- adef6d2 Smack: prevent underflow in smk_set_cipso() by Dan Carpenter · 4 years, 4 months ago
- 820defe Smack: fix another vsscanf out of bounds by Dan Carpenter · 4 years, 4 months ago
- 67b4be3 Smack: fix use-after-free in smk_write_relabel_self() by Eric Biggers · 4 years, 4 months ago
- 8498142 Smack: slab-out-of-bounds in vsscanf by Casey Schaufler · 4 years, 7 months ago
- 87ca9aa LSM: generalize flag passing to security_capable by Micah Morton · 6 years ago
- 1b42503 smack: use GFP_NOFS while holding inode_smack::smk_lock by Eric Biggers · 5 years ago
- ef9744a Smack: Don't ignore other bprm->unsafe flags if LSM_UNSAFE_PTRACE is set by Jann Horn · 5 years ago
- 9a87ab2 security: smack: Fix possible null-pointer dereferences in smack_socket_sock_rcv_skb() by Jia-Ju Bai · 5 years ago
- 54e71cb smack: fix access permissions for keyring by Zoran Markovic · 6 years ago
- 7a47855 Smack: ptrace capability use fixes by Casey Schaufler · 6 years ago
- 04743f8 Merge branch 'next-smack' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security by Linus Torvalds · 6 years ago
- a66b4cd Merge branch 'work.open3' of git://git.kernel.org/pub/scm/linux/kernel/git/viro/vfs by Linus Torvalds · 6 years ago
- d66a8ac Smack: Inform peer that IPv6 traffic has been blocked by Piotr Sawicki · 6 years ago
- a07ef95 Smack: Check UDP-Lite and DCCP protocols during IPv6 handling by Piotr Sawicki · 6 years ago
- 129a998 Smack: Fix handling of IPv4 traffic received by PF_INET6 sockets by Piotr Sawicki · 6 years ago
- 9481769 ->file_open(): lose cred argument by Al Viro · 6 years ago
- 7b4e884 Smack: Mark inode instant in smack_task_to_inode by Casey Schaufler · 6 years ago
- 2531a0c Merge branch 'smack-for-4.18' of https://github.com/cschaufler/next-smack into next-smack by James Morris · 6 years ago
- 0f8983c Smack: Fix memory leak in smack_inode_getsecctx by Casey Schaufler · 6 years ago
- 5859cdf smack: provide socketpair callback by Tom Gundersen · 7 years ago
- 23c8cec ipc/msg: introduce msgctl(MSG_STAT_ANY) by Davidlohr Bueso · 7 years ago
- a280d6d ipc/sem: introduce semctl(SEM_STAT_ANY) by Davidlohr Bueso · 7 years ago
- c21a697 ipc/shm: introduce shmctl(SHM_STAT_ANY) by Davidlohr Bueso · 7 years ago
- f8cf2f1 Merge branch 'next-integrity' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security by Linus Torvalds · 7 years ago
- 706ffc8 Merge branch 'next-smack' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security by Linus Torvalds · 7 years ago
- 3612605 Merge branch 'next-general' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security by Linus Torvalds · 7 years ago
- 0d79cbf ipc/smack: Tidy up from the change in type of the ipc security hooks by Eric W. Biederman · 7 years ago
- d54d27c Merge branch 'smack-for-4.17' of git://github.com/cschaufler/next-smack into next-smack by James Morris · 7 years ago
- 3ec3011 security: Add a cred_getsecid hook by Matthew Garrett · 7 years ago
- d8c6e85 msg/security: Pass kern_ipc_perm not msg_queue into the msg_queue security hooks by Eric W. Biederman · 7 years ago
- 7191adf shm/security: Pass kern_ipc_perm not shmid_kernel into the shm security hooks by Eric W. Biederman · 7 years ago
- aefad95 sem/security: Pass kern_ipc_perm not sem_array into the sem security hooks by Eric W. Biederman · 7 years ago
- 6b4f3d0 usb, signal, security: only pass the cred, not the secid, to kill_pid_info_as_cred and security_task_kill by Stephen Smalley · 7 years ago
- 58c442f Smack: Handle CGROUP2 in the same way that CGROUP by José Bollo · 7 years ago
- d19dfe5 Smack: Privilege check on key operations by Casey Schaufler · 7 years ago
- da49b5d Smack: fix dereferenced before check by Vasyl Gomonovych · 7 years ago
- 55b3a0c Merge branch 'next-general' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security by Linus Torvalds · 7 years ago
- d6d80cb Smack: Base support for overlayfs by Casey Schaufler · 7 years ago
- 57e7ba0 lsm: fix smack_inode_removexattr and xattr_getsecurity memleak by Casey Schaufler · 7 years ago
- 828f425 Merge tag 'secureexec-v4.14-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/kees/linux by Linus Torvalds · 7 years ago
- 35b372b smack: Remove redundant pdeath_signal clearing by Kees Cook · 7 years ago
- ccbb6e1 smack: Refactor to remove bprm_secureexec hook by Kees Cook · 7 years ago
- ddb4a14 exec: Rename bprm->cred_prepared to called_set_creds by Kees Cook · 7 years ago
- 591bb27 netfilter: nf_hook_ops structs can be const by Florian Westphal · 7 years ago
- f28e783 Smack: Use cap_capable in privilege check by Casey Schaufler · 7 years ago
- 51d59af Smack: Safer check for a socket in file_receive by Casey Schaufler · 7 years ago
- e661a58 smack: use pernet operations for hook registration by Florian Westphal · 8 years ago
- 11fbf53 Merge branch 'work.misc' of git://git.kernel.org/pub/scm/linux/kernel/git/viro/vfs by Linus Torvalds · 8 years ago
- cda3712 fs: constify tree_descr arrays passed to simple_fill_super() by Eric Biggers · 8 years ago
- af96f0d Smack: Use GFP_KERNEL for smk_netlbl_mls(). by Tetsuo Handa · 8 years ago
- c3c8dc9 smack: fix double free in smack_parse_opts_str() by Tetsuo Handa · 8 years ago
- ca97d93 security: mark LSM hooks as __ro_after_init by James Morris · 8 years ago
- f1ef09f Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiederm/user-namespace by Linus Torvalds · 8 years ago
- a2a1547 Merge branch 'stable-4.11' of git://git.infradead.org/users/pcmoore/selinux into next by James Morris · 8 years ago
- 710584b Merge branch 'smack-for-4.11' of git://github.com/cschaufler/smack-next into next by James Morris · 8 years ago
- 9227dd2 exec: Remove LSM_UNSAFE_PTRACE_CAP by Eric W. Biederman · 8 years ago
- d69dece LSM: Add /sys/kernel/security/lsm by Casey Schaufler · 8 years ago
- 3a2f5a5 security,selinux,smack: kill security_task_wait hook by Stephen Smalley · 8 years ago
- 83a1e53 Smack: ignore private inode for file functions by Seung-Woo Kim · 8 years ago
- 805b65a Smack: fix d_instantiate logic for sockfs and pipefs by Rafal Krypa · 8 years ago
- c9d238a SMACK: Use smk_tskacc() instead of smk_access() for proper logging by Himanshu Shukla · 8 years ago
- 348dc28 Smack: Traverse the smack_known_list using list_for_each_entry_rcu macro by Vishal Goel · 8 years ago
- 3d4f673 SMACK: Free the i_security blob in inode using RCU by Himanshu Shukla · 8 years ago
- d54a197 SMACK: Delete list_head repeated initialization by Himanshu Shukla · 8 years ago
- 2e962e2 SMACK: Add new lock for adding entry in smack master list by Vishal Goel · 8 years ago
- 0c96d1f Smack: Fix the issue of wrong SMACK label update in socket bind fail case by Vishal Goel · 8 years ago
- 9d44c97 Smack: Fix the issue of permission denied error in ipv6 hook by Vishal Goel · 8 years ago
- 3c7ce34 SMACK: Add the rcu synchronization mechanism in ipv6 hooks by Vishal Goel · 8 years ago
- b21507e proc,security: move restriction on writing /proc/pid/attr nodes to proc by Stephen Smalley · 8 years ago
- 9a19a6d Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/viro/vfs by Linus Torvalds · 8 years ago
- 4506309 don't open-code file_inode() by Al Viro · 8 years ago
- 152f91d Smack: Remove unnecessary smack_known_invalid by Casey Schaufler · 8 years ago
- 8c15d66 Smack: Use GFP_KERNEL for smack_parse_opts_str(). by Tetsuo Handa · 8 years ago
- 2e4939f Smack: ipv6 label match fix by Casey Schaufler · 8 years ago
- b437aba SMACK: Fix the memory leak in smack_cred_prepare() hook by Himanshu Shukla · 8 years ago
- 7128ea1 SMACK: Do not apply star label in smack_setprocattr hook by Himanshu Shukla · 8 years ago
- 2097f59 smack: parse mnt opts after privileges check by Himanshu Shukla · 8 years ago
- 08382c9 Smack: Assign smack_known_web label for kernel thread's by jooseong lee · 8 years ago
- 97d2116 Merge branch 'work.xattr' of git://git.kernel.org/pub/scm/linux/kernel/git/viro/vfs by Linus Torvalds · 8 years ago
- 5d6c319 xattr: Add __vfs_{get,set,remove}xattr helpers by Andreas Gruenbacher · 8 years ago
- de2f4b3 Merge branch 'stable-4.9' of git://git.infradead.org/users/pcmoore/selinux into next by James Morris · 8 years ago
- c60b906 Smack: Signal delivery as an append operation by Casey Schaufler · 8 years ago
- 63e24c4 Smack: Use memdup_user() rather than duplicating its implementation by Markus Elfring · 8 years ago
- 1a93a6e security: Use IS_ENABLED() instead of checking for built-in or module by Javier Martinez Canillas · 8 years ago
- 7a1e8b8 Merge branch 'next' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security by Linus Torvalds · 8 years ago
- a867d73 Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiederm/user-namespace by Linus Torvalds · 8 years ago
- c632809 Merge branch 'smack-for-4.8' of https://github.com/cschaufler/smack-next into next by James Morris · 8 years ago
- d011a4d Merge branch 'stable-4.8' of git://git.infradead.org/users/pcmoore/selinux into next by James Morris · 8 years ago
- a04e71f netlabel: Pass a family parameter to netlbl_skbuff_err(). by Huw Davies · 8 years ago
- 809c02e Smack: Handle labels consistently in untrusted mounts by Seth Forshee · 9 years ago
- 9f50eda Smack: Add support for unprivileged mounts from user namespaces by Seth Forshee · 9 years ago
- 8387ff2 vfs: make the string hashes salt the hash by Linus Torvalds · 8 years ago
- 18d872f Smack: ignore null signal in smack_task_kill by Rafal Krypa · 9 years ago
- 3767e25 switch ->setxattr() to passing dentry and inode separately by Al Viro · 8 years ago
- ce23e64 ->getxattr(): pass dentry and inode as separate arguments by Al Viro · 9 years ago
- fc64005 don't bother with ->d_inode->i_sb - it's always equal to ->d_sb by Al Viro · 9 years ago
- 8012495 smack: fix cache of access labels by José Bollo · 9 years ago
- 491a0b0 Smack: Remove pointless hooks by Casey Schaufler · 9 years ago
- 3dfb7d8 security: let security modules use PTRACE_MODE_* with bitmasks by Jann Horn · 9 years ago
- 5807fca Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security by Linus Torvalds · 9 years ago