Linux Integrity Measurement development
 help / color / mirror / Atom feed
* [RFC] Finding the right target branch for patches that span IMA and SeLinux
@ 2020-10-29 23:33 Tushar Sugandhi
  2020-10-30  0:32 ` Mimi Zohar
  0 siblings, 1 reply; 10+ messages in thread
From: Tushar Sugandhi @ 2020-10-29 23:33 UTC (permalink / raw)
  To: Mimi Zohar, stephen.smalley.work, paul
  Cc: SELinux, Tyler Hicks, Lakshmi Ramasubramanian, linux-integrity

Hello Mimi/Stephen/Paul,

As you are already aware, we have several patch-sets in review for
IMA infrastructure for measurement of critical kernel data and it's
usage.

[1] infrastructure for measurement of critical data patch-set:

https://patchwork.kernel.org/project/linux-integrity/list/?series=354437

[2] Using [1] to measure SeLinux data:
     https://patchwork.kernel.org/patch/11801585/

[3] Using [1] to measure dm-crypt data:

https://patchwork.kernel.org/project/linux-integrity/list/?series=366903

[4] Using [1] to measure kernel_version:
     https://patchwork.kernel.org/patch/11854625/

[5] built-in IMA policy rule to handle critical data before
     a custom IMA policy is loaded:
     {Patch is not yet sent for public review}

Mimi has suggested that patch-set [1] should include a demonstrative
example use of the functionality in the same series. And that example
should be SeLinux (patch-set [2]).

However, SeLinux patch-set [2] depends on the functionality in SeLinux
branch [7], which is not yet merged in Integrity branch [6].
Therefore SeLinux patch-set [2] does not apply on the Integrity branch
at this time.

Further, SeLinux patch-set [2] also depends on the new code for
critical data infrastructure (patch-set [1] and [5]) which is all
IMA code. Patch-set [1] and [5], even though all IMA code, applies
cleanly on SeLinux branch - along with patch-set [2].

For the above reason, the new series we are going to post, which
combines [1], [2], and [5], needs to be based on SeLinux branch.

Since [1] and [5] contains IMA code - we wanted to confirm with the
maintainers if there are any concerns to base the series on SeLinux
branch.

Thanks,
Tushar

[6] Integrity Repo/Branch:
Repo: 
https://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity.git
Branch: linux-integrity

[7] SeLinux Branch:
Repo: https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux.git
Branch: next

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2020-11-03 18:57 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2020-10-29 23:33 [RFC] Finding the right target branch for patches that span IMA and SeLinux Tushar Sugandhi
2020-10-30  0:32 ` Mimi Zohar
2020-10-30 16:43   ` Tushar Sugandhi
2020-10-30 20:37     ` Paul Moore
2020-11-01  3:08       ` Tushar Sugandhi
2020-11-02 16:35         ` Mimi Zohar
2020-11-02 20:38           ` Tushar Sugandhi
2020-11-03  3:11         ` Paul Moore
2020-11-03 12:25           ` Mimi Zohar
2020-11-03 18:57           ` Lakshmi Ramasubramanian

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox