Linux Integrity Measurement development
 help / color / mirror / Atom feed
From: Mimi Zohar <zohar@linux.ibm.com>
To: Tushar Sugandhi <tusharsu@linux.microsoft.com>,
	stephen.smalley.work@gmail.com, paul@paul-moore.com
Cc: SELinux <selinux@vger.kernel.org>,
	Tyler Hicks <tyhicks@linux.microsoft.com>,
	Lakshmi Ramasubramanian <nramas@linux.microsoft.com>,
	linux-integrity@vger.kernel.org
Subject: Re: [RFC] Finding the right target branch for patches that span IMA and SeLinux
Date: Thu, 29 Oct 2020 20:32:12 -0400	[thread overview]
Message-ID: <f99f0f03aecc778826d79eb83d60cfd1a95196c5.camel@linux.ibm.com> (raw)
In-Reply-To: <703ced1a-3a48-f29e-9141-af78415d8402@linux.microsoft.com>

On Thu, 2020-10-29 at 16:33 -0700, Tushar Sugandhi wrote:
> Hello Mimi/Stephen/Paul,
> 
> As you are already aware, we have several patch-sets in review for
> IMA infrastructure for measurement of critical kernel data and it's
> usage.
> 
> [1] infrastructure for measurement of critical data patch-set:
> 
> https://patchwork.kernel.org/project/linux-integrity/list/?series=354437
> 
> [2] Using [1] to measure SeLinux data:
>      https://patchwork.kernel.org/patch/11801585/
> 
> [3] Using [1] to measure dm-crypt data:
> 
> https://patchwork.kernel.org/project/linux-integrity/list/?series=366903
> 
> [4] Using [1] to measure kernel_version:
>      https://patchwork.kernel.org/patch/11854625/
> 
> [5] built-in IMA policy rule to handle critical data before
>      a custom IMA policy is loaded:
>      {Patch is not yet sent for public review}
> 
> Mimi has suggested that patch-set [1] should include a demonstrative
> example use of the functionality in the same series. And that example
> should be SeLinux (patch-set [2]).
> 
> However, SeLinux patch-set [2] depends on the functionality in SeLinux
> branch [7], which is not yet merged in Integrity branch [6].
> Therefore SeLinux patch-set [2] does not apply on the Integrity branch
> at this time.
> 
> Further, SeLinux patch-set [2] also depends on the new code for
> critical data infrastructure (patch-set [1] and [5]) which is all
> IMA code. Patch-set [1] and [5], even though all IMA code, applies
> cleanly on SeLinux branch - along with patch-set [2].
> 
> For the above reason, the new series we are going to post, which
> combines [1], [2], and [5], needs to be based on SeLinux branch.
> 
> Since [1] and [5] contains IMA code - we wanted to confirm with the
> maintainers if there are any concerns to base the series on SeLinux
> branch.
> 
> Thanks,
> Tushar
> 
> [6] Integrity Repo/Branch:
> Repo: 
> https://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity.git
> Branch: linux-integrity
> 
> [7] SeLinux Branch:
> Repo: https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux.git
> Branch: next

Unless this patch set is specifically dependent on the two patches in
the SELinux tree beyond v5.10.0-rc1, please base it on v5.10.0-rc1.

thanks,

Mimi



  reply	other threads:[~2020-10-30  0:32 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-10-29 23:33 [RFC] Finding the right target branch for patches that span IMA and SeLinux Tushar Sugandhi
2020-10-30  0:32 ` Mimi Zohar [this message]
2020-10-30 16:43   ` Tushar Sugandhi
2020-10-30 20:37     ` Paul Moore
2020-11-01  3:08       ` Tushar Sugandhi
2020-11-02 16:35         ` Mimi Zohar
2020-11-02 20:38           ` Tushar Sugandhi
2020-11-03  3:11         ` Paul Moore
2020-11-03 12:25           ` Mimi Zohar
2020-11-03 18:57           ` Lakshmi Ramasubramanian

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=f99f0f03aecc778826d79eb83d60cfd1a95196c5.camel@linux.ibm.com \
    --to=zohar@linux.ibm.com \
    --cc=linux-integrity@vger.kernel.org \
    --cc=nramas@linux.microsoft.com \
    --cc=paul@paul-moore.com \
    --cc=selinux@vger.kernel.org \
    --cc=stephen.smalley.work@gmail.com \
    --cc=tusharsu@linux.microsoft.com \
    --cc=tyhicks@linux.microsoft.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox