index
:
wireguard-linux
backport-5.4.y
davem/net
davem/net-next
devel
gregkh/stable-5.4.y
jd/bump-compilers
jd/deferred-aip-removal
jd/new-archs
jd/orphan-parallel
jd/rcu-barrier
jd/shorter-socket-lock
jd/unified-crypt-queue
jd/xdp-l3
stable
update-toolchain
WireGuard for the Linux kernel
Jason A. Donenfeld
about
summary
refs
log
tree
commit
diff
stats
homepage
log msg
author
committer
range
path:
root
/
security
Age
Commit message (
Expand
)
Author
Files
Lines
2025-07-20
apparmor: fix: accept2 being specifie even when permission table is presnt
John Johansen
1
-1
/
+2
2025-07-20
apparmor: transition from a list of rules to a vector of rules
John Johansen
15
-113
/
+85
2025-07-20
apparmor: fix documentation mismatches in val_mask_to_str and socket functions
Peng Jiang
2
-3
/
+23
2025-07-20
apparmor: remove redundant perms.allow MAY_EXEC bitflag set
Ryan Lee
1
-3
/
+1
2025-07-20
apparmor: fix kernel doc warnings for kernel test robot
John Johansen
2
-4
/
+10
2025-07-20
apparmor: Fix unaligned memory accesses in KUnit test
Helge Deller
1
-2
/
+4
2025-07-20
apparmor: Fix 8-byte alignment for initial dfa blob streams
Helge Deller
1
-2
/
+2
2025-07-20
apparmor: shift uid when mediating af_unix in userns
Gabriel Totev
1
-2
/
+6
2025-07-20
apparmor: shift ouid when mediating hard links in userns
Gabriel Totev
1
-2
/
+4
2025-07-20
apparmor: make sure unix socket labeling is correctly updated.
John Johansen
6
-62
/
+231
2025-07-19
landlock: Fix cosmetic change
Mickaël Salaün
1
-0
/
+1
2025-07-15
apparmor: fix regression in fs based unix sockets when using old abi
John Johansen
2
-51
/
+71
2025-07-15
apparmor: fix AA_DEBUG_LABEL()
John Johansen
1
-1
/
+1
2025-07-15
apparmor: fix af_unix auditing to include all address information
John Johansen
3
-10
/
+18
2025-07-15
apparmor: Remove use of the double lock
John Johansen
5
-102
/
+104
2025-07-15
apparmor: update kernel doc comments for xxx_label_crit_section
John Johansen
1
-0
/
+8
2025-07-15
apparmor: make __begin_current_label_crit_section() indicate whether put is needed
Mateusz Guzik
3
-41
/
+67
2025-07-15
Revert "apparmor: use SHA-256 library API instead of crypto_shash API"
John Johansen
2
-13
/
+75
2025-07-15
apparmor: mitigate parser generating large xtables
John Johansen
3
-6
/
+45
2025-07-14
apparmor: use SHA-256 library API instead of crypto_shash API
Eric Biggers
2
-75
/
+13
2025-07-09
integrity/platform_certs: Allow loading of keys in the static key management mode
Srish Srinivasan
1
-2
/
+3
2025-07-04
tree-wide: s/struct fileattr/struct file_kattr/g
Christian Brauner
2
-4
/
+4
2025-07-01
selinux: implement inode_file_[g|s]etattr hooks
Andrey Albershteyn
1
-0
/
+14
2025-07-01
lsm: introduce new hooks for setting/getting inode fsxattr
Andrey Albershteyn
1
-0
/
+30
2025-06-30
smack: fix kernel-doc warnings for smk_import_valid_label()
Konstantin Andreev
1
-2
/
+4
2025-06-27
landlock: Fix warning from KUnit tests
Tingmao Wang
1
-27
/
+42
2025-06-24
selinux: don't bother with selinuxfs_info_free() on failures
Al Viro
1
-2
/
+0
2025-06-24
smack: fix bug: setting task label silently ignores input garbage
Konstantin Andreev
3
-63
/
+148
2025-06-24
smack: fix bug: unprivileged task can create labels
Konstantin Andreev
1
-14
/
+27
2025-06-23
exec: Correct the permission check for unsafe exec
Eric W. Biederman
1
-12
/
+8
2025-06-22
smack: fix bug: invalid label of unix socket file
Konstantin Andreev
1
-14
/
+44
2025-06-22
smack: always "instantiate" inode in smack_inode_init_security()
Konstantin Andreev
1
-3
/
+7
2025-06-22
smack: deduplicate xattr setting in smack_inode_init_security()
Konstantin Andreev
1
-26
/
+28
2025-06-22
smack: fix bug: SMACK64TRANSMUTE set on non-directory
Konstantin Andreev
1
-11
/
+13
2025-06-22
smack: deduplicate "does access rule request transmutation"
Konstantin Andreev
1
-25
/
+32
2025-06-19
selinux: add __GFP_NOWARN to hashtab_init() allocations
Paul Moore
1
-1
/
+2
2025-06-19
selinux: optimize selinux_inode_getattr/permission() based on neveraudit|permissive
Stephen Smalley
2
-1
/
+21
2025-06-19
selinux: introduce neveraudit types
Stephen Smalley
5
-1
/
+48
2025-06-19
selinux: change security_compute_sid to return the ssid or tsid on match
Stephen Smalley
1
-5
/
+11
2025-06-17
ipe: don't bother with removal of files in directory we'll be removing
Al Viro
2
-22
/
+14
2025-06-17
evm_secfs: clear securityfs interactions
Al Viro
1
-8
/
+7
2025-06-17
ima_fs: get rid of lookup-by-dentry stuff
Al Viro
1
-66
/
+16
2025-06-17
ima_fs: don't bother with removal of files in directory we'll be removing
Al Viro
1
-39
/
+18
2025-06-17
apparmor: file never has NULL f_path.mnt
Al Viro
1
-1
/
+1
2025-06-17
landlock: opened file never has a negative dentry
Al Viro
1
-1
/
+0
2025-06-16
selinux: fix selinux_xfrm_alloc_user() to set correct ctx_len
Stephen Smalley
1
-1
/
+1
2025-06-16
selinux: add a 5 second sleep to /sys/fs/selinux/user
Paul Moore
1
-0
/
+1
2025-06-16
lsm: trivial comment fix
Kalevi Kolttonen
1
-1
/
+1
2025-06-16
ima: add a knob ima= to allow disabling IMA in kdump kernel
Baoquan He
1
-0
/
+26
2025-06-11
make securityfs_remove() remove the entire subtree
Al Viro
1
-37
/
+10
[prev]
[next]