Show patches with: none      |   13120 patches
« 1 2 3 4131 132 »
Patch Series A/R/T S/W/F Date Submitter Delegate State
[ima-evm-utils,v5] Add tests for MMAP_CHECK and MMAP_CHECK_REQPROT hooks [ima-evm-utils,v5] Add tests for MMAP_CHECK and MMAP_CHECK_REQPROT hooks - - - --- 2023-02-03 Roberto Sassu New
landlock: Clarify documentation for the LANDLOCK_ACCESS_FS_REFER right landlock: Clarify documentation for the LANDLOCK_ACCESS_FS_REFER right - - - --- 2023-02-02 Günther Noack New
[ima-evm-utils,v4] Add tests for MMAP_CHECK and MMAP_CHECK_REQPROT hooks [ima-evm-utils,v4] Add tests for MMAP_CHECK and MMAP_CHECK_REQPROT hooks - - - --- 2023-02-02 Roberto Sassu New
[ima-evm-utils,v3] Add tests for MMAP_CHECK and MMAP_CHECK_REQPROT hooks [ima-evm-utils,v3] Add tests for MMAP_CHECK and MMAP_CHECK_REQPROT hooks - - - --- 2023-02-01 Roberto Sassu New
[ima-evm-utils,v2] Add tests for MMAP_CHECK and MMAP_CHECK_REQPROT hooks [ima-evm-utils,v2] Add tests for MMAP_CHECK and MMAP_CHECK_REQPROT hooks - 1 - --- 2023-01-31 Roberto Sassu New
[v4,2/2] ima: Introduce MMAP_CHECK_REQPROT hook [v4,1/2] ima: Align ima_file_mmap() parameters with mmap_file LSM hook - - - --- 2023-01-31 Roberto Sassu New
[v4,1/2] ima: Align ima_file_mmap() parameters with mmap_file LSM hook [v4,1/2] ima: Align ima_file_mmap() parameters with mmap_file LSM hook - 1 - --- 2023-01-31 Roberto Sassu New
[-next] evm: call dump_security_xattr() in all cases to remove code duplication [-next] evm: call dump_security_xattr() in all cases to remove code duplication - - - --- 2023-01-31 xiujianfeng New
[RFC,v9,16/16] documentation: add ipe documentation Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,15/16] ipe: kunit test for parser Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,14/16] scripts: add boot policy generation program Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,13/16] ipe: enable support for fs-verity as a trust provider Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,12/16] fsverity: consume builtin signature via LSM hook Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,11/16] ipe: add support for dm-verity as a trust provider Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,10/16] dm-verity: consume root hash digest and signature data via LSM hook Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,09/16] block|security: add LSM blob to block_device Integrity Policy Enforcement LSM (IPE) - 1 - --- 2023-01-30 Fan Wu New
[RFC,v9,08/16] ipe: add permissive toggle Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,07/16] uapi|audit|ipe: add ipe auditing support Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,06/16] ipe: add LSM hooks on execution and kernel read Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,05/16] ipe: add userspace interface Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,04/16] security: add new securityfs delete function Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,03/16] ipe: add evaluation loop and introduce 'boot_verified' as a trust provider Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,02/16] ipe: add policy parser Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[RFC,v9,01/16] security: add ipe lsm Integrity Policy Enforcement LSM (IPE) - - - --- 2023-01-30 Fan Wu New
[-next] evm: call dump_security_xattr() in all cases to remove code duplication [-next] evm: call dump_security_xattr() in all cases to remove code duplication - - - --- 2023-01-29 xiujianfeng New
[25/35] Documentation: security: correct spelling Documentation: correct lots of spelling errors (series 1) - 1 - --- 2023-01-27 Randy Dunlap New
[ima-evm-utils] Add tests for MMAP_CHECK and MMAP_CHECK_REQPROT hooks [ima-evm-utils] Add tests for MMAP_CHECK and MMAP_CHECK_REQPROT hooks - - - --- 2023-01-26 Roberto Sassu New
[v3,2/2] ima: Introduce MMAP_CHECK_REQPROT hook [v3,1/2] ima: Align ima_file_mmap() parameters with mmap_file LSM hook - - - --- 2023-01-26 Roberto Sassu New
[v3,1/2] ima: Align ima_file_mmap() parameters with mmap_file LSM hook [v3,1/2] ima: Align ima_file_mmap() parameters with mmap_file LSM hook - 1 - --- 2023-01-26 Roberto Sassu New
[v3,2/2] vfs: avoid duplicating creds in faccessat if possible [v3,1/2] capability: add cap_isidentical - - - --- 2023-01-25 Mateusz Guzik New
[v3,1/2] capability: add cap_isidentical [v3,1/2] capability: add cap_isidentical - 1 - --- 2023-01-25 Mateusz Guzik New
smackfs: Added check catlen smackfs: Added check catlen - - - --- 2023-01-24 Denis Arefev New
[RESEND,bpf-next,4/4] bpf: Only enable BPF LSM hooks when an LSM program is attached Reduce overhead of LSMs with static calls - - - --- 2023-01-20 KP Singh pcmoore New
[RESEND,bpf-next,3/4] security: Replace indirect LSM hook calls with static calls Reduce overhead of LSMs with static calls - - - --- 2023-01-20 KP Singh pcmoore New
[RESEND,bpf-next,2/4] security: Generate a header with the count of enabled LSMs Reduce overhead of LSMs with static calls - - - --- 2023-01-20 KP Singh pcmoore New
[RESEND,bpf-next,1/4] kernel: Add helper macros for loop unrolling Reduce overhead of LSMs with static calls - - - --- 2023-01-20 KP Singh pcmoore New
[v2,2/2] vfs: avoid duplicating creds in faccessat if possible [v2,1/2] capability: add cap_isidentical - - - --- 2023-01-16 Mateusz Guzik pcmoore New
[v2,1/2] capability: add cap_isidentical [v2,1/2] capability: add cap_isidentical - 1 - --- 2023-01-16 Mateusz Guzik pcmoore New
[v2] security: Restore passing final prot to ima_file_mmap() [v2] security: Restore passing final prot to ima_file_mmap() - - - --- 2022-12-21 Roberto Sassu pcmoore New
[RFC,v2,7/7] selftests/bpf: Change return value in test_libbpf_get_fd_by_id_opts.c bpf-lsm: Check return values of security modules - - - --- 2022-12-07 Roberto Sassu New
[RFC,v2,6/7] selftests/bpf: Prevent positive ret values in test_lsm and verify_pkcs7_sig bpf-lsm: Check return values of security modules - - - --- 2022-12-07 Roberto Sassu New
[RFC,v2,5/7] selftests/bpf: Check if return values of LSM programs are allowed bpf-lsm: Check return values of security modules - - - --- 2022-12-07 Roberto Sassu New
[RFC,v2,4/7] bpf-lsm: Enforce return value limitations on security modules bpf-lsm: Check return values of security modules - - - --- 2022-12-07 Roberto Sassu New
[RFC,v2,3/7] lsm: Redefine LSM_HOOK() macro to add return value flags as argument bpf-lsm: Check return values of security modules - - - --- 2022-12-07 Roberto Sassu New
[RFC,v2,2/7] bpf: Mark ALU32 operations in bpf_reg_state structure bpf-lsm: Check return values of security modules - - - --- 2022-12-07 Roberto Sassu New
[RFC,v2,1/7] bpf: Remove superfluous btf_id_set_contains() declaration bpf-lsm: Check return values of security modules - - - --- 2022-12-07 Roberto Sassu New
[v7,6/6] evm: Support multiple LSMs providing an xattr evm: Do HMAC of multiple per LSM xattrs for new inodes - 1 - --- 2022-12-01 Roberto Sassu pcmoore New
[v7,5/6] evm: Align evm_inode_init_security() definition with LSM infrastructure evm: Do HMAC of multiple per LSM xattrs for new inodes - 1 - --- 2022-12-01 Roberto Sassu pcmoore New
[v7,4/6] security: Allow all LSMs to provide xattrs for inode_init_security hook evm: Do HMAC of multiple per LSM xattrs for new inodes - 1 - --- 2022-12-01 Roberto Sassu pcmoore New
[v7,3/6] security: Remove security_old_inode_init_security() evm: Do HMAC of multiple per LSM xattrs for new inodes - 1 - --- 2022-12-01 Roberto Sassu pcmoore New
[v7,2/6] ocfs2: Switch to security_inode_init_security() evm: Do HMAC of multiple per LSM xattrs for new inodes - 1 - --- 2022-12-01 Roberto Sassu pcmoore New
[v7,1/6] reiserfs: Switch to security_inode_init_security() evm: Do HMAC of multiple per LSM xattrs for new inodes - 1 - --- 2022-12-01 Roberto Sassu pcmoore New
[v5] evm: Correct inode_init_security hooks behaviors [v5] evm: Correct inode_init_security hooks behaviors - - - --- 2022-11-25 Nicolas Bouchinet New
[RFC,v2,1/1] Use a fs callback to set security specific data RFC on how to include LSM hooks for io_uring commands - - - --- 2022-11-22 Joel Granados pcmoore New
[v5] vfs, security: Fix automount superblock LSM init problem, preventing NFS sb sharing [v5] vfs, security: Fix automount superblock LSM init problem, preventing NFS sb sharing 2 1 1 --- 2022-11-10 David Howells pcmoore New
[v3,1/8] capability: add any wrapper to test for multiple caps with exactly one audit message [v3,1/8] capability: add any wrapper to test for multiple caps with exactly one audit message - 1 - --- 2022-06-15 Christian Göttsche pcmoore New
[v3,8/8] net: use new capable_any functionality [v3,1/8] capability: add any wrapper to test for multiple caps with exactly one audit message - - - --- 2022-06-15 Christian Göttsche pcmoore New
[v3,7/8] bpf: use new capable_any functionality [v3,1/8] capability: add any wrapper to test for multiple caps with exactly one audit message - - - --- 2022-06-15 Christian Göttsche pcmoore New
[v3,6/8] kernel: use new capable_any functionality [v3,1/8] capability: add any wrapper to test for multiple caps with exactly one audit message - - - --- 2022-06-15 Christian Göttsche pcmoore New
[v3,5/8] fs: use new capable_any functionality [v3,1/8] capability: add any wrapper to test for multiple caps with exactly one audit message - - - --- 2022-06-15 Christian Göttsche pcmoore New
[v3,4/8] drivers: use new capable_any functionality [v3,1/8] capability: add any wrapper to test for multiple caps with exactly one audit message - 1 - --- 2022-06-15 Christian Göttsche pcmoore New
[v3,3/8] block: use new capable_any functionality [v3,1/8] capability: add any wrapper to test for multiple caps with exactly one audit message - 1 - --- 2022-06-15 Christian Göttsche pcmoore New
[v3,2/8] capability: use new capable_any functionality [v3,1/8] capability: add any wrapper to test for multiple caps with exactly one audit message - - - --- 2022-06-15 Christian Göttsche pcmoore New
[v10,6/7] doc: trusted-encrypted: describe new CAAM trust source KEYS: trusted: Introduce support for NXP CAAM-based trusted keys - 2 - --- 2022-05-13 Ahmad Fatoum New
[v10,5/7] KEYS: trusted: Introduce support for NXP CAAM-based trusted keys KEYS: trusted: Introduce support for NXP CAAM-based trusted keys - 3 5 --- 2022-05-13 Ahmad Fatoum New
[v10,4/7] crypto: caam - add in-kernel interface for blob generator KEYS: trusted: Introduce support for NXP CAAM-based trusted keys - 2 5 --- 2022-05-13 Ahmad Fatoum New
[v10,3/7] crypto: caam - determine whether CAAM supports blob encap/decap KEYS: trusted: Introduce support for NXP CAAM-based trusted keys - 1 1 --- 2022-05-13 Ahmad Fatoum New
[v10,2/7] KEYS: trusted: allow use of kernel RNG for key material KEYS: trusted: Introduce support for NXP CAAM-based trusted keys 2 3 3 --- 2022-05-13 Ahmad Fatoum New
[v10,1/7] KEYS: trusted: allow use of TEE as backend without TCG_TPM support KEYS: trusted: Introduce support for NXP CAAM-based trusted keys - 3 5 --- 2022-05-13 Ahmad Fatoum New
[v2] landlock: Explain how to support Landlock [v2] landlock: Explain how to support Landlock - 1 - --- 2022-05-13 Mickaël Salaün New
[v4] x86/kexec: Carry forward IMA measurement log on kexec [v4] x86/kexec: Carry forward IMA measurement log on kexec - 1 - --- 2022-05-12 Jonathan McDowell New
[v1] landlock: Explain how to support Landlock [v1] landlock: Explain how to support Landlock - - - --- 2022-05-12 Mickaël Salaün New
[-next] apparmor: Fix aa_str_perms() kernel-doc comment [-next] apparmor: Fix aa_str_perms() kernel-doc comment 1 - - --- 2022-05-12 Yang Li New
[v8,4/4] kexec, KEYS, s390: Make use of built-in and secondary keyring for signature verification Untitled series #640875 2 1 - --- 2022-05-12 Coiby Xu New
[v8,3/4] arm64: kexec_file: use more system keyrings to verify kernel image signature Untitled series #640875 2 - - --- 2022-05-12 Coiby Xu New
[v8,2/4] kexec, KEYS: make the code in bzImage64_verify_sig generic Untitled series #640875 1 1 - --- 2022-05-12 Coiby Xu New
loadpin: stop using bdevname loadpin: stop using bdevname - - - --- 2022-05-12 Christoph Hellwig New
[v7,4/4] kexec, KEYS, s390: Make use of built-in and secondary keyring for signature verification Untitled series #640797 1 1 - --- 2022-05-12 Coiby Xu New
[v7,3/4] arm64: kexec_file: use more system keyrings to verify kernel image signature Untitled series #640797 2 - - --- 2022-05-12 Coiby Xu New
[v7,2/4] kexec, KEYS: make the code in bzImage64_verify_sig generic Untitled series #640797 1 1 - --- 2022-05-12 Coiby Xu New
[v3] x86/kexec: Carry forward IMA measurement log on kexec [v3] x86/kexec: Carry forward IMA measurement log on kexec - - - --- 2022-05-11 Jonathan McDowell New
[v2] big_keys: Use struct for internal payload [v2] big_keys: Use struct for internal payload - - - --- 2022-05-10 Kees Cook New
big_keys: Use struct for internal payload big_keys: Use struct for internal payload - - - --- 2022-05-08 Kees Cook New
[v3,12/12] landlock: Add design choices documentation for filesystem access rights Landlock: file linking and renaming support - 1 - --- 2022-05-06 Mickaël Salaün New
[v3,11/12] landlock: Document good practices about filesystem policies Landlock: file linking and renaming support - 1 - --- 2022-05-06 Mickaël Salaün New
[v3,10/12] landlock: Document LANDLOCK_ACCESS_FS_REFER and ABI versioning Landlock: file linking and renaming support - 1 - --- 2022-05-06 Mickaël Salaün New
[v3,09/12] samples/landlock: Add support for file reparenting Landlock: file linking and renaming support - 1 - --- 2022-05-06 Mickaël Salaün New
[v3,08/12] selftests/landlock: Add 11 new test suites dedicated to file reparenting Landlock: file linking and renaming support - - - --- 2022-05-06 Mickaël Salaün New
[v3,07/12] landlock: Add support for file reparenting with LANDLOCK_ACCESS_FS_REFER Landlock: file linking and renaming support - 1 - --- 2022-05-06 Mickaël Salaün New
[v3,06/12] LSM: Remove double path_rename hook calls for RENAME_EXCHANGE Landlock: file linking and renaming support 2 1 - --- 2022-05-06 Mickaël Salaün New
[v3,05/12] landlock: Move filesystem helpers and add a new one Landlock: file linking and renaming support - 1 - --- 2022-05-06 Mickaël Salaün New
[v3,04/12] landlock: Fix same-layer rule unions Landlock: file linking and renaming support - 1 - --- 2022-05-06 Mickaël Salaün New
[v3,03/12] landlock: Create find_rule() from unmask_layers() Landlock: file linking and renaming support - 1 - --- 2022-05-06 Mickaël Salaün New
[v3,02/12] landlock: Reduce the maximum number of layers to 16 Landlock: file linking and renaming support - 1 - --- 2022-05-06 Mickaël Salaün New
[v3,01/12] landlock: Define access_mask_t to enforce a consistent access mask size Landlock: file linking and renaming support - 1 - --- 2022-05-06 Mickaël Salaün New
[v2,10/10] selftests/landlock: Test landlock_create_ruleset(2) argument check ordering Minor Landlock fixes and new tests - - - --- 2022-05-06 Mickaël Salaün New
[v2,09/10] landlock: Change landlock_restrict_self(2) check ordering Minor Landlock fixes and new tests - - - --- 2022-05-06 Mickaël Salaün New
[v2,08/10] landlock: Change landlock_add_rule(2) argument check ordering Minor Landlock fixes and new tests - - - --- 2022-05-06 Mickaël Salaün New
[v2,07/10] selftests/landlock: Add tests for O_PATH Minor Landlock fixes and new tests - - - --- 2022-05-06 Mickaël Salaün New
[v2,06/10] selftests/landlock: Fully test file rename with "remove" access Minor Landlock fixes and new tests - - - --- 2022-05-06 Mickaël Salaün New
« 1 2 3 4131 132 »