netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 00/13] NetLabel cleanups for 2.6.20
@ 2006-11-17 22:38 paul.moore
  2006-11-17 22:38 ` [PATCH 01/13] NetLabel: use gfp_t instead of int where it makes sense paul.moore
                   ` (13 more replies)
  0 siblings, 14 replies; 20+ messages in thread
From: paul.moore @ 2006-11-17 22:38 UTC (permalink / raw)
  To: netdev, selinux; +Cc: jmorris

This patchset consists of a lot of small-ish cleanups for NetLabel and in some
cases labeled networking in general.  I've tested these patches for the past
few days and I haven't seen any regressions so please consider them for the
net-2.6.20 git tree.

The patches are fairly varied so it doesn't make sense to go into too much
details here, please see each patch for an explanation of what it does.

--
paul moore
linux security @ hp

^ permalink raw reply	[flat|nested] 20+ messages in thread
* Re: [PATCH 10/13] NetLabel: use cipso_v4_doi_search() for local CIPSOv4 functions
@ 2006-11-24 18:59 Paul Moore
  0 siblings, 0 replies; 20+ messages in thread
From: Paul Moore @ 2006-11-24 18:59 UTC (permalink / raw)
  To: viro; +Cc: eparis, netdev, selinux, jmorris, aviro

-----Original Message-----
From: Al Viro <viro@ftp.linux.org.uk>
Date: Friday, Nov 24, 2006 2:07 am
Subject: Re: [PATCH 10/13] NetLabel: use cipso_v4_doi_search() for local CIPSOv4 functions

On Thu, Nov 23, 2006 at 08:24:34PM -0500, Eric Paris wrote:
> On Fri, 2006-11-17 at 17:38 -0500, paul.moore@hp.com wrote:
> 
> > Index: net-2.6.20_netlabel-base-work/net/ipv4/cipso_ipv4.c
> > ===================================================================
> > --- net-2.6.20_netlabel-base-work.orig/net/ipv4/cipso_ipv4.c
> > +++ net-2.6.20_netlabel-base-work/net/ipv4/cipso_ipv4.c
> > @@ -1136,7 +1136,7 @@ int cipso_v4_validate(unsigned char **op
> >  	}
> >  
> >  	rcu_read_lock();
> > -	doi_def = cipso_v4_doi_getdef(ntohl(*((__be32 *)&opt[2])));
> > +	doi_def = cipso_v4_doi_search(ntohl(*((u32 *)&opt[2])));
> >  	if (doi_def == NULL) {
> >  		err_offset = 2;
> >  		goto validate_return_locked;
> 
> 
> This appears to reverse the previous endian work by Al Viro, was this
> intended?
>
>Mismerge, most likely.  Fixed in net-2.6.20 since then (
>commit 835ec2525544c744333bf0da00049f323eb75c58
>Author: Al Viro <viro@zeniv.linux.org.uk>
>Date:   Mon Nov 20 18:08:37 2006 -0800
>
>    [CIPSO]: Missing annotation in cipso_ipv4 update.
>) 
>
>Note that there are two changes in that line - u32 -> __be32 and
>..._getdef -> ..._search.  They do not really conflict, but any merge tool would throw a conflict at that point and apparently it got
>resolved the dumb way...
>

Yep, Al is right, I just made a dumb mistake when merging my code with the latest net-2.6.20 tree.  I thought I caught everything but it looks like I missed one.  Sorry.

. paul moore
. linux security @ hp


^ permalink raw reply	[flat|nested] 20+ messages in thread

end of thread, other threads:[~2006-11-24 19:00 UTC | newest]

Thread overview: 20+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-11-17 22:38 [PATCH 00/13] NetLabel cleanups for 2.6.20 paul.moore
2006-11-17 22:38 ` [PATCH 01/13] NetLabel: use gfp_t instead of int where it makes sense paul.moore
2006-11-17 22:38 ` [PATCH 02/13] NetLabel: convert the unlabeled accept flag to use RCU paul.moore
2006-11-17 22:38 ` [PATCH 03/13] NetLabel: change netlbl_secattr_init() to return void paul.moore
2006-11-17 22:38 ` [PATCH 04/13] NetLabel: make netlbl_lsm_secattr struct easier/quicker to understand paul.moore
2006-11-17 22:38 ` [PATCH 05/13] NetLabel: check for a CIPSOv4 option before we do call into the CIPSOv4 layer paul.moore
2006-11-17 22:38 ` [PATCH 06/13] NetLabel: add tag verification when adding new CIPSOv4 DOI definitions paul.moore
2006-11-17 22:38 ` [PATCH 07/13] NetLabel: fixup the handling of CIPSOv4 tags to allow for multiple tag types paul.moore
2006-11-17 22:38 ` [PATCH 08/13] NetLabel: return the correct error for translated CIPSOv4 tags paul.moore
2006-11-17 22:38 ` [PATCH 09/13] NetLabel: use the correct CIPSOv4 MLS label limits paul.moore
2006-11-17 22:38 ` [PATCH 10/13] NetLabel: use cipso_v4_doi_search() for local CIPSOv4 functions paul.moore
2006-11-24  1:24   ` Eric Paris
2006-11-24  5:53     ` Al Viro
2006-11-17 22:38 ` [PATCH 11/13] NetLabel: SELinux cleanups paul.moore
2006-11-17 22:38 ` [PATCH 12/13] SELinux: peer secid consolidation for external network labeling paul.moore
2006-11-17 22:38 ` [PATCH 13/13] NetLabel: honor the audit_enabled flag paul.moore
2006-11-18  4:12 ` [PATCH 00/13] NetLabel cleanups for 2.6.20 [GIT] James Morris
2006-11-18 16:10   ` Paul Moore
2006-11-19  3:19     ` James Morris
  -- strict thread matches above, loose matches on Subject: below --
2006-11-24 18:59 [PATCH 10/13] NetLabel: use cipso_v4_doi_search() for local CIPSOv4 functions Paul Moore

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).