Commit Graph

107 Commits (3b259e365998291a02488225e32b9f2b73723b3e)

Author SHA1 Message Date
Paul Moore 6c5b3fc014 selinux: Cache NetLabel secattrs in the socket's security struct 17 years ago
Paul Moore 014ab19a69 selinux: Set socket NetLabel based on connection endpoint 17 years ago
Paul Moore 948bf85c1b netlabel: Add functionality to set the security attributes of a packet 17 years ago
Paul Moore dfaebe9825 selinux: Fix missing calls to netlbl_skbuff_err() 17 years ago
KaiGai Kohei d9250dea3f SELinux: add boundary support and thread context assignment 17 years ago
James Morris 089be43e40 Revert "SELinux: allow fstype unknown to policy to use xattrs if present" 17 years ago
Eric Paris 811f379927 SELinux: allow fstype unknown to policy to use xattrs if present 17 years ago
James Morris feb2a5b82d SELinux: remove inherit field from inode_security_struct 17 years ago
Richard Kennedy fdeb05184b SELinux: reorder inode_security_struct to increase objs/slab on 64bit 17 years ago
Eric Paris f526971078 SELinux: keep the code clean formating and syntax 17 years ago
Stephen Smalley 12b29f3455 selinux: support deferred mapping of contexts 17 years ago
David Howells e52c1764f1 Security: Make secctx_to_secid() take const secdata 17 years ago
David Howells 7bf570dc8d Security: Make secctx_to_secid() take const secdata 17 years ago
David Howells 8f0cfa52a1 xattr: add missing consts to function arguments 17 years ago
Eric Paris b19d8eae99 SELinux: selinux/include/security.h whitespace, syntax, and other cleanups 17 years ago
Eric Paris a936b79bdf SELinux: objsec.h whitespace, syntax, and other cleanups 17 years ago
Eric Paris cc03766aaf SELinux: netlabel.h whitespace, syntax, and other cleanups 17 years ago
Eric Paris e392febedb SELinux: avc_ss.h whitespace, syntax, and other cleanups 17 years ago
Ahmed S. Darwish 04305e4aff Audit: Final renamings and cleanup 17 years ago
James Morris 27cc2a6e57 SELinux: add netport.[ch] 17 years ago
Paul Moore 3e11217263 SELinux: Add network port SID cache 17 years ago
Eric Paris 832cbd9aa1 SELinux: turn mount options strings into defines 17 years ago
Eric Paris 64dbf07474 selinux: introduce permissive types 17 years ago
Roland McGrath 0356357c51 selinux: remove ptrace_sid 17 years ago
Eric Paris b0c636b999 SELinux: create new open permission 17 years ago
James Morris 98e9894650 SELinux: remove unused backpointers from security objects 17 years ago
Paul Moore f74af6e816 SELinux: Correct the NetLabel locking for the sk_security_struct 17 years ago
Paul Moore 03e1ad7b5d LSM: Make the Labeled IPsec hooks more stack friendly 17 years ago
Stephen Smalley 869ab5147e SELinux: more GFP_NOFS fixups to prevent selinux from re-entering the fs code 17 years ago
Eric Paris e000752989 LSM/SELinux: Interfaces to allow FS to control mount options 17 years ago
Jan Blunck 44707fdf59 d_path: Use struct path in struct avc_audit_data 17 years ago
Stephen Smalley b68e418c44 selinux: support 64-bit capabilities 17 years ago
Paul Moore 394c675397 SELinux: Remove security_get_policycaps() 17 years ago
Paul Moore 5dbe1eb0cf SELinux: Allow NetLabel to directly cache SIDs 17 years ago
Paul Moore d621d35e57 SELinux: Enable dynamic enable/disable of the network access checks 17 years ago
Paul Moore 220deb966e SELinux: Better integration between peer labeling subsystems 17 years ago
Paul Moore f67f4f315f SELinux: Add a new peer class and permissions to the Flask definitions 17 years ago
Paul Moore 3bb56b25db SELinux: Add a capabilities bitmap to SELinux policy version 22 17 years ago
Paul Moore 224dfbd81e SELinux: Add a network node caching mechanism similar to the sel_netif_*() functions 17 years ago
Paul Moore da5645a28a SELinux: Only store the network interface's ifindex 17 years ago
Paul Moore e8bfdb9d0d SELinux: Convert the netif code to use ifindex values 17 years ago
Paul Moore 75e22910cf NetLabel: Add IP address family information to the netlbl_skbuff_getattr() function 17 years ago
Eric Paris c9180a57a9 Security: add get, set, and cloning of superblock security information 17 years ago
Eric Paris 3f12070e27 SELinux: policy selectable handling of unknown classes and perms 18 years ago
Yuichi Nakamura 788e7dd4c2 SELinux: Improve read/write performance 18 years ago
Eric Paris ed03218951 security: Protection for exploiting null dereference using mmap 18 years ago
Stephen Smalley 2c3c05dbcb SELinux: allow preemption between transition permission checks 18 years ago
Christopher J. PeBenito e47c8fc582 selinux: add selinuxfs structure for object class discovery 18 years ago
Christopher J. PeBenito 55fcf09b3f selinux: add support for querying object classes and permissions from the running policy 18 years ago
James Carter f0ee2e467f selinux: export initial SID contexts via selinuxfs 18 years ago