From gjelinek@sac.sfbay.sun.com Wed Feb  4 07:33:26 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n14FXPoc025922
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 4 Feb 2009 07:33:25 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n14FXO05033966;
	Wed, 4 Feb 2009 08:33:25 -0700 (MST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KEJ00L3BSJNOE00@brm-avmta-1.central.sun.com>; Wed,
 04 Feb 2009 08:33:23 -0700 (MST)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KEJ00IUOSJLPVE0@brm-avmta-1.central.sun.com>; Wed,
 04 Feb 2009 08:33:21 -0700 (MST)
Received: from sac.sfbay.sun.com (new-sac.SFBay.Sun.COM [129.146.175.65])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n14FXKUM024439; Wed, 04 Feb 2009 07:33:20 -0800 (PST)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n14FXIaG025903; Wed,
 04 Feb 2009 07:33:18 -0800 (PST)
Received: (from gjelinek@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id n14FXIua025899; Wed,
 04 Feb 2009 07:33:18 -0800 (PST)
Date: Wed, 04 Feb 2009 07:33:18 -0800 (PST)
From: Gerald Jelinek <gjelinek@sac.sfbay.sun.com>
Subject: labeled brand zone [PSARC/2009/065 FastTrack timeout 02/11/2009]
To: PSARC-ext@sun.com
Cc: Ric.Aleshire@sun.com, gerald.jelinek@sun.com
Message-id: <200902041533.n14FXIua025899@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 4368

I'm sponsoring this fast-track for Ric Aleshire.
The contract is in the case directory and both
managers will sign the contract before the case times
out.

Thanks,
Jerry


Template Version: @(#)sac_nextcase %I% %G% SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 labeled brand zone
    1.2. Name of Document Author/Supplier:
	 Author:  Ric Aleshire
    1.3  Date of This Document:
	04 February, 2009
4. Technical Description

"Labeled" Brand Zone

Problem

Configuring and operating Trusted Extensions is a complex
administrative task.  When Trusted extensions is enabled, each zone
must be associated with a unique sensitivity label.  Only labeled zones
are compatible with the Trusted Gnome desktop.  The creation of labeled
zones is particularly involved, and requires zone configuration
differences compared to traditional native zones.  In OpenSolaris, for
example, labeled zones need additional IPS packages, additional lofs
mounts, and additional customization prior to first boot.  We need a
convenient way to provide indirection for these customizations, to
automate and "hide" them, to simplify system administration.


Proposal

Interfaces for branded zones (PSARC/2005/471) provide a transparent way
to handle differences in zone environments.  This case reserves a new
brand type, "labeled", which will be used to implement zones for Trusted
Extensions.  The "labeled" brand type is closely related to the native
brand.  No kernel modules or other additional software is required for
this brand; it is a native-equivalent brand.

This case also establishes a contract for zone interfaces used to support
the new "labeled" brand type.

In addition, the following applies when Trusted Extensions is enabled:

1) Except where directed explicitly by the content of the brand files,
   zones infrastructure will not implicitly distinguish between brands
   (i.e., conditional behavior based on brand name) and will treat all
   zones as native.

2) Only native and native-equivalent brands can be started.  Non-native
   zones cannot be run under TX.


Interfaces

_________________________________________________________________________
|                         Interfaces Exported                           |
|_______________________________________________________________________|
| Interface                                  | Stability                |
|____________________________________________|__________________________|
| brand name "labeled"                       | Committed                |
|____________________________________________|__________________________|


This case imports the following BrandZ interfaces, which are all Project
Private to the BrandZ project.  (A contract for use of these interfaces
is included in materials for this case.)

_________________________________________________________________________
|                         Interfaces Imported                           |
|_______________________________________________________________________|
| Interface                                  | Comment                  |
|____________________________________________|__________________________|
| /usr/share/lib/xml/dtd/zone_platform.dtd.1 |                          |
|____________________________________________|__________________________|
| /usr/share/lib/xml/dtd/brand.dtd.1         | Specifically, these tags |
|                                            | in brand.dtd.1 are used: |
|                                            |    <install>             |
|                                            |    <installopts>         |
|                                            |    <initname>            |
|                                            |    <login_cmd>           |
|                                            |    <user_cmd>            |
|____________________________________________|__________________________|

(Note that no libbrand.so interfaces are used.)


References

PSARC 2002/762 - Layered Trusted Solaris
PSARC/2002/174 - Virtualization and Namespace Isolation in Solaris
PSARC/2005/471 - BrandZ: Support for non-native zones


6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From gww@eng.sun.com Wed Feb  4 08:08:41 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n14G8eUP002515
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 4 Feb 2009 08:08:41 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n14G8aBt019335
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 4 Feb 2009 16:08:39 GMT
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KEJ00A39U6EGO00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 04 Feb 2009 08:08:38 -0800 (PST)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KEJ009SGU6D2I10@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 04 Feb 2009 08:08:37 -0800 (PST)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n14G8bxE059596; Wed, 04 Feb 2009 08:08:37 -0800 (PST)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n14G7K1U018835; Wed,
 04 Feb 2009 08:07:20 -0800 (PST)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n14G7Kjo018834; Wed,
 04 Feb 2009 08:07:20 -0800 (PST)
Date: Wed, 04 Feb 2009 08:07:20 -0800 (PST)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: labeled brand zone [PSARC/2009/065 FastTrack timeout 02/11/2009]
To: PSARC-ext@sun.com, gjelinek@sac.sfbay.sun.com
Cc: Ric.Aleshire@sun.com, gerald.jelinek@sun.com
Message-id: <200902041607.n14G7Kjo018834@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 228

> I'm sponsoring this fast-track for Ric Aleshire.
> The contract is in the case directory and both
> managers will sign the contract before the case times
> out.

> 4. Technical Description
> 
> "Labeled" Brand Zone

+1
Gary..

From Glenn.Faden@sun.com Wed Feb  4 12:07:49 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n14K7nuM007403
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 4 Feb 2009 12:07:49 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n14K7mRZ029034
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 4 Feb 2009 12:07:49 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KEK00H07590TK00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.Com); Wed, 04 Feb 2009 12:07:48 -0800 (PST)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KEK007MB590GK70@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.Com); Wed,
 04 Feb 2009 12:07:48 -0800 (PST)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n14K7mD0027375	for
 <PSARC-ext@Sun.Com>; Wed, 04 Feb 2009 12:07:48 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KEK00K004ONSU00@fe-sfbay-10.sun.com> for PSARC-ext@Sun.Com
 (ORCPT PSARC-ext@Sun.Com); Wed, 04 Feb 2009 12:07:48 -0800 (PST)
Received: from [192.168.0.140] ([unknown] [24.5.105.37])
 by fe-sfbay-10.sun.com (Sun Java(tm) System Messaging Server 7.0-3.01 64bit
 (built Dec 23 2008)) with ESMTPSA id <0KEK0090D58Z3NG0@fe-sfbay-10.sun.com>;
 Wed, 04 Feb 2009 12:07:47 -0800 (PST)
Date: Wed, 04 Feb 2009 12:07:47 -0800
From: Glenn Faden <Glenn.Faden@sun.com>
Subject: Re: labeled brand zone [PSARC/2009/065 FastTrack timeout 02/11/2009]
In-reply-to: <200902041533.n14FXIua025899@sac.sfbay.sun.com>
Sender: Glenn.Faden@sun.com
To: Gerald Jelinek <gjelinek@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com, Ric.Aleshire@sun.com, Gerald.Jelinek@sun.com
Message-id: <4989F593.4010208@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200902041533.n14FXIua025899@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.19 (Macintosh/20081209)
Status: RO
Content-Length: 4745

Gerald Jelinek wrote:
> I'm sponsoring this fast-track for Ric Aleshire.
> The contract is in the case directory and both
> managers will sign the contract before the case times
> out.
>
> Thanks,
> Jerry
>
>
> Template Version: @(#)sac_nextcase %I% %G% SMI
> This information is Copyright 2009 Sun Microsystems
> 1. Introduction
>     1.1. Project/Component Working Name:
> 	 labeled brand zone
>     1.2. Name of Document Author/Supplier:
> 	 Author:  Ric Aleshire
>     1.3  Date of This Document:
> 	04 February, 2009
> 4. Technical Description
>
> "Labeled" Brand Zone
>
> Problem
>
> Configuring and operating Trusted Extensions is a complex
> administrative task.  When Trusted extensions is enabled, each zone
> must be associated with a unique sensitivity label.  Only labeled zones
> are compatible with the Trusted Gnome desktop.  The creation of labeled
> zones is particularly involved, and requires zone configuration
> differences compared to traditional native zones.  In OpenSolaris, for
> example, labeled zones need additional IPS packages, additional lofs
> mounts, and additional customization prior to first boot.  We need a
> convenient way to provide indirection for these customizations, to
> automate and "hide" them, to simplify system administration.
>
>
> Proposal
>
> Interfaces for branded zones (PSARC/2005/471) provide a transparent way
> to handle differences in zone environments.  This case reserves a new
> brand type, "labeled", which will be used to implement zones for Trusted
> Extensions.  The "labeled" brand type is closely related to the native
> brand.  No kernel modules or other additional software is required for
> this brand; it is a native-equivalent brand.
>
> This case also establishes a contract for zone interfaces used to support
> the new "labeled" brand type.
>
> In addition, the following applies when Trusted Extensions is enabled:
>
> 1) Except where directed explicitly by the content of the brand files,
>    zones infrastructure will not implicitly distinguish between brands
>    (i.e., conditional behavior based on brand name) and will treat all
>    zones as native.
>
> 2) Only native and native-equivalent brands can be started.  Non-native
>    zones cannot be run under TX.
>   
Similarly, when TX is disabled, it should not be possible to boot zones 
with the "labeled" brand type since that would effectively declassify them.

--Glenn
>
> Interfaces
>
> _________________________________________________________________________
> |                         Interfaces Exported                           |
> |_______________________________________________________________________|
> | Interface                                  | Stability                |
> |____________________________________________|__________________________|
> | brand name "labeled"                       | Committed                |
> |____________________________________________|__________________________|
>
>
> This case imports the following BrandZ interfaces, which are all Project
> Private to the BrandZ project.  (A contract for use of these interfaces
> is included in materials for this case.)
>
> _________________________________________________________________________
> |                         Interfaces Imported                           |
> |_______________________________________________________________________|
> | Interface                                  | Comment                  |
> |____________________________________________|__________________________|
> | /usr/share/lib/xml/dtd/zone_platform.dtd.1 |                          |
> |____________________________________________|__________________________|
> | /usr/share/lib/xml/dtd/brand.dtd.1         | Specifically, these tags |
> |                                            | in brand.dtd.1 are used: |
> |                                            |    <install>             |
> |                                            |    <installopts>         |
> |                                            |    <initname>            |
> |                                            |    <login_cmd>           |
> |                                            |    <user_cmd>            |
> |____________________________________________|__________________________|
>
> (Note that no libbrand.so interfaces are used.)
>
>
> References
>
> PSARC 2002/762 - Layered Trusted Solaris
> PSARC/2002/174 - Virtualization and Namespace Isolation in Solaris
> PSARC/2005/471 - BrandZ: Support for non-native zones
>
>
> 6. Resources and Schedule
>     6.4. Steering Committee requested information
>    	6.4.1. Consolidation C-team Name:
> 		ON
>     6.5. ARC review type: FastTrack
>     6.6. ARC Exposure: open
>
>   


From Sridhar.Yedunuthula@sun.com Wed Feb 11 09:43:45 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1BHhjmP004865
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 11 Feb 2009 09:43:45 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n1BHhhnd026493
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 11 Feb 2009 10:43:44 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KEW00905X8W4E00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.Com); Wed, 11 Feb 2009 09:43:44 -0800 (PST)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KEW00KGBX8W1R80@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.Com); Wed,
 11 Feb 2009 09:43:44 -0800 (PST)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n1BHhi5g000284	for
 <PSARC-ext@Sun.Com>; Wed, 11 Feb 2009 17:43:44 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KEW00L00WD7R500@mail-amer.sun.com> for PSARC-ext@Sun.Com
 (ORCPT PSARC-ext@Sun.Com); Wed, 11 Feb 2009 10:43:44 -0700 (MST)
Received: from dhcp-umpk17-228-192.SFBay.Sun.COM ([unknown] [129.146.228.192])
 by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 with ESMTPSA id <0KEW00F8RX8QE2H0@mail-amer.sun.com>; Wed,
 11 Feb 2009 10:43:38 -0700 (MST)
Date: Wed, 11 Feb 2009 09:46:03 -0800
From: Sridhar Yedunuthula <Sridhar.Yedunuthula@sun.com>
Subject: Re: labeled brand zone [PSARC/2009/065 FastTrack timeout 02/11/2009]
In-reply-to: <4989B793.1070709@sun.com>
Sender: Sridhar.Yedunuthula@sun.com
To: PSARC-ext@sun.com
Cc: Craig Payne <Craig.Payne@sun.com>, Ric Aleshire <Ric.Aleshire@sun.com>
Message-id: <49930EDB.8080701@sun.com>
Organization: Solaris
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4989B793.1070709@sun.com>
User-Agent: Thunderbird 2.0.0.19 (Macintosh/20081209)
Status: RO
Content-Length: 287

Approved.

- Sridhar

Jerry Jelinek wrote:
> I submitted the ARC case for the contract for TX to
> use the zones brand interfaces.  Craig and Sridhar,
> both of you need to "sign" this contract by responding
> to this email indicating that you approve the contract.
> 
> Thanks,
> Jerry

From Craig.Payne@sun.com Wed Feb 11 12:18:21 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1BKIK80012336
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 11 Feb 2009 12:18:20 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n1BKIH8x026610
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 11 Feb 2009 20:18:19 GMT
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KEX004054EHOP00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 11 Feb 2009 12:18:17 -0800 (PST)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KEX00IG94EHC370@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 11 Feb 2009 12:18:17 -0800 (PST)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n1BKIHAk001767	for
 <PSARC-ext@sun.com>; Wed, 11 Feb 2009 12:18:17 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KEX002003SI6W00@fe-sfbay-10.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 11 Feb 2009 12:18:17 -0800 (PST)
Received: from [129.146.11.146] ([unknown] [129.146.11.146])
 by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 with ESMTPSA id <0KEX0073T4EELB80@fe-sfbay-10.sun.com>; Wed,
 11 Feb 2009 12:18:14 -0800 (PST)
Date: Wed, 11 Feb 2009 12:18:14 -0800
From: Craig Payne <Craig.Payne@sun.com>
Subject: Re: labeled brand zone [PSARC/2009/065 FastTrack timeout 02/11/2009]
In-reply-to: <499331B0.5090500@sun.com>
Sender: Craig.Payne@sun.com
To: PSARC-ext@sun.com
Cc: Ric Aleshire <Ric.Aleshire@sun.com>
Reply-to: Craig.Payne@sun.com
Message-id: <49933286.8070500@Sun.COM>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_zEbqV+OUO1qiTwzH0U+I9Q)"
X-PMX-Version: 5.4.1.325704
References: <4989B793.1070709@sun.com> <49930EDB.8080701@sun.com>
 <499331B0.5090500@sun.com>
User-Agent: Thunderbird 2.0.0.16 (X11/20080807)
Status: RO
Content-Length: 6691

This is a multi-part message in MIME format.

--Boundary_(ID_zEbqV+OUO1qiTwzH0U+I9Q)
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

On 02/11/09 12:14, Jerry Jelinek wrote:
> Craig,
> 
> The contract is attached.  If you respond to this email
> then the contract will be signed.
> 
> Thanks,
> Jerry
> 

Approved.

-- 
Craig Payne
Sr. Manager, Solaris Platform Security
Direct: (510) 550-7413
Internal: x30176

--Boundary_(ID_zEbqV+OUO1qiTwzH0U+I9Q)
Content-type: text/plain; name=contract1
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=contract1


        CONTRACT ALLOWING/REQUIRING SPECIAL ARRANGEMENTS FOR INTERFACES

0.  Number: PSARC/2009/065

1.  This contract is between
        a SUPPLIER of INTERFACES and
        a CONSUMER of those INTERFACES,
    both of whom are entities within Sun Microsystems, Incorporated.

2.  The SUPPLIER (definer and/or implementor) is identified by the following:
    Product or Bundle:                  Solaris
    Consolidation:                      ON
    Department or Group:                Solaris Core Technologies
    Bugtraq Category/SubCategory:       kernel/zones
    Responsible Manager:                Sridhar Yedunuthula

3.  The CONSUMER is identified by the following:
    Product or Bundle:                  Solaris
    Consolidation:                      ON
    Department or Group:                Solaris Security
    Bugtraq Category/SubCategory:       utility/sec_labeling
    Responsible Manager:                Craig Payne

4.  The INTERFACES are:

INTERFACE                               STABILITY

BrandZ Interfaces                       Project Private
                                        for all interfaces

// The "labeled" brand is closely related to the "native" brand type,
// and does not use any libbrand.so interface.
// Solaris Security needs notification when there are changes to
// the two files below. 

/usr/share/lib/xml/dtd/zone_platform.dtd.1
/usr/share/lib/xml/dtd/brand.dtd.1

// The "labeled" brand "customizes" the following tags from brand.dtd.1

        <install></install>
	<installopts></installopts>
	<initname></initname>
	<login_cmd></login_cmd>
	<user_cmd></user_cmd>


5.  The ARC controlling these INTERFACES is:

PSARC

6.  The CASE describing these INTERFACES is:

        PSARC/2002/174 - Virtualization and Namespace Isolation in Solaris
        PSARC/2005/471 - BrandZ: Support for non-native zones

7.  The following SPECIAL ARRANGEMENTS are made which modify the rules
    imposed by the stability levels listed in section 4 above:


_N_ 7a. Although the stability level doesn't normally restrict it,
        SUPPLIER promises to only modify INTERFACES in an incompatible
        way as follows:

                SUPPLIER agrees to only change the contracted interface
                in an incompatible manner in a new minor release.

_N_ 7b. Although the stability level doesn't normally allow it, CONSUMER will
        expose INTERFACES to a PARTNER, which is external to Sun, namely:
                Name of Company:
                Name of Department or Group within Company:
                Responsible Manager:

_N_ 7c. Although the stability level doesn't normally allow it, CONSUMER will
        import INTERFACES from a separate consolidation.


        SUPPLIER will notify CONSUMER of any changes to the interface.

_Y_ 7d. If SUPPLIER decides to change (including replace or remove) any
        portion of the INTERFACES, SUPPLIER will notify CONSUMER of the
        proposed new version, no later than the application for ARC
        approval of the new version.
        If SUPPLIER and CONSUMER are contained in the same consolidation,
        they have the option of arranging for simultaneous conversion
        to the new interfaces.  If this is not possible, or if they are
        not in the same consolidation, then SUPPLIER will either make best
        effort to work with CONSUMER so that CONSUMER can detect which
        version of INTERFACES is being supplied, or else SUPPLIER will
        make best effort to supply both old and new versions of INTERFACES.
        If SUPPLIER cannot make both versions of INTERFACES available,
        and SUPPLIER and CONSUMER cannot devise a method whereby
        CONSUMER can detect which version of INTERFACES is being
        supplied, and the old version of CONSUMER will not run with the
        new version of SUPPLIER, then either the EOL process must be
        followed by SUPPLIER, or else a major release of SUPPLIER will
        be required, or the change will not be allowed. 

10. SUPPLIER and CONSUMER agree that evolution of INTERFACES shall be
    handled as follows:

        SUPPLIER will notify CONSUMER of any proposed changes to the
        interface.

11. SUPPLIER and CONSUMER agree that INTERFACES will be supported as
    follows:

        CONSUMER shall file bugster change requests against the
        interfaces under solaris/kernel/zones.  SUPPLIER agrees to
        respond to these change requests according to the usual
        sustaining process.

12. SUPPLIER and CONSUMER agree that INTERFACES will be documented as
    follows:

        The materials in this case.

13. SUPPLIER and CONSUMER agree that changes to the INTERFACES will be
    tested as follows:

        SUPPLIER agrees to test any changes to the interface as part of
        existing or updated test suites.  CONSUMER agrees to test their
        use of these interfaces at the usual release intervals and when
        any changes are made to the implementation of the contracted
        interface.

14. SUPPLIER and CONSUMER agree that this contract can be terminated as
    follows:

        Contract will be terminated by mutual agreement between the
        SUPPLIER and CONSUMER.

15. This contract is not valid until "signed" via agreement from the
    SUPPLIER and CONSUMER, and approved by the ARC CASE referenced by
    this contract.  E-mail agreement to the contract should be archived
    in the mail archive of CASE; verbal agreement to the contract
    should be noted in the meeting minutes.  This contract remains
    valid until superseded or invalidated.

For SUPPLIER: Sridar Yedunuthula        Date: 
For CONSUMER: Craig Payne               Date: 
For ARC: ?                              Date: 

    A copy of this contract shall be deposited in the CASE directory as
    "contract-<digits>" or in a "contracts" subdirectory.

16. (Not to be filled in until superseded or invalidated.)
    This contract was superseded or invalidated by CASE:
    For ARC:                    Date:




--Boundary_(ID_zEbqV+OUO1qiTwzH0U+I9Q)--

From Gerald.Jelinek@sun.com Wed Feb 11 12:22:01 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n1BKM1v0012399
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 11 Feb 2009 12:22:01 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n1BKM0aT010270
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 11 Feb 2009 12:22:01 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KEX00K034KPBH00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.Com); Wed, 11 Feb 2009 12:22:01 -0800 (PST)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KEX00HL64KNJ150@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.Com); Wed,
 11 Feb 2009 12:21:59 -0800 (PST)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n1BKLxBR018914	for
 <PSARC-ext@Sun.Com>; Wed, 11 Feb 2009 20:21:59 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KEX007004J54E00@mail-amer.sun.com> for PSARC-ext@Sun.Com
 (ORCPT PSARC-ext@Sun.Com); Wed, 11 Feb 2009 13:21:59 -0700 (MST)
Received: from [192.168.0.11] ([unknown] [206.53.29.107])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7.0-3.01 64bit
 (built Dec 23 2008)) with ESMTPSA id <0KEX002GK4KMWI80@mail-amer.sun.com>; Wed,
 11 Feb 2009 13:21:58 -0700 (MST)
Date: Wed, 11 Feb 2009 13:21:58 -0700
From: Jerry Jelinek <Gerald.Jelinek@sun.com>
Subject: Re: labeled brand zone [PSARC/2009/065 FastTrack timeout 02/11/2009]
In-reply-to: <200902041533.n14FXIua025899@sac.sfbay.sun.com>
Sender: Gerald.Jelinek@sun.com
To: PSARC-ext@sun.com
Cc: Gerald Jelinek <gjelinek@sac.sfbay.sun.com>, Ric.Aleshire@sun.com
Message-id: <49933366.5010007@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200902041533.n14FXIua025899@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081203)
Status: RO
Content-Length: 140

This case was approved at todays PSARC meeting.
Both managers have signed the contract so I
marked the case closed approved.

Thanks,
Jerry

