)]}'
{
  "commit": "788084aba2ab7348257597496befcbccabdc98a3",
  "tree": "2da42d746d67b16ef705229a1b5a3528ec19c725",
  "parents": [
    "8cf948e744e0218af604c32edecde10006dc8e9e"
  ],
  "author": {
    "name": "Eric Paris",
    "email": "eparis@redhat.com",
    "time": "Fri Jul 31 12:54:11 2009 -0400"
  },
  "committer": {
    "name": "James Morris",
    "email": "jmorris@namei.org",
    "time": "Mon Aug 17 15:09:11 2009 +1000"
  },
  "message": "Security/SELinux: seperate lsm specific mmap_min_addr\n\nCurrently SELinux enforcement of controls on the ability to map low memory\nis determined by the mmap_min_addr tunable.  This patch causes SELinux to\nignore the tunable and instead use a seperate Kconfig option specific to how\nmuch space the LSM should protect.\n\nThe tunable will now only control the need for CAP_SYS_RAWIO and SELinux\npermissions will always protect the amount of low memory designated by\nCONFIG_LSM_MMAP_MIN_ADDR.\n\nThis allows users who need to disable the mmap_min_addr controls (usual reason\nbeing they run WINE as a non-root user) to do so and still have SELinux\ncontrols preventing confined domains (like a web server) from being able to\nmap some area of low memory.\n\nSigned-off-by: Eric Paris \u003ceparis@redhat.com\u003e\nSigned-off-by: James Morris \u003cjmorris@namei.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "ba3a7cb1eaa0d6a3d3c67401592728c58742917f",
      "old_mode": 33188,
      "old_path": "include/linux/mm.h",
      "new_id": "9a72cc78e6b817d2b7c24b076eef7bd0061235f2",
      "new_mode": 33188,
      "new_path": "include/linux/mm.h"
    },
    {
      "type": "modify",
      "old_id": "ac4bc3760b464a79515c3b9841421dc0eb1d8922",
      "old_mode": 33188,
      "old_path": "include/linux/security.h",
      "new_id": "dc3472c1f78153d8ea1c0da1d8909cd95a5cc691",
      "new_mode": 33188,
      "new_path": "include/linux/security.h"
    },
    {
      "type": "modify",
      "old_id": "98e02328c67de053dc55bdee746ca381e526660e",
      "old_mode": 33188,
      "old_path": "kernel/sysctl.c",
      "new_id": "58be76017fd000f3b019c0acab6d3cdeb672afda",
      "new_mode": 33188,
      "new_path": "kernel/sysctl.c"
    },
    {
      "type": "modify",
      "old_id": "c948d4ca8bde0dc0d73ba1c40b984d395a73b4d8",
      "old_mode": 33188,
      "old_path": "mm/Kconfig",
      "new_id": "fe5f674d7a7d571a1f456d2df3d5a31bb965db2e",
      "new_mode": 33188,
      "new_path": "mm/Kconfig"
    },
    {
      "type": "modify",
      "old_id": "34579b23ebd55ebed1a99a5473c6ca0693b559e2",
      "old_mode": 33188,
      "old_path": "mm/mmap.c",
      "new_id": "8101de490c73941ab8815733a3899c614cdb8cb7",
      "new_mode": 33188,
      "new_path": "mm/mmap.c"
    },
    {
      "type": "modify",
      "old_id": "53cab10fece40a3f5835604e62754818de0e1e7c",
      "old_mode": 33188,
      "old_path": "mm/nommu.c",
      "new_id": "28754c40be986608e96fe3cb1db7111a6e161cf8",
      "new_mode": 33188,
      "new_path": "mm/nommu.c"
    },
    {
      "type": "modify",
      "old_id": "d23c839038f00836cb96a51e53e27db8b8ec163c",
      "old_mode": 33188,
      "old_path": "security/Kconfig",
      "new_id": "9c60c346a91ddded5dcbff3186a0c501619ae477",
      "new_mode": 33188,
      "new_path": "security/Kconfig"
    },
    {
      "type": "modify",
      "old_id": "c67557cdaa857f9046d30cacb7f3ecc42196f9bb",
      "old_mode": 33188,
      "old_path": "security/Makefile",
      "new_id": "b56e7f9ecbc2adf22706a849d704d8761dfa91dd",
      "new_mode": 33188,
      "new_path": "security/Makefile"
    },
    {
      "type": "modify",
      "old_id": "6bcf6e81e5473fc32177df7faf71e9b476a9cb3b",
      "old_mode": 33188,
      "old_path": "security/commoncap.c",
      "new_id": "e3097c0a1311205cc231cee85cb012b271db1ed8",
      "new_mode": 33188,
      "new_path": "security/commoncap.c"
    },
    {
      "type": "add",
      "old_id": "0000000000000000000000000000000000000000",
      "old_mode": 0,
      "old_path": "/dev/null",
      "new_id": "14cc7b3b8d0379ef0cd17e071aa2821ea6dd4a95",
      "new_mode": 33188,
      "new_path": "security/min_addr.c"
    },
    {
      "type": "modify",
      "old_id": "e6d1432b08001bb7da651bf9d5bfdd901d7c1af9",
      "old_mode": 33188,
      "old_path": "security/selinux/hooks.c",
      "new_id": "8d8b69c5664ef7f1eaa89c8a19139152ca159477",
      "new_mode": 33188,
      "new_path": "security/selinux/hooks.c"
    }
  ]
}
