Show patches with: Archived = No       |   5569 patches
« 1 2 ... 46 47 4855 56 »
Patch Series A/R/T S/W/F Date Submitter Delegate State
[v2] samples/landlock: Document best-effort approach for LANDLOCK_ACCESS_FS_REFER [v2] samples/landlock: Document best-effort approach for LANDLOCK_ACCESS_FS_REFER - - - --- 2022-11-04 Günther Noack Handled Elsewhere
ima: Make a copy of sig and digest in asymmetric_verify() ima: Make a copy of sig and digest in asymmetric_verify() - - - --- 2022-11-04 Roberto Sassu Handled Elsewhere
[v4,06/11] security: keys: trusted: Verify creation data Encrypted Hibernation - 1 - --- 2022-11-03 Evan Green Handled Elsewhere
[v4,05/11] security: keys: trusted: Allow storage of PCR values in creation data Encrypted Hibernation - 2 - --- 2022-11-03 Evan Green Handled Elsewhere
[v4,04/11] security: keys: trusted: Include TPM2 creation data Encrypted Hibernation - 1 - --- 2022-11-03 Evan Green Handled Elsewhere
[v2] fs: don't audit the capability check in simple_xattr_list() [v2] fs: don't audit the capability check in simple_xattr_list() - 2 - --- 2022-11-03 Ondrej Mosnacek pcmoore Handled Elsewhere
[6b/10] CaitSith: Add policy management functions. [6b/10] CaitSith: Add policy management functions. - - - --- 2022-11-02 Tetsuo Handa pcmoore Rejected
[6a/10] CaitSith: Add policy management functions. [6a/10] CaitSith: Add policy management functions. - - - --- 2022-11-02 Tetsuo Handa pcmoore Rejected
[10/10] CaitSith: Add Kconfig and Makefile files. [01/10] security: Export security_hook_heads - - - --- 2022-11-02 Tetsuo Handa pcmoore Rejected
[09/10] CaitSith: Add garbage collector functions. [01/10] security: Export security_hook_heads - - - --- 2022-11-02 Tetsuo Handa pcmoore Rejected
[08/10] CaitSith: Add pathname calculation functions. [01/10] security: Export security_hook_heads - - - --- 2022-11-02 Tetsuo Handa pcmoore Rejected
[07/10] CaitSith: Add permission checking functions. [01/10] security: Export security_hook_heads - - - --- 2022-11-02 Tetsuo Handa pcmoore Rejected
[05/10] CaitSith: Add LSM interface management file. [01/10] security: Export security_hook_heads - - - --- 2022-11-02 Tetsuo Handa pcmoore Rejected
[04/10] CaitSith: Add header file. [01/10] security: Export security_hook_heads - - - --- 2022-11-02 Tetsuo Handa pcmoore Rejected
[03/10] fs,kernel: Export d_absolute_path()/find_task_by_pid_ns()/find_task_by_vpid() [01/10] security: Export security_hook_heads - - - --- 2022-11-02 Tetsuo Handa pcmoore Rejected
[02/10] mm: Export copy_to_kernel_nofault() [01/10] security: Export security_hook_heads - - - --- 2022-11-02 Tetsuo Handa pcmoore Rejected
[01/10] security: Export security_hook_heads [01/10] security: Export security_hook_heads - - - --- 2022-11-02 Tetsuo Handa pcmoore Rejected
ima: Fix memory leak in __ima_inode_hash() ima: Fix memory leak in __ima_inode_hash() - 1 - --- 2022-11-02 Roberto Sassu Handled Elsewhere
[v2] LSM: Better reporting of actual LSMs at boot [v2] LSM: Better reporting of actual LSMs at boot 2 - - --- 2022-11-02 Kees Cook pcmoore Accepted
capabilities: fix undefined behavior in bit shift for CAP_TO_MASK capabilities: fix undefined behavior in bit shift for CAP_TO_MASK 1 1 - --- 2022-10-31 cuigaosheng pcmoore Accepted
[GIT,PULL] LSM fixes for v6.1 (#1) [GIT,PULL] LSM fixes for v6.1 (#1) - - - --- 2022-10-31 Paul Moore pcmoore Accepted
samples/landlock: Document best-effort approach for LANDLOCK_ACCESS_FS_REFER samples/landlock: Document best-effort approach for LANDLOCK_ACCESS_FS_REFER - - - --- 2022-10-30 Günther Noack Handled Elsewhere
apparmor: Add __init annotation to aa_{setup/teardown}_dfa_engine() apparmor: Add __init annotation to aa_{setup/teardown}_dfa_engine() 1 - - --- 2022-10-29 Xiu Jianfeng Handled Elsewhere
[RESEND,RFC,3/3] selftests/bpf: Check if return values of LSM programs are allowed [RESEND,RFC,1/3] lsm: Clarify documentation of vm_enough_memory hook - - - --- 2022-10-28 Roberto Sassu pcmoore Superseded
[RESEND,RFC,2/3] bpf-lsm: Limit values that can be returned by security modules [RESEND,RFC,1/3] lsm: Clarify documentation of vm_enough_memory hook - - - --- 2022-10-28 Roberto Sassu pcmoore Superseded
[RESEND,RFC,1/3] lsm: Clarify documentation of vm_enough_memory hook [RESEND,RFC,1/3] lsm: Clarify documentation of vm_enough_memory hook - 1 - --- 2022-10-28 Roberto Sassu pcmoore Superseded
[RFC,3/3] selftests/bpf: Check if return values of LSM programs are allowed [RFC,1/3] lsm: Clarify documentation of vm_enough_memory hook - - - --- 2022-10-28 Roberto Sassu Superseded
[RFC,2/3] bpf-lsm: Limit values that can be returned by security modules [RFC,1/3] lsm: Clarify documentation of vm_enough_memory hook - - - --- 2022-10-28 Roberto Sassu Superseded
[RFC,1/3] lsm: Clarify documentation of vm_enough_memory hook [RFC,1/3] lsm: Clarify documentation of vm_enough_memory hook - - - --- 2022-10-28 Roberto Sassu Superseded
apparmor: Fix memleak in alloc_ns() apparmor: Fix memleak in alloc_ns() 1 - - --- 2022-10-28 Xiu Jianfeng Handled Elsewhere
efi: Add iMac Pro 2017 to uefi skip cert quirk efi: Add iMac Pro 2017 to uefi skip cert quirk - - - --- 2022-10-27 Aditya Garg Handled Elsewhere
efi: Add iMac Pro 2017 to uefi skip cert quirk efi: Add iMac Pro 2017 to uefi skip cert quirk - - - --- 2022-10-27 Aditya Garg Handled Elsewhere
[v4] evm: Correct inode_init_security hooks behaviors [v4] evm: Correct inode_init_security hooks behaviors - - - --- 2022-10-26 Nicolas Bouchinet pcmoore Changes Requested
[1/1] smack_lsm: remove unnecessary type casting [1/1] smack_lsm: remove unnecessary type casting - - - --- 2022-10-26 XU pengfei Handled Elsewhere
[v2] audit: Fix some kernel-doc warnings [v2] audit: Fix some kernel-doc warnings - - - --- 2022-10-26 Bo Liu pcmoore Accepted
[v2,1/1] audit: Fix some kernel-doc warnings [v2,1/1] audit: Fix some kernel-doc warnings - - - --- 2022-10-26 Bo Liu Superseded
[v1,8/8] lsm: wireup syscalls lsm_self_attr and lsm_module_list LSM: Two basic syscalls 1 - - --- 2022-10-25 Casey Schaufler pcmoore Changes Requested
[v1,7/8] LSM: Create lsm_module_list system call LSM: Two basic syscalls - - - --- 2022-10-25 Casey Schaufler pcmoore Changes Requested
[v1,6/8] LSM: lsm_self_attr syscall for LSM self attributes LSM: Two basic syscalls - - - --- 2022-10-25 Casey Schaufler pcmoore Changes Requested
[v1,5/8] proc: Use lsmids instead of lsm names for attrs LSM: Two basic syscalls - - - --- 2022-10-25 Casey Schaufler pcmoore Changes Requested
[v1,4/8] LSM: Maintain a table of LSM attribute data LSM: Two basic syscalls - - - --- 2022-10-25 Casey Schaufler pcmoore Changes Requested
[v1,3/8] LSM: Identify the process attributes for each module LSM: Two basic syscalls - - - --- 2022-10-25 Casey Schaufler pcmoore Changes Requested
[v1,2/8] LSM: Add an LSM identifier for external use LSM: Two basic syscalls - - - --- 2022-10-25 Casey Schaufler pcmoore Changes Requested
[v1,1/8] LSM: Identify modules by more than name LSM: Two basic syscalls - - - --- 2022-10-25 Casey Schaufler pcmoore Changes Requested
[v3] evm: Correct inode_init_security hooks behaviors [v3] evm: Correct inode_init_security hooks behaviors - - - --- 2022-10-25 Nicolas Bouchinet pcmoore Superseded
[v2] security: commoncap: fix potential memleak on error path from vfs_getxattr_alloc [v2] security: commoncap: fix potential memleak on error path from vfs_getxattr_alloc 1 - - --- 2022-10-25 cuigaosheng pcmoore Accepted
device_cgroup: Roll back to original exceptions after copy failure device_cgroup: Roll back to original exceptions after copy failure - 1 - --- 2022-10-25 Wang Weiyang pcmoore Accepted
security: commoncap: fix potential memleak on error path from vfs_getxattr_alloc security: commoncap: fix potential memleak on error path from vfs_getxattr_alloc - - - --- 2022-10-25 cuigaosheng Changes Requested
ima: fix a possible null pointer dereference ima: fix a possible null pointer dereference - - - --- 2022-10-25 cuigaosheng Handled Elsewhere
audit: Fix some kernel-doc warnings audit: Fix some kernel-doc warnings 1 - - --- 2022-10-25 Bo Liu pcmoore Changes Requested
[-next] apparmor: fix a memleak in free_ruleset() [-next] apparmor: fix a memleak in free_ruleset() 1 - - --- 2022-10-25 cuigaosheng Handled Elsewhere
[5.10,053/390] hardening: Clarify Kconfig text for auto-var-init Untitled series #688216 1 - - --- 2022-10-24 Greg KH Handled Elsewhere
[3/8] caps: use type safe idmapping helpers Untitled series #688152 - - - --- 2022-10-24 Christian Brauner pcmoore Handled Elsewhere
[RFC] bpf: Check xattr name/value pair from bpf_lsm_inode_init_security() [RFC] bpf: Check xattr name/value pair from bpf_lsm_inode_init_security() - - - --- 2022-10-21 Roberto Sassu pcmoore Handled Elsewhere
[v8,12/12] landlock: Document Landlock's network support Network support for Landlock - - - --- 2022-10-21 Konstantin Meskhidze (A) Handled Elsewhere
[v8,11/12] samples/landlock: Add network demo Network support for Landlock - - - --- 2022-10-21 Konstantin Meskhidze (A) Handled Elsewhere
[v8,10/12] selftests/landlock: Add 10 new test suites dedicated to network Network support for Landlock - - - --- 2022-10-21 Konstantin Meskhidze (A) Handled Elsewhere
[v8,09/12] selftests/landlock: Share enforce_ruleset() Network support for Landlock - - - --- 2022-10-21 Konstantin Meskhidze (A) Handled Elsewhere
[v8,08/12] landlock: Implement TCP network hooks Network support for Landlock - - - --- 2022-10-21 Konstantin Meskhidze (A) Handled Elsewhere
[v8,07/12] landlock: Add network rules support Network support for Landlock - - - --- 2022-10-21 Konstantin Meskhidze (A) Handled Elsewhere
[v8,06/12] landlock: Refactor landlock_add_rule() syscall Network support for Landlock - - - --- 2022-10-21 Konstantin Meskhidze (A) Handled Elsewhere
[v8,05/12] landlock: Refactor unmask_layers() and init_layer_masks() Network support for Landlock - - - --- 2022-10-21 Konstantin Meskhidze (A) Handled Elsewhere
[v8,04/12] landlock: Move unmask_layers() and init_layer_masks() Network support for Landlock - - - --- 2022-10-21 Konstantin Meskhidze (A) Handled Elsewhere
[v8,03/12] landlock: Refactor merge/inherit_ruleset functions Network support for Landlock - - - --- 2022-10-21 Konstantin Meskhidze (A) Handled Elsewhere
[v8,02/12] landlock: Refactor landlock_find_rule/insert_rule Network support for Landlock - - - --- 2022-10-21 Konstantin Meskhidze (A) Handled Elsewhere
[v8,01/12] landlock: Make ruleset's access masks more generic Network support for Landlock - - - --- 2022-10-21 Konstantin Meskhidze (A) Handled Elsewhere
[v2] evm: Correct inode_init_security hooks behaviors [v2] evm: Correct inode_init_security hooks behaviors - - - --- 2022-10-21 Nicolas Bouchinet Handled Elsewhere
apparmor: Fix memleak issue in unpack_profile() apparmor: Fix memleak issue in unpack_profile() 1 - - --- 2022-10-21 Xiu Jianfeng Handled Elsewhere
[v2] apparmor: Use pointer to struct aa_label for lbs_cred [v2] apparmor: Use pointer to struct aa_label for lbs_cred 1 - - --- 2022-10-21 Xiu Jianfeng Handled Elsewhere
[GIT,PULL] SELinux fixes for v6.1 (#1) [GIT,PULL] SELinux fixes for v6.1 (#1) - - - --- 2022-10-20 Paul Moore pcmoore Handled Elsewhere
evm: Correct inode_init_security hooks behaviors evm: Correct inode_init_security hooks behaviors - - - --- 2022-10-20 Nicolas Bouchinet pcmoore Superseded
apparmor: Use pointer to struct aa_label for lbs_cred apparmor: Use pointer to struct aa_label for lbs_cred - - - --- 2022-10-20 Xiu Jianfeng Handled Elsewhere
[v1] selftests/landlock: Build without static libraries [v1] selftests/landlock: Build without static libraries - - - --- 2022-10-19 Mickaël Salaün Handled Elsewhere
[v6] KEYS: encrypted: fix key instantiation with user-provided data [v6] KEYS: encrypted: fix key instantiation with user-provided data - 1 - --- 2022-10-19 Nikolaus Voss Handled Elsewhere
[v5] KEYS: encrypted: fix key instantiation with user-provided data [v5] KEYS: encrypted: fix key instantiation with user-provided data - 1 - --- 2022-10-19 Nikolaus Voss Handled Elsewhere
[v2] selinux: use GFP_ATOMIC in convert_context() [v2] selinux: use GFP_ATOMIC in convert_context() - 1 - --- 2022-10-19 GONG Ruiqi Handled Elsewhere
[v10,11/11] landlock: Document Landlock's file truncation support landlock: truncate support - - - --- 2022-10-18 Günther Noack Handled Elsewhere
[v10,10/11] samples/landlock: Extend sample tool to support LANDLOCK_ACCESS_FS_TRUNCATE landlock: truncate support - - - --- 2022-10-18 Günther Noack Handled Elsewhere
[v10,09/11] selftests/landlock: Test ftruncate on FDs created by memfd_create(2) landlock: truncate support - - - --- 2022-10-18 Günther Noack Handled Elsewhere
[v10,08/11] selftests/landlock: Test FD passing from restricted to unrestricted processes landlock: truncate support - - - --- 2022-10-18 Günther Noack Handled Elsewhere
[v10,07/11] selftests/landlock: Locally define __maybe_unused landlock: truncate support - - - --- 2022-10-18 Günther Noack Handled Elsewhere
[v10,06/11] selftests/landlock: Test open() and ftruncate() in multiple scenarios landlock: truncate support - - - --- 2022-10-18 Günther Noack Handled Elsewhere
[v10,05/11] selftests/landlock: Test file truncation support landlock: truncate support - - - --- 2022-10-18 Günther Noack Handled Elsewhere
[v10,04/11] landlock: Support file truncation landlock: truncate support 1 - - --- 2022-10-18 Günther Noack Handled Elsewhere
[v10,03/11] landlock: Document init_layer_masks() helper landlock: truncate support - - - --- 2022-10-18 Günther Noack Handled Elsewhere
[v10,02/11] landlock: Refactor check_access_path_dual() into is_access_to_paths_allowed() landlock: truncate support - - - --- 2022-10-18 Günther Noack Handled Elsewhere
[v10,01/11] security: Create file_truncate hook from path_truncate hook landlock: truncate support 3 - - --- 2022-10-18 Günther Noack Handled Elsewhere
selinux: use GFP_ATOMIC in convert_context() selinux: use GFP_ATOMIC in convert_context() - - - --- 2022-10-18 GONG Ruiqi Handled Elsewhere
[v5,30/30] acl: remove a slew of now unused helpers acl: add vfs posix acl api - - - --- 2022-10-18 Christian Brauner Handled Elsewhere
[v5,29/30] 9p: use stub posix acl handlers acl: add vfs posix acl api - - - --- 2022-10-18 Christian Brauner Handled Elsewhere
[v5,28/30] cifs: use stub posix acl handlers acl: add vfs posix acl api - - - --- 2022-10-18 Christian Brauner Handled Elsewhere
[v5,27/30] ovl: use stub posix acl handlers acl: add vfs posix acl api - - - --- 2022-10-18 Christian Brauner Handled Elsewhere
[v5,26/30] ecryptfs: use stub posix acl handlers acl: add vfs posix acl api - - - --- 2022-10-18 Christian Brauner Handled Elsewhere
[v5,25/30] evm: remove evm_xattr_acl_change() acl: add vfs posix acl api - - - --- 2022-10-18 Christian Brauner Handled Elsewhere
[v5,24/30] xattr: use posix acl api acl: add vfs posix acl api - - - --- 2022-10-18 Christian Brauner Handled Elsewhere
[v5,23/30] ovl: use posix acl api acl: add vfs posix acl api 1 - - --- 2022-10-18 Christian Brauner Handled Elsewhere
[v5,22/30] ovl: implement set acl method acl: add vfs posix acl api 1 - - --- 2022-10-18 Christian Brauner Handled Elsewhere
[v5,21/30] ovl: implement get acl method acl: add vfs posix acl api - - - --- 2022-10-18 Christian Brauner Handled Elsewhere
[v5,20/30] ecryptfs: implement set acl method acl: add vfs posix acl api - - - --- 2022-10-18 Christian Brauner Handled Elsewhere
[v5,19/30] ecryptfs: implement get acl method acl: add vfs posix acl api - - - --- 2022-10-18 Christian Brauner Handled Elsewhere
« 1 2 ... 46 47 4855 56 »