public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Paul Moore <pmoore@redhat.com>
To: Stephen Rothwell <sfr@canb.auug.org.au>
Cc: Linus Torvalds <torvalds@linux-foundation.org>,
	linux-audit@redhat.com, linux-kernel@vger.kernel.org
Subject: Re: [GIT PULL] Audit patches for 4.5
Date: Wed, 13 Jan 2016 11:24:29 -0500	[thread overview]
Message-ID: <1633246.WIdWYpcqb3@sifl> (raw)
In-Reply-To: <20160114020325.7f778cda@canb.auug.org.au>

On Thursday, January 14, 2016 02:03:25 AM Stephen Rothwell wrote:
> Hi Paul,
> 
> On Wed, 13 Jan 2016 09:29:55 -0500 Paul Moore <pmoore@redhat.com> wrote:
> > The following changes since commit afd2ff9b7e...:
> >   Linux 4.4 (2016-01-10 15:01:32 -0800)
> > 
> > are available in the git repository at:
> >   git://git.infradead.org/users/pcmoore/audit upstream
> 
> This has all been rebased onto v4.4 (and all the author dates changed) :-(
> 
> And your "next" branch hasn't been updated to match :-(

Hi Stephen,

In December I made some changes to how I manage the SELinux and audit trees:

 * https://www.redhat.com/archives/linux-audit/2015-December/msg00019.html

... I will readily admit it isn't a perfect system, in fact it is a step back 
in some areas, but the changes make it easier for me to get pre-built kernel 
packages to users who are interested in testing the bleeding edge (the Fedora 
COPR repository, see below) and it helps me keep up with weekly testing of 
both the -rcX kernel releases and the changes in the SELinux and audit trees.  
One of the things I've been trying to work on lately is better, more 
automated, testing of the SELinux and audit bits in the Linux kernel; 
unfortunately, some things have had to change a little to help make this 
happen, but I think the more frequent testing outweighs any disadvantages.

The date change is likely a result of moving the patches from audit#next to 
audit#upstream as part of the process mentioned above.  I haven't updated 
audit#next yet because I know you try to keep linux-next quiet until -rc1 is 
released; if that has changed let me know and I'll be happy to update 
audit#next.  Also, if you have any suggestions on how to improve my process, 
I'm always open to new ideas.

For reference, the Fedora COPR repository can be found below, it was announced 
back in November, but only to the relevant lists.  Anyone is welcome to give 
the kernels a try (instructions are provided) and report any problems they 
find.  I tend to push out an update at least once a week to coincide with the 
new -rcX release, although the exact day varies due to merge conflicts, build 
problems, etc.

 * https://copr.fedoraproject.org/coprs/pcmoore/kernel-secnext

Eventually I'd like to do something similar for Debian, Gentoo, distro du 
juor, etc. (I'm hoping if I lower the barrier for testing, more people will 
give it a try) but I'm starting with Fedora Rawhide to get the kinks worked 
out and improve my automation.

-Paul

-- 
paul moore
security @ redhat

  reply	other threads:[~2016-01-13 16:24 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-01-13 14:29 [GIT PULL] Audit patches for 4.5 Paul Moore
2016-01-13 15:03 ` Stephen Rothwell
2016-01-13 16:24   ` Paul Moore [this message]
2016-01-14  0:28     ` Stephen Rothwell
2016-01-14 17:32       ` Paul Moore

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1633246.WIdWYpcqb3@sifl \
    --to=pmoore@redhat.com \
    --cc=linux-audit@redhat.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=sfr@canb.auug.org.au \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox