[GIT PULL] SELinux fixes for 4.4 (#1)

2015-11-25 Thread Paul Moore
Hi James, A single SELinux fix for 4.4 that corrects a problem with SELinux's conditional rules handling. The fix is small, easily understood, and passes the SELinux testsuite. Please pull and send to Linus. As of a few minutes ago, selinux#upstream applied cleanly on top of linux-

Re: [PATCH 1/2] KEYS: Reserve an extra certificate symbol for inserting without recompiling

2015-11-25 Thread Mimi Zohar
On Tue, 2015-11-24 at 16:18 -0500, Mehmet Kayaalp wrote: > Place a system_extra_cert buffer of configurable size, right after the > system_certificate_list, so that inserted keys can be readily processed by > the existing mechanism. Added script takes a key file and a kernel image > and inserts

Re: [PATCH] KEYS: Fix handling of stored error in a negatively instantiated user key

2015-11-25 Thread David Howells
James Morris wrote: > Is this triggerable by normal users? Yes. David -- To unsubscribe from this list: send the line "unsubscribe linux-security-module" in the body of a message to majord...@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html