Received: by 2002:a05:6358:3188:b0:123:57c1:9b43 with SMTP id q8csp3111786rwd; Sat, 10 Jun 2023 01:30:25 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ6boIVVAA/nVMZXMqB9zwu3I1NrU4AjRHDfU37rCb147EmxEqgQn8FDl5S2CQYyOr3DP8rN X-Received: by 2002:a05:6a00:2794:b0:658:e9f4:f7b6 with SMTP id bd20-20020a056a00279400b00658e9f4f7b6mr7363421pfb.15.1686385825050; Sat, 10 Jun 2023 01:30:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1686385825; cv=none; d=google.com; s=arc-20160816; b=wv23ZKpIguAEpiyADNRlq582iIUuNvZZjnAf+VBUbH2rfd1xpkH6yetzHHgETnNNx1 m8ntZ6cDn6gNpvPf+8kqOsuCUCpjOhq8jVFcpoelPMhP95bz3DjGK48aEBmGIJLx1vdK 4lKwS/CekX1X+Hdrk2zUhZfvAa+4nbkkoxvqMETmqlN2Y29wdkpO1ateSUgRs+goP9kO geqfv7YelZ7f+crWaiXc/QIKdLFoyWIJNUT1OdjYdJ70Y34OgHRcx8I5CyokvRcG3H8E 5o8qKpRzjQl7FsJO3byGaLlvsDeYKeCLgOUscjYv7woig20V2RpyhckI+na2FPt3tpjr HgNw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:in-reply-to:from :references:cc:to:content-language:subject:user-agent:mime-version :date:message-id; bh=hi/AJ3yiWhxKdyO/bkDiL8jKfsxec7AiA5mC3JrULCo=; b=hAHZvSUCAvnd0xILUrNVCQMryLbJVRnxZ0uv1dDWFnduTar3t1gkdVZjiAIPRcROy1 CyiYOPdB4VASxtpqpDeYLQFaK3Z0Imaa/WWwOvAEr+nhWQhhcPra2oKJhSlor7DGck2m 1f43WTb40JCkXFR0LjzT5c46/bLhkPkHNei//q/DzkwfLdWOD7bjsrNcoPBQtzue+IN2 MSJqwTM8K+lsCYVqlLm0Pg34rRFR5432N92dDcIO0batXqwzrW+qcKOzYTLl1JV3uo6n 0fE/pBHzB7I+O/FRukFI5wVVGTWR0AOunUN/u/2aQLBfFmGA1ZLoDouVUXB3x9RtJL2R i4HA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id w66-20020a626245000000b0063b8f0a6f51si3777517pfb.117.2023.06.10.01.30.13; Sat, 10 Jun 2023 01:30:25 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S233092AbjFJIBk (ORCPT + 99 others); Sat, 10 Jun 2023 04:01:40 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:45786 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230060AbjFJIBj (ORCPT ); Sat, 10 Jun 2023 04:01:39 -0400 Received: from frasgout13.his.huawei.com (unknown [14.137.139.46]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 1F67F1FDB; Sat, 10 Jun 2023 01:01:38 -0700 (PDT) Received: from mail02.huawei.com (unknown [172.18.147.229]) by frasgout13.his.huawei.com (SkyGuard) with ESMTP id 4QdVWJ0GVGz9y7KF; Sat, 10 Jun 2023 15:51:08 +0800 (CST) Received: from [10.81.219.229] (unknown [10.81.219.229]) by APP2 (Coremail) with SMTP id GxC2BwDHilG_LYRkHqEfAw--.38471S2; Sat, 10 Jun 2023 09:01:14 +0100 (CET) Message-ID: Date: Sat, 10 Jun 2023 10:00:57 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Thunderbird/102.6.0 Subject: Re: [PATCH v11 0/4] evm: Do HMAC of multiple per LSM xattrs for new inodes Content-Language: en-US To: Paul Moore Cc: zohar@linux.ibm.com, dmitry.kasatkin@gmail.com, jmorris@namei.org, serge@hallyn.com, stephen.smalley.work@gmail.com, eparis@parisplace.org, casey@schaufler-ca.com, linux-kernel@vger.kernel.org, linux-integrity@vger.kernel.org, linux-security-module@vger.kernel.org, selinux@vger.kernel.org, bpf@vger.kernel.org, kpsingh@kernel.org, keescook@chromium.org, nicolas.bouchinet@clip-os.org, Roberto Sassu References: <20230603191518.1397490-1-roberto.sassu@huaweicloud.com> From: Roberto Sassu In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-CM-TRANSID: GxC2BwDHilG_LYRkHqEfAw--.38471S2 X-Coremail-Antispam: 1UD129KBjvdXoWrZw1DAw43Aw4Dtw4fAF4kXrb_yoWDZrbE9a 10yrZrCw45Xws7GF4aqr1YvrWkKFW8GF1jq3y5WrWay34rAan7AF4vkF4rZr4rJay3Z343 Cr9Iy34Sy3sFgjkaLaAFLSUrUUUUUb8apTn2vfkv8UJUUUU8Yxn0WfASr-VFAUDa7-sFnT 9fnUUIcSsGvfJTRUUUbsxYFVCjjxCrM7AC8VAFwI0_Xr0_Wr1l1xkIjI8I6I8E6xAIw20E Y4v20xvaj40_Wr0E3s1l1IIY67AEw4v_Jr0_Jr4l8cAvFVAK0II2c7xJM28CjxkF64kEwV A0rcxSw2x7M28EF7xvwVC0I7IYx2IY67AKxVWUCVW8JwA2z4x0Y4vE2Ix0cI8IcVCY1x02 67AKxVW8Jr0_Cr1UM28EF7xvwVC2z280aVAFwI0_Gr0_Cr1l84ACjcxK6I8E87Iv6xkF7I 0E14v26r4UJVWxJr1le2I262IYc4CY6c8Ij28IcVAaY2xG8wAqx4xG64xvF2IEw4CE5I8C rVC2j2WlYx0E2Ix0cI8IcVAFwI0_Jr0_Jr4lYx0Ex4A2jsIE14v26r1j6r4UMcvjeVCFs4 IE7xkEbVWUJVW8JwACjcxG0xvEwIxGrwACI402YVCY1x02628vn2kIc2xKxwCYjI0SjxkI 62AI1cAE67vIY487MxAIw28IcxkI7VAKI48JMxC20s026xCaFVCjc4AY6r1j6r4UMI8I3I 0E5I8CrVAFwI0_Jr0_Jr4lx2IqxVCjr7xvwVAFwI0_JrI_JrWlx4CE17CEb7AF67AKxVW8 ZVWrXwCIc40Y0x0EwIxGrwCI42IY6xIIjxv20xvE14v26r1I6r4UMIIF0xvE2Ix0cI8IcV CY1x0267AKxVW8Jr0_Cr1UMIIF0xvE42xK8VAvwI8IcIk0rVW3JVWrJr1lIxAIcVC2z280 aVAFwI0_Jr0_Gr1lIxAIcVC2z280aVCY1x0267AKxVW8Jr0_Cr1UYxBIdaVFxhVjvjDU0x ZFpf9x07UZ18PUUUUU= X-CM-SenderInfo: purev21wro2thvvxqx5xdzvxpfor3voofrz/1tbiAgAEBF1jj4qCKQAAsS X-CFilter-Loop: Reflected X-Spam-Status: No, score=-1.0 required=5.0 tests=BAYES_00,KHOP_HELO_FCRDNS, MAY_BE_FORGED,NICE_REPLY_A,PDS_RDNS_DYNAMIC_FP,RCVD_IN_MSPIKE_BL, RCVD_IN_MSPIKE_L3,RDNS_DYNAMIC,SPF_HELO_NONE,SPF_NONE, T_SCC_BODY_TEXT_LINE autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 6/9/2023 10:05 PM, Paul Moore wrote: > On Sat, Jun 3, 2023 at 3:16 PM Roberto Sassu > wrote: >> >> From: Roberto Sassu >> >> One of the major goals of LSM stacking is to run multiple LSMs side by side >> without interfering with each other. The ultimate decision will depend on >> individual LSM decision. >> >> Several changes need to be made to the LSM infrastructure to be able to >> support that. This patch set tackles one of them: gives to each LSM the >> ability to specify one or multiple xattrs to be set at inode creation >> time and, at the same time, gives to EVM the ability to access all those >> xattrs and calculate the HMAC on them ... > > Thanks for sticking with this Roberto, I see a few > comments/suggestions on this patchset, but overall it is looking > pretty good; I'm hopeful we will be able to merge the next revision. Thanks for looking at it. Just sent v12 with the suggestions. One is addressed with a different patch set (Smack transmute fixes). Roberto