From: paul.moore@hp.com
To: netdev@vger.kernel.org, selinux@tycho.nsa.gov
Cc: davem@davemloft.net, sds@epoch.ncsc.mil, jmorris@redhat.com,
pratt@argus-systems.com
Subject: [PATCH 0/7] Updated patchset w/James' comments
Date: Mon, 17 Jul 2006 11:52:24 -0400 [thread overview]
Message-ID: <20060717155224.060020000@hp.com> (raw)
Some changes in the patchset based on James Morris' comments over the weekend, in
addition I rebased the patchset against 2.6.18-rc2. For those who want/need some
background and missed my posting last week I have pasted the announcement below.
Once again, please consider this patchset for inclusion into the 2.6.19 kernel.
Thanks.
--
I am posting this patchset for consideration and inclusion into the 2.6.19
kernel, it is against 2.6.18-rc1 [now rebased against 2.6.18-rc2].
This patchset introduces NetLabel, a implementation of explicit packet
labeling (i.e. CIPSO), to the Linux kernel. NetLabel has been designed to
have as minimal an impact on the base networking stack as possible; this
includes both code changes as well as performance. I, as well as many others
who have posted to various lists on earlier NetLabel patches, believe that an
interoperable form of labeled networking is important for Linux's success in
the Trusted OS arena currently being dominated by commercial UNIX systems.
DaveM, I know you have previously posted that you feel CIPSO does not belong
in the Linux kernel on principle, however, I'm hoping the arguments posted
in response have softened your position ...
Earlier versions of this patchset have been posted to the netdev, SELinux,
LSM and RH-LSPP mailing lists over the past couple of months. It now contains
several rounds of comments and has been tested on a variety of architectures
by people on the RH-LSPP mailing list over the course of the last several
weeks.
If accepted into the mainline kernel, both HP and myself pledge to maintain
this code.
- Notes on Performance
This past week there was a thread on the RH-LSPP list where the performance of
the NetLabel patch was measured and discussed using the 2.6.17 kernel. A copy
of the discussion can be found here:
* http://www.redhat.com/archives/redhat-lspp/2006-July/msg00063.html
With the conclusion being that performance should not be an issue.
Unfortunately the vanilla 2.6.18-rc1 kernel has problems on the two machines
I use for performance testing so I am not currently able to update the
NetLabel performance numbers for 2.6.18-rc1.
- Notes on Interoperability Testing
The NetLabel CIPSO implementation has been tested against Trusted Solaris and
HP-UX CMW without problems.
- Instructions for Testing
For those of you wishing to test this patchset you will need the latest
release of the netlabel_tools tarball found here:
* http://free.linux.hp.com/~pmoore/projects/linux_cipso
You also may want to make use of the "toy policy module" for SELinux which has
been posted to the RH-LSPP mailing list, the archived message can be found
here:
* http://www.redhat.com/archives/redhat-lspp/2006-June/msg00243.html
Thanks.
--
paul moore
linux security @ hp
next reply other threads:[~2006-07-17 15:58 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-07-17 15:52 paul.moore [this message]
2006-07-17 15:52 ` [PATCH 1/7] NetLabel: documentation paul.moore
2006-07-28 7:51 ` David Miller
2006-07-28 18:52 ` Paul Moore
2006-07-17 15:52 ` [PATCH 2/7] NetLabel: core network changes paul.moore
2006-07-28 7:55 ` David Miller
2006-07-28 18:45 ` Paul Moore
2006-07-28 19:55 ` David Miller
2006-07-28 11:24 ` Thomas Graf
2006-07-28 17:58 ` Paul Moore
2006-07-28 18:12 ` Thomas Graf
2006-07-28 18:39 ` Paul Moore
2006-07-28 18:58 ` Thomas Graf
2006-07-28 19:08 ` Paul Moore
2006-07-28 19:43 ` Evgeniy Polyakov
2006-07-28 19:58 ` David Miller
2006-07-28 20:09 ` Paul Moore
2006-07-28 20:56 ` David Miller
2006-07-28 20:59 ` Paul Moore
2006-07-17 15:52 ` [PATCH 3/7] NetLabel: CIPSOv4 engine paul.moore
2006-07-28 7:56 ` David Miller
2006-07-17 15:52 ` [PATCH 4/7] NetLabel: core NetLabel subsystem paul.moore
2006-07-17 15:52 ` [PATCH 5/7] NetLabel: CIPSOv4 and Unlabeled packet integration paul.moore
2006-07-17 15:52 ` [PATCH 6/7] NetLabel: SELinux support paul.moore
2006-07-17 15:52 ` [PATCH 7/7] NetLabel: tie NetLabel into the Kconfig system paul.moore
2006-07-17 18:48 ` [PATCH 0/7] Updated patchset w/James' comments Valdis.Kletnieks
2006-07-17 19:00 ` Paul Moore
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20060717155224.060020000@hp.com \
--to=paul.moore@hp.com \
--cc=davem@davemloft.net \
--cc=jmorris@redhat.com \
--cc=netdev@vger.kernel.org \
--cc=pratt@argus-systems.com \
--cc=sds@epoch.ncsc.mil \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).