get:
Show a patch.

patch:
Update a patch.

put:
Update a patch.

GET /api/patches/808428/?format=api
HTTP 200 OK
Allow: GET, PUT, PATCH, HEAD, OPTIONS
Content-Type: application/json
Vary: Accept

{
    "id": 808428,
    "url": "http://patchwork.ozlabs.org/api/patches/808428/?format=api",
    "web_url": "http://patchwork.ozlabs.org/project/netdev/patch/20170831205635.80256-4-chenbofeng.kernel@gmail.com/",
    "project": {
        "id": 7,
        "url": "http://patchwork.ozlabs.org/api/projects/7/?format=api",
        "name": "Linux network development",
        "link_name": "netdev",
        "list_id": "netdev.vger.kernel.org",
        "list_email": "netdev@vger.kernel.org",
        "web_url": null,
        "scm_url": null,
        "webscm_url": null,
        "list_archive_url": "",
        "list_archive_url_format": "",
        "commit_url_format": ""
    },
    "msgid": "<20170831205635.80256-4-chenbofeng.kernel@gmail.com>",
    "list_archive_url": null,
    "date": "2017-08-31T20:56:35",
    "name": "[3/3] selinux: bpf: Implement the selinux checks for eBPF object",
    "commit_ref": null,
    "pull_url": null,
    "state": "changes-requested",
    "archived": true,
    "hash": "c3da470241ab6b59536e62f1f36df0fc81028cd1",
    "submitter": {
        "id": 70894,
        "url": "http://patchwork.ozlabs.org/api/people/70894/?format=api",
        "name": "Chenbo Feng",
        "email": "chenbofeng.kernel@gmail.com"
    },
    "delegate": {
        "id": 34,
        "url": "http://patchwork.ozlabs.org/api/users/34/?format=api",
        "username": "davem",
        "first_name": "David",
        "last_name": "Miller",
        "email": "davem@davemloft.net"
    },
    "mbox": "http://patchwork.ozlabs.org/project/netdev/patch/20170831205635.80256-4-chenbofeng.kernel@gmail.com/mbox/",
    "series": [
        {
            "id": 906,
            "url": "http://patchwork.ozlabs.org/api/series/906/?format=api",
            "web_url": "http://patchwork.ozlabs.org/project/netdev/list/?series=906",
            "date": "2017-08-31T20:56:32",
            "name": "Security: add lsm hooks for checking permissions on eBPF objects",
            "version": 1,
            "mbox": "http://patchwork.ozlabs.org/series/906/mbox/"
        }
    ],
    "comments": "http://patchwork.ozlabs.org/api/patches/808428/comments/",
    "check": "pending",
    "checks": "http://patchwork.ozlabs.org/api/patches/808428/checks/",
    "tags": {},
    "related": [],
    "headers": {
        "Return-Path": "<netdev-owner@vger.kernel.org>",
        "X-Original-To": "patchwork-incoming@ozlabs.org",
        "Delivered-To": "patchwork-incoming@ozlabs.org",
        "Authentication-Results": [
            "ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=vger.kernel.org\n\t(client-ip=209.132.180.67; helo=vger.kernel.org;\n\tenvelope-from=netdev-owner@vger.kernel.org;\n\treceiver=<UNKNOWN>)",
            "ozlabs.org; dkim=pass (2048-bit key;\n\tunprotected) header.d=gmail.com header.i=@gmail.com\n\theader.b=\"dYoDlvXJ\"; dkim-atps=neutral"
        ],
        "Received": [
            "from vger.kernel.org (vger.kernel.org [209.132.180.67])\n\tby ozlabs.org (Postfix) with ESMTP id 3xjvnm724zz9t1t\n\tfor <patchwork-incoming@ozlabs.org>;\n\tFri,  1 Sep 2017 06:57:16 +1000 (AEST)",
            "(majordomo@vger.kernel.org) by vger.kernel.org via listexpand\n\tid S1751623AbdHaU5O (ORCPT <rfc822;patchwork-incoming@ozlabs.org>);\n\tThu, 31 Aug 2017 16:57:14 -0400",
            "from mail-pf0-f196.google.com ([209.85.192.196]:36708 \"EHLO\n\tmail-pf0-f196.google.com\" rhost-flags-OK-OK-OK-OK) by vger.kernel.org\n\twith ESMTP id S1751443AbdHaU5L (ORCPT\n\t<rfc822;netdev@vger.kernel.org>); Thu, 31 Aug 2017 16:57:11 -0400",
            "by mail-pf0-f196.google.com with SMTP id k3so442882pfc.3;\n\tThu, 31 Aug 2017 13:57:11 -0700 (PDT)",
            "from fengc.mtv.corp.google.com ([100.98.121.64])\n\tby smtp.gmail.com with ESMTPSA id\n\tg68sm710967pfj.33.2017.08.31.13.57.10\n\t(version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128);\n\tThu, 31 Aug 2017 13:57:10 -0700 (PDT)"
        ],
        "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=gmail.com; s=20161025;\n\th=from:to:cc:subject:date:message-id:in-reply-to:references;\n\tbh=ZQwf78Y7+8SpP7CrKLxmsUluboYOsNY+gmSAPXJnhRo=;\n\tb=dYoDlvXJ/J5Hhc9NeJZMhhYSjLuD0RQTFIYhMXnPX6FUjl8IfOLiWxSmQRBYSAXiK3\n\tUiZ7X8xFtOOZ9m0BqhET5V46Qw/HnbQvQLes6VnUIcZYLl6daY3fZmqdBH4JybiNJb8M\n\tZhXj3c8Ie9vm3OfmvrOg0n5r840DTU4oAR6HOJrC0eybRyLa0hDJesWmz3+MV1ZfCU89\n\tr/qisZe8qM8eyyyaMQelJBlsr5eFsSUanLvtB1G2vhj154vtljCjv53MUhGr9APgdWhc\n\tOTIuOCtmAXaoltHe6LsgJYBcJ+wQC0hzHtKdP1poiPuXFW+50ocdLpkD05+9e9LuRwFv\n\tzxww==",
        "X-Google-DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=1e100.net; s=20161025;\n\th=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to\n\t:references;\n\tbh=ZQwf78Y7+8SpP7CrKLxmsUluboYOsNY+gmSAPXJnhRo=;\n\tb=n0FDRxhZjrywbZVPF1zaRcLGDSdandaOsrRCFrBO/iuiW3tgxGzNCNwx+t+KNl6lE0\n\tGHaqN6/vBSoxuGJk5ez6q3KZtd9rFBjccA8KqxF5zuCCh2igbVZs17fHwDLeqnKkslOI\n\tcurryRZYfnclMWVTiC7EfUcBIFPnOjm42SY9jZdzzjZRjubNh6JK73gmpSGJ9Z4FbO+Q\n\tiCaIYFTPhH1D/vXe7l36zqXOe3CYDPIjbeg9q2Uqej53asguDusX5mOOKhXcME84PQlS\n\tcfgD4npc+vgCzjoNV+psJ5GP2ACD4NQjhv4t5yE959AS86SeZmB7Mh+STRy52qquBVxD\n\tUm2Q==",
        "X-Gm-Message-State": "AHYfb5g5Gv58W2ICLWTXtXmfdmPMNlxLdV1IJ67n88U//kuRDENI1ick\n\ta8dMG/5/pyNYDzwI",
        "X-Google-Smtp-Source": "ADKCNb7FttGeWvNw9kTzuAMY5iQowygHVrSvBDPi9Sks/9fvmamxA35d05Zk+Nb5yFTEWN7P3+ncsA==",
        "X-Received": "by 10.84.194.228 with SMTP id h91mr3931939pld.419.1504213031150; \n\tThu, 31 Aug 2017 13:57:11 -0700 (PDT)",
        "From": "Chenbo Feng <chenbofeng.kernel@gmail.com>",
        "To": "linux-security-module@vger.kernel.org",
        "Cc": "Jeffrey Vander Stoep <jeffv@google.com>, netdev@vger.kernel.org,\n\tSELinux <Selinux@tycho.nsa.gov>,\n\tAlexei Starovoitov <alexei.starovoitov@gmail.com>,\n\tlorenzo@google.com, Chenbo Feng <fengc@google.com>",
        "Subject": "[PATCH 3/3] selinux: bpf: Implement the selinux checks for eBPF\n\tobject",
        "Date": "Thu, 31 Aug 2017 13:56:35 -0700",
        "Message-Id": "<20170831205635.80256-4-chenbofeng.kernel@gmail.com>",
        "X-Mailer": "git-send-email 2.14.1.581.gf28d330327-goog",
        "In-Reply-To": "<20170831205635.80256-1-chenbofeng.kernel@gmail.com>",
        "References": "<20170831205635.80256-1-chenbofeng.kernel@gmail.com>",
        "Sender": "netdev-owner@vger.kernel.org",
        "Precedence": "bulk",
        "List-ID": "<netdev.vger.kernel.org>",
        "X-Mailing-List": "netdev@vger.kernel.org"
    },
    "content": "From: Chenbo Feng <fengc@google.com>\n\nIntroduce 5 new selinux checks for eBPF object related operations. The\ncheck is based on the ownership information of eBPF maps and the\ncapability of creating eBPF object.\n\nSigned-off-by: Chenbo Feng <fengc@google.com>\n---\n security/selinux/hooks.c            | 54 +++++++++++++++++++++++++++++++++++++\n security/selinux/include/classmap.h |  2 ++\n security/selinux/include/objsec.h   |  4 +++\n 3 files changed, 60 insertions(+)",
    "diff": "diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c\nindex 33fd061305c4..39ad7d9f335d 100644\n--- a/security/selinux/hooks.c\n+++ b/security/selinux/hooks.c\n@@ -85,6 +85,7 @@\n #include <linux/export.h>\n #include <linux/msg.h>\n #include <linux/shm.h>\n+#include <linux/bpf.h>\n \n #include \"avc.h\"\n #include \"objsec.h\"\n@@ -6245,6 +6246,52 @@ static void selinux_ib_free_security(void *ib_sec)\n }\n #endif\n \n+#ifdef CONFIG_BPF_SYSCALL\n+static int selinux_bpf_map_create(void)\n+{\n+\tu32 sid = current_sid();\n+\n+\treturn avc_has_perm(sid, sid, SECCLASS_BPF, BPF__MAP_CREATE, NULL);\n+}\n+\n+static int selinux_bpf_map_modify(struct bpf_map *map)\n+{\n+\tstruct bpf_security_struct *bpfsec = map->security;\n+\n+\treturn avc_has_perm(current_sid(), bpfsec->sid, SECCLASS_BPF,\n+\t\t\t    BPF__MAP_MODIFY, NULL);\n+}\n+\n+static int selinux_bpf_map_read(struct bpf_map *map)\n+{\n+\tstruct bpf_security_struct *bpfsec = map->security;\n+\n+\treturn avc_has_perm(current_sid(), bpfsec->sid, SECCLASS_BPF,\n+\t\t\t    BPF__MAP_READ, NULL);\n+}\n+\n+static int selinux_bpf_prog_load(void)\n+{\n+\tu32 sid = current_sid();\n+\n+\treturn avc_has_perm(sid, sid, SECCLASS_BPF, BPF__PROG_LOAD, NULL);\n+}\n+\n+static int selinux_bpf_post_create(struct bpf_map *map)\n+{\n+\tstruct bpf_security_struct *bpfsec;\n+\n+\tbpfsec = kzalloc(sizeof(*bpfsec), GFP_KERNEL);\n+\tif (!bpfsec)\n+\t\treturn -ENOMEM;\n+\n+\tbpfsec->sid = current_sid();\n+\tmap->security = bpfsec;\n+\n+\treturn 0;\n+}\n+#endif\n+\n static struct security_hook_list selinux_hooks[] __lsm_ro_after_init = {\n \tLSM_HOOK_INIT(binder_set_context_mgr, selinux_binder_set_context_mgr),\n \tLSM_HOOK_INIT(binder_transaction, selinux_binder_transaction),\n@@ -6465,6 +6512,13 @@ static struct security_hook_list selinux_hooks[] __lsm_ro_after_init = {\n \tLSM_HOOK_INIT(audit_rule_match, selinux_audit_rule_match),\n \tLSM_HOOK_INIT(audit_rule_free, selinux_audit_rule_free),\n #endif\n+#ifdef CONFIG_BPF_SYSCALL\n+\tLSM_HOOK_INIT(bpf_map_create, selinux_bpf_map_create),\n+\tLSM_HOOK_INIT(bpf_map_modify, selinux_bpf_map_modify),\n+\tLSM_HOOK_INIT(bpf_map_read, selinux_bpf_map_read),\n+\tLSM_HOOK_INIT(bpf_prog_load, selinux_bpf_prog_load),\n+\tLSM_HOOK_INIT(bpf_post_create, selinux_bpf_post_create),\n+#endif\n };\n \n static __init int selinux_init(void)\ndiff --git a/security/selinux/include/classmap.h b/security/selinux/include/classmap.h\nindex b9fe3434b036..83c880fb17b4 100644\n--- a/security/selinux/include/classmap.h\n+++ b/security/selinux/include/classmap.h\n@@ -235,6 +235,8 @@ struct security_class_mapping secclass_map[] = {\n \t  { \"access\", NULL } },\n \t{ \"infiniband_endport\",\n \t  { \"manage_subnet\", NULL } },\n+\t{ \"bpf\",\n+\t  {\"map_create\", \"map_modify\", \"map_read\", \"prog_load\" } },\n \t{ NULL }\n   };\n \ndiff --git a/security/selinux/include/objsec.h b/security/selinux/include/objsec.h\nindex 6ebc61e370ff..ba564f662b0d 100644\n--- a/security/selinux/include/objsec.h\n+++ b/security/selinux/include/objsec.h\n@@ -150,6 +150,10 @@ struct pkey_security_struct {\n \tu32\tsid;\t/* SID of pkey */\n };\n \n+struct bpf_security_struct {\n+\tu32 sid;\t/*SID of bpf obj creater*/\n+};\n+\n extern unsigned int selinux_checkreqprot;\n \n #endif /* _SELINUX_OBJSEC_H_ */\n",
    "prefixes": [
        "3/3"
    ]
}