summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)Author
2008-04-13LSM: Make the Labeled IPsec hooks more stack friendlyPaul Moore
2008-04-13NetLabel: Allow passing the LSM domain as a shared pointerPaul Moore
2008-04-03Merge branch 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/davem/...David S. Miller
2008-04-02selinux: handle files opened with flags 3 by checking ioctl permissionStephen Smalley
2008-03-25[NET] NETNS: Omit net_device->nd_net without CONFIG_NET_NS.YOSHIFUJI Hideaki
2008-03-25smackfs: remove redundant lock, fix open(,O_RDWR)Ahmed S. Darwish
2008-03-20file capabilities: remove cap_task_kill()Serge Hallyn
2008-03-20smack: do not dereference NULL ipc objectAhmed S. Darwish
2008-03-17make selinux_parse_opts_str() staticAdrian Bunk
2008-03-13smackfs: do not trust `count' in inodes write()sAhmed S. Darwish
2008-03-05LSM/SELinux: Interfaces to allow FS to control mount optionsEric Paris
2008-02-24Smack: update for file capabilitiesCasey Schaufler
2008-02-24file capabilities: simplify signal checkSerge E. Hallyn
2008-02-19Smack: unlabeled outgoing ambient packetsCasey Schaufler
2008-02-15d_path: Use struct path in struct avc_audit_dataJan Blunck
2008-02-15Embed a struct path into struct nameidata instead of nd->{dentry,mnt}Jan Blunck
2008-02-14Smack: check for 'struct socket' with NULL skAhmed S. Darwish
2008-02-11selinux: support 64-bit capabilitiesStephen Smalley
2008-02-07Convert ERR_PTR(PTR_ERR(p)) instances to ERR_CAST(p)David Howells
2008-02-06SELinux: Remove security_get_policycaps()Paul Moore
2008-02-06security: allow Kconfig to set default mmap_min_addr protectionEric Paris
2008-02-05Smack: Simplified Mandatory Access Control KernelCasey Schaufler
2008-02-05capabilities: introduce per-process capability bounding setSerge E. Hallyn
2008-02-05Add 64-bit capability support to the kernelAndrew Morgan
2008-02-05revert "capabilities: clean up file capability reading"Andrew Morton
2008-02-05VFS/Security: Rework inode_getsecurity and callers to return resulting bufferDavid P. Quigley
2008-02-01[AUDIT] add session id to audit messagesEric Paris
2008-02-01[PATCH] switch audit_get_loginuid() to task_struct *Al Viro
2008-02-01[SELinux]: Fix double free in selinux_netlbl_sock_setsid()Paul Moore
2008-01-29security: compile capabilities by defaultsergeh@us.ibm.com
2008-01-29selinux: make selinux_set_mnt_opts() staticAdrian Bunk
2008-01-29SELinux: Add warning messages on network denial due to errorPaul Moore
2008-01-29SELinux: Add network ingress and egress control permission checksPaul Moore
2008-01-29SELinux: Allow NetLabel to directly cache SIDsPaul Moore
2008-01-29SELinux: Enable dynamic enable/disable of the network access checksPaul Moore
2008-01-29SELinux: Better integration between peer labeling subsystemsPaul Moore
2008-01-29SELinux: Add a new peer class and permissions to the Flask definitionsPaul Moore
2008-01-29SELinux: Add a capabilities bitmap to SELinux policy version 22Paul Moore
2008-01-29SELinux: Add a network node caching mechanism similar to the sel_netif_*() fu...Paul Moore
2008-01-29SELinux: Only store the network interface's ifindexPaul Moore
2008-01-29SELinux: Convert the netif code to use ifindex valuesPaul Moore
2008-01-29NetLabel: Add IP address family information to the netlbl_skbuff_getattr() fu...Paul Moore
2008-01-29NetLabel: Add secid token support to the NetLabel secattr structPaul Moore
2008-01-28[NETFILTER]: Introduce NF_INET_ hook valuesPatrick McHardy
2008-01-26selinux: fix labeling of /proc/net inodesStephen Smalley
2008-01-25Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmo...Linus Torvalds
2008-01-25Kobject: convert remaining kobject_unregister() to kobject_put()Greg Kroah-Hartman
2008-01-25kobject: convert kernel_kset to be a kobjectGreg Kroah-Hartman
2008-01-25kset: convert kernel_subsys to use kset_createGreg Kroah-Hartman
2008-01-25kobject: convert securityfs to use kobject_createGreg Kroah-Hartman