)]}'
{
  "commit": "8cf948e744e0218af604c32edecde10006dc8e9e",
  "tree": "c5d48e9210976e28e5ce07d69ca9b87d4c437389",
  "parents": [
    "9c0d90103c7e0eb6e638e5b649e9f6d8d9c1b4b3"
  ],
  "author": {
    "name": "Eric Paris",
    "email": "eparis@redhat.com",
    "time": "Fri Jul 31 12:54:05 2009 -0400"
  },
  "committer": {
    "name": "James Morris",
    "email": "jmorris@namei.org",
    "time": "Mon Aug 17 15:08:48 2009 +1000"
  },
  "message": "SELinux: call cap_file_mmap in selinux_file_mmap\n\nCurrently SELinux does not check CAP_SYS_RAWIO in the file_mmap hook.  This\nmeans there is no DAC check on the ability to mmap low addresses in the\nmemory space.  This function adds the DAC check for CAP_SYS_RAWIO while\nmaintaining the selinux check on mmap_zero.  This means that processes\nwhich need to mmap low memory will need CAP_SYS_RAWIO and mmap_zero but will\nNOT need the SELinux sys_rawio capability.\n\nSigned-off-by: Eric Paris \u003ceparis@redhat.com\u003e\nSigned-off-by: James Morris \u003cjmorris@namei.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "1e8cfc4c2ed6214c7accf4a7429e3e051cf63670",
      "old_mode": 33188,
      "old_path": "security/selinux/hooks.c",
      "new_id": "e6d1432b08001bb7da651bf9d5bfdd901d7c1af9",
      "new_mode": 33188,
      "new_path": "security/selinux/hooks.c"
    }
  ]
}
