Received: by 2002:ac0:a5a6:0:0:0:0:0 with SMTP id m35-v6csp118429imm; Fri, 21 Sep 2018 19:49:15 -0700 (PDT) X-Google-Smtp-Source: ACcGV63iIfGdiGeBCUDIJa7n3wYvTLbkEPI5fAN4iwCX8qqolKzxZGuLbVhjBRZ/RMECwNCP/g/L X-Received: by 2002:a17:902:2e01:: with SMTP id q1-v6mr487718plb.40.1537584555736; Fri, 21 Sep 2018 19:49:15 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1537584555; cv=none; d=google.com; s=arc-20160816; b=JxaEmtJioSjztgyMZjuTfiweIqXzDYtYN0+qdO2BPwaJ4oks8XunGiZLxXkjklsv8I +HUoj0k/uHQCIfEeFgqnXzHUyOO/UjzzmpLHslnW6oIw3PACVVTObJGio92+gQi7lAdT 2H8JfjPL76ZxrAoLBSCYBaGJRYQu45vcSrX7T6gAm128OROYdzo4pWejjJ/gE7EFo11b qH+dI8XlRbMbdpel5cDlFsZX5t+GsszjEzUiMe20VZ3EmhbfMVRoEo0DCx3PPi1BNNIG Q91GYlghj+TUo87EtUrtIIpHBljV+JKHx4bdcX+oOGaDFsjSDTw4bN1sMRegqD93C/PY K+8A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :references:in-reply-to:mime-version:dkim-signature; bh=/DwY8Hsv8xYW8i78a17yt3JxgNy6juVebR3psO5Eyf0=; b=BtoawXUzcLZMvT3wOpZ1qCew9c8LR8iseqzIXAVKJC1IdtCEQSDot0/3FoSOQxP75Y /8tLaztbd1r2XyLO1R+AUPlMrBdqSNPO4VNtLye1qneeIwqOc3B71UqE/WltolSKW1Lg op1cqeqMVvCTmX0rbimgTHVQW8gUnl4JQqz0HAdY8OD469vDtM0Mwpgvecsco39PnseP fSqMiI/5Rm/45hssFEWiR+GYq6jBDDC/wjCl1WbAqA0E7Kkixyq81nU+5FdjXscdJ/wd 2ktfox1AWSRK1b7PSke1XOu6O/kHE686t8rrUiHwKht3pmsKsmxbIGyU8tCKHoWPpESa rfxQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=f4nJxnw+; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id r14-v6si29362326pfa.44.2018.09.21.19.48.59; Fri, 21 Sep 2018 19:49:15 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=f4nJxnw+; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726039AbeIVIiz (ORCPT + 99 others); Sat, 22 Sep 2018 04:38:55 -0400 Received: from mail-yw1-f67.google.com ([209.85.161.67]:46851 "EHLO mail-yw1-f67.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725841AbeIVIiz (ORCPT ); Sat, 22 Sep 2018 04:38:55 -0400 Received: by mail-yw1-f67.google.com with SMTP id j131-v6so5958367ywc.13 for ; Fri, 21 Sep 2018 19:47:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=/DwY8Hsv8xYW8i78a17yt3JxgNy6juVebR3psO5Eyf0=; b=f4nJxnw+jm8/ogq+3HX8GEA5MGsvf0zr/845tgO7+V4Yu9H6WS94TNOgTL1GS1qO3P i61TbX0qUNWyCKg73A+ViFvt7vBKp+Sx3BxenuR4dGZ5TLFmhzPF2ZVikY8qYnPhGywz 45TLh2sNGV9X0k/+lvz2Bcmhr9tmnTWgBSMRo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=/DwY8Hsv8xYW8i78a17yt3JxgNy6juVebR3psO5Eyf0=; b=W2IlGtcmx0qAYaCcEM9SGHBEXP0/S3EdfeYMs7C4ANTVKwBvWq0ODUqSYDczm8xSSH 9tidqiyc3+8qgvoH+2oJE/hCdfwY4TnoROPhVXt4fKvhyOaUpVJeoVhSexhXssfbEpD5 mPsZO5UjIeSkL5jj94fUFpSLz/30H2e2wwhQ1X/ZC8CuUaNWYFNMdPYx6I3lnov5ULZi HItFT013Js9HvxN0QeTqraC/ufIf4Od6TMc2PqLWahe0pEybFf1exAtZM6SKVxeVU0Ac 0wxhB3WrJ6ZbHzz6sQYhMNMsWO8HvcjP84C6hkktwYQkH0XpfxsVvPunFw30+RnlFwkc Gwag== X-Gm-Message-State: APzg51DlDexRTqnQqbxIqMagcYIrzR0eqUxDRyF228Q3AOYFcE9x0bPI ObAEQjN4QENaVbBbd9PCI6eca2AQYGs= X-Received: by 2002:a81:7d46:: with SMTP id y67-v6mr199334ywc.457.1537584426098; Fri, 21 Sep 2018 19:47:06 -0700 (PDT) Received: from mail-yb1-f181.google.com (mail-yb1-f181.google.com. [209.85.219.181]) by smtp.gmail.com with ESMTPSA id k184-v6sm5119891ywc.62.2018.09.21.19.47.04 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 21 Sep 2018 19:47:04 -0700 (PDT) Received: by mail-yb1-f181.google.com with SMTP id e190-v6so6255698ybb.5 for ; Fri, 21 Sep 2018 19:47:04 -0700 (PDT) X-Received: by 2002:a25:396:: with SMTP id 144-v6mr202782ybd.403.1537584423705; Fri, 21 Sep 2018 19:47:03 -0700 (PDT) MIME-Version: 1.0 Received: by 2002:a25:5f04:0:0:0:0:0 with HTTP; Fri, 21 Sep 2018 19:47:03 -0700 (PDT) In-Reply-To: <8ea966f7-924e-b805-56e8-9ad74e7f9d86@schaufler-ca.com> References: <8ea966f7-924e-b805-56e8-9ad74e7f9d86@schaufler-ca.com> From: Kees Cook Date: Fri, 21 Sep 2018 19:47:03 -0700 X-Gmail-Original-Message-ID: Message-ID: Subject: Re: [PATCH v4 07/19] TOMOYO: Abstract use of cred security blob To: Casey Schaufler Cc: LSM , James Morris , SE Linux , LKLM , John Johansen , Tetsuo Handa , Paul Moore , Stephen Smalley , "linux-fsdevel@vger.kernel.org" , Alexey Dobriyan , =?UTF-8?B?TWlja2HDq2wgU2FsYcO8bg==?= , Salvatore Mesoraca Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Sep 21, 2018 at 5:18 PM, Casey Schaufler wrote: > Don't use the cred->security pointer directly. > Provide helper functions that provide the security blob pointer. > > Signed-off-by: Casey Schaufler Reviewed-by: Kees Cook -Kees -- Kees Cook Pixel Security