summaryrefslogtreecommitdiffstats
path: root/security/selinux
Commit message (Expand)AuthorAgeFilesLines
* selinux: initialize proto variable in selinux_ip_postroute_compat()Tom Rix2022-01-051-1/+1
* binder: use cred instead of task for selinux checksTodd Kjos2021-11-261-18/+13
* selinux: use __GFP_NOWARN with GFP_NOWAIT in the AVCMinchan Kim2021-07-201-6/+7
* selinux: sel_avc_get_stat_idx should increase position indexVasily Averin2020-10-011-0/+1
* selinux: fix double freeTom Rix2020-06-301-0/+4
* selinux: properly handle multiple messages in selinux_netlink_send()Paul Moore2020-05-051-24/+44
* selinux: ensure we cleanup the internal AVC counters on error in avc_update()Jaihind Yadav2020-02-281-1/+1
* selinux: fix memory leak in policydb_init()Ondrej Mosnacek2019-08-061-1/+5
* selinux: never allow relabeling on context mountsOndrej Mosnacek2019-05-081-9/+31
* selinux: do not override context on context mountsOndrej Mosnacek2019-04-051-1/+8
* selinux: always allow mounting submountsOndrej Mosnacek2019-01-261-1/+1
* selinux: fix GPF on invalid policyStephen Smalley2019-01-231-1/+2
* selinux: Add __GFP_NOWARN to allocation at str_read()Tetsuo Handa2018-12-011-1/+1
* selinux: use GFP_NOWAIT in the AVC kmem_cachesMichal Hocko2018-09-191-8/+6
* selinux: KASAN: slab-out-of-bounds in xattr_getsecuritySachin Grover2018-06-061-1/+1
* selinux: do not check open permission on socketsStephen Smalley2018-04-131-3/+7
* selinux: Remove redundant check for unknown labeling behaviorMatthias Kaehlcke2018-04-081-16/+0
* selinux: Remove unnecessary check of array base in selinux_set_mapping()Matthias Kaehlcke2018-04-081-1/+1
* selinux: check for address length in selinux_socket_bind()Alexander Potapenko2018-03-221-0/+8
* selinux: skip bounded transition processing if the policy isn't loadedPaul Moore2018-02-251-0/+3
* selinux: ensure the context is NUL terminated in security_context_to_sid_core()Paul Moore2018-02-251-10/+8
* selinux: fix off-by-one in setprocattrStephen Smalley2017-02-141-1/+1
* mm: Change vm_is_stack_for_task() to vm_is_stack_for_current()Andy Lutomirski2016-10-201-1/+1
* Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/vir...Linus Torvalds2016-10-101-1/+1
|\
| * fs: Replace CURRENT_TIME with current_time() for inode timestampsDeepa Dinamani2016-09-271-1/+1
* | Merge branch 'work.xattr' of git://git.kernel.org/pub/scm/linux/kernel/git/vi...Linus Torvalds2016-10-101-12/+7
|\ \
| * | xattr: Add __vfs_{get,set,remove}xattr helpersAndreas Gruenbacher2016-10-071-12/+7
| |/
* | Merge branch 'printk-cleanups'Linus Torvalds2016-10-101-2/+2
|\ \
| * | printk: reinstate KERN_CONT for printing continuation linesLinus Torvalds2016-10-091-2/+2
| |/
* | lsm,audit,selinux: Introduce a new audit data type LSM_AUDIT_DATA_FILEVivek Goyal2016-09-191-8/+8
* | selinux: fix error return code in policydb_read()Wei Yongjun2016-09-131-0/+1
* | selinux: fix overflow and 0 length allocationsWilliam Roberts2016-08-302-0/+5
* | selinux: initialize structuresWilliam Roberts2016-08-291-4/+4
* | selinux: detect invalid ebitmapWilliam Roberts2016-08-291-0/+3
* | selinux: drop SECURITY_SELINUX_POLICYDB_VERSION_MAXWilliam Roberts2016-08-182-42/+0
* | selinux: Implement dentry_create_files_as() hookVivek Goyal2016-08-101-0/+22
* | selinux: Pass security pointer to determine_inode_label()Vivek Goyal2016-08-081-9/+10
* | selinux: Implementation for inode_copy_up_xattr() hookVivek Goyal2016-08-081-0/+16
* | selinux: Implementation for inode_copy_up() hookVivek Goyal2016-08-081-0/+21
* | security: Use IS_ENABLED() instead of checking for built-in or moduleJavier Martinez Canillas2016-08-081-6/+6
|/
* Merge branch 'work.const-qstr' of git://git.kernel.org/pub/scm/linux/kernel/g...Linus Torvalds2016-08-061-1/+1
|\
| * qstr: constify dentry_init_securityAl Viro2016-07-201-1/+1
* | Merge branch 'next' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/...Linus Torvalds2016-07-296-63/+72
|\ \
| * \ Merge branch 'stable-4.8' of git://git.infradead.org/users/pcmoore/selinux in...James Morris2016-07-076-63/+72
| |\ \ | | |/ | |/|
| | * calipso: Add a label cache.Huw Davies2016-06-271-3/+6
| | * netlabel: Pass a family parameter to netlbl_skbuff_err().Huw Davies2016-06-273-7/+9
| | * calipso: Allow the lsm to label the skbuff directly.Huw Davies2016-06-271-0/+15
| | * calipso: Allow request sockets to be relabelled by the lsm.Huw Davies2016-06-271-1/+1
| | * netlabel: Prevent setsockopt() from changing the hop-by-hop option.Huw Davies2016-06-271-1/+16
| | * calipso: Set the calipso socket label to match the secattr.Huw Davies2016-06-271-1/+1