- 95ca907 selinux: handle MPTCP consistently with TCP by Paolo Abeni · 4 years, 1 month ago
- ca5b877 Merge tag 'selinux-pr-20201214' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux by Linus Torvalds · 4 years, 1 month ago
- 41dd959 security: add const qualifier to struct sock in various places by Florian Westphal · 4 years, 2 months ago
- 3df98d7 lsm,selinux: pass flowi_common instead of flowi to the LSM hooks by Paul Moore · 4 years, 4 months ago
- b2d99bc selinux: Fix fall-through warnings for Clang by Gustavo A. R. Silva · 4 years, 2 months ago
- b159e86 selinux: drop super_block backpointer from superblock_security_struct by Ondrej Mosnacek · 4 years, 2 months ago
- 200ea5a selinux: fix inode_doinit_with_dentry() LABEL_INVALID error handling by Paul Moore · 4 years, 2 months ago
- 83370b3 selinux: fix error initialization in inode_doinit_with_dentry() by Tianyue Ren · 4 years, 3 months ago
- 726eb70 Merge tag 'char-misc-5.10-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc by Linus Torvalds · 4 years, 3 months ago
- 7b54081 Merge tag 'selinux-pr-20201012' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux by Linus Torvalds · 4 years, 3 months ago
- 2039bda LSM: Add "contents" flag to kernel_read_file hook by Kees Cook · 4 years, 4 months ago
- b64fcae LSM: Introduce kernel_post_load_data() hook by Kees Cook · 4 years, 4 months ago
- b89999d0 fs/kernel_read_file: Split into separate include file by Scott Branden · 4 years, 4 months ago
- 8861d0a selinux: Add helper functions to get and set checkreqprot by Lakshmi Ramasubramanian · 4 years, 4 months ago
- 9ff9abc selinux: move policy mutex to selinux_state, use in lockdep checks by Stephen Smalley · 4 years, 5 months ago
- 1b8b31a selinux: convert policy read-write lock to RCU by Stephen Smalley · 4 years, 5 months ago
- c76a2f9 selinux: delete repeated words in comments by Randy Dunlap · 4 years, 5 months ago
- df561f66 treewide: Use fallthrough pseudo-keyword by Gustavo A. R. Silva · 4 years, 5 months ago
- 9530a3e selinux: permit removing security.selinux xattr before policy load by Stephen Smalley · 4 years, 5 months ago
- c8e2226 selinux: allow reading labels before policy is loaded by Jonathan Lebon · 4 years, 8 months ago
- 6c32978 Merge tag 'notifications-20200601' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs by Linus Torvalds · 4 years, 7 months ago
- 15a2bc4 Merge branch 'exec-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiederm/user-namespace by Linus Torvalds · 4 years, 8 months ago
- b8bff59 exec: Factor security_bprm_creds_for_exec out of security_bprm_set_creds by Eric W. Biederman · 4 years, 10 months ago
- 3e412cc selinux: Implement the watch_key security hook by David Howells · 5 years ago
- 8c0637e keys: Make the KEY_NEED_* perms an enum rather than a mask by David Howells · 4 years, 8 months ago
- 39e16d9 Merge tag 'selinux-pr-20200430' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux by Linus Torvalds · 4 years, 9 months ago
- fb73974 selinux: properly handle multiple messages in selinux_netlink_send() by Paul Moore · 4 years, 9 months ago
- b3aa112 Merge tag 'selinux-pr-20200330' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux by Linus Torvalds · 4 years, 10 months ago
- e4cfa05 selinux: Add xfs quota command types by Richard Haines · 5 years ago
- 4ca54d3 security: selinux: allow per-file labeling for bpffs by Connor O'Brien · 5 years ago
- a5650ac Merge tag 'selinux-pr-20200210' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux by Linus Torvalds · 5 years ago
- 7470d0d1 selinux: allow kernfs symlinks to inherit parent directory context by Christian Göttsche · 5 years ago
- e9c38f9 Documentation,selinux: deprecate setting checkreqprot to 1 by Stephen Smalley · 5 years ago
- 4b36cb7 selinux: move status variables out of selinux_ss by Ondrej Mosnacek · 5 years ago
- c9d35ee Merge branch 'merge.nfs-fs_parse.1' of git://git.kernel.org/pub/scm/linux/kernel/git/viro/vfs by Linus Torvalds · 5 years ago
- d7167b1 fs_parse: fold fs_parameter_desc/fs_parameter_spec by Al Viro · 5 years ago
- 96cafb9 fs_parser: remove fs_parameter_description name field by Eric Sandeen · 5 years ago
- a20456a selinux: fix typo in filesystem name by Hridya Valsaraju · 5 years ago
- 98aa003 selinux: fix regression introduced by move_mount(2) syscall by Stephen Smalley · 5 years ago
- cb89e24 selinux: remove redundant allocation and helper functions by Paul Moore · 5 years ago
- df4779b selinux: remove redundant selinux_nlmsg_perm by Huaisheng Ye · 5 years ago
- cfff75d selinux: reorder hooks to make runtime disable less broken by Ondrej Mosnacek · 5 years ago
- 65cddd5 selinux: treat atomic flags more carefully by Ondrej Mosnacek · 5 years ago
- b78b7d5 selinux: make default_noexec read-only after init by Stephen Smalley · 5 years ago
- b82f3f6 selinux: remove redundant msg_msg_alloc_security by Huaisheng Ye · 5 years ago
- 7a4b519 selinux: allow per-file labelling for binderfs by Hridya Valsaraju · 5 years ago
- 6c5a682 selinux: clean up selinux_enabled/disabled/enforcing_boot by Stephen Smalley · 5 years ago
- 210a292 selinux: remove unnecessary selinux cred request by Yang Guo · 5 years ago
- 5298d0b selinux: clean up selinux_inode_permission MAY_NOT_BLOCK tests by Stephen Smalley · 5 years ago
- 0188d5c selinux: fall back to ref-walk if audit is required by Stephen Smalley · 5 years ago
- 1a37079 selinux: revert "stop passing MAY_NOT_BLOCK to the AVC upon follow_link" by Stephen Smalley · 5 years ago
- 59438b46 security,lockdown,selinux: implement SELinux lockdown by Stephen Smalley · 5 years ago
- ceb3074 Merge tag 'y2038-cleanups-5.5' of git://git.kernel.org:/pub/scm/linux/kernel/git/arnd/playground by Linus Torvalds · 5 years ago
- ba75082 Merge tag 'selinux-pr-20191126' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux by Linus Torvalds · 5 years ago
- 8c39f71 Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net by Linus Torvalds · 5 years ago
- 82f31eb net: port < inet_prot_sock(net) --> inet_port_requires_bind_service(net, port) by Maciej Żenczykowski · 5 years ago
- ddbc7d0 y2038: move itimer reset into itimer.c by Arnd Bergmann · 5 years ago
- da97e18 perf_event: Add support for LSM and SELinux checks by Joel Fernandes (Google) · 5 years ago
- 3e3e24b selinux: allow labeling before policy is loaded by Jonathan Lebon · 5 years ago
- 5825a95 Merge tag 'selinux-pr-20190917' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux by Linus Torvalds · 5 years ago
- 169ce0c selinux: fix residual uses of current_security() for the SELinux blob by Stephen Smalley · 5 years ago
- ac5656d fanotify, inotify, dnotify, security: add security hook for fs notifications by Aaron Goidel · 5 years ago
- 028db3e Revert "Merge tag 'keys-acl-20190703' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs" by Linus Torvalds · 6 years ago
- 8b68150 Merge branch 'next-integrity' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity by Linus Torvalds · 6 years ago
- 0f75ef6 Merge tag 'keys-acl-20190703' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs by Linus Torvalds · 6 years ago
- 7c0f896 Merge tag 'selinux-pr-20190702' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux by Linus Torvalds · 6 years ago
- 2e12256 keys: Replace uid/gid/perm permissions checking with an ACL by David Howells · 6 years ago
- d2912cb treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500 by Thomas Gleixner · 6 years ago
- 42df744 LSM: switch to blocking policy update notifiers by Janne Karhunen · 6 years ago
- 464c258 selinux: fix empty write to keycreate file by Ondrej Mosnacek · 6 years ago
- fec6375 selinux: fix a missing-check bug in selinux_sb_eat_lsm_opts() by Gen Zhang · 6 years ago
- e2e0e09 selinux: fix a missing-check bug in selinux_add_mnt_opt( ) by Gen Zhang · 6 years ago
- 05174c9 selinux: do not report error on connect(AF_UNSPEC) by Paolo Abeni · 6 years ago
- e711ab9 Revert "selinux: do not report error on connect(AF_UNSPEC)" by Paolo Abeni · 6 years ago
- c7e0d6c selinux: do not report error on connect(AF_UNSPEC) by Paolo Abeni · 6 years ago
- c750e69 selinux: Check address length before reading address family by Tetsuo Handa · 6 years ago
- 1537ad1 kernfs: fix xattr name handling in LSM helpers by Ondrej Mosnacek · 6 years ago
- c72c4cd selinux: Make selinux_kernfs_init_security static by YueHaibing · 6 years ago
- ec882da selinux: implement the kernfs_init_security hook by Ondrej Mosnacek · 6 years ago
- b754026 selinux: try security xattr after genfs for kernfs filesystems by Ondrej Mosnacek · 6 years ago
- fa3d493 Merge tag 'selinux-pr-20190312' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux by Linus Torvalds · 6 years ago
- 7b47a9e Merge branch 'work.mount' of git://git.kernel.org/pub/scm/linux/kernel/git/viro/vfs by Linus Torvalds · 6 years ago
- 3815a24 security/selinux: fix SECURITY_LSM_NATIVE_LABELS on reused superblock by J. Bruce Fields · 6 years ago
- 292c997 selinux: add the missing walk_size + len check in selinux_sctp_bind_connect by Xin Long · 6 years ago
- 1a29e85 Merge tag 'docs-5.1' of git://git.lwn.net/linux by Linus Torvalds · 6 years ago
- 3ac96c3 Merge tag 'selinux-pr-20190305' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux by Linus Torvalds · 6 years ago
- 0b52075 introduce cloning of fs_context by Al Viro · 6 years ago
- 442155c selinux: Implement the new mount API LSM hooks by David Howells · 6 years ago
- d61330c doc: sctp: Merge and clean up rst files by Kees Cook · 6 years ago
- 1cfb2a5 LSM: Make lsm_early_cred() and lsm_early_task() local functions. by Tetsuo Handa · 6 years ago
- 53e0c2a selinux: do not override context on context mounts by Ondrej Mosnacek · 6 years ago
- a83d6dd selinux: never allow relabeling on context mounts by Ondrej Mosnacek · 6 years ago
- e46e01e selinux: stop passing MAY_NOT_BLOCK to the AVC upon follow_link by Stephen Smalley · 6 years ago
- 3a28cff selinux: avoid silent denials in permissive mode under RCU walk by Stephen Smalley · 6 years ago
- c1a85a0 LSM: generalize flag passing to security_capable by Micah Morton · 6 years ago
- ecd5f82 LSM: Infrastructure management of the ipc security blob by Casey Schaufler · 6 years ago
- 7c65382 SELinux: Abstract use of ipc security blobs by Casey Schaufler · 6 years ago
- afb1cbe3 LSM: Infrastructure management of the inode security by Casey Schaufler · 6 years ago
- 80788c2 SELinux: Abstract use of inode security blob by Casey Schaufler · 6 years ago
- 33bf60c LSM: Infrastructure management of the file security by Casey Schaufler · 6 years ago