Show patches with: Archived = No       |   896 patches
« 1 2 3 48 9 »
Patch Series A/R/T S/W/F Date Submitter Delegate State
[RFC,bpf-next,seccomp,12/12] seccomp-ebpf: support task storage from BPF-LSM, defaulting to group l… eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,11/12] bpf/verifier: support NULL-able ptr to BTF ID as helper argument eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,10/12] seccomp-ebpf: Add ability to read user memory eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,09/12] yama: (concept) restrict seccomp-eBPF with ptrace_scope eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,08/12] seccomp-ebpf: restrict filter to almost cBPF if LSM request such eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,07/12] bpf/verifier: allow restricting direct map access eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,06/12] lsm: New hook seccomp_extended eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,05/12] samples/bpf: Add eBPF seccomp sample programs eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,04/12] libbpf: recognize section "seccomp" eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,03/12] seccomp, ptrace: Add a mechanism to retrieve attached eBPF seccomp fil… eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,02/12] bpf, seccomp: Add eBPF filter capabilities eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,01/12] seccomp: Move no_new_privs check to after prepare_filter eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
Keys: Remove redundant initialization of cred Keys: Remove redundant initialization of cred - 1 - --- 2021-05-08 Yang Li New
[RFC,09/12] apparmor: use get_unaligned() only for multi-byte words Unify asm/unaligned.h around struct helper 1 - - --- 2021-05-07 Arnd Bergmann New
[RESEND,v6,05/11] evm: Introduce evm_hmac_disabled() to safely ignore verification errors Untitled series #478471 - 1 - --- 2021-05-07 Roberto Sassu New
[v2] debugfs: fix security_locked_down() call for SELinux [v2] debugfs: fix security_locked_down() call for SELinux - - - --- 2021-05-07 Ondrej Mosnacek New
serial: core: fix suspicious security_locked_down() call serial: core: fix suspicious security_locked_down() call 1 - - --- 2021-05-07 Ondrej Mosnacek New
debugfs: fix security_locked_down() call for SELinux debugfs: fix security_locked_down() call for SELinux - - - --- 2021-05-07 Ondrej Mosnacek New
lockdown,selinux: fix bogus SELinux lockdown permission checks lockdown,selinux: fix bogus SELinux lockdown permission checks - - - --- 2021-05-07 Ondrej Mosnacek New
vfio: Lock down no-IOMMU mode when kernel is locked down vfio: Lock down no-IOMMU mode when kernel is locked down - - - --- 2021-05-06 Maxime Coquelin New
Makefile: Introduce CONFIG_ZERO_CALL_USED_REGS Makefile: Introduce CONFIG_ZERO_CALL_USED_REGS - - - --- 2021-05-05 Kees Cook New
[v6,11/11] ima: Don't remove security.ima if file must not be appraised evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,10/11] ima: Introduce template field evmsig and write to field sig as fallback evm: Improve usability of portable signatures - - - --- 2021-05-05 Roberto Sassu New
[v6,09/11] ima: Allow imasig requirement to be satisfied by EVM portable signatures evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,08/11] evm: Allow setxattr() and setattr() for unmodified metadata evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,07/11] evm: Pass user namespace to set/remove xattr hooks evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,06/11] evm: Allow xattr/attr operations for portable signatures evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,05/11] evm: Introduce evm_hmac_disabled() to safely ignore verification errors evm: Improve usability of portable signatures - - - --- 2021-05-05 Roberto Sassu New
[v6,04/11] evm: Introduce evm_status_revalidate() evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,03/11] evm: Refuse EVM_ALLOW_METADATA_WRITES only if an HMAC key is loaded evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,02/11] evm: Load EVM key in ima_load_x509() to avoid appraisal evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,01/11] evm: Execute evm_inode_init_security() only when an HMAC key is loaded evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[GIT,PULL] SafeSetID changes for v5.13 [GIT,PULL] SafeSetID changes for v5.13 - - - --- 2021-05-03 Micah Morton New
KEYS: trusted: fix memory leak KEYS: trusted: fix memory leak - - - --- 2021-04-30 Tom Rix New
KEYS: trusted: Fix memory leak on object td KEYS: trusted: Fix memory leak on object td - 3 - --- 2021-04-30 Colin Ian King New
[v2,1/1] trusted-keys: match tpm_get_ops on all return paths trusted-keys: match tpm_get_ops on all return paths - - - --- 2021-04-29 Ben Boeckel New
[1/1] trusted-keys: match tpm_get_ops on all return paths trusted-keys: match tpm_get_ops on all return paths - - - --- 2021-04-29 Ben Boeckel New
[v2] samples/landlock: fix path_list memory leak [v2] samples/landlock: fix path_list memory leak - 1 - --- 2021-04-28 Tom Rix New
[GIT,PULL,Security] Add new Landlock LSM [GIT,PULL,Security] Add new Landlock LSM - - - --- 2021-04-28 James Morris New
[GIT,PULL,Security,Subsystem] Fixes for v5.13 [GIT,PULL,Security,Subsystem] Fixes for v5.13 - - - --- 2021-04-27 James Morris New
samples/landlock: fix path_list memory leak samples/landlock: fix path_list memory leak - 1 - --- 2021-04-27 Tom Rix New
[v3,6/6] evm: Support multiple LSMs providing an xattr evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-27 Roberto Sassu New
[v3,5/6] evm: Align evm_inode_init_security() definition with LSM infrastructure evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-27 Roberto Sassu New
[v3,4/6] security: Support multiple LSMs implementing the inode_init_security hook evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-27 Roberto Sassu New
[v3,3/6] security: Pass xattrs allocated by LSMs to the inode_init_security hook evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-27 Roberto Sassu New
[v3,2/6] security: Rewrite security_old_inode_init_security() evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-27 Roberto Sassu New
[v3,1/6] reiserfs: Add missing calls to reiserfs_security_free() evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-27 Roberto Sassu New
[GIT,PULL] SELinux patches for v5.13 [GIT,PULL] SELinux patches for v5.13 - - - --- 2021-04-26 Paul Moore New
[v4,2/2] certs: Add support for using elliptic curve keys for signing modules Add support for ECDSA-signed kernel modules - - - --- 2021-04-23 Stefan Berger New
[v4,1/2] certs: Trigger creation of RSA module signing key if it's not an RSA key Add support for ECDSA-signed kernel modules - - - --- 2021-04-23 Stefan Berger New
ima: ensure IMA_APPRAISE_MODSIG has necessary dependencies ima: ensure IMA_APPRAISE_MODSIG has necessary dependencies 1 - - --- 2021-04-23 Nayna Jain New
[v34,13/13] landlock: Enable user space to infer supported features Landlock LSM - - - --- 2021-04-22 Mickaël Salaün New
[v34,12/13] landlock: Add user and kernel documentation Landlock LSM - 2 - --- 2021-04-22 Mickaël Salaün New
[v34,11/13] samples/landlock: Add a sandbox manager example Landlock LSM - 2 - --- 2021-04-22 Mickaël Salaün New
[v34,09/13] arch: Wire up Landlock syscalls Landlock LSM - - - --- 2021-04-22 Mickaël Salaün New
[v34,08/13] landlock: Add syscall implementations Landlock LSM 1 - - --- 2021-04-22 Mickaël Salaün New
[v34,07/13] landlock: Support filesystem access-control Landlock LSM - - - --- 2021-04-22 Mickaël Salaün New
[v34,06/13] fs,security: Add sb_delete hook Landlock LSM 1 2 - --- 2021-04-22 Mickaël Salaün New
[v34,05/13] LSM: Infrastructure management of the superblock Landlock LSM 1 2 - --- 2021-04-22 Mickaël Salaün New
[v34,04/13] landlock: Add ptrace restrictions Landlock LSM 1 2 - --- 2021-04-22 Mickaël Salaün New
[v34,03/13] landlock: Set up the security framework and manage credentials Landlock LSM 1 2 - --- 2021-04-22 Mickaël Salaün New
[v34,02/13] landlock: Add ruleset and domain management Landlock LSM 1 2 - --- 2021-04-22 Mickaël Salaün New
[v34,01/13] landlock: Add object management Landlock LSM 1 2 - --- 2021-04-22 Mickaël Salaün New
ima: require CONFIG_MODULES for IMA_APPRAISE_MODSIG ima: require CONFIG_MODULES for IMA_APPRAISE_MODSIG - - - --- 2021-04-22 Arnd Bergmann New
[v3,2/2] certs: Add support for using elliptic curve keys for signing modules Add support for ECDSA-signed kernel modules 1 - - --- 2021-04-21 Stefan Berger New
[v3,1/2] certs: Trigger creation of RSA module signing key if it's not an RSA key Add support for ECDSA-signed kernel modules - 1 - --- 2021-04-21 Stefan Berger New
[RFC,2/2] selinux: add capability to map anon inode types to separate classes selinux,anon_inodes: Use a separate SELinux class for each type of anon inode - - - --- 2021-04-21 Ondrej Mosnacek New
[RFC,1/2] LSM,anon_inodes: explicitly distinguish anon inode types selinux,anon_inodes: Use a separate SELinux class for each type of anon inode - - - --- 2021-04-21 Ondrej Mosnacek New
[v2,6/6] evm: Support multiple LSMs providing an xattr evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-21 Roberto Sassu New
[v2,5/6] evm: Align evm_inode_init_security() definition with LSM infrastructure evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-21 Roberto Sassu New
[v2,4/6] security: Support multiple LSMs implementing the inode_init_security hook evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-21 Roberto Sassu New
[v2,3/6] security: Pass xattrs allocated by LSMs to the inode_init_security hook evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-21 Roberto Sassu New
[v2,2/6] reiserfs: Add missing calls to reiserfs_security_free() evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-21 Roberto Sassu New
[v2,1/6] xattr: Complete constify ->name member of "struct xattr" evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-21 Roberto Sassu New
[v3,18/18] keyctl_pkey: Add pkey parameters saltlen and mgfhash for PSS Untitled series #470177 - - - --- 2021-04-20 Varad Gautam New
[RFC] integrity: fix null ptr dereference in integrity_inode_free() [RFC] integrity: fix null ptr dereference in integrity_inode_free() - - - --- 2021-04-19 Mimi Zohar New
[v3] lsm:fix a missing-check bug in smack_sb_eat_lsm_opts() [v3] lsm:fix a missing-check bug in smack_sb_eat_lsm_opts() - - - --- 2021-04-19 Zhongjun Tan New
[3/3] include/linux: Update LSM hook text part2 LSM Documentation - Render lsm_hooks.h for kernel_docs - - - --- 2021-04-16 Richard Haines New
[2/3] include/linux: Update LSM hook text part1 LSM Documentation - Render lsm_hooks.h for kernel_docs - - - --- 2021-04-16 Richard Haines New
[1/3] Documentation/security: Update LSM security hook text LSM Documentation - Render lsm_hooks.h for kernel_docs - - - --- 2021-04-16 Richard Haines New
[v2] lsm:fix a missing-check bug in smack_sb_eat_lsm_opts() [v2] lsm:fix a missing-check bug in smack_sb_eat_lsm_opts() - - - --- 2021-04-16 Zhongjun Tan New
lsm:fix a missing-check bug in smack_sb_eat_lsm_opts() lsm:fix a missing-check bug in smack_sb_eat_lsm_opts() - - - --- 2021-04-16 Zhongjun Tan New
[RESEND,v5] proc: Allow pid_revalidate() during LOOKUP_RCU [RESEND,v5] proc: Allow pid_revalidate() during LOOKUP_RCU - - - --- 2021-04-16 Stephen Brennan New
[5/5] evm: Support multiple LSMs providing an xattr evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-15 Roberto Sassu New
[4/5] evm: Align evm_inode_init_security() definition with LSM infrastructure evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-15 Roberto Sassu New
[3/5] security: Pass xattrs allocated by LSMs to the inode_init_security hook evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-15 Roberto Sassu New
[2/5] security: Support multiple LSMs implementing the inode_init_security hook evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-15 Roberto Sassu New
[1/5] xattr: Complete constify ->name member of "struct xattr" evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-15 Roberto Sassu New
KEYS: trusted: fix a couple error pointer dereferences KEYS: trusted: fix a couple error pointer dereferences - 1 - --- 2021-04-14 Dan Carpenter New
security: keys: trusted: prevent memory leak in error path security: keys: trusted: prevent memory leak in error path - - - --- 2021-04-13 Muhammad Usama Anjum New
[next] KEYS: trusted: Fix missing null return from kzalloc call [next] KEYS: trusted: Fix missing null return from kzalloc call - 2 - --- 2021-04-12 Colin Ian King New
[-next] KEYS: trusted: Switch to kmemdup_nul() [-next] KEYS: trusted: Switch to kmemdup_nul() - - - --- 2021-04-12 Wei Yongjun New
security: commoncap: clean up kernel-doc comments security: commoncap: clean up kernel-doc comments - 1 - --- 2021-04-12 Randy Dunlap New
[RFC] Tainting tasks after poking at them [RFC] Tainting tasks after poking at them - - - --- 2021-04-10 Alexey Dobriyan New
[GIT,PULL] SELinux fixes for v5.12 (#2) [GIT,PULL] SELinux fixes for v5.12 (#2) - - - --- 2021-04-09 Paul Moore New
[v4,3/3] ima: enable loading of build time generated key on .ima keyring ima: kernel build support for loading the kernel module signing key 1 - - --- 2021-04-09 Nayna Jain New
[v4,2/3] ima: enable signing of modules with build time generated key ima: kernel build support for loading the kernel module signing key 1 - - --- 2021-04-09 Nayna Jain New
[v4,1/3] keys: cleanup build time module signing keys ima: kernel build support for loading the kernel module signing key - 3 - --- 2021-04-09 Nayna Jain New
[7/7] evm: Extend evm= with allow_metadata_writes and complete values ima/evm: Small enhancements - - - --- 2021-04-09 Roberto Sassu New
[6/7] evm: Allow choice of hash algorithm for HMAC ima/evm: Small enhancements - - - --- 2021-04-09 Roberto Sassu New
« 1 2 3 48 9 »