aboutsummaryrefslogtreecommitdiff
path: root/security/landlock
AgeCommit message (Expand)AuthorFilesLines
2024-03-08landlock: Use f_cred in security_file_open() hookGravatar Mickaël Salaün 1-7/+11
2024-03-08landlock: Rename "ptrace" files to "task"Gravatar Mickaël Salaün 4-9/+9
2024-03-08landlock: Simplify current_check_access_socket()Gravatar Mickaël Salaün 1-4/+3
2024-03-07landlock: Warn once if a Landlock action is requested while disabledGravatar Mickaël Salaün 1-3/+15
2024-02-27landlock: Add support for KUnit testsGravatar Mickaël Salaün 4-0/+255
2024-02-26landlock: Fix asymmetric private inodes referringGravatar Mickaël Salaün 1-2/+2
2024-01-09Merge tag 'landlock-6.8-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git...Gravatar Linus Torvalds 2-16/+17
2024-01-03landlock: Optimize the number of calls to get_access_mask slightlyGravatar Günther Noack 1-2/+3
2024-01-03landlock: Remove remaining "inline" modifiers in .c files [v6.6]Gravatar Günther Noack 1-1/+1
2024-01-03landlock: Remove remaining "inline" modifiers in .c files [v6.1]Gravatar Günther Noack 1-9/+9
2024-01-03landlock: Remove remaining "inline" modifiers in .c files [v5.15]Gravatar Günther Noack 2-4/+4
2023-11-12LSM: Identify modules by more than nameGravatar Casey Schaufler 6-4/+11
2023-10-26landlock: Support network rules with TCP bind and connectGravatar Konstantin Meskhidze 9-24/+414
2023-10-26landlock: Refactor landlock_add_rule() syscallGravatar Konstantin Meskhidze 1-44/+45
2023-10-26landlock: Refactor layer helpersGravatar Konstantin Meskhidze 3-42/+66
2023-10-26landlock: Move and rename layer helpersGravatar Konstantin Meskhidze 3-115/+129
2023-10-26landlock: Refactor merge/inherit_ruleset helpersGravatar Konstantin Meskhidze 1-42/+74
2023-10-26landlock: Refactor landlock_find_rule/insert_rule helpersGravatar Konstantin Meskhidze 3-54/+165
2023-10-26landlock: Allow FS topology changes for domains without such rule typeGravatar Mickaël Salaün 3-40/+60
2023-10-26landlock: Make ruleset's access masks more genericGravatar Konstantin Meskhidze 5-20/+50
2023-08-18landlock: Annotate struct landlock_rule with __counted_byGravatar Kees Cook 1-1/+1
2023-06-12hostfs: Fix ephemeral inodesGravatar Mickaël Salaün 1-1/+1
2023-03-20selinux: remove the runtime disable functionalityGravatar Paul Moore 4-5/+5
2022-10-19landlock: Support file truncationGravatar Günther Noack 5-7/+126
2022-10-19landlock: Document init_layer_masks() helperGravatar Günther Noack 1-0/+13
2022-10-19landlock: Refactor check_access_path_dual() into is_access_to_paths_allowed()Gravatar Günther Noack 1-45/+44
2022-09-29landlock: Fix documentation styleGravatar Mickaël Salaün 1-20/+20
2022-09-29landlock: Slightly improve documentation and fix spellingGravatar Mickaël Salaün 1-1/+1
2022-09-02landlock: Fix file reparenting without explicit LANDLOCK_ACCESS_FS_REFERGravatar Mickaël Salaün 1-23/+25
2022-05-23landlock: Add support for file reparenting with LANDLOCK_ACCESS_FS_REFERGravatar Mickaël Salaün 3-76/+528
2022-05-23LSM: Remove double path_rename hook calls for RENAME_EXCHANGEGravatar Mickaël Salaün 1-1/+10
2022-05-23landlock: Move filesystem helpers and add a new oneGravatar Mickaël Salaün 1-41/+46
2022-05-23landlock: Fix same-layer rule unionsGravatar Mickaël Salaün 2-26/+54
2022-05-23landlock: Create find_rule() from unmask_layers()Gravatar Mickaël Salaün 1-13/+28
2022-05-23landlock: Reduce the maximum number of layers to 16Gravatar Mickaël Salaün 3-11/+12
2022-05-23landlock: Define access_mask_t to enforce a consistent access mask sizeGravatar Mickaël Salaün 5-15/+30
2022-05-23landlock: Change landlock_restrict_self(2) check orderingGravatar Mickaël Salaün 1-4/+4
2022-05-23landlock: Change landlock_add_rule(2) argument check orderingGravatar Mickaël Salaün 1-9/+13
2022-05-23landlock: Fix landlock_add_rule(2) documentationGravatar Mickaël Salaün 1-4/+3
2022-05-09landlock: Format with clang-formatGravatar Mickaël Salaün 10-136/+142
2022-05-09landlock: Add clang-format exceptionsGravatar Mickaël Salaün 2-0/+6
2022-02-04landlock: Use square brackets around "landlock-ruleset"Gravatar Christian Brauner 1-1/+1
2021-04-22landlock: Enable user space to infer supported featuresGravatar Mickaël Salaün 1-4/+13
2021-04-22landlock: Add syscall implementationsGravatar Mickaël Salaün 2-1/+443
2021-04-22landlock: Support filesystem access-controlGravatar Mickaël Salaün 8-2/+781
2021-04-22landlock: Add ptrace restrictionsGravatar Mickaël Salaün 4-1/+137
2021-04-22landlock: Set up the security framework and manage credentialsGravatar Mickaël Salaün 6-1/+173
2021-04-22landlock: Add ruleset and domain managementGravatar Mickaël Salaün 4-1/+652
2021-04-22landlock: Add object managementGravatar Mickaël Salaün 4-0/+182