)]}'
{
  "commit": "b94c7e677b9d28bd3f9ba4a70df6bfa7942867ca",
  "tree": "ea116d586f821526513d32fd5e7c2f8fa6d59485",
  "parents": [
    "bb242497474da317a7169cc939c741ccf2e79e8c"
  ],
  "author": {
    "name": "Chad Sellers",
    "email": "csellers@tresys.com",
    "time": "Mon Nov 06 12:38:18 2006 -0500"
  },
  "committer": {
    "name": "James Morris",
    "email": "jmorris@namei.org",
    "time": "Tue Nov 28 12:04:38 2006 -0500"
  },
  "message": "SELinux: validate kernel object classes and permissions\n\nThis is a new object class and permission validation scheme that validates\nagainst the defined kernel headers. This scheme allows extra classes\nand permissions that do not conflict with the kernel definitions to be\nadded to the policy. This validation is now done for all policy loads,\nnot just subsequent loads after the first policy load.\n\nThe implementation walks the three structrures containing the defined\nobject class and permission values and ensures their values are the\nsame in the policy being loaded. This includes verifying the object\nclasses themselves, the permissions they contain, and the permissions\nthey inherit from commons. Classes or permissions that are present in the\nkernel but missing from the policy cause a warning (printed to KERN_INFO)\nto be printed, but do not stop the policy from loading, emulating current\nbehavior. Any other inconsistencies cause the load to fail.\n\nSigned-off-by: Chad Sellers \u003ccsellers@tresys.com\u003e\nAcked-by:  Stephen Smalley \u003csds@tycho.nsa.gov\u003e\nSigned-off-by: James Morris \u003cjmorris@namei.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "33ae1020091ec34181aecb32c8a5fcd2b33b2590",
      "old_mode": 33188,
      "old_path": "security/selinux/ss/services.c",
      "new_id": "408820486af04eaa9574d5f014324d1029309fed",
      "new_mode": 33188,
      "new_path": "security/selinux/ss/services.c"
    }
  ]
}
