)]}'
{
  "commit": "67f83cbf081a70426ff667e8d14f94e13ed3bdca",
  "tree": "776a40733eacb9071478f865e6791daa3f6fd602",
  "parents": [
    "6b877699c6f1efede4545bcecc367786a472eedb"
  ],
  "author": {
    "name": "Venkat Yekkirala",
    "email": "vyekkirala@trustedcs.com",
    "time": "Wed Nov 08 17:04:26 2006 -0600"
  },
  "committer": {
    "name": "David S. Miller",
    "email": "davem@sunset.davemloft.net",
    "time": "Sat Dec 02 21:21:34 2006 -0800"
  },
  "message": "SELinux: Fix SA selection semantics\n\nFix the selection of an SA for an outgoing packet to be at the same\ncontext as the originating socket/flow. This eliminates the SELinux\npolicy\u0027s ability to use/sendto SAs with contexts other than the socket\u0027s.\n\nWith this patch applied, the SELinux policy will require one or more of the\nfollowing for a socket to be able to communicate with/without SAs:\n\n1. To enable a socket to communicate without using labeled-IPSec SAs:\n\nallow socket_t unlabeled_t:association { sendto recvfrom }\n\n2. To enable a socket to communicate with labeled-IPSec SAs:\n\nallow socket_t self:association { sendto };\nallow socket_t peer_sa_t:association { recvfrom };\n\nSigned-off-by: Venkat Yekkirala \u003cvyekkirala@TrustedCS.com\u003e\nSigned-off-by: James Morris \u003cjmorris@namei.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "84cebcdb3f833e0f6fb061ed724123f32095e3c3",
      "old_mode": 33188,
      "old_path": "include/linux/security.h",
      "new_id": "83cdefae993165cce7e8601dc127fcb520420161",
      "new_mode": 33188,
      "new_path": "include/linux/security.h"
    },
    {
      "type": "modify",
      "old_id": "7736b23c3f0386a7c0bab1840425fdb69e7a7cd8",
      "old_mode": 33188,
      "old_path": "net/xfrm/xfrm_policy.c",
      "new_id": "b88b038530c97719be0f81f03663cfecc15dea3a",
      "new_mode": 33188,
      "new_path": "net/xfrm/xfrm_policy.c"
    },
    {
      "type": "modify",
      "old_id": "0148d1518dd1f718eb33fd66037178f11d76a771",
      "old_mode": 33188,
      "old_path": "security/dummy.c",
      "new_id": "558795b237d6d873d5f729faf2208779a5db384e",
      "new_mode": 33188,
      "new_path": "security/dummy.c"
    },
    {
      "type": "modify",
      "old_id": "5bbd599a4471a5301c64911b05f67f9e67bafe86",
      "old_mode": 33188,
      "old_path": "security/selinux/hooks.c",
      "new_id": "956137baf3e76771924f5e98a89ed296c6eaccef",
      "new_mode": 33188,
      "new_path": "security/selinux/hooks.c"
    },
    {
      "type": "modify",
      "old_id": "27502365d70608e4ed05d8833a0d4da119ffee58",
      "old_mode": 33188,
      "old_path": "security/selinux/include/xfrm.h",
      "new_id": "ebd7246a4be5d1824b164aab4967e2b398a0129f",
      "new_mode": 33188,
      "new_path": "security/selinux/include/xfrm.h"
    },
    {
      "type": "modify",
      "old_id": "8fef74271f22ca8320f00fd616b471edf8acdf38",
      "old_mode": 33188,
      "old_path": "security/selinux/xfrm.c",
      "new_id": "9b777140068f2da5999c7e243ed6e89f6905dafb",
      "new_mode": 33188,
      "new_path": "security/selinux/xfrm.c"
    }
  ]
}
