get:
Show a patch.

patch:
Update a patch.

put:
Update a patch.

GET /api/patches/808427/?format=api
HTTP 200 OK
Allow: GET, PUT, PATCH, HEAD, OPTIONS
Content-Type: application/json
Vary: Accept

{
    "id": 808427,
    "url": "http://patchwork.ozlabs.org/api/patches/808427/?format=api",
    "web_url": "http://patchwork.ozlabs.org/project/netdev/patch/20170831205635.80256-3-chenbofeng.kernel@gmail.com/",
    "project": {
        "id": 7,
        "url": "http://patchwork.ozlabs.org/api/projects/7/?format=api",
        "name": "Linux network development",
        "link_name": "netdev",
        "list_id": "netdev.vger.kernel.org",
        "list_email": "netdev@vger.kernel.org",
        "web_url": null,
        "scm_url": null,
        "webscm_url": null,
        "list_archive_url": "",
        "list_archive_url_format": "",
        "commit_url_format": ""
    },
    "msgid": "<20170831205635.80256-3-chenbofeng.kernel@gmail.com>",
    "list_archive_url": null,
    "date": "2017-08-31T20:56:34",
    "name": "[2/3] security: bpf: Add eBPF LSM hooks and security field to eBPF map",
    "commit_ref": null,
    "pull_url": null,
    "state": "changes-requested",
    "archived": true,
    "hash": "40649b4ea1b910069ac6526d64f75f8a7d3cb832",
    "submitter": {
        "id": 70894,
        "url": "http://patchwork.ozlabs.org/api/people/70894/?format=api",
        "name": "Chenbo Feng",
        "email": "chenbofeng.kernel@gmail.com"
    },
    "delegate": {
        "id": 34,
        "url": "http://patchwork.ozlabs.org/api/users/34/?format=api",
        "username": "davem",
        "first_name": "David",
        "last_name": "Miller",
        "email": "davem@davemloft.net"
    },
    "mbox": "http://patchwork.ozlabs.org/project/netdev/patch/20170831205635.80256-3-chenbofeng.kernel@gmail.com/mbox/",
    "series": [
        {
            "id": 906,
            "url": "http://patchwork.ozlabs.org/api/series/906/?format=api",
            "web_url": "http://patchwork.ozlabs.org/project/netdev/list/?series=906",
            "date": "2017-08-31T20:56:32",
            "name": "Security: add lsm hooks for checking permissions on eBPF objects",
            "version": 1,
            "mbox": "http://patchwork.ozlabs.org/series/906/mbox/"
        }
    ],
    "comments": "http://patchwork.ozlabs.org/api/patches/808427/comments/",
    "check": "pending",
    "checks": "http://patchwork.ozlabs.org/api/patches/808427/checks/",
    "tags": {},
    "related": [],
    "headers": {
        "Return-Path": "<netdev-owner@vger.kernel.org>",
        "X-Original-To": "patchwork-incoming@ozlabs.org",
        "Delivered-To": "patchwork-incoming@ozlabs.org",
        "Authentication-Results": [
            "ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=vger.kernel.org\n\t(client-ip=209.132.180.67; helo=vger.kernel.org;\n\tenvelope-from=netdev-owner@vger.kernel.org;\n\treceiver=<UNKNOWN>)",
            "ozlabs.org; dkim=pass (2048-bit key;\n\tunprotected) header.d=gmail.com header.i=@gmail.com\n\theader.b=\"IrG4ahoP\"; dkim-atps=neutral"
        ],
        "Received": [
            "from vger.kernel.org (vger.kernel.org [209.132.180.67])\n\tby ozlabs.org (Postfix) with ESMTP id 3xjvnk3fdhz9t1t\n\tfor <patchwork-incoming@ozlabs.org>;\n\tFri,  1 Sep 2017 06:57:14 +1000 (AEST)",
            "(majordomo@vger.kernel.org) by vger.kernel.org via listexpand\n\tid S1751555AbdHaU5L (ORCPT <rfc822;patchwork-incoming@ozlabs.org>);\n\tThu, 31 Aug 2017 16:57:11 -0400",
            "from mail-pf0-f194.google.com ([209.85.192.194]:37337 \"EHLO\n\tmail-pf0-f194.google.com\" rhost-flags-OK-OK-OK-OK) by vger.kernel.org\n\twith ESMTP id S1751393AbdHaU5K (ORCPT\n\t<rfc822;netdev@vger.kernel.org>); Thu, 31 Aug 2017 16:57:10 -0400",
            "by mail-pf0-f194.google.com with SMTP id a2so436393pfj.4;\n\tThu, 31 Aug 2017 13:57:09 -0700 (PDT)",
            "from fengc.mtv.corp.google.com ([100.98.121.64])\n\tby smtp.gmail.com with ESMTPSA id\n\tg68sm710967pfj.33.2017.08.31.13.57.08\n\t(version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128);\n\tThu, 31 Aug 2017 13:57:08 -0700 (PDT)"
        ],
        "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=gmail.com; s=20161025;\n\th=from:to:cc:subject:date:message-id:in-reply-to:references;\n\tbh=iE+8q6k9lURg86d+cOt5WJmpRTtHS/EDp4sAtG33OPk=;\n\tb=IrG4ahoPNAAlYuDWJ1FiryYsDXlrPkEBHoiq1OYuha2pg4Xxkp4kk77zaLSSN030pZ\n\tldMzXOYFhJvzdm/izSAWIKEPcLVErE8ec9sQrA0+81/AFepKxMGFFzaro4V+lzW/GfxP\n\tUw7UNSX1Xpx5UZxkiPvb0vAcN6iX5VpBKBGGD3+BbZadAt76ExIY2J3w4OZsYwJEefN+\n\tZhJR6yMXM04pgvGkTkI6gaNViYOTE2HWUGnavtq008eXrWopJML7WigOaV7khIsrRae5\n\t5/S9KrgWHSMwKc4TWj/hWgrSWfQuw7s4JuFMMdwi3LYIwYBMmZyxlnKMIp1r7CD+YE9b\n\tMH7g==",
        "X-Google-DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=1e100.net; s=20161025;\n\th=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to\n\t:references;\n\tbh=iE+8q6k9lURg86d+cOt5WJmpRTtHS/EDp4sAtG33OPk=;\n\tb=ufg77I2NXtwWf4DfaLSzSHVFslctQodFDR92n6Z8ZIkMUbHlt3AcsX3w2iqpV/RFrW\n\tnoZwDHekSK1PJmjxaIJPH0hNejg+uqaToAiR/r4MHkepa5w6HpR/n6qCze+bmxuqcnSJ\n\tatIuy7lWOFd9auWK2IsX8wJdv77DtcUe24FDpA4QZetewF99hD0B92J1ZyOrjWboCYrV\n\tfXP+EzFAYtQErzSmIDrvpWCWf22alRxlQ5PWDaRNdO1gEKD9EJaTOhdUM5ERpUEqm36d\n\tu9o4WC4jFZp37nogQ25qRzUt0vViODMbLYU1rrXEpS9B91sqYwNxCjAWWvqLLHPg4UEf\n\tfEvQ==",
        "X-Gm-Message-State": "AHYfb5iGst5XisUDbYTAPp8QrCuWd2W4r7MQjhe+nAgl7t5C2Ykj+BLD\n\t7jaNxUy6+3eZH6sh",
        "X-Google-Smtp-Source": "ADKCNb6hW91RFnxaRwJpRYuhE3jhkWVjSZ5J8ycKZ0ABuBDDXt02HUKUPB82WMEZDyI4eluRdlANnQ==",
        "X-Received": "by 10.98.158.12 with SMTP id s12mr3737838pfd.246.1504213029400; \n\tThu, 31 Aug 2017 13:57:09 -0700 (PDT)",
        "From": "Chenbo Feng <chenbofeng.kernel@gmail.com>",
        "To": "linux-security-module@vger.kernel.org",
        "Cc": "Jeffrey Vander Stoep <jeffv@google.com>, netdev@vger.kernel.org,\n\tSELinux <Selinux@tycho.nsa.gov>,\n\tAlexei Starovoitov <alexei.starovoitov@gmail.com>,\n\tlorenzo@google.com, Chenbo Feng <fengc@google.com>",
        "Subject": "[PATCH 2/3] security: bpf: Add eBPF LSM hooks and security field to\n\teBPF map",
        "Date": "Thu, 31 Aug 2017 13:56:34 -0700",
        "Message-Id": "<20170831205635.80256-3-chenbofeng.kernel@gmail.com>",
        "X-Mailer": "git-send-email 2.14.1.581.gf28d330327-goog",
        "In-Reply-To": "<20170831205635.80256-1-chenbofeng.kernel@gmail.com>",
        "References": "<20170831205635.80256-1-chenbofeng.kernel@gmail.com>",
        "Sender": "netdev-owner@vger.kernel.org",
        "Precedence": "bulk",
        "List-ID": "<netdev.vger.kernel.org>",
        "X-Mailing-List": "netdev@vger.kernel.org"
    },
    "content": "From: Chenbo Feng <fengc@google.com>\n\nIntroduce a pointer into struct bpf_map to hold the security information\nabout the map. The actual security struct varies based on the security\nmodels implemented. Place the LSM hooks before each of the unrestricted\neBPF operations, the map_update_elem and map_delete_elem operations are\nchecked by security_map_modify. The map_lookup_elem and map_get_next_key\noperations are checked by securtiy_map_read.\n\nSigned-off-by: Chenbo Feng <fengc@google.com>\n---\n include/linux/bpf.h  |  3 +++\n kernel/bpf/syscall.c | 28 ++++++++++++++++++++++++++++\n 2 files changed, 31 insertions(+)",
    "diff": "diff --git a/include/linux/bpf.h b/include/linux/bpf.h\nindex b69e7a5869ff..ca3e6ff7091d 100644\n--- a/include/linux/bpf.h\n+++ b/include/linux/bpf.h\n@@ -53,6 +53,9 @@ struct bpf_map {\n \tstruct work_struct work;\n \tatomic_t usercnt;\n \tstruct bpf_map *inner_map_meta;\n+#ifdef CONFIG_SECURITY\n+\tvoid *security;\n+#endif\n };\n \n /* function argument constraints */\ndiff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c\nindex 045646da97cc..b15580bcf3b1 100644\n--- a/kernel/bpf/syscall.c\n+++ b/kernel/bpf/syscall.c\n@@ -279,6 +279,10 @@ static int map_create(union bpf_attr *attr)\n \tif (err)\n \t\treturn -EINVAL;\n \n+\terr = security_map_create();\n+\tif (err)\n+\t\treturn -EACCES;\n+\n \t/* find map type and init map: hashtable vs rbtree vs bloom vs ... */\n \tmap = find_and_alloc_map(attr);\n \tif (IS_ERR(map))\n@@ -291,6 +295,10 @@ static int map_create(union bpf_attr *attr)\n \tif (err)\n \t\tgoto free_map_nouncharge;\n \n+\terr = security_post_create(map);\n+\tif (err < 0)\n+\t\tgoto free_map;\n+\n \terr = bpf_map_alloc_id(map);\n \tif (err)\n \t\tgoto free_map;\n@@ -410,6 +418,10 @@ static int map_lookup_elem(union bpf_attr *attr)\n \tif (IS_ERR(map))\n \t\treturn PTR_ERR(map);\n \n+\terr = security_map_read(map);\n+\tif (err)\n+\t\treturn -EACCES;\n+\n \tkey = memdup_user(ukey, map->key_size);\n \tif (IS_ERR(key)) {\n \t\terr = PTR_ERR(key);\n@@ -490,6 +502,10 @@ static int map_update_elem(union bpf_attr *attr)\n \tif (IS_ERR(map))\n \t\treturn PTR_ERR(map);\n \n+\terr = security_map_modify(map);\n+\tif (err)\n+\t\treturn -EACCES;\n+\n \tkey = memdup_user(ukey, map->key_size);\n \tif (IS_ERR(key)) {\n \t\terr = PTR_ERR(key);\n@@ -573,6 +589,10 @@ static int map_delete_elem(union bpf_attr *attr)\n \tif (IS_ERR(map))\n \t\treturn PTR_ERR(map);\n \n+\terr = security_map_modify(map);\n+\tif (err)\n+\t\treturn -EACCES;\n+\n \tkey = memdup_user(ukey, map->key_size);\n \tif (IS_ERR(key)) {\n \t\terr = PTR_ERR(key);\n@@ -616,6 +636,10 @@ static int map_get_next_key(union bpf_attr *attr)\n \tif (IS_ERR(map))\n \t\treturn PTR_ERR(map);\n \n+\terr = security_map_read(map);\n+\tif (err)\n+\t\treturn -EACCES;\n+\n \tif (ukey) {\n \t\tkey = memdup_user(ukey, map->key_size);\n \t\tif (IS_ERR(key)) {\n@@ -935,6 +959,10 @@ static int bpf_prog_load(union bpf_attr *attr)\n \tif (CHECK_ATTR(BPF_PROG_LOAD))\n \t\treturn -EINVAL;\n \n+\terr = security_prog_load();\n+\tif (err)\n+\t\treturn -EACCES;\n+\n \tif (attr->prog_flags & ~BPF_F_STRICT_ALIGNMENT)\n \t\treturn -EINVAL;\n \n",
    "prefixes": [
        "2/3"
    ]
}