Commit Graph

2063 Commits (cc9fa74e2a195f7bab27fbbc4896d2fe3ec32150)

Author SHA1 Message Date
Serge Hallyn f54fb863c6 capabilities: allow nice if we are privileged 12 years ago
Eric W. Biederman 160da84dbb userns: Allow PR_CAPBSET_DROP in a user namespace. 12 years ago
Steven Rostedt 5265fc6219 module/lsm: Have apparmor module parameters work with no args 12 years ago
John Johansen f8eb8a1324 apparmor: add the ability to report a sha1 hash of loaded policy 12 years ago
John Johansen 84f1f78742 apparmor: export set of capabilities supported by the apparmor module 12 years ago
John Johansen 29b3822f1e apparmor: add the profile introspection file to interface 12 years ago
John Johansen 556d0be74b apparmor: add an optional profile attachment string for profiles 12 years ago
John Johansen 0d259f043f apparmor: add interface files for profiles and namespaces 12 years ago
John Johansen 038165070a apparmor: allow setting any profile into the unconfined state 12 years ago
John Johansen 8651e1d657 apparmor: make free_profile available outside of policy.c 12 years ago
John Johansen 742058b0f3 apparmor: rework namespace free path 12 years ago
John Johansen fa2ac468db apparmor: update how unconfined is handled 12 years ago
John Johansen 77b071b340 apparmor: change how profile replacement update is done 12 years ago
John Johansen 01e2b670aa apparmor: convert profile lists to RCU based locking 12 years ago
John Johansen dd51c84857 apparmor: provide base for multiple profiles to be replaced at once 12 years ago
John Johansen 9d910a3bc0 apparmor: add a features/policy dir to interface 12 years ago
John Johansen c611616cd3 apparmor: enable users to query whether apparmor is enabled 12 years ago
Tetsuo Handa dfe4ac28be apparmor: remove minimum size check for vmalloc() 12 years ago
Rafal Krypa 10289b0f73 Smack: parse multiple rules per write to load2, up to PAGE_SIZE-1 bytes 12 years ago
Tejun Heo bd8815a6d8 cgroup: make css_for_each_descendant() and friends include the origin css in the iteration 12 years ago
Tejun Heo 492eb21b98 cgroup: make hierarchy iterators deal with cgroup_subsys_state instead of cgroup 12 years ago
Tejun Heo 182446d087 cgroup: pass around cgroup_subsys_state instead of cgroup in file methods 12 years ago
Tejun Heo eb95419b02 cgroup: pass around cgroup_subsys_state instead of cgroup in subsystem methods 12 years ago
Tejun Heo 6387698699 cgroup: add css_parent() 12 years ago
Tejun Heo a7c6d554aa cgroup: add/update accessors which obtain subsys specific data from css 12 years ago
Tejun Heo 8af01f56a0 cgroup: s/cgroup_subsys_state/cgroup_css/ s/task_subsys_state/task_css/ 12 years ago
Casey Schaufler 6ea062475a Smack: IPv6 casting error fix for 3.11 12 years ago
Casey Schaufler 677264e8fb Smack: network label match fix 12 years ago
Tomasz Stanislawski 4d7cf4a1f4 security: smack: add a hash table to quicken smk_find_entry() 12 years ago
Tomasz Stanislawski 470043ba99 security: smack: fix memleak in smk_write_rules_list() 12 years ago
fan.du ca4c3fc24e net: split rt_genid for ipv4 and ipv6 12 years ago
Tetsuo Handa 9548906b2b xattr: Constify ->name member of "struct xattr". 12 years ago
David Howells 13f8e9810b SELinux: Institute file_path_has_perm() 12 years ago
David Howells c77cecee52 Replace a bunch of file->dentry->d_inode refs with file_inode() 12 years ago
Mimi Zohar 9b97b6cdd4 evm: audit integrity metadata failures 12 years ago
Mimi Zohar d726d8d719 integrity: move integrity_audit_msg() 12 years ago
David Quigley c9bccef6b9 NFS: Extend NFS xattr handlers to accept the security namespace 12 years ago
David Quigley aa9c266962 NFS: Client implementation of Labeled-NFS 12 years ago
David Quigley eb9ae68650 SELinux: Add new labeling type native labels 12 years ago
David Quigley 649f6e7718 LSM: Add flags field to security_sb_set_mnt_opts for in kernel mount data. 12 years ago
David Quigley 746df9b59c Security: Add Hook to test if the particular xattr is part of a MAC model. 12 years ago
David Quigley d47be3dfec Security: Add hook to calculate context based on a negative dentry. 12 years ago
Passion,Zhao 0fcfee61d6 Smack: Fix the bug smackcipso can't set CIPSO correctly 12 years ago
Paul Moore e4e8536f65 selinux: fix the labeled xfrm/IPsec reference count handling 12 years ago
Jiri Pirko 351638e7de net: pass info struct via netdevice notifier 12 years ago
Tetsuo Handa 8cd77a0bd4 Smack: Fix possible NULL pointer dereference at smk_netlbl_mls() 12 years ago
Casey Schaufler e830b39412 Smack: Add smkfstransmute mount option 12 years ago
Casey Schaufler 2f823ff8be Smack: Improve access check performance 12 years ago
Casey Schaufler c673944347 Smack: Local IPv6 port based controls 12 years ago
Tejun Heo d591fb5661 device_cgroup: simplify cgroup tree walk in propagate_exception() 12 years ago