summaryrefslogtreecommitdiffstats
path: root/security/integrity
Commit message (Expand)AuthorAgeFilesLines
* ima/evm: Fix type mismatchRoberto Sassu2021-06-084-11/+12
* ima: Set correct casting typesRoberto Sassu2021-06-082-9/+10
* evm: Don't return an error in evm_write_xattrs() if audit is not enabledRoberto Sassu2021-06-031-1/+1
* ima: Define new template evm-sigRoberto Sassu2021-06-031-1/+4
* ima: Define new template fields xattrnames, xattrlengths and xattrvaluesRoberto Sassu2021-06-024-0/+148
* evm: Verify portable signatures against all protected xattrsRoberto Sassu2021-06-014-12/+68
* ima: Define new template field imodeRoberto Sassu2021-06-013-0/+26
* ima: Define new template fields iuid and igidRoberto Sassu2021-06-013-0/+53
* ima: Add ima_show_template_uint() template library functionRoberto Sassu2021-06-012-1/+39
* ima: Don't remove security.ima if file must not be appraisedRoberto Sassu2021-06-011-2/+0
* ima: Introduce template field evmsig and write to field sig as fallbackRoberto Sassu2021-06-013-1/+36
* ima: Allow imasig requirement to be satisfied by EVM portable signaturesRoberto Sassu2021-06-011-7/+17
* evm: Allow setxattr() and setattr() for unmodified metadataRoberto Sassu2021-06-011-1/+112
* evm: Pass user namespace to set/remove xattr hooksRoberto Sassu2021-05-211-6/+11
* evm: Allow xattr/attr operations for portable signaturesRoberto Sassu2021-05-212-6/+29
* evm: Introduce evm_hmac_disabled() to safely ignore verification errorsRoberto Sassu2021-05-211-1/+38
* evm: Introduce evm_revalidate_status()Roberto Sassu2021-05-212-9/+46
* evm: Refuse EVM_ALLOW_METADATA_WRITES only if an HMAC key is loadedRoberto Sassu2021-05-211-4/+4
* evm: Load EVM key in ima_load_x509() to avoid appraisalRoberto Sassu2021-05-212-1/+7
* evm: Execute evm_inode_init_security() only when an HMAC key is loadedRoberto Sassu2021-05-211-2/+3
* evm: fix writing <securityfs>/evm overflowMimi Zohar2021-05-201-2/+3
* Merge tag 'integrity-v5.13' of git://git.kernel.org/pub/scm/linux/kernel/git/...Linus Torvalds2021-05-015-4/+15
|\
| * ima: Fix fall-through warnings for ClangGustavo A. R. Silva2021-04-202-0/+3
| * integrity: Add declarations to init_once void arguments.Jiele Zhao2021-04-091-1/+1
| * ima: Fix function name error in comment.Jiele Zhao2021-04-091-1/+1
| * ima: enable loading of build time generated key on .ima keyringNayna Jain2021-04-091-0/+2
| * ima: Fix the error code for restoring the PCR valueLi Huafei2021-03-241-2/+2
| * ima: without an IMA policy loaded, return quicklyMimi Zohar2021-03-221-0/+6
* | Merge tag 'devicetree-for-5.13' of git://git.kernel.org/pub/scm/linux/kernel/...Linus Torvalds2021-04-282-10/+3
|\ \
| * | powerpc: Move arch independent ima kexec functions to drivers/of/kexec.cLakshmi Ramasubramanian2021-03-082-4/+1
| * | powerpc: Move ima buffer fields to struct kimageLakshmi Ramasubramanian2021-03-081-6/+2
* | | Merge tag 'selinux-pr-20210426' of git://git.kernel.org/pub/scm/linux/kernel/...Linus Torvalds2021-04-272-8/+8
|\ \ \
| * | | lsm: separate security_task_getsecid() into subjective and objective variantsPaul Moore2021-03-222-8/+8
| |/ /
* | | Merge branch 'linus' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert...Linus Torvalds2021-04-261-16/+14
|\ \ \
| * | | ima: Support EC keys for signature verificationStefan Berger2021-03-261-16/+14
| |/ /
* | | Merge tag 'keys-cve-2020-26541-v3' of git://git.kernel.org/pub/scm/linux/kern...Linus Torvalds2021-04-262-2/+29
|\ \ \ | |_|/ |/| |
| * | integrity: Load mokx variables into the blacklist keyringEric Snowberg2021-03-111-2/+18
| * | certs: Add EFI_CERT_X509_GUID support for dbx entriesEric Snowberg2021-03-111-0/+11
* | | integrity: double check iint_cache was initializedMimi Zohar2021-03-221-0/+8
| |/ |/|
* | Merge tag 'keys-misc-20210126' of git://git.kernel.org/pub/scm/linux/kernel/g...Linus Torvalds2021-02-231-3/+2
|\|
| * certs: Fix blacklist flag type confusionDavid Howells2021-01-211-3/+2
* | Merge tag 'idmapped-mounts-v5.12' of git://git.kernel.org/pub/scm/linux/kerne...Linus Torvalds2021-02-2310-54/+82
|\ \
| * | ima: handle idmapped mountsChristian Brauner2021-01-247-40/+68
| * | fs: make helpers idmap mount awareChristian Brauner2021-01-241-1/+1
| * | xattr: handle idmapped mountsTycho Andersen2021-01-243-11/+12
| |/
* | integrity: Make function integrity_add_key() staticWei Yongjun2021-02-121-2/+2
* | Merge branch 'ima-kexec-fixes' into next-integrityMimi Zohar2021-02-101-0/+3
|\ \
| * | ima: Free IMA measurement buffer after kexec syscallLakshmi Ramasubramanian2021-02-101-0/+2
| * | ima: Free IMA measurement buffer on errorLakshmi Ramasubramanian2021-02-101-0/+1
| |/
* | IMA: Measure kernel version in early bootRaphael Gianotti2021-01-261-0/+5