Commit Graph

372 Commits (45b583b10a8b438b970e95a7d1d4db22c9e35004)

Author SHA1 Message Date
James Morris af294e41d0 selinux: remove secondary ops call to task_create 16 years ago
James Morris d541bbee69 selinux: remove secondary ops call to file_mprotect 16 years ago
James Morris 438add6b32 selinux: remove secondary ops call to inode_setattr 16 years ago
James Morris 188fbcca9d selinux: remove secondary ops call to inode_permission 16 years ago
James Morris f51115b9ab selinux: remove secondary ops call to inode_follow_link 16 years ago
James Morris dd4907a6d4 selinux: remove secondary ops call to inode_mknod 16 years ago
James Morris e4737250b7 selinux: remove secondary ops call to inode_unlink 16 years ago
James Morris efdfac4376 selinux: remove secondary ops call to inode_link 16 years ago
James Morris 97422ab9ef selinux: remove secondary ops call to sb_umount 16 years ago
James Morris ef935b9136 selinux: remove secondary ops call to sb_mount 16 years ago
James Morris 5565b0b865 selinux: remove secondary ops call to bprm_committed_creds 16 years ago
James Morris 2ec5dbe23d selinux: remove secondary ops call to bprm_committing_creds 16 years ago
James Morris bc05595845 selinux: remove unused bprm_check_security hook 16 years ago
David P. Quigley cd89596f0c SELinux: Unify context mount and genfs behavior 16 years ago
David P. Quigley 11689d47f0 SELinux: Add new security mount option to indicate security label support. 16 years ago
David P. Quigley 0d90a7ec48 SELinux: Condense super block security structure flags and cleanup necessary code. 16 years ago
David Howells 3699c53c48 CRED: Fix regression in cap_capable() as shown up by sys_faccessat() [ver #3] 16 years ago
James Morris 29881c4502 Revert "CRED: Fix regression in cap_capable() as shown up by sys_faccessat() [ver #2]" 16 years ago
David Howells 14eaddc967 CRED: Fix regression in cap_capable() as shown up by sys_faccessat() [ver #2] 16 years ago
Paul Moore 277d342fc4 selinux: Deprecate and schedule the removal of the the compat_net functionality 16 years ago
James Morris 7419224691 SELinux: don't check permissions for kernel mounts 16 years ago
James Morris 12204e24b1 security: pass mount flags to security_sb_kern_mount() 16 years ago
Stephen Smalley 459c19f524 SELinux: correctly detect proc filesystems of the form "proc/foo" 16 years ago
David Howells 3a3b7ce933 CRED: Allow kernel services to override LSM settings for task actions 16 years ago
David Howells 3b11a1dece CRED: Differentiate objective and effective subjective credentials on a task 16 years ago
David Howells a6f76f23d2 CRED: Make execve() take advantage of copy-on-write credentials 16 years ago
David Howells d84f4f992c CRED: Inaugurate COW credentials 16 years ago
David Howells 745ca2475a CRED: Pass credentials through dentry_open() 16 years ago
David Howells 88e67f3b88 CRED: Make inode_has_perm() and file_has_perm() take a cred pointer 16 years ago
David Howells 275bb41e9d CRED: Wrap access to SELinux's task SID 16 years ago
David Howells f1752eec61 CRED: Detach the credentials from task_struct 16 years ago
David Howells b6dff3ec5e CRED: Separate task security context from task_struct 16 years ago
David Howells 15a2460ed0 CRED: Constify the kernel_cap_t arguments to the capset LSM hooks 16 years ago
David Howells 1cdcbec1a3 CRED: Neuter sys_capset() 16 years ago
Eric Paris 066746796b Currently SELinux jumps through some ugly hoops to not audit a capbility 16 years ago
Eric Paris 06112163f5 Add a new capable interface that will be used by systems that use audit to 16 years ago
Eric Paris 39c9aede2b SELinux: Use unknown perm handling to handle unknown netlink msg types 16 years ago
Eric Paris 41d9f9c524 SELinux: hold tasklist_lock and siglock while waking wait_chldexit 16 years ago
Eric Paris 37dd0bd04a SELinux: properly handle empty tty_files list 17 years ago
Eric Paris 8b6a5a37f8 SELinux: check open perms in dentry_open not inode_permission 17 years ago
Alexey Dobriyan def8b4faff net: reduce structures when XFRM=n 17 years ago
Steven Whitehouse a447c09324 vfs: Use const for kernel parser table 17 years ago
Alan Cox 934e6ebf96 tty: Redo current tty locking 17 years ago
Alan Cox 452a00d2ee tty: Make get_current_tty use a kref 17 years ago
Paul Moore 6c5b3fc014 selinux: Cache NetLabel secattrs in the socket's security struct 17 years ago
Paul Moore 014ab19a69 selinux: Set socket NetLabel based on connection endpoint 17 years ago
Paul Moore 948bf85c1b netlabel: Add functionality to set the security attributes of a packet 17 years ago
Paul Moore dfaebe9825 selinux: Fix missing calls to netlbl_skbuff_err() 17 years ago
Paul Moore d8395c876b selinux: Better local/forward check in selinux_ip_postroute() 17 years ago
Paul Moore aa86290089 selinux: Correctly handle IPv4 packets on IPv6 sockets in all cases 17 years ago