summaryrefslogtreecommitdiffstats
path: root/security
AgeCommit message (Expand)AuthorLines
2015-12-24IMA: policy can be updated zero timesSasha Levin-0/+14
2015-12-24selinux: rate-limit netlink message warnings in selinux_nlmsg_perm()Vladis Dronov-4/+5
2015-12-24selinux: export validatetrans decisionsAndrew Perepechko-8/+111
2015-12-24selinux: Revalidate invalid inode security labelsAndreas Gruenbacher-8/+68
2015-12-24security: Add hook to invalidate inode security labelsAndreas Gruenbacher-10/+34
2015-12-24selinux: Add accessor functions for inode->i_securityAndreas Gruenbacher-41/+56
2015-12-24security: Make inode argument of inode_getsecid non-constAndreas Gruenbacher-3/+3
2015-12-24security: Make inode argument of inode_getsecurity non-constAndreas Gruenbacher-3/+3
2015-12-24selinux: Remove unused variable in selinux_inode_init_securityAndreas Gruenbacher-2/+0
2015-12-20keys, trusted: seal with a TPM2 authorization policyJarkko Sakkinen-0/+26
2015-12-20keys, trusted: select hash algorithm for TPM2 chipsJarkko Sakkinen-1/+27
2015-12-20keys, trusted: fix: *do not* allow duplicate key optionsJarkko Sakkinen-0/+3
2015-12-19KEYS: Fix race between read and revokeDavid Howells-9/+9
2015-12-17Smack: type confusion in smak sendmsg() handlerRoman Kubiak-1/+1
2015-12-15security/integrity: make ima/ima_mok.c explicitly non-modularPaul Gortmaker-3/+2
2015-12-15ima: update appraise flags after policy update completesMimi Zohar-2/+5
2015-12-15IMA: prevent keys on the .ima_blacklist from being removedMimi Zohar-0/+2
2015-12-15KEYS: prevent keys from being removed from specified keyringsMimi Zohar-11/+51
2015-12-15IMA: allow reading back the current IMA policyPetko Manolov-8/+253
2015-12-15IMA: create machine owner and blacklist keyringsPetko Manolov-0/+87
2015-12-15IMA: policy can now be updated multiple timesPetko Manolov-28/+75
2015-12-15evm: EVM_LOAD_X509 depends on EVMArnd Bergmann-1/+1
2015-12-15evm: reset EVM status when file attributes changeDmitry Kasatkin-0/+13
2015-12-15evm: provide a function to set the EVM key from the kernelDmitry Kasatkin-14/+46
2015-12-15evm: enable EVM when X509 certificate is loadedDmitry Kasatkin-3/+14
2015-12-15evm: load an x509 certificate from the kernelDmitry Kasatkin-0/+33
2015-12-13nfs: Move call to security_inode_listsecurity into nfs_listxattrAndreas Gruenbacher-2/+0
2015-12-09Smack: File receive for socketsCasey Schaufler-0/+22
2015-11-26Merge branch 'upstream' of git://git.infradead.org/users/pcmoore/selinux into...James Morris-2/+2
2015-11-25KEYS: Fix handling of stored error in a negatively instantiated user keyDavid Howells-2/+10
2015-11-24selinux: fix bug in conditional rules handlingStephen Smalley-2/+2
2015-11-23integrity: define '.evm' as a builtin 'trusted' keyringDmitry Kasatkin-22/+35
2015-11-10Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/netLinus Torvalds-9/+10
2015-11-08smack: use skb_to_full_sk() helperEric Dumazet-4/+7
2015-11-08net: add skb_to_full_sk() helper and use it in selinux_netlbl_skbuff_setsid()Eric Dumazet-15/+3
2015-11-06mm, page_alloc: rename __GFP_WAIT to __GFP_RECLAIMMel Gorman-1/+1
2015-11-05Merge branch 'next' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/...Linus Torvalds-183/+393
2015-11-05selinux: fix random read in selinux_ip_postroute_compat()Eric Dumazet-4/+14
2015-11-01Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/netDavid S. Miller-2/+7
2015-10-23Merge tag 'keys-next-20151021' of git://git.kernel.org/pub/scm/linux/kernel/g...James Morris-75/+84
2015-10-22Merge branch 'upstream' of git://git.infradead.org/users/pcmoore/selinux into...James Morris-45/+36
2015-10-22apparmor: clarify CRYPTO dependencyArnd Bergmann-1/+1
2015-10-21selinux: Use a kmem_cache for allocation struct file_security_structSangwoo-2/+6
2015-10-21selinux: ioctl_has_perm should be staticGeliang Tang-1/+1
2015-10-21selinux: use sprintf return valueRasmus Villemoes-4/+1
2015-10-21selinux: use kstrdup() in security_get_bools()Rasmus Villemoes-7/+1
2015-10-21selinux: use kmemdup in security_sid_to_context_core()Rasmus Villemoes-2/+2
2015-10-21selinux: remove pointless cast in selinux_inode_setsecurity()Rasmus Villemoes-1/+1
2015-10-21selinux: introduce security_context_str_to_sidRasmus Villemoes-25/+20
2015-10-21selinux: do not check open perm on ftruncate callJeff Vander Stoep-1/+2