From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Paul Moore <paul@paul-moore.com>,
Casey Schaufler <casey@schaufler-ca.com>,
John Johansen <john.johansen@canonical.com>,
Sasha Levin <sashal@kernel.org>
Subject: [PATCH 5.10 46/73] lsm: make security_socket_getpeersec_stream() sockptr_t safe
Date: Wed, 13 Mar 2024 12:46:13 -0400 [thread overview]
Message-ID: <20240313164640.616049-47-sashal@kernel.org> (raw)
In-Reply-To: <20240313164640.616049-1-sashal@kernel.org>
From: Paul Moore <paul@paul-moore.com>
[ Upstream commit b10b9c342f7571f287fd422be5d5c0beb26ba974 ]
Commit 4ff09db1b79b ("bpf: net: Change sk_getsockopt() to take the
sockptr_t argument") made it possible to call sk_getsockopt()
with both user and kernel address space buffers through the use of
the sockptr_t type. Unfortunately at the time of conversion the
security_socket_getpeersec_stream() LSM hook was written to only
accept userspace buffers, and in a desire to avoid having to change
the LSM hook the commit author simply passed the sockptr_t's
userspace buffer pointer. Since the only sk_getsockopt() callers
at the time of conversion which used kernel sockptr_t buffers did
not allow SO_PEERSEC, and hence the
security_socket_getpeersec_stream() hook, this was acceptable but
also very fragile as future changes presented the possibility of
silently passing kernel space pointers to the LSM hook.
There are several ways to protect against this, including careful
code review of future commits, but since relying on code review to
catch bugs is a recipe for disaster and the upstream eBPF maintainer
is "strongly against defensive programming", this patch updates the
LSM hook, and all of the implementations to support sockptr_t and
safely handle both user and kernel space buffers.
Acked-by: Casey Schaufler <casey@schaufler-ca.com>
Acked-by: John Johansen <john.johansen@canonical.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Stable-dep-of: 5a287d3d2b9d ("lsm: fix default return value of the socket_getpeersec_*() hooks")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/lsm_hook_defs.h | 2 +-
include/linux/lsm_hooks.h | 4 ++--
include/linux/security.h | 11 +++++++----
net/core/sock.c | 3 ++-
security/apparmor/lsm.c | 29 +++++++++++++----------------
security/security.c | 6 +++---
security/selinux/hooks.c | 13 ++++++-------
security/smack/smack_lsm.c | 19 ++++++++++---------
8 files changed, 44 insertions(+), 43 deletions(-)
diff --git a/include/linux/lsm_hook_defs.h b/include/linux/lsm_hook_defs.h
index 92a76ce0c382d..9f550eab8ebdb 100644
--- a/include/linux/lsm_hook_defs.h
+++ b/include/linux/lsm_hook_defs.h
@@ -294,7 +294,7 @@ LSM_HOOK(int, 0, socket_setsockopt, struct socket *sock, int level, int optname)
LSM_HOOK(int, 0, socket_shutdown, struct socket *sock, int how)
LSM_HOOK(int, 0, socket_sock_rcv_skb, struct sock *sk, struct sk_buff *skb)
LSM_HOOK(int, 0, socket_getpeersec_stream, struct socket *sock,
- char __user *optval, int __user *optlen, unsigned len)
+ sockptr_t optval, sockptr_t optlen, unsigned int len)
LSM_HOOK(int, 0, socket_getpeersec_dgram, struct socket *sock,
struct sk_buff *skb, u32 *secid)
LSM_HOOK(int, 0, sk_alloc_security, struct sock *sk, int family, gfp_t priority)
diff --git a/include/linux/lsm_hooks.h b/include/linux/lsm_hooks.h
index 64cdf4d7bfb30..bbf9c8c7bd9c5 100644
--- a/include/linux/lsm_hooks.h
+++ b/include/linux/lsm_hooks.h
@@ -926,8 +926,8 @@
* SO_GETPEERSEC. For tcp sockets this can be meaningful if the
* socket is associated with an ipsec SA.
* @sock is the local socket.
- * @optval userspace memory where the security state is to be copied.
- * @optlen userspace int where the module should copy the actual length
+ * @optval memory where the security state is to be copied.
+ * @optlen memory where the module should copy the actual length
* of the security state.
* @len as input is the maximum length to copy to userspace provided
* by the caller.
diff --git a/include/linux/security.h b/include/linux/security.h
index e388b1666bcfc..5b61aa19fac66 100644
--- a/include/linux/security.h
+++ b/include/linux/security.h
@@ -31,6 +31,7 @@
#include <linux/err.h>
#include <linux/string.h>
#include <linux/mm.h>
+#include <linux/sockptr.h>
struct linux_binprm;
struct cred;
@@ -1366,8 +1367,8 @@ int security_socket_getsockopt(struct socket *sock, int level, int optname);
int security_socket_setsockopt(struct socket *sock, int level, int optname);
int security_socket_shutdown(struct socket *sock, int how);
int security_sock_rcv_skb(struct sock *sk, struct sk_buff *skb);
-int security_socket_getpeersec_stream(struct socket *sock, char __user *optval,
- int __user *optlen, unsigned len);
+int security_socket_getpeersec_stream(struct socket *sock, sockptr_t optval,
+ sockptr_t optlen, unsigned int len);
int security_socket_getpeersec_dgram(struct socket *sock, struct sk_buff *skb, u32 *secid);
int security_sk_alloc(struct sock *sk, int family, gfp_t priority);
void security_sk_free(struct sock *sk);
@@ -1501,8 +1502,10 @@ static inline int security_sock_rcv_skb(struct sock *sk,
return 0;
}
-static inline int security_socket_getpeersec_stream(struct socket *sock, char __user *optval,
- int __user *optlen, unsigned len)
+static inline int security_socket_getpeersec_stream(struct socket *sock,
+ sockptr_t optval,
+ sockptr_t optlen,
+ unsigned int len)
{
return -ENOPROTOOPT;
}
diff --git a/net/core/sock.c b/net/core/sock.c
index 42da46965b16f..016c0b9e01b70 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c
@@ -1503,7 +1503,8 @@ static int sk_getsockopt(struct sock *sk, int level, int optname,
break;
case SO_PEERSEC:
- return security_socket_getpeersec_stream(sock, optval.user, optlen.user, len);
+ return security_socket_getpeersec_stream(sock,
+ optval, optlen, len);
case SO_MARK:
v.val = sk->sk_mark;
diff --git a/security/apparmor/lsm.c b/security/apparmor/lsm.c
index 585edcc6814d2..052f1b920e43f 100644
--- a/security/apparmor/lsm.c
+++ b/security/apparmor/lsm.c
@@ -1070,11 +1070,10 @@ static struct aa_label *sk_peer_label(struct sock *sk)
* Note: for tcp only valid if using ipsec or cipso on lan
*/
static int apparmor_socket_getpeersec_stream(struct socket *sock,
- char __user *optval,
- int __user *optlen,
+ sockptr_t optval, sockptr_t optlen,
unsigned int len)
{
- char *name;
+ char *name = NULL;
int slen, error = 0;
struct aa_label *label;
struct aa_label *peer;
@@ -1091,23 +1090,21 @@ static int apparmor_socket_getpeersec_stream(struct socket *sock,
/* don't include terminating \0 in slen, it breaks some apps */
if (slen < 0) {
error = -ENOMEM;
- } else {
- if (slen > len) {
- error = -ERANGE;
- } else if (copy_to_user(optval, name, slen)) {
- error = -EFAULT;
- goto out;
- }
- if (put_user(slen, optlen))
- error = -EFAULT;
-out:
- kfree(name);
-
+ goto done;
+ }
+ if (slen > len) {
+ error = -ERANGE;
+ goto done_len;
}
+ if (copy_to_sockptr(optval, name, slen))
+ error = -EFAULT;
+done_len:
+ if (copy_to_sockptr(optlen, &slen, sizeof(slen)))
+ error = -EFAULT;
done:
end_current_label_crit_section(label);
-
+ kfree(name);
return error;
}
diff --git a/security/security.c b/security/security.c
index 269c3965393f4..e9dcde3c4f14b 100644
--- a/security/security.c
+++ b/security/security.c
@@ -2224,11 +2224,11 @@ int security_sock_rcv_skb(struct sock *sk, struct sk_buff *skb)
}
EXPORT_SYMBOL(security_sock_rcv_skb);
-int security_socket_getpeersec_stream(struct socket *sock, char __user *optval,
- int __user *optlen, unsigned len)
+int security_socket_getpeersec_stream(struct socket *sock, sockptr_t optval,
+ sockptr_t optlen, unsigned int len)
{
return call_int_hook(socket_getpeersec_stream, -ENOPROTOOPT, sock,
- optval, optlen, len);
+ optval, optlen, len);
}
int security_socket_getpeersec_dgram(struct socket *sock, struct sk_buff *skb, u32 *secid)
diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index 50d3ddfe15fd1..46c00a68bb4bd 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -5110,11 +5110,12 @@ static int selinux_socket_sock_rcv_skb(struct sock *sk, struct sk_buff *skb)
return err;
}
-static int selinux_socket_getpeersec_stream(struct socket *sock, char __user *optval,
- int __user *optlen, unsigned len)
+static int selinux_socket_getpeersec_stream(struct socket *sock,
+ sockptr_t optval, sockptr_t optlen,
+ unsigned int len)
{
int err = 0;
- char *scontext;
+ char *scontext = NULL;
u32 scontext_len;
struct sk_security_struct *sksec = sock->sk->sk_security;
u32 peer_sid = SECSID_NULL;
@@ -5130,17 +5131,15 @@ static int selinux_socket_getpeersec_stream(struct socket *sock, char __user *op
&scontext_len);
if (err)
return err;
-
if (scontext_len > len) {
err = -ERANGE;
goto out_len;
}
- if (copy_to_user(optval, scontext, scontext_len))
+ if (copy_to_sockptr(optval, scontext, scontext_len))
err = -EFAULT;
-
out_len:
- if (put_user(scontext_len, optlen))
+ if (copy_to_sockptr(optlen, &scontext_len, sizeof(scontext_len)))
err = -EFAULT;
kfree(scontext);
return err;
diff --git a/security/smack/smack_lsm.c b/security/smack/smack_lsm.c
index e1669759403a6..5388f143eecd8 100644
--- a/security/smack/smack_lsm.c
+++ b/security/smack/smack_lsm.c
@@ -4022,12 +4022,12 @@ static int smack_socket_sock_rcv_skb(struct sock *sk, struct sk_buff *skb)
* returns zero on success, an error code otherwise
*/
static int smack_socket_getpeersec_stream(struct socket *sock,
- char __user *optval,
- int __user *optlen, unsigned len)
+ sockptr_t optval, sockptr_t optlen,
+ unsigned int len)
{
struct socket_smack *ssp;
char *rcp = "";
- int slen = 1;
+ u32 slen = 1;
int rc = 0;
ssp = sock->sk->sk_security;
@@ -4035,15 +4035,16 @@ static int smack_socket_getpeersec_stream(struct socket *sock,
rcp = ssp->smk_packet->smk_known;
slen = strlen(rcp) + 1;
}
-
- if (slen > len)
+ if (slen > len) {
rc = -ERANGE;
- else if (copy_to_user(optval, rcp, slen) != 0)
- rc = -EFAULT;
+ goto out_len;
+ }
- if (put_user(slen, optlen) != 0)
+ if (copy_to_sockptr(optval, rcp, slen))
+ rc = -EFAULT;
+out_len:
+ if (copy_to_sockptr(optlen, &slen, sizeof(slen)))
rc = -EFAULT;
-
return rc;
}
--
2.43.0
next prev parent reply other threads:[~2024-03-13 16:47 UTC|newest]
Thread overview: 98+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-03-13 16:45 [PATCH 5.10 00/73] 5.10.213-rc1 review Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 01/73] mmc: mmci: stm32: use a buffer for unaligned DMA requests Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 02/73] mmc: mmci: stm32: fix DMA API overlapping mappings warning Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 03/73] lan78xx: Fix white space and style issues Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 04/73] lan78xx: Add missing return code checks Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 05/73] lan78xx: Fix partial packet errors on suspend/resume Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 06/73] lan78xx: Fix race conditions in suspend/resume handling Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 07/73] net: lan78xx: fix runtime PM count underflow on link stop Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 08/73] ixgbe: {dis, en}able irqs in ixgbe_txrx_ring_{dis, en}able Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 09/73] i40e: disable NAPI right after disabling irqs when handling xsk_pool Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 10/73] tracing/net_sched: Fix tracepoints that save qdisc_dev() as a string Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 11/73] geneve: make sure to pull inner header in geneve_rx() Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 12/73] net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 13/73] net/ipv6: avoid possible UAF in ip6_route_mpath_notify() Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 14/73] cpumap: Zero-initialise xdp_rxq_info struct before running XDP program Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 15/73] net/rds: fix WARNING in rds_conn_connect_if_down Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 16/73] netfilter: nft_ct: fix l3num expectations with inet pseudo family Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 17/73] netfilter: nf_conntrack_h323: Add protection for bmp length out of range Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 18/73] netrom: Fix a data-race around sysctl_netrom_default_path_quality Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 19/73] netrom: Fix a data-race around sysctl_netrom_obsolescence_count_initialiser Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 20/73] netrom: Fix data-races around sysctl_netrom_network_ttl_initialiser Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 21/73] netrom: Fix a data-race around sysctl_netrom_transport_timeout Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 22/73] netrom: Fix a data-race around sysctl_netrom_transport_maximum_tries Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 23/73] netrom: Fix a data-race around sysctl_netrom_transport_acknowledge_delay Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 24/73] netrom: Fix a data-race around sysctl_netrom_transport_busy_delay Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 25/73] netrom: Fix a data-race around sysctl_netrom_transport_requested_window_size Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 26/73] netrom: Fix a data-race around sysctl_netrom_transport_no_activity_timeout Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 27/73] netrom: Fix a data-race around sysctl_netrom_routing_control Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 28/73] netrom: Fix a data-race around sysctl_netrom_link_fails_count Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 29/73] netrom: Fix data-races around sysctl_net_busy_read Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 30/73] selftests/mm: switch to bash from sh Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 31/73] selftests: mm: fix map_hugetlb failure on 64K page size systems Sasha Levin
2024-03-13 16:45 ` [PATCH 5.10 32/73] um: allow not setting extra rpaths in the linux binary Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 33/73] xhci: remove extra loop in interrupt context Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 34/73] xhci: prevent double-fetch of transfer and transfer event TRBs Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 35/73] xhci: process isoc TD properly when there was a transaction error mid TD Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 36/73] xhci: handle isoc Babble and Buffer Overrun events properly Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 37/73] serial: max310x: Use devm_clk_get_optional() to get the input clock Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 38/73] serial: max310x: Try to get crystal clock rate from property Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 39/73] serial: max310x: fail probe if clock crystal is unstable Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 40/73] serial: max310x: Make use of device properties Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 41/73] serial: max310x: use regmap methods for SPI batch operations Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 42/73] serial: max310x: use a separate regmap for each port Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 43/73] serial: max310x: prevent infinite while() loop in port startup Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 44/73] net: Change sock_getsockopt() to take the sk ptr instead of the sock ptr Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 45/73] bpf: net: Change sk_getsockopt() to take the sockptr_t argument Sasha Levin
2024-03-13 16:46 ` Sasha Levin [this message]
2024-03-13 16:46 ` [PATCH 5.10 47/73] lsm: fix default return value of the socket_getpeersec_*() hooks Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 48/73] ext4: make ext4_es_insert_extent() return void Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 49/73] ext4: refactor ext4_da_map_blocks() Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 50/73] ext4: convert to exclusive lock while inserting delalloc extents Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 51/73] Drivers: hv: vmbus: Add vmbus_requestor data structure for VMBus hardening Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 52/73] hv_netvsc: Use vmbus_requestor to generate transaction IDs " Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 53/73] hv_netvsc: Wait for completion on request SWITCH_DATA_PATH Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 54/73] hv_netvsc: Process NETDEV_GOING_DOWN on VF hot remove Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 55/73] hv_netvsc: Make netvsc/VF binding check both MAC and serial number Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 56/73] hv_netvsc: use netif_is_bond_master() instead of open code Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 57/73] hv_netvsc: Register VF in netvsc_probe if NET_DEVICE_REGISTER missed Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 58/73] mm/hugetlb: change hugetlb_reserve_pages() to type bool Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 59/73] mm: hugetlb pages should not be reserved by shmat() if SHM_NORESERVE Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 60/73] getrusage: add the "signal_struct *sig" local variable Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 61/73] getrusage: move thread_group_cputime_adjusted() outside of lock_task_sighand() Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 62/73] getrusage: use __for_each_thread() Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 63/73] getrusage: use sig->stats_lock rather than lock_task_sighand() Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 64/73] exit: Fix typo in comment: s/sub-theads/sub-threads Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 65/73] exit: wait_task_zombie: kill the no longer necessary spin_lock_irq(siglock) Sasha Levin
2024-03-13 17:03 ` Oleg Nesterov
2024-03-13 20:10 ` Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 66/73] serial: max310x: Unprepare and disable clock in error path Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 67/73] Drivers: hv: vmbus: Drop error message when 'No request id available' Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 68/73] regmap: allow to define reg_update_bits for no bus configuration Sasha Levin
2024-03-13 16:52 ` Mark Brown
2024-03-13 16:46 ` [PATCH 5.10 69/73] regmap: Add bulk read/write callbacks into regmap_config Sasha Levin
2024-03-13 16:53 ` Mark Brown
2024-03-13 16:46 ` [PATCH 5.10 70/73] serial: max310x: make accessing revision id interface-agnostic Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 71/73] serial: max310x: implement I2C support Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 72/73] serial: max310x: fix IO data corruption in batched operations Sasha Levin
2024-03-13 16:46 ` [PATCH 5.10 73/73] Linux 5.10.213-rc1 Sasha Levin
2024-03-13 20:05 ` [PATCH 5.10 00/73] 5.10.213-rc1 review Pavel Machek
2024-03-14 7:03 ` Dominique Martinet
2024-03-14 15:07 ` Daniel Díaz
2024-03-15 16:52 ` Sasha Levin
2024-03-14 14:50 ` Naresh Kamboju
2024-03-14 19:52 ` Florian Fainelli
2024-03-14 21:47 ` Salvatore Bonaccorso
2024-03-15 18:39 ` Sasha Levin
2024-03-26 6:59 ` Salvatore Bonaccorso
2024-03-27 13:45 ` Greg Kroah-Hartman
2024-03-15 10:48 ` Shreeya Patel
2024-03-20 13:41 ` Pavel Machek
2024-03-20 20:03 ` Marek Vasut
2024-03-22 9:48 ` Pavel Machek
2024-03-22 11:23 ` Marek Vasut
2024-03-22 13:35 ` Pavel Machek
2024-03-20 13:44 ` btrfs fix missing in 5.10-stable was " Pavel Machek
2024-03-20 22:12 ` Sasha Levin
2024-03-25 6:55 ` Daniel Díaz
2024-03-25 15:20 ` Daniel Díaz
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240313164640.616049-47-sashal@kernel.org \
--to=sashal@kernel.org \
--cc=casey@schaufler-ca.com \
--cc=john.johansen@canonical.com \
--cc=linux-kernel@vger.kernel.org \
--cc=paul@paul-moore.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome