Message ID | 20180815235355.14908-1-casey.schaufler@intel.com (mailing list archive) |
---|---|
Headers | show
Return-Path: <selinux-bounces@tycho.nsa.gov> Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id 3E82F1390 for <patchwork-selinux@patchwork.kernel.org>; Thu, 16 Aug 2018 13:48:02 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 44D9C2AAA1 for <patchwork-selinux@patchwork.kernel.org>; Thu, 16 Aug 2018 13:48:01 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 38E212AAC2; Thu, 16 Aug 2018 13:48:01 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.2 required=2.0 tests=BAYES_00,MAILING_LIST_MULTI, RCVD_IN_DNSWL_MED autolearn=ham version=3.3.1 Received: from USFB19PA13.eemsg.mail.mil (uphb19pa10.eemsg.mail.mil [214.24.26.84]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id 7E8542AAA1 for <patchwork-selinux@patchwork.kernel.org>; Thu, 16 Aug 2018 13:48:00 +0000 (UTC) Received: from emsm-gh1-uea11.ncsc.mil ([214.29.60.3]) by USFB19PA13.eemsg.mail.mil with ESMTP; 16 Aug 2018 13:47:58 +0000 X-IronPort-AV: E=Sophos;i="5.53,247,1531785600"; d="scan'208";a="17089246" IronPort-PHdr: 9a23:AZRduhUjuvCFYpD4iiN+9MeVIRLV8LGtZVwlr6E/grcLSJyIuqrYYRKBv6dThVPEFb/W9+hDw7KP9fy4BypYud6oizMrSNR0TRgLiMEbzUQLIfWuLgnFFsPsdDEwB89YVVVorDmROElRH9viNRWJ+iXhpTEdFQ/iOgVrO+/7BpDdj9it1+C15pbffxhEiCCybL9uLRi6txndutULioZ+N6g9zQfErGFVcOpM32NoIlyTnxf45siu+ZNo7jpdtfE8+cNeSKv2Z6s3Q6BWAzQgKGA1+dbktQLfQguV53sTSXsZnxxVCAXY9h76X5Pxsizntuph3SSRIMP7QawoVTmk8qxkRgXoiCMaPDAn9m/ZhNF7gKZCrB68uxBzxojZa5yXOvVjZKPQZdMUS3RPUMhSUCJPH5u8YokSA+cPMulXs4bzqEUVrRalGQmhBvnixiNSi3Pqw6E31fkqHwHc3AwnGtIDqGrZo8/uNKgMUeG+0bTGwinDb/xMxDf95ozIfQ47ofqRWr9/bdDeyVIxGALFlFmQspDqPzOP2eQQvWib6/RvVfi0hm4mrQFxviagxsM2hobVgYIVz0nJ+CNky4g2Pd21UFN3bNGrHZdKtyyWKpF6Tt0tTm12oio216UKtYO/cSUJ0pgr2hzSZvydf4WM5h/vTuicLDd+iXl4YrywnQyy/lKlyuDkU8m010tFoTRdn9nXs3ANywTT6s+aSvth5kuh2SiA1wTU6uxcPUA7j7DbK588wr4rjJYTsELDHiHxmEXtkqCZal8o+vSo6uv7YrXmoYWQN4lohQHlLqsigMm/AeU8MgQWXmib//qz1KH78EHkT7hHgec6n6nEvJzAO8gWqbC1DxVI3oo77hawFTam0NAWnXkdK1JFfQqKj5P3NFHKIfD4C+q/glu1nDhwwPDGI7vhDYnTIXjYi7rhYbZ85FJcyAo019xf4YlUBasbLPL8XU/xqsTUDgUlPAys3+bnFNJ925scWWKIBK+WKr/SsV+S6eIpOOSMZogVuDD4K/c//P7ukWE2mUUGfaWz2psXcn+4FOx8I0qFeXrsnssBEWASswo8TuzlkkGNUT1IZ3a1WaI85y87BZmoDYfHW4Csj6eO3Dq9Hp1Ke2BKEFeMEW3nd4+cQfcDdDqSItN9kjwDTbWgRY4h1RWrtADk0bpqNeTU9TMFupLkzth6/fXTlQs19Tx2EcuSz32NQ3tznmMSSD88xLp/rlBlylefzah4hORVGsFP6PNMVQc6M4Lcw/FhBtDsRA3BZNaJSVehQtWgGz0xSMw+w8MWaUZnB9qilgzD3zatA7INirOLGIY78rjH0nftIMZ9zmrJ27M6j1k6WMdPM3OphrJn/QjJG4HJi1mZl7qtdakE3y7C7mSDzW2TvExDUw5/S6bFXXcCZkfMqtT5/EzCRae0Cbs7KgtB1dKCKqxSZ9LzkFpGXvbjN8rEY2+qgWi/GROIyqmLbIrwdGUXxD/dB1QckwAP4XaGMhAzBj28rG3DFzFuGlfvYkz2/el4tny7Ulc+zxuWYE15y7q15hkViOSHS/MdxLIEvzwhqylvEVam2dLWDNSBpw97c6Vae9895klI1X7BvQxnIpOgN7xihkIZcwlvsULhzRF3Cplensgwt3Mn1xRyJryC0FxaajOY2Ir8OrrNKmn95BqvcbLZ2knC0NaK/acC8PI4q1TnvAGtCEUi6G5q3MNL3HuG4ZXGFg0SUYj+Ukwv7Rh1u6naYjUh54PTzXBsL6i0vSPe29IuHusp0Aqvf9dYMKOCGw//CMkaB8moKOMwgVipaQgIPOdI9K47J8mmbeeJ2La3POZ8mzKrlWBH4IFm0kKQ7iZ8UfDH35IEw/GewwuGWCzxjEy5ssD2n4BEZC0dHnGlxSjiGoFRerV4fZwXBme2P8232tJ+iob3W35f8F6jA00J2NW1dhqVYV3wxhZQ1VkLrny8gye4yCZ0kz4xpKqFwCPO2/jidAYAOmNTR2ltk1HsIZOvgtAZQkeoaRMplB276kbm3aRbo75/L2bLS0dSYyf2N31iUre3treae85A8o4osSFJX+Ske1+aTKL9rAUA0y74Amte3y40dyuxupnjhBx6j3+dLGxvo3XHd8Fwwg3f5NPCSvJL2DoJWjV4gyHNBlegJ9mp4cmUl5Dbv+CgUWKuS4ZecTftzYydtCu3/2tqDgOjn/qrgN3oDRA60TPn19ltTSjItAzzYpTv16mhLe1nf1VoBV/l58p0AI5+lJE8hJYK2XgVnp+V52YIkX/vMdVH3qLzdHQNSiQNw97J5wjl3VZuLnyXyI3kUXWd2NFuZ8GgYmMR2CIy8dxFCLuO4LxDhyt1rUKyrRjNbvhlgjcd1fwu5WYfg+4TvAotyjuSAqwOHUZCJyPhjBKI4M6irKVMeGmga6Cw21RkkdCnEr6CvhlWWGzldZc6AS9w8sJ/PUrC0H3p9I7rZcLQYsgVth2IlBfAlPNYJ4gtmfoPnyZnPnj9vXI9we4hkRNuxY26vJSAK2h15KK2HAVXOSPzZ8MS5jHtir1TnseI0I+xAJptADILXIHnTfiwCjIdqeznNxqSED07snqUAqHQEQib6EdntHLPD4urO2uMJHYH0dpuXgKdK1JbgAAVWjU6g5E4Gxu2y83hakd5+ysR6kT2qxRW1uJoLB7/UmHFqAevcDc0R4CVLABK4QFa+0fVLcue4/poECFZ8Z2hqwqNJ3eGaAtWFm4JW1aLB1b5Mrmp/9nA/PCSBvCiIPvWfbWOteteWu+SypKgyIRm4SiDO96IPnl6EfI73E9DUmp4G8TdgDoPTCMWmzjKb86Bqxe24jd3odyn8PT3RALv4pOCC6dVMdVq4Ry2m6CDNu+OiyZ/MjlYzJQMymHLyLUEwFESjCRueCW3HrQbqS7BVqTQlbFLDxQDcSN8KNNI774g3glKIcPbiNP1175gjv4yD1dFVEDhld+yaMwPImG9KEnHC1iROLSBPz3LzNn9YbmgRr1IkOVUqxqwtC6YE07jOjSMiSLkVxWoMeFCgiGUIgBeuJ29chZqDGjsUsjqahulP99rlTc226E7hmvWNW4ANjhxa11CrqWK4iNCg/V/AHdM7mJ/IumemiaZ9PHYKpIMvvR3HCt4jeVa4G41y7FN9iFLWOR1mDfOrt5pu1ymlPeAxSBjUBdVqTZLg5mLvVl4NqXf7ZlAWnfE8AgL7WqOFxQAv8FlBcH3u6BM1tjPk7r+KC1c/NLP48QTHdLUJ96HMHc6KhXpGSTUAxYCTT6lLWHfnVJSkfGI+n2TsJc6toDmmIASRb9DSFw1CvQaB1x4E9wFJpd3WC4rnqCfjM4J/nextgfeRN9dvpzdUfKSG/rvIi6DjbZYfxsI3a/4LYMLO4LmwUNidFh6k5nRG0fLR99NuDdhbgg6oUVW7ndxUnAz21jkagOx4H4fD/i0kQAqigFme+Qi6C/s40srJlrNvCYwlE4xmc/7jjCXcT/xK7y9XY5QCyrprUQxNYn7QwltZw2ogUNkLCvER65Wj7Z4bmBklgvcuZpJGf5BQqxJewMfxfaSZ/o0y1tcsTmnyVVB5eTbFZtojBEqfoK0r3JcxwJja8Y4JbDRJKpMyVhQmqKOvy+z2+8swQ8fJ1wC/3iIdC4OpkMIKqEsJzC08ex09QyChzxDdXAWWPouo/Jl6l0yNPyFzyPg1b5DLUaxOPaEIqyCumjPj8iITko+1kMVjUVF+6Z50ds7eUqOS08v1KeRFwgONcfaMg5accxS+WPJcimTr+XC34h1P56nGeDyTe6CrqEUglirHAwxBYQD8twBHoWw0EHfNcrnI6MFyRQp5ATvOlqFCe9Edw+VnzgcosGw1pl30ZNaJjEHDmV3KT+36arPpg82nPqDW887Ym0cXosFKn02WMq6mypCv3pYFTe5z/gXxRSF4TLnuivQCzz8YMZ5a/ePeRNgEte29isj86Kuk17Y7o3eJ33mNdRlotLP8/kVp4yAC/xPVrR9r13clJNGR3O0V27PENi1J5f0a4ktYtz0Cmq6UlKlhDIvSsf9JtCtIbaUgQvwX4ZbrJGb3Cw/Nc+6DjwfFQ18qP0D5KJ9YA0DYoA0YR3zugQ/KaOwPhmX3s+pQ2a3JjtcV+NfwvmiZ7xL0yosafe3yH46QZEgzOm471INRJAMjhHR3vuiaZNRUS7vFXxZfAXPuDc2l3N7OuY03Og/3AvCsUMAPDCTaOxpdGtEsskmClOIPHV2DHA0R1yHgIrC4w6s3qwS8DBHk9ZSz+JFrGD0voXDbzK0RKyrtZLVvjIhbdggv61+L4jjLdWDtJzAgjzfVpnRvxaCUC6iCfVanN1QLzhZQPlMgm4lPsMHtZBG6UorWcc0P6ZPB7U0prC2dTpkCjYfzTMeV4OFxzECnvuw277BmRuKdpQtLgAEuo1YgtQBSy52fj8epKi7WoXUkG+LVHMGLxoN4gRX+g0AjJNwcf7474bSSp9D1SJWqepuUiTXDplo60f7SmaOjFjkVfquju2p0hhWzP/3ztYbXxt/BlRHyOZNikskMrd3JLcMvoTSqD+HaVv6vH7xyOuhPFRR0dbUd0HiA4XYqWrxSTYc+XoJRY9V1H7QC5ISkxZjaKkxoFVAOoemelzx5zY83YRmA6G4Vdy3x1YitXsJXCmqHMZdB+xkrV7aViZobIysqJXgJ5pdWHRQ+IGHp1dfjkptLzazyYBAJMFV/j4MQD9PrC2HvNSsVcJD2dV5D4MXL9d7vHf9Br1LNIaNrH0xp7Pg1GXV+zYiv1em3D+zAbO3T/pF/20CHQUkP3ieqlMxAOQy72jf6U3NslRo/+dBHLePk0RxoDF5Hp9QGjZFz3elL058THNeqeVVNLzVc9BAQ/k1fRKvOQYxFeQh30yS+UF7h2n5bjd3tgtH/yDdQwg0WjUUgrj3nz0esdurOTgAS5JHdT8hdTvKKxqHmSBLuxZSc0NqVIofAtZL4bEb2pZb8dTZREawMy4FWgdiNgUi3fpZi0FDrF2SeTrBAgqwafbPrhp3cN+XrM6tN/n5/QFHiob9vOA58aUDSWemlhe2QdDCtY/8q8GFtleTdKfiLeKwe3jBTCLDjRqon7crE4HK/zTPMApcM5R6z3skboTmCW7PJxtGPLgXJ0tcVaB9ctVGuftXZ8prdacG46NtAQiHRhz3Eoy1sPZGNkrTRSjZLyiZ7uOwu4bT4qLGSej8Zs2MwG3KQ7lrMZd79zb7Havq0Y5E9Ubs3Pdi6F96Q0DcMy+dtNThOh8L5M66e0vmpZ0pGDPbDYx+kHXz205AcNAXTDey8JQCz5NZ6mj/Rv5k0kTpt+1S7bZk45Et47910ce0ObvSKfNCvE9lAxiUAx5n9pAzD2l/WW9ReO4RKPHefagDi8Dhtfz3HbQN6BKJ4+xZdcfHJ0bZl8m+CzCTUwZLkxsapD4BMAScy+CKlLNuRcaiv+j51Von40KiIR4e0LBt+YCE97KTq+/WdBvQw6ILWqrrRsPvtrQjoV6S5fk/mbESfWx6fhOoH/IAVs4HwWfg17olwTgrE8PZELLq4ORDWG4hnjL8h5B9GE0bGusOErqX4Ytenmk5m+vDNt0Va6xCgXiAFRqlEr8E1H6q5DCaIHF/jRHSzx7wQW2y7FjsrS97WyfMzMnsklBTVrapAUdeRS2pOVV3sDmXJgrnqML3ubgp7EExKmHku8yClG29OLNQGM3zI8ecLjcwpFIWip0xW9Ou1JsfGdWjOtcQ8GtxYuHY62y1jy9Lu71HiJbG4sGJ5vXXGmGtgLGYq7qX2D9V0WQ3vVY76tCkN/HB+ceKQ+i22GkNTydzoQzBXwS6qrbDtVAbJVSL0FvXmIwNJtxZ2H441kf65OgsXt0+7wBeFofaaPMEuz/zJDX1wVGFY9I0TSmSyT1XEUzpEVNgAqgzxHrwvN7VlXfX41AoSZV/d1f8hRBuEos2JkQj6FkRwioeHgkAch+bDLSyCkTjM4QIT08DaQ6I3LKiYKc4wVVzwq+z5O/UdeF8Ba0NNvZbjgKUgFdbGpYWsbADT7N9el9d8rXXpgvjC4X8QfjmlGQwOuexQs9H8MAVrX0i7RijRxC485dM864biIyUdq5DeZXMvd584F1h5TMUcixNnQVwjxK+UeAHvuzj5cLbsJWw4Oa0SKktX/kX9wQzB2lmjZv/nl4jod/T1+pHRIzak4L//x5RI3KQvobVzQV8I/IUK423ZLZg62kHJy8GKnIBOdqWbPc97DFpMDXX/FFCGcQMZdUZPMXRgwxUjFPmWK1L/MrBBlCYE5tzd9wv72fvxjA164EzUuD85z+3PpDS9FRNP+tCjCl1j9LDqvMVzeDVCCgN7nmTcwJ1zT+ay5mRF/bw+v2ByNTVV1MFHS42VJxQJDiY9gykQeq1kovmUgWO5s/1np0+aFqaRmatk6QdrqZMDelAhz3g0TdAEID1m+mYs8Go6GtQql1HDJhz4gPYF6lFOZV7Ixv4nNGxRkdgHiv/ZN3Udh02teqOwecM5/9xN1HwZI8cJhIExan36X9STgtpU775oEqWXfgWZNt9U/PEr3ZV6Y16J68IJlidq4Tgri1Up1AuHA8pdLgwoyRUdkbQmA1VWr70t6AbhwodUN55vEpMFnyqOGI6+TXLT6NVjLOeCPYN6DWcUrQOU1l0MiN5Wx601o1ue6Gonf9brGxLhSZ9oPk20zx8WhSwoyrsp7gC2Tg44rG3qC0BuWBZTuWZiyrIDlFDw+oRgKcED3bt80e8YGUCbITu/LlnP9rv+pc773Q5fxojYzUMXf68BCHok6OIHouPvcpYhB6MvsXOcLCyITEWNrQ80hLjW2N93xPfnBly9msLRS+s7Ng+JIWyIcwl3DanGXDHdFYQ5aNEqM7xukQXQ+s2aFNhxmJj39OZRi0MQszABWI1jgkiaWVZf5NP8xgaF7MngjyQpKlJ4hkUYCvIEoSi4oTQn93H2Xo6Tdhx3W/Wu6uFho8q0H1ihtN04S6OuGgIe+zeTcBsHmD51p1Dxuzme/WtrucHRZNkyLSkV/8CKNOj+Wqt2JhxXE+q3LEeEES4MOMZwbfbSSilQ3WCWeuXa2iMgyo5Mknq6BmzIF03bdtFok4+P+bZmJ5TiRfhUbJ1RyWXo1/X1mojPv0Gd1F+hIDyeAEQSuMVIuiVP+Qjxvw4B3MIbmTVBm1xE+KwrlepmM5wPHAkqUH7Z/n9twPrKt2fHjEaHoPA6J184/q3QiSGI3AkhBlzOlRksvzSHEkrt/NNNpOWkcXUivxl3uMfMfRgKyswvpgUgI0noZKZ1MaMbAH50of5JdaTpOORRfLY0QBiQURzeZlcbQLu7JghJfY9WqbPBv0B5FIbH6d+CJcoLGrgsrp/LApufArcfpy1hNXnoqSAYZ4Q73Pf8F92LC7aoBAF4v2yUQF/KZutgjG6LJ02Sz9H6cErBhxtH6NOHd8Nq0ysBJvQ0KKhisSt9kVSv+4MrLq2C/bW2dD/1IJ0G9BT/06COh7VBa92kgJkiPi/hrHL1ZyiJ9nlfIYvXfN2Uyb+Yb/PA4u7JyjGbsn1YENXtaWX0LtkXBGcfgj4WbaLsGuvM/AyshZz8ZBxYOeGlG9l1LrcwtanIjgDqw== X-IPAS-Result: A2BfBACFf3Vb/wHyM5BcHgEGDIUfEhYSjFejXRSBXBUYFIgjNRcBAgEBAQEBAQIBbCiCNSSCZgI3FCAOAwkCQAgIAwEtFRgHCwUYBIMBggKqNIN+AYZihlGEHz+DbweEeQESAYV3Ao1CMIx7BwKBf41RCxWOLpMhgUIBNmFxTSNQgmmQHVZPfYsZgjoBAQ Received: from tarius.tycho.ncsc.mil (HELO tarius.infosec.tycho.ncsc.mil) ([144.51.242.1]) by emsm-gh1-uea11.NCSC.MIL with ESMTP; 16 Aug 2018 13:47:57 +0000 Received: from prometheus.infosec.tycho.ncsc.mil (prometheus.infosec.tycho.ncsc.mil [192.168.25.40]) by tarius.infosec.tycho.ncsc.mil (8.14.4/8.14.4) with ESMTP id w7GDlrjC024182; Thu, 16 Aug 2018 09:47:56 -0400 Received: from tarius.infosec.tycho.ncsc.mil (tarius.infosec.tycho.ncsc.mil [144.51.242.1]) by prometheus.infosec.tycho.ncsc.mil (8.15.2/8.15.2) with ESMTP id w7FNsTRk004965 for <selinux@prometheus.infosec.tycho.ncsc.mil>; Wed, 15 Aug 2018 19:54:29 -0400 Received: from goalie.tycho.ncsc.mil (goalie.infosec.tycho.ncsc.mil [144.51.242.250]) by tarius.infosec.tycho.ncsc.mil (8.14.4/8.14.4) with ESMTP id w7FNsShk004257 for <selinux@tycho.nsa.gov>; Wed, 15 Aug 2018 19:54:29 -0400 X-IronPort-Anti-Spam-Filtered: true X-IronPort-Anti-Spam-Result: A1D5AQDsvHRbfSNjr8ZdhWIWEpgsmCCBegsTiA8hNBgBAgEBAQEBAQIUAQEWOoglEoMiggKsa4N+AYZghk2CR4FYP4NvB4sCAo1yjHkHAoF/jVELFY4skyGBQTeBU00jgzmQHVYfMI5BAQE X-IPAS-Result: A1D5AQDsvHRbfSNjr8ZdhWIWEpgsmCCBegsTiA8hNBgBAgEBAQEBAQIUAQEWOoglEoMiggKsa4N+AYZghk2CR4FYP4NvB4sCAo1yjHkHAoF/jVELFY4skyGBQTeBU00jgzmQHVYfMI5BAQE X-IronPort-AV: E=Sophos;i="5.53,245,1531800000"; d="scan'208";a="347543" Received: from emsm-gh1-uea11.corp.nsa.gov (HELO emsm-gh1-uea11.nsa.gov) ([10.208.41.37]) by goalie.tycho.ncsc.mil with ESMTP; 15 Aug 2018 19:54:22 -0400 IronPort-PHdr: 9a23:+214Fx34+wovGshksmDT+DRfVm0co7zxezQtwd8ZseMeLvad9pjvdHbS+e9qxAeQG9mDtbQc06L/iOPJYSQ4+5GPsXQPItRndiQuroEopTEmG9OPEkbhLfTnPGQQFcVGU0J5rTngaRAGUMnxaEfPrXKs8DUcBgvwNRZvJuTyB4Xek9m72/q99pHPYghEniaxba9vJxiqsAvdsdUbj5F/Iagr0BvJpXVIe+VSxWx2IF+Yggjx6MSt8pN96ipco/0u+dJOXqX8ZKQ4UKdXDC86PGAv5c3krgfMQA2S7XYBSGoWkx5IAw/Y7BHmW5r6ryX3uvZh1CScIMb7S60/Vza/4KdxUBLmiDkJOSM3/m/UjcJ9l75XrA67qhBj2YPYfJ2ZOfxjda3dZ9MaQm9BU95PWiNbGYOzcYsOBPccM+lEr4nyvUYOrRW6BQayHuPk1zhFiWPs0q0hzesgERvK3Bc8ENIOqnvUsdv1NKMMXuCv16TIzDPDb+9I1jf58oTHbhchofSVUL92bMHfylEvGhvYgliUqoHpJS6Z2+YNvmSB6+dtUfijhmAnpgx3vzOh3N0jipPTiYIQ0l3E9Tt2wIIyJdCgRk57ZMWkEJ5fty6AK4d6Xt0uT3hpuCkm1rIKo5C7fC0QxJQmwR7fd+KIc4yS7h3/U+aRJC90hHNjeL2hmxa/6VWsx+n/W8WuzVpHrCpInsPIu30JzRDe5MiKRuN4/ki72DaP0w7T6vtDIUAxjafUN4QuwqUumZsTq0jDBTP5mEXsg6+LeEUk/van6/78b7XnoJ+cK5F7igXkPqsyncy/BPw0MhISUGiD5eS8yLrj8FXiQLpUiv02k6/ZsI3VJMkAuq64AxNa0oYk6xqlCTemy84XkWMILFJCZhLUx7TublLDOvb1CbK/ik6gnTFqwf/uOrz6Ho6LKWDOlqjoebI74ElZjEI3zNZC99dXB6sHLfbbRED8rprbAwU/PgjyxPzoTJ1514UDSSeUD6SEKqLOoBqN4e4yJ+SkeoAYonD+JuIj6vqoimU23RcGcK2o24YHQGypFfRhZUOCaDzjhclFWVwvlyEdCeDrk1afSiV7Y3epQ7l6vmh9D5ipSc/IT5ugkfqa1yeyA5NSa3puC1aQHHOufIKBH78AYTyfZM9olCcJU5CgTZMs0Velswq+g7ZqKOfZ/GsE857k39td5uvPmBV0/jtxS4yeyWCWU2xytmcJQSImmqF5vUF5jFyE1OwwiuZaHNp74/JPTxd8NJjAwug8ANf3CSzbedLcY1+9T8TuOjoxR88/x9IUKxJ2Es6vn1bY1CqjHrERmqajBZoo/6aa1H/0cZUug03a3bUs2gF1CvBEMner0/Zy X-IronPort-Anti-Spam-Filtered: true X-IronPort-Anti-Spam-Result: A0HuAQDsvHRbfSNjr8ZdhWIWEpgtmCCBegsTiBAhNBgBAgEBAQEBAQIBAQIQAQEWOi+CNSKFIBKDIoICrGuDfgGGYIZNgkeBWD+DbweLAgKNcox5BwKBf41RCxWOLJMhgUE3gVRNI4M5kB1WHzCOQQEB X-IPAS-Result: A0HuAQDsvHRbfSNjr8ZdhWIWEpgtmCCBegsTiBAhNBgBAgEBAQEBAQIBAQIQAQEWOi+CNSKFIBKDIoICrGuDfgGGYIZNgkeBWD+DbweLAgKNcox5BwKBf41RCxWOLJMhgUE3gVRNI4M5kB1WHzCOQQEB X-IronPort-AV: E=Sophos;i="5.53,245,1531785600"; d="scan'208";a="7618546" X-IronPort-Outbreak-Status: No, level 0, Unknown - Unknown Received: from fmsmga002-icc.fm.intel.com ([198.175.99.35]) by emsm-gh1-uea11.nsa.gov with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 15 Aug 2018 23:54:02 +0000 Received: from orsmga003.jf.intel.com ([10.7.209.27]) by fmsmga002-icc.fm.intel.com with ESMTP; 15 Aug 2018 16:53:56 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.53,245,1531810800"; d="scan'208";a="75694058" Received: from cschaufl-mobl.amr.corp.intel.com ([10.252.130.105]) by orsmga003.jf.intel.com with ESMTP; 15 Aug 2018 16:53:56 -0700 From: Casey Schaufler <casey.schaufler@intel.com> To: kernel-hardening@lists.openwall.com, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, selinux@tycho.nsa.gov, SMACK-discuss@lists.01.org, casey.schaufler@intel.com, dave.hansen@intel.com, deneen.t.dock@intel.com, kristen@linux.intel.com, arjan@linux.intel.com Date: Wed, 15 Aug 2018 16:53:50 -0700 Message-Id: <20180815235355.14908-1-casey.schaufler@intel.com> X-Mailer: git-send-email 2.17.0 X-Mailman-Approved-At: Thu, 16 Aug 2018 09:42:40 -0400 Subject: [PATCH RFC 0/5] LSM: Add and use a hook for side-channel safety checks X-BeenThere: selinux@tycho.nsa.gov X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Security-Enhanced Linux \(SELinux\) mailing list" <selinux.tycho.nsa.gov> List-Post: <mailto:selinux@tycho.nsa.gov> List-Help: <mailto:selinux-request@tycho.nsa.gov?subject=help> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: selinux-bounces@tycho.nsa.gov Sender: "Selinux" <selinux-bounces@tycho.nsa.gov> X-Virus-Scanned: ClamAV using ClamSMTP |
Series |
LSM: Add and use a hook for side-channel safety checks
|
expand
|
This patchset provide a mechanism by which a security module can advise the system about potential side-channel vulnerabilities. If security_task_safe_sidechannel() returns 0 the security modules do not know of any data that would be subject to a side-channel attack. If the security module maintains data that it believes may be susceptible to a side-channel attack it will return -EACCES. Simple hooks are provided for SELinux and Smack. A new security module is provided to make determinations regarding traditional task attributes, including user IDs, capability sets and namespaces. Signed-off-by: Casey Schaufler <casey.schaufler@intel.com> --- MAINTAINERS | 6 ++ arch/x86/mm/tlb.c | 12 ++- include/linux/lsm_hooks.h | 12 +++ include/linux/security.h | 1 + security/Kconfig | 1 + security/Makefile | 2 + security/security.c | 6 ++ security/selinux/hooks.c | 9 +++ security/sidechannel/Kconfig | 60 ++++++++++++++ security/sidechannel/Makefile | 1 + security/sidechannel/sidechannel.c | 156 +++++++++++++++++++++++++++++++++++++ security/smack/smack_lsm.c | 18 +++++ 12 files changed, 280 insertions(+), 4 deletions(-)