Received: by 2002:a05:6a10:9848:0:0:0:0 with SMTP id x8csp1320149pxf; Fri, 12 Mar 2021 07:06:44 -0800 (PST) X-Google-Smtp-Source: ABdhPJwaeZSqtn7UcgQs7bDL33IA//qwhvx9yjheTpfM+wDAhbbC6Xs/gtxYzTqRYjdkGEEEyVwE X-Received: by 2002:a17:906:22d2:: with SMTP id q18mr8991339eja.437.1615561603512; Fri, 12 Mar 2021 07:06:43 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1615561603; cv=none; d=google.com; s=arc-20160816; b=CkwD7vsw1SBkJ45n3Xyh16eTMQduRrwCJviRZFi203la39mAbe7Hz7IL+zU1RXF7xM JmBF63WYq9aHsyv3LOAy75nv6gA2372ama+Q9LdKVM4v8TjS8YYm587f0JHcED1Yd4OD bI28hIvUG0+a5EEzAsXXQqB4tN68xq/MB14n+SlrzRmHMO2MvHZ0YFF3eZyb3sNco807 FjwWiEJUVYzZuEdWJTs/a/zBZPkEqp1bU857zRLXjgVmAfJ9t3bRdZLTkdJebw5Ixy+Q tCukeKScp9ghUn21vfUggkmPydBpZGmy/EQN7WuKClRDs/Pl3dcmgSmOD/+KizdALxci I0DA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:content-language :in-reply-to:mime-version:user-agent:date:message-id:from:references :cc:to:subject:dkim-signature; bh=K5YqNOXid4mcmkvggGywPg7CxWclX1wIUY+ctG/tfmE=; b=y3zSQq9q1keAqynSkZCwzXdCWnWCky5aM7B6wE4jGO7Le6F27CvlsvlHoippfl62wU GxGdwhFc9Zut1WOJFxtSmVVedZKoAMWBYrzUqsKNPpeRgsSjQZPFwgGrVRRmeMFbN23Q seYpXCe4fLLFeeMfteohq9ziDgHwdQ/UHCXnyZ9io32dahd6sb6z4oT4mXdUYPx9au9E 1RisJ3g+eeHzjoRrpRrfQ7Epct38pGfBDpqrdYS2IWiuRA7eDaZKPetNfnGmDQ8Y0J48 N070NyrdSx6RCP2Dqspo+a4koP4ahqZpJrDBSyQZzzMfLIuYt3bEhNfiZK+pUBt6+FSw Q5Dw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@ieee.org header.s=google header.b=Zu4NDgKl; spf=pass (google.com: domain of selinux-refpolicy-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=selinux-refpolicy-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ieee.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id h6si4515551edw.354.2021.03.12.07.06.38; Fri, 12 Mar 2021 07:06:43 -0800 (PST) Received-SPF: pass (google.com: domain of selinux-refpolicy-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@ieee.org header.s=google header.b=Zu4NDgKl; spf=pass (google.com: domain of selinux-refpolicy-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=selinux-refpolicy-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ieee.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229968AbhCLPEE (ORCPT + 16 others); Fri, 12 Mar 2021 10:04:04 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:38284 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231351AbhCLPDw (ORCPT ); Fri, 12 Mar 2021 10:03:52 -0500 Received: from mail-qt1-x830.google.com (mail-qt1-x830.google.com [IPv6:2607:f8b0:4864:20::830]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 99165C061574 for ; Fri, 12 Mar 2021 07:03:51 -0800 (PST) Received: by mail-qt1-x830.google.com with SMTP id 94so3924775qtc.0 for ; Fri, 12 Mar 2021 07:03:51 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ieee.org; s=google; h=subject:to:cc:references:from:message-id:date:user-agent :mime-version:in-reply-to:content-language:content-transfer-encoding; bh=K5YqNOXid4mcmkvggGywPg7CxWclX1wIUY+ctG/tfmE=; b=Zu4NDgKl9CKftcXUlHQSQnOXRitiP0iZp2nDcZVoBYfjcqxgAaJt8pJEyuH7US9Szb 8Mfm7bPwQYxQ9Lbz/HWttTTM1BIV9W884KC0RB99BPEd3loxrZnKxhKh7bjnKoy9adFl DFl+TD85PlEh9Skda0u4Ax1SLO9dZ3NPejBGQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=K5YqNOXid4mcmkvggGywPg7CxWclX1wIUY+ctG/tfmE=; b=cQpqgfp37O31od9StmvcuK+gr0gTKlzspA1Jbas9gpgV1AUPS2m9Vjpi8/czIPbw5i Qy18WfUV3d8+kcyuSq4e0qWZ47X4d3oS/CsRt2jAjsh19dKAh8S8fe6gCI/U4Yqsjzzb X2eb0dOuFd+kN/weLcDpET9w6M3Sy32YSTG7piT4UctO5IbzPTZksNiMumKxVKRFcMNF lYEkZKcHhIQOe9C7/O/+LTFA6vJkijFJm7IiiNm7K9SpS5hZjX2cCv9FtBMqPZY7xxlN FD2rsvynx6qq7blEPGaSxhjUs6WTTJKMZHenGLnwb9jZUR6cCZ4dCOkWun3EdFPMbztR 9pkw== X-Gm-Message-State: AOAM531SgGeKK9cS3PxXBL4SIsOsvTYIFUSnffV97xFX9sTf0V41lTnN G1seQL+pQJAmTIbsrw6iAIA+0O/Nyv9itg== X-Received: by 2002:a05:622a:48d:: with SMTP id p13mr7781838qtx.21.1615561430540; Fri, 12 Mar 2021 07:03:50 -0800 (PST) Received: from fedora.pebenito.net (pool-96-234-173-17.bltmmd.fios.verizon.net. [96.234.173.17]) by smtp.gmail.com with ESMTPSA id z5sm4459293qkz.2.2021.03.12.07.03.49 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 12 Mar 2021 07:03:50 -0800 (PST) Subject: Re: [PATCH] rasdaemon (replacement for mcelog) To: Dominick Grift , Russell Coker Cc: selinux-refpolicy@vger.kernel.org References: From: Chris PeBenito Message-ID: Date: Fri, 12 Mar 2021 10:03:48 -0500 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.8.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-US Content-Transfer-Encoding: 7bit Precedence: bulk List-ID: X-Mailing-List: selinux-refpolicy@vger.kernel.org On 3/8/21 3:59 AM, Dominick Grift wrote: > Dominick Grift writes: > >> Russell Coker writes: >> >>> This is policy for rasdaemon, the new replacement for mcelog. The >>> /dev/mcelog device is now an obsolete kernel feature that can be enabled >>> for backward compatibility and rasdaeon with tracefs is the new way. >>> >>> I've tested this and it seems to work OK, but all my servers are working >>> well so I haven't been able to test the case of actually detecting an >>> error. It would be good if someone with a known damaged server could give >>> it a go. >>> >>> I think this is ready for merging. >>> >>> Signed-off-by: Russell Coker >>> [...] >>> +++ refpolicy-2.20210203/policy/modules/services/rasdaemon.te >>> @@ -0,0 +1,49 @@ >>> +policy_module(rasdaemon, 1.0.0) >>> + >>> +# rasdaemon is a RAS (Reliability, Availability and Serviceability) logging >>> +# tool. It currently records memory errors, using the EDAC tracing events. >>> +# EDAC are drivers in the Linux kernel that handle detection of ECC errors >>> +# from memory controllers for most chipsets on x86 and ARM architectures. >>> +# >>> +# https://git.infradead.org/users/mchehab/rasdaemon.git >> >> Please use the for description. We have an api >> browser (make doc) and the description should end up there as well. >> >> Reliability, Availability and Serviceability (RAS) logging tool. >> >> I would omit the url because those are often subject to change anyway. I agree if we have this amount of description it should go in the XML, but the module level actually has a tag that goes after . I like Dominick's summary, but the Russel's comment can go in the module . The URL can remain. Yes, it can change, but at least there are some breadcrumbs if this program becomes obsolete or unmaintained. -- Chris PeBenito