--- trunk/1.5.x/ccs-patch/README.ccs 2007/08/16 09:01:38 358 +++ trunk/1.5.x/ccs-patch/README.ccs 2008/01/15 01:30:33 893 @@ -769,7 +769,7 @@ @ Allow reuse of memory allocated for domain policy. - As with domain policy, unlike other policies, didn't have + Regarding domain policy, unlike other policies, didn't have "is_deleted" flag and new memory were allocated if the deleted entries are given again. But to allow administrators switch domain policy periodically, @@ -992,7 +992,7 @@ I moved hooks from sock_recvmsg() to skb_recv_datagram() so that network access control for incoming UDP and RAW packets always work. -Fix 2007/03/07 +Fix 2007/08/16 @ Return appropriate error code for CheckMountPermission(). @@ -1000,3 +1000,138 @@ But SELinux determines whether selinuxfs is supported by kernel based on whether error code is -ENODEV or not. So I stopped returning -EPERM unconditionally. + +Fix 2007/08/17 + + @ Remove initializer directive. + + Use "initialize_domain" instrad of "initializer". + +Fix 2007/08/21 + + @ Fix "allow_argv0 ... if if ..." bug. + + It was impossible to use a word "if" to the second argument of + allow_argv0 if condition part is used. + +Fix 2007/08/24 + + @ Move /proc/ccs/\*/\* to /proc/ccs/\* . + + Some pathnames for /proc/ccs/ interface were changed. + +Fix 2007/09/05 + + @ Drop MSG_PEEK'ed message before skb_free_datagram(). + + I need to remove head message from unwanted source + from socket's receive queue so that the caller can pick up + next message from wanted source with MSG_PEEK flags. + +Version 1.5.0 2007/09/20 Usability enhancement release. + +Fix 2007/09/27 + + @ Avoid eating memory after quota exceeded. + + Although ACL entries in a domain won't be added if the domain's quota + has exceeded, SaveName() in AddFileACL() is called anyway. + This caused unneeded memory consumption. + + Now, quota checking is done before getting domain_acl_lock lock. + This may exceed quota by one or two entries, but that won't matter. + +Fix 2007/10/16 + + @ Add environment variable check. + + There are environment variables that may cause dangerous behavior + like LD_\* . + So I introduced 'allow_env' directive that allows specified + environment variable inherited to next domain. + Unlike other permissions, this check is done at execve() time + using next domain's ACL information. + + To manage commonly inherited environments like PATH , + you can use 'allow_env' directive in exception policy + to globally grant specified environment variable. + +Fix 2007/11/05 + + @ Replace semaphore with mutex. + + I replaced semaphore with mutex. + + @ Add missing down() in AddReservedEntry(). + + Mutex debugging capability told me that I had forgotten to call down() + since TOMOYO version 1.3.2 . + This function is not called by learning mode, + so the semaphore's counter will not overflow for normal usage. + +Fix 2005/11/27 + + @ Fix ReadTable() truncation bug. + + "snprintf(str, size, format, ...) >= size" means truncated. + But I was checking for "snprintf(str, size, format, ...) > size". + As a result, some entries might be dumped without '\n'. + + @ Purge direct "->prev"/"->next" manipulation. + + All list manipulations use "struct list_head" or "struct list1_head". + "struct list1_head" doesn't have "->prev" member to save memory usage. + +Fix 2007/11/29 + + @ Add missing semaphore in GetEXE(). + + mm->mmap_sem was missing. + +Fix 2007/12/17 + + @ Remove unused EXPORT_SYMBOL(). + + Mark some functions static. + +Fix 2007/12/18 + + @ Fix AddMountACL() rejection bug. + + To my surprise, "mount --bind source dest" accepts + not only "both source and dest are directory" + but also "both source and dest are non-directory". + I was rejecting if dest is not a derectory in AddMountACL(). + + @ Change log format. + + Profile number and mode is added in audit logs. + +Fix 2008/01/03 + + @ Change directive for file's read/write/execute permission. + + Directives for file's read/write/execute permissions were + 4/2/1 respectively. But for easier understanding, they are now + replaced by read/write/execute (e.g. "allow_read" instead of "4"). + But for easier inputting, 4/2/1 are still accepted instead of + allow_read/allow_write/allow_execute respectively. + + @ Change internal data structure. + + Since I don't have more than 16 types of file permissions, + I combined them using bit-fields. + + Each entry had a field for conditional permission support. + But since this field is unlikely used, I separated the field from + common part. + + These changes will reduce memory used by policy. + +Fix 2008/01/15 + + @ Add ptrace() hook. + + To prevent attackers from controlling important processes using + ptrace(), I added a hook for ptrace(). + Most programs (except strace(1) and gdb(1)) won't use ptrace(2).