From mboxrd@z Thu Jan 1 00:00:00 1970 From: Stefan Berger Subject: Re: [RFC PATCH v4 3/5] ima: differentiate auditing policy rules from "audit" actions Date: Wed, 16 May 2018 16:28:43 -0400 Message-ID: <2496f165-67f7-304d-08a0-ea8eedd3c3d4__35651.519712019$1526502421$gmane$org@linux.vnet.ibm.com> References: <20180511144230.75384-1-stefanb@linux.vnet.ibm.com> <20180511144230.75384-4-stefanb@linux.vnet.ibm.com> <1526391655.3937.151.camel@linux.vnet.ibm.com> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8"; Format="flowed" Content-Transfer-Encoding: base64 Return-path: In-Reply-To: <1526391655.3937.151.camel-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org> Content-Language: en-MW List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: containers-bounces-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org Errors-To: containers-bounces-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org To: Mimi Zohar , linux-integrity-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org, linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, linux-security-module-u79uwXL29TY76Z2rM5mHXA@public.gmane.org Cc: mkayaalp-4hyTIkVWTs8LubxHQvXPfYdd74u8MsAO@public.gmane.org, sunyuqiong1988-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org, david.safford-JJi787mZWgc@public.gmane.org, James.Bottomley-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org, john.johansen-Z7WLFzj8eWMS+FvcfC7Uqw@public.gmane.org, ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org List-Id: containers.vger.kernel.org T24gMDUvMTUvMjAxOCAwOTo0MCBBTSwgTWltaSBab2hhciB3cm90ZToKPiBIaSBTdGVmYW4sCj4K PiBPbiBGcmksIDIwMTgtMDUtMTEgYXQgMTA6NDIgLTA0MDAsIFN0ZWZhbiBCZXJnZXIgd3JvdGU6 Cj4+IEZyb206IE1pbWkgWm9oYXIgPHpvaGFyQGxpbnV4LnZuZXQuaWJtLmNvbT4KPj4KPj4gVGhl IEFVRElUX0lOVEVHUklUWV9SVUxFIGlzIHVzZWQgZm9yIGF1ZGl0aW5nIElNQSBwb2xpY3kgcnVs ZXMgYW5kCj4+IHRoZSBJTUEgImF1ZGl0IiBwb2xpY3kgYWN0aW9uLiAgVGhpcyBwYXRjaCBkZWZp bmVzIEFVRElUX0lOVEVHUklUWV9QT0xJQ1kKPj4gdG8gcmVmbGVjdCB0aGUgSU1BIHBvbGljeSBy dWxlcy4KPj4KPj4gU2lnbmVkLW9mZi1ieTogTWltaSBab2hhciA8em9oYXJAbGludXgudm5ldC5p Ym0uY29tPgo+IFdlIGRvIG5lZWQgdG8gc2VwYXJhdGUgb3V0IGF1ZGl0aW5nIHRoZSBJTUEgcG9s aWN5IHJ1bGVzIGZyb20gdGhlCj4gIklNQS1hdWRpdCIgbWVzc2FnZXMuIMKgQmFzZWQgb24gdGhl IElNQSBwb2xpY3kgcnVsZSBhc3BlY3Qgb2YgdGhlCj4gZGlzY3Vzc2lvbnMgWzFdLCDCoEkgd291 bGQgcmVhbGx5IGFwcHJlY2lhdGUgaWYgeW91IGNvdWxkIHdvcmsgd2l0aAo+IFJpY2hhcmQgYW5k IFN0ZXZlIG9uIHRoZSBuZXcgSU1BIHBvbGljeSBydWxlIGF1ZGl0IGZvcm1hdC4KSXMgeW91ciBw YXRjaCBiZWxvdyBzdGlsbCB2YWxpZCBmb3Igc3BsaXR0aW5nIGl0IHVwIGludG8gJ3R3byBkaXN0 aW5jdCAKYXVkaXQgcmVjb3JkIHR5cGVzJyA/Cgo+Cj4gVGhpcyBjaGFuZ2UgY2FuIGJlIHVwc3Ry ZWFtZWQgaW5kZXBlbmRlbnRseSBvZiBlaXRoZXIgdGhlIElNQQo+IG5hbWVzcGFjaW5nIG9yIHRo ZSBhdWRpdCBjb250YWluZXJpZCBwYXRjaCBzZXRzLiDCoFRoZSBzb29uZXIgd2UgbWFrZQo+IHRo aXMgY2hhbmdlIGFuZCB1cHN0cmVhbSBpdCwgdGhlIGJldHRlci4KPgo+IFsxXcKgaHR0cHM6Ly93 d3cucmVkaGF0LmNvbS9hcmNoaXZlcy9saW51eC1hdWRpdC8yMDE4LU1hcmNoL21zZzAwMDkyLmh0 bWwKPgo+IHRoYW5rcywKPgo+IE1pbWkKPgo+PiAtLS0KPj4gICBpbmNsdWRlL3VhcGkvbGludXgv YXVkaXQuaCAgICAgICAgICB8IDMgKystCj4+ICAgc2VjdXJpdHkvaW50ZWdyaXR5L2ltYS9pbWFf cG9saWN5LmMgfCAyICstCj4+ICAgMiBmaWxlcyBjaGFuZ2VkLCAzIGluc2VydGlvbnMoKyksIDIg ZGVsZXRpb25zKC0pCj4+Cj4+IGRpZmYgLS1naXQgYS9pbmNsdWRlL3VhcGkvbGludXgvYXVkaXQu aCBiL2luY2x1ZGUvdWFwaS9saW51eC9hdWRpdC5oCj4+IGluZGV4IDRlNjFhOWUwNTEzMi4uODk2 NmU3ZmYxYzRjIDEwMDY0NAo+PiAtLS0gYS9pbmNsdWRlL3VhcGkvbGludXgvYXVkaXQuaAo+PiAr KysgYi9pbmNsdWRlL3VhcGkvbGludXgvYXVkaXQuaAo+PiBAQCAtMTQ2LDcgKzE0Niw4IEBACj4+ ICAgI2RlZmluZSBBVURJVF9JTlRFR1JJVFlfU1RBVFVTCSAgICAxODAyIC8qIEludGVncml0eSBl bmFibGUgc3RhdHVzICovCj4+ICAgI2RlZmluZSBBVURJVF9JTlRFR1JJVFlfSEFTSAkgICAgMTgw MyAvKiBJbnRlZ3JpdHkgSEFTSCB0eXBlICovCj4+ICAgI2RlZmluZSBBVURJVF9JTlRFR1JJVFlf UENSCSAgICAxODA0IC8qIFBDUiBpbnZhbGlkYXRpb24gbXNncyAqLwo+PiAtI2RlZmluZSBBVURJ VF9JTlRFR1JJVFlfUlVMRQkgICAgMTgwNSAvKiBwb2xpY3kgcnVsZSAqLwo+PiArI2RlZmluZSBB VURJVF9JTlRFR1JJVFlfUlVMRQkgICAgMTgwNSAvKiBJTUEgImF1ZGl0IiBhY3Rpb24gcG9saWN5 IG1zZ3MgICovCj4+ICsjZGVmaW5lIEFVRElUX0lOVEVHUklUWV9QT0xJQ1kJICAgIDE4MDYgLyog SU1BIHBvbGljeSBydWxlcyAqLwo+Pgo+PiAgICNkZWZpbmUgQVVESVRfS0VSTkVMCQkyMDAwCS8q IEFzeW5jaHJvbm91cyBhdWRpdCByZWNvcmQuIE5PVCBBIFJFUVVFU1QuICovCj4+Cj4+IGRpZmYg LS1naXQgYS9zZWN1cml0eS9pbnRlZ3JpdHkvaW1hL2ltYV9wb2xpY3kuYyBiL3NlY3VyaXR5L2lu dGVncml0eS9pbWEvaW1hX3BvbGljeS5jCj4+IGluZGV4IDkxNWY1NTcyYzZmZi4uM2ExNDEyZGIw MmEzIDEwMDY0NAo+PiAtLS0gYS9zZWN1cml0eS9pbnRlZ3JpdHkvaW1hL2ltYV9wb2xpY3kuYwo+ PiArKysgYi9zZWN1cml0eS9pbnRlZ3JpdHkvaW1hL2ltYV9wb2xpY3kuYwo+PiBAQCAtNjE5LDcg KzYxOSw3IEBAIHN0YXRpYyBpbnQgaW1hX3BhcnNlX3J1bGUoY2hhciAqcnVsZSwgc3RydWN0IGlt YV9ydWxlX2VudHJ5ICplbnRyeSkKPj4gICAJYm9vbCB1aWRfdG9rZW47Cj4+ICAgCWludCByZXN1 bHQgPSAwOwo+Pgo+PiAtCWFiID0gYXVkaXRfbG9nX3N0YXJ0KE5VTEwsIEdGUF9LRVJORUwsIEFV RElUX0lOVEVHUklUWV9SVUxFKTsKPj4gKwlhYiA9IGF1ZGl0X2xvZ19zdGFydChOVUxMLCBHRlBf S0VSTkVMLCBBVURJVF9JTlRFR1JJVFlfUE9MSUNZKTsKPj4KPj4gICAJZW50cnktPnVpZCA9IElO VkFMSURfVUlEOwo+PiAgIAllbnRyeS0+Zm93bmVyID0gSU5WQUxJRF9VSUQ7CgoKX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KQ29udGFpbmVycyBtYWlsaW5n IGxpc3QKQ29udGFpbmVyc0BsaXN0cy5saW51eC1mb3VuZGF0aW9uLm9yZwpodHRwczovL2xpc3Rz LmxpbnV4Zm91bmRhdGlvbi5vcmcvbWFpbG1hbi9saXN0aW5mby9jb250YWluZXJz