Commit Graph

2532 Commits (ec654e50c67ad4ba89c9f9f81ccf6f061695e36d)

Author SHA1 Message Date
Paul Moore f64410ec66 selinux: correctly label /proc inodes in use before the policy is loaded 11 years ago
Paul Moore 98883bfd9d selinux: put the mmap() DAC controls before the MAC controls 11 years ago
Tejun Heo 4d3bb511b5 cgroup: drop const from @buffer of cftype->write_string() 11 years ago
Dmitry Kasatkin fffea214ab smack: fix key permission verification 11 years ago
David Howells f5895943d9 KEYS: Move the flags representing required permission to linux/key.h 11 years ago
Nikolay Aleksandrov 52a4c6404f selinux: add gfp argument to security_xfrm_policy_alloc and fix callers 11 years ago
David Howells 979e0d7465 KEYS: Make the keyring cycle detector ignore other keyrings of the same name 11 years ago
Dmitry Kasatkin a3aef94b31 evm: enable key retention service automatically 11 years ago
Dmitry Kasatkin 1d91ac6213 ima: skip memory allocation for empty files 11 years ago
Dmitry Kasatkin e0420039b6 evm: EVM does not use MD5 11 years ago
Dmitry Kasatkin 61997c4383 ima: return d_name.name if d_path fails 11 years ago
Dmitry Kasatkin 2bb930abcf integrity: fix checkpatch errors 11 years ago
Dmitry Kasatkin 09b1148ef5 ima: fix erroneous removal of security.ima xattr 11 years ago
Joe Perches 20ee451f5a security: integrity: Use a more current logging style 11 years ago
Roberto Sassu e3b64c268b ima: reduce memory usage when a template containing the n field is used 11 years ago
Roberto Sassu c019e307ad ima: restore the original behavior for sending data with ima template 11 years ago
Tetsuo Handa 73a6b44a00 Integrity: Pass commname via get_task_comm() 11 years ago
Mimi Zohar 52a1328484 ima: use static const char array definitions 11 years ago
Jeff Layton d4a141c8e7 security: have cap_dentry_init_security return error 11 years ago
Heiko Carstens 875ec3da4c security/compat: convert to COMPAT_SYSCALL_DEFINE 11 years ago
Paul Moore eee3094683 selinux: correctly label /proc inodes in use before the policy is loaded 11 years ago
Libo Chen 31d4b76189 ima: new helper: file_inode(file) 11 years ago
Paul Moore 0909c0ae99 selinux: put the mmap() DAC controls before the MAC controls 11 years ago
Eric Paris 9085a64229 SELinux: bigendian problems with filename trans rules 11 years ago
Sam Ravnborg e0c2de2b15 security: cleanup Makefiles to use standard syntax for specifying sub-directories 11 years ago
Fan Du ca925cf153 flowcache: Make flow cache name space aware 11 years ago
Tejun Heo 073219e995 cgroup: clean up cgroup_subsys names and initialization 11 years ago
Jingoo Han 29707b206c security: replace strict_strto*() with kstrto*() 11 years ago
Stephen Smalley 2172fa709a SELinux: Fix kernel BUG on empty security contexts. 11 years ago
Paul Moore 6a96e15096 selinux: add SOCK_DIAG_BY_FAMILY to the list of netlink message types 11 years ago
Colin Cross 530b099dfe security: select correct default LSM_MMAP_MIN_ADDR on arm on arm64 11 years ago
Richard Guy Briggs 4eb0f4abfb smack: call WARN_ONCE() instead of calling audit_log_start() 11 years ago
Richard Guy Briggs 9ad42a7924 selinux: call WARN_ONCE() instead of calling audit_log_start() 11 years ago
Steven Rostedt 3dc91d4338 SELinux: Fix possible NULL pointer dereference in selinux_inode_permission() 11 years ago
Tetsuo Handa 8ed8146028 SELinux: Fix memory leak upon loading policy 11 years ago
Roberto Sassu dcf4e39286 ima: remove unneeded size_limit argument from ima_eventdigest_init_common() 11 years ago
Roberto Sassu 712a49bd7d ima: pass HASH_ALGO__LAST as hash algo in ima_eventdigest_init() 11 years ago
Roberto Sassu c502c78ba7 ima: change the default hash algorithm to SHA1 in ima_eventdigest_ng_init() 11 years ago
Casey Schaufler 4482a44f6a Smack: File receive audit correction 11 years ago
Casey Schaufler 24ea1b6efc Smack: Rationalize mount restrictions 11 years ago
Casey Schaufler 4afde48be8 Smack: change rule cap check 11 years ago
Casey Schaufler 00f84f3f2e Smack: Make the syslog control configurable 11 years ago
Oleg Nesterov c0c1439541 selinux: selinux_setprocattr()->ptrace_parent() needs rcu_read_lock() 11 years ago
Chad Hanson 46d01d6322 selinux: fix broken peer recv check 11 years ago
Casey Schaufler 19760ad03c Smack: Prevent the * and @ labels from being used in SMACK64EXEC 11 years ago
Oleg Nesterov 465954cd64 selinux: selinux_setprocattr()->ptrace_parent() needs rcu_read_lock() 11 years ago
Wei Yongjun a5e333d340 SELinux: remove duplicated include from hooks.c 11 years ago
Linus Torvalds 29b1deb2a4 Revert "selinux: consider filesystem subtype in policies" 11 years ago
Paul Moore 4d546f8171 selinux: revert 102aefdda4 11 years ago
Paul Moore c0828e5048 selinux: process labeled IPsec TCP SYN-ACK packets properly in selinux_ip_postroute() 11 years ago