Gitiles
Code Review
Sign In
gerrit-public.fairphone.software
/
kernel
/
msm-4.19
/
c4758fa59285fe4dbfeab4364a6957936d040fbf
/
security
c4758fa
apparmor: put back designators in struct initialisers
by Stephen Rothwell
· 7 years ago
5965453
Merge branch 'stable-4.13' of git://git.infradead.org/users/pcmoore/selinux into next
by James Morris
· 7 years ago
915d9d2
ima: Log the same audit cause whenever a file has no signature
by Thiago Jung Bauermann
· 8 years ago
2663218
ima: Simplify policy_func_show.
by Thiago Jung Bauermann
· 8 years ago
bb543e3
integrity: Small code improvements
by Thiago Jung Bauermann
· 8 years ago
e4586c79
ima: fix get_binary_runtime_size()
by Roberto Sassu
· 8 years ago
28a8dc4
ima: use ima_parse_buf() to parse template data
by Roberto Sassu
· 8 years ago
47fdee6
ima: use ima_parse_buf() to parse measurements headers
by Roberto Sassu
· 8 years ago
b17fd9e
ima: introduce ima_parse_buf()
by Roberto Sassu
· 8 years ago
82e3bb4
ima: Add cgroups2 to the defaults list
by Laura Abbott
· 8 years ago
b4e2803
ima: use memdup_user_nul
by Geliang Tang
· 8 years ago
5d659f2
ima: fix up #endif comments
by Tycho Andersen
· 8 years ago
38d1926
IMA: Correct Kconfig dependencies for hash selection
by Ben Hutchings
· 8 years ago
6f6723e
ima: define is_ima_appraise_enabled()
by Mimi Zohar
· 8 years ago
e1f5e01
ima: define Kconfig IMA_APPRAISE_BOOTPARAM option
by Mimi Zohar
· 8 years ago
503ceae
ima: define a set of appraisal rules requiring file signatures
by Mimi Zohar
· 8 years ago
33ce954
ima: extend the "ima_policy" boot command line to support multiple policies
by Mimi Zohar
· 8 years ago
cdac74d
Merge branch 'smack-for-4.13' of git://github.com/cschaufler/smack-next into next
by James Morris
· 7 years ago
6a39118
selinux: enable genfscon labeling for tracefs
by Jeff Vander Stoep
· 7 years ago
33f2ead
apparmor: export that basic profile namespaces are supported
by John Johansen
· 8 years ago
6c5fc8f
apparmor: add stacked domain labels interface
by John Johansen
· 8 years ago
40cde7f
apparmor: add domain label stacking info to apparmorfs
by John Johansen
· 8 years ago
e00b02bb
apparmor: move change_profile mediation to using labels
by John Johansen
· 8 years ago
89dbf19
apparmor: move change_hat mediation to using labels
by John Johansen
· 8 years ago
93c98a4
apparmor: move exec domain mediation to using labels
by John Johansen
· 8 years ago
5379a33
apparmor: support v7 transition format compatible with label_parse
by John Johansen
· 8 years ago
064dc94
apparmor: mediate files when they are received
by John Johansen
· 8 years ago
496c931
apparmor: rework file permission to cache file access in file->ctx
by John Johansen
· 8 years ago
8014370
apparmor: move path_link mediation to using labels
by John Johansen
· 8 years ago
aebd873
apparmor: refactor path name lookup and permission checks around labels
by John Johansen
· 8 years ago
98c3d18
apparmor: update aa_audit_file() to use labels
by John Johansen
· 8 years ago
190a951
apparmor: move aa_file_perm() to use labels
by John Johansen
· 8 years ago
290f458
apparmor: allow ptrace checks to be finer grained than just capability
by John Johansen
· 8 years ago
b2d09ae
apparmor: move ptrace checks to using labels
by John Johansen
· 8 years ago
ca916e8
apparmor: add cross check permission helper macros
by John Johansen
· 8 years ago
86b92cb
apparmor: move resource checks to using labels
by John Johansen
· 8 years ago
c70c86c
apparmor: move capability checks to using labels
by John Johansen
· 8 years ago
317d9a0
apparmor: update query interface to support label queries
by John Johansen
· 8 years ago
76a1d26
apparmor: switch getprocattr to using label_print fns()
by John Johansen
· 8 years ago
637f688
apparmor: switch from profiles to using labels on contexts
by John Johansen
· 8 years ago
f1bd904
apparmor: add the base fns() for domain labels
by John Johansen
· 8 years ago
192ca6b
apparmor: revalidate files during exec
by John Johansen
· 8 years ago
2835a13
apparmor: cleanup rename XXX_file_context() to XXX_file_ctx()
by John Johansen
· 8 years ago
df8073c
apparmor: convert aa_change_XXX bool parameters to flags
by John Johansen
· 8 years ago
dca9140
apparmor: cleanup remove unused and not fully implemented profile rename
by John Johansen
· 8 years ago
435222b
apparmor: refactor updating profiles to the newest parent
by John Johansen
· 8 years ago
a1bd627
apparmor: share profile name on replacement
by John Johansen
· 8 years ago
cf797c0
apparmor: convert to profile block critical sections
by John Johansen
· 8 years ago
fe86482
apparmor: move bprm_committing_creds/committed_creds to lsm.c
by John Johansen
· 8 years ago
d9f02d9
apparmor: fix display of ns name
by John Johansen
· 8 years ago
5262ef6
apparmor: fix apparmor_query data
by John Johansen
· 8 years ago
60285eb
apparmor: fix policy load/remove semantics
by John Johansen
· 8 years ago
3664268
apparmor: add namespace lookup fns()
by John Johansen
· 8 years ago
ae3b316
apparmor: cleanup __find_child()
by John Johansen
· 8 years ago
39d8482
apparmor: provide information about path buffer size at boot
by John Johansen
· 8 years ago
4f3b3f2
apparmor: add profile permission query ability
by John Johansen
· 8 years ago
2d679f3
apparmor: switch from file_perms to aa_perms
by John Johansen
· 8 years ago
aa9aeea
apparmor: add gerneric permissions struct and support fns
by John Johansen
· 8 years ago
b5b2557
apparmor: add fn to test if profile supports a given mediation class
by John Johansen
· 8 years ago
1dea3b4
apparmor: speed up transactional queries
by John Johansen
· 8 years ago
a83bd86
apparmor: add label data availability to the feature set
by John Johansen
· 8 years ago
4ae47f3
apparmor: add mkdir/rmdir interface to manage policy namespaces
by John Johansen
· 8 years ago
d9bf2c2
apparmor: add policy revision file interface
by John Johansen
· 8 years ago
18e99f1
apparmor: provide finer control over policy management
by John Johansen
· 8 years ago
0b4d345
security/selinux: allow security_sb_clone_mnt_opts to enable/disable native labeling behavior
by Scott Mayhew
· 8 years ago
b4958c8
selinux: use kmem_cache for ebitmap
by Junil Lee
· 8 years ago
e53cfe6
apparmor: rework perm mapping to a slightly broader set
by John Johansen
· 8 years ago
fc7e0b2
apparmor: move permissions into their own file to be more easily shared
by John Johansen
· 8 years ago
c961ee5
apparmor: convert from securityfs to apparmorfs for policy ns files
by John Johansen
· 8 years ago
98407f0
apparmor: allow specifying an already created dir to create ns entries in
by John Johansen
· 8 years ago
c97204b
apparmor: rename apparmor file fns and data to indicate use
by John Johansen
· 8 years ago
a481f4d
apparmor: add custom apparmorfs that will be used by policy namespace files
by John Johansen
· 8 years ago
64c8697
apparmor: use macro template to simplify namespace seq_files
by John Johansen
· 8 years ago
52b97de
apparmor: use macro template to simplify profile seq_files
by John Johansen
· 8 years ago
5d5182ca
apparmor: move to per loaddata files, instead of replicating in profiles
by John Johansen
· 8 years ago
6623ec7
securityfs: add the ability to support symlinks
by John Johansen
· 8 years ago
4227c33
apparmor: Move path lookup to using preallocated buffers
by John Johansen
· 8 years ago
72c8a76
apparmor: allow profiles to provide info to disconnected paths
by John Johansen
· 8 years ago
b91deb9
apparmor: make internal lib fn skipn_spaces available to the rest of apparmor
by John Johansen
· 8 years ago
af7caa8
apparmor: move file context into file.h
by John Johansen
· 8 years ago
651e549
security/apparmor: Use POSIX-compatible "printf '%s'"
by Thomas Schneider
· 8 years ago
ffac1de
apparmor: Fix error cod in __aa_fs_profile_mkdir()
by Dan Carpenter
· 8 years ago
47dbd1c
apparmorfs: Use seq_putc() in two functions
by Markus Elfring
· 8 years ago
0ff3d97
apparmorfs: Combine two function calls into one in aa_fs_seq_raw_abi_show()
by Markus Elfring
· 8 years ago
8e71bf7
selinux: use pernet operations for hook registration
by Florian Westphal
· 8 years ago
f28e783
Smack: Use cap_capable in privilege check
by Casey Schaufler
· 8 years ago
51d59af
Smack: Safer check for a socket in file_receive
by Casey Schaufler
· 8 years ago
e661a58
smack: use pernet operations for hook registration
by Florian Westphal
· 8 years ago
409dcf3
selinux: Add a cache for quicker retreival of PKey SIDs
by Daniel Jurgens
· 8 years ago
ab861df
selinux: Add IB Port SMP access vector
by Daniel Jurgens
· 8 years ago
cfc4d88
selinux: Implement Infiniband PKey "Access" access vector
by Daniel Jurgens
· 8 years ago
3a976fa
selinux: Allocate and free infiniband security hooks
by Daniel Jurgens
· 8 years ago
a806f7a
selinux: Create policydb version for Infiniband support
by Daniel Jurgens
· 8 years ago
47a2b33
IB/core: Enforce security on management datagrams
by Daniel Jurgens
· 8 years ago
8f408ab
selinux lsm IB/core: Implement LSM notification system
by Daniel Jurgens
· 8 years ago
d291f1a
IB/core: Enforce PKey security on QPs
by Daniel Jurgens
· 8 years ago
270e857
selinux: Remove redundant check for unknown labeling behavior
by Matthias Kaehlcke
· 8 years ago
4dc2fce
selinux: log policy capability state when a policy is loaded
by Stephen Smalley
· 8 years ago
ccb5447
selinux: do not check open permission on sockets
by Stephen Smalley
· 8 years ago
3ba4bf5
selinux: add a map permission check for mmap
by Stephen Smalley
· 8 years ago
Next »