Commit Graph

71 Commits (011e3fcd1e1f14ef54db30b93404ab7caa726477)

Author SHA1 Message Date
Paul Moore 5dbe1eb0cf SELinux: Allow NetLabel to directly cache SIDs 17 years ago
Paul Moore d621d35e57 SELinux: Enable dynamic enable/disable of the network access checks 17 years ago
Paul Moore 220deb966e SELinux: Better integration between peer labeling subsystems 17 years ago
Paul Moore f67f4f315f SELinux: Add a new peer class and permissions to the Flask definitions 17 years ago
Paul Moore 3bb56b25db SELinux: Add a capabilities bitmap to SELinux policy version 22 17 years ago
Paul Moore 224dfbd81e SELinux: Add a network node caching mechanism similar to the sel_netif_*() functions 17 years ago
Paul Moore da5645a28a SELinux: Only store the network interface's ifindex 17 years ago
Paul Moore e8bfdb9d0d SELinux: Convert the netif code to use ifindex values 17 years ago
Paul Moore 75e22910cf NetLabel: Add IP address family information to the netlbl_skbuff_getattr() function 17 years ago
Eric Paris c9180a57a9 Security: add get, set, and cloning of superblock security information 17 years ago
Eric Paris 3f12070e27 SELinux: policy selectable handling of unknown classes and perms 18 years ago
Yuichi Nakamura 788e7dd4c2 SELinux: Improve read/write performance 18 years ago
Eric Paris ed03218951 security: Protection for exploiting null dereference using mmap 18 years ago
Stephen Smalley 2c3c05dbcb SELinux: allow preemption between transition permission checks 18 years ago
Christopher J. PeBenito e47c8fc582 selinux: add selinuxfs structure for object class discovery 18 years ago
Christopher J. PeBenito 55fcf09b3f selinux: add support for querying object classes and permissions from the running policy 18 years ago
James Carter f0ee2e467f selinux: export initial SID contexts via selinuxfs 18 years ago
Stephen Smalley a764ae4b07 selinux: remove userland security class and permission definitions 18 years ago
Paul Moore 4f6a993f96 SELinux: move security_skb_extlbl_sid() out of the security server 18 years ago
Paul Moore c60475bf35 SELinux: rename selinux_netlabel.h to netlabel.h 18 years ago
Paul Moore 5778eabd9c SELinux: extract the NetLabel SELinux support from the security server 18 years ago
Venkat Yekkirala 342a0cff0a [SELINUX]: Fix 2.6.20-rc6 build when no xfrm 18 years ago
Al Viro 87fcd70d98 [PATCH] selinux endianness annotations 18 years ago
James Morris bb22f58087 Compile fix for "peer secid consolidation for external network labeling" 18 years ago
Paul Moore 3de4bab5b9 SELinux: peer secid consolidation for external network labeling 18 years ago
Paul Moore 9f2ad66509 NetLabel: SELinux cleanups 18 years ago
James Morris 2ee92d46c6 [SELinux]: Add support for DCCP 18 years ago
Venkat Yekkirala 67f83cbf08 SELinux: Fix SA selection semantics 18 years ago
Venkat Yekkirala 6b877699c6 SELinux: Return correct context for SO_PEERSEC 18 years ago
Venkat Yekkirala c1a856c964 SELinux: Various xfrm labeling fixes 18 years ago
Chad Sellers 5c45899879 SELinux: export object class and permission definitions 18 years ago
Paul Moore f8687afefc [NetLabel]: protect the CIPSOv4 socket option from setsockopt() 19 years ago
Venkat Yekkirala 5b368e61c2 IPsec: correct semantics for SELinux policy matching 19 years ago
Eric Paris bc7e982b84 [PATCH] SELinux: convert sbsec semaphore to a mutex 19 years ago
Eric Paris 2397074172 [PATCH] SELinux: change isec semaphore to a mutex 19 years ago
Darrel Goeddel f3f8771420 [PATCH] selinux: add support for range transitions on object classes 19 years ago
Stephen Smalley 016b9bdb81 [PATCH] selinux: enable configuration of max policy version 19 years ago
Paul Moore 7a0e1d6022 [NetLabel]: add some missing #includes to various header files 19 years ago
Paul Moore e448e93130 [NetLabel]: uninline selinux_netlbl_inode_permission() 19 years ago
Paul Moore 99f59ed073 [NetLabel]: Correctly initialize the NetLabel fields. 19 years ago
Venkat Yekkirala 7420ed23a4 [NetLabel]: SELinux support 19 years ago
Venkat Yekkirala a51c64f1e5 [MLSXFRM]: Fix build with SECURITY_NETWORK_XFRM disabled. 19 years ago
Venkat Yekkirala cb969f072b [MLSXFRM]: Default labeling of socket specific IPSec policies 19 years ago
Venkat Yekkirala beb8d13bed [MLSXFRM]: Add flow labeling 19 years ago
Venkat Yekkirala e0d1caa7b0 [MLSXFRM]: Flow based matching of xfrm policy and state 19 years ago
Venkat Yekkirala 892c141e62 [MLSXFRM]: Add security sid to sock 19 years ago
Venkat Yekkirala 08554d6b33 [MLSXFRM]: Define new SELinux service routine 19 years ago
Venkat Yekkirala 51bd39860f [MLSXFRM]: Granular IPSec associations for use in MLS environments 19 years ago
Eric Paris c312feb293 [PATCH] SELinux: decouple fscontext/context mount options 19 years ago
Eric Paris 42c3e03ef6 [PATCH] SELinux: Add sockcreate node to procattr API 19 years ago