Summary: Configurability of IMM Access control V2
Review request for Trac Ticket(s): 938
Peer Reviewer(s): Anders B & TLC?
Pull request to: <<LIST THE PERSON WITH PUSH ACCESS HERE>>
Affected branch(es): 4.5 & default
Development branch: <<IF ANY GIVE THE REPO URL>>

--------------------------------
Impacted area       Impact y/n
--------------------------------
 Docs                    n
 Build system            n
 RPM/packaging           n
 Configuration files     n
 Startup scripts         n
 SAF services            n
 OpenSAF services        n
 Core libraries          n
 Samples                 n
 Tests                   n
 Other                   n


Comments (indicate scope for each "y" above):
---------------------------------------------

changeset 09d1696802ed782c5720ab3776d3144de8a7fe26
Author: Hans Feldt <[email protected]>
Date:   Fri, 15 Aug 2014 12:00:57 +0200

        immsv: add configurability of access control [#938]

        A new int attribute accessControlMode is added to the OpensafImm class.
        Supported values are: 0 - DISABLED 1 - PERMISSIVE 2 - ENFORCING

        Its default value is DISABLED meaning no access control. This is to be
        backwards compatible for upgrade of existing systems.

        Changes to the mode needs to be done as root e.g. using sudo.

        Permissive access control is done with: sudo immcfg -a 
accessControlMode=1
        opensafImm=opensafImm,safApp=safImmService

        Enforcing access control is done with: sudo immcfg -a 
accessControlMode=2
        opensafImm=opensafImm,safApp=safImmService

        Disabling access control is done with: sudo immcfg -a 
accessControlMode=0
        opensafImm=opensafImm,safApp=safImmService

        An additional UNIX group that allows IMM access can be configured with 
the
        adminGroupName attribute in the OpensafImm class. For example: sudo 
immcfg
        -a adminGroupName=osafimmadm opensafImm=opensafImm,safApp=safImmService

changeset d9faa20e3571cd95728e3d4795c0c8a15d11d882
Author: Hans Feldt <[email protected]>
Date:   Fri, 22 Aug 2014 13:20:23 +0200

        immsv: enforce root user for access control mode changes [#938]


Complete diffstat:
------------------
 osaf/libs/common/immsv/include/immsv_api.h     |   8 ++++++++
 osaf/services/saf/immsv/immloadd/imm_loader.cc |  23 +++++++++++++++++++++--
 osaf/services/saf/immsv/immnd/ImmModel.cc      |  69 
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 osaf/services/saf/immsv/immnd/ImmModel.hh      |   3 +++
 osaf/services/saf/immsv/immnd/immnd_cb.h       |   1 -
 osaf/services/saf/immsv/immnd/immnd_evt.c      |  75 
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-----------------
 osaf/services/saf/immsv/immnd/immnd_init.h     |   3 +++
 osaf/services/saf/immsv/immnd/immnd_main.c     |   2 --
 samples/immsv/OpensafImm_Upgrade_4.5.xml       |  13 +++++++++++++
 9 files changed, 175 insertions(+), 22 deletions(-)


Testing Commands:
-----------------
 See previous review request plus additionally now only root can change mode.


Testing, Expected Results:
--------------------------
 <<PASTE COMMAND OUTPUTS / TEST RESULTS>>


Conditions of Submission:
-------------------------
 <<HOW MANY DAYS BEFORE PUSHING, CONSENSUS ETC>>


Arch      Built     Started    Linux distro
-------------------------------------------
mips        n          n
mips64      n          n
x86         n          n
x86_64      n          n
powerpc     n          n
powerpc64   n          n


Reviewer Checklist:
-------------------
[Submitters: make sure that your review doesn't trigger any checkmarks!]


Your checkin has not passed review because (see checked entries):

___ Your RR template is generally incomplete; it has too many blank entries
    that need proper data filled in.

___ You have failed to nominate the proper persons for review and push.

___ Your patches do not have proper short+long header

___ You have grammar/spelling in your header that is unacceptable.

___ You have exceeded a sensible line length in your headers/comments/text.

___ You have failed to put in a proper Trac Ticket # into your commits.

___ You have incorrectly put/left internal data in your comments/files
    (i.e. internal bug tracking tool IDs, product names etc)

___ You have not given any evidence of testing beyond basic build tests.
    Demonstrate some level of runtime or other sanity testing.

___ You have ^M present in some of your files. These have to be removed.

___ You have needlessly changed whitespace or added whitespace crimes
    like trailing spaces, or spaces before tabs.

___ You have mixed real technical changes with whitespace and other
    cosmetic code cleanup changes. These have to be separate commits.

___ You need to refactor your submission into logical chunks; there is
    too much content into a single commit.

___ You have extraneous garbage in your review (merge commits etc)

___ You have giant attachments which should never have been sent;
    Instead you should place your content in a public tree to be pulled.

___ You have too many commits attached to an e-mail; resend as threaded
    commits, or place in a public tree for a pull.

___ You have resent this content multiple times without a clear indication
    of what has changed between each re-send.

___ You have failed to adequately and individually address all of the
    comments and change requests that were proposed in the initial review.

___ You have a misconfigured ~/.hgrc file (i.e. username, email etc)

___ Your computer have a badly configured date and time; confusing the
    the threaded patch review.

___ Your changes affect IPC mechanism, and you don't present any results
    for in-service upgradability test.

___ Your changes affect user manual and documentation, your patch series
    do not contain the patch that updates the Doxygen manual.


------------------------------------------------------------------------------
Slashdot TV.  
Video for Nerds.  Stuff that matters.
http://tv.slashdot.org/
_______________________________________________
Opensaf-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/opensaf-devel

Reply via email to