2021-11-22lsm: security_task_getsecid_subj() -> security_current_getsecid_subj()Paul Moore1-5/+4
2021-10-13Smack: fix W=1 build warningsCasey Schaufler1-12/+18
2021-09-28Smack:- Use overlay inode label in smack_inode_copy_up()Vishal Goel1-1/+1
2021-09-24smack: Guard smack_ipv6_lock definition within a SMACK_IPV6_PORT_LABELING blockSebastian Andrzej Siewior1-3/+6
2021-09-23selinux,smack: fix subjective/objective credential use mixupsPaul Moore1-2/+2
2021-09-19Smack: Brutalist io_uring supportCasey Schaufler1-0/+46
2021-07-20smack: mark 'smack_enabled' global variable as __initdataAustin Kim1-1/+1
2021-04-22LSM: Infrastructure management of the superblockCasey Schaufler1-26/+9
2021-03-22smack: differentiate between subjective and objective task credentialsPaul Moore1-13/+27
2021-03-22lsm: separate security_task_getsecid() into subjective and objective variantsPaul Moore1-1/+2
2021-01-24commoncap: handle idmapped mountsChristian Brauner1-6/+8
2021-01-24xattr: handle idmapped mountsTycho Andersen1-3/+5
2020-12-03security: add const qualifier to struct sock in various placesFlorian Westphal1-2/+2
2020-11-16security/smack: remove unused varible 'rc'Alex Shi1-2/+1
2020-10-05Smack: Remove unnecessary variable initializationCasey Schaufler1-1/+1
2020-09-22Smack: Fix build when NETWORK_SECMARK is not setCasey Schaufler1-0/+7
2020-09-11Smack: Use the netlabel cacheCasey Schaufler1-6/+21
2020-09-11Smack: Set socket labels only onceCasey Schaufler1-76/+93
2020-09-11Smack: Consolidate uses of secmark into a functionCasey Schaufler1-28/+33
2020-08-23treewide: Use fallthrough pseudo-keywordGustavo A. R. Silva1-1/+1
2020-05-20exec: Factor security_bprm_creds_for_exec out of security_bprm_set_credsEric W. Biederman1-6/+3
2020-05-19smack: Implement the watch_key and post_notification hooksDavid Howells1-1/+82
2020-05-19keys: Make the KEY_NEED_* perms an enum rather than a maskDavid Howells1-7/+22
2020-05-06Smack:- Remove redundant inode_smack cacheCasey Schaufler1-8/+1
2020-05-06Smack:- Remove mutex lock "smk_lock" from inode_smackCasey Schaufler1-6/+2
2020-05-06smack: avoid unused 'sip' variable warningArnd Bergmann1-17/+8
2020-02-07fs_parse: fold fs_parameter_desc/fs_parameter_specAl Viro1-6/+2
2020-02-07fs_parser: remove fs_parameter_description name fieldEric Sandeen1-1/+0
2020-02-05broken ping to ipv6 linklocal addresses on debian busterCasey Schaufler1-22/+19
2019-10-23pipe: Reduce #inclusion of pipe_fs_i.hDavid Howells1-1/+0
2019-09-04smack: use GFP_NOFS while holding inode_smack::smk_lockEric Biggers1-1/+1
2019-09-04security: smack: Fix possible null-pointer dereferences in smack_socket_sock_rcv_skb()Jia-Ju Bai1-0/+2
2019-09-04smack: fix some kernel-doc notationsluanshi1-18/+15
2019-09-04Smack: Don't ignore other bprm->unsafe flags if LSM_UNSAFE_PTRACE is setJann Horn1-1/+2
2019-07-10Revert "Merge tag 'keys-acl-20190703' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs"Linus Torvalds1-2/+1
2019-06-27keys: Replace uid/gid/perm permissions checking with an ACLDavid Howells1-1/+2
2019-06-19treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500Thomas Gleixner1-4/+1
2019-06-14Smack: Restore the smackfsdef mount option and add missing prefixesCasey Schaufler1-5/+7
2019-04-30Smack: Fix kbuild reported build errorCasey Schaufler1-0/+2
2019-04-29smack: Check address length before reading address familyTetsuo Handa1-4/+15
2019-04-03Smack: Fix IPv6 handling of 0 secmarkCasey Schaufler1-0/+2
2019-04-02Smack: Create smack_rule cache to optimize memory usageCasey Schaufler1-2/+9
2019-02-28introduce cloning of fs_contextAl Viro1-0/+49
2019-02-28smack: Implement filesystem context security hooksDavid Howells1-1/+42
2019-02-22security: mark expected switch fall-throughs and add a missing breakGustavo A. R. Silva1-2/+1
2019-01-31audit: remove unused actx param from audit_rule_matchRichard Guy Briggs1-3/+1
2019-01-18LSM: Make lsm_early_cred() and lsm_early_task() local functions.Tetsuo Handa1-2/+0
2019-01-08LSM: Infrastructure management of the ipc security blobCasey Schaufler1-28/+4
2019-01-08Smack: Abstract use of ipc security blobsCasey Schaufler1-5/+9
2019-01-08LSM: Infrastructure management of the inode securityCasey Schaufler1-59/+17