Security Enhanced Linux (SELINUX)
[Prev Page][Next Page]
- Re: [PATCH v2 11/25] security: add hooks for set/get/remove of fscaps, (continued)
- [PATCH v2 14/25] evm: add support for fscaps security hooks, Seth Forshee (DigitalOcean)
- [PATCH v2 13/25] smack: add hooks for fscaps operations, Seth Forshee (DigitalOcean)
- [PATCH v2 08/25] xattr: add is_fscaps_xattr() helper, Seth Forshee (DigitalOcean)
- [PATCH v2 10/25] xattr: use is_fscaps_xattr(), Seth Forshee (DigitalOcean)
- [PATCH v2 09/25] commoncap: use is_fscaps_xattr(), Seth Forshee (DigitalOcean)
- [PATCH v2 22/25] fs: use vfs interfaces for capabilities xattrs, Seth Forshee (DigitalOcean)
- [PATCH v2 16/25] fs: add inode operations to get/set/remove fscaps, Seth Forshee (DigitalOcean)
- [PATCH v2 17/25] fs: add vfs_get_fscaps(), Seth Forshee (DigitalOcean)
- [PATCH v2 20/25] ovl: add fscaps handlers, Seth Forshee (DigitalOcean)
- [PATCH v2 21/25] ovl: use vfs_{get,set}_fscaps() for copy-up, Seth Forshee (DigitalOcean)
- [PATCH v2 19/25] fs: add vfs_remove_fscaps(), Seth Forshee (DigitalOcean)
- [PATCH v2 18/25] fs: add vfs_set_fscaps(), Seth Forshee (DigitalOcean)
- [PATCH v2 15/25] security: call evm fscaps hooks from generic security hooks, Seth Forshee (DigitalOcean)
- [PATCH v2 23/25] commoncap: remove cap_inode_getsecurity(), Seth Forshee (DigitalOcean)
- [PATCH v2 25/25] vfs: return -EOPNOTSUPP for fscaps from vfs_*xattr(), Seth Forshee (DigitalOcean)
- [PATCH v2 24/25] commoncap: use vfs fscaps interfaces, Seth Forshee (DigitalOcean)
- Re: [PATCH v2 00/25] fs: use type-safe uid representation for filesystem capabilities, Christian Brauner
- [PATCH v2] checkpolicy, libsepol: Fix potential double free of mls_level_t,
James Carter
- [PATCH PR#420 v2] audit2allow: CIL output mode, Topi Miettinen
- [PATCH PR#420] audit2allow: CIL output mode,
Topi Miettinen
- [PATCH] Always build for LFS mode on 32-bit archs.,
Steve Langasek
- [PATCH v7 0/4] per-vma locks in userfaultfd,
Lokesh Gidra
- [PATCH v10 00/25] security: Move IMA and EVM to the LSM infrastructure,
Roberto Sassu
- [PATCH v10 01/25] ima: Align ima_inode_post_setattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v10 02/25] ima: Align ima_file_mprotect() definition with LSM infrastructure, Roberto Sassu
- [PATCH v10 03/25] ima: Align ima_inode_setxattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v10 04/25] ima: Align ima_inode_removexattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v10 05/25] ima: Align ima_post_read_file() definition with LSM infrastructure, Roberto Sassu
- [PATCH v10 06/25] evm: Align evm_inode_post_setattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v10 07/25] evm: Align evm_inode_setxattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v10 08/25] evm: Align evm_inode_post_setxattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v10 09/25] security: Align inode_setattr hook definition with EVM, Roberto Sassu
- [PATCH v10 10/25] security: Introduce inode_post_setattr hook, Roberto Sassu
- [PATCH v10 11/25] security: Introduce inode_post_removexattr hook, Roberto Sassu
- [PATCH v10 12/25] security: Introduce file_post_open hook, Roberto Sassu
- [PATCH v10 13/25] security: Introduce file_release hook, Roberto Sassu
- [PATCH v10 14/25] security: Introduce path_post_mknod hook, Roberto Sassu
- [PATCH v10 15/25] security: Introduce inode_post_create_tmpfile hook, Roberto Sassu
- [PATCH v10 16/25] security: Introduce inode_post_set_acl hook, Roberto Sassu
- [PATCH v10 17/25] security: Introduce inode_post_remove_acl hook, Roberto Sassu
- [PATCH v10 18/25] security: Introduce key_post_create_or_update hook, Roberto Sassu
- [PATCH v10 19/25] integrity: Move integrity_kernel_module_request() to IMA, Roberto Sassu
- [PATCH v10 20/25] ima: Move to LSM infrastructure, Roberto Sassu
- [PATCH v10 21/25] ima: Move IMA-Appraisal to LSM infrastructure, Roberto Sassu
- [PATCH v10 23/25] evm: Make it independent from 'integrity' LSM, Roberto Sassu
- [PATCH v10 24/25] ima: Make it independent from 'integrity' LSM, Roberto Sassu
- [PATCH v10 25/25] integrity: Remove LSM, Roberto Sassu
- [PATCH v10 22/25] evm: Move to LSM infrastructure, Roberto Sassu
- Re: [PATCH v10 0/25] security: Move IMA and EVM to the LSM infrastructure, Paul Moore
- Re: [PATCH v10 00/25] security: Move IMA and EVM to the LSM infrastructure, Eric Snowberg
- [PATCH v6 0/3] per-vma locks in userfaultfd,
Lokesh Gidra
- [PATCH] checkpolicy, libsepol: Fix potential double free of mls_level_t,
James Carter
- [PATCH v5 0/3] per-vma locks in userfaultfd,
Lokesh Gidra
- [PATCH testsuite] tests/inet_socket: test CALIPSO also with datagram protocols,
Ondrej Mosnacek
- [PATCH v4 0/3] per-vma locks in userfaultfd,
Lokesh Gidra
- [PATCH testsuite] policy: fix testsuite_domain_type_minimal() to work with rpm-ostree,
Ondrej Mosnacek
- [PATCH] python/semanage: Do not sort local fcontext definitions,
Vit Mojzis
- [PATCH 5.4,4.19] lsm: new security_file_ioctl_compat() hook,
Eric Biggers
- [PATCH v3 0/3] per-vma locks in userfaultfd,
Lokesh Gidra
- Calls to vfs_setlease() from NFSD code cause unnecessary CAP_LEASE security checks,
Ondrej Mosnacek
- [PATCH v2] selinux: only filter copy-up xattrs following initialization,
David Disseldorp
- [RFC PATCH v2 0/9] libselinux: rework selabel_file(5) database,
Christian Göttsche
- [PATCH 1/3] libsepol: ensure transitivity in compare functions,
Christian Göttsche
- [PATCH] selinux: correct return values in selinux_socket_getpeersec_dgram(),
Paul Moore
- [PATCH v2 0/3] per-vma locks in userfaultfd,
Lokesh Gidra
- [PATCH] security: fix no-op hook logic in security_inode_{set,remove}xattr(),
Ondrej Mosnacek
- [PATCH] selinux: Use kfree_sensitive for certain code paths of security,
Ronald Monthero
- [PATCH] lsm: fix default return value of the socket_getpeersec_* hooks,
Ondrej Mosnacek
- [PATCH 1/3] userfaultfd: move userfaultfd_ctx struct to header file,
Lokesh Gidra
- [PATCH] security: fix the logic in security_inode_getsecctx(),
Ondrej Mosnacek
- selinux-testsuite nfs tests?,
Stephen Smalley
- [PATCH] python/semanage: Allow modifying records on "add",
Vit Mojzis
- [PATCH] io_uring: enable audit and restrict cred override for IORING_OP_FIXED_FD_INSTALL,
Paul Moore
- [PATCH 01/15] checkpolicy: add libfuzz based fuzzer,
Christian Göttsche
- [PATCH 02/15] checkpolicy: cleanup resources on parse error, Christian Göttsche
- [PATCH 04/15] checkpolicy: free ebitmap on error, Christian Göttsche
- [PATCH 03/15] checkpolicy: cleanup identifiers on error, Christian Göttsche
- [PATCH 05/15] checkpolicy: check allocation and free memory on error at type definition, Christian Göttsche
- [PATCH 08/15] checkpolicy: bail out on invalid role, Christian Göttsche
- [PATCH 09/15] libsepol: use typedef, Christian Göttsche
- [PATCH 06/15] checkpolicy: clean expression on error, Christian Göttsche
- [PATCH 07/15] checkpolicy: call YYABORT on parse errors, Christian Göttsche
- [PATCH 11/15] checkpolicy: fix use-after-free on invalid sens alias, Christian Göttsche
- [PATCH 10/15] libsepol: add copy member to level_datum, Christian Göttsche
- [PATCH 13/15] checkpolicy: free temporary bounds type, Christian Göttsche
- [PATCH 12/15] checkpolicy: provide more descriptive error messages, Christian Göttsche
- [PATCH 15/15] checkpolicy: misc policy_define.c cleanup, Christian Göttsche
- [PATCH 14/15] checkpolicy: avoid assigning garbage values, Christian Göttsche
- Re: [PATCH 01/15] checkpolicy: add libfuzz based fuzzer, James Carter
- IORING_OP_FIXED_FD_INSTALL and audit/LSM interactions,
Paul Moore
- [PATCH] selinux: reduce the object class calculations at inode init time,
Paul Moore
- Race in security/selinux/hooks.c on isec->sclass and isec->sid usage,
Gabriel Ryan
- [PATCH] userfaultfd: fix return error if mmap_changing is non-zero in MOVE ioctl,
Lokesh Gidra
- [PATCH] userfaultfd: fix mmap_changing checking in mfill_atomic_hugetlb,
Lokesh Gidra
[PATCH v9 00/25] security: Move IMA and EVM to the LSM infrastructure,
Roberto Sassu
- [PATCH v9 01/25] ima: Align ima_inode_post_setattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v9 02/25] ima: Align ima_file_mprotect() definition with LSM infrastructure, Roberto Sassu
- [PATCH v9 03/25] ima: Align ima_inode_setxattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v9 05/25] ima: Align ima_post_read_file() definition with LSM infrastructure, Roberto Sassu
- [PATCH v9 06/25] evm: Align evm_inode_post_setattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v9 07/25] evm: Align evm_inode_setxattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v9 08/25] evm: Align evm_inode_post_setxattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v9 09/25] security: Align inode_setattr hook definition with EVM, Roberto Sassu
- [PATCH v9 10/25] security: Introduce inode_post_setattr hook, Roberto Sassu
- [PATCH v9 11/25] security: Introduce inode_post_removexattr hook, Roberto Sassu
- [PATCH v9 12/25] security: Introduce file_post_open hook, Roberto Sassu
- [PATCH v9 14/25] security: Introduce path_post_mknod hook, Roberto Sassu
- [PATCH v9 15/25] security: Introduce inode_post_create_tmpfile hook, Roberto Sassu
- [PATCH v9 16/25] security: Introduce inode_post_set_acl hook, Roberto Sassu
- [PATCH v9 17/25] security: Introduce inode_post_remove_acl hook, Roberto Sassu
- [PATCH v9 18/25] security: Introduce key_post_create_or_update hook, Roberto Sassu
- [PATCH v9 19/25] integrity: Move integrity_kernel_module_request() to IMA, Roberto Sassu
- [PATCH v9 20/25] ima: Move to LSM infrastructure, Roberto Sassu
- [PATCH v9 21/25] ima: Move IMA-Appraisal to LSM infrastructure, Roberto Sassu
- [PATCH v9 22/25] evm: Move to LSM infrastructure, Roberto Sassu
- [PATCH v9 23/25] evm: Make it independent from 'integrity' LSM, Roberto Sassu
- [PATCH v9 24/25] ima: Make it independent from 'integrity' LSM, Roberto Sassu
- [PATCH v9 25/25] integrity: Remove LSM, Roberto Sassu
- [PATCH v9 04/25] ima: Align ima_inode_removexattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v9 13/25] security: Introduce file_release hook, Roberto Sassu
- Re: [PATCH v9 0/25] security: Move IMA and EVM to the LSM infrastructure, Paul Moore
[PATCH] libselinux: use reentrant strtok_r(3),
Christian Göttsche
ANN: SELint 1.5, Daniel Burgener
[PATCH] libsepol/src/Makefile: fix reallocarray detection,
Fabrice Fontaine
[RFC PATCH] libselinux: disable capturing in fcontext matching,
Christian Göttsche
[GIT PULL] selinux/selinux-pr-20240105,
Paul Moore
[PATCH] libselinux: Fix ordering of arguments to calloc,
James Carter
[PATCH 1/4] libsepol: reorder calloc(3) arguments,
Christian Göttsche
SELinux style fixes,
Paul Moore
- [PATCH 03/15] selinux: align avc_has_perm_noaudit() prototype with definition, Paul Moore
- [PATCH 02/15] selinux: fix style issues in security/selinux/include/avc.h, Paul Moore
- [PATCH 01/15] selinux: fix style issues in security/selinux/include/audit.h, Paul Moore
- [PATCH 06/15] selinux: fix style issues in security/selinux/include/conditional.h, Paul Moore
- [PATCH 04/15] selinux: fix style issues in security/selinux/include/avc_ss.h, Paul Moore
- [PATCH 05/15] selinux: fix style issues in security/selinux/include/classmap.h, Paul Moore
- [PATCH 08/15] selinux: fix style issues in security/selinux/include/netif.h, Paul Moore
- [PATCH 09/15] selinux: fix style issues with security/selinux/include/netlabel.h, Paul Moore
- [PATCH 07/15] selinux: fix style issues in security/selinux/include/ima.h, Paul Moore
- [PATCH 10/15] selinux: fix style issues in security/selinux/include/objsec.h, Paul Moore
- [PATCH 11/15] selinux: fix style issues in security/selinux/include/policycap.h, Paul Moore
- [PATCH 13/15] selinux: fix style issues in security/selinux/include/security.h, Paul Moore
- [PATCH 12/15] selinux: fix style issues with security/selinux/include/policycap_names.h, Paul Moore
- [PATCH 14/15] selinux: fix style issues in security/selinux/include/xfrm.h, Paul Moore
- [PATCH 15/15] selinux: fix style issues in security/selinux/include/initial_sid_to_string.h, Paul Moore
[PATCH] MAINTAINERS: drop Eric Paris from his SELinux role,
Paul Moore
[PATCH] MAINTAINERS: add Ondrej Mosnacek as a SELinux reviewer,
Paul Moore
[PATCH 01/11] libselinux/man: mention errno for regex compilation failure,
Christian Göttsche
- [PATCH 02/11] libselinux/man: sync selinux_check_securetty_context(3), Christian Göttsche
- [PATCH 06/11] libselinux: fail selabel_open(3) on invalid option, Christian Göttsche
- [PATCH 04/11] libselinux/utils: improve compute_av output, Christian Göttsche
- [PATCH 03/11] libselinux/utils: free allocated resources, Christian Göttsche
- [PATCH 05/11] libselinux: align SELABEL_OPT_DIGEST usage with man page, Christian Göttsche
- [PATCH 07/11] libselinux: use logging wrapper in getseuser(3) and get_default_context(3) family, Christian Göttsche
- [PATCH 09/11] libsemanage: support huge passwd entries, Christian Göttsche
- [PATCH 08/11] libselinux: support huge passwd/group entries, Christian Göttsche
- [PATCH 11/11] setfiles: avoid unsigned integer underflow, Christian Göttsche
- [PATCH 10/11] libselinux: enable usage with pedantic UB sanitizers, Christian Göttsche
- Re: [PATCH 01/11] libselinux/man: mention errno for regex compilation failure, James Carter
[PATCH] SELinux: Introduce security_file_ioctl_compat hook,
Alfred Piccioni
[PATCH v8 00/24] security: Move IMA and EVM to the LSM infrastructure,
Roberto Sassu
- [PATCH v8 01/24] ima: Align ima_inode_post_setattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v8 02/24] ima: Align ima_file_mprotect() definition with LSM infrastructure, Roberto Sassu
- [PATCH v8 03/24] ima: Align ima_inode_setxattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v8 04/24] ima: Align ima_inode_removexattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v8 05/24] ima: Align ima_post_read_file() definition with LSM infrastructure, Roberto Sassu
- [PATCH v8 06/24] evm: Align evm_inode_post_setattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v8 07/24] evm: Align evm_inode_setxattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v8 08/24] evm: Align evm_inode_post_setxattr() definition with LSM infrastructure, Roberto Sassu
- [PATCH v8 09/24] security: Align inode_setattr hook definition with EVM, Roberto Sassu
- [PATCH v8 10/24] security: Introduce inode_post_setattr hook, Roberto Sassu
- [PATCH v8 11/24] security: Introduce inode_post_removexattr hook, Roberto Sassu
- [PATCH v8 12/24] security: Introduce file_post_open hook, Roberto Sassu
- [PATCH v8 13/24] security: Introduce file_release hook, Roberto Sassu
- [PATCH v8 14/24] security: Introduce path_post_mknod hook, Roberto Sassu
- [PATCH v8 15/24] security: Introduce inode_post_create_tmpfile hook, Roberto Sassu
- [PATCH v8 16/24] security: Introduce inode_post_set_acl hook, Roberto Sassu
- [PATCH v8 17/24] security: Introduce inode_post_remove_acl hook, Roberto Sassu
- [PATCH v8 18/24] security: Introduce key_post_create_or_update hook, Roberto Sassu
- [PATCH v8 19/24] ima: Move to LSM infrastructure, Roberto Sassu
- [PATCH v8 20/24] ima: Move IMA-Appraisal to LSM infrastructure, Roberto Sassu
- [PATCH v8 21/24] evm: Move to LSM infrastructure, Roberto Sassu
- [PATCH v8 22/24] evm: Make it independent from 'integrity' LSM, Roberto Sassu
- [PATCH v8 23/24] ima: Make it independent from 'integrity' LSM, Roberto Sassu
- [PATCH v8 24/24] integrity: Remove LSM, Roberto Sassu
Fwd: SELinux mprotect EACCES/execheap for memory segment directly adjacent to heap,
Bagas Sanjaya
[UTIL-LINUX PATCH] sulogin: relabel terminal according to SELinux policy,
Christian Göttsche
[PATCH v2] libsepol: Use a dynamic buffer in sepol_av_to_string(),
James Carter
[PATCH v5 0/4] vduse: add support for networking devices,
Maxime Coquelin
[PATCH] libsepol: Use a dynamic buffer in sepol_av_to_string(),
James Carter
[PATCH 1/3] libselinux: update const qualifier of parameters in man pages,
Christian Göttsche
[PATCH] libsepol: validate empty common classes in scope indices,
Christian Göttsche
[RFC PATCH] libsepol: handle long permission names in sepol_av_to_string(),
Christian Göttsche
[PATCH 1/3] libsepol: constify tokenized input,
Christian Göttsche
Where's 3.6-rc3 and plan with 3.6 release,
Petr Lautrbach
[PATCH] libsepol: validate common classes in scope indices,
Christian Göttsche
[PATCH v2] checkpolicy/dispol: misc updates,
Christian Göttsche
[RFC PATCH] libsepol: validate permission identifier length,
Christian Göttsche
ANN: SETools 4.4.4, Chris PeBenito
[PATCH] mm: fix VMA heap bounds checking,
Kefeng Wang
[PATCH] python: Harden more tools agains "rogue" modules,
Vit Mojzis
[PATCH 0/11] vfs: inode cache scalability improvements,
Dave Chinner
[Index of Archives]
[Selinux Refpolicy]
[Fedora Users]
[Fedora Desktop]
[Kernel]
[KDE Users]
[Gnome Users]