summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)Author
2025-07-20apparmor: transition from a list of rules to a vector of rulesJohn Johansen
2025-07-20apparmor: fix documentation mismatches in val_mask_to_str and socket functionsPeng Jiang
2025-07-20apparmor: remove redundant perms.allow MAY_EXEC bitflag setRyan Lee
2025-07-20apparmor: fix kernel doc warnings for kernel test robotJohn Johansen
2025-07-20apparmor: Fix unaligned memory accesses in KUnit testHelge Deller
2025-07-20apparmor: Fix 8-byte alignment for initial dfa blob streamsHelge Deller
2025-07-20apparmor: shift uid when mediating af_unix in usernsGabriel Totev
2025-07-20apparmor: shift ouid when mediating hard links in usernsGabriel Totev
2025-07-20apparmor: make sure unix socket labeling is correctly updated.John Johansen
2025-07-19landlock: Fix cosmetic changeMickaël Salaün
2025-07-15apparmor: fix regression in fs based unix sockets when using old abiJohn Johansen
2025-07-15apparmor: fix AA_DEBUG_LABEL()John Johansen
2025-07-15apparmor: fix af_unix auditing to include all address informationJohn Johansen
2025-07-15apparmor: Remove use of the double lockJohn Johansen
2025-07-15apparmor: update kernel doc comments for xxx_label_crit_sectionJohn Johansen
2025-07-15apparmor: make __begin_current_label_crit_section() indicate whether put is n...Mateusz Guzik
2025-07-15Revert "apparmor: use SHA-256 library API instead of crypto_shash API"John Johansen
2025-07-15apparmor: mitigate parser generating large xtablesJohn Johansen
2025-07-14apparmor: use SHA-256 library API instead of crypto_shash APIEric Biggers
2025-07-09integrity/platform_certs: Allow loading of keys in the static key management ...Srish Srinivasan
2025-07-04tree-wide: s/struct fileattr/struct file_kattr/gChristian Brauner
2025-07-01selinux: implement inode_file_[g|s]etattr hooksAndrey Albershteyn
2025-07-01lsm: introduce new hooks for setting/getting inode fsxattrAndrey Albershteyn
2025-06-30smack: fix kernel-doc warnings for smk_import_valid_label()Konstantin Andreev
2025-06-27landlock: Fix warning from KUnit testsTingmao Wang
2025-06-24selinux: don't bother with selinuxfs_info_free() on failuresAl Viro
2025-06-24smack: fix bug: setting task label silently ignores input garbageKonstantin Andreev
2025-06-24smack: fix bug: unprivileged task can create labelsKonstantin Andreev
2025-06-23exec: Correct the permission check for unsafe execEric W. Biederman
2025-06-22smack: fix bug: invalid label of unix socket fileKonstantin Andreev
2025-06-22smack: always "instantiate" inode in smack_inode_init_security()Konstantin Andreev
2025-06-22smack: deduplicate xattr setting in smack_inode_init_security()Konstantin Andreev
2025-06-22smack: fix bug: SMACK64TRANSMUTE set on non-directoryKonstantin Andreev
2025-06-22smack: deduplicate "does access rule request transmutation"Konstantin Andreev
2025-06-19selinux: add __GFP_NOWARN to hashtab_init() allocationsPaul Moore
2025-06-19selinux: optimize selinux_inode_getattr/permission() based on neveraudit|perm...Stephen Smalley
2025-06-19selinux: introduce neveraudit typesStephen Smalley
2025-06-19selinux: change security_compute_sid to return the ssid or tsid on matchStephen Smalley
2025-06-17ipe: don't bother with removal of files in directory we'll be removingAl Viro
2025-06-17evm_secfs: clear securityfs interactionsAl Viro
2025-06-17ima_fs: get rid of lookup-by-dentry stuffAl Viro
2025-06-17ima_fs: don't bother with removal of files in directory we'll be removingAl Viro
2025-06-17apparmor: file never has NULL f_path.mntAl Viro
2025-06-17landlock: opened file never has a negative dentryAl Viro
2025-06-16selinux: fix selinux_xfrm_alloc_user() to set correct ctx_lenStephen Smalley
2025-06-16selinux: add a 5 second sleep to /sys/fs/selinux/userPaul Moore
2025-06-16lsm: trivial comment fixKalevi Kolttonen
2025-06-16ima: add a knob ima= to allow disabling IMA in kdump kernelBaoquan He
2025-06-11make securityfs_remove() remove the entire subtreeAl Viro
2025-06-11securityfs: pin filesystem only for objects directly in rootAl Viro