Security Enhanced Linux (SELINUX)
[Prev Page][Next Page]
- Re: [PATCH 4/4] libsemanage: cleanup linker map file, (continued)
- [PATCH v4] Add tests for default_range glblub,
Joshua Brindle
- [PATCH v3] Add tests for default_range glblub,
Joshua Brindle
- Looking for help testing patch attestation,
Konstantin Ryabitsev
- checkpolicy does not forward (t1 == t2) constraint correctly,
Christian Göttsche
- Policy module to allow a domain transition,
Alan Stern
- [PATCH v2] secilc: add basic test for policy optimization,
Ondrej Mosnacek
- [PATCH v1] perf tool: make Perf tool aware of SELinux access control,
Alexey Budankov
- [RFC PATCH 1/5] selinux-testsuite: add tests/sandbox/nodir_no_allow.cil,
Stephen Smalley
- [RFC PATCH] libsepol,secilc,policycoreutils: add unprivileged sandboxing capability, Stephen Smalley
- [RFC PATCH] selinux: add unprivileged sandboxing capability,
Stephen Smalley
- [PATCH] secilc: add basic test for policy optimization,
Ondrej Mosnacek
- [PATCH 0/2] selinux-testsuite: Use native filesystem for tests,
Richard Haines
- [PATCH testsuite] tests/bpf: ask for unlimited RLIMIT_MEMLOCK,
Ondrej Mosnacek
- [PATCH v2] Add tests for default_range glblub,
Joshua Brindle
- [PATCH] MAINTAINERS: Update my email address,
Stephen Smalley
- [RFC V3 PATCH 0/2] selinux-testsuite: Use native filesystem for tests,
Richard Haines
- [PATCH] checkpolicy: Treat invalid characters as an error,
Daniel Burgener
- libsepol drop dso.h,
bill . c . roberts
- libsepol: drop dso question on CFLAGS (package maintainers weigh in please),
William Roberts
- [PATCH] selinux: avtab_init() and cond_policydb_init() return void,
Paul Moore
- [PATCH] checkpolicy: Add --werror flag to checkmodule and checkpolicy to treat warnings as errors.,
Daniel Burgener
- [RFC PATCH v2] libsepol/cil: raise default attrs_expand_size to 2,
Ondrej Mosnacek
- [PATCH] libsepol/cil: Do not check flavor when checking for duplicate parameters,
James Carter
- [PATCH] libsepol/cil: Check if name is a macro parameter first,
James Carter
- [RFC PATCH] libsepol/cil: raise default attrs_expand_size to 2,
Ondrej Mosnacek
- strange pam selinux issue,
Dominick Grift
- [PATCH] NFS: Ensure security label is set for root inode,
Scott Mayhew
- [PATCH] selinux: clean up error path in policydb_init(),
Ondrej Mosnacek
- [PATCH] Revert "libsepol: cache ebitmap cardinality value",
Ondrej Mosnacek
- [PATCH testsuite] tests: add test for default_range glblub support,
Ondrej Mosnacek
- target context of security:setbool permission check,
Christian Göttsche
- ANN: Reference Policy 2.20200229, Chris PeBenito
- Please revert SELinux/keys patches from the keys linux-next branch,
Paul Moore
- libselinux: drop dso.h,
bill . c . roberts
[PATCH] libsemange: add missing header sepol/policydb.h,
bill . c . roberts
[PATCH 0/3] libsepol: Speed up policy optimization,
Ondrej Mosnacek
wrong secmark labels for ipsec packets from local service,
Christian Göttsche
[PATCH V2] libsepol: Create the macro ebitmap_is_empty() and use it where needed,
James Carter
[PATCH v3] selinux: reduce the use of hard-coded hash sizes,
Ondrej Mosnacek
[PATCH 1/1] libsepol: make ebitmap_cardinality() of linear complexity,
Nicolas Iooss
Annotate Deprecated Functions in libselinux,
bill . c . roberts
- [PATCH 01/17] security_load_booleans: update return comment, bill . c . roberts
- [PATCH 02/17] selinux_booleans_path: annotate deprecated, bill . c . roberts
- [PATCH 03/17] selinux_booleans_path: annotate deprecated, bill . c . roberts
- [PATCH 05/17] rpm_execcon: annotate deprecated, bill . c . roberts
- [PATCH 04/17] selinux_users_path: annotate deprecated, bill . c . roberts
- [PATCH 06/17] sidget: annotate deprecated, bill . c . roberts
- [PATCH 07/17] sidput: annotate deprecated, bill . c . roberts
- [PATCH 08/17] checkPasswdAccess: annotate deprecated, bill . c . roberts
- [PATCH 09/17] matchpathcon_init: annotate deprecated, bill . c . roberts
- [PATCH 10/17] matchpathcon_fini: annotate deprecated, bill . c . roberts
- [PATCH 11/17] matchpathcon: annotate deprecated, bill . c . roberts
- [PATCH 12/17] avc_init: annotate deprecated, bill . c . roberts
- [PATCH 13/17] src/selinux_internal.h: fix hidden_proto indents, bill . c . roberts
- [PATCH 14/17] selinux_internal.h: disable warnings on deprecated, bill . c . roberts
- [PATCH 15/17] avc_open: mark allowed use of avc_init, bill . c . roberts
- [PATCH 16/17] src/matchpathcon: allow use of deprecated funcs, bill . c . roberts
- [PATCH 17/17] utils/matchpathcon: allow use of deprecated funcs, bill . c . roberts
- Re: Annotate Deprecated Functions in libselinux, Stephen Smalley
- Annotate Deprecated Functions in libselinux, bill . c . roberts
- [PATCH v2 01/18] security_load_booleans: update return comment, bill . c . roberts
- [PATCH v2 03/18] selinux_booleans_path: annotate deprecated, bill . c . roberts
- [PATCH v2 02/18] security_load_booleans: annotate deprecated, bill . c . roberts
- [PATCH v2 04/18] selinux_users_path: annotate deprecated, bill . c . roberts
- [PATCH v2 05/18] rpm_execcon: annotate deprecated, bill . c . roberts
- [PATCH v2 06/18] sidget: annotate deprecated, bill . c . roberts
- [PATCH v2 08/18] checkPasswdAccess: annotate deprecated, bill . c . roberts
- [PATCH v2 07/18] sidput: annotate deprecated, bill . c . roberts
- [PATCH v2 10/18] matchpathcon_fini: annotate deprecated, bill . c . roberts
- [PATCH v2 11/18] matchpathcon: annotate deprecated, bill . c . roberts
- [PATCH v2 12/18] avc_init: annotate deprecated, bill . c . roberts
- [PATCH v2 09/18] matchpathcon_init: annotate deprecated, bill . c . roberts
- [PATCH v2 13/18] avc: create internal avc_init interface, bill . c . roberts
- [PATCH v2 14/18] matchpathcon: create internal matchpathcon_fini interface, bill . c . roberts
- [PATCH v2 15/18] matchpathcon: create internal matchpathcon interface, bill . c . roberts
- [PATCH v2 16/18] selinux_check_passwd_access: annotate deprecated, bill . c . roberts
- [PATCH v2 18/18] utils: matchpathcon add deprecated warning, bill . c . roberts
- [PATCH v2 17/18] utils: matchpathcon to use interal interfaces, bill . c . roberts
- Re: Annotate Deprecated Functions in libselinux, Nicolas Iooss
- RE: Annotate Deprecated Functions in libselinux, Roberts, William C
- [v3] Annotate Deprecated Functions in libselinux, bill . c . roberts
- [PATCH v3 01/19] security_load_booleans: update return comment, bill . c . roberts
- [PATCH v3 02/19] security_load_booleans: annotate deprecated, bill . c . roberts
- [PATCH v3 03/19] selinux_booleans_path: annotate deprecated, bill . c . roberts
- [PATCH v3 04/19] selinux_users_path: annotate deprecated, bill . c . roberts
- [PATCH v3 05/19] rpm_execcon: annotate deprecated, bill . c . roberts
- [PATCH v3 06/19] sidget: annotate deprecated, bill . c . roberts
- [PATCH v3 07/19] sidput: annotate deprecated, bill . c . roberts
- [PATCH v3 08/19] checkPasswdAccess: annotate deprecated, bill . c . roberts
- [PATCH v3 09/19] matchpathcon_init: annotate deprecated, bill . c . roberts
- [PATCH v3 10/19] matchpathcon_fini: annotate deprecated, bill . c . roberts
- [PATCH v3 11/19] matchpathcon: annotate deprecated, bill . c . roberts
- [PATCH v3 12/19] avc_init: annotate deprecated, bill . c . roberts
- [PATCH v3 13/19] avc: create internal avc_init interface, bill . c . roberts
- [PATCH v3 14/19] matchpathcon: create internal matchpathcon_fini interface, bill . c . roberts
- [PATCH v3 16/19] selinux_check_passwd_access: annotate deprecated, bill . c . roberts
- [PATCH v3 17/19] matchpathcon: allow use of deprecated routines, bill . c . roberts
- [PATCH v3 15/19] matchpathcon: create internal matchpathcon interface, bill . c . roberts
- [PATCH v3 18/19] utils: matchpathcon add deprecated warning, bill . c . roberts
- [PATCH v3 19/19] Makefile: swig build allow deprecated functions, bill . c . roberts
- [v4] Annotate Deprecated Functions in libselinux, bill . c . roberts
- [PATCH v4 01/18] security_load_booleans: update return comment, bill . c . roberts
- [PATCH v4 02/18] security_load_booleans: annotate deprecated, bill . c . roberts
- [PATCH v4 03/18] selinux_booleans_path: annotate deprecated, bill . c . roberts
- [PATCH v4 04/18] selinux_users_path: annotate deprecated, bill . c . roberts
- [PATCH v4 05/18] rpm_execcon: annotate deprecated, bill . c . roberts
- [PATCH v4 06/18] sidget: annotate deprecated, bill . c . roberts
- [PATCH v4 07/18] sidput: annotate deprecated, bill . c . roberts
- [PATCH v4 08/18] checkPasswdAccess: annotate deprecated, bill . c . roberts
- [PATCH v4 09/18] matchpathcon_init: annotate deprecated, bill . c . roberts
- [PATCH v4 10/18] matchpathcon_fini: annotate deprecated, bill . c . roberts
- [PATCH v4 11/18] matchpathcon: annotate deprecated, bill . c . roberts
- [PATCH v4 13/18] avc: create internal avc_init interface, bill . c . roberts
- [PATCH v4 14/18] matchpathcon: create internal matchpathcon_fini interface, bill . c . roberts
- [PATCH v4 15/18] selinux_check_passwd_access: annotate deprecated, bill . c . roberts
- [PATCH v4 16/18] matchpathcon: allow use of deprecated routines, bill . c . roberts
- [PATCH v4 12/18] avc_init: annotate deprecated, bill . c . roberts
- [PATCH v4 17/18] utils: matchpathcon add deprecated warning, bill . c . roberts
- [PATCH v4 18/18] Makefile: swig build allow deprecated functions, bill . c . roberts
- Re: [v4] Annotate Deprecated Functions in libselinux, Nicolas Iooss
[PATCH testsuite v2] tests/sctp: fix setting of the SCTP_EVENTS sockopt,
Ondrej Mosnacek
Fwd: [PATCH v4] selinux: remove unused initial SIDs and improve handling,
Paul Moore
strange issue with name-base type trans,
Dominick Grift
[RFC V2 PATCH 0/2] selinux-testsuite: Use native filesystem for tests,
Richard Haines
[PATCH testsuite] tests/sctp: fix setting of the SCTP_EVENTS sockopt,
Ondrej Mosnacek
Re: ❌ FAIL: Test report for kernel 5.4.22-rc2-b0b4130.cki (stable), Ondrej Mosnacek
[PATCH V2] selinux-testsuite: Allow nfs test script to close cleanly,
Richard Haines
[PATCH] libselinux: deprecate security_compute_user(), update man pages,
Petr Lautrbach
Message not available
Re: [PATCH] libselinux: deprecate security_compute_user(), update man pages, Stephen Smalley
[RFC PATCH 0/1] selinux: Add support for new key permissions,
Richard Haines
Message not available
Re: [RFC PATCH 1/1] selinux: Add support for new key permissions, David Howells
[PATCH] selinux-testsuite: Allow nfs test script to close cleanly, Richard Haines
[PATCH 0/1] selinux: Add xfs quota command types,
Richard Haines
[PATCH] libselinux/getconlist: add verbose switch to print more information,
Christian Göttsche
Test to trace NFS unlabeled bug,
Richard Haines
[PATCH] libsepol: Create the macro ebitmap_is_empty() and use it where needed,
James Carter
Re: [selinux-internal] SELinux support in virtio-fs,
Ondrej Mosnacek
[PATCH v2 0/2] libsepol: Grow hashtab dynamically,
Ondrej Mosnacek
[PATCH 0/2] libsepol: Grow hashtab dynamically,
Ondrej Mosnacek
[PATCH v2] selinux: reduce the use of hard-coded hash sizes,
Ondrej Mosnacek
[RFC PATCH] libselinux: deprecate security_compute_user(), update man pages, Stephen Smalley
[PATCH] libsepol: Use ebitmap_length() to check for an empty ebitmap,
James Carter
[PATCH v3] selinux: optimize storage of filename transitions,
Ondrej Mosnacek
[PATCH] libselinux: Fix Ru translation of failsafe context,
Mikhail Novosyolov
[PATCH v6] libselinux: Eliminate use of security_compute_user(),
Petr Lautrbach
[PATCH] selinux: reduce the use of hard-coded hash sizes,
Ondrej Mosnacek
[PATCH v7 00/12] Introduce CAP_PERFMON to secure system performance monitoring and observability,
Alexey Budankov
- [PATCH v7 01/12] capabilities: introduce CAP_PERFMON to kernel and user space, Alexey Budankov
- [PATCH v7 02/12] perf/core: open access to the core for CAP_PERFMON privileged process, Alexey Budankov
- [PATCH v7 03/12] perf/core: open access to probes for CAP_PERFMON privileged process, Alexey Budankov
- [PATCH v7 04/12] perf tool: extend Perf tool with CAP_PERFMON capability support, Alexey Budankov
- [PATCH v7 05/12] drm/i915/perf: open access for CAP_PERFMON privileged process, Alexey Budankov
- [PATCH v7 06/12] trace/bpf_trace: open access for CAP_PERFMON privileged process, Alexey Budankov
- [PATCH v7 07/12] powerpc/perf: open access for CAP_PERFMON privileged process, Alexey Budankov
- [PATCH v7 08/12] parisc/perf: open access for CAP_PERFMON privileged process, Alexey Budankov
- [PATCH v7 09/12] drivers/perf: open access for CAP_PERFMON privileged process, Alexey Budankov
- [PATCH v7 10/12] drivers/oprofile: open access for CAP_PERFMON privileged process, Alexey Budankov
- [PATCH v7 11/12] doc/admin-guide: update perf-security.rst with CAP_PERFMON information, Alexey Budankov
- [PATCH v7 12/12] doc/admin-guide: update kernel.rst with CAP_PERFMON information, Alexey Budankov
- Re: [PATCH v7 00/12] Introduce CAP_PERFMON to secure system performance monitoring and observability, Alexey Budankov
Duplicate hashtab code in libsepol vs. policycoreutils/newrole?,
Ondrej Mosnacek
[PATCH v15 00/23] LSM: Module stacking for AppArmor,
Casey Schaufler
- [PATCH v15 01/23] LSM: Infrastructure management of the sock security, Casey Schaufler
- [PATCH v15 03/23] LSM: Use lsmblob in security_audit_rule_match, Casey Schaufler
- [PATCH v15 02/23] LSM: Create and manage the lsmblob data structure., Casey Schaufler
- [PATCH v15 04/23] LSM: Use lsmblob in security_kernel_act_as, Casey Schaufler
- [PATCH v15 05/23] net: Prepare UDS for security module stacking, Casey Schaufler
- [PATCH v15 06/23] Use lsmblob in security_secctx_to_secid, Casey Schaufler
- [PATCH v15 07/23] LSM: Use lsmblob in security_secid_to_secctx, Casey Schaufler
- [PATCH v15 08/23] LSM: Use lsmblob in security_ipc_getsecid, Casey Schaufler
- [PATCH v15 09/23] LSM: Use lsmblob in security_task_getsecid, Casey Schaufler
- [PATCH v15 10/23] LSM: Use lsmblob in security_inode_getsecid, Casey Schaufler
- [PATCH v15 11/23] LSM: Use lsmblob in security_cred_getsecid, Casey Schaufler
- [PATCH v15 12/23] IMA: Change internal interfaces to use lsmblobs, Casey Schaufler
- [PATCH v15 13/23] LSM: Specify which LSM to display, Casey Schaufler
- [PATCH v15 14/23] LSM: Ensure the correct LSM context releaser, Casey Schaufler
- [PATCH v15 15/23] LSM: Use lsmcontext in security_secid_to_secctx, Casey Schaufler
- [PATCH v15 17/23] LSM: security_secid_to_secctx in netlink netfilter, Casey Schaufler
- [PATCH v15 16/23] LSM: Use lsmcontext in security_inode_getsecctx, Casey Schaufler
- [PATCH v15 19/23] LSM: Verify LSM display sanity in binder, Casey Schaufler
- [PATCH v15 18/23] NET: Store LSM netlabel data in a lsmblob, Casey Schaufler
- [PATCH v15 20/23] Audit: Add subj_LSM fields when necessary, Casey Schaufler
- [PATCH v15 21/23] Audit: Include object data for all security modules, Casey Schaufler
- [PATCH v15 23/23] AppArmor: Remove the exclusive flag, Casey Schaufler
- [PATCH v15 22/23] LSM: Add /proc attr entry for full LSM context, Casey Schaufler
- <Possible follow-ups>
- [PATCH v15 00/23] LSM: Module stacking for AppArmor, Casey Schaufler
- [PATCH v15 00/23] LSM: Module stacking for AppArmor, Casey Schaufler
- [PATCH v15 00/23] LSM: Module stacking for AppArmor, Casey Schaufler
- [PATCH v15 00/23] LSM: Module stacking for AppArmor, Casey Schaufler
- [PATCH v15 00/23] LSM: Module stacking for AppArmor, Casey Schaufler
Re: [RFC PATCH 1/1] selinux-testsuite: Use native filesystem for fs tests,
Stephen Smalley
[PATCH AUTOSEL 5.5 182/542] selinux: fall back to ref-walk if audit is required, Sasha Levin
[PATCH AUTOSEL 5.5 181/542] selinux: revert "stop passing MAY_NOT_BLOCK to the AVC upon follow_link", Sasha Levin
[PATCH AUTOSEL 5.5 190/542] selinux: ensure we cleanup the internal AVC counters on error in avc_insert(),
Sasha Levin
[PATCH AUTOSEL 5.5 249/542] selinux: ensure we cleanup the internal AVC counters on error in avc_update(), Sasha Levin
[PATCH AUTOSEL 5.5 417/542] selinux: fix regression introduced by move_mount(2) syscall, Sasha Levin
[PATCH AUTOSEL 5.4 157/459] selinux: revert "stop passing MAY_NOT_BLOCK to the AVC upon follow_link", Sasha Levin
[PATCH AUTOSEL 5.4 158/459] selinux: fall back to ref-walk if audit is required, Sasha Levin
[PATCH AUTOSEL 5.4 216/459] selinux: ensure we cleanup the internal AVC counters on error in avc_update(), Sasha Levin
[PATCH AUTOSEL 5.4 357/459] selinux: fix regression introduced by move_mount(2) syscall, Sasha Levin
[PATCH AUTOSEL 4.19 080/252] selinux: fall back to ref-walk if audit is required, Sasha Levin
[PATCH AUTOSEL 4.19 085/252] selinux: ensure we cleanup the internal AVC counters on error in avc_insert(), Sasha Levin
[PATCH AUTOSEL 4.19 115/252] selinux: ensure we cleanup the internal AVC counters on error in avc_update(), Sasha Levin
[PATCH AUTOSEL 5.4 166/459] selinux: ensure we cleanup the internal AVC counters on error in avc_insert(), Sasha Levin
[RFC PATCH] security,anon_inodes,kvm: enable security support for anon inodes,
Stephen Smalley
[RFC PATCH 0/1] selinux-testsuite: Use native filesystem for fs tests,
Richard Haines
[PATCH userspace v2] libsepol: cache ebitmap cardinality value,
Ondrej Mosnacek
FYI: selinux/working-selinuxns branch has been updated, Paul Moore
[PATCH userspace] libsepol: cache ebitmap cardinality value,
Ondrej Mosnacek
[PATCH v2 0/2] Optimize storage of filename transitions,
Ondrej Mosnacek
[PATCH v2 0/6] Harden userfaultfd,
Daniel Colascione
[Index of Archives]
[Selinux Refpolicy]
[Fedora Users]
[Fedora Desktop]
[Kernel]
[KDE Users]
[Gnome Users]