Received: by 2002:a25:4158:0:0:0:0:0 with SMTP id o85csp3742348yba; Tue, 7 May 2019 06:26:08 -0700 (PDT) X-Google-Smtp-Source: APXvYqz5mnZUkSwDLnPk2jDCiveoli17OxYe2Y59X3e9OOAap93b+b8r1X/QWWp5dt2uPzGr85XA X-Received: by 2002:a62:582:: with SMTP id 124mr26292524pff.209.1557235568286; Tue, 07 May 2019 06:26:08 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1557235568; cv=none; d=google.com; s=arc-20160816; b=DPnUDHrslCAwwwt01Lgyxq8PHDanU3HHXh/YQ0ECciK6J4INnMeBN+Bh/fQkTue2oI 0xD3d/CMFCHJfSqd+H/BzQdjYN6F3bOvM7QLwRFS5voEX1ErogKPTGUSDI88QGek/wJE QoxmEQ8ABlHbumgnpPAAifZ8fAZ8n63CGbQa6eXxxHspxa1oEDW2DJdI5NwZ9DzJHmLN pz6OGbgMxq35S+rsFX0iCO3XC1ER1w0iE9S9nHGCXo8Oytf3Ha8oHhCxS287VcUFb3/P g/AWuoDtn6K9N2PnA5wRoaRLyfTcf4KxVZuLaIDPnKEGEJoUaeU8wFFPu1CJgJQwIrIR FAWg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:references:cms-type :content-transfer-encoding:mime-version:user-agent:in-reply-to:date :cc:to:from:subject:message-id:dkim-signature:dkim-filter; bh=HePsI2obF6bYrams1J31uq3qDheNx0jPg7cbk18CcCo=; b=ndbxCmX54nKRaOit/KzvKQR5Ypobr8YYRtcJuaKPx6QdFKjdnNk3+5DR0n5a3d0RTQ 34SKy4HTGST84WSTPiEbnDIM453lK+qfPSIx0zSvULf9y3ceWzSpP3Vh6FZHrZA2Dx+Q AZK+xxVaeu7mLXD3NIyidk07uNfFZ8Q/nHE0OfPnkOAItrSVk749m/XOix7FmYah0gfi 2tmZt+44JDG7601/rBkEZNun9MrCmeDJwOFSHoV3YgFTDDRtt1RXssNbPre7iMIb6Fmf 5SmmZdDMiD7O/+a+b9BbB6GzhstkM6rXF+JCozIRmX8A48RcowmnmvqfmqXV7x/GPq4v vuAg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@samsung.com header.s=mail20170921 header.b=gVNh+gdZ; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=samsung.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id e9si9318404plk.253.2019.05.07.06.25.52; Tue, 07 May 2019 06:26:08 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@samsung.com header.s=mail20170921 header.b=gVNh+gdZ; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=samsung.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726690AbfEGNYz (ORCPT + 99 others); Tue, 7 May 2019 09:24:55 -0400 Received: from mailout2.w1.samsung.com ([210.118.77.12]:59428 "EHLO mailout2.w1.samsung.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726446AbfEGNYz (ORCPT ); Tue, 7 May 2019 09:24:55 -0400 Received: from eucas1p1.samsung.com (unknown [182.198.249.206]) by mailout2.w1.samsung.com (KnoxPortal) with ESMTP id 20190507132446euoutp02c8ce8d7f6fecc2c873e7994d8b690c24~caWy_EQT60769007690euoutp02k for ; Tue, 7 May 2019 13:24:46 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 mailout2.w1.samsung.com 20190507132446euoutp02c8ce8d7f6fecc2c873e7994d8b690c24~caWy_EQT60769007690euoutp02k DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=samsung.com; s=mail20170921; t=1557235486; bh=HePsI2obF6bYrams1J31uq3qDheNx0jPg7cbk18CcCo=; h=Subject:From:To:Cc:Date:In-Reply-To:References:From; b=gVNh+gdZP8JjL6KEk/sofaf92S2jaBESPYs7IhzM7dlD+BgqGGsb3lpSkmfsZavBP OweODdkZt3q69D1IKxStAYeBcoJZHk5yQ6iKWlrJmcg4MBtplp/MMefhwmRv9lHSfE cBa8Uu9eftmkrlqa7CHJ0Xxvd3qOW7+KTntymA3c= Received: from eusmges2new.samsung.com (unknown [203.254.199.244]) by eucas1p2.samsung.com (KnoxPortal) with ESMTP id 20190507132446eucas1p276c1b2db5552552d991f368747316488~caWyKfuMs1887718877eucas1p21; Tue, 7 May 2019 13:24:46 +0000 (GMT) Received: from eucas1p2.samsung.com ( [182.198.249.207]) by eusmges2new.samsung.com (EUCPMTA) with SMTP id F5.3A.04377.D1781DC5; Tue, 7 May 2019 14:24:45 +0100 (BST) Received: from eusmtrp1.samsung.com (unknown [182.198.249.138]) by eucas1p1.samsung.com (KnoxPortal) with ESMTPA id 20190507132445eucas1p12fed4a0cdc75e8f5343b450bf1893c54~caWxVbC6C1246812468eucas1p11; Tue, 7 May 2019 13:24:45 +0000 (GMT) Received: from eusmgms2.samsung.com (unknown [182.198.249.180]) by eusmtrp1.samsung.com (KnoxPortal) with ESMTP id 20190507132444eusmtrp17aa7a507c83e6e2dfe5747c7b1b08091~caWxHRTcE2518525185eusmtrp1Z; Tue, 7 May 2019 13:24:44 +0000 (GMT) X-AuditID: cbfec7f4-12dff70000001119-01-5cd1871d0c78 Received: from eusmtip1.samsung.com ( [203.254.199.221]) by eusmgms2.samsung.com (EUCPMTA) with SMTP id 4A.BA.04140.C1781DC5; Tue, 7 May 2019 14:24:44 +0100 (BST) Received: from amdc2143 (unknown [106.120.51.59]) by eusmtip1.samsung.com (KnoxPortal) with ESMTPA id 20190507132444eusmtip102380f308f9d3546384b476e83d2801e~caWwssKF41198511985eusmtip16; Tue, 7 May 2019 13:24:44 +0000 (GMT) Message-ID: Subject: Re: [PATCH] extensions: libxt_owner: Add complementary groups option From: Lukasz Pawelczyk To: Pablo Neira Ayuso Cc: Jozsef Kadlecsik , Florian Westphal , "David S. Miller" , netfilter-devel@vger.kernel.org, coreteam@netfilter.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Lukasz Pawelczyk Date: Tue, 07 May 2019 15:24:43 +0200 In-Reply-To: <20190505225930.w4bcrlsgzq7cipvg@salvia> User-Agent: Evolution 3.30.5 (3.30.5-1.fc29) MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFlrFKsWRmVeSWpSXmKPExsWy7djP87qy7RdjDC6dNbD4u7Od2WLO+RYW i229qxkt/r/WsbjcN43Z4vKuOWwWxxaIWUxYd4rFYvqbq8wOnB6nmzayeGxZeZPJY+esu+we b3+fYPI49H0Bq8fnTXIBbFFcNimpOZllqUX6dglcGVu/rmUvaGCtWPwnroHxF3MXIyeHhICJ xM7pz9m7GLk4hARWMEp8/bOTFcL5wijxdsdkJpAqIYHPjBLrZ4vBdKy8PpEFomg5o8SV+Y2M EM4zRol16/6BzeUV8JB4On85WLewgL9E6+kjYHE2AQOJ7xf2gtkiAtoS7TdawSYxC0xnkrhz q50NJMEioCrxoP8CK4jNKWAq8evTN7AGUQFdiRsbnrFBLBCUODnzCQuIzSwgL7H97RxmkEES AtvYJWbO2soGcauLxOwPlxghbGGJV8e3sEPYMhKnJ/cANXMA2dUSJ89UQPR2MEpsfDEbqt5a 4vOkLcwgNcwCmhLrd+lDhB0lpvadYYVo5ZO48VYQ4gQ+iUnbpjNDhHklOtqEIKpVJV7vgRko LfHxz16oAzwkek4dYJzAqDgLyTOzkDwzC2HvAkbmVYziqaXFuempxUZ5qeV6xYm5xaV56XrJ +bmbGIEp6PS/4192MO76k3SIUYCDUYmH90XBxRgh1sSy4srcQ4wSHMxKIryJz87FCPGmJFZW pRblxxeV5qQWH2KU5mBREuetZngQLSSQnliSmp2aWpBaBJNl4uCUamCMbvVtrthXYPVHc+/6 k8Uc/n+mPYp6K7h9++uElG3rvGoZJbNX1Nn3H7A3uKF1T95lMVt+lWcg+/+scK8bn9x//zz3 JWXHhf+8Rzk1omct9HV0dVyb+aF1Znv1w6US03/p9La0n/JYrGv5wlp5155X9tnK6dVq6W+V /KLn6i73vuv179+Tx8lKLMUZiYZazEXFiQCCSFnPPQMAAA== X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrMIsWRmVeSWpSXmKPExsVy+t/xu7oy7RdjDL5eMrf4u7Od2WLO+RYW i229qxkt/r/WsbjcN43Z4vKuOWwWxxaIWUxYd4rFYvqbq8wOnB6nmzayeGxZeZPJY+esu+we b3+fYPI49H0Bq8fnTXIBbFF6NkX5pSWpChn5xSW2StGGFkZ6hpYWekYmlnqGxuaxVkamSvp2 NimpOZllqUX6dgl6GVu/rmUvaGCtWPwnroHxF3MXIyeHhICJxMrrE1m6GLk4hASWMkq8W3OL FSIhLXH8wEIoW1jiz7UuNoiiJ4wSiyfNYAFJ8Ap4SDydv5wJxBYW8JXYM/8/WJxNwEDi+4W9 YBtEBLQl2m+0gm1gFpjOJHFmznawIhYBVYkH/RfANnAKmEr8+vSNGWLDfkaJS+tesoMkmAU0 JVq3/wazRQV0JW5seMYGsVlQ4uTMJywQNfIS29/OYZ7AKDgLScssJGWzkJQtYGRexSiSWlqc m55bbKRXnJhbXJqXrpecn7uJERhh24793LKDsetd8CFGAQ5GJR7eFwUXY4RYE8uKK3MPMUpw MCuJ8CY+OxcjxJuSWFmVWpQfX1Sak1p8iNEU6KOJzFKiyfnA6M8riTc0NTS3sDQ0NzY3NrNQ EuftEDgYIySQnliSmp2aWpBaBNPHxMEp1cB4ZIme4QYbuRVtLJx+1yJvtMgevb87xbJBIVv9 9DTnhL33FgkJc27azH/27sF9s3lF2NxVj7NoS8+0s3DYsIcz+lC0aJGB5tYQzzy1o9kPMyfd Obs+OHDxpbk392t25nFENYTGaTmxHlnTI/WVK61/1sIq49e9C/98X5G5v+HNr9LOHf/5npQp sRRnJBpqMRcVJwIAoFjKicYCAAA= X-CMS-MailID: 20190507132445eucas1p12fed4a0cdc75e8f5343b450bf1893c54 X-Msg-Generator: CA Content-Type: text/plain; charset="utf-8" X-RootMTR: 20190426160306eucas1p1a0c8ec9783cc78db7381582a70d6de10 X-EPHeader: CA CMS-TYPE: 201P X-CMS-RootMailID: 20190426160306eucas1p1a0c8ec9783cc78db7381582a70d6de10 References: <20190426160257.4139-1-l.pawelczyk@samsung.com> <20190505225930.w4bcrlsgzq7cipvg@salvia> Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, 2019-05-06 at 00:59 +0200, Pablo Neira Ayuso wrote: > On Fri, Apr 26, 2019 at 06:02:57PM +0200, Lukasz Pawelczyk wrote: > > The --compl-groups option causes GIDs specified with --gid-owner to > > be > > also checked in the complementary groups of a process. > > Please, could you also update manpage? Will do. iptables-extensions(8) I presume? Anything else? > BTW, I think you refer to _supplementary_ groups, right? Existing > documentation uses this term. Yes, that's correct, my bad. I'll send the updated patches. Thanks. -- Lukasz Pawelczyk Samsung R&D Institute Poland Samsung Electronics