summaryrefslogtreecommitdiffstats
path: root/security
AgeCommit message (Expand)AuthorLines
2017-11-08EVM: Include security.apparmor in EVM measurementsMatthew Garrett-0/+3
2017-11-08integrity: use kernel_read_file_from_path() to read x509 certsChristoph Hellwig-56/+13
2017-11-08ima: always measure and audit files in policyMimi Zohar-30/+56
2017-11-08ima: don't remove the securityfs policy fileMimi Zohar-2/+2
2017-11-08apparmor: fix off-by-one comparison on MAXMAPPED_SIGJohn Johansen-2/+2
2017-11-07Merge branch 'linus' into locking/core, to resolve conflictsIngo Molnar-871/+96
2017-11-05device_cgroup: prepare code for bpf-based device controllerRoman Gushchin-45/+2
2017-11-05device_cgroup: add DEVCG_ prefix to ACC_* and DEV_* constantsRoman Gushchin-36/+36
2017-11-04Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/netDavid S. Miller-31/+80
2017-11-03ima: move to generic async completionGilad Ben-Yossef-39/+17
2017-11-02Merge tag 'spdx_identifiers-4.14-rc8' of git://git.kernel.org/pub/scm/linux/k...Linus Torvalds-0/+49
2017-11-02License cleanup: add SPDX GPL-2.0 license identifier to files with no licenseGreg Kroah-Hartman-0/+49
2017-11-02KEYS: trusted: fix writing past end of buffer in trusted_read()Eric Biggers-11/+12
2017-11-02KEYS: return full count in keyring_read() if buffer is too smallEric Biggers-20/+19
2017-11-02Smack: Base support for overlayfsCasey Schaufler-0/+79
2017-10-31treewide: Fix function prototypes for module_param_call()Kees Cook-8/+8
2017-10-30Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/netDavid S. Miller-840/+16
2017-10-26Revert "apparmor: add base infastructure for socket mediation"Linus Torvalds-840/+16
2017-10-24Merge tag 'v4.14-rc6' into locking/core, to pick up fixesIngo Molnar-54/+90
2017-10-22Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/netDavid S. Miller-54/+90
2017-10-21tomoyo: fix timestamping for y2038Arnd Bergmann-34/+13
2017-10-20selinux: bpf: Add addtional check for bpf object file receiveChenbo Feng-0/+49
2017-10-20selinux: bpf: Add selinux check for eBPF syscall operationsChenbo Feng-0/+117
2017-10-20security: bpf: Add LSM hooks for bpf object related syscallChenbo Feng-0/+32
2017-10-20capabilities: audit log other surprising conditionsRichard Guy Briggs-7/+22
2017-10-20capabilities: fix logic for effective root or real rootRichard Guy Briggs-3/+2
2017-10-20capabilities: invert logic for clarityRichard Guy Briggs-4/+4
2017-10-20capabilities: remove a layer of conditional logicRichard Guy Briggs-13/+10
2017-10-20capabilities: move audit log decision to functionRichard Guy Briggs-20/+30
2017-10-20capabilities: use intuitive names for id changesRichard Guy Briggs-6/+22
2017-10-20capabilities: use root_priveleged inline to clarify logicRichard Guy Briggs-2/+4
2017-10-20capabilities: rename has_cap to has_fcapRichard Guy Briggs-10/+10
2017-10-20capabilities: intuitive names for cap gain statusRichard Guy Briggs-7/+11
2017-10-20capabilities: factor out cap_bprm_set_creds privileged rootRichard Guy Briggs-28/+48
2017-10-19commoncap: move assignment of fs_ns to avoid null pointer dereferenceColin Ian King-1/+2
2017-10-19Merge commit 'tags/keys-fixes-20171018' into fixes-v4.14-rc5James Morris-53/+88
2017-10-18KEYS: load key flags and expiry time atomically in proc_keys_show()Eric Biggers-10/+14
2017-10-18KEYS: Load key expiry time atomically in keyring_search_iterator()Eric Biggers-1/+3
2017-10-18KEYS: load key flags and expiry time atomically in key_validate()Eric Biggers-3/+4
2017-10-18KEYS: don't let add_key() update an uninstantiated keyDavid Howells-0/+10
2017-10-18KEYS: Fix race between updating and finding a negative keyDavid Howells-39/+49
2017-10-18security/keys: BIG_KEY requires CONFIG_CRYPTOArnd Bergmann-0/+1
2017-10-16selinux: remove extraneous initialization of slots_used and max_chain_lenColin Ian King-1/+1
2017-10-16selinux: remove redundant assignment to lenColin Ian King-1/+0
2017-10-16selinux: remove redundant assignment to strColin Ian King-3/+2
2017-10-12KEYS: encrypted: fix dereference of NULL user_key_payloadEric Biggers-0/+7
2017-10-10locking/rwsem, security/apparmor: Replace homebrew use of write_can_lock() wi...Will Deacon-15/+4
2017-10-05timer: Remove expires and data arguments from DEFINE_TIMERKees Cook-1/+1
2017-10-04selinux: fix build warningCorentin LABBE-2/+2
2017-10-04selinux: fix build warning by removing the unused sid variableCorentin LABBE-2/+1