summaryrefslogtreecommitdiff
path: root/security/selinux
AgeCommit message (Expand)AuthorFilesLines
2020-03-05selinux: clean up error path in policydb_init()Ondrej Mosnacek1-13/+5
2020-02-28selinux: remove unused initial SIDs and improve handlingStephen Smalley4-56/+58
2020-02-28selinux: reduce the use of hard-coded hash sizesOndrej Mosnacek4-40/+45
2020-02-22selinux: Add xfs quota command typesRichard Haines1-0/+7
2020-02-22selinux: optimize storage of filename transitionsOndrej Mosnacek3-80/+110
2020-02-14selinux: factor out loop body from filename_trans_read()Ondrej Mosnacek1-59/+63
2020-02-12security: selinux: allow per-file labeling for bpffsConnor O'Brien1-0/+1
2020-02-12selinux: generalize evaluate_cond_node()Ondrej Mosnacek3-6/+12
2020-02-12selinux: convert cond_expr to arrayOndrej Mosnacek2-43/+33
2020-02-12selinux: convert cond_av_list to arrayOndrej Mosnacek2-79/+53
2020-02-12selinux: convert cond_list to arrayOndrej Mosnacek7-59/+43
2020-02-11Merge tag 'selinux-pr-20200210' of git://git.kernel.org/pub/scm/linux/kernel/...Linus Torvalds2-10/+4
2020-02-10selinux: sel_avc_get_stat_idx should increase position indexVasily Averin1-0/+1
2020-02-10selinux: allow kernfs symlinks to inherit parent directory contextChristian Göttsche3-2/+13
2020-02-10selinux: simplify evaluate_cond_node()Ondrej Mosnacek3-13/+6
2020-02-10Documentation,selinux: deprecate setting checkreqprot to 1Stephen Smalley3-1/+15
2020-02-10selinux: move status variables out of selinux_ssOndrej Mosnacek6-22/+23
2020-02-09Merge branch 'merge.nfs-fs_parse.1' of git://git.kernel.org/pub/scm/linux/ker...Linus Torvalds1-8/+3
2020-02-07fs_parse: fold fs_parameter_desc/fs_parameter_specAl Viro1-7/+3
2020-02-07fs_parser: remove fs_parameter_description name fieldEric Sandeen1-2/+1
2020-02-06selinux: fix sidtab string cache lockingOndrej Mosnacek1-9/+3
2020-02-06selinux: fix typo in filesystem nameHridya Valsaraju1-1/+1
2020-01-29Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-nextLinus Torvalds1-1/+4
2020-01-20selinux: fix regression introduced by move_mount(2) syscallStephen Smalley1-0/+10
2020-01-17selinux: do not allocate ancillary buffer on first loadOndrej Mosnacek1-15/+13
2020-01-16selinux: remove redundant allocation and helper functionsPaul Moore1-58/+36
2020-01-16selinux: remove redundant selinux_nlmsg_permHuaisheng Ye1-39/+34
2020-01-16selinux: fix wrong buffer types in policydb.cOndrej Mosnacek1-2/+2
2020-01-15net: bridge: vlan: add rtm definitions and dump supportNikolay Aleksandrov1-1/+4
2020-01-10selinux: reorder hooks to make runtime disable less brokenOndrej Mosnacek1-31/+70
2020-01-10selinux: treat atomic flags more carefullyOndrej Mosnacek3-31/+61
2020-01-10selinux: make default_noexec read-only after initStephen Smalley1-1/+1
2020-01-10selinux: move ibpkeys code under CONFIG_SECURITY_INFINIBAND.Ravi Kumar Siddojigari2-2/+15
2020-01-10selinux: remove redundant msg_msg_alloc_securityHuaisheng Ye1-11/+6
2020-01-07Documentation,selinux: fix references to old selinuxfs mount pointStephen Smalley1-3/+4
2020-01-07selinux: deprecate disabling SELinux and runtimePaul Moore2-0/+10
2020-01-07selinux: allow per-file labelling for binderfsHridya Valsaraju1-0/+1
2020-01-07selinuxfs: use scnprintf to get real length for inodeliuyang341-2/+2
2019-12-24selinux: remove set but not used variable 'sidtab'YueHaibing1-8/+0
2019-12-24selinux: ensure the policy has been loaded before reading the sidtab statsPaul Moore1-0/+6
2019-12-21selinux: ensure we cleanup the internal AVC counters on error in avc_update()Jaihind Yadav1-1/+1
2019-12-19selinux: randomize layout of key structuresStephen Smalley4-4/+4
2019-12-19selinux: clean up selinux_enabled/disabled/enforcing_bootStephen Smalley7-18/+17
2019-12-12selinux: remove unnecessary selinux cred requestYang Guo1-4/+3
2019-12-10selinux: ensure we cleanup the internal AVC counters on error in avc_insert()Paul Moore1-27/+24
2019-12-10selinux: clean up selinux_inode_permission MAY_NOT_BLOCK testsStephen Smalley1-4/+4
2019-12-10selinux: fall back to ref-walk if audit is requiredStephen Smalley3-26/+17
2019-12-10selinux: revert "stop passing MAY_NOT_BLOCK to the AVC upon follow_link"Stephen Smalley3-4/+30
2019-12-10security,lockdown,selinux: implement SELinux lockdownStephen Smalley2-0/+32
2019-12-10selinux: cache the SID -> context string translationOndrej Mosnacek4-94/+288