)]}'
{
  "commit": "3a3b7ce9336952ea7b9564d976d068a238976c9d",
  "tree": "3f0a3be33022492161f534636a20a4b1059f8236",
  "parents": [
    "1bfdc75ae077d60a01572a7781ec6264d55ab1b9"
  ],
  "author": {
    "name": "David Howells",
    "email": "dhowells@redhat.com",
    "time": "Fri Nov 14 10:39:28 2008 +1100"
  },
  "committer": {
    "name": "James Morris",
    "email": "jmorris@namei.org",
    "time": "Fri Nov 14 10:39:28 2008 +1100"
  },
  "message": "CRED: Allow kernel services to override LSM settings for task actions\n\nAllow kernel services to override LSM settings appropriate to the actions\nperformed by a task by duplicating a set of credentials, modifying it and then\nusing task_struct::cred to point to it when performing operations on behalf of\na task.\n\nThis is used, for example, by CacheFiles which has to transparently access the\ncache on behalf of a process that thinks it is doing, say, NFS accesses with a\npotentially inappropriate (with respect to accessing the cache) set of\ncredentials.\n\nThis patch provides two LSM hooks for modifying a task security record:\n\n (*) security_kernel_act_as() which allows modification of the security datum\n     with which a task acts on other objects (most notably files).\n\n (*) security_kernel_create_files_as() which allows modification of the\n     security datum that is used to initialise the security data on a file that\n     a task creates.\n\nThe patch also provides four new credentials handling functions, which wrap the\nLSM functions:\n\n (1) prepare_kernel_cred()\n\n     Prepare a set of credentials for a kernel service to use, based either on\n     a daemon\u0027s credentials or on init_cred.  All the keyrings are cleared.\n\n (2) set_security_override()\n\n     Set the LSM security ID in a set of credentials to a specific security\n     context, assuming permission from the LSM policy.\n\n (3) set_security_override_from_ctx()\n\n     As (2), but takes the security context as a string.\n\n (4) set_create_files_as()\n\n     Set the file creation LSM security ID in a set of credentials to be the\n     same as that on a particular inode.\n\nSigned-off-by: Casey Schaufler \u003ccasey@schaufler-ca.com\u003e [Smack changes]\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\nSigned-off-by: James Morris \u003cjmorris@namei.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "55a9c995d694a23d47e53fa6107d8c8a7a1dfd9e",
      "old_mode": 33188,
      "old_path": "include/linux/cred.h",
      "new_id": "26c1ab179946e745bc5e5c1aca11c17dfb1cc8f0",
      "new_mode": 33188,
      "new_path": "include/linux/cred.h"
    },
    {
      "type": "modify",
      "old_id": "56a0eed656733945833e82b0cc67997778c37975",
      "old_mode": 33188,
      "old_path": "include/linux/security.h",
      "new_id": "59a11e19b617d2b2e55151a8214d5163cccefd4c",
      "new_mode": 33188,
      "new_path": "include/linux/security.h"
    },
    {
      "type": "modify",
      "old_id": "f3ca1066061715bd5c2e9f0dd93c8576fa9617d0",
      "old_mode": 33188,
      "old_path": "kernel/cred.c",
      "new_id": "13697ca2bb382cb0950d4902a4e4cbaa9e6b1c53",
      "new_mode": 33188,
      "new_path": "kernel/cred.c"
    },
    {
      "type": "modify",
      "old_id": "185804f99ad13a8913f0c5199e70ae27528fca8e",
      "old_mode": 33188,
      "old_path": "security/capability.c",
      "new_id": "b9e391425e6fb5efb1e56fa12771af1cac876e89",
      "new_mode": 33188,
      "new_path": "security/capability.c"
    },
    {
      "type": "modify",
      "old_id": "dc5babb2d6d89cd6ac8fa5ca5c9803b5638d0db0",
      "old_mode": 33188,
      "old_path": "security/security.c",
      "new_id": "038ef04b2c7f87ed8b5e46216f113faa2b6aee1a",
      "new_mode": 33188,
      "new_path": "security/security.c"
    },
    {
      "type": "modify",
      "old_id": "91b06f2aa96363f49fe8999d665cd1e9328fe23a",
      "old_mode": 33188,
      "old_path": "security/selinux/hooks.c",
      "new_id": "520f82ab3fbfbea2fc136af8f881bf41420c990a",
      "new_mode": 33188,
      "new_path": "security/selinux/hooks.c"
    },
    {
      "type": "modify",
      "old_id": "de396742abf4bd391fa9ee1df9ec63e94cc4802f",
      "old_mode": 33188,
      "old_path": "security/smack/smack_lsm.c",
      "new_id": "8ad48161cef50405ca55c4174483df3e337e673c",
      "new_mode": 33188,
      "new_path": "security/smack/smack_lsm.c"
    }
  ]
}
