On Thu, May 13, 2021 at 4:24 PM Casey Schaufler <ca...@schaufler-ca.com> wrote: > > Add a new lsmcontext data structure to hold all the information > about a "security context", including the string, its size and > which LSM allocated the string. The allocation information is > necessary because LSMs have different policies regarding the > lifecycle of these strings. SELinux allocates and destroys > them on each use, whereas Smack provides a pointer to an entry > in a list that never goes away. > > Reviewed-by: Kees Cook <keesc...@chromium.org> > Reviewed-by: John Johansen <john.johan...@canonical.com> > Acked-by: Stephen Smalley <s...@tycho.nsa.gov> > Acked-by: Chuck Lever <chuck.le...@oracle.com> > Signed-off-by: Casey Schaufler <ca...@schaufler-ca.com> > Cc: linux-integr...@vger.kernel.org > Cc: net...@vger.kernel.org > Cc: linux-audit@redhat.com > Cc: netfilter-de...@vger.kernel.org > To: Pablo Neira Ayuso <pa...@netfilter.org> > Cc: linux-...@vger.kernel.org > --- > drivers/android/binder.c | 10 ++++--- > fs/ceph/xattr.c | 6 ++++- > fs/nfs/nfs4proc.c | 8 ++++-- > fs/nfsd/nfs4xdr.c | 7 +++-- > include/linux/security.h | 35 +++++++++++++++++++++++-- > include/net/scm.h | 5 +++- > kernel/audit.c | 14 +++++++--- > kernel/auditsc.c | 12 ++++++--- > net/ipv4/ip_sockglue.c | 4 ++- > net/netfilter/nf_conntrack_netlink.c | 4 ++- > net/netfilter/nf_conntrack_standalone.c | 4 ++- > net/netfilter/nfnetlink_queue.c | 13 ++++++--- > net/netlabel/netlabel_unlabeled.c | 19 +++++++++++--- > net/netlabel/netlabel_user.c | 4 ++- > security/security.c | 11 ++++---- > 15 files changed, 121 insertions(+), 35 deletions(-)
Acked-by: Paul Moore <p...@paul-moore.com> -- paul moore www.paul-moore.com -- Linux-audit mailing list Linux-audit@redhat.com https://listman.redhat.com/mailman/listinfo/linux-audit