From mboxrd@z Thu Jan 1 00:00:00 1970 Return-path: Received: from out03.mta.xmission.com ([166.70.13.233]) by bombadil.infradead.org with esmtps (Exim 4.90_1 #2 (Red Hat Linux)) id 1fEGWj-0000nu-F0 for kexec@lists.infradead.org; Thu, 03 May 2018 15:52:14 +0000 From: ebiederm@xmission.com (Eric W. Biederman) References: <1523572911-16363-1-git-send-email-zohar@linux.vnet.ibm.com> <1523572911-16363-3-git-send-email-zohar@linux.vnet.ibm.com> <87h8nqglpx.fsf@xmission.com> <1525275904.5669.308.camel@linux.vnet.ibm.com> Date: Thu, 03 May 2018 10:51:38 -0500 In-Reply-To: <1525275904.5669.308.camel@linux.vnet.ibm.com> (Mimi Zohar's message of "Wed, 02 May 2018 11:45:04 -0400") Message-ID: <87h8nospo5.fsf@xmission.com> MIME-Version: 1.0 Subject: Re: [PATCH 2/3] kexec: call LSM hook for kexec_load syscall List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Sender: "kexec" Errors-To: kexec-bounces+dwmw2=infradead.org@lists.infradead.org To: Mimi Zohar Cc: kexec@lists.infradead.org, linux-kernel@vger.kernel.org, Matthew Garrett , David Howells , linux-security-module@vger.kernel.org, linux-integrity@vger.kernel.org TWltaSBab2hhciA8em9oYXJAbGludXgudm5ldC5pYm0uY29tPiB3cml0ZXM6Cgo+IE9uIFdlZCwg MjAxOC0wNS0wMiBhdCAwOTo0NSAtMDUwMCwgRXJpYyBXLiBCaWVkZXJtYW4gd3JvdGU6Cj4+IE1p bWkgWm9oYXIgPHpvaGFyQGxpbnV4LnZuZXQuaWJtLmNvbT4gd3JpdGVzOgo+PiAKPj4gPiBBbGxv dyBMU01zIGFuZCBJTUEgdG8gZGlmZmVyZW50aWF0ZSBiZXR3ZWVuIHRoZSBrZXhlY19sb2FkIGFu ZAo+PiA+IGtleGVjX2ZpbGVfbG9hZCBzeXNjYWxscyBieSBhZGRpbmcgYW4gInVubmVjZXNzYXJ5 IiBjYWxsIHRvCj4+ID4gc2VjdXJpdHlfa2VybmVsX3JlYWRfZmlsZSgpIGluIGtleGVjX2xvYWQu ICBUaGlzIHdvdWxkIGJlIHNpbWlsYXIgdG8gdGhlCj4+ID4gZXhpc3RpbmcgaW5pdF9tb2R1bGUg c3lzY2FsbCBjYWxsaW5nIHNlY3VyaXR5X2tlcm5lbF9yZWFkX2ZpbGUoKS4KPj4gCj4+IEdpdmVu IHRoZSByZWFzb25hYmxlIGRlc2lyZSB0byBsb2FkIGEgcG9saWN5IHRoYXQgZW5zdXJlcyBldmVy eXRoaW5nCj4+IGhhcyBhIHNpZ25hdHVyZSBJIGRvbid0IGhhdmUgZnVuZGFtZW50YWwgb2JqZWN0 aW9ucy4KPj4gCj4+IHNlY3VyaXR5X2tlcm5lbF9yZWFkX2ZpbGUgYXMgYSBob29rIHNlZW1zIGFu IG9kZCBjaG9pY2UuICBBdCB0aGUgdmVyeQo+PiBsZWFzdCBpdCBoYXMgYSBiYWQgbmFtZSBiZWNh dXNlIHRoZXJlIGlzIG5vIGZpbGUgcmVhZGluZyBnb2luZyBvbiBoZXJlLgo+PiAKPj4gSSBhbSBj b25jZXJuZWQgdGhhdCBJIGRvbid0IHNlZSBDT05GSUdfS0VYRUNfVkVSSUZZX1NJRyBiZWluZyB0 ZXN0ZWQKPj4gYW55d2hlcmUuICBXaGljaCBtZWFucyBJIGNvdWxkIGhhdmUgYSBrZXJuZWwgY29t cGlsZWQgd2l0aG91dCB0aGF0IGFuZCBJCj4+IHdvdWxkIGJlIGFsbG93ZWQgdG8gdXNlIGtleGVj X2ZpbGVfbG9hZCB3aXRob3V0IHNpZ25hdHVyZSBjaGVja2luZy4KPj4gV2hpbGUga2V4ZWNfbG9h ZCB3b3VsZCBiZSBkZW5pZWQuCj4+IAo+PiBBbSBJIG1pc3Npbmcgc29tZXRoaW5nIGhlcmU/Cj4K PiBUaGUga2V4ZWNfZmlsZV9sb2FkKCkgY2FsbHMga2VybmVsX3JlYWRfZmlsZV9mcm9tX2ZkKCks IHdoaWNoIGluIHR1cm4KPiBjYWxscyBzZWN1cml0eV9rZXJuZWxfcmVhZF9maWxlKCkuIMKgU28g a2V4ZWNfZmlsZV9sb2FkIGFuZCBrZXhlY19sb2FkCj4gc3lzY2FsbCB3b3VsZCBiZSB1c2luZyB0 aGUgc2FtZSBtZXRob2QgZm9yIGVuZm9yY2luZyBzaWduYXR1cmUKPiB2ZXJpZmljYXRpb24uCgpI YXZpbmcgbG9va2VkIGF0IHlvdXIgcGF0Y2hlcyBhbmQgdGhlIGtlcm5lbCBhIGxpdHRsZSBtb3Jl IEkgdGhpbmsKdGhpcyBzaG91bGQgYmUgYSBzZXBhcmF0ZSBzZWN1cml0eSBob29rIHRoYXQgZG9l cyBub3QgdGFrZSBhIGZpbGUKcGFyYW1ldGVyLgoKUmlnaHQgbm93IGV2ZXJ5IG90aGVyIHNlY3Vy aXR5IG1vZHVsZSBhc3N1bWVzICFmaWxlIGlzIGluaXRfbW9kdWxlLgpTbyBJIHRoaW5rIHRoaXMg Y2hhbmdlIGhhcyB0aGUgcG90ZW50aWFsIHRvIGNvbmZ1c2Ugb3RoZXIgc2VjdXJpdHkKbW9kdWxl cywgd2l0aCB0aGUgcmVzdWx0IG9mIHVuaW50ZW5kZWQgcG9saWN5IGJlaW5nIGFwcGxpZWQuCgpT byBqdXN0IGZvciBnb29kIHNlY3VyaXR5IG1vZHVsZSBoeWdlaW5lIEkgdGhpbmsgdGhpcyBuZWVk cyBhIGRlZGljYXRlZAprZXhlY19sb2FkIHNlY3VyaXR5IGhvb2suCgoKPiBUaGlzIGlzIGluZGVw ZW5kZW50IG9mIHRoZSBhcmNoaXRlY3R1cmUgc3BlY2lmaWMgbWV0aG9kIGZvciB2ZXJpZnlpbmcK PiBzaWduYXR1cmVzLiDCoFRoZSBjb29yZGluYXRpb24gYmV0d2VlbiB0aGVzZSB0d28gbWV0aG9k cyB3YXMgaW5jbHVkZWQKPiBpbiB0aGUgbG9ja2Rvd24gcGF0Y2ggc2V0LCBidXQgaXMgYmVpbmcg cmVtb3ZlZCwgYXMgd2VsbCB0aGUgZ2F0aW5nIG9mCj4ga2V4ZWNfbG9hZCBzeXNjYWxsLiDCoElu c3RlYWQgb2YgYmVpbmcgYmFzZWQgb24gdGhlIGxvY2tkb3duIGZsYWcsIEkKPiBhc3N1bWUgdGhl IGNvb3JkaW5hdGlvbiBiZXR3ZWVuIHRoZSB0d28gbWV0aG9kcyB3aWxsIHJlYXBwZWFyIGJhc2Vk IG9uCj4gYSBzZWN1cmUgYm9vdCBmbGFnIG9mIHNvbWUgc29ydC4KCkkgd2FzIGJsaW5kIHRoZXJl IGZvciBhIG1vbWVudC4gIFllcyB0aGlzIGlzIGFsbCBhYm91dCB0aGUgaW1hIHhhdHRycwphbGxv d2luZyBhIGZpbGUgdG8gYmUgbG9hZGVkLgoKRXJpYwoKCl9fX19fX19fX19fX19fX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fCmtleGVjIG1haWxpbmcgbGlzdAprZXhlY0BsaXN0cy5p bmZyYWRlYWQub3JnCmh0dHA6Ly9saXN0cy5pbmZyYWRlYWQub3JnL21haWxtYW4vbGlzdGluZm8v a2V4ZWMK