallyn <serge-A9i7LUbDfNHQT0dZR+AlfA@public.gmane.org> - Stefan Berger <stefanb-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org> - " Mimi Zohar <zohar-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>\0" - "Cc\0containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org" - linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org - linux-security-module-u79uwXL29TY76Z2rM5mHXA@public.gmane.org - Eric W. Biederman <ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org> - casey-iSGtlc1asvQWG2LlvL+J4A@public.gmane.org - Theodore Ts'o <tytso-3s7WtUTddSA@public.gmane.org> - " lkp-JC7UmRfGjtg@public.gmane.org\0" + "To\0James Bottomley <James.Bottomley@hansenpartnership.com>" + Serge E. Hallyn <serge@hallyn.com> + Stefan Berger <stefanb@linux.vnet.ibm.com> + " Mimi Zohar <zohar@us.ibm.com>\0" + "Cc\0Eric W. Biederman <ebiederm@xmission.com>" + Theodore Ts'o <tytso@mit.edu> + containers@lists.linux-foundation.org + lkp@01.org + linux-kernel@vger.kernel.org + tycho@docker.com + vgoyal@redhat.com + christian.brauner@mailbox.org + amir73il@gmail.com + linux-security-module@vger.kernel.org + " casey@schaufler-ca.com\0" "\00:1\0" "b\0" "On Fri, 2017-07-14 at 11:52 -0700, James Bottomley wrote:\n" @@ -51,11 +54,6 @@ "privileges. \302\240I wouldn't want to give root within the namespace\n" "permission to over write or just extend the native security.ima.\n" "\n" - "Mimi\n" - "\n" - "_______________________________________________\n" - "Containers mailing list\n" - "Containers@lists.linux-foundation.org\n" - https://lists.linuxfoundation.org/mailman/listinfo/containers + Mimi -1e166eba0de5de059947503da501ea3213cb547b207bf9dd553549b22d293752 +568f438ae65837ddace815fbb4b2cb48a5846ad33a63e14211502e95b25dd1f6
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.