Re: [GIT PULL] Keys: Set 4 - Key ACLs for 5.3

2019-08-21 Thread David Howells
I added a bunch of tests to the keyutils testsuite, currently on my -next branch: https://git.kernel.org/pub/scm/linux/kernel/git/dhowells/keyutils.git/log/?h=next See: Add a keyctl command for granting a permit on a key Handle kernel having key/keyring ACLs I've added

Re: [GIT PULL] Keys: Set 4 - Key ACLs for 5.3

2019-08-21 Thread Mimi Zohar
On Fri, 2019-08-16 at 14:36 +0100, David Howells wrote: > Mimi Zohar wrote: > > > Sorry for the delay.  An exception is needed for loading builtin keys > > "KEY_ALLOC_BUILT_IN" onto a keyring that is not writable by userspace. > >  The following works, but probably is not how David would handle t

Re: [GIT PULL] Keys: Set 4 - Key ACLs for 5.3

2019-08-21 Thread Mimi Zohar
On Fri, 2019-08-16 at 14:36 +0100, David Howells wrote: > Mimi Zohar wrote: > > > Sorry for the delay.  An exception is needed for loading builtin keys > > "KEY_ALLOC_BUILT_IN" onto a keyring that is not writable by userspace. > >  The following works, but probably is not how David would handle t

Re: [GIT PULL] Keys: Set 4 - Key ACLs for 5.3

2019-08-16 Thread David Howells
Mimi Zohar wrote: > Sorry for the delay.  An exception is needed for loading builtin keys > "KEY_ALLOC_BUILT_IN" onto a keyring that is not writable by userspace. >  The following works, but probably is not how David would handle the > exception. I think the attached is the right way to fix it.

Re: [GIT PULL] Keys: Set 4 - Key ACLs for 5.3

2019-07-10 Thread Mimi Zohar
Hi Linus, On Wed, 2019-07-10 at 18:59 -0700, Linus Torvalds wrote: > Anyway, since it does seem like David is offline, I've just reverted > this from my tree, and will be continuing my normal merge window pull > requests (the other issues I have seen have fixes in their respective > trees). Sorry

Re: [GIT PULL] Keys: Set 4 - Key ACLs for 5.3

2019-07-10 Thread Linus Torvalds
On Wed, Jul 10, 2019 at 1:15 PM Eric Biggers wrote: > > Also worth noting that the key ACL patches were only in linux-next for 9 days > before the pull request was sent. Yes. I was not entirely happy with the whole key subsystem situation. See my concerns in https://lore.kernel.org/lkml/CAHk-

Re: [GIT PULL] Keys: Set 4 - Key ACLs for 5.3

2019-07-10 Thread Eric Biggers
On Wed, Jul 10, 2019 at 12:46:22PM -0700, Eric Biggers wrote: > On Wed, Jul 10, 2019 at 11:35:07AM -0700, Linus Torvalds wrote: > > On Fri, Jul 5, 2019 at 2:30 PM David Howells wrote: > > > > > > Here's my fourth block of keyrings changes for the next merge window. > > > They > > > change the pe

Re: [GIT PULL] Keys: Set 4 - Key ACLs for 5.3

2019-07-10 Thread Eric Biggers
On Wed, Jul 10, 2019 at 11:35:07AM -0700, Linus Torvalds wrote: > On Fri, Jul 5, 2019 at 2:30 PM David Howells wrote: > > > > Here's my fourth block of keyrings changes for the next merge window. They > > change the permissions model used by keys and keyrings to be based on an > > internal ACL by

Re: [GIT PULL] Keys: Set 4 - Key ACLs for 5.3

2019-07-10 Thread Linus Torvalds
On Fri, Jul 5, 2019 at 2:30 PM David Howells wrote: > > Here's my fourth block of keyrings changes for the next merge window. They > change the permissions model used by keys and keyrings to be based on an > internal ACL by the following means: It turns out that this is broken, and I'll probably

Re: [GIT PULL] Keys: Set 4 - Key ACLs for 5.3

2019-07-08 Thread pr-tracker-bot
The pull request you sent on Fri, 05 Jul 2019 22:30:39 +0100: > git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs.git > tags/keys-acl-20190703 has been merged into torvalds/linux.git: https://git.kernel.org/torvalds/c/0f75ef6a9cff49ff612f7ce0578bced9d0b38325 Thank you! -- Deet-d