- 3cee607 apparmor: handle idmapped mounts by Christian Brauner · 4 years ago
- c7c7a1a1 xattr: handle idmapped mounts by Tycho Andersen · 4 years ago
- df561f66 treewide: Use fallthrough pseudo-keyword by Gustavo A. R. Silva · 4 years, 5 months ago
- 453431a mm, treewide: rename kzfree() to kfree_sensitive() by Waiman Long · 4 years, 5 months ago
- a2b4470 Merge tag 'apparmor-pr-2020-06-07' of git://git.kernel.org/pub/scm/linux/kernel/git/jj/linux-apparmor by Linus Torvalds · 4 years, 7 months ago
- 15a2bc4 Merge branch 'exec-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiederm/user-namespace by Linus Torvalds · 4 years, 7 months ago
- a0b845f apparmor: fix potential label refcnt leak in aa_change_profile by Xiyu Yang · 4 years, 10 months ago
- b8bff59 exec: Factor security_bprm_creds_for_exec out of security_bprm_set_creds by Eric W. Biederman · 4 years, 10 months ago
- 01df52d apparmor: remove duplicate check of xattrs on profile attachment. by John Johansen · 5 years ago
- 0df34a6 apparmor: add outofband transition and use it in xattr match by John Johansen · 5 years ago
- 3ed4aaa9 apparmor: fix nnp subset test for unconfined by John Johansen · 5 years ago
- 8c62ed2 apparmor: fix aa_xattrs_match() may sleep while holding a RCU lock by John Johansen · 5 years ago
- 79e178a Merge tag 'apparmor-pr-2019-12-03' of git://git.kernel.org/pub/scm/linux/kernel/git/jj/linux-apparmor by Linus Torvalds · 5 years ago
- 341c1fd apparmor: make it so work buffers can be allocated from atomic context by John Johansen · 5 years ago
- 8ac2ca3 apparmor: Switch to GFP_KERNEL where possible by Sebastian Andrzej Siewior · 6 years ago
- df32333 apparmor: Use a memory pool instead per-CPU caches by Sebastian Andrzej Siewior · 6 years ago
- b886d83c treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 441 by Thomas Gleixner · 6 years ago
- ae5906c Merge branch 'next-general' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security by Linus Torvalds · 6 years ago
- 09186e5 security: mark expected switch fall-throughs and add a missing break by Gustavo A. R. Silva · 6 years ago
- d6d478ae apparmor: Fix aa_label_build() error handling for failed merges by John Johansen · 6 years ago
- 69b5a44 AppArmor: Abstract use of cred security blob by Casey Schaufler · 6 years ago
- 24b87a1 apparmor: Fix failure to audit context info in build_change_hat by John Johansen · 6 years ago
- b2c2086 apparmor: fix typo "loosen" by Zygmunt Krynicki · 7 years ago
- a61ecd3 apparmor: fix error returns checks by making size a ssize_t by Colin Ian King · 7 years ago
- 21f6066 apparmor: improve overlapping domain attachment resolution by John Johansen · 7 years ago
- 73f488c apparmor: convert attaching profiles via xattrs to use dfa matching by John Johansen · 7 years ago
- 8e51f90 apparmor: Add support for attaching profiles via xattr, presence and value by Matthew Garrett · 7 years ago
- 9fcf78c apparmor: update domain transitions that are subsets of confinement at nnp by John Johansen · 7 years ago
- d8889d4 apparmor: move context.h to cred.h by John Johansen · 7 years ago
- de62de5 apparmor: move task related defines and fns to task.X files by John Johansen · 7 years ago
- f175221 apparmor: rename tctx to ctx by John Johansen · 8 years ago
- d9087c4 apparmor: drop cred_ctx and reference the label directly by John Johansen · 8 years ago
- 3b529a7 apparmor: move task domain change info to task security by John Johansen · 8 years ago
- 4d2f8ba apparmor: rename task_ctx to the more accurate cred_ctx by John Johansen · 8 years ago
- 1a3881d apparmor: Fix regression in profile conflict logic by Matthew Garrett · 7 years ago
- 5d7c44e apparmor: fix locking when creating a new complain profile. by John Johansen · 7 years ago
- 06d426d apparmor: fix profile attachment for special unconfined profiles by John Johansen · 7 years ago
- 844b829 apparmor: ensure that undecidable profile attachments fail by John Johansen · 7 years ago
- 79444df Merge tag 'apparmor-pr-2017-09-22' of git://git.kernel.org/pub/scm/linux/kernel/git/jj/linux-apparmor by Linus Torvalds · 7 years ago
- 2ea3ffb apparmor: add mount mediation by John Johansen · 7 years ago
- 993b3ab apparmor: Refactor to remove bprm_secureexec hook by Kees Cook · 7 years ago
- ddb4a14 exec: Rename bprm->cred_prepared to called_set_creds by Kees Cook · 7 years ago
- e00b02bb apparmor: move change_profile mediation to using labels by John Johansen · 8 years ago
- 89dbf19 apparmor: move change_hat mediation to using labels by John Johansen · 8 years ago
- 93c98a4 apparmor: move exec domain mediation to using labels by John Johansen · 8 years ago
- 98c3d18 apparmor: update aa_audit_file() to use labels by John Johansen · 8 years ago
- b2d09ae apparmor: move ptrace checks to using labels by John Johansen · 8 years ago
- 637f688 apparmor: switch from profiles to using labels on contexts by John Johansen · 8 years ago
- df8073c apparmor: convert aa_change_XXX bool parameters to flags by John Johansen · 8 years ago
- cf797c0 apparmor: convert to profile block critical sections by John Johansen · 8 years ago
- fe86482 apparmor: move bprm_committing_creds/committed_creds to lsm.c by John Johansen · 8 years ago
- 2d679f3 apparmor: switch from file_perms to aa_perms by John Johansen · 8 years ago
- 4227c33 apparmor: Move path lookup to using preallocated buffers by John Johansen · 8 years ago
- 72c8a76 apparmor: allow profiles to provide info to disconnected paths by John Johansen · 8 years ago
- f1ef09f Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiederm/user-namespace by Linus Torvalds · 8 years ago
- 9227dd2 exec: Remove LSM_UNSAFE_PTRACE_CAP by Eric W. Biederman · 8 years ago
- aa9a39a apparmor: convert change_profile to use fqname later to give better control by John Johansen · 8 years ago
- ef88a7a apparmor: change aad apparmor_audit_data macro to a fn macro by John Johansen · 8 years ago
- 47f6e5c apparmor: change op from int to const char * by John Johansen · 8 years ago
- 55a26eb apparmor: rename context abreviation cxt to the more standard ctx by John Johansen · 8 years ago
- 181f7c9 apparmor: name null-XXX profiles after the executable by John Johansen · 8 years ago
- 98849df apparmor: rename namespace to ns to improve code line lengths by John Johansen · 8 years ago
- cff281f apparmor: split apparmor policy namespaces code into its own file by John Johansen · 8 years ago
- 3d40658 apparmor: fix change_hat not finding hat after policy replacement by John Johansen · 8 years ago
- f7da2de apparmor: ensure the target profile name is always audited by John Johansen · 9 years ago
- 9049a79 apparmor: exec should not be returning ENOENT when it denies by John Johansen · 10 years ago
- b1d9e6b LSM: Switch to lists of hooks by Casey Schaufler · 10 years ago
- 1d4457f sched: move no_new_privs into new atomic flags by Kees Cook · 11 years ago
- 51775fe apparmor: remove the "task" arg from may_change_ptraced_domain() by Oleg Nesterov · 11 years ago
- dd0c6e8 apparmor: fix capability to not use the current task, during reporting by John Johansen · 11 years ago
- 0381650 apparmor: allow setting any profile into the unconfined state by John Johansen · 12 years ago
- fa2ac46 apparmor: update how unconfined is handled by John Johansen · 12 years ago
- 77b071b apparmor: change how profile replacement update is done by John Johansen · 12 years ago
- 01e2b67 apparmor: convert profile lists to RCU based locking by John Johansen · 12 years ago
- 214beac apparmor: localize getting the security context to a few macros by John Johansen · 12 years ago
- 7a2871b apparmor: use common fn to clear task_context for domain transitions by John Johansen · 12 years ago
- 3cfcc19 apparmor: add utility function to get an arbitrary tasks profile. by John Johansen · 12 years ago
- 0426623 apparmor: Remove -W1 warnings by John Johansen · 12 years ago
- 17322cc apparmor: fix auditing of domain transition failures due to incomplete policy by John Johansen · 12 years ago
- 496ad9a new helper: file_inode(file) by Al Viro · 12 years ago
- 2db8145 userns: Convert apparmor to use kuid and kgid where appropriate by Eric W. Biederman · 13 years ago
- c29bceb Fix execve behavior apparmor for PR_{GET,SET}_NO_NEW_PRIVS by John Johansen · 13 years ago
- 259e5e6 Add PR_{GET,SET}_NO_NEW_PRIVS to prevent execve from granting privs by Andy Lutomirski · 13 years ago
- 0421ea9 apparmor: Fix change_onexec when called from a confined task by John Johansen · 13 years ago
- 57fa1e1 AppArmor: Move path failure information into aa_get_name and rename by John Johansen · 13 years ago
- 95b6886 Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/security-testing-2.6 by Linus Torvalds · 13 years ago
- 04fdc09 AppArmor: Fix reference to rcu protected pointer outside of rcu_read_lock by John Johansen · 14 years ago
- 06d9847 ptrace: s/tracehook_tracer_task()/ptrace_parent()/ by Tejun Heo · 14 years ago
- 77c80e6 AppArmor: fix build warnings for non-const use of get_task_cred by James Morris · 14 years ago
- 898127c AppArmor: functions for domain transitions by John Johansen · 14 years ago