All of lore.kernel.org
 help / color / mirror / Atom feed
From: Lakshmi Ramasubramanian <nramas@linux.microsoft.com>
To: Paul Moore <paul@paul-moore.com>
Cc: Ondrej Mosnacek <omosnace@redhat.com>,
	Stephen Smalley <stephen.smalley.work@gmail.com>,
	Mimi Zohar <zohar@linux.ibm.com>,
	Casey Schaufler <casey@schaufler-ca.com>,
	Tyler Hicks <tyhicks@linux.microsoft.com>,
	tusharsu@linux.microsoft.com, Sasha Levin <sashal@kernel.org>,
	James Morris <jmorris@namei.org>,
	linux-integrity@vger.kernel.org,
	SElinux list <selinux@vger.kernel.org>,
	LSM List <linux-security-module@vger.kernel.org>,
	linux-kernel <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH] SELinux: Measure state and hash of policy using IMA
Date: Tue, 25 Aug 2020 13:49:44 -0700	[thread overview]
Message-ID: <07854807-c495-b7e5-fc44-26d78ff14f1b@linux.microsoft.com> (raw)
In-Reply-To: <CAHC9VhQP7_rV+Oi6weLjVhrx2d8iu9UJ8zeE=ZcqnBMqngrJ4Q@mail.gmail.com>

On 8/24/20 3:18 PM, Paul Moore wrote:

Hi Paul,

>>>>> Is Ondrej's re-try approach I need to use to workaround policy reload issue?
>>>>
>>>> No, I think perhaps we should move the mutex to selinux_state instead
>>>> of selinux_fs_info.  selinux_fs_info has a pointer to selinux_state so
>>>> it can then use it indirectly.  Note that your patches are going to
>>>> conflict with other ongoing work in the selinux next branch that is
>>>> refactoring policy load and converting the policy rwlock to RCU.
>>>
>>> Yeah, and I'm experimenting with a patch on top of Stephen's RCU work
>>> that would allow you to do this in a straightforward way without even
>>> messing with the fsi->mutex. My patch may or may not be eventually
>>> committed, but either way I'd recommend holding off on this for a
>>> while until the dust settles around the RCU conversion.
>>
>> I can make the SELinux\IMA changes in "selinux next branch" taking
>> dependencies on Stephen's patches + relevant IMA patches.
> 
> I know it can be frustrating to hear what I'm about to say, but the
> best option is probably just to wait a little to let things settle in
> the SELinux -next branch.  There is a lot of stuff going on right now
> with patches flooding in (at least "flooding" from a SELinux kernel
> development perspective) and we/I've haven't gotten through all of
> them yet.
> 

Could you please let me know when the current set of changes in SELinux 
next branch would be completed and be ready to take new changes?

I mean, roughly - would it be a month from now or you expect that to 
take longer?

thanks,
  -lakshmi


  reply	other threads:[~2020-08-25 20:49 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-08-22  1:00 [PATCH] SELinux: Measure state and hash of policy using IMA Lakshmi Ramasubramanian
2020-08-24 14:00 ` Stephen Smalley
2020-08-24 14:35   ` Lakshmi Ramasubramanian
2020-08-24 18:13   ` Lakshmi Ramasubramanian
2020-08-24 19:29     ` Stephen Smalley
2020-08-24 20:01       ` Ondrej Mosnacek
2020-08-24 21:29         ` Lakshmi Ramasubramanian
2020-08-24 22:18           ` Paul Moore
2020-08-25 20:49             ` Lakshmi Ramasubramanian [this message]
2020-08-26 12:51               ` Stephen Smalley
2020-08-31 14:47                 ` Stephen Smalley
2020-08-31 16:39                   ` Lakshmi Ramasubramanian
2020-09-07 21:38 Lakshmi Ramasubramanian
2020-09-07 22:32 ` Stephen Smalley
2020-09-08  4:44   ` Lakshmi Ramasubramanian
2020-09-08 11:58     ` Stephen Smalley
2020-09-08 16:01       ` Lakshmi Ramasubramanian
2020-09-08 12:28 ` Stephen Smalley
2020-09-08 12:35   ` Stephen Smalley
2020-09-08 13:03   ` Ondrej Mosnacek

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=07854807-c495-b7e5-fc44-26d78ff14f1b@linux.microsoft.com \
    --to=nramas@linux.microsoft.com \
    --cc=casey@schaufler-ca.com \
    --cc=jmorris@namei.org \
    --cc=linux-integrity@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=omosnace@redhat.com \
    --cc=paul@paul-moore.com \
    --cc=sashal@kernel.org \
    --cc=selinux@vger.kernel.org \
    --cc=stephen.smalley.work@gmail.com \
    --cc=tusharsu@linux.microsoft.com \
    --cc=tyhicks@linux.microsoft.com \
    --cc=zohar@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.