Re: [PATCH v9 0/3] SELinux support for anonymous inodes and UFFD

2020-10-08 Thread James Morris
On Wed, 7 Oct 2020, Lokesh Gidra wrote: > Is there anything else that needs to be done before merging this > patch series? I urge the reviewers to please take a look. > It looks generally fine to me from a security POV, we really need some feedback from VFS folk. -- James Morris

Re: [PATCH v9 0/3] SELinux support for anonymous inodes and UFFD

2020-10-07 Thread Lokesh Gidra
On Wed, Sep 23, 2020 at 12:33 PM Lokesh Gidra wrote: > > Userfaultfd in unprivileged contexts could be potentially very > useful. We'd like to harden userfaultfd to make such unprivileged use > less risky. This patch series allows SELinux to manage userfaultfd > file descriptors and in the future,

[PATCH v9 0/3] SELinux support for anonymous inodes and UFFD

2020-09-23 Thread Lokesh Gidra
Userfaultfd in unprivileged contexts could be potentially very useful. We'd like to harden userfaultfd to make such unprivileged use less risky. This patch series allows SELinux to manage userfaultfd file descriptors and in the future, other kinds of anonymous-inode-based file descriptor. SELinux