Age | Commit message (Expand) | Author | Files | Lines |
2017-01-16 | apparmor: change aad apparmor_audit_data macro to a fn macro | John Johansen | 12 | -161/+155 |
2017-01-16 | apparmor: change op from int to const char * | John Johansen | 10 | -134/+84 |
2017-01-16 | apparmor: rename context abreviation cxt to the more standard ctx | John Johansen | 5 | -144/+150 |
2017-01-16 | apparmor: fail task profile update if current_cred isn't real_cred | John Johansen | 1 | -0/+3 |
2017-01-16 | apparmor: add per policy ns .load, .replace, .remove interface files | John Johansen | 2 | -22/+130 |
2017-01-16 | apparmor: pass the subject profile into profile replace/remove | John Johansen | 3 | -16/+21 |
2017-01-16 | apparmor: audit policy ns specified in policy load | John Johansen | 3 | -24/+77 |
2017-01-16 | apparmor: allow introspecting the loaded policy pre internal transform | John Johansen | 8 | -58/+278 |
2017-01-16 | apparmor: add ns name to the audit data for policy loads | John Johansen | 2 | -10/+25 |
2017-01-16 | apparmor: add profile and ns params to aa_may_manage_policy() | John Johansen | 3 | -14/+12 |
2017-01-16 | apparmor: add ns being viewed as a param to policy_admin_capable() | John Johansen | 3 | -10/+16 |
2017-01-16 | apparmor: add ns being viewed as a param to policy_view_capable() | John Johansen | 4 | -8/+35 |
2017-01-16 | apparmor: allow specifying the profile doing the management | John Johansen | 1 | -11/+21 |
2017-01-16 | apparmor: allow introspecting the policy namespace name | John Johansen | 1 | -0/+24 |
2017-01-16 | apparmor: Make aa_remove_profile() callable from a different view | John Johansen | 3 | -5/+7 |
2017-01-16 | apparmor: track ns level so it can be used to help in view checks | John Johansen | 1 | -0/+1 |
2017-01-16 | apparmor: add special .null file used to "close" fds at exec | John Johansen | 3 | -1/+81 |
2017-01-16 | apparmor: provide userspace flag indicating binfmt_elf_mmap change | John Johansen | 1 | -0/+1 |
2017-01-16 | apparmor: add a default null dfa | John Johansen | 6 | -2/+46 |
2017-01-16 | apparmor: allow policydb to be used as the file dfa | John Johansen | 1 | -4/+8 |
2017-01-16 | apparmor: add get_dfa() fn | John Johansen | 1 | -0/+15 |
2017-01-16 | apparmor: prepare to support newer versions of policy | John Johansen | 2 | -10/+25 |
2017-01-16 | apparmor: add support for force complain flag to support learning mode | John Johansen | 1 | -1/+3 |
2017-01-16 | apparmor: remove paranoid load switch | John Johansen | 2 | -16/+10 |
2017-01-16 | apparmor: name null-XXX profiles after the executable | John Johansen | 3 | -17/+47 |
2017-01-16 | apparmor: pass gfp_t parameter into profile allocation | John Johansen | 4 | -8/+9 |
2017-01-16 | apparmor: refactor prepare_ns() and make usable from different views | John Johansen | 5 | -38/+79 |
2017-01-16 | apparmor: update policy_destroy to use new debug asserts | John Johansen | 1 | -9/+2 |
2017-01-16 | apparmor: pass gfp param into aa_policy_init() | John Johansen | 4 | -7/+7 |
2017-01-16 | apparmor: constify policy name and hname | John Johansen | 3 | -4/+4 |
2017-01-16 | apparmor: rename hname_tail to basename | John Johansen | 3 | -4/+4 |
2017-01-16 | apparmor: rename mediated_filesystem() to path_mediated_fs() | John Johansen | 2 | -8/+8 |
2017-01-16 | apparmor: add debug assert AA_BUG and Kconfig to control debug info | John Johansen | 3 | -4/+43 |
2017-01-16 | apparmor: add macro for bug asserts to check that a lock is held | John Johansen | 1 | -0/+11 |
2017-01-16 | apparmor: allow ns visibility question to consider subnses | John Johansen | 4 | -8/+14 |
2017-01-16 | apparmor: add fn to lookup profiles by fqname | John Johansen | 4 | -7/+38 |
2017-01-16 | apparmor: add lib fn to find the "split" for fqnames | John Johansen | 2 | -0/+55 |
2017-01-16 | apparmor: add strn version of aa_find_ns | John Johansen | 2 | -6/+29 |
2017-01-16 | apparmor: add strn version of lookup_profile fn | John Johansen | 2 | -11/+27 |
2017-01-16 | apparmor: rename replacedby to proxy | John Johansen | 5 | -65/+65 |
2017-01-16 | apparmor: rename PFLAG_INVALID to PFLAG_STALE | John Johansen | 3 | -5/+5 |
2017-01-16 | apparmor: rename sid to secid | John Johansen | 4 | -65/+65 |
2017-01-16 | apparmor: rename namespace to ns to improve code line lengths | John Johansen | 8 | -128/+122 |
2017-01-16 | apparmor: split apparmor policy namespaces code into its own file | John Johansen | 10 | -391/+454 |
2017-01-16 | apparmor: split out shared policy_XXX fns to lib | John Johansen | 4 | -132/+137 |
2017-01-16 | apparmor: move lib definitions into separate lib include | John Johansen | 5 | -82/+99 |
2017-01-16 | apparmor: use designated initializers | Kees Cook | 2 | -5/+7 |
2017-01-16 | AppArmor: Use GFP_KERNEL for __aa_kvmalloc(). | Tetsuo Handa | 1 | -1/+2 |
2017-01-14 | locking/atomic, kref: Use kref_get_unless_zero() more | Peter Zijlstra | 2 | -8/+2 |
2017-01-12 | security,selinux,smack: kill security_task_wait hook | Stephen Smalley | 3 | -33/+0 |