Commit Graph

277 Commits (893e26e61d04eac974ded0c11e1647b335c8cb7b)

Author SHA1 Message Date
Casey Schaufler d69dece5f5 LSM: Add /sys/kernel/security/lsm 8 years ago
John Johansen 3ccb76c5df apparmor: fix undefined reference to `aa_g_hash_policy' 8 years ago
John Johansen e6bfa25deb apparmor: replace remaining BUG_ON() asserts with AA_BUG() 8 years ago
John Johansen 2c17cd3681 apparmor: fix restricted endian type warnings for policy unpack 8 years ago
John Johansen e6e8bf4188 apparmor: fix restricted endian type warnings for dfa unpack 8 years ago
John Johansen ca4bd5ae0a apparmor: add check for apparmor enabled in module parameters missing it 8 years ago
John Johansen d4669f0b03 apparmor: add per cpu work buffers to avoid allocating buffers at every hook 8 years ago
Tyler Hicks e3ea1ca59a apparmor: sysctl to enable unprivileged user ns AppArmor policy loading 8 years ago
William Hua e025be0f26 apparmor: support querying extended trusted helper extra data 8 years ago
John Johansen 12eb87d50b apparmor: update cap audit to check SECURITY_CAP_NOAUDIT 8 years ago
John Johansen 31f75bfecd apparmor: make computing policy hashes conditional on kernel parameter 8 years ago
John Johansen aa9a39ad8f apparmor: convert change_profile to use fqname later to give better control 8 years ago
John Johansen c3e1e584ad apparmor: fix change_hat debug output 8 years ago
John Johansen 5ef50d014c apparmor: remove unused op parameter from simple_write_to_buffer() 8 years ago
John Johansen ef88a7ac55 apparmor: change aad apparmor_audit_data macro to a fn macro 8 years ago
John Johansen 47f6e5cc73 apparmor: change op from int to const char * 8 years ago
John Johansen 55a26ebf63 apparmor: rename context abreviation cxt to the more standard ctx 8 years ago
John Johansen a20aa95fbe apparmor: fail task profile update if current_cred isn't real_cred 8 years ago
John Johansen b7fd2c0340 apparmor: add per policy ns .load, .replace, .remove interface files 8 years ago
John Johansen 12dd7171d6 apparmor: pass the subject profile into profile replace/remove 8 years ago
John Johansen 04dc715e24 apparmor: audit policy ns specified in policy load 8 years ago
John Johansen 5ac8c355ae apparmor: allow introspecting the loaded policy pre internal transform 8 years ago
John Johansen fc1c9fd10a apparmor: add ns name to the audit data for policy loads 8 years ago
John Johansen 078c73c63f apparmor: add profile and ns params to aa_may_manage_policy() 8 years ago
John Johansen fd2a80438d apparmor: add ns being viewed as a param to policy_admin_capable() 8 years ago
John Johansen 2bd8dbbf22 apparmor: add ns being viewed as a param to policy_view_capable() 8 years ago
John Johansen a6f233003b apparmor: allow specifying the profile doing the management 8 years ago
John Johansen 3e3e569539 apparmor: allow introspecting the policy namespace name 8 years ago
John Johansen b79473f2de apparmor: Make aa_remove_profile() callable from a different view 8 years ago
John Johansen ee2351e4b0 apparmor: track ns level so it can be used to help in view checks 8 years ago
John Johansen a71ada3058 apparmor: add special .null file used to "close" fds at exec 8 years ago
John Johansen 34c426acb7 apparmor: provide userspace flag indicating binfmt_elf_mmap change 8 years ago
John Johansen 11c236b89d apparmor: add a default null dfa 8 years ago
John Johansen 6604d4c1c1 apparmor: allow policydb to be used as the file dfa 8 years ago
John Johansen 293a4886f9 apparmor: add get_dfa() fn 8 years ago
John Johansen 474d6b7510 apparmor: prepare to support newer versions of policy 8 years ago
John Johansen 5ebfb12822 apparmor: add support for force complain flag to support learning mode 8 years ago
John Johansen abbf873403 apparmor: remove paranoid load switch 8 years ago
John Johansen 181f7c9776 apparmor: name null-XXX profiles after the executable 8 years ago
John Johansen 30b026a8d1 apparmor: pass gfp_t parameter into profile allocation 8 years ago
John Johansen 73688d1ed0 apparmor: refactor prepare_ns() and make usable from different views 8 years ago
John Johansen 5fd1b95fc9 apparmor: update policy_destroy to use new debug asserts 8 years ago
John Johansen d102d89571 apparmor: pass gfp param into aa_policy_init() 8 years ago
John Johansen bbe4a7c873 apparmor: constify policy name and hname 8 years ago
John Johansen 6e474e3063 apparmor: rename hname_tail to basename 8 years ago
John Johansen efeee83a70 apparmor: rename mediated_filesystem() to path_mediated_fs() 8 years ago
John Johansen 680cd62e91 apparmor: add debug assert AA_BUG and Kconfig to control debug info 8 years ago
John Johansen 57e36bbd67 apparmor: add macro for bug asserts to check that a lock is held 8 years ago
John Johansen 92b6d8eff5 apparmor: allow ns visibility question to consider subnses 8 years ago
John Johansen 31617ddfdd apparmor: add fn to lookup profiles by fqname 8 years ago