)]}'
{
  "commit": "560ee653b67074b805f1b661988a72a0e58811a5",
  "tree": "e480158d626854dde7421d87e76b1fa6443c457f",
  "parents": [
    "a258860e01b80e8f554a4ab1a6c95e6042eb8b73"
  ],
  "author": {
    "name": "James Morris",
    "email": "jmorris@namei.org",
    "time": "Mon Jun 09 15:57:24 2008 -0700"
  },
  "committer": {
    "name": "David S. Miller",
    "email": "davem@davemloft.net",
    "time": "Mon Jun 09 15:57:24 2008 -0700"
  },
  "message": "netfilter: ip_tables: add iptables security table for mandatory access control rules\n\nThe following patch implements a new \"security\" table for iptables, so\nthat MAC (SELinux etc.) networking rules can be managed separately to\nstandard DAC rules.\n\nThis is to help with distro integration of the new secmark-based\nnetwork controls, per various previous discussions.\n\nThe need for a separate table arises from the fact that existing tools\nand usage of iptables will likely clash with centralized MAC policy\nmanagement.\n\nThe SECMARK and CONNSECMARK targets will still be valid in the mangle\ntable to prevent breakage of existing users.\n\nSigned-off-by: James Morris \u003cjmorris@namei.org\u003e\nSigned-off-by: Patrick McHardy \u003ckaber@trash.net\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "650318b0c405b2669fcfe413eb7a73f9b4628240",
      "old_mode": 33188,
      "old_path": "include/linux/netfilter_ipv4.h",
      "new_id": "29c7727ff0e82faa06a636d10ff64eab8c5af2ca",
      "new_mode": 33188,
      "new_path": "include/linux/netfilter_ipv4.h"
    },
    {
      "type": "modify",
      "old_id": "34ee348a2cf207e9b1522706fa2e7a3b216d1b55",
      "old_mode": 33188,
      "old_path": "include/net/netns/ipv4.h",
      "new_id": "6ef90b5fafb351e279a007bf6913dc375ed816f2",
      "new_mode": 33188,
      "new_path": "include/net/netns/ipv4.h"
    },
    {
      "type": "modify",
      "old_id": "2767841a8cefc19377a96506e2f2c4e1c2db7586",
      "old_mode": 33188,
      "old_path": "net/ipv4/netfilter/Kconfig",
      "new_id": "6e251402506e6e0b6e2e3c3c705060bd7d099e09",
      "new_mode": 33188,
      "new_path": "net/ipv4/netfilter/Kconfig"
    },
    {
      "type": "modify",
      "old_id": "d9b92fbf5579583918a7d5f01a1ea3ce0184b60a",
      "old_mode": 33188,
      "old_path": "net/ipv4/netfilter/Makefile",
      "new_id": "3f31291f37ce7c6c68513eb269ccb87de09b3dac",
      "new_mode": 33188,
      "new_path": "net/ipv4/netfilter/Makefile"
    },
    {
      "type": "add",
      "old_id": "0000000000000000000000000000000000000000",
      "old_mode": 0,
      "old_path": "/dev/null",
      "new_id": "2b472ac2263a612a3d6776764abd1410e1a7ed01",
      "new_mode": 33188,
      "new_path": "net/ipv4/netfilter/iptable_security.c"
    },
    {
      "type": "modify",
      "old_id": "211189eb2b679a2f4b815fbb15a3999a883128f9",
      "old_mode": 33188,
      "old_path": "net/netfilter/xt_CONNSECMARK.c",
      "new_id": "76ca1f2421eb875472eb27ee2a26dd71892a0e95",
      "new_mode": 33188,
      "new_path": "net/netfilter/xt_CONNSECMARK.c"
    },
    {
      "type": "modify",
      "old_id": "c0284856ccd490bf32c23b7fafd01f04ff793d08",
      "old_mode": 33188,
      "old_path": "net/netfilter/xt_SECMARK.c",
      "new_id": "94f87ee7552b0708b855ce998a3a355e71b13af4",
      "new_mode": 33188,
      "new_path": "net/netfilter/xt_SECMARK.c"
    }
  ]
}
