Re: Looking for users of userfaultfd(2) syscall in Fedora

2021-04-07 Thread Florian Weimer
* Colin Walters: > On Tue, Apr 6, 2021, at 4:30 PM, Florian Weimer wrote: >> * Ondrej Mosnacek: >> >> > Kernel 5.12 added support to SELinux for controlling access to the >> > userfaultfd interface [1][2] and we'd like to implement this in >> > Fedora's selinux-policy. However, once we add the

Re: Looking for users of userfaultfd(2) syscall in Fedora

2021-04-07 Thread Colin Walters
On Tue, Apr 6, 2021, at 4:30 PM, Florian Weimer wrote: > * Ondrej Mosnacek: > > > Kernel 5.12 added support to SELinux for controlling access to the > > userfaultfd interface [1][2] and we'd like to implement this in > > Fedora's selinux-policy. However, once we add the corresponding class > >

Re: Looking for users of userfaultfd(2) syscall in Fedora

2021-04-07 Thread Ondrej Mosnacek
On Tue, Apr 6, 2021 at 10:30 PM Florian Weimer wrote: > * Ondrej Mosnacek: > > > Kernel 5.12 added support to SELinux for controlling access to the > > userfaultfd interface [1][2] and we'd like to implement this in > > Fedora's selinux-policy. However, once we add the corresponding class > > to

Re: Looking for users of userfaultfd(2) syscall in Fedora

2021-04-07 Thread Ondrej Mosnacek
On Tue, Apr 6, 2021 at 7:33 PM Zbigniew Jędrzejewski-Szmek wrote: > On Tue, Apr 06, 2021 at 06:57:27PM +0200, Ondrej Mosnacek wrote: > > Hi all, > > > > Kernel 5.12 added support to SELinux for controlling access to the > > userfaultfd interface [1][2] and we'd like to implement this in > >

Re: Looking for users of userfaultfd(2) syscall in Fedora

2021-04-06 Thread Florian Weimer
* Ondrej Mosnacek: > Kernel 5.12 added support to SELinux for controlling access to the > userfaultfd interface [1][2] and we'd like to implement this in > Fedora's selinux-policy. However, once we add the corresponding class > to the policy, all SELinux domains for which we don't add the >

Re: Looking for users of userfaultfd(2) syscall in Fedora

2021-04-06 Thread Florian Weimer
* Zbigniew Jędrzejewski-Szmek: > The code is available. From what I remember, they had a fairly beefy > server dedicated to the indexing... But if somebody provides that, it > should be fairly easy to duplicate. Michael even expressed interest about setting up an instance, if I recall correctly,

Re: Looking for users of userfaultfd(2) syscall in Fedora

2021-04-06 Thread Zbigniew Jędrzejewski-Szmek
On Tue, Apr 06, 2021 at 01:20:33PM -0400, Matthew Miller wrote: > On Tue, Apr 06, 2021 at 05:16:52PM +, Zbigniew Jędrzejewski-Szmek wrote: > > https://codesearch.debian.net/search?q=userfaultfd(=1 > > lists a few candidates… > > You beat me to this suggestion. :) > > I'd love for Fedora to

Re: Looking for users of userfaultfd(2) syscall in Fedora

2021-04-06 Thread Matthew Miller
On Tue, Apr 06, 2021 at 05:16:52PM +, Zbigniew Jędrzejewski-Szmek wrote: > https://codesearch.debian.net/search?q=userfaultfd(=1 > lists a few candidates… You beat me to this suggestion. :) I'd love for Fedora to someday have a similar service! -- Matthew Miller Fedora Project Leader

Re: Looking for users of userfaultfd(2) syscall in Fedora

2021-04-06 Thread Daniel P . Berrangé
On Tue, Apr 06, 2021 at 06:57:27PM +0200, Ondrej Mosnacek wrote: > Hi all, > > Kernel 5.12 added support to SELinux for controlling access to the > userfaultfd interface [1][2] and we'd like to implement this in > Fedora's selinux-policy. However, once we add the corresponding class > to the

Re: Looking for users of userfaultfd(2) syscall in Fedora

2021-04-06 Thread Zbigniew Jędrzejewski-Szmek
On Tue, Apr 06, 2021 at 06:57:27PM +0200, Ondrej Mosnacek wrote: > Hi all, > > Kernel 5.12 added support to SELinux for controlling access to the > userfaultfd interface [1][2] and we'd like to implement this in > Fedora's selinux-policy. However, once we add the corresponding class > to the

Re: Looking for users of userfaultfd(2) syscall in Fedora

2021-04-06 Thread Adrian Reber
On Tue, Apr 06, 2021 at 06:57:27PM +0200, Ondrej Mosnacek wrote: > Hi all, > > Kernel 5.12 added support to SELinux for controlling access to the > userfaultfd interface [1][2] and we'd like to implement this in > Fedora's selinux-policy. However, once we add the corresponding class > to the

Looking for users of userfaultfd(2) syscall in Fedora

2021-04-06 Thread Ondrej Mosnacek
Hi all, Kernel 5.12 added support to SELinux for controlling access to the userfaultfd interface [1][2] and we'd like to implement this in Fedora's selinux-policy. However, once we add the corresponding class to the policy, all SELinux domains for which we don't add the appropriate rules will