From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752118AbbKIPkf (ORCPT ); Mon, 9 Nov 2015 10:40:35 -0500 Received: from mailout3.w1.samsung.com ([210.118.77.13]:33290 "EHLO mailout3.w1.samsung.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751493AbbKIPka (ORCPT ); Mon, 9 Nov 2015 10:40:30 -0500 X-AuditID: cbfec7f4-f79c56d0000012ee-4f-5640be6ad00d Message-id: <1447083624.2216.14.camel@samsung.com> Subject: Re: [PATCH v4 00/11] Smack namespace From: Lukasz Pawelczyk To: "David S. Miller" , "Eric W. Biederman" , "Serge E. Hallyn" , Al Viro , Alexey Dobriyan , Andrew Morton , Andy Lutomirski , Calvin Owens , Casey Schaufler , David Howells , Eric Dumazet , Eric Paris , Greg Kroah-Hartman , James Morris , Jann Horn , Jiri Slaby , Joe Perches , John Johansen , Jonathan Corbet , Kees Cook , Mauro Carvalho Chehab , NeilBrown , Paul Moore , Serge Hallyn , Stephen Smalley , Tejun Heo , Tetsuo Handa , containers@lists.linuxfoundation.org, linux-doc@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, selinux@tycho.nsa.gov Cc: Lukasz Pawelczyk Date: Mon, 09 Nov 2015 16:40:24 +0100 In-reply-to: <1444826525-9758-1-git-send-email-l.pawelczyk@samsung.com> References: <1444826525-9758-1-git-send-email-l.pawelczyk@samsung.com> Content-type: text/plain; charset=UTF-8 X-Mailer: Evolution 3.16.5 (3.16.5-3.fc22) MIME-version: 1.0 Content-transfer-encoding: 7bit X-Brightmail-Tracker: H4sIAAAAAAAAA02SbUhTYRTHe3afe3dnDq7T7KGoYCBBpGkWHSRtFdRNMCrC0A/W0ouvU9uc pUTNtBc1S52kTCt1aaYLTUVSW+Z60fJlhhhkZVQ6wUoNzUxJc6jgt9855/fnnA+HpWS59Do2 MjZBUMcqY+SMA+6Ya3vnHvVUEej55JE35Kf4Q1G1iYHq4k0w0DDDQMdchRgGn11FUGRNwzB6 aRbDfEOaGIZefRVD+pcuClKN1QzMf98KN74dg3bbEA2Fn79haJ+8zEBezbgIOjNVUHLlHoYn 5tcYepuKGBi//pUBa9NDGqps58B8V4fhQ24+hsK0URqeNxsp0A9aMHSnDGOw9nSLYeb+SwTW f220Qs4bdFkMX6h7i/n6B+9FfE7qqJhvNHwS88W1Wv5dcxDf+LBSxNdWpjN8e8Es5ltum8T8 7LQe8cYbepr/NdS/kLy54Hf9Dj6yPthhd5gQE5koqLf5nXKImJmeoeMLVp8z/O3HOqSXZCAJ S7gdpGI6j15kV9IzUM1kIAdWxpUhYizvoxeLCUT6R7pFdkvKbSe2u2axnZ05d9Jo62TszHCe 5E+PmbIHXLhBCRmYGkH2AcVtJmWFqdjOmHMjObfqFiSWlXAHSf1lX3tbxh0gLdmf8LKee6eU WrxoC2kdHlra60Sm9QNLziZSZ/pJZSPOsCJiWKEZVmjFiKpEawRtaLzmdLjKy0OjVGm0seEe oXGqWrT4KZOPkfGVjwVxLJI7Slfl7wmU0cpETZLKgghLyV2k8U2KQJk0TJmULKjjTqq1MYLG gtazWL5Wertp7LiMC1cmCNGCEC+ol6ciVrJOh5w1UxuCKkqYF9f27jsha4Xk4n29k/szs07V ZKT1BfzxstXR2hJFebqTY+z7nqOH/bRupSEVZz3JxY43vfVm7x9VYXln/u3KXj0VrVJ0+oTU fmzz+BWVM+avcN74xmmYbfbNNjlOaqMrJ6xPXRqOH7pwPvFOa4yw0+QaEmBhhnVlcqyJUHpt odQa5X/3LcBwJQMAAA== Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org If I understand correctly the security window for 4.4 has been closed now (as changes went to next). Anyway, I updated the series to the latest smack-for-4.4 branch. Including the new relabel-self interface that received namespace treatment as well. Also the RCU fix reported on the list has been included. The latest version is available here: https://github.com/Havner/smack-namespace/tree/smack-namespace-current Also I've uploaded our Linux Test Project branch I use for Smack and Smack namespace testing (including regressions): https://github.com/Havner/ltp It has the basic smack tests rewritten to C. The ones that were scripts before. They are integrated with LTP framework. Inside testcases/kernel/security/smack/ns is a separate set of tests that share some common functions with the former, but are not otherwise integrated with LTP (yet). In this regard this is very much WIP. Those tests have an advantage though that they run a common set of tests in 6 Smack environments: no namespace, user namespace, user namespace + smack map. Each in a privileged and non-privileged scenario. To run them do the following: cd testcases/kernel/security/smack/ns make ./smack_ns_run.sh smackfs has to be mounted in /smack (following the regular tests). mount -o bind /sys/fs/smackfs /smack is enough. -- Lukasz Pawelczyk Samsung R&D Institute Poland Samsung Electronics