RE: [RFC PATCH v7 12/16] fsverity|security: add security hooks to fsverity digest and signature

2021-11-03 Thread Roberto Sassu
> From: Deven Bowers [mailto:deven.de...@linux.microsoft.com] > Sent: Friday, October 15, 2021 9:26 PM > On 10/13/2021 12:24 PM, Eric Biggers wrote: > > On Wed, Oct 13, 2021 at 12:06:31PM -0700, > deven.de...@linux.microsoft.com wrote: > >> From: Fan Wu > >> > >> Add security_inode_setsecurity to

RE: [RFC PATCH v7 04/16] ipe: add userspace interface

2021-11-03 Thread Roberto Sassu
> From: deven.de...@linux.microsoft.com > [mailto:deven.de...@linux.microsoft.com] > From: Deven Bowers > > As is typical with LSMs, IPE uses securityfs as its interface with > userspace. for a complete list of the interfaces and the respective > inputs/outputs, please see the documentation

Re: [PATCH v2 RESEND] powerpc/audit: Convert powerpc to AUDIT_ARCH_COMPAT_GENERIC

2021-11-03 Thread Michael Ellerman
Michael Ellerman writes: > On Tue, 24 Aug 2021 13:36:13 + (UTC), Christophe Leroy wrote: >> Commit e65e1fc2d24b ("[PATCH] syscall class hookup for all normal >> targets") added generic support for AUDIT but that didn't include >> support for bi-arch like powerpc. >> >> Commit 4b58841149dc

Re: [PATCH v2 RESEND] powerpc/audit: Convert powerpc to AUDIT_ARCH_COMPAT_GENERIC

2021-11-03 Thread Michael Ellerman
Paul Moore writes: > On Tue, Nov 2, 2021 at 7:38 AM Michael Ellerman > wrote: >> >> On Tue, 24 Aug 2021 13:36:13 + (UTC), Christophe Leroy wrote: >> > Commit e65e1fc2d24b ("[PATCH] syscall class hookup for all normal >> > targets") added generic support for AUDIT but that didn't include >> >

Re: [PATCH v2 RESEND] powerpc/audit: Convert powerpc to AUDIT_ARCH_COMPAT_GENERIC

2021-11-03 Thread Konstantin Ryabitsev
On Wed, Nov 03, 2021 at 10:18:57AM +1100, Michael Ellerman wrote: > It's not in next, that notification is from the b4 thanks script, which > didn't notice that the commit has since been reverted. Yeah... I'm not sure how to catch that, but I'm open to suggestions. -K -- Linux-audit mailing

RE: [RFC PATCH v7 14/16] scripts: add boot policy generation program

2021-11-03 Thread Roberto Sassu
> From: Roberto Sassu [mailto:roberto.sa...@huawei.com] > Sent: Wednesday, November 3, 2021 5:43 PM > > From: deven.de...@linux.microsoft.com > > [mailto:deven.de...@linux.microsoft.com] > > From: Deven Bowers > > > > Enables an IPE policy to be enforced from kernel start, enabling access > >

RE: [RFC PATCH v7 14/16] scripts: add boot policy generation program

2021-11-03 Thread Roberto Sassu
> From: deven.de...@linux.microsoft.com > [mailto:deven.de...@linux.microsoft.com] > From: Deven Bowers > > Enables an IPE policy to be enforced from kernel start, enabling access > control based on trust from kernel startup. This is accomplished by > transforming an IPE policy indicated by