All of lore.kernel.org
 help / color / mirror / Atom feed
From: kernel test robot <lkp@intel.com>
To: Stefan Berger <stefanb@linux.vnet.ibm.com>,
	linux-integrity@vger.kernel.org
Cc: kbuild-all@lists.01.org, zohar@linux.ibm.com, serge@hallyn.com,
	christian.brauner@ubuntu.com, containers@lists.linux.dev,
	dmitry.kasatkin@gmail.com, ebiederm@xmission.com,
	krzysztof.struczynski@huawei.com, roberto.sassu@huawei.com,
	mpeters@redhat.com
Subject: Re: [PATCH v7 04/14] ima: Move policy related variables into ima_namespace
Date: Thu, 16 Dec 2021 22:26:08 +0800	[thread overview]
Message-ID: <202112162247.XcCvdc6L-lkp@intel.com> (raw)
In-Reply-To: <20211216054323.1707384-5-stefanb@linux.vnet.ibm.com>

Hi Stefan,

Thank you for the patch! Yet something to improve:

[auto build test ERROR on zohar-integrity/next-integrity]
[also build test ERROR on linux/master linus/master v5.16-rc5]
[cannot apply to jmorris-security/next-testing next-20211215]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch]

url:    https://github.com/0day-ci/linux/commits/Stefan-Berger/ima-Namespace-IMA-with-audit-support-in-IMA-ns/20211216-134611
base:   https://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity.git next-integrity
config: alpha-buildonly-randconfig-r004-20211216 (https://download.01.org/0day-ci/archive/20211216/202112162247.XcCvdc6L-lkp@intel.com/config)
compiler: alpha-linux-gcc (GCC) 11.2.0
reproduce (this is a W=1 build):
        wget https://raw.githubusercontent.com/intel/lkp-tests/master/sbin/make.cross -O ~/bin/make.cross
        chmod +x ~/bin/make.cross
        # https://github.com/0day-ci/linux/commit/4927ddb1c276a9aa164fced45c2614ec93b5b425
        git remote add linux-review https://github.com/0day-ci/linux
        git fetch --no-tags linux-review Stefan-Berger/ima-Namespace-IMA-with-audit-support-in-IMA-ns/20211216-134611
        git checkout 4927ddb1c276a9aa164fced45c2614ec93b5b425
        # save the config file to linux build tree
        mkdir build_dir
        COMPILER_INSTALL_PATH=$HOME/0day COMPILER=gcc-11.2.0 make.cross O=build_dir ARCH=alpha SHELL=/bin/bash security/integrity/ima/

If you fix the issue, kindly add following tag as appropriate
Reported-by: kernel test robot <lkp@intel.com>

All errors (new ones prefixed by >>):

   security/integrity/ima/ima_policy.c: In function 'ima_update_policy':
>> security/integrity/ima/ima_policy.c:1014:9: error: too many arguments to function 'ima_process_queued_keys'
    1014 |         ima_process_queued_keys(ns);
         |         ^~~~~~~~~~~~~~~~~~~~~~~
   In file included from security/integrity/ima/ima_policy.c:23:
   security/integrity/ima/ima.h:276:20: note: declared here
     276 | static inline void ima_process_queued_keys(void) {}
         |                    ^~~~~~~~~~~~~~~~~~~~~~~


vim +/ima_process_queued_keys +1014 security/integrity/ima/ima_policy.c

   980	
   981	/**
   982	 * ima_update_policy - update default_rules with new measure rules
   983	 * @ns: IMA namespace that has the policy
   984	 * Called on file .release to update the default rules with a complete new
   985	 * policy.  What we do here is to splice ima_policy_rules and ima_temp_rules so
   986	 * they make a queue.  The policy may be updated multiple times and this is the
   987	 * RCU updater.
   988	 *
   989	 * Policy rules are never deleted so ima_policy_flag gets zeroed only once when
   990	 * we switch from the default policy to user defined.
   991	 */
   992	void ima_update_policy(struct ima_namespace *ns)
   993	{
   994		struct list_head *policy = &ns->ima_policy_rules;
   995	
   996		list_splice_tail_init_rcu(&ns->ima_temp_rules, policy,
   997					  synchronize_rcu);
   998	
   999		if (ns->ima_rules != (struct list_head __rcu *)policy) {
  1000			ns->ima_policy_flag = 0;
  1001	
  1002			rcu_assign_pointer(ns->ima_rules, policy);
  1003			/*
  1004			 * IMA architecture specific policy rules are specified
  1005			 * as strings and converted to an array of ima_entry_rules
  1006			 * on boot.  After loading a custom policy, free the
  1007			 * architecture specific rules stored as an array.
  1008			 */
  1009			kfree(arch_policy_entry);
  1010		}
  1011		ima_update_policy_flags(ns);
  1012	
  1013		/* Custom IMA policy has been loaded */
> 1014		ima_process_queued_keys(ns);
  1015	}
  1016	

---
0-DAY CI Kernel Test Service, Intel Corporation
https://lists.01.org/hyperkitty/list/kbuild-all@lists.01.org

WARNING: multiple messages have this Message-ID (diff)
From: kernel test robot <lkp@intel.com>
To: kbuild-all@lists.01.org
Subject: Re: [PATCH v7 04/14] ima: Move policy related variables into ima_namespace
Date: Thu, 16 Dec 2021 22:26:08 +0800	[thread overview]
Message-ID: <202112162247.XcCvdc6L-lkp@intel.com> (raw)
In-Reply-To: <20211216054323.1707384-5-stefanb@linux.vnet.ibm.com>

[-- Attachment #1: Type: text/plain, Size: 3958 bytes --]

Hi Stefan,

Thank you for the patch! Yet something to improve:

[auto build test ERROR on zohar-integrity/next-integrity]
[also build test ERROR on linux/master linus/master v5.16-rc5]
[cannot apply to jmorris-security/next-testing next-20211215]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch]

url:    https://github.com/0day-ci/linux/commits/Stefan-Berger/ima-Namespace-IMA-with-audit-support-in-IMA-ns/20211216-134611
base:   https://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity.git next-integrity
config: alpha-buildonly-randconfig-r004-20211216 (https://download.01.org/0day-ci/archive/20211216/202112162247.XcCvdc6L-lkp(a)intel.com/config)
compiler: alpha-linux-gcc (GCC) 11.2.0
reproduce (this is a W=1 build):
        wget https://raw.githubusercontent.com/intel/lkp-tests/master/sbin/make.cross -O ~/bin/make.cross
        chmod +x ~/bin/make.cross
        # https://github.com/0day-ci/linux/commit/4927ddb1c276a9aa164fced45c2614ec93b5b425
        git remote add linux-review https://github.com/0day-ci/linux
        git fetch --no-tags linux-review Stefan-Berger/ima-Namespace-IMA-with-audit-support-in-IMA-ns/20211216-134611
        git checkout 4927ddb1c276a9aa164fced45c2614ec93b5b425
        # save the config file to linux build tree
        mkdir build_dir
        COMPILER_INSTALL_PATH=$HOME/0day COMPILER=gcc-11.2.0 make.cross O=build_dir ARCH=alpha SHELL=/bin/bash security/integrity/ima/

If you fix the issue, kindly add following tag as appropriate
Reported-by: kernel test robot <lkp@intel.com>

All errors (new ones prefixed by >>):

   security/integrity/ima/ima_policy.c: In function 'ima_update_policy':
>> security/integrity/ima/ima_policy.c:1014:9: error: too many arguments to function 'ima_process_queued_keys'
    1014 |         ima_process_queued_keys(ns);
         |         ^~~~~~~~~~~~~~~~~~~~~~~
   In file included from security/integrity/ima/ima_policy.c:23:
   security/integrity/ima/ima.h:276:20: note: declared here
     276 | static inline void ima_process_queued_keys(void) {}
         |                    ^~~~~~~~~~~~~~~~~~~~~~~


vim +/ima_process_queued_keys +1014 security/integrity/ima/ima_policy.c

   980	
   981	/**
   982	 * ima_update_policy - update default_rules with new measure rules
   983	 * @ns: IMA namespace that has the policy
   984	 * Called on file .release to update the default rules with a complete new
   985	 * policy.  What we do here is to splice ima_policy_rules and ima_temp_rules so
   986	 * they make a queue.  The policy may be updated multiple times and this is the
   987	 * RCU updater.
   988	 *
   989	 * Policy rules are never deleted so ima_policy_flag gets zeroed only once when
   990	 * we switch from the default policy to user defined.
   991	 */
   992	void ima_update_policy(struct ima_namespace *ns)
   993	{
   994		struct list_head *policy = &ns->ima_policy_rules;
   995	
   996		list_splice_tail_init_rcu(&ns->ima_temp_rules, policy,
   997					  synchronize_rcu);
   998	
   999		if (ns->ima_rules != (struct list_head __rcu *)policy) {
  1000			ns->ima_policy_flag = 0;
  1001	
  1002			rcu_assign_pointer(ns->ima_rules, policy);
  1003			/*
  1004			 * IMA architecture specific policy rules are specified
  1005			 * as strings and converted to an array of ima_entry_rules
  1006			 * on boot.  After loading a custom policy, free the
  1007			 * architecture specific rules stored as an array.
  1008			 */
  1009			kfree(arch_policy_entry);
  1010		}
  1011		ima_update_policy_flags(ns);
  1012	
  1013		/* Custom IMA policy has been loaded */
> 1014		ima_process_queued_keys(ns);
  1015	}
  1016	

---
0-DAY CI Kernel Test Service, Intel Corporation
https://lists.01.org/hyperkitty/list/kbuild-all(a)lists.01.org

  reply	other threads:[~2021-12-16 14:27 UTC|newest]

Thread overview: 42+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-12-16  5:43 [PATCH v7 00/14] ima: Namespace IMA with audit support in IMA-ns Stefan Berger
2021-12-16  5:43 ` [PATCH v7 01/14] ima: Add IMA namespace support Stefan Berger
2021-12-16 14:08   ` Christian Brauner
2021-12-16 21:52     ` James Bottomley
2021-12-17  9:55       ` Christian Brauner
2021-12-16  5:43 ` [PATCH v7 02/14] ima: Define ns_status for storing namespaced iint data Stefan Berger
2021-12-16  5:43 ` [PATCH v7 03/14] ima: Namespace audit status flags Stefan Berger
2021-12-16  5:43 ` [PATCH v7 04/14] ima: Move policy related variables into ima_namespace Stefan Berger
2021-12-16 14:26   ` kernel test robot [this message]
2021-12-16 14:26     ` kernel test robot
2021-12-16  5:43 ` [PATCH v7 05/14] ima: Move ima_htable " Stefan Berger
2021-12-16  5:43 ` [PATCH v7 06/14] ima: Move measurement list related variables " Stefan Berger
2021-12-16  5:43 ` [PATCH v7 07/14] ima: Only accept AUDIT rules for IMA non-init_ima_ns namespaces for now Stefan Berger
2021-12-16  5:43 ` [PATCH v7 08/14] ima: Implement hierarchical processing of file accesses Stefan Berger
2021-12-16  5:43 ` [PATCH v7 09/14] securityfs: Only use simple_pin_fs/simple_release_fs for init_user_ns Stefan Berger
2021-12-16  5:43 ` [PATCH v7 10/14] securityfs: Extend securityfs with namespacing support Stefan Berger
2021-12-16 13:40   ` Christian Brauner
2021-12-16 16:28     ` Christian Brauner
2022-01-03 14:09     ` Stefan Berger
2021-12-17 16:21   ` [RFC PATCH] securityfs: securityfs_dir_inode_operations can be static kernel test robot
2021-12-17 16:21     ` kernel test robot
2021-12-17 16:29   ` [PATCH v7 10/14] securityfs: Extend securityfs with namespacing support kernel test robot
2021-12-17 16:29     ` kernel test robot
2021-12-16  5:43 ` [PATCH v7 11/14] ima: Move some IMA policy and filesystem related variables into ima_namespace Stefan Berger
2021-12-16  5:43 ` [PATCH v7 12/14] ima: Use mac_admin_ns_capable() to check corresponding capability Stefan Berger
2021-12-16  5:43 ` [PATCH v7 13/14] ima: Move dentry into ima_namespace and others onto stack Stefan Berger
2021-12-16  5:43 ` [PATCH v7 14/14] ima: Setup securityfs for IMA namespace Stefan Berger
2021-12-16 10:59   ` kernel test robot
2021-12-16 10:59     ` kernel test robot
2021-12-16 12:02   ` kernel test robot
2021-12-16 12:02     ` kernel test robot
2021-12-16 13:51   ` Christian Brauner
2021-12-16 21:38     ` Stefan Berger
2021-12-16 12:50 ` [PATCH v7 00/14] ima: Namespace IMA with audit support in IMA-ns Christian Brauner
2021-12-16 13:31   ` Christian Brauner
2021-12-16 21:27     ` Stefan Berger
2021-12-17 10:25       ` Christian Brauner
2021-12-18  2:38     ` Stefan Berger
2021-12-18 12:41       ` Christian Brauner
2021-12-16 21:00   ` Stefan Berger
2021-12-17 10:06     ` Christian Brauner
2021-12-27 17:29       ` Stefan Berger

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=202112162247.XcCvdc6L-lkp@intel.com \
    --to=lkp@intel.com \
    --cc=christian.brauner@ubuntu.com \
    --cc=containers@lists.linux.dev \
    --cc=dmitry.kasatkin@gmail.com \
    --cc=ebiederm@xmission.com \
    --cc=kbuild-all@lists.01.org \
    --cc=krzysztof.struczynski@huawei.com \
    --cc=linux-integrity@vger.kernel.org \
    --cc=mpeters@redhat.com \
    --cc=roberto.sassu@huawei.com \
    --cc=serge@hallyn.com \
    --cc=stefanb@linux.vnet.ibm.com \
    --cc=zohar@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.