From: Mimi Zohar <zohar@linux.ibm.com>
To: Tushar Sugandhi <tusharsu@linux.microsoft.com>,
stephen.smalley.work@gmail.com, paul@paul-moore.com
Cc: SELinux <selinux@vger.kernel.org>,
Tyler Hicks <tyhicks@linux.microsoft.com>,
Lakshmi Ramasubramanian <nramas@linux.microsoft.com>,
linux-integrity@vger.kernel.org
Subject: Re: [RFC] Finding the right target branch for patches that span IMA and SeLinux
Date: Thu, 29 Oct 2020 20:32:12 -0400 [thread overview]
Message-ID: <f99f0f03aecc778826d79eb83d60cfd1a95196c5.camel@linux.ibm.com> (raw)
In-Reply-To: <703ced1a-3a48-f29e-9141-af78415d8402@linux.microsoft.com>
On Thu, 2020-10-29 at 16:33 -0700, Tushar Sugandhi wrote:
> Hello Mimi/Stephen/Paul,
>
> As you are already aware, we have several patch-sets in review for
> IMA infrastructure for measurement of critical kernel data and it's
> usage.
>
> [1] infrastructure for measurement of critical data patch-set:
>
> https://patchwork.kernel.org/project/linux-integrity/list/?series=354437
>
> [2] Using [1] to measure SeLinux data:
> https://patchwork.kernel.org/patch/11801585/
>
> [3] Using [1] to measure dm-crypt data:
>
> https://patchwork.kernel.org/project/linux-integrity/list/?series=366903
>
> [4] Using [1] to measure kernel_version:
> https://patchwork.kernel.org/patch/11854625/
>
> [5] built-in IMA policy rule to handle critical data before
> a custom IMA policy is loaded:
> {Patch is not yet sent for public review}
>
> Mimi has suggested that patch-set [1] should include a demonstrative
> example use of the functionality in the same series. And that example
> should be SeLinux (patch-set [2]).
>
> However, SeLinux patch-set [2] depends on the functionality in SeLinux
> branch [7], which is not yet merged in Integrity branch [6].
> Therefore SeLinux patch-set [2] does not apply on the Integrity branch
> at this time.
>
> Further, SeLinux patch-set [2] also depends on the new code for
> critical data infrastructure (patch-set [1] and [5]) which is all
> IMA code. Patch-set [1] and [5], even though all IMA code, applies
> cleanly on SeLinux branch - along with patch-set [2].
>
> For the above reason, the new series we are going to post, which
> combines [1], [2], and [5], needs to be based on SeLinux branch.
>
> Since [1] and [5] contains IMA code - we wanted to confirm with the
> maintainers if there are any concerns to base the series on SeLinux
> branch.
>
> Thanks,
> Tushar
>
> [6] Integrity Repo/Branch:
> Repo:
> https://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity.git
> Branch: linux-integrity
>
> [7] SeLinux Branch:
> Repo: https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux.git
> Branch: next
Unless this patch set is specifically dependent on the two patches in
the SELinux tree beyond v5.10.0-rc1, please base it on v5.10.0-rc1.
thanks,
Mimi
next prev parent reply other threads:[~2020-10-30 0:32 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-10-29 23:33 [RFC] Finding the right target branch for patches that span IMA and SeLinux Tushar Sugandhi
2020-10-30 0:32 ` Mimi Zohar [this message]
2020-10-30 16:43 ` Tushar Sugandhi
2020-10-30 20:37 ` Paul Moore
2020-11-01 3:08 ` Tushar Sugandhi
2020-11-02 16:35 ` Mimi Zohar
2020-11-02 20:38 ` Tushar Sugandhi
2020-11-03 3:11 ` Paul Moore
2020-11-03 12:25 ` Mimi Zohar
2020-11-03 18:57 ` Lakshmi Ramasubramanian
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f99f0f03aecc778826d79eb83d60cfd1a95196c5.camel@linux.ibm.com \
--to=zohar@linux.ibm.com \
--cc=linux-integrity@vger.kernel.org \
--cc=nramas@linux.microsoft.com \
--cc=paul@paul-moore.com \
--cc=selinux@vger.kernel.org \
--cc=stephen.smalley.work@gmail.com \
--cc=tusharsu@linux.microsoft.com \
--cc=tyhicks@linux.microsoft.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox