summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)Author
2008-04-19SELinux: setup new inode/ipc getsecid hooksAhmed S. Darwish
2008-04-19LSM: Introduce inode_getsecid and ipc_getsecid hooksAhmed S. Darwish
2008-04-18security: enhance DEFAULT_MMAP_MIN_ADDR descriptionmaximilian attems
2008-04-18SELinux: add netport.[ch]James Morris
2008-04-18SELinux: Add network port SID cachePaul Moore
2008-04-18SELinux: turn mount options strings into definesEric Paris
2008-04-18selinux/ss/services.c should #include <linux/selinux.h>Adrian Bunk
2008-04-18selinux: introduce permissive typesEric Paris
2008-04-18selinux: remove ptrace_sidRoland McGrath
2008-04-18SELinux: requesting no permissions in avc_has_perm_noaudit is a BUG()Eric Paris
2008-04-18security: code cleanupAndrew Morton
2008-04-18security: replace remaining __FUNCTION__ occurrencesHarvey Harrison
2008-04-18SELinux: create new open permissionEric Paris
2008-04-18selinux: selinux/netlabel.c should #include "netlabel.h"Adrian Bunk
2008-04-18SELinux: unify printk messagesJames Morris
2008-04-18SELinux: remove unused backpointers from security objectsJames Morris
2008-04-18SELinux: Correct the NetLabel locking for the sk_security_structPaul Moore
2008-04-10SELinux: don't BUG if fs reuses a superblockEric Paris
2008-04-08SELinux: more GFP_NOFS fixups to prevent selinux from re-entering the fs codeStephen Smalley
2008-04-04selinux: prevent rentry into the FSJosef Bacik
2008-04-02selinux: handle files opened with flags 3 by checking ioctl permissionStephen Smalley
2008-03-24smackfs: remove redundant lock, fix open(,O_RDWR)Ahmed S. Darwish
2008-03-20file capabilities: remove cap_task_kill()Serge Hallyn
2008-03-19smack: do not dereference NULL ipc objectAhmed S. Darwish
2008-03-18make selinux_parse_opts_str() staticAdrian Bunk
2008-03-13smackfs: do not trust `count' in inodes write()sAhmed S. Darwish
2008-03-06LSM/SELinux: Interfaces to allow FS to control mount optionsEric Paris
2008-02-23Smack: update for file capabilitiesCasey Schaufler
2008-02-23file capabilities: simplify signal checkSerge E. Hallyn
2008-02-19Smack: unlabeled outgoing ambient packetsCasey Schaufler
2008-02-14d_path: Use struct path in struct avc_audit_dataJan Blunck
2008-02-14Embed a struct path into struct nameidata instead of nd->{dentry,mnt}Jan Blunck
2008-02-13Smack: check for 'struct socket' with NULL skAhmed S. Darwish
2008-02-11selinux: support 64-bit capabilitiesStephen Smalley
2008-02-07Convert ERR_PTR(PTR_ERR(p)) instances to ERR_CAST(p)David Howells
2008-02-06SELinux: Remove security_get_policycaps()Paul Moore
2008-02-06security: allow Kconfig to set default mmap_min_addr protectionEric Paris
2008-02-05Smack: Simplified Mandatory Access Control KernelCasey Schaufler
2008-02-05capabilities: introduce per-process capability bounding setSerge E. Hallyn
2008-02-05Add 64-bit capability support to the kernelAndrew Morgan
2008-02-05revert "capabilities: clean up file capability reading"Andrew Morton
2008-02-05VFS/Security: Rework inode_getsecurity and callers to return resulting bufferDavid P. Quigley
2008-02-01[AUDIT] add session id to audit messagesEric Paris
2008-02-01[PATCH] switch audit_get_loginuid() to task_struct *Al Viro
2008-01-31[SELinux]: Fix double free in selinux_netlbl_sock_setsid()Paul Moore
2008-01-30security: compile capabilities by defaultsergeh@us.ibm.com
2008-01-30selinux: make selinux_set_mnt_opts() staticAdrian Bunk
2008-01-30SELinux: Add warning messages on network denial due to errorPaul Moore
2008-01-30SELinux: Add network ingress and egress control permission checksPaul Moore
2008-01-30SELinux: Allow NetLabel to directly cache SIDsPaul Moore