Re: [Xen-devel] [PATCH] flask: Add check for io{port, mem}con sorting

2018-10-03 Thread Jan Beulich
>>> "DeGraaf, Daniel G" 10/02/18 7:39 PM >>> >> From: Jan Beulich >> >>> On 28.09.18 at 21:13, wrote: >> > These entries are not always sorted by checkpolicy. Enforce the sorting >> > (which can be done manually if using an unpatched checkpolicy) when >> > loading the policy so that later uses

Re: [Xen-devel] [PATCH] flask: Add check for io{port, mem}con sorting

2018-10-02 Thread DeGraaf, Daniel G
> From: Jan Beulich > >>> On 28.09.18 at 21:13, wrote: > > These entries are not always sorted by checkpolicy. Enforce the sorting > > (which can be done manually if using an unpatched checkpolicy) when > > loading the policy so that later uses by the security server do not > > incorrectly use t

Re: [Xen-devel] [PATCH] flask: Add check for io{port, mem}con sorting

2018-10-02 Thread nicolas . poirot
> To: xen-devel@lists.xenproject.org > From: Daniel De Graaf > Sent by: "Xen-devel" > Date: 09/28/2018 09:13PM > Cc: George Dunlap , Daniel De Graaf > Subject: [Xen-devel] [PATCH] flask: Add check for io{port,mem}con sorting > > These entries are not always s

Re: [Xen-devel] [PATCH] flask: Add check for io{port, mem}con sorting

2018-10-02 Thread Jan Beulich
>>> On 28.09.18 at 21:13, wrote: > These entries are not always sorted by checkpolicy. Enforce the sorting > (which can be done manually if using an unpatched checkpolicy) when > loading the policy so that later uses by the security server do not > incorrectly use the initial sid. "Enforce the s

[Xen-devel] [PATCH] flask: Add check for io{port,mem}con sorting

2018-09-28 Thread Daniel De Graaf
These entries are not always sorted by checkpolicy. Enforce the sorting (which can be done manually if using an unpatched checkpolicy) when loading the policy so that later uses by the security server do not incorrectly use the initial sid. Reported-by: Nicolas Poirot Signed-off-by: Daniel De Gr