Show patches with: State = Action Required       |   108 patches
« 1 2 »
Patch Series A/R/T S/W/F Date Submitter Delegate State
[userspace] travis: run only selinux-testsuite [userspace] travis: run only selinux-testsuite - - - --- 2020-11-27 Ondrej Mosnacek New
[3/3] Simplify the tarball generating scripts [1/3] Introduce VERSION file for selinux - - - --- 2020-11-27 Petr Lautrbach New
[2/3] Use X.Y instead of date for release tag [1/3] Introduce VERSION file for selinux - - - --- 2020-11-27 Petr Lautrbach New
[1/3] Introduce VERSION file for selinux [1/3] Introduce VERSION file for selinux - - - --- 2020-11-27 Petr Lautrbach New
[v1,1/1] selinux-testsuite: Add userfaultfd test [v1,1/1] selinux-testsuite: Add userfaultfd test - - - --- 2020-11-25 Lokesh Gidra New
[1/1] scripts/ci: add configuration for a Vagrant virtual machine [1/1] scripts/ci: add configuration for a Vagrant virtual machine - - - --- 2020-11-24 Nicolas Iooss New
[1/1] Add configuration to build and run tests in GitHub Actions [1/1] Add configuration to build and run tests in GitHub Actions 1 - - --- 2020-11-24 Nicolas Iooss New
[v23,23/23] AppArmor: Remove the exclusive flag [v23,01/23] LSM: Infrastructure management of the sock security 2 1 - --- 2020-11-20 Casey Schaufler New
[v23,22/23] LSM: Add /proc attr entry for full LSM context [v23,01/23] LSM: Infrastructure management of the sock security - 1 - --- 2020-11-20 Casey Schaufler New
[v23,21/23] Audit: Add a new record for multiple object LSM attributes [v23,01/23] LSM: Infrastructure management of the sock security - - - --- 2020-11-20 Casey Schaufler New
[v23,20/23] Audit: Add new record for multiple process LSM attributes [v23,01/23] LSM: Infrastructure management of the sock security - - - --- 2020-11-20 Casey Schaufler New
[v23,19/23] audit: add support for non-syscall auxiliary records [v23,01/23] LSM: Infrastructure management of the sock security - - - --- 2020-11-20 Casey Schaufler New
[v23,18/23] LSM: Verify LSM display sanity in binder [v23,01/23] LSM: Infrastructure management of the sock security 2 2 - --- 2020-11-20 Casey Schaufler New
[v23,17/23] NET: Store LSM netlabel data in a lsmblob [v23,01/23] LSM: Infrastructure management of the sock security 2 2 - --- 2020-11-20 Casey Schaufler New
[v23,16/23] LSM: security_secid_to_secctx in netlink netfilter [v23,01/23] LSM: Infrastructure management of the sock security 2 2 - --- 2020-11-20 Casey Schaufler New
[v23,15/23] LSM: Use lsmcontext in security_inode_getsecctx [v23,01/23] LSM: Infrastructure management of the sock security 2 1 - --- 2020-11-20 Casey Schaufler New
[v23,14/23] LSM: Use lsmcontext in security_secid_to_secctx [v23,01/23] LSM: Infrastructure management of the sock security 2 1 - --- 2020-11-20 Casey Schaufler New
[v23,13/23] LSM: Ensure the correct LSM context releaser [v23,01/23] LSM: Infrastructure management of the sock security 1 2 - --- 2020-11-20 Casey Schaufler New
[v23,12/23] LSM: Specify which LSM to display [v23,01/23] LSM: Infrastructure management of the sock security - - - --- 2020-11-20 Casey Schaufler New
[v23,11/23] IMA: Change internal interfaces to use lsmblobs [v23,01/23] LSM: Infrastructure management of the sock security 1 2 - --- 2020-11-20 Casey Schaufler New
[v23,10/23] LSM: Use lsmblob in security_cred_getsecid [v23,01/23] LSM: Infrastructure management of the sock security 2 2 - --- 2020-11-20 Casey Schaufler New
[v23,09/23] LSM: Use lsmblob in security_inode_getsecid [v23,01/23] LSM: Infrastructure management of the sock security 2 2 - --- 2020-11-20 Casey Schaufler New
[v23,08/23] LSM: Use lsmblob in security_task_getsecid [v23,01/23] LSM: Infrastructure management of the sock security 2 2 - --- 2020-11-20 Casey Schaufler New
[v23,07/23] LSM: Use lsmblob in security_ipc_getsecid [v23,01/23] LSM: Infrastructure management of the sock security 2 2 - --- 2020-11-20 Casey Schaufler New
[v23,06/23] LSM: Use lsmblob in security_secid_to_secctx [v23,01/23] LSM: Infrastructure management of the sock security - - - --- 2020-11-20 Casey Schaufler New
[v23,05/23] LSM: Use lsmblob in security_secctx_to_secid [v23,01/23] LSM: Infrastructure management of the sock security - - - --- 2020-11-20 Casey Schaufler New
[v23,04/23] LSM: Use lsmblob in security_kernel_act_as [v23,01/23] LSM: Infrastructure management of the sock security 2 2 - --- 2020-11-20 Casey Schaufler New
[v23,03/23] LSM: Use lsmblob in security_audit_rule_match [v23,01/23] LSM: Infrastructure management of the sock security 2 2 - --- 2020-11-20 Casey Schaufler New
[v23,02/23] LSM: Create and manage the lsmblob data structure. [v23,01/23] LSM: Infrastructure management of the sock security 3 - - --- 2020-11-20 Casey Schaufler New
[v23,01/23] LSM: Infrastructure management of the sock security [v23,01/23] LSM: Infrastructure management of the sock security 2 2 - --- 2020-11-20 Casey Schaufler New
[v6,8/8] selinux: measure state and hash of the policy using IMA IMA: support for measuring kernel integrity critical data - - - --- 2020-11-19 Tushar Sugandhi New
[v6,7/8] IMA: add a built-in policy rule for critical data measurement IMA: support for measuring kernel integrity critical data - - - --- 2020-11-19 Tushar Sugandhi New
[v6,6/8] IMA: add support to critical data hook to limit data sources for measurement IMA: support for measuring kernel integrity critical data - - - --- 2020-11-19 Tushar Sugandhi New
[v6,5/8] IMA: extend policy to add data sources as a critical data measurement constraint IMA: support for measuring kernel integrity critical data - - - --- 2020-11-19 Tushar Sugandhi New
[v6,4/8] IMA: add policy rule to measure critical data IMA: support for measuring kernel integrity critical data - - - --- 2020-11-19 Tushar Sugandhi New
[v6,3/8] IMA: define a hook to measure kernel integrity critical data IMA: support for measuring kernel integrity critical data - - - --- 2020-11-19 Tushar Sugandhi New
[v6,2/8] IMA: add support to measure buffer data hash IMA: support for measuring kernel integrity critical data - - - --- 2020-11-19 Tushar Sugandhi New
[v6,1/8] IMA: generalize keyring specific measurement constructs IMA: support for measuring kernel integrity critical data - - - --- 2020-11-19 Tushar Sugandhi New
vfs: fix fsconfig(2) LSM mount option handling for btrfs vfs: fix fsconfig(2) LSM mount option handling for btrfs - - 1 --- 2020-11-18 Ondrej Mosnacek New
[6/6] libspepol/cil: Use the macro FLAVOR() whenever possible libsepol/cil: Various CIL cleanups - - - --- 2020-11-16 James Carter New
[5/6] libsepol/cil: Use the macro NODE() whenever possible libsepol/cil: Various CIL cleanups - - - --- 2020-11-16 James Carter New
[4/6] libsepol/cil: Remove unnecessary assignment in cil_resolve_name_keep_aliases() libsepol/cil: Various CIL cleanups - - - --- 2020-11-16 James Carter New
[3/6] libsepol/cil: Remove unused field from struct cil_args_resolve libsepol/cil: Various CIL cleanups - - - --- 2020-11-16 James Carter New
[2/6] libsepol/cil: Git rid of unnecessary check in cil_gen_node() libsepol/cil: Various CIL cleanups - - - --- 2020-11-16 James Carter New
[1/6] libsepol/cil: cil_tree_walk() helpers should use CIL_TREE_SKIP_* libsepol/cil: Various CIL cleanups - - - --- 2020-11-16 James Carter New
[v13,4/4] userfaultfd: use secure anon inodes for userfaultfd SELinux support for anonymous inodes and UFFD - 1 - --- 2020-11-12 Lokesh Gidra pcmoore New
[v13,3/4] selinux: teach SELinux about anonymous inodes SELinux support for anonymous inodes and UFFD - - - --- 2020-11-12 Lokesh Gidra pcmoore New
[v13,2/4] fs: add LSM-supporting anon-inode interface SELinux support for anonymous inodes and UFFD - 1 - --- 2020-11-12 Lokesh Gidra pcmoore New
[v13,1/4] security: add inode_init_security_anon() LSM hook SELinux support for anonymous inodes and UFFD - 1 - --- 2020-11-12 Lokesh Gidra pcmoore New
[RFC] docs: ABI: ABI documentation for procfs attribute files used by multiple LSMs [RFC] docs: ABI: ABI documentation for procfs attribute files used by multiple LSMs - - - --- 2020-11-10 Casey Schaufler New
[v5,7/7] selinux: measure state and hash of the policy using IMA IMA: Infrastructure for measurement of critical kernel data - - - --- 2020-11-01 Tushar Sugandhi pcmoore New
[v5,6/7] IMA: add critical_data to the built-in policy rules IMA: Infrastructure for measurement of critical kernel data - - - --- 2020-11-01 Tushar Sugandhi pcmoore New
[v5,5/7] IMA: validate supported kernel data sources before measurement IMA: Infrastructure for measurement of critical kernel data - - - --- 2020-11-01 Tushar Sugandhi pcmoore New
[v5,4/7] IMA: add policy to measure critical data IMA: Infrastructure for measurement of critical kernel data - - - --- 2020-11-01 Tushar Sugandhi pcmoore New
[v5,3/7] IMA: add hook to measure critical data IMA: Infrastructure for measurement of critical kernel data - - - --- 2020-11-01 Tushar Sugandhi pcmoore New
[v5,2/7] IMA: update process_buffer_measurement to measure buffer hash IMA: Infrastructure for measurement of critical kernel data - - - --- 2020-11-01 Tushar Sugandhi pcmoore New
[v5,1/7] IMA: generalize keyring specific measurement constructs IMA: Infrastructure for measurement of critical kernel data - - - --- 2020-11-01 Tushar Sugandhi pcmoore New
[RESEND,v18,4/4] overlayfs: inode_owner_or_capable called during execv Untitled series #368853 - - - --- 2020-10-22 Mark Salyzyn pcmoore New
[RESEND,v18,3/4] overlayfs: override_creds=off option bypass creator_cred overlayfs override_creds=off & nested get xattr fix - - - --- 2020-10-21 Mark Salyzyn pcmoore New
[RESEND,v18,2/4] overlayfs: handle XATTR_NOSECURITY flag for get xattr method overlayfs override_creds=off & nested get xattr fix - - - --- 2020-10-21 Mark Salyzyn pcmoore New
[RESEND,v18,1/4] Add flags option to get xattr method paired to __vfs_getxattr overlayfs override_creds=off & nested get xattr fix 5 1 - --- 2020-10-21 Mark Salyzyn pcmoore New
[RFC] sched: only issue an audit on privileged operation [RFC] sched: only issue an audit on privileged operation - - - --- 2020-09-04 Christian Göttsche pcmoore New
[RFC,V2,2/2] selinux-testsuite: Run SCTP tests using remote server selinux-testsuite: Run tests using remote server - - - --- 2020-08-26 Richard Haines omos New
[RFC,V2,1/2] selinux-testsuite: Run tests using remote server selinux-testsuite: Run tests using remote server - - - --- 2020-08-26 Richard Haines omos New
selinux: make use of variables when defining libdir and includedir selinux: make use of variables when defining libdir and includedir - - - --- 2020-07-16 W. Michael Petullo New
chcat: don't crash if access to binary policy is prohibited chcat: don't crash if access to binary policy is prohibited - - - --- 2020-05-09 bauen1 New
[RFC,5/5] selinux-testsuite: add testing for unprivileged sandboxing capability [RFC,1/5] selinux-testsuite: add tests/sandbox/nodir_no_allow.cil - - - --- 2020-03-13 Stephen Smalley omos New
[RFC,4/5] selinux-testsuite: add tests/sandbox/rxdir_rx_allow.cil [RFC,1/5] selinux-testsuite: add tests/sandbox/nodir_no_allow.cil - - - --- 2020-03-13 Stephen Smalley omos New
[RFC,3/5] selinux-testsuite: add tests/sandbox/rxdir_no_allow.cil [RFC,1/5] selinux-testsuite: add tests/sandbox/nodir_no_allow.cil - - - --- 2020-03-13 Stephen Smalley omos New
[RFC,2/5] selinux-testsuite: add tests/sandbox/nodir_rx_allow.cil [RFC,1/5] selinux-testsuite: add tests/sandbox/nodir_no_allow.cil - - - --- 2020-03-13 Stephen Smalley omos New
[RFC,1/5] selinux-testsuite: add tests/sandbox/nodir_no_allow.cil [RFC,1/5] selinux-testsuite: add tests/sandbox/nodir_no_allow.cil - - - --- 2020-03-13 Stephen Smalley omos New
[RFC] libsepol,secilc,policycoreutils: add unprivileged sandboxing capability [RFC] libsepol,secilc,policycoreutils: add unprivileged sandboxing capability - - - --- 2020-03-13 Stephen Smalley pcmoore New
[RFC] selinux: add unprivileged sandboxing capability [RFC] selinux: add unprivileged sandboxing capability - - - --- 2020-03-13 Stephen Smalley pcmoore New
[RFC,v3] security,capability: pass object information to security_capable [RFC,v3] security,capability: pass object information to security_capable - - - --- 2019-08-15 Aaron Goidel pcmoore New
[RFC] audit, security: allow LSMs to selectively enable audit collection [RFC] audit, security: allow LSMs to selectively enable audit collection - - - --- 2019-08-15 Aaron Goidel pcmoore New
[v4,21/21] fuse: Allow user namespace mounts 1 - - --- 2016-04-26 Seth Forshee New
[v4,20/21] fuse: Restrict allow_other to the superblock's namespace or a descendant 2 - - --- 2016-04-26 Seth Forshee New
[v4,19/21] fuse: Support fuse filesystems outside of init_user_ns - - - --- 2016-04-26 Seth Forshee New
[v4,18/21] fuse: Add support for pid namespaces 1 - - --- 2016-04-26 Seth Forshee New
[v4,17/21] capabilities: Allow privileged user in s_user_ns to set security.* xattrs 2 - - --- 2016-04-26 Seth Forshee New
[v4,16/21] fs: Allow superblock owner to access do_remount_sb() 2 - - --- 2016-04-26 Seth Forshee New
[v4,15/21] fs: Don't remove suid for CAP_FSETID in s_user_ns 1 - - --- 2016-04-26 Seth Forshee New
[v4,14/21] fs: Allow superblock owner to change ownership of inodes with unmappable ids 1 - - --- 2016-04-26 Seth Forshee New
[v4,13/21] fs: Update posix_acl support to handle user namespace mounts 1 - - --- 2016-04-26 Seth Forshee New
[v4,12/21] fs: Refuse uid/gid changes which don't map into s_user_ns 1 - - --- 2016-04-26 Seth Forshee New
[v4,11/21] cred: Reject inodes with invalid ids in set_create_file_as() 1 - - --- 2016-04-26 Seth Forshee New
[v4,10/21] fs: Check for invalid i_uid in may_follow_link() 1 1 - --- 2016-04-26 Seth Forshee New
[v4,09/21] Smack: Handle labels consistently in untrusted mounts 1 - - --- 2016-04-26 Seth Forshee New
[v4,08/21] userns: Replace in_userns with current_in_userns 2 - - --- 2016-04-26 Seth Forshee New
[v4,07/21] selinux: Add support for unprivileged mounts from user namespaces 2 - - --- 2016-04-26 Seth Forshee New
[v4,06/21] fs: Treat foreign mounts as nosuid 2 - - --- 2016-04-26 Seth Forshee New
[v4,05/21] block_dev: Check permissions towards block device inode when mounting 1 - - --- 2016-04-26 Seth Forshee New
[v4,04/21] block_dev: Support checking inode permissions in lookup_bdev() 1 - - --- 2016-04-26 Seth Forshee New
[v4,03/21] fs: Allow sysfs and cgroupfs to share super blocks between user namespaces 1 - - --- 2016-04-26 Seth Forshee New
[v4,02/21] fs: Remove check of s_user_ns for existing mounts in fs_fully_visible() - - - --- 2016-04-26 Seth Forshee New
[v4,01/21] fs: fix a posible leak of allocated superblock 1 - - --- 2016-04-26 Seth Forshee New
[v4,19/21] fuse: Support fuse filesystems outside of init_user_ns - - - --- 2016-04-26 Seth Forshee New
[v4,18/21] fuse: Add support for pid namespaces 1 - - --- 2016-04-26 Seth Forshee New
[v4,16/21] fs: Allow superblock owner to access do_remount_sb() 2 - - --- 2016-04-26 Seth Forshee New
[v4,14/21] fs: Allow superblock owner to change ownership of inodes with unmappable ids 1 - - --- 2016-04-26 Seth Forshee New
« 1 2 »