Linux Security Modules development
 help / color / mirror / Atom feed
* [PATCH 0/6] ipe: cleanups, an audit fix and updated links
@ 2026-10-03  2:51 Fan Wu
  2026-10-03  2:51 ` [PATCH 1/6] ipe: constify token_default() Fan Wu
                   ` (6 more replies)
  0 siblings, 7 replies; 14+ messages in thread
From: Fan Wu @ 2026-10-03  2:51 UTC (permalink / raw)
  To: linux-security-module

This series contains small IPE cleanups, a fix for an extra empty audit
record, and updated documentation links.

Patches 1-4 are cleanups with no functional change.

Patch 5 fixes an extra empty audit record on enforcement changes.

Patch 6 points the documentation to the new IPE website and test suite
repository.

Fan Wu (6):
  ipe: constify token_default()
  ipe: use designated initializers for audit name tables
  ipe: check parser token table sizes
  ipe: correct policy text ownership comment
  ipe: fix enforcement audit
  ipe: update the project and test suite links

 Documentation/admin-guide/LSM/ipe.rst |  2 +-
 Documentation/security/ipe.rst        |  2 +-
 security/ipe/audit.c                  | 52 ++++++++++++---------------
 security/ipe/policy.c                 |  2 +-
 security/ipe/policy_parser.c          | 10 +++++-
 5 files changed, 34 insertions(+), 34 deletions(-)


base-commit: 72d3fcf802c45d00b300f25b848a93c3a2bd7c7e
-- 
2.55.0


^ permalink raw reply	[flat|nested] 14+ messages in thread

* [PATCH 1/6] ipe: constify token_default()
  2026-10-03  2:51 [PATCH 0/6] ipe: cleanups, an audit fix and updated links Fan Wu
@ 2026-10-03  2:51 ` Fan Wu
  2026-10-03  2:56   ` sashiko-bot
  2026-10-03  2:51 ` [PATCH 2/6] ipe: use designated initializers for audit name tables Fan Wu
                   ` (5 subsequent siblings)
  6 siblings, 1 reply; 14+ messages in thread
From: Fan Wu @ 2026-10-03  2:51 UTC (permalink / raw)
  To: linux-security-module

token_default() does not modify its argument, so make it const.

Assisted-by: LLM
Signed-off-by: Fan Wu <wufan@kernel.org>
---
 security/ipe/policy_parser.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/security/ipe/policy_parser.c b/security/ipe/policy_parser.c
index 6fa5bebf8471..f1c05e53667f 100644
--- a/security/ipe/policy_parser.c
+++ b/security/ipe/policy_parser.c
@@ -201,7 +201,7 @@ static int parse_header(char *line, struct ipe_parsed_policy *p)
  * * %false	- The token is not "DEFAULT"
  * * %true	- The token is "DEFAULT"
  */
-static bool token_default(char *token)
+static bool token_default(const char *token)
 {
 	return !strcmp(token, "DEFAULT");
 }
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 14+ messages in thread

* [PATCH 2/6] ipe: use designated initializers for audit name tables
  2026-10-03  2:51 [PATCH 0/6] ipe: cleanups, an audit fix and updated links Fan Wu
  2026-10-03  2:51 ` [PATCH 1/6] ipe: constify token_default() Fan Wu
@ 2026-10-03  2:51 ` Fan Wu
  2026-10-03  2:59   ` sashiko-bot
  2026-10-03  2:51 ` [PATCH 3/6] ipe: check parser token table sizes Fan Wu
                   ` (4 subsequent siblings)
  6 siblings, 1 reply; 14+ messages in thread
From: Fan Wu @ 2026-10-03  2:51 UTC (permalink / raw)
  To: linux-security-module

The audit name tables are indexed by enum values but initialized
positionally. Adding an enum value in the middle can associate the
following names with the wrong values.

Use designated initializers to bind each name to its enum value.

No functional changes.

Assisted-by: LLM
Signed-off-by: Fan Wu <wufan@kernel.org>
---
 security/ipe/audit.c | 44 ++++++++++++++++++++++----------------------
 1 file changed, 22 insertions(+), 22 deletions(-)

diff --git a/security/ipe/audit.c b/security/ipe/audit.c
index 93fb59fbddd6..5b4f24914c74 100644
--- a/security/ipe/audit.c
+++ b/security/ipe/audit.c
@@ -34,34 +34,34 @@
 				    "new_policy_digest=" IPE_AUDIT_HASH_ALG ":"
 
 static const char *const audit_op_names[__IPE_OP_MAX + 1] = {
-	"EXECUTE",
-	"FIRMWARE",
-	"KMODULE",
-	"KEXEC_IMAGE",
-	"KEXEC_INITRAMFS",
-	"POLICY",
-	"X509_CERT",
-	"UNKNOWN",
+	[IPE_OP_EXEC]			= "EXECUTE",
+	[IPE_OP_FIRMWARE]		= "FIRMWARE",
+	[IPE_OP_KERNEL_MODULE]		= "KMODULE",
+	[IPE_OP_KEXEC_IMAGE]		= "KEXEC_IMAGE",
+	[IPE_OP_KEXEC_INITRAMFS]	= "KEXEC_INITRAMFS",
+	[IPE_OP_POLICY]			= "POLICY",
+	[IPE_OP_X509]			= "X509_CERT",
+	[IPE_OP_INVALID]		= "UNKNOWN",
 };
 
 static const char *const audit_hook_names[__IPE_HOOK_MAX] = {
-	"BPRM_CHECK",
-	"BPRM_CREDS_FOR_EXEC",
-	"MMAP",
-	"MPROTECT",
-	"KERNEL_READ",
-	"KERNEL_LOAD",
+	[IPE_HOOK_BPRM_CHECK]		= "BPRM_CHECK",
+	[IPE_HOOK_BPRM_CREDS_FOR_EXEC]	= "BPRM_CREDS_FOR_EXEC",
+	[IPE_HOOK_MMAP]			= "MMAP",
+	[IPE_HOOK_MPROTECT]		= "MPROTECT",
+	[IPE_HOOK_KERNEL_READ]		= "KERNEL_READ",
+	[IPE_HOOK_KERNEL_LOAD]		= "KERNEL_LOAD",
 };
 
 static const char *const audit_prop_names[__IPE_PROP_MAX] = {
-	"boot_verified=FALSE",
-	"boot_verified=TRUE",
-	"dmverity_roothash=",
-	"dmverity_signature=FALSE",
-	"dmverity_signature=TRUE",
-	"fsverity_digest=",
-	"fsverity_signature=FALSE",
-	"fsverity_signature=TRUE",
+	[IPE_PROP_BOOT_VERIFIED_FALSE]	= "boot_verified=FALSE",
+	[IPE_PROP_BOOT_VERIFIED_TRUE]	= "boot_verified=TRUE",
+	[IPE_PROP_DMV_ROOTHASH]		= "dmverity_roothash=",
+	[IPE_PROP_DMV_SIG_FALSE]	= "dmverity_signature=FALSE",
+	[IPE_PROP_DMV_SIG_TRUE]		= "dmverity_signature=TRUE",
+	[IPE_PROP_FSV_DIGEST]		= "fsverity_digest=",
+	[IPE_PROP_FSV_SIG_FALSE]	= "fsverity_signature=FALSE",
+	[IPE_PROP_FSV_SIG_TRUE]		= "fsverity_signature=TRUE",
 };
 
 /**
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 14+ messages in thread

* [PATCH 3/6] ipe: check parser token table sizes
  2026-10-03  2:51 [PATCH 0/6] ipe: cleanups, an audit fix and updated links Fan Wu
  2026-10-03  2:51 ` [PATCH 1/6] ipe: constify token_default() Fan Wu
  2026-10-03  2:51 ` [PATCH 2/6] ipe: use designated initializers for audit name tables Fan Wu
@ 2026-10-03  2:51 ` Fan Wu
  2026-10-03  2:56   ` sashiko-bot
  2026-10-03  2:51 ` [PATCH 4/6] ipe: correct policy text ownership comment Fan Wu
                   ` (3 subsequent siblings)
  6 siblings, 1 reply; 14+ messages in thread
From: Fan Wu @ 2026-10-03  2:51 UTC (permalink / raw)
  To: linux-security-module

The parser token tables contain one entry for each enum value followed
by a terminator. Add static assertions so adding an enum value without a
corresponding token fails the build.

Assisted-by: LLM
Signed-off-by: Fan Wu <wufan@kernel.org>
---
 security/ipe/policy_parser.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/security/ipe/policy_parser.c b/security/ipe/policy_parser.c
index f1c05e53667f..309a61594e1d 100644
--- a/security/ipe/policy_parser.c
+++ b/security/ipe/policy_parser.c
@@ -128,6 +128,8 @@ static const match_table_t header_tokens = {
 	{__IPE_HEADER_MAX,		NULL}
 };
 
+static_assert(ARRAY_SIZE(header_tokens) == __IPE_HEADER_MAX + 1);
+
 /**
  * parse_header() - Parse policy header information.
  * @line: Supplies header line to be parsed.
@@ -240,6 +242,8 @@ static const match_table_t operation_tokens = {
 	{IPE_OP_INVALID,		NULL}
 };
 
+static_assert(ARRAY_SIZE(operation_tokens) == __IPE_OP_MAX + 1);
+
 /**
  * parse_operation() - Parse the operation type given a token string.
  * @t: Supplies the token string to be parsed.
@@ -259,6 +263,8 @@ static const match_table_t action_tokens = {
 	{IPE_ACTION_INVALID,	NULL}
 };
 
+static_assert(ARRAY_SIZE(action_tokens) == __IPE_ACTION_MAX + 1);
+
 /**
  * parse_action() - Parse the action type given a token string.
  * @t: Supplies the token string to be parsed.
@@ -284,6 +290,8 @@ static const match_table_t property_tokens = {
 	{IPE_PROP_INVALID,		NULL}
 };
 
+static_assert(ARRAY_SIZE(property_tokens) == __IPE_PROP_MAX + 1);
+
 /**
  * parse_property() - Parse a rule property given a token string.
  * @t: Supplies the token string to be parsed.
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 14+ messages in thread

* [PATCH 4/6] ipe: correct policy text ownership comment
  2026-10-03  2:51 [PATCH 0/6] ipe: cleanups, an audit fix and updated links Fan Wu
                   ` (2 preceding siblings ...)
  2026-10-03  2:51 ` [PATCH 3/6] ipe: check parser token table sizes Fan Wu
@ 2026-10-03  2:51 ` Fan Wu
  2026-10-03  2:57   ` sashiko-bot
  2026-10-03  2:51 ` [PATCH 5/6] ipe: fix enforcement audit Fan Wu
                   ` (2 subsequent siblings)
  6 siblings, 1 reply; 14+ messages in thread
From: Fan Wu @ 2026-10-03  2:51 UTC (permalink / raw)
  To: linux-security-module

Policy text is separately allocated only when p->pkcs7 is NULL.
Correct the comment to match the existing free logic.

No functional changes.

Assisted-by: LLM
Signed-off-by: Fan Wu <wufan@kernel.org>
---
 security/ipe/policy.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/security/ipe/policy.c b/security/ipe/policy.c
index 827867be4fac..e542329726bc 100644
--- a/security/ipe/policy.c
+++ b/security/ipe/policy.c
@@ -52,7 +52,7 @@ void ipe_free_policy(struct ipe_policy *p)
 	ipe_del_policyfs_node(p);
 	ipe_free_parsed_policy(p->parsed);
 	/*
-	 * p->text is allocated only when p->pkcs7 is not NULL
+	 * p->text is allocated only when p->pkcs7 is NULL
 	 * otherwise it points to the plaintext data inside the pkcs7
 	 */
 	if (!p->pkcs7)
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 14+ messages in thread

* [PATCH 5/6] ipe: fix enforcement audit
  2026-10-03  2:51 [PATCH 0/6] ipe: cleanups, an audit fix and updated links Fan Wu
                   ` (3 preceding siblings ...)
  2026-10-03  2:51 ` [PATCH 4/6] ipe: correct policy text ownership comment Fan Wu
@ 2026-10-03  2:51 ` Fan Wu
  2026-10-03  2:55   ` sashiko-bot
  2026-10-03  2:51 ` [PATCH 6/6] ipe: update the project and test suite links Fan Wu
  2026-10-06 16:59 ` [PATCH 0/6] ipe: cleanups, an audit fix and updated links Fan Wu
  6 siblings, 1 reply; 14+ messages in thread
From: Fan Wu @ 2026-10-03  2:51 UTC (permalink / raw)
  To: linux-security-module

ipe_audit_enforce() starts an audit buffer but writes the state change
with audit_log(), which logs its own record. Ending the unused buffer
then emits an extra empty AUDIT_MAC_STATUS record.

Remove the unused buffer and log the state change with audit_log()
alone.

Fixes: a68916eaedcd ("ipe: add permissive toggle")
Assisted-by: LLM
Signed-off-by: Fan Wu <wufan@kernel.org>
---
 security/ipe/audit.c | 8 --------
 1 file changed, 8 deletions(-)

diff --git a/security/ipe/audit.c b/security/ipe/audit.c
index 5b4f24914c74..b6f8fb54085a 100644
--- a/security/ipe/audit.c
+++ b/security/ipe/audit.c
@@ -262,18 +262,10 @@ void ipe_audit_policy_load(const struct ipe_policy *const p)
  */
 void ipe_audit_enforce(bool new_enforce, bool old_enforce)
 {
-	struct audit_buffer *ab;
-
-	ab = audit_log_start(audit_context(), GFP_KERNEL, AUDIT_MAC_STATUS);
-	if (!ab)
-		return;
-
 	audit_log(audit_context(), GFP_KERNEL, AUDIT_MAC_STATUS,
 		  "enforcing=%d old_enforcing=%d auid=%u ses=%u"
 		  " enabled=1 old-enabled=1 lsm=ipe res=1",
 		  new_enforce, old_enforce,
 		  from_kuid(&init_user_ns, audit_get_loginuid(current)),
 		  audit_get_sessionid(current));
-
-	audit_log_end(ab);
 }
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 14+ messages in thread

* [PATCH 6/6] ipe: update the project and test suite links
  2026-10-03  2:51 [PATCH 0/6] ipe: cleanups, an audit fix and updated links Fan Wu
                   ` (4 preceding siblings ...)
  2026-10-03  2:51 ` [PATCH 5/6] ipe: fix enforcement audit Fan Wu
@ 2026-10-03  2:51 ` Fan Wu
  2026-10-03  2:55   ` sashiko-bot
  2026-10-06 16:59 ` [PATCH 0/6] ipe: cleanups, an audit fix and updated links Fan Wu
  6 siblings, 1 reply; 14+ messages in thread
From: Fan Wu @ 2026-10-03  2:51 UTC (permalink / raw)
  To: linux-security-module

IPE now has a project website at https://ipe-lsm.org/, and its
integration tests are maintained in the Integrity-Policy-Enforcement/ci
repository.

Point the admin guide to the website, and point the test suite link in
the developer documentation to the new repository.

Assisted-by: LLM
Signed-off-by: Fan Wu <wufan@kernel.org>
---
 Documentation/admin-guide/LSM/ipe.rst | 2 +-
 Documentation/security/ipe.rst        | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/Documentation/admin-guide/LSM/ipe.rst b/Documentation/admin-guide/LSM/ipe.rst
index a756d8158531..978773a256e4 100644
--- a/Documentation/admin-guide/LSM/ipe.rst
+++ b/Documentation/admin-guide/LSM/ipe.rst
@@ -791,7 +791,7 @@ Allow execution of a specific fs-verity file
 Additional Information
 ----------------------
 
-- `Github Repository <https://github.com/microsoft/ipe>`_
+- `IPE website <https://ipe-lsm.org/>`_
 - :doc:`Developer and design docs for IPE </security/ipe>`
 
 FAQ
diff --git a/Documentation/security/ipe.rst b/Documentation/security/ipe.rst
index 5eb3e6265fbd..4490aed5918a 100644
--- a/Documentation/security/ipe.rst
+++ b/Documentation/security/ipe.rst
@@ -442,5 +442,5 @@ IPE has KUnit Tests for the policy parser. Recommended kunitconfig::
   CONFIG_SECURITY_IPE_KUNIT_TEST=y
 
 In addition, IPE has a python based integration
-`test suite <https://github.com/microsoft/ipe/tree/test-suite>`_ that
+`test suite <https://github.com/Integrity-Policy-Enforcement/ci>`_ that
 can test both user interfaces and enforcement functionalities.
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 14+ messages in thread

* Re: [PATCH 5/6] ipe: fix enforcement audit
  2026-10-03  2:51 ` [PATCH 5/6] ipe: fix enforcement audit Fan Wu
@ 2026-10-03  2:55   ` sashiko-bot
  0 siblings, 0 replies; 14+ messages in thread
From: sashiko-bot @ 2026-10-03  2:55 UTC (permalink / raw)
  Cc: linux-security-module

> ipe_audit_enforce() starts an audit buffer but writes the state change
> with audit_log(), which logs its own record. Ending the unused buffer
> then emits an extra empty AUDIT_MAC_STATUS record.
> 
> Remove the unused buffer and log the state change with audit_log()
> alone.
> 
> Fixes: a68916eaedcd ("ipe: add permissive toggle")
> Assisted-by: LLM
> Signed-off-by: Fan Wu <wufan@kernel.org>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261003025135.3666767-1-wufan@kernel.org?part=5


^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: [PATCH 6/6] ipe: update the project and test suite links
  2026-10-03  2:51 ` [PATCH 6/6] ipe: update the project and test suite links Fan Wu
@ 2026-10-03  2:55   ` sashiko-bot
  0 siblings, 0 replies; 14+ messages in thread
From: sashiko-bot @ 2026-10-03  2:55 UTC (permalink / raw)
  Cc: linux-security-module

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] docs: missing test suite link update in zh_CN ipe.rst translation
--

commit 74b3b0aa8d1b1dfdacaa4326fe2dba8c20c146af
Author: Fan Wu <wufan@kernel.org>

ipe: update the project and test suite links

This commit updates the IPE project website and integration tests repository
links in the documentation. It points the developer documentation to the new
test suite repository.

[ ... ]

> diff --git a/Documentation/security/ipe.rst b/Documentation/security/ipe.rst
> index 5eb3e6265fbde..4490aed5918a6 100644
> --- a/Documentation/security/ipe.rst
> +++ b/Documentation/security/ipe.rst
> @@ -442,5 +442,5 @@ IPE has KUnit Tests for the policy parser. Recommended kunitconfig::
>    CONFIG_SECURITY_IPE_KUNIT_TEST=y
>  
>  In addition, IPE has a python based integration
> -`test suite <https://github.com/microsoft/ipe/tree/test-suite>`_ that
> +`test suite <https://github.com/Integrity-Policy-Enforcement/ci>`_ that

[Severity: Low]
Is the translated Chinese documentation missing this update?

Looking at Documentation/translations/zh_CN/security/ipe.rst, it still
points to the old repository:

此外,IPE 具有一个基于 Python 的集成
`测试套件 <https://github.com/microsoft/ipe/tree/test-suite>`_
可以测试用户界面和强制执行功能。

Should this file also be updated to use the new Integrity-Policy-Enforcement/ci
link?

>  can test both user interfaces and enforcement functionalities.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261003025135.3666767-1-wufan@kernel.org?part=6

^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: [PATCH 1/6] ipe: constify token_default()
  2026-10-03  2:51 ` [PATCH 1/6] ipe: constify token_default() Fan Wu
@ 2026-10-03  2:56   ` sashiko-bot
  0 siblings, 0 replies; 14+ messages in thread
From: sashiko-bot @ 2026-10-03  2:56 UTC (permalink / raw)
  Cc: linux-security-module

> token_default() does not modify its argument, so make it const.
> 
> Assisted-by: LLM
> Signed-off-by: Fan Wu <wufan@kernel.org>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261003025135.3666767-1-wufan@kernel.org?part=1


^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: [PATCH 3/6] ipe: check parser token table sizes
  2026-10-03  2:51 ` [PATCH 3/6] ipe: check parser token table sizes Fan Wu
@ 2026-10-03  2:56   ` sashiko-bot
  0 siblings, 0 replies; 14+ messages in thread
From: sashiko-bot @ 2026-10-03  2:56 UTC (permalink / raw)
  Cc: linux-security-module

> The parser token tables contain one entry for each enum value followed
> by a terminator. Add static assertions so adding an enum value without a
> corresponding token fails the build.
> 
> Assisted-by: LLM
> Signed-off-by: Fan Wu <wufan@kernel.org>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261003025135.3666767-1-wufan@kernel.org?part=3


^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: [PATCH 4/6] ipe: correct policy text ownership comment
  2026-10-03  2:51 ` [PATCH 4/6] ipe: correct policy text ownership comment Fan Wu
@ 2026-10-03  2:57   ` sashiko-bot
  0 siblings, 0 replies; 14+ messages in thread
From: sashiko-bot @ 2026-10-03  2:57 UTC (permalink / raw)
  Cc: linux-security-module

> Policy text is separately allocated only when p->pkcs7 is NULL.
> Correct the comment to match the existing free logic.
> 
> No functional changes.
> 
> Assisted-by: LLM
> Signed-off-by: Fan Wu <wufan@kernel.org>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261003025135.3666767-1-wufan@kernel.org?part=4


^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: [PATCH 2/6] ipe: use designated initializers for audit name tables
  2026-10-03  2:51 ` [PATCH 2/6] ipe: use designated initializers for audit name tables Fan Wu
@ 2026-10-03  2:59   ` sashiko-bot
  0 siblings, 0 replies; 14+ messages in thread
From: sashiko-bot @ 2026-10-03  2:59 UTC (permalink / raw)
  Cc: linux-security-module

> The audit name tables are indexed by enum values but initialized
> positionally. Adding an enum value in the middle can associate the
> following names with the wrong values.
> 
> Use designated initializers to bind each name to its enum value.
> 
> No functional changes.
> 
> Assisted-by: LLM
> Signed-off-by: Fan Wu <wufan@kernel.org>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261003025135.3666767-1-wufan@kernel.org?part=2


^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: [PATCH 0/6] ipe: cleanups, an audit fix and updated links
  2026-10-03  2:51 [PATCH 0/6] ipe: cleanups, an audit fix and updated links Fan Wu
                   ` (5 preceding siblings ...)
  2026-10-03  2:51 ` [PATCH 6/6] ipe: update the project and test suite links Fan Wu
@ 2026-10-06 16:59 ` Fan Wu
  6 siblings, 0 replies; 14+ messages in thread
From: Fan Wu @ 2026-10-06 16:59 UTC (permalink / raw)
  To: linux-security-module

On 10/2/2026 7:51 PM, Fan Wu wrote:
> This series contains small IPE cleanups, a fix for an extra empty audit
> record, and updated documentation links.
> 
> Patches 1-4 are cleanups with no functional change.
> 
> Patch 5 fixes an extra empty audit record on enforcement changes.
> 
> Patch 6 points the documentation to the new IPE website and test suite
> repository.
> 
> Fan Wu (6):
>   ipe: constify token_default()
>   ipe: use designated initializers for audit name tables
>   ipe: check parser token table sizes
>   ipe: correct policy text ownership comment
>   ipe: fix enforcement audit
>   ipe: update the project and test suite links
> 
>  Documentation/admin-guide/LSM/ipe.rst |  2 +-
>  Documentation/security/ipe.rst        |  2 +-
>  security/ipe/audit.c                  | 52 ++++++++++++---------------
>  security/ipe/policy.c                 |  2 +-
>  security/ipe/policy_parser.c          | 10 +++++-
>  5 files changed, 34 insertions(+), 34 deletions(-)
> 
> 
> base-commit: 72d3fcf802c45d00b300f25b848a93c3a2bd7c7e

I'm putting this set into ipe/next for testing.

Fan


^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2026-10-06 16:59 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-03  2:51 [PATCH 0/6] ipe: cleanups, an audit fix and updated links Fan Wu
2026-10-03  2:51 ` [PATCH 1/6] ipe: constify token_default() Fan Wu
2026-10-03  2:56   ` sashiko-bot
2026-10-03  2:51 ` [PATCH 2/6] ipe: use designated initializers for audit name tables Fan Wu
2026-10-03  2:59   ` sashiko-bot
2026-10-03  2:51 ` [PATCH 3/6] ipe: check parser token table sizes Fan Wu
2026-10-03  2:56   ` sashiko-bot
2026-10-03  2:51 ` [PATCH 4/6] ipe: correct policy text ownership comment Fan Wu
2026-10-03  2:57   ` sashiko-bot
2026-10-03  2:51 ` [PATCH 5/6] ipe: fix enforcement audit Fan Wu
2026-10-03  2:55   ` sashiko-bot
2026-10-03  2:51 ` [PATCH 6/6] ipe: update the project and test suite links Fan Wu
2026-10-03  2:55   ` sashiko-bot
2026-10-06 16:59 ` [PATCH 0/6] ipe: cleanups, an audit fix and updated links Fan Wu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox