)]}'
{
  "commit": "23bcdc1adebd3cb47d5666f2e9ecada95c0134e4",
  "tree": "71caf0ac9fa86e4a9cf423d968a2486656c2e196",
  "parents": [
    "589f1e81bde732dd0b1bc5d01b6bddd4bcb4527b"
  ],
  "author": {
    "name": "Paul Moore",
    "email": "paul.moore@hp.com",
    "time": "Wed Jul 18 12:28:45 2007 -0400"
  },
  "committer": {
    "name": "James Morris",
    "email": "jmorris@namei.org",
    "time": "Thu Jul 19 10:21:11 2007 -0400"
  },
  "message": "SELinux: enable dynamic activation/deactivation of NetLabel/SELinux enforcement\n\nCreate a new NetLabel KAPI interface, netlbl_enabled(), which reports on the\ncurrent runtime status of NetLabel based on the existing configuration.  LSMs\nthat make use of NetLabel, i.e. SELinux, can use this new function to determine\nif they should perform NetLabel access checks.  This patch changes the\nNetLabel/SELinux glue code such that SELinux only enforces NetLabel related\naccess checks when netlbl_enabled() returns true.\n\nAt present NetLabel is considered to be enabled when there is at least one\nlabeled protocol configuration present.  The result is that by default NetLabel\nis considered to be disabled, however, as soon as an administrator configured\na CIPSO DOI definition NetLabel is enabled and SELinux starts enforcing\nNetLabel related access controls - including unlabeled packet controls.\n\nThis patch also tries to consolidate the multiple \"#ifdef CONFIG_NETLABEL\"\nblocks into a single block to ease future review as recommended by Linus.\n\nSigned-off-by: Paul Moore \u003cpaul.moore@hp.com\u003e\nSigned-off-by: James Morris \u003cjmorris@namei.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "9b7d6f2ac9a3ed9c0107a16131be3e165477e6ed",
      "old_mode": 33188,
      "old_path": "include/net/netlabel.h",
      "new_id": "ffbc7f28335a2c4f915e98b0216dcb49195e8753",
      "new_mode": 33188,
      "new_path": "include/net/netlabel.h"
    },
    {
      "type": "modify",
      "old_id": "24b660f16ce3b5c74bb74035ed935f7a2f96ed86",
      "old_mode": 33188,
      "old_path": "net/netlabel/netlabel_cipso_v4.c",
      "new_id": "c060e3f991f10ab9d13bb0c5aa4c043d17c2a66e",
      "new_mode": 33188,
      "new_path": "net/netlabel/netlabel_cipso_v4.c"
    },
    {
      "type": "modify",
      "old_id": "b165712aaa702ae09d4d35c252c089ac5506a906",
      "old_mode": 33188,
      "old_path": "net/netlabel/netlabel_kapi.c",
      "new_id": "4f50949722a95a6e082404601b98c98f39190821",
      "new_mode": 33188,
      "new_path": "net/netlabel/netlabel_kapi.c"
    },
    {
      "type": "modify",
      "old_id": "e00fc219c72b7c70cd6c581ccd474e0a8c3b2034",
      "old_mode": 33188,
      "old_path": "net/netlabel/netlabel_mgmt.c",
      "new_id": "5315dacc5222cd91220194cf9776ac1b248593a8",
      "new_mode": 33188,
      "new_path": "net/netlabel/netlabel_mgmt.c"
    },
    {
      "type": "modify",
      "old_id": "3642d3bfc8eb07ed91f1000b0ad7f25258476e21",
      "old_mode": 33188,
      "old_path": "net/netlabel/netlabel_mgmt.h",
      "new_id": "ccb2b3923591c9e45afe30e73d141704b1659396",
      "new_mode": 33188,
      "new_path": "net/netlabel/netlabel_mgmt.h"
    },
    {
      "type": "modify",
      "old_id": "e64eca246f1ab25ce57cb1190cc578fa643421e9",
      "old_mode": 33188,
      "old_path": "security/selinux/netlabel.c",
      "new_id": "ed9155b29c1a9bf6eebedec3311a0971dc596342",
      "new_mode": 33188,
      "new_path": "security/selinux/netlabel.c"
    }
  ]
}
