Show patches with: State = Action Required       |   12149 patches
« 1 2 ... 19 20 21121 122 »
Patch Series A/R/T S/W/F Date Submitter Delegate State
[5/7] evm: Verify portable signatures against all protected xattrs ima: Add template fields to verify EVM portable signatures - - - --- 2021-05-20 Roberto Sassu New
[4/7] ima: Introduce template field imode ima: Add template fields to verify EVM portable signatures - - - --- 2021-05-20 Roberto Sassu New
[3/7] ima: Introduce template fields mntuidmap and mntgidmap ima: Add template fields to verify EVM portable signatures - - - --- 2021-05-20 Roberto Sassu New
[2/7] ima: Introduce template fields iuid and igid ima: Add template fields to verify EVM portable signatures - - - --- 2021-05-20 Roberto Sassu New
[1/7] ima: Add ima_show_template_uint() template library function ima: Add template fields to verify EVM portable signatures - - - --- 2021-05-20 Roberto Sassu New
[RESEND,05/12] evm: Introduce evm_hmac_disabled() to safely ignore verification errors Untitled series #485589 - 1 - --- 2021-05-20 Roberto Sassu New
[RFC,3/3] ima: Enable IMA SB Policy if MokIMAPolicy found Add additional MOK vars - - - --- 2021-05-17 Eric Snowberg New
[RFC,2/3] keys: Trust platform keyring if MokTrustPlatform found Add additional MOK vars - - - --- 2021-05-17 Eric Snowberg New
[RFC,1/3] keys: Add ability to trust the platform keyring Add additional MOK vars - - - --- 2021-05-17 Eric Snowberg New
[v2,2/2] selinux: fix SECURITY_LSM_NATIVE_LABELS flag handling on double mount vfs/security/NFS/btrfs: clean up and fix LSM option handling - - - --- 2021-05-17 Ondrej Mosnacek New
[v2,1/2] vfs,LSM: introduce the FS_HANDLES_LSM_OPTS flag vfs/security/NFS/btrfs: clean up and fix LSM option handling - - 1 --- 2021-05-17 Ondrej Mosnacek New
[v2] lockdown,selinux: avoid bogus SELinux lockdown permission checks [v2] lockdown,selinux: avoid bogus SELinux lockdown permission checks 4 - 2 --- 2021-05-17 Ondrej Mosnacek New
[v7,12/12] ima: Don't remove security.ima if file must not be appraised evm: Improve usability of portable signatures - 1 - --- 2021-05-14 Roberto Sassu New
[v7,11/12] ima: Introduce template field evmsig and write to field sig as fallback evm: Improve usability of portable signatures - - - --- 2021-05-14 Roberto Sassu New
[v7,10/12] ima: Allow imasig requirement to be satisfied by EVM portable signatures evm: Improve usability of portable signatures - 1 - --- 2021-05-14 Roberto Sassu New
[v7,09/12] evm: Deprecate EVM_ALLOW_METADATA_WRITES evm: Improve usability of portable signatures - - - --- 2021-05-14 Roberto Sassu New
[v7,08/12] evm: Allow setxattr() and setattr() for unmodified metadata evm: Improve usability of portable signatures - 1 - --- 2021-05-14 Roberto Sassu New
[v7,07/12] evm: Pass user namespace to set/remove xattr hooks evm: Improve usability of portable signatures - 1 - --- 2021-05-14 Roberto Sassu New
[v7,06/12] evm: Allow xattr/attr operations for portable signatures evm: Improve usability of portable signatures - 1 - --- 2021-05-14 Roberto Sassu New
[v7,05/12] evm: Introduce evm_hmac_disabled() to safely ignore verification errors evm: Improve usability of portable signatures - 1 - --- 2021-05-14 Roberto Sassu New
[v7,04/12] evm: Introduce evm_revalidate_status() evm: Improve usability of portable signatures - 1 - --- 2021-05-14 Roberto Sassu New
[v7,03/12] evm: Refuse EVM_ALLOW_METADATA_WRITES only if an HMAC key is loaded evm: Improve usability of portable signatures - 1 - --- 2021-05-14 Roberto Sassu New
[v7,02/12] evm: Load EVM key in ima_load_x509() to avoid appraisal evm: Improve usability of portable signatures - 1 - --- 2021-05-14 Roberto Sassu New
[v7,01/12] evm: Execute evm_inode_init_security() only when an HMAC key is loaded evm: Improve usability of portable signatures - 1 - --- 2021-05-14 Roberto Sassu New
[v2,09/13] apparmor: use get_unaligned() only for multi-byte words Unify asm/unaligned.h around struct helper 1 - - --- 2021-05-14 Arnd Bergmann New
[v26,25/25] AppArmor: Remove the exclusive flag LSM: Module stacking for AppArmor 2 1 - --- 2021-05-13 Casey Schaufler New
[v26,24/25] LSM: Add /proc attr entry for full LSM context LSM: Module stacking for AppArmor - 1 - --- 2021-05-13 Casey Schaufler New
[v26,23/25] Audit: Add a new record for multiple object LSM attributes LSM: Module stacking for AppArmor - - - --- 2021-05-13 Casey Schaufler New
[v26,22/25] Audit: Add new record for multiple process LSM attributes LSM: Module stacking for AppArmor - - - --- 2021-05-13 Casey Schaufler New
[v26,21/25] audit: add support for non-syscall auxiliary records LSM: Module stacking for AppArmor 1 - - --- 2021-05-13 Casey Schaufler New
[v26,20/25] LSM: Verify LSM display sanity in binder LSM: Module stacking for AppArmor 2 2 - --- 2021-05-13 Casey Schaufler New
[v26,19/25] NET: Store LSM netlabel data in a lsmblob LSM: Module stacking for AppArmor 2 2 - --- 2021-05-13 Casey Schaufler New
[v26,18/25] LSM: security_secid_to_secctx in netlink netfilter LSM: Module stacking for AppArmor 3 2 - --- 2021-05-13 Casey Schaufler New
[v26,17/25] LSM: Use lsmcontext in security_inode_getsecctx LSM: Module stacking for AppArmor 3 2 - --- 2021-05-13 Casey Schaufler New
[v26,16/25] LSM: Use lsmcontext in security_secid_to_secctx LSM: Module stacking for AppArmor 2 1 - --- 2021-05-13 Casey Schaufler New
[v26,15/25] LSM: Ensure the correct LSM context releaser LSM: Module stacking for AppArmor 3 2 - --- 2021-05-13 Casey Schaufler New
[v26,14/25] LSM: Specify which LSM to display LSM: Module stacking for AppArmor 1 - - --- 2021-05-13 Casey Schaufler New
[v26,13/25] IMA: Change internal interfaces to use lsmblobs LSM: Module stacking for AppArmor 1 2 - --- 2021-05-13 Casey Schaufler New
[v26,12/25] LSM: Use lsmblob in security_cred_getsecid LSM: Module stacking for AppArmor 2 2 - --- 2021-05-13 Casey Schaufler New
[v26,11/25] LSM: Use lsmblob in security_inode_getsecid LSM: Module stacking for AppArmor 2 2 - --- 2021-05-13 Casey Schaufler New
[v26,10/25] LSM: Use lsmblob in security_task_getsecid LSM: Module stacking for AppArmor 2 2 - --- 2021-05-13 Casey Schaufler New
[v26,09/25] LSM: Use lsmblob in security_ipc_getsecid LSM: Module stacking for AppArmor 2 2 - --- 2021-05-13 Casey Schaufler New
[v26,08/25] LSM: Use lsmblob in security_secid_to_secctx LSM: Module stacking for AppArmor 1 1 - --- 2021-05-13 Casey Schaufler New
[v26,07/25] LSM: Use lsmblob in security_secctx_to_secid LSM: Module stacking for AppArmor 1 1 - --- 2021-05-13 Casey Schaufler New
[v26,06/25] LSM: Use lsmblob in security_kernel_act_as LSM: Module stacking for AppArmor 2 2 - --- 2021-05-13 Casey Schaufler New
[v26,05/25] LSM: Use lsmblob in security_audit_rule_match LSM: Module stacking for AppArmor 2 2 - --- 2021-05-13 Casey Schaufler New
[v26,04/25] IMA: avoid label collisions with stacked LSMs LSM: Module stacking for AppArmor - 1 - --- 2021-05-13 Casey Schaufler New
[v26,03/25] LSM: provide lsm name and id slot mappings LSM: Module stacking for AppArmor 1 1 - --- 2021-05-13 Casey Schaufler New
[v26,02/25] LSM: Add the lsmblob data structure. LSM: Module stacking for AppArmor 3 - - --- 2021-05-13 Casey Schaufler New
[v26,01/25] LSM: Infrastructure management of the sock security LSM: Module stacking for AppArmor 2 2 - --- 2021-05-13 Casey Schaufler New
[v2,09/10] apparmor: test: Remove some casts which are no-longer required Untitled series #482063 1 1 - --- 2021-05-13 David Gow New
[RFC,3/3] virt: Add sev_secret module to expose confidential computing secrets Allow access to confidential computing secret area - - - --- 2021-05-13 Dov Murik New
[RFC,bpf-next,1/1] bpf: Add a BPF helper for getting the cgroup path of current task Implement getting cgroup path bpf helper - - - --- 2021-05-12 xufeng zhang New
[RFC,bpf-next,seccomp,12/12] seccomp-ebpf: support task storage from BPF-LSM, defaulting to group l… eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,11/12] bpf/verifier: support NULL-able ptr to BTF ID as helper argument eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,10/12] seccomp-ebpf: Add ability to read user memory eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,09/12] yama: (concept) restrict seccomp-eBPF with ptrace_scope eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,08/12] seccomp-ebpf: restrict filter to almost cBPF if LSM request such eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,07/12] bpf/verifier: allow restricting direct map access eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,06/12] lsm: New hook seccomp_extended eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,05/12] samples/bpf: Add eBPF seccomp sample programs eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,04/12] libbpf: recognize section "seccomp" eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,03/12] seccomp, ptrace: Add a mechanism to retrieve attached eBPF seccomp fil… eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,02/12] bpf, seccomp: Add eBPF filter capabilities eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
[RFC,bpf-next,seccomp,01/12] seccomp: Move no_new_privs check to after prepare_filter eBPF seccomp filters - - - --- 2021-05-10 YiFei Zhu New
Keys: Remove redundant initialization of cred Keys: Remove redundant initialization of cred - 1 - --- 2021-05-08 Yang Li New
[RFC,09/12] apparmor: use get_unaligned() only for multi-byte words Unify asm/unaligned.h around struct helper 1 - - --- 2021-05-07 Arnd Bergmann New
[RESEND,v6,05/11] evm: Introduce evm_hmac_disabled() to safely ignore verification errors Untitled series #478471 - 1 - --- 2021-05-07 Roberto Sassu New
[v2] debugfs: fix security_locked_down() call for SELinux [v2] debugfs: fix security_locked_down() call for SELinux - - - --- 2021-05-07 Ondrej Mosnacek New
serial: core: fix suspicious security_locked_down() call serial: core: fix suspicious security_locked_down() call 1 - - --- 2021-05-07 Ondrej Mosnacek New
debugfs: fix security_locked_down() call for SELinux debugfs: fix security_locked_down() call for SELinux - - - --- 2021-05-07 Ondrej Mosnacek New
lockdown,selinux: fix bogus SELinux lockdown permission checks lockdown,selinux: fix bogus SELinux lockdown permission checks - - - --- 2021-05-07 Ondrej Mosnacek New
vfio: Lock down no-IOMMU mode when kernel is locked down vfio: Lock down no-IOMMU mode when kernel is locked down - - - --- 2021-05-06 Maxime Coquelin New
Makefile: Introduce CONFIG_ZERO_CALL_USED_REGS Makefile: Introduce CONFIG_ZERO_CALL_USED_REGS - - - --- 2021-05-05 Kees Cook New
[v6,11/11] ima: Don't remove security.ima if file must not be appraised evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,10/11] ima: Introduce template field evmsig and write to field sig as fallback evm: Improve usability of portable signatures - - - --- 2021-05-05 Roberto Sassu New
[v6,09/11] ima: Allow imasig requirement to be satisfied by EVM portable signatures evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,08/11] evm: Allow setxattr() and setattr() for unmodified metadata evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,07/11] evm: Pass user namespace to set/remove xattr hooks evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,06/11] evm: Allow xattr/attr operations for portable signatures evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,05/11] evm: Introduce evm_hmac_disabled() to safely ignore verification errors evm: Improve usability of portable signatures - - - --- 2021-05-05 Roberto Sassu New
[v6,04/11] evm: Introduce evm_status_revalidate() evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,03/11] evm: Refuse EVM_ALLOW_METADATA_WRITES only if an HMAC key is loaded evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,02/11] evm: Load EVM key in ima_load_x509() to avoid appraisal evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[v6,01/11] evm: Execute evm_inode_init_security() only when an HMAC key is loaded evm: Improve usability of portable signatures - 1 - --- 2021-05-05 Roberto Sassu New
[GIT,PULL] SafeSetID changes for v5.13 [GIT,PULL] SafeSetID changes for v5.13 - - - --- 2021-05-03 Micah Morton New
KEYS: trusted: fix memory leak KEYS: trusted: fix memory leak - - - --- 2021-04-30 Tom Rix New
KEYS: trusted: Fix memory leak on object td KEYS: trusted: Fix memory leak on object td - 3 - --- 2021-04-30 Colin King New
[v2,1/1] trusted-keys: match tpm_get_ops on all return paths trusted-keys: match tpm_get_ops on all return paths - 1 - --- 2021-04-29 Ben Boeckel New
[1/1] trusted-keys: match tpm_get_ops on all return paths trusted-keys: match tpm_get_ops on all return paths - - - --- 2021-04-29 Ben Boeckel New
[v2] samples/landlock: fix path_list memory leak [v2] samples/landlock: fix path_list memory leak - 1 - --- 2021-04-28 Tom Rix New
[GIT,PULL,Security] Add new Landlock LSM [GIT,PULL,Security] Add new Landlock LSM - - - --- 2021-04-28 James Morris New
[GIT,PULL,Security,Subsystem] Fixes for v5.13 [GIT,PULL,Security,Subsystem] Fixes for v5.13 - - - --- 2021-04-27 James Morris New
samples/landlock: fix path_list memory leak samples/landlock: fix path_list memory leak - 1 - --- 2021-04-27 Tom Rix New
[v3,6/6] evm: Support multiple LSMs providing an xattr evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-27 Roberto Sassu New
[v3,5/6] evm: Align evm_inode_init_security() definition with LSM infrastructure evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-27 Roberto Sassu New
[v3,4/6] security: Support multiple LSMs implementing the inode_init_security hook evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-27 Roberto Sassu New
[v3,3/6] security: Pass xattrs allocated by LSMs to the inode_init_security hook evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-27 Roberto Sassu New
[v3,2/6] security: Rewrite security_old_inode_init_security() evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-27 Roberto Sassu New
[v3,1/6] reiserfs: Add missing calls to reiserfs_security_free() evm: Prepare for moving to the LSM infrastructure - - - --- 2021-04-27 Roberto Sassu New
« 1 2 ... 19 20 21121 122 »