All of lore.kernel.org
 help / color / mirror / Atom feed
From: Casey Schaufler <casey@schaufler-ca.com>
To: Andrew Morgan <morgan@kernel.org>, casey@schaufler-ca.com
Cc: akpm@osdl.org, torvalds@osdl.org, linux-kernel@vger.kernel.org,
	linux-security-module@vger.kernel.org
Subject: Re: [PATCH] -mm (2.6.24-rc3-mm1) Smack using capabilities 32 and 33
Date: Sun, 25 Nov 2007 09:13:31 -0800 (PST)	[thread overview]
Message-ID: <201388.56853.qm@web36605.mail.mud.yahoo.com> (raw)
In-Reply-To: <4749A3EF.1010606@kernel.org>


--- Andrew Morgan <morgan@kernel.org> wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> 
> 
> Casey Schaufler wrote:
> > diff -uprN -X linux-2.6.24-rc3-mm1-base/Documentation/dontdiff
> linux-2.6.24-rc3-mm1-base/include/linux/capability.h
> linux-2.6.24-rc3-mm1-smack/include/linux/capability.h
> > --- linux-2.6.24-rc3-mm1-base/include/linux/capability.h	2007-11-22
> 01:51:36.000000000 -0800
> > +++ linux-2.6.24-rc3-mm1-smack/include/linux/capability.h	2007-11-24
> 11:26:51.000000000 -0800
> > @@ -314,6 +314,23 @@ typedef struct kernel_cap_struct {
> >  
> >  #define CAP_SETFCAP	     31
> >  
> > +/* Override MAC access.
> > +   The base kernel enforces no MAC policy.
> > +   An LSM may enforce a MAC policy, and if it does and it chooses
> > +   to implement capability based overrides of that policy, this is
> > +   the capability it should use to do so. */
> > +
> > +#define CAP_MAC_OVERRIDE     32
> > +
> > +/* Allow MAC configuration or state changes.
> > +   The base kernel requires no MAC configuration.
> > +   An LSM may enforce a MAC policy, and if it does and it chooses
> > +   to implement capability based checks on modifications to that
> > +   policy or the data required to maintain it, this is the
> > +   capability it should use to do so. */
> > +
> > +#define CAP_MAC_ADMIN        33
> > +
> >  /*
> >   * Bit location of each capability (used by user-space library and kernel)
> >   */
> > @@ -334,7 +351,8 @@ typedef struct kernel_cap_struct {
> >  			    | CAP_TO_MASK(CAP_DAC_OVERRIDE)	\
> >  			    | CAP_TO_MASK(CAP_DAC_READ_SEARCH)	\
> >  			    | CAP_TO_MASK(CAP_FOWNER)		\
> > -			    | CAP_TO_MASK(CAP_FSETID))
> > +			    | CAP_TO_MASK(CAP_FSETID) \
> 
> The following looks a bit fishy:
> > +			    | CAP_TO_MASK(CAP_MAC_OVERRIDE))
> 
>   (1<<32) & 0xffffffff == 0
> 
> I think you need to define CAP_FS_MASK_B1.

I think you're right, and I'll need to use it, too.


Casey Schaufler
casey@schaufler-ca.com

  reply	other threads:[~2007-11-25 17:13 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-11-25  5:53 [PATCH] -mm (2.6.24-rc3-mm1) Smack using capabilities 32 and 33 Casey Schaufler
2007-11-25 16:33 ` Andrew Morgan
2007-11-25 17:13   ` Casey Schaufler [this message]
2007-11-26 16:28 ` Serge E. Hallyn

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=201388.56853.qm@web36605.mail.mud.yahoo.com \
    --to=casey@schaufler-ca.com \
    --cc=akpm@osdl.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=morgan@kernel.org \
    --cc=torvalds@osdl.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.