July 2026 Archives by date
Starting: Wed Jul 1 06:09:52 UTC 2026
Ending: Fri Jul 31 23:35:35 UTC 2026
Messages: 569
- [PATCH v4 bpf-next 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Alexei Starovoitov
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Mickaël Salaün
- linux-next: apparmor: ld.lld: error: undefined symbol: decompress_zstd
Tetsuo Handa
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Paul Moore
- [PATCH 0/6] selftests: fix multiple spelling errors across submodules
Wang Yan
- [PATCH 5/6] selftests/landlock: fix spelling error in fs_test comment
Wang Yan
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Justin Suess
- [PATCH v4 bpf-next 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Paul Moore
- [PATCH 0/6] selftests: fix multiple spelling errors across submodules
Sean Christopherson
- [PATCH v4 bpf-next 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Justin Suess
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Paul Moore
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Mickaël Salaün
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Paul Moore
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Mickaël Salaün
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Justin Suess
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Paul Moore
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Paul Moore
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Mickaël Salaün
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Casey Schaufler
- [RFC PATCH 1/2] landlock: fix TCP Fast Open connection bypass
Matthieu Buffet
- [PATCH v2 1/2] landlock: fix TCP Fast Open connection bypass
Matthieu Buffet
- [PATCH v2 2/2] selftests/landlock: Add test for TCP fast open
Matthieu Buffet
- [PATCH v4 bpf-next 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
David Windsor
- [PATCH v4 bpf-next 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Paul Moore
- [PATCH v2] selftests/landlock: fix spelling error in fs_test comment
Wang Yan
- [RFC PATCH 0/4] Introduce capable_noaudit
Christian Brauner
- [RFC PATCH 1/4] capabily: Add new capable_noaudit
Carlos Maiolino
- [RFC PATCH 0/4] Introduce capable_noaudit
Carlos Maiolino
- [PATCH v2] selftests/landlock: fix spelling error in fs_test comment
Günther Noack
- [PATCH v3 0/5] Fix quota evasion on xfs and add capable_noaudit
cem at kernel.org
- [PATCH v3 1/5] xfs: fix capability check in xfs
cem at kernel.org
- [PATCH v3 2/5] capability: Add new capable_noaudit
cem at kernel.org
- [PATCH v3 3/5] quota: Don't issue audit messages on quota enforcing
cem at kernel.org
- [PATCH v3 4/5] xfs: replace ns_capable_noaudit
cem at kernel.org
- [PATCH v3 5/5] capability: unexport has_capability_noaudit
cem at kernel.org
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Mickaël Salaün
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Mickaël Salaün
- [PATCH v3 1/5] xfs: fix capability check in xfs
Christoph Hellwig
- [PATCH v3 3/5] quota: Don't issue audit messages on quota enforcing
Jan Kara
- [PATCH v3 1/5] xfs: fix capability check in xfs
Carlos Maiolino
- [PATCH v3 1/5] xfs: fix capability check in xfs
Christoph Hellwig
- [PATCH v3 1/5] xfs: fix capability check in xfs
Carlos Maiolino
- [PATCH v3 1/5] xfs: fix capability check in xfs
Carlos Maiolino
- [RFC PATCH 0/4] Introduce capable_noaudit
Christian Brauner
- [PATCH bpf-next v3 0/6] Verify BPF signed loader at load time
Daniel Borkmann
- [PATCH bpf-next v3 1/6] bpf: Resolve and cache fd_array objects at load time
Daniel Borkmann
- [PATCH bpf-next v3 2/6] bpf: Verify signed loader metadata at load time
Daniel Borkmann
- [PATCH bpf-next v3 3/6] libbpf: Drop in-loader metadata check for load-time verification
Daniel Borkmann
- [PATCH bpf-next v3 4/6] bpftool: Cover loader metadata with the program signature
Daniel Borkmann
- [PATCH bpf-next v3 5/6] selftests/bpf: Verify load-time signed loader metadata
Daniel Borkmann
- [PATCH bpf-next v3 6/6] Documentation/bpf: Add BPF signing and enforcement doc
Daniel Borkmann
- [RFC PATCH 0/4] Introduce capable_noaudit
Carlos Maiolino
- [PATCH v2 1/2] landlock: fix TCP Fast Open connection bypass
Mickaël Salaün
- [PATCH bpf-next v3 5/6] selftests/bpf: Verify load-time signed loader metadata
bot+bpf-ci at kernel.org
- [PATCH bpf-next v3 5/6] selftests/bpf: Verify load-time signed loader metadata
Daniel Borkmann
- [PATCH v3 2/5] capability: Add new capable_noaudit
Darrick J. Wong
- [PATCH v3 4/5] xfs: replace ns_capable_noaudit
Darrick J. Wong
- [PATCH -next] lockdown: Add break in lockdown_write
Paul Moore
- [PATCH v3] hardening: Default randstruct off with rust for better allmodconfig support
Mark Brown
- [PATCH v6 1/4] security: lsm: allow LSMs to register for late_initcall_sync init
Paul Moore
- [PATCH] security: clarify task_prctl hook documentation
Paul Moore
- [PATCH bpf-next v3 1/6] bpf: Resolve and cache fd_array objects at load time
Anton Protopopov
- [PATCH] lsm: cleanup repeated lsm_blob_size_update() calls in lsm_prepare()
Paul Moore
- [PATCH] ipe: fix bracket
Manuel Ebner
- [PATCH v6 1/4] security: lsm: allow LSMs to register for late_initcall_sync init
Yeoreum Yun
- [PATCH] lsm: cleanup repeated lsm_blob_size_update() calls in lsm_prepare()
Matt Bobrowski
- [PATCH 1/2] security: Some cleanup code
Paul Moore
- [PATCH 2/2] security: Fix call security_backing_file_free second time
Paul Moore
- [PATCH v4 0/2] Delete task_euid()
Paul Moore
- [PATCH] lsm: cleanup repeated lsm_blob_size_update() calls in lsm_prepare()
Paul Moore
- [PATCH bpf-next v3 1/6] bpf: Resolve and cache fd_array objects at load time
Daniel Borkmann
- [PATCH bpf-next v3 2/6] bpf: Verify signed loader metadata at load time
Paul Moore
- [PATCH bpf-next v3 2/6] bpf: Verify signed loader metadata at load time
Alexei Starovoitov
- [PATCH] selftests/lsm: Fix memory leak in attr_lsm_count
Wang Yan
- [PATCH] selftests/lsm: Fix memory leak in attr_lsm_count
William Roberts
- [PATCH v5 0/2] Delete task_euid()
Alice Ryhl
- [PATCH v5 1/2] rust: task: clarify comments on task UID accessors
Alice Ryhl
- [PATCH v5 2/2] cred: delete task_euid()
Alice Ryhl
- [PATCH v4 0/2] Delete task_euid()
Alice Ryhl
- [PATCH -next] lockdown: Add break in lockdown_write
Nicolas Bouchinet
- [RFC PATCH 0/3] coredump, net: fix layer violation with direct connection
John Ericson
- [RFC PATCH 1/3] af_unix: factor out unix_lookup_bsd_path()
John Ericson
- [RFC PATCH 2/3] af_unix: factor out kernel_unix_connect_direct()
John Ericson
- [RFC PATCH 3/3] coredump, net: remove `SOCK_COREDUMP`
John Ericson
- [RFC PATCH 3/3] coredump, net: remove `SOCK_COREDUMP`
Christian Brauner
- [RFC PATCH 3/3] coredump, net: remove `SOCK_COREDUMP`
John Ericson
- [RFC PATCH 3/3] coredump, net: remove `SOCK_COREDUMP`
Christian Brauner
- [PATCH v2] selftests/lsm: Fix memory leak in attr_lsm_count
Wang Yan
- [PATCH v1] landlock: Fix kernel-doc for the nested quiet layer flag
Mickaël Salaün
- [PATCH v1] landlock: Harden sock_is_scoped() against file-less sockets
Mickaël Salaün
- [PATCH v2] selftests/lsm: Fix memory leak in attr_lsm_count
William Roberts
- [PATCH 01/10] docs/zh_CN: add LSM/index Chinese translation
Weijie Yuan
- [PATCH 09/10] docs/zh_CN: add LSM/ipe Chinese translation
Alex Shi
- [PATCH] ipe: fix bracket
Fan Wu
- [PATCH bpf-next v4 0/9] Verify BPF signed loader at load time
Daniel Borkmann
- [PATCH bpf-next v4 1/9] bpf: Resolve and cache fd_array objects at load time
Daniel Borkmann
- [PATCH bpf-next v4 2/9] bpf: Move bigger allocations below fd_array resolution
Daniel Borkmann
- [PATCH bpf-next v4 3/9] bpf: Verify signed loader metadata at load time
Daniel Borkmann
- [PATCH bpf-next v4 4/9] libbpf: Drop in-loader metadata check for load-time verification
Daniel Borkmann
- [PATCH bpf-next v4 5/9] bpftool: Check EVP_Digest when computing excl_prog_hash
Daniel Borkmann
- [PATCH bpf-next v4 6/9] bpftool: Cover loader metadata with the program signature
Daniel Borkmann
- [PATCH bpf-next v4 7/9] selftests/bpf: Adjust bpf_map layout in verifier_map_ptr
Daniel Borkmann
- [PATCH bpf-next v4 8/9] selftests/bpf: Verify load-time signed loader metadata
Daniel Borkmann
- [PATCH bpf-next v4 9/9] Documentation/bpf: Add BPF signing and enforcement doc
Daniel Borkmann
- [PATCH bpf-next v4 4/9] libbpf: Drop in-loader metadata check for load-time verification
bot+bpf-ci at kernel.org
- [PATCH bpf-next v4 3/9] bpf: Verify signed loader metadata at load time
bot+bpf-ci at kernel.org
- [PATCH bpf-next v4 1/9] bpf: Resolve and cache fd_array objects at load time
Anton Protopopov
- [PATCH bpf-next v3 2/6] bpf: Verify signed loader metadata at load time
Paul Moore
- [PATCH bpf-next v4 0/9] Verify BPF signed loader at load time
Paul Moore
- [PATCH bpf-next v4 3/9] bpf: Verify signed loader metadata at load time
Paul Moore
- [PATCH v2] ipe: fix typo
Manuel Ebner
- [PATCH bpf-next v4 0/9] Verify BPF signed loader at load time
Daniel Borkmann
- [PATCH bpf-next v4 0/9] Verify BPF signed loader at load time
Paul Moore
- [PATCH v6 0/8] lsm: Replace security_sb_mount with granular mount hooks
Song Liu
- [PATCH v6 1/8] lsm: Add granular mount hooks
Song Liu
- [PATCH v6 2/8] apparmor: Remove redundant MS_MGC_MSK stripping in apparmor_sb_mount
Song Liu
- [PATCH v6 3/8] apparmor: Convert from sb_mount to granular mount hooks
Song Liu
- [PATCH v6 4/8] selinux: Convert from sb_mount to granular mount hooks
Song Liu
- [PATCH v6 5/8] landlock: Convert from sb_mount to granular mount hooks
Song Liu
- [PATCH v6 6/8] tomoyo: Convert from sb_mount to granular mount hooks
Song Liu
- [PATCH v6 7/8] vfs: Replace security_sb_mount/security_move_mount with granular hooks
Song Liu
- [PATCH v6 8/8] lsm: Remove security_sb_mount and security_move_mount
Song Liu
- [PATCH v2 -next 0/2] security: Fix call security_backing_file_free second time
Cai Xinchen
- [PATCH v2 -next 1/2] security: Delete dumplicate assignment
Cai Xinchen
- [PATCH v2 -next 2/2] security: Fix call security_backing_file_free second time
Cai Xinchen
- [PATCH v3 2/5] capability: Add new capable_noaudit
Carlos Maiolino
- [PATCH v3 4/5] xfs: replace ns_capable_noaudit
Carlos Maiolino
- [PATCH] Documentation: landlock: Document fs.resolve_unix audit blocker
Doehyun Baek
- [PATCH v19 4/8] rust: page: convert to `Ownable`
Alice Ryhl
- [PATCH v19 3/8] rust: implement `ForeignOwnable` for `Owned`
Alice Ryhl
- [PATCH] Documentation: landlock: Document fs.resolve_unix audit blocker
Mickaël Salaün
- [PATCH v2] NFSv4.2: fix nfs4_listxattr size accounting
Paul Moore
- [PATCH v5 1/2] rust: task: clarify comments on task UID accessors
Paul Moore
- [PATCH v5 2/2] cred: delete task_euid()
Paul Moore
- [PATCH v2] NFSv4.2: fix nfs4_listxattr size accounting
Anna Schumaker
- [PATCH v2] selftests/lsm: Fix memory leak in attr_lsm_count
Paul Moore
- [PATCH bpf-next v5 0/8] Verify BPF signed loader at load time
Daniel Borkmann
- [PATCH bpf-next v5 1/8] bpf: Resolve and cache fd_array objects at load time
Daniel Borkmann
- [PATCH bpf-next v5 2/8] bpf: Verify signed loader metadata at load time
Daniel Borkmann
- [PATCH bpf-next v5 3/8] libbpf: Drop in-loader metadata check for load-time verification
Daniel Borkmann
- [PATCH bpf-next v5 4/8] bpftool: Check EVP_Digest when computing excl_prog_hash
Daniel Borkmann
- [PATCH bpf-next v5 5/8] bpftool: Cover loader metadata with the program signature
Daniel Borkmann
- [PATCH bpf-next v5 6/8] selftests/bpf: Adjust bpf_map layout in verifier_map_ptr
Daniel Borkmann
- [PATCH bpf-next v5 7/8] selftests/bpf: Verify load-time signed loader metadata
Daniel Borkmann
- [PATCH bpf-next v5 8/8] Documentation/bpf: Add BPF signing and enforcement doc
Daniel Borkmann
- [PATCH v2] NFSv4.2: fix nfs4_listxattr size accounting
Paul Moore
- [PATCH v1] landlock: Document the threat model
Mickaël Salaün
- [PATCH v5 1/2] rust: task: clarify comments on task UID accessors
Alice Ryhl
- [PATCH v5 bpf-next 0/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
David Windsor
- [PATCH v5 bpf-next 1/3] security: rework inode_init_security xattr handling
David Windsor
- [PATCH v5 bpf-next 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
David Windsor
- [PATCH v5 bpf-next 3/3] selftests/bpf: add tests for bpf_init_inode_xattr kfunc
David Windsor
- [PATCH v5 bpf-next 0/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH bpf-next v6 0/8] Verify BPF signed loader at load time
Daniel Borkmann
- [PATCH bpf-next v6 1/8] bpf: Resolve and cache fd_array objects at load time
Daniel Borkmann
- [PATCH bpf-next v6 2/8] bpf: Verify signed loader metadata at load time
Daniel Borkmann
- [PATCH bpf-next v6 3/8] libbpf: Drop in-loader metadata check for load-time verification
Daniel Borkmann
- [PATCH bpf-next v6 4/8] bpftool: Check EVP_Digest when computing excl_prog_hash
Daniel Borkmann
- [PATCH bpf-next v6 5/8] bpftool: Cover loader metadata with the program signature
Daniel Borkmann
- [PATCH bpf-next v6 6/8] selftests/bpf: Adjust bpf_map layout in verifier_map_ptr
Daniel Borkmann
- [PATCH bpf-next v6 7/8] selftests/bpf: Verify load-time signed loader metadata
Daniel Borkmann
- [PATCH bpf-next v6 8/8] Documentation/bpf: Add BPF signing and enforcement doc
Daniel Borkmann
- [PATCH bpf-next v6 4/8] bpftool: Check EVP_Digest when computing excl_prog_hash
Quentin Monnet
- [PATCH bpf-next v6 5/8] bpftool: Cover loader metadata with the program signature
Quentin Monnet
- [PATCH] landlock: Documentation wording cleanups
Mickaël Salaün
- [PATCH v2] selftests/landlock: fix spelling error in fs_test comment
Mickaël Salaün
- [PATCH v1] landlock: Update formatting
Mickaël Salaün
- [RFC/discuss] memfd_secret(): opt-in visibility for security monitoring (eBPF/audit)
BoxStrikesTeam
- [PATCH v5 bpf-next 0/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
David Windsor
- [PATCH 0/3] Implement LANDLOCK_RESTRICT_SELF_NNP_ON_EXEC
Justin Suess
- [PATCH 1/3] landlock: Add LANDLOCK_RESTRICT_SELF_NNP_ON_EXEC
Justin Suess
- [PATCH 2/3] selftests/landlock: Test LANDLOCK_RESTRICT_SELF_NNP_ON_EXEC
Justin Suess
- [PATCH 3/3] landlock: Document LANDLOCK_RESTRICT_SELF_NNP_ON_EXEC
Justin Suess
- [PATCH v1] landlock: Update formatting
Günther Noack
- [PATCH 0/2] Bring includes in linux/kmod.h up to date
Petr Pavlu
- [PATCH 1/2] umh, treewide: Explicitly include linux/umh.h where needed
Petr Pavlu
- [PATCH 2/2] module: Bring includes in linux/kmod.h up to date
Petr Pavlu
- [PATCH bpf-next v6 0/8] Verify BPF signed loader at load time
patchwork-bot+netdevbpf at kernel.org
- [PATCH v2] NFSv4.2: fix nfs4_listxattr size accounting
Stephen Smalley
- [PATCH v2] NFSv4.2: fix nfs4_listxattr size accounting
Paul Moore
- [PATCH v1] landlock: Document the threat model
Jann Horn
- [RFC/discuss] memfd_secret(): opt-in visibility for security monitoring (eBPF/audit)
Paul Moore
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Paul Moore
- [PATCH v2 1/9] security: add LSM blob and hooks for namespaces
Paul Moore
- [RESEND][RFC/discuss] memfd_secret(): opt-in visibility for security monitoring (eBPF/audit)
BoxStrikesTeam
- [PATCH v2 1/9] security: add LSM blob and hooks for namespaces
Mickaël Salaün
- [PATCH 1/2] umh, treewide: Explicitly include linux/umh.h where needed
Petr Pavlu
- [PATCH 0/3] Implement LANDLOCK_RESTRICT_SELF_NNP_ON_EXEC
Mickaël Salaün
- [PATCH 0/3] Implement LANDLOCK_RESTRICT_SELF_NNP_ON_EXEC
Simon McVittie
- [PATCH v2] NFSv4.2: fix nfs4_listxattr size accounting
Stephen Smalley
- [PATCH v2 1/9] security: add LSM blob and hooks for namespaces
Paul Moore
- [PATCH v2 1/9] security: add LSM blob and hooks for namespaces
Mickaël Salaün
- [PATCH] selftests/landlock: Fix screwed up pointers in the scoped_signal_test
Thomas Huth
- [PATCH] PM: hibernate: Allow hibernation opt-in when locked down
Sean Rhodes
- [PATCH] PM: hibernate: Allow hibernation opt-in when locked down
Sean Rhodes
- [PATCH v2 1/9] security: add LSM blob and hooks for namespaces
Christian Brauner
- [PATCH] selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available
Thomas Huth
- [PATCH] selftests/landlock: Fix screwed up pointers in the scoped_signal_test
Mickaël Salaün
- [PATCH] selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available
Mickaël Salaün
- [PATCH] PM: hibernate: Allow hibernation opt-in when locked down
Nicolas Bouchinet
- İlt: Re: [RFC/discuss] memfd_secret(): opt-in visibility for security monitoring (eBPF/audit)
BoxStrikesTeam
- [PATCH 0/3] Implement LANDLOCK_RESTRICT_SELF_NNP_ON_EXEC
Justin Suess
- [PATCH 2/2] module: Bring includes in linux/kmod.h up to date
Aaron Tomlin
- [GIT PULL] selinux/selinux-pr-20260710
Paul Moore
- [PATCH v2 1/9] security: add LSM blob and hooks for namespaces
Paul Moore
- [RESEND][RFC/discuss] memfd_secret(): opt-in visibility for security monitoring (eBPF/audit)
Paul Moore
- İlt: Re: [RESEND][RFC/discuss] memfd_secret(): opt-in visibility for security monitoring (eBPF/audit)
BoxStrikesTeam
- [PATCH v2] NFSv4.2: fix nfs4_listxattr size accounting
Paul Moore
- [PATCH v2] NFSv4.2: fix nfs4_listxattr size accounting
Paul Moore
- [PATCH v2] NFSv4.2: fix nfs4_listxattr size accounting
Paul Moore
- [GIT PULL] selinux/selinux-pr-20260710
pr-tracker-bot at kernel.org
- [PATCH 0/3] Implement LANDLOCK_RESTRICT_SELF_NNP_ON_EXEC
Justin Suess
- [PATCH 11/13 RFC net-next] net: cipso: guard IPv4 packet manipulation functions
Fernando Fernandez Mancera
- [PATCH 0/3] keys: fix keyring assoc-array out-of-bounds read and index inconsistency
Michael Bommarito
- [PATCH 1/3] keys: fix out-of-bounds read in keyring_get_key_chunk()
Michael Bommarito
- [PATCH 2/3] keys: make keyring key-chunk byte order agree with keyring_diff_objects()
Michael Bommarito
- [PATCH 3/3] assoc_array: trim the final shortcut word when skip_to_level is chunk-aligned
Michael Bommarito
- [PATCH] apparmor: replace decompress_zstd() prototype with its entity
Tetsuo Handa
- [PATCH 11/13 RFC net-next] net: cipso: guard IPv4 packet manipulation functions
Paul Moore
- [PATCH -next] ima: add cond_resched() in ima_calc_file_hash_tfm loop
Gaosheng Cui
- [PATCH -next] ima: add cond_resched() in ima_calc_file_hash_tfm loop
Roberto Sassu
- [PATCH v3] hardening: Default randstruct off with rust for better allmodconfig support
Gary Guo
- [PATCH v3] hardening: Default randstruct off with rust for better allmodconfig support
Miguel Ojeda
- [PATCH 11/13 RFC net-next] net: cipso: guard IPv4 packet manipulation functions
Fernando Fernandez Mancera
- [PATCH v2 0/7] fs/9p: Reuse inode based on path (in addition to qid)
Tingmao Wang
- [PATCH 0/2] doc: LSM: update usage document for current LSM stacking
Lincoln Wallace
- [PATCH 1/2] doc: LSM: describe CONFIG_LSM and lsm= as the selection mechanism
Lincoln Wallace
- [PATCH 2/2] doc: LSM: fix module ordering description for /sys/kernel/security/lsm
Lincoln Wallace
- [PATCH 0/3] keys: fix keyring assoc-array out-of-bounds read and index inconsistency
Andrew Morton
- [PATCH -next, v2] ima: add cond_resched() in ima_calc_file_hash_tfm loop
Gaosheng Cui
- [PATCH -next,v2] ima: add cond_resched() in ima_calc_file_hash_tfm loop
Roberto Sassu
- [PATCH -next] ima: add cond_resched() in ima_calc_file_hash_tfm loop
cuigaosheng
- [PATCH v2 0/3] keys: fix keyring assoc-array out-of-bounds read and index inconsistency
Michael Bommarito
- [PATCH v2 1/3] keys: fix out-of-bounds read in keyring_get_key_chunk()
Michael Bommarito
- [PATCH v2 2/3] keys: make keyring key-chunk byte order agree with keyring_diff_objects()
Michael Bommarito
- [PATCH v2 3/3] assoc_array: trim the final shortcut word using the current chunk end
Michael Bommarito
- [PATCH] apparmor: fix cred UAF caused by begin_current_label_crit_section()
Jann Horn
- [PATCH] apparmor: fix cred UAF caused by begin_current_label_crit_section()
Jann Horn
- [PATCH v2] NFSv4.2: fix nfs4_listxattr size accounting
Paul Moore
- [PATCH v2] NFSv4.2: fix nfs4_listxattr size accounting
Scott Mayhew
- [BUG] Landlock denies LANDLOCK_ACCESS_FS_EXECUTE despite a correctly-anchored PathBeneath rule (contradicts selftest layout1.execute)
Günther Noack
- [PATCH] apparmor: replace decompress_zstd() prototype with its entity
Georgia Garcia
- [PATCH v2] NFSv4.2: fix nfs4_listxattr size accounting
Paul Moore
- [PATCH] apparmor: replace decompress_zstd() prototype with its entity
Tetsuo Handa
- [PATCH] apparmor: replace decompress_zstd() prototype with its entity
John Johansen
- 障害者の就労を支援する事業 新規開業パートナー募集
就労移行支援事業説明会
- [PATCH -next,v2] ima: add cond_resched() in ima_calc_file_hash_tfm loop
Roberto Sassu
- [BUG] Landlock denies LANDLOCK_ACCESS_FS_EXECUTE despite a correctly-anchored PathBeneath rule (contradicts selftest layout1.execute)
Mickaël Salaün
- [RFC PATCH 00/24] pidfd: add a minimal process spawn builder
Li Chen
- [RFC PATCH 01/24] pidfd: add spawn builder uapi
Li Chen
- [RFC PATCH 02/24] libfs: allow custom validation of stashed inode data
Li Chen
- [RFC PATCH 03/24] pidfs: add taskless future pidfd inodes
Li Chen
- [RFC PATCH 04/24] pidfd: create taskless spawn builders
Li Chen
- [RFC PATCH 05/24] pidfd: add spawn builder path configuration
Li Chen
- [RFC PATCH 06/24] exec: expose execveat internals to process builders
Li Chen
- [RFC PATCH 07/24] fork: expose vfork completion helper
Li Chen
- [RFC PATCH 08/24] pidfs: attach pids to future pidfd files
Li Chen
- [RFC PATCH 09/24] fork: let process builders supply preallocated pids
Li Chen
- [RFC PATCH 10/24] pidfs: publish future pidfd files
Li Chen
- [RFC PATCH 11/24] pidfd: add spawn builder state tracking
Li Chen
- [RFC PATCH 12/24] fork: let kernel callers create embryonic tasks
Li Chen
- [RFC PATCH 13/24] fork: let new tasks start with task work
Li Chen
- [RFC PATCH 14/24] pidfd: create and execute spawn builder tasks
Li Chen
- [RFC PATCH 15/24] fork: keep embryonic tasks hidden until exec completes
Li Chen
- [RFC PATCH 16/24] audit: add pidfd spawn child contexts
Li Chen
- [RFC PATCH 17/24] pidfd: audit child spawn execution
Li Chen
- [RFC PATCH 18/24] pidfd: make spawn builder execution signal-safe
Li Chen
- [RFC PATCH 19/24] file: expose spawn file-action helpers
Li Chen
- [RFC PATCH 20/24] pidfd: add initial spawn file actions
Li Chen
- [RFC PATCH 21/24] pidfd: consume spawn builders on the first run attempt
Li Chen
- [RFC PATCH 22/24] pidfd: expose spawn builder system calls
Li Chen
- [RFC PATCH 23/24] selftests/pidfd: cover pidfd spawn builders
Li Chen
- [RFC PATCH 24/24] Documentation: describe pidfd spawn builders
Li Chen
- [RFC PATCH 12/24] fork: let kernel callers create embryonic tasks
Andy Lutomirski
- [PATCH -next,v2] ima: add cond_resched() in ima_calc_file_hash_tfm loop
Mimi Zohar
- [PATCH] ima: Report errno for failed hash collection to audit
Frederick Lawler
- [GIT PULL] Landlock fix for v7.2-rc4
Mickaël Salaün
- [GIT PULL] Landlock fix for v7.2-rc4
pr-tracker-bot at kernel.org
- [PATCH v5 1/3] security: rework inode_init_security xattr handling
Paul Moore
- [PATCH v5 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v3 1/3] landlock: Require LANDLOCK_ACCESS_FS_MAKE_WHITEOUT for RENAME_WHITEOUT
Günther Noack
- [GIT PULL] selinux/selinux-pr-20260717
Paul Moore
- [GIT PULL] selinux/selinux-pr-20260717
pr-tracker-bot at kernel.org
- [PATCH] apparmor: leverage audit_log_n_untrustedstring() when possible
Paul Moore
- [PATCH] apparmor: leverage audit_log_n_untrustedstring() when possible
Paul Moore
- [PATCH] apparmor: leverage audit_log_n_untrustedstring() when possible
Paul Moore
- [PATCH v2 0/3] Implement LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH v2 1/3] landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH v2 2/3] selftests/landlock: Test LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH v2 3/3] landlock: Document LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH] apparmor: leverage audit_log_n_untrustedstring() when possible
Ryan Lee
- Landlock: mount_setattr(2) is unmediated by LSMs (ro-mount confinement bypass)
Vivek Parikh
- Landlock: LANDLOCK_ACCESS_FS_IOCTL_DEV is bypassable via io_uring IORING_OP_URING_CMD (confirmed on real NVMe hardware)
Vivek Parikh
- Landlock: LANDLOCK_ACCESS_FS_IOCTL_DEV is bypassable via io_uring IORING_OP_URING_CMD (confirmed on real NVMe hardware)
Mickaël Salaün
- [PATCH 0/3] keys: fix keyring assoc-array out-of-bounds read and index inconsistency
Jarkko Sakkinen
- [PATCH 1/3] keys: fix out-of-bounds read in keyring_get_key_chunk()
Jarkko Sakkinen
- [PATCH 2/3] keys: make keyring key-chunk byte order agree with keyring_diff_objects()
Jarkko Sakkinen
- [PATCH 3/3] assoc_array: trim the final shortcut word when skip_to_level is chunk-aligned
Jarkko Sakkinen
- [PATCH 3/3] assoc_array: trim the final shortcut word when skip_to_level is chunk-aligned
Jarkko Sakkinen
- [PATCH v2 1/3] keys: fix out-of-bounds read in keyring_get_key_chunk()
Jarkko Sakkinen
- [PATCH v2 2/3] keys: make keyring key-chunk byte order agree with keyring_diff_objects()
Jarkko Sakkinen
- [PATCH v2 3/3] assoc_array: trim the final shortcut word using the current chunk end
Jarkko Sakkinen
- [PATCH v2 3/3] assoc_array: trim the final shortcut word using the current chunk end
Jarkko Sakkinen
- unix_stream_connect and socket address resolution
John Ericson
- [PATCH v2 3/3] assoc_array: trim the final shortcut word using the current chunk end
Michael Bommarito
- unix_stream_connect and socket address resolution
David Laight
- [PATCH v2 3/3] assoc_array: trim the final shortcut word using the current chunk end
Jarkko Sakkinen
- unix_stream_connect and socket address resolution
John Ericson
- [PATCH v3 0/3] keys: fix keyring assoc-array out-of-bounds read and index inconsistency
Michael Bommarito
- [PATCH v3 1/3] keys: fix out-of-bounds read in keyring_get_key_chunk()
Michael Bommarito
- [PATCH v3 2/3] keys: make keyring key-chunk byte order agree with keyring_diff_objects()
Michael Bommarito
- [PATCH v3 3/3] assoc_array: trim the final shortcut word using the current chunk end
Michael Bommarito
- [PATCH 0/2] Add Apple T2 NHI device links
Atharva Tiwari
- [PATCH 1/2] treewide: Add a flag to detect the Apple T2 chip
Atharva Tiwari
- [PATCH 2/2] thunderbolt: Add device links for Apple T2 NHI
Atharva Tiwari
- [PATCH v4] security: Expand task_setscheduler LSM hook
Aaron Tomlin
- [PATCH v3 1/3] landlock: Require LANDLOCK_ACCESS_FS_MAKE_WHITEOUT for RENAME_WHITEOUT
Mickaël Salaün
- [PATCH v1] landlock: Document the threat model
Mickaël Salaün
- [PATCH v5 1/3] security: rework inode_init_security xattr handling
David Windsor
- [PATCH v5 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
David Windsor
- [PATCH v5 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v5 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v5 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
David Windsor
- [PATCH v5 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v5 1/3] security: rework inode_init_security xattr handling
Paul Moore
- [PATCH v5 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v5 2/3] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH] apparmor: leverage audit_log_n_untrustedstring() when possible
John Johansen
- [PATCH] apparmor: leverage audit_log_n_untrustedstring() when possible
Paul Moore
- [PATCH v2 0/2] Add Apple T2 NHI device links
Atharva Tiwari
- [PATCH v2 1/2] treewide: Add a flag to detect the Apple T2 chip
Atharva Tiwari
- [PATCH v2 2/2] thunderbolt: Add device links for Apple T2 NHI
Atharva Tiwari
- [PATCH v3 0/2] Add Apple T2 NHI device links
Atharva Tiwari
- [PATCH v3 1/2] treewide: Add a flag to detect the Apple T2 chip
Atharva Tiwari
- [PATCH v3 2/2] thunderbolt: Add device links for Apple T2 NHI
Atharva Tiwari
- [PATCH v3 2/2] thunderbolt: Add device links for Apple T2 NHI
Ilpo Järvinen
- [PATCH v2 1/2] treewide: Add a flag to detect the Apple T2 chip
Jarkko Sakkinen
- [PATCH v3 1/2] treewide: Add a flag to detect the Apple T2 chip
Jarkko Sakkinen
- [PATCH] apparmor: update website link
Baruch Siach
- [PATCH v2 0/3] Bring includes in linux/kmod.h up to date
Petr Pavlu
- [PATCH v2 1/3] umh, treewide: Explicitly include linux/umh.h where needed
Petr Pavlu
- [PATCH v2 2/3] time/jiffies: Include linux/sysctl.h for proc_int_u2k_conv_uop(), ...
Petr Pavlu
- [PATCH v2 3/3] module: Bring includes in linux/kmod.h up to date
Petr Pavlu
- [PATCH v4] security: Expand task_setscheduler LSM hook
Casey Schaufler
- [PATCH v3 1/2] treewide: Add a flag to detect the Apple T2 chip
Hans de Goede
- unix_stream_connect and socket address resolution
John Ericson
- [RFC PATCH 06/20] bpf: lsm: Add Landlock kfuncs
Justin Suess
- unix_stream_connect and socket address resolution
Günther Noack
- unix_stream_connect and socket address resolution
David Laight
- [PATCH 0/6] landlock: Add POSIX message queue scoping
Oxana Kharitonova
- [PATCH 1/6] ipc: Move mqueue fs magic to uapi magic header
Oxana Kharitonova
- [PATCH 2/6] landlock: Scope POSIX message queue opens
Oxana Kharitonova
- [PATCH 3/6] landlock: Bump ABI for LANDLOCK_SCOPE_POSIX_MSG_QUEUE
Oxana Kharitonova
- [PATCH 4/6] selftests/landlock: Test POSIX message queue scoping
Oxana Kharitonova
- [PATCH 5/6] samples/landlock: Support POSIX message queue scoping
Oxana Kharitonova
- [PATCH 6/6] landlock: Document POSIX message queue scoping
Oxana Kharitonova
- [PATCH 1/6] ipc: Move mqueue fs magic to uapi magic header
Günther Noack
- [PATCH v1] selftests/landlock: Add tests for O_TMPFILE
Mickaël Salaün
- [PATCH 1/6] ipc: Move mqueue fs magic to uapi magic header
Oxana Kharitonova
- [PATCH v3 0/3] keys: fix keyring assoc-array out-of-bounds read and index inconsistency
Jarkko Sakkinen
- unix_stream_connect and socket address resolution
John Ericson
- [PATCH] apparmor: update website link
Ryan Lee
- [PATCH v3 00/20] Landlock tracepoints
Mickaël Salaün
- [PATCH v3 01/20] landlock: Prepare ruleset and domain type split
Mickaël Salaün
- [PATCH v3 02/20] landlock: Move domain query functions to domain.c
Mickaël Salaün
- [PATCH v3 03/20] landlock: Split struct landlock_domain from struct landlock_ruleset
Mickaël Salaün
- [PATCH v3 04/20] landlock: Split denial logging from audit into common framework
Mickaël Salaün
- [PATCH v3 05/20] landlock: Decouple the per-denial logging decision from CONFIG_AUDIT
Mickaël Salaün
- [PATCH v3 06/20] landlock: Consolidate access-right and scope names in a shared header
Mickaël Salaün
- [PATCH v3 07/20] tracing: Add __print_untrusted_str()
Mickaël Salaün
- [PATCH v3 08/20] landlock: Add create_ruleset and free_ruleset tracepoints
Mickaël Salaün
- [PATCH v3 09/20] landlock: Add landlock_add_rule_fs and landlock_add_rule_net tracepoints
Mickaël Salaün
- [PATCH v3 10/20] landlock: Add create_domain and free_domain tracepoints
Mickaël Salaün
- [PATCH v3 11/20] landlock: Add landlock_enforce_domain tracepoint
Mickaël Salaün
- [PATCH v3 12/20] landlock: Add tracepoints for rule checking
Mickaël Salaün
- [PATCH v3 13/20] landlock: Add landlock_deny_access_fs and landlock_deny_access_net
Mickaël Salaün
- [PATCH v3 14/20] landlock: Add tracepoints for ptrace and scope denials
Mickaël Salaün
- [PATCH v3 15/20] selftests/landlock: Add trace event test infrastructure and tests
Mickaël Salaün
- [PATCH v3 16/20] selftests/landlock: Add filesystem tracepoint tests
Mickaël Salaün
- [PATCH v3 17/20] selftests/landlock: Add network tracepoint tests
Mickaël Salaün
- [PATCH v3 18/20] selftests/landlock: Add scope and ptrace tracepoint tests
Mickaël Salaün
- [PATCH v3 19/20] selftests/landlock: Add landlock_enforce_domain trace tests
Mickaël Salaün
- [PATCH v3 20/20] landlock: Document tracepoints
Mickaël Salaün
- [PATCH v3 03/20] landlock: Split struct landlock_domain from struct landlock_ruleset
Justin Suess
- [PATCH] apparmor: update website link
Serge Hallyn
- [PATCH] apparmor: update website link
John Johansen
- unix_stream_connect and socket address resolution
Günther Noack
- [PATCH v1] selftests/landlock: Add tests for O_TMPFILE
Günther Noack
- [PATCH v3 0/3] keys: fix keyring assoc-array out-of-bounds read and index inconsistency
Jarkko Sakkinen
- [RFC PATCH 3/4] xfs: replace ns_capable_noaudit()
Serge E. Hallyn
- [PATCH] apparmor: update website link
Baruch Siach
- [PATCH] capability: remove non-kernel-doc comments
Randy Dunlap
- [PATCH] capability: remove non-kernel-doc comments
Paul Moore
- [PATCH] apparmor: update website link
John Johansen
- [PATCH] apparmor: switch website link to https
Baruch Siach
- [PATCH 0/2] doc: LSM: update usage document for current LSM stacking
Casey Schaufler
- [PATCH] apparmor: switch website link to https
John Johansen
- [PATCH v6 0/8] lsm: Replace security_sb_mount with granular mount hooks
Song Liu
- [PATCH] capability: remove non-kernel-doc comments
sergeh at kernel.org
- [PATCH 2/6] landlock: Scope POSIX message queue opens
Justin Suess
- [PATCH 0/2] doc: LSM: update usage document for current LSM stacking
Lincoln Wallace
- [PATCH v5 1/3] security: rework inode_init_security xattr handling
David Windsor
- [PATCH v2 1/9] security: add LSM blob and hooks for namespaces
Mickaël Salaün
- [PATCH v2 1/9] security: add LSM blob and hooks for namespaces
Mickaël Salaün
- [PATCH v2 9/9] landlock: Add documentation for capability and namespace restrictions
Mickaël Salaün
- [RFC PATCH 3/4] xfs: replace ns_capable_noaudit()
Carlos Maiolino
- [PATCH v3 1/3] landlock: Require LANDLOCK_ACCESS_FS_MAKE_WHITEOUT for RENAME_WHITEOUT
Günther Noack
- [PATCH v4 0/5] landlock: Restrict whiteout object creation
Günther Noack
- [PATCH v4 1/5] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test
Günther Noack
- [PATCH v4 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Günther Noack
- [PATCH v4 3/5] selftests/landlock: Add tests for whiteout object creation
Günther Noack
- [PATCH v4 4/5] selftests/landlock: Test whiteout object behaviour in OverlayFS renames
Günther Noack
- [PATCH v4 5/5] landlock: Link the erratum documentation for whiteout objects
Günther Noack
- [PATCH v4 0/2] Add Apple T2 NHI device links
Atharva Tiwari
- [PATCH v4 1/2] treewide: Add a flag to detect the Apple T2 chip
Atharva Tiwari
- [PATCH v4 2/2] thunderbolt: Add device links for Apple T2 NHI
Atharva Tiwari
- [PATCH] ima: Report errno for failed hash collection to audit
Mimi Zohar
- [PATCH] ima: Report errno for failed hash collection to audit
Frederick Lawler
- [PATCH v2] security, fs, nfs, net: update security_inode_listsecurity() interface
Chuck Lever
- [PATCH v2 2/3] time/jiffies: Include linux/sysctl.h for proc_int_u2k_conv_uop(), ...
Thomas Gleixner
- [PATCH v2] security, fs, nfs, net: update security_inode_listsecurity() interface
Paul Moore
- [PATCH v3 00/12] Landlock: Namespace and capability control
Mickaël Salaün
- [PATCH v3 01/12] ns: Free anonymous mount namespaces via ns_common_free()
Mickaël Salaün
- [PATCH v3 02/12] security: add LSM blob and hooks for namespaces
Mickaël Salaün
- [PATCH v3 03/12] security: Add LSM_AUDIT_DATA_NS for namespace audit records
Mickaël Salaün
- [PATCH v3 04/12] landlock: Rename quiet_masks to quiet_access
Mickaël Salaün
- [PATCH v3 05/12] landlock: Wrap per-layer access masks in struct layer_config
Mickaël Salaün
- [PATCH v3 06/12] landlock: Copy the quiet mask in the ruleset merge helper
Mickaël Salaün
- [PATCH v3 07/12] landlock: Enforce namespace use restrictions
Mickaël Salaün
- [PATCH v3 08/12] landlock: Enforce capability restrictions
Mickaël Salaün
- [PATCH v3 09/12] selftests/landlock: Add namespace restriction tests
Mickaël Salaün
- [PATCH v3 10/12] selftests/landlock: Add capability restriction tests
Mickaël Salaün
- [PATCH v3 11/12] samples/landlock: Add capability and namespace restriction support
Mickaël Salaün
- [PATCH v3 12/12] landlock: Add documentation for capability and namespace restrictions
Mickaël Salaün
- [PATCH v2] security, fs, nfs, net: update security_inode_listsecurity() interface
Paul Moore
- [PATCH v4 2/2] thunderbolt: Add device links for Apple T2 NHI
Mika Westerberg
- [PATCH v2 2/3] time/jiffies: Include linux/sysctl.h for proc_int_u2k_conv_uop(), ...
Petr Pavlu
- [PATCH v1] landlock: Document the threat model
Günther Noack
- [PATCH v5 0/2] Add Apple T2 NHI device links
Atharva Tiwari
- [PATCH v5 1/2] treewide: Add a flag to detect the Apple T2 chip
Atharva Tiwari
- [PATCH v5 2/2] thunderbolt: Add device links for Apple T2 NHI
Atharva Tiwari
- [PATCH v2 0/3] integrity: Return error codes in audit messages
Frederick Lawler
- [PATCH v2 1/3] integrity: Replace all uses of integrity_audit_msg() with integrity_audit_message()
Frederick Lawler
- [PATCH v2 2/3] integrity: Remove integrity_audit_msg()
Frederick Lawler
- [PATCH v2 3/3] integrity: Report error code in integrity_audit_message() call sites
Frederick Lawler
- [PATCH v2 0/6] landlock: Add scoped access bit for SysV message queues
Justin Suess
- [PATCH v2 1/6] landlock: Add kern_ipc_perm credential blob structs
Justin Suess
- [PATCH v2 2/6] landlock: Add LANDLOCK_SCOPE_SYSV_MSG_QUEUE
Justin Suess
- [PATCH v2 3/6] landlock: Bump ABI for LANDLOCK_SCOPE_SYSV_MSG_QUEUE
Justin Suess
- [PATCH v2 4/6] selftests/landlock: Test LANDLOCK_SCOPE_SYSV_MSG_QUEUE
Justin Suess
- [PATCH v2 5/6] samples/landlock: Support LANDLOCK_SCOPE_SYSV_MSG_QUEUE in sandboxer
Justin Suess
- [PATCH v2 6/6] landlock: Document LANDLOCK_SCOPE_SYSV_MSG_QUEUE
Justin Suess
- [PATCH v5 1/2] treewide: Add a flag to detect the Apple T2 chip
Borislav Petkov
- [PATCH net] netlabel: check register_netdevice_notifier() error in netlbl_unlabel_init()
Minhong He
- [PATCH v5 2/2] thunderbolt: Add device links for Apple T2 NHI
Mika Westerberg
- [PATCH] landlock: Document io_uring credentials management
Günther Noack
- [PATCH 0/6] landlock: Add POSIX message queue scoping
Mickaël Salaün
- [PATCH 2/6] landlock: Scope POSIX message queue opens
Mickaël Salaün
- [PATCH 3/6] landlock: Bump ABI for LANDLOCK_SCOPE_POSIX_MSG_QUEUE
Mickaël Salaün
- [PATCH 4/6] selftests/landlock: Test POSIX message queue scoping
Mickaël Salaün
- [PATCH 5/6] samples/landlock: Support POSIX message queue scoping
Mickaël Salaün
- [PATCH -next, v3] ima: add cond_resched() in ima_calc_file_hash_tfm loop
Gaosheng Cui
- [PATCH -next,v3] ima: add cond_resched() in ima_calc_file_hash_tfm loop
Eric Biggers
- [PATCH v2 06/17] landlock: Add create_ruleset and free_ruleset tracepoints
Mickaël Salaün
- [PATCH net] netlabel: check register_netdevice_notifier() error in netlbl_unlabel_init()
Paul Moore
- [PATCH v2 06/17] landlock: Add create_ruleset and free_ruleset tracepoints
Justin Suess
- [PATCH net v2] netlabel: check register_netdevice_notifier() error in netlbl_unlabel_init()
Minhong He
- [PATCH 0/6] landlock: Add POSIX message queue scoping
Oxana Kharitonova
- [PATCH v5 2/2] thunderbolt: Add device links for Apple T2 NHI
Atharva Tiwari
- [syzbot] [integrity?] [lsm?] possible deadlock in process_measurement (6)
syzbot
- [PATCH] ima: fix out-of-bounds read in xattr_verify()
Lincoln Wallace
- linux-next: Tree for Jul 29 (apparmor)
Randy Dunlap
- [PATCH v3 01/12] ns: Free anonymous mount namespaces via ns_common_free()
Christian Brauner
- [PATCH v5 2/2] thunderbolt: Add device links for Apple T2 NHI
Mika Westerberg
- linux-next: Tree for Jul 29 (apparmor)
John Johansen
- [PATCH v5 2/2] thunderbolt: Add device links for Apple T2 NHI
Atharva Tiwari
- [PATCH v6 bpf-next 0/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
David Windsor
- [PATCH v6 bpf-next 1/4] security: introduce struct lsm_xattrs
David Windsor
- [PATCH v6 bpf-next 2/4] security: add security_lsmxattr_add()
David Windsor
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
David Windsor
- [PATCH v6 bpf-next 4/4] selftests/bpf: add tests for bpf_init_inode_xattr kfunc
David Windsor
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
David Windsor
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Justin Suess
- [PATCH bpf-next 01/13] lsm: Add LSM hook security_policy_kptr_from_fd
Justin Suess
- [PATCH bpf-next 02/13] lsm: Add LSM hook security_policy_kptr_put
Justin Suess
- [PATCH bpf-next 03/13] lsm: Add LSM hook security_bprm_enforce_policy_kptr
Justin Suess
- [PATCH bpf-next 04/13] landlock: Expose the ruleset fd lookup to the rest of Landlock
Justin Suess
- [PATCH bpf-next 05/13] landlock: Factor the credential restriction out of landlock_restrict_self()
Justin Suess
- [PATCH bpf-next 06/13] landlock: Implement the LSM policy kptr hooks
Justin Suess
- [PATCH bpf-next 07/13] bpf: Add the LSM policy kfunc infrastructure
Justin Suess
- [PATCH bpf-next 08/13] bpf: Add the bpf_landlock_put_ruleset kfunc and ruleset destructor
Justin Suess
- [PATCH bpf-next 09/13] bpf: Add the bpf_landlock_get_ruleset_from_fd kfunc
Justin Suess
- [PATCH bpf-next 10/13] bpf: Add the bpf_landlock_restrict_binprm kfunc
Justin Suess
- [PATCH bpf-next 11/13] selftests/bpf: Add tests for the Landlock policy kfuncs
Justin Suess
- [PATCH bpf-next 12/13] landlock: Document the BPF kfunc interface
Justin Suess
- [PATCH bpf-next 13/13] lsm: Document the LSM policy kptr hooks
Justin Suess
- [PATCH v4 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Mickaël Salaün
- [PATCH v4 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Mickaël Salaün
- [PATCH v4 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Günther Noack
- [PATCH v4 3/5] selftests/landlock: Add tests for whiteout object creation
Mickaël Salaün
- [PATCH v4 4/5] selftests/landlock: Test whiteout object behaviour in OverlayFS renames
Mickaël Salaün
- Landlock: mount_setattr(2) is unmediated by LSMs (ro-mount confinement bypass)
Christian Brauner
- [PATCH v4 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Günther Noack
- [PATCH] KEYS: trusted: Fix TPM teardown ordering
Chengfeng Ye
- [PATCH v4 3/5] selftests/landlock: Add tests for whiteout object creation
Günther Noack
- [PATCH v4 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Günther Noack
- [PATCH v4 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Mickaël Salaün
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
David Windsor
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
David Windsor
- [PATCH v5 0/5] landlock: Restrict whiteout object creation
Günther Noack
- [PATCH v5 1/5] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test
Günther Noack
- [PATCH v5 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Günther Noack
- [PATCH v5 3/5] selftests/landlock: Add tests for whiteout object creation
Günther Noack
- [PATCH v5 4/5] selftests/landlock: Test whiteout object behaviour in OverlayFS renames
Günther Noack
- [PATCH v5 5/5] landlock: Link the erratum documentation for whiteout objects
Günther Noack
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v2] security, fs, nfs, net: update security_inode_listsecurity() interface
Paul Moore
- [PATCH 0/4] CRASH_ZEROIZE: Wipe secrets before kdump
Jan Sebastian Götte
- [PATCH 1/4] of/kexec: fix typo in comment (usable-memory-range)
Jan Sebastian Götte
- [PATCH 2/4] kexec: add CRASH_ZEROIZE to wipe secrets before kdump
Jan Sebastian Götte
- [PATCH 3/4] mm/secretmem: zeroize secret pages before kdump
Jan Sebastian Götte
- [PATCH 4/4] security/keys: zeroize key payloads before kdump
Jan Sebastian Götte
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v2] security, fs, nfs, net: update security_inode_listsecurity() interface
Chuck Lever
- [PATCH v2] security, fs, nfs, net: update security_inode_listsecurity() interface
Anna Schumaker
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v2] security, fs, nfs, net: update security_inode_listsecurity() interface
Paul Moore
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Paul Moore
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Justin Suess
- [PATCH 0/3] Implement LANDLOCK_RESTRICT_SELF_NNP_ON_EXEC
Mickaël Salaün
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Paul Moore
- [PATCH 0/3] Implement LANDLOCK_RESTRICT_SELF_NNP_ON_EXEC
Mickaël Salaün
- [PATCH v2 0/3] Implement LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Mickaël Salaün
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v2 1/3] landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Mickaël Salaün
- [PATCH v2 2/3] selftests/landlock: Test LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Mickaël Salaün
- [PATCH v2 3/3] landlock: Document LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Mickaël Salaün
- [PATCH v5 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Mickaël Salaün
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v6 bpf-next 1/4] security: introduce struct lsm_xattrs
bot+bpf-ci at kernel.org
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH bpf-next 05/13] landlock: Factor the credential restriction out of landlock_restrict_self()
bot+bpf-ci at kernel.org
- [PATCH bpf-next 07/13] bpf: Add the LSM policy kfunc infrastructure
bot+bpf-ci at kernel.org
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
bot+bpf-ci at kernel.org
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Casey Schaufler
- [PATCH v2 1/3] landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Casey Schaufler
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
David Windsor
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Kumar Kartikeya Dwivedi
Last message date:
Fri Jul 31 23:35:35 UTC 2026
Archived on: Fri Jul 31 23:36:55 UTC 2026
This archive was generated by
Pipermail 0.09 (Mailman edition).