Show patches with: State = Action Required       |   12026 patches
« 1 2 3 4120 121 »
Patch Series A/R/T S/W/F Date Submitter Delegate State
[GIT,PULL] capabilities update for 6.15 [GIT,PULL] capabilities update for 6.15 - - - --- 2025-03-28 Serge E. Hallyn New
[v3] ima: process_measurement() needlessly takes inode_lock() on MAY_READ [v3] ima: process_measurement() needlessly takes inode_lock() on MAY_READ 1 - - --- 2025-03-27 Frederick Lawler New
ima: process_measurement() needlessly takes inode_lock() on MAY_READ ima: process_measurement() needlessly takes inode_lock() on MAY_READ - - - --- 2025-03-25 Frederick Lawler New
[GIT,PULL] Smack patches for 6.15 [GIT,PULL] Smack patches for 6.15 - - - --- 2025-03-25 Casey Schaufler New
ima: process_measurement() needlessly takes inode_lock() on MAY_READ ima: process_measurement() needlessly takes inode_lock() on MAY_READ - - - --- 2025-03-25 Frederick Lawler New
[GIT,PULL] IPE update for 6.15 [GIT,PULL] IPE update for 6.15 - - - --- 2025-03-24 Fan Wu New
[GIT,PULL] selinux/selinux-pr-20250323 [GIT,PULL] selinux/selinux-pr-20250323 - - - --- 2025-03-23 Paul Moore New
[GIT,PULL] lsm/lsm-pr-20250323 [GIT,PULL] lsm/lsm-pr-20250323 - - - --- 2025-03-23 Paul Moore New
[RFC,v2,13/13] ima: don't re-invalidate unsupported PCR banks after kexec ima: get rid of hard dependency on SHA-1 - - - --- 2025-03-23 Nicolai Stange New
[RFC,v2,12/13] ima: make ima_free_tfm()'s linkage extern ima: get rid of hard dependency on SHA-1 - - - --- 2025-03-23 Nicolai Stange New
[RFC,v2,11/13] ima: introduce ima_pcr_invalidated_banks() helper ima: get rid of hard dependency on SHA-1 - - - --- 2025-03-23 Nicolai Stange New
[RFC,v2,10/13] tpm: authenticate tpm2_pcr_read() ima: get rid of hard dependency on SHA-1 - - - --- 2025-03-23 Nicolai Stange New
[RFC,v2,09/13] ima: invalidate unsupported PCR banks only once ima: get rid of hard dependency on SHA-1 - - - --- 2025-03-23 Nicolai Stange New
[RFC,v2,08/13] ima: track the set of PCRs ever extended ima: get rid of hard dependency on SHA-1 - - - --- 2025-03-23 Nicolai Stange New
[RFC,v2,07/13] tpm: enable bank selection for PCR extend ima: get rid of hard dependency on SHA-1 - - - --- 2025-03-23 Nicolai Stange New
[RFC,v2,06/13] ima: move INVALID_PCR() to ima.h ima: get rid of hard dependency on SHA-1 - - - --- 2025-03-23 Nicolai Stange New
[RFC,v2,05/13] ima: select CRYPTO_SHA256 from Kconfig ima: get rid of hard dependency on SHA-1 - - - --- 2025-03-23 Nicolai Stange New
[RFC,v2,04/13] ima: make SHA1 non-mandatory ima: get rid of hard dependency on SHA-1 - - - --- 2025-03-23 Nicolai Stange New
[RFC,v2,03/13] ima: invalidate unsupported PCR banks ima: get rid of hard dependency on SHA-1 - - - --- 2025-03-23 Nicolai Stange New
[RFC,v2,02/13] ima: always create runtime_measurements sysfs file for ima_hash ima: get rid of hard dependency on SHA-1 - - - --- 2025-03-23 Nicolai Stange New
[RFC,v2,01/13] ima: don't expose runtime_measurements for unsupported hashes ima: get rid of hard dependency on SHA-1 - 1 - --- 2025-03-23 Nicolai Stange New
[RFC,security-next,4/4] selftests/hornet: Add a selftest for the hornet LSM Introducing Hornet LSM - - - --- 2025-03-21 Blaise Boscaccy pcmoore Under Review
[RFC,security-next,3/4] hornet: Add an example lskel data extactor script Introducing Hornet LSM - - - --- 2025-03-21 Blaise Boscaccy pcmoore Under Review
[RFC,security-next,2/4] hornet: Introduce sign-ebpf Introducing Hornet LSM - - - --- 2025-03-21 Blaise Boscaccy pcmoore Under Review
[RFC,security-next,1/4] security: Hornet LSM Introducing Hornet LSM - - - --- 2025-03-21 Blaise Boscaccy pcmoore Under Review
[2/2] lockdown/kunit: Introduce kunit tests Allow individual features to be locked down - - - --- 2025-03-21 Nikolay Borisov pcmoore Under Review
[1/2] lockdown: Switch implementation to using bitmap Allow individual features to be locked down - 1 - --- 2025-03-21 Nikolay Borisov pcmoore Under Review
[v3,5/5] Audit: Add record for multiple object contexts [v3,1/5] Audit: Create audit_stamp structure - - - --- 2025-03-19 Casey Schaufler New
[v3,4/5] Audit: multiple subject lsm values for netlabel [v3,1/5] Audit: Create audit_stamp structure - - - --- 2025-03-19 Casey Schaufler New
[v3,3/5] Audit: Add record for multiple task security contexts [v3,1/5] Audit: Create audit_stamp structure - - - --- 2025-03-19 Casey Schaufler New
[v3,2/5] LSM: security_lsmblob_to_secctx module selection [v3,1/5] Audit: Create audit_stamp structure - - 1 --- 2025-03-19 Casey Schaufler New
[v3,1/5] Audit: Create audit_stamp structure [v3,1/5] Audit: Create audit_stamp structure - - - --- 2025-03-19 Casey Schaufler New
[v5] hwmon: (pmbus/tps53679) Add support for TPS53685 [v5] hwmon: (pmbus/tps53679) Add support for TPS53685 - - - --- 2025-03-14 Chiang Brian New
[v5,1/1] ipe: add errno field to IPE policy load auditing ipe: add errno field to IPE policy load auditing - - - --- 2025-03-13 Jasjiv Singh New
[v6,bpf-next,2/2] selftests/bpf: Add a kernel flag test for LSM bpf hook security: Propagate caller information in bpf hooks - - - --- 2025-03-08 Blaise Boscaccy pcmoore Under Review
[v6,bpf-next,1/2] security: Propagate caller information in bpf hooks security: Propagate caller information in bpf hooks 2 - - --- 2025-03-08 Blaise Boscaccy pcmoore Under Review
[v5,bpf-next,2/2] selftests/bpf: Add a kernel flag test for LSM bpf hook security: Propagate caller information in bpf hooks - - - --- 2025-03-07 Blaise Boscaccy pcmoore Under Review
[v5,bpf-next,1/2] security: Propagate caller information in bpf hooks security: Propagate caller information in bpf hooks 2 - - --- 2025-03-07 Blaise Boscaccy pcmoore Under Review
[RFC] MAINTAINERS: add an explicit credentials entry [RFC] MAINTAINERS: add an explicit credentials entry 1 - - --- 2025-03-04 Paul Moore pcmoore Under Review
[v4,bpf-next,2/2] selftests/bpf: Add is_kernel parameter to LSM/bpf test programs security: Propagate caller information in bpf hooks - - - --- 2025-03-04 Blaise Boscaccy pcmoore Under Review
[v4,bpf-next,1/2] security: Propagate caller information in bpf hooks security: Propagate caller information in bpf hooks 2 - - --- 2025-03-04 Blaise Boscaccy pcmoore Under Review
[v2] capability: Remove unused has_capability [v2] capability: Remove unused has_capability 1 1 - --- 2024-12-19 Dr. David Alan Gilbert pcmoore Under Review
lsm: integrity: Allow enable/disable ima and evm with lsm= cmdline lsm: integrity: Allow enable/disable ima and evm with lsm= cmdline - - - --- 2024-12-18 Song Liu pcmoore New
[6/6] Audit: Add record for multiple object contexts [1/6] Audit: Create audit_stamp structure - - - --- 2024-12-17 Casey Schaufler pcmoore New
[5/6] Audit: multiple subject lsm values for netlabel [1/6] Audit: Create audit_stamp structure - - - --- 2024-12-17 Casey Schaufler pcmoore New
[4/6] Audit: Add record for multiple task security contexts [1/6] Audit: Create audit_stamp structure - - - --- 2024-12-17 Casey Schaufler pcmoore New
[3/6] LSM: security_lsmblob_to_secctx module selection [1/6] Audit: Create audit_stamp structure - - - --- 2024-12-17 Casey Schaufler pcmoore New
[2/6] Audit: Allow multiple records in an audit_buffer [1/6] Audit: Create audit_stamp structure - - - --- 2024-12-17 Casey Schaufler pcmoore New
[1/6] Audit: Create audit_stamp structure [1/6] Audit: Create audit_stamp structure - - - --- 2024-12-17 Casey Schaufler pcmoore New
capability: Remove unused has_capability capability: Remove unused has_capability - 1 - --- 2024-12-15 Dr. David Alan Gilbert pcmoore Under Review
lsm: add reserved flag in lsm_prop struct lsm: add reserved flag in lsm_prop struct - - - --- 2024-12-06 李豪杰 pcmoore Under Review
[01/11] coccinelle: Add script to reorder capable() calls [01/11] coccinelle: Add script to reorder capable() calls - 1 - --- 2024-11-25 Christian Göttsche pcmoore New
[11/11] infiniband: reorder capability check last [01/11] coccinelle: Add script to reorder capable() calls - - - --- 2024-11-25 Christian Göttsche pcmoore New
[10/11] skbuff: reorder capability check last [01/11] coccinelle: Add script to reorder capable() calls - - - --- 2024-11-25 Christian Göttsche pcmoore New
[09/11] fs: reorder capability check last [01/11] coccinelle: Add script to reorder capable() calls - 1 - --- 2024-11-25 Christian Göttsche pcmoore New
[08/11] gfs2: reorder capability check last [01/11] coccinelle: Add script to reorder capable() calls - - - --- 2024-11-25 Christian Göttsche pcmoore New
[07/11] ipv4: reorder capability check last [01/11] coccinelle: Add script to reorder capable() calls - - - --- 2024-11-25 Christian Göttsche pcmoore New
[06/11] ubifs: reorder capability check last [01/11] coccinelle: Add script to reorder capable() calls 1 - - --- 2024-11-25 Christian Göttsche pcmoore New
[05/11] genwqe: reorder capability check last [01/11] coccinelle: Add script to reorder capable() calls - - - --- 2024-11-25 Christian Göttsche pcmoore New
[04/11] hugetlbfs: reorder capability check last [01/11] coccinelle: Add script to reorder capable() calls - - - --- 2024-11-25 Christian Göttsche pcmoore New
[03/11] ext4: reorder capability check last [01/11] coccinelle: Add script to reorder capable() calls - - - --- 2024-11-25 Christian Göttsche pcmoore New
[02/11] quota: reorder capability check last [01/11] coccinelle: Add script to reorder capable() calls - - - --- 2024-11-25 Christian Göttsche pcmoore New
[v21,6/6] samples/check-exec: Add an enlighten "inc" interpreter and 28 tests Script execution control (was O_MAYEXEC) - - - --- 2024-11-12 Mickaël Salaün pcmoore New
[v21,5/6] samples/check-exec: Add set-exec Script execution control (was O_MAYEXEC) - - - --- 2024-11-12 Mickaël Salaün pcmoore New
[v21,4/6] selftests/landlock: Add tests for execveat + AT_EXECVE_CHECK Script execution control (was O_MAYEXEC) - - - --- 2024-11-12 Mickaël Salaün pcmoore New
[v21,3/6] selftests/exec: Add 32 tests for AT_EXECVE_CHECK and exec securebits Script execution control (was O_MAYEXEC) - - - --- 2024-11-12 Mickaël Salaün pcmoore New
[v21,2/6] security: Add EXEC_RESTRICT_FILE and EXEC_DENY_INTERACTIVE securebits Script execution control (was O_MAYEXEC) - 1 - --- 2024-11-12 Mickaël Salaün pcmoore New
[v21,1/6] exec: Add a new AT_EXECVE_CHECK flag to execveat(2) Script execution control (was O_MAYEXEC) 1 1 - --- 2024-11-12 Mickaël Salaün pcmoore New
selinux,xfrm: fix dangling refcount on deferred skb free selinux,xfrm: fix dangling refcount on deferred skb free - - - --- 2024-11-06 Ondrej Mosnacek pcmoore Under Review
[v2] mm: Split critical region in remap_file_pages() and invoke LSMs in between [v2] mm: Split critical region in remap_file_pages() and invoke LSMs in between - 5 2 --- 2024-10-18 Roberto Sassu pcmoore Under Review
[RFC,v4] mm: move the check of READ_IMPLIES_EXEC out of do_mmap() [RFC,v4] mm: move the check of READ_IMPLIES_EXEC out of do_mmap() - - - --- 2024-09-28 Shu Han Under Review
mm: move security_file_mmap() back into do_mmap() mm: move security_file_mmap() back into do_mmap() - - - --- 2024-09-25 Shu Han Under Review
mm: move the check of READ_IMPLIES_EXEC out of do_mmap() mm: move the check of READ_IMPLIES_EXEC out of do_mmap() - - - --- 2024-09-25 Shu Han Under Review
[RESEND] cred: separate the refcount from frequently read fields [RESEND] cred: separate the refcount from frequently read fields - - - --- 2024-08-22 Mateusz Guzik pcmoore New
[v2,2/2] security: remove unused cred_alloc_blank/cred_transfer helpers get rid of cred_transfer - - - --- 2024-08-05 Jann Horn pcmoore Under Review
[v2,1/2] KEYS: use synchronous task work for changing parent credentials get rid of cred_transfer - - - --- 2024-08-05 Jann Horn pcmoore Under Review
cred: plug a hole in struct cred cred: plug a hole in struct cred - - - --- 2024-05-30 Mateusz Guzik pcmoore New
[v1,1/2] landlock: Fix d_parent walk Fix warning in collect_domain_accesses() - - - --- 2024-05-16 Mickaël Salaün pcmoore New
[RFC] ima: Use sequence number to wait for policy updates [RFC] ima: Use sequence number to wait for policy updates - - - --- 2024-05-07 Roberto Sassu pcmoore New
[2/2] selftests/landlock: Create 'listen_zero', 'deny_listen_zero' tests Forbid illegitimate binding via listen(2) - 1 - --- 2024-04-08 Mikhail Ivanov pcmoore New
[1/2] landlock: Add hook on socket_listen() Forbid illegitimate binding via listen(2) - 1 - --- 2024-04-08 Mikhail Ivanov pcmoore New
[RFC,1/2] lsm: introduce new hook security_vm_execstack [RFC,1/2] lsm: introduce new hook security_vm_execstack - - - --- 2024-03-15 Christian Göttsche pcmoore Under Review
[RFC,2/2] selinux: wire up new execstack LSM hook [RFC,1/2] lsm: introduce new hook security_vm_execstack - - - --- 2024-03-15 Christian Göttsche pcmoore Under Review
[10/10] coccinelle: add script for capable_any() [01/10] capability: introduce new capable flag CAP_OPT_NOAUDIT_ONDENY - - - --- 2024-03-15 Christian Göttsche pcmoore Under Review
[09/10] bpf: use new capable_any functionality [01/10] capability: introduce new capable flag CAP_OPT_NOAUDIT_ONDENY 1 - - --- 2024-03-15 Christian Göttsche pcmoore Under Review
[08/10] net: use new capable_any functionality [01/10] capability: introduce new capable flag CAP_OPT_NOAUDIT_ONDENY - 1 - --- 2024-03-15 Christian Göttsche pcmoore Under Review
[07/10] kernel: use new capable_any functionality [01/10] capability: introduce new capable flag CAP_OPT_NOAUDIT_ONDENY - 2 - --- 2024-03-15 Christian Göttsche pcmoore Under Review
[06/10] fs: use new capable_any functionality [01/10] capability: introduce new capable flag CAP_OPT_NOAUDIT_ONDENY 1 - - --- 2024-03-15 Christian Göttsche pcmoore Under Review
[05/10] drivers: use new capable_any functionality [01/10] capability: introduce new capable flag CAP_OPT_NOAUDIT_ONDENY 2 - - --- 2024-03-15 Christian Göttsche pcmoore Under Review
[04/10] block: use new capable_any functionality [01/10] capability: introduce new capable flag CAP_OPT_NOAUDIT_ONDENY - - - --- 2024-03-15 Christian Göttsche pcmoore Under Review
[03/10] capability: use new capable_any functionality [01/10] capability: introduce new capable flag CAP_OPT_NOAUDIT_ONDENY 1 - - --- 2024-03-15 Christian Göttsche pcmoore Under Review
[02/10] capability: add any wrappers to test for multiple caps with exactly one audit message [01/10] capability: introduce new capable flag CAP_OPT_NOAUDIT_ONDENY - 1 - --- 2024-03-15 Christian Göttsche pcmoore Under Review
[01/10] capability: introduce new capable flag CAP_OPT_NOAUDIT_ONDENY [01/10] capability: introduce new capable flag CAP_OPT_NOAUDIT_ONDENY 2 1 - --- 2024-03-15 Christian Göttsche pcmoore Under Review
[v3,3/3] fs/exec: remove current->in_execve flag fs/exec: remove current->in_execve flag 1 - - --- 2024-02-06 Tetsuo Handa pcmoore Under Review
[v3,2/3] tomoyo: replace current->in_execve flag with security_execve_abort() hook fs/exec: remove current->in_execve flag 1 - - --- 2024-02-06 Tetsuo Handa pcmoore Under Review
[v3,1/3] LSM: add security_execve_abort() hook fs/exec: remove current->in_execve flag 1 - - --- 2024-02-06 Tetsuo Handa pcmoore Under Review
[v39,42/42] Smack: Remove LSM_FLAG_EXCLUSIVE LSM: General module stacking - - - --- 2023-12-15 Casey Schaufler pcmoore Under Review
[v39,41/42] LSM: restrict security_cred_getsecid() to a single LSM LSM: General module stacking - - - --- 2023-12-15 Casey Schaufler pcmoore Under Review
[v39,40/42] LSM: Allow reservation of netlabel LSM: General module stacking - - - --- 2023-12-15 Casey Schaufler pcmoore Under Review
[v39,39/42] LSM: Remove lsmblob scaffolding LSM: General module stacking - - - --- 2023-12-15 Casey Schaufler pcmoore Under Review
« 1 2 3 4120 121 »