August 2026 Archives by author
Starting: Sat Aug 1 10:50:28 UTC 2026
Ending: Mon Aug 31 22:42:08 UTC 2026
Messages: 514
- [PATCH 1/3] proc: refactor /proc/$pid/mem to use struct as private_data
Lorenzo Stoakes (ARM)
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Lorenzo Stoakes (ARM)
- [PATCH 3/3] selinux: require EXECMEM or PTRACE for FOLL_FORCE introspection
Lorenzo Stoakes (ARM)
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Lorenzo Stoakes (ARM)
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Lorenzo Stoakes (ARM)
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Lorenzo Stoakes (ARM)
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Lorenzo Stoakes (ARM)
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Lorenzo Stoakes (ARM)
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Lorenzo Stoakes (ARM)
- [PATCH v2 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Lorenzo Stoakes (ARM)
- [PATCH v2 3/3] selinux: require PROCESS__PTRACE for FOLL_FORCE introspection
Lorenzo Stoakes (ARM)
- [PATCH 3/4] mm/secretmem: zeroize secret pages before kdump
David Hildenbrand (Arm)
- [PATCH 3/4] mm/secretmem: zeroize secret pages before kdump
David Hildenbrand (Arm)
- [PATCH 1/3] proc: refactor /proc/$pid/mem to use struct as private_data
David Hildenbrand (Arm)
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
David Hildenbrand (Arm)
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
David Hildenbrand (Arm)
- [PATCH 3/4] mm/secretmem: zeroize secret pages before kdump
David Hildenbrand (Arm)
- [PATCH v2 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
David Hildenbrand (Arm)
- [BUG] general protection fault in security_path_post_mknod
Farhad Alemi
- [PATCH v2 00/13] CRASH_WIPE_SECRETS: Wipe secrets before kdump (was: CRASH_ZEROIZE)
Eric Biggers
- [PATCH v2 00/13] CRASH_WIPE_SECRETS: Wipe secrets before kdump (was: CRASH_ZEROIZE)
Eric Biggers
- [PATCH 0/3] lib/crypto: Provide a function for zeroizing hmac_sha1_ctx
Eric Biggers
- keys: request_key_auth shows a global pid in /proc/keys across pid namespaces
James Bottomley
- [RFC] IMA: periodic runtime re-measurement of process .text/GOT
James Bottomley
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
Nicolas Bouchinet
- [PATCH] ima: clean up IMA_MEASURE_PCR_IDX in Kconfig
Julian Braha
- [PATCH] ima: clean up IMA_MEASURE_PCR_IDX in Kconfig
Julian Braha
- [PATCH] ima: allow users to specify the pcr index with IMA_MEASURE_PCR_IDX
Julian Braha
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Christian Brauner
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Christian Brauner
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Christian Brauner
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Christian Brauner
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Christian Brauner
- [PATCH v2 0/3] pidfd: add task path ioctls
Christian Brauner
- [PATCH RESEND v3] hardening: Default randstruct off with rust for better allmodconfig support
Mark Brown
- [PATCH v2 13/13] dm crypt: wipe key material before kdump
Milan Broz
- [PATCH] apparmor: fix NULL ctx->peer derefs in unix socket ctx updates
Maxime Bélair
- [RFC PATCH 00/24] pidfd: add a minimal process spawn builder
Li Chen
- [RFC PATCH 12/24] fork: let kernel callers create embryonic tasks
Li Chen
- [PATCH RESEND v3] hardening: Default randstruct off with rust for better allmodconfig support
Kees Cook
- [PATCH] apparmor: fix integer overflow in verify_tags() bounds check
Fabrice Derepas
- [PATCH] ima: reject a kexec buffer whose declared size exceeds the buffer
Fabrice Derepas
- [PATCH] ima: bound line scan in ima_read_policy() to fix OOB read
Fabrice Derepas
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
Kumar Kartikeya Dwivedi
- [PATCH v20 7/8] rust: Add `OwnableRefCounted`
Gary Guo
- [RFC PATCH 00/24] pidfd: add a minimal process spawn builder
Mateusz Guzik
- [PATCH 0/4] CRASH_ZEROIZE: Wipe secrets before kdump
Jan Sebastian Götte
- [PATCH 0/4] CRASH_ZEROIZE: Wipe secrets before kdump
Jan Sebastian Götte
- [PATCH 0/4] CRASH_ZEROIZE: Wipe secrets before kdump
Jan Sebastian Götte
- [PATCH 4/4] security/keys: zeroize key payloads before kdump
Jan Sebastian Götte
- [PATCH 3/4] mm/secretmem: zeroize secret pages before kdump
Jan Sebastian Götte
- [PATCH 3/4] mm/secretmem: zeroize secret pages before kdump
Jan Sebastian Götte
- [PATCH v2 00/13] CRASH_WIPE_SECRETS: Wipe secrets before kdump (was: CRASH_ZEROIZE)
Jan Sebastian Götte
- [PATCH v2 01/13] kexec: add CRASH_WIPE_SECRETS to wipe secrets before kdump
Jan Sebastian Götte
- [PATCH v2 02/13] crash-core: Flush caches on CRASH_WIPE_SECRETS
Jan Sebastian Götte
- [PATCH v2 03/13] arm64/mm: add set_direct_map_default_nosplit()
Jan Sebastian Götte
- [PATCH v2 04/13] mm/secretmem: wipe secret pages before kdump
Jan Sebastian Götte
- [PATCH v2 05/13] security/keys: wipe key payloads before kdump
Jan Sebastian Götte
- [PATCH v2 06/13] security/keys: implement wipe op for user-type keys
Jan Sebastian Götte
- [PATCH v2 07/13] security/keys: implement wipe op for big_key
Jan Sebastian Götte
- [PATCH v2 08/13] security/keys: implement wipe op for trusted and encrypted keys
Jan Sebastian Götte
- [PATCH v2 09/13] security/keys: implement wipe op for asymmetric keys
Jan Sebastian Götte
- [PATCH v2 10/13] rxrpc: implement wipe op for rxrpc keys
Jan Sebastian Götte
- [PATCH v2 11/13] fscrypt: wipe master keys before kdump
Jan Sebastian Götte
- [PATCH v2 12/13] crypto: api - wipe tfm contexts before kdump
Jan Sebastian Götte
- [PATCH v2 13/13] dm crypt: wipe key material before kdump
Jan Sebastian Götte
- [PATCH v2 00/13] CRASH_WIPE_SECRETS: Wipe secrets before kdump (was: CRASH_ZEROIZE)
Jan Sebastian Götte
- [PATCH v2 13/13] dm crypt: wipe key material before kdump
Jan Sebastian Götte
- [PATCH v2 01/13] kexec: add CRASH_WIPE_SECRETS to wipe secrets before kdump
Jan Sebastian Götte
- [PATCH v2 01/13] kexec: add CRASH_WIPE_SECRETS to wipe secrets before kdump
Jan Sebastian Götte
- [PATCH] cred: clarify that task_struct::cred is only for the current task
Serge E. Hallyn
- [GIT PULL] capabilities update for v7.3
Serge E. Hallyn
- [GIT PULL] capabilities update for v7.3
Serge E. Hallyn
- [PATCH] selftests/landlock: prevent mount propagation from test namespaces
Peng Hao
- [PATCH 0/4] CRASH_ZEROIZE: Wipe secrets before kdump
Baoquan He
- [PATCH v2 01/13] kexec: add CRASH_WIPE_SECRETS to wipe secrets before kdump
Baoquan He
- [PATCH v2 01/13] kexec: add CRASH_WIPE_SECRETS to wipe secrets before kdump
Baoquan He
- [PATCH v2 01/13] kexec: add CRASH_WIPE_SECRETS to wipe secrets before kdump
Baoquan He
- [PATCH v4 1/5] xfs: fix capability check in xfs
Christoph Hellwig
- [PATCH v4 4/5] xfs: replace ns_capable_noaudit
Christoph Hellwig
- [PATCH 1/4] of/kexec: fix typo in comment (usable-memory-range)
Rob Herring
- [PATCH v6] rust: aref: make `AlwaysRefCounted::inc_ref` an associated function
Andreas Hindborg
- [PATCH v7] rust: aref: make `AlwaysRefCounted::inc_ref` an associated function
Andreas Hindborg
- [PATCH v20 0/8] rust: add `Ownable` trait and `Owned` type
Andreas Hindborg
- [PATCH v20 1/8] rust: alloc: add `KBox::into_non_null`
Andreas Hindborg
- [PATCH v20 2/8] rust: types: Add Ownable/Owned types
Andreas Hindborg
- [PATCH v20 3/8] rust: implement `ForeignOwnable` for `Owned`
Andreas Hindborg
- [PATCH v20 4/8] rust: page: convert to `Ownable`
Andreas Hindborg
- [PATCH v20 5/8] rust: rename `AlwaysRefCounted` to `RefCounted`.
Andreas Hindborg
- [PATCH v20 6/8] rust: Add missing SAFETY documentation for `ARef` example
Andreas Hindborg
- [PATCH v20 7/8] rust: Add `OwnableRefCounted`
Andreas Hindborg
- [PATCH v20 8/8] rust: page: add `from_raw()`
Andreas Hindborg
- [PATCH v20 6/8] rust: Add missing SAFETY documentation for `ARef` example
Andreas Hindborg
- [PATCH] apparmor: fix cred UAF caused by begin_current_label_crit_section()
Jann Horn
- [PATCH] apparmor: fix cred UAF caused by begin_current_label_crit_section()
Jann Horn
- [PATCH] apparmor: fix cred UAF caused by begin_current_label_crit_section()
Jann Horn
- [PATCH v2] apparmor: fix cred UAF caused by begin_current_label_crit_section()
Jann Horn
- [PATCH] smack: fix cred UAF in smack_file_send_sigiotask()
Jann Horn
- [PATCH] smack: fix cred UAF in smack_file_send_sigiotask()
Jann Horn
- [PATCH] cred: clarify that task_struct::cred is only for the current task
Jann Horn
- [PATCH] cred: remove RCU initializer for init_task.cred
Jann Horn
- [PATCH 0/3] proc,security,selinux: let SELinux block FOLL_FORCE for /proc/self/mem
Jann Horn
- [PATCH 1/3] proc: refactor /proc/$pid/mem to use struct as private_data
Jann Horn
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH 3/3] selinux: require EXECMEM or PTRACE for FOLL_FORCE introspection
Jann Horn
- [PATCH 3/3] selinux: require EXECMEM or PTRACE for FOLL_FORCE introspection
Jann Horn
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH 3/3] selinux: require EXECMEM or PTRACE for FOLL_FORCE introspection
Jann Horn
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH 3/3] selinux: require EXECMEM or PTRACE for FOLL_FORCE introspection
Jann Horn
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH v2 0/3] proc,security,selinux: let SELinux block FOLL_FORCE for /proc/self/mem
Jann Horn
- [PATCH v2 1/3] proc: refactor /proc/$pid/mem to use struct as private_data
Jann Horn
- [PATCH v2 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH v2 3/3] selinux: require PROCESS__PTRACE for FOLL_FORCE introspection
Jann Horn
- [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH v2 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH v2 3/3] selinux: require PROCESS__PTRACE for FOLL_FORCE introspection
Jann Horn
- [PATCH v2 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH 0/4] CRASH_ZEROIZE: Wipe secrets before kdump
David Howells
- [PATCH 0/3] lib/crypto: Provide a function for zeroizing hmac_sha1_ctx
Thomas Huth
- [PATCH 1/3] crypto: Provide a wrapper for zeroizing hmac_sha1_ctx
Thomas Huth
- [PATCH 2/3] security: keys: trusted: always clear the hmac_sha1_ctx before returning
Thomas Huth
- [PATCH 3/3] lib/crypto: sha1: Use hmac_sha1_zeroize_ctx() instead of memzero_explicit()
Thomas Huth
- [PATCH 0/3] lib/crypto: Provide a function for zeroizing hmac_sha1_ctx
Thomas Huth
- [PATCH] apparmor: fix NULL ctx->peer derefs in unix socket ctx updates
Aurelien Jarno
- [PATCH] apparmor: fix NULL ctx->peer derefs in unix socket ctx updates
Aurelien Jarno
- [PATCH] ima: reject modsig if detached data cannot be supplied
Jérémy Jean
- [PATCH] apparmor: fix cred UAF caused by begin_current_label_crit_section()
John Johansen
- [REGRESSION] apparmor: AF_UNIX datagram send slowdown after 6456ccbd2ff7
John Johansen
- [PATCH] apparmor: fix cred UAF caused by begin_current_label_crit_section()
John Johansen
- [PATCH] apparmor: fix cred UAF caused by begin_current_label_crit_section()
John Johansen
- [PATCH v2] apparmor: fix cred UAF caused by begin_current_label_crit_section()
John Johansen
- [PATCH] apparmor: fix integer overflow in verify_tags() bounds check
John Johansen
- [PATCH] apparmor: fix integer overflow in verify_tags() bounds check
John Johansen
- [PATCH] apparmor: fix out-of-bounds write when null terminating a label vec
John Johansen
- [REGRESSION] Apparmor deadlock in 6.12.101 in complain mode
John Johansen
- [GIT PULL] AppArmor updates for v7.3
John Johansen
- [PATCH 1/3] proc: refactor /proc/$pid/mem to use struct as private_data
Jan Kara
- [PATCH net v2] netlabel: check register_netdevice_notifier() error in netlbl_unlabel_init()
Jakub Kicinski
- [PATCH bpf-next 0/7] Add new way to add BPF LSM hooks
Jakub Kicinski
- [PATCH] apparmor: fix out-of-bounds write when null terminating a label vec
Hyunwoo Kim
- [PATCH] keys: reject descriptions that exceed the index length
Daehyeon Ko
- [PATCH] keys: reject descriptions that exceed the index length
Daehyeon Ko
- [PATCH v2] keys: reject descriptions that exceed the index length
Daehyeon Ko
- [PATCH v20 1/8] rust: alloc: add `KBox::into_non_null`
Danilo Krummrich
- [PATCH v20 7/8] rust: Add `OwnableRefCounted`
Danilo Krummrich
- [PATCH v20 4/8] rust: page: convert to `Ownable`
Danilo Krummrich
- [RFC] IMA: periodic runtime re-measurement of process .text/GOT
Nicolai Kuntze
- [RFC] IMA: periodic runtime re-measurement of process .text/GOT
Nicolai Kuntze
- [PATCH v2] keys: reject descriptions that exceed the index length
Sudhakar Kuppusamy
- [PATCH v2] KEYS: encrypted: fix integer overflow of datablob_len
Cen Zhang (Microsoft Security FORGE Labs)
- [syzbot] [lsm?] [integrity?] possible deadlock in ima_file_truncate
Frederick Lawler
- [syzbot] [lsm?] [integrity?] possible deadlock in ima_file_truncate
Frederick Lawler
- [PATCH 0/2] ima: don't measure/appraise files on configfs
Frederick Lawler
- [PATCH 1/2] configfs: move CONFIGFS_MAGIC definition to magic.h
Frederick Lawler
- [PATCH 2/2] ima: don't measure/appraise files on configfs
Frederick Lawler
- [syzbot] [lsm?] [integrity?] possible deadlock in ima_file_truncate
Frederick Lawler
- [PATCH 1/2] configfs: move CONFIGFS_MAGIC definition to magic.h
Frederick Lawler
- [PATCH v2 0/2] ima: don't measure/appraise files on configfs
Frederick Lawler
- [PATCH v2 1/2] configfs: move CONFIGFS_MAGIC definition to magic.h
Frederick Lawler
- [PATCH v2 2/2] ima: don't measure/appraise files on configfs
Frederick Lawler
- [PATCH v2 1/2] configfs: move CONFIGFS_MAGIC definition to magic.h
Frederick Lawler
- [PATCH] rust: security: replace `core::mem::zeroed` with `pin_init::zeroed`
Nils Lehnen
- [PATCH 1/2] configfs: move CONFIGFS_MAGIC definition to magic.h
Breno Leitao
- [PATCH v2 1/2] configfs: move CONFIGFS_MAGIC definition to magic.h
Breno Leitao
- [PATCH v2 1/2] configfs: move CONFIGFS_MAGIC definition to magic.h
Breno Leitao
- [PATCH AUTOSEL 6.18-5.10] ima: return error early if file xattr cannot be changed
Sasha Levin
- [PATCH AUTOSEL 6.18-5.15] integrity: Check for NULL returned by asymmetric_key_public_key
Sasha Levin
- [PATCH AUTOSEL 6.18-6.12] apparmor: propagate -ENOMEM correctly in unpack_table
Sasha Levin
- [PATCH AUTOSEL 6.18-5.10] netlabel: fix IPv6 unlabeled address add error handling
Sasha Levin
- [REGRESSION] apparmor: AF_UNIX datagram send slowdown after 6456ccbd2ff7
Chengfeng Lin
- [PATCH v4 5/5] capability: unexport has_capability_noaudit
Carlos Maiolino
- [PATCH v4 4/5] xfs: replace ns_capable_noaudit
Carlos Maiolino
- [PATCH v4 1/5] xfs: fix capability check in xfs
Carlos Maiolino
- [PATCH v4 0/5] Fix quota evasion on xfs and add capable_noaudit
Carlos Maiolino
- [PATCH] keys: fix lost wakeup when reaping a dead key type
Karl Mehltretter
- [PATCH v2] keys: fix lost wakeup when reaping a dead key type
Karl Mehltretter
- [PATCH] keys: set persistent keyring timeout before destination linking
Karl Mehltretter
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH v6 bpf-next 3/4] bpf: add bpf_init_inode_xattr kfunc for atomic inode labeling
Paul Moore
- [PATCH] fs: fix user path of nested backing files
Paul Moore
- [PATCH RESEND v3] hardening: Default randstruct off with rust for better allmodconfig support
Paul Moore
- [GIT PULL] selinux/selinux-pr-20260805
Paul Moore
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Paul Moore
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Paul Moore
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Paul Moore
- [PATCH] cred: clarify that task_struct::cred is only for the current task
Paul Moore
- [PATCH v3 3/12] security: Add LSM_AUDIT_DATA_NS for namespace audit records
Paul Moore
- [PATCH] cred: clarify that task_struct::cred is only for the current task
Paul Moore
- [PATCH] cred: remove RCU initializer for init_task.cred
Paul Moore
- [PATCH] lsm: update the BUILD_BUG_ON() in audit_log_lsm_data()
Paul Moore
- [PATCH] lsm: update the BUILD_BUG_ON() in audit_log_lsm_data()
Paul Moore
- [GIT PULL] selinux/selinux-pr-20260814
Paul Moore
- [GIT PULL] lsm/lsm-pr-20260814
Paul Moore
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
Paul Moore
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
Paul Moore
- [PATCH v2 1/2] security: Delete dumplicate assignment
Paul Moore
- [PATCH v2 2/2] security: Fix call security_backing_file_free second time
Paul Moore
- [PATCH v2 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Paul Moore
- [PATCH v2 3/3] selinux: require PROCESS__PTRACE for FOLL_FORCE introspection
Paul Moore
- [BUG] general protection fault in security_path_post_mknod
Paul Moore
- [PATCH v2 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Paul Moore
- [PATCH v2 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Paul Moore
- [PATCH] cred: clarify that task_struct::cred is only for the current task
Paul Moore
- [PATCH v3 3/12] security: Add LSM_AUDIT_DATA_NS for namespace audit records
Paul Moore
- [PATCH] lsm: update the BUILD_BUG_ON() in audit_log_lsm_data()
Paul Moore
- [PATCH v2 1/2] security: Delete dumplicate assignment
Paul Moore
- [PATCH v2 2/2] security: Fix call security_backing_file_free second time
Paul Moore
- [PATCH bpf-next 1/7] bpf: Allow BPF LSM programs to attach to more hooks
Paul Moore
- [PATCH] ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()
Bradley Morgan
- Re: [syzbot] [audit?] BUG: unable to handle kernel paging request in integrity_audit_message
Bradley Morgan
- [PATCH v5 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Günther Noack
- [PATCH v4 4/5] selftests/landlock: Test whiteout object behaviour in OverlayFS renames
Günther Noack
- [PATCH v6 0/6] landlock: Restrict whiteout object creation
Günther Noack
- [PATCH v6 1/6] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test
Günther Noack
- [PATCH v6 2/6] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Günther Noack
- [PATCH v6 3/6] selftests/landlock: Add tests for whiteout object creation
Günther Noack
- [PATCH v6 4/6] selftests/landlock: Add audit test for whiteout object creation
Günther Noack
- [PATCH v6 5/6] selftests/landlock: Test whiteout object behaviour in OverlayFS renames
Günther Noack
- [PATCH v6 6/6] landlock: Link the erratum documentation for whiteout objects
Günther Noack
- [PATCH v6 3/6] selftests/landlock: Add tests for whiteout object creation
Günther Noack
- [PATCH v4 09/19] landlock: Add create_domain and free_domain tracepoints
Günther Noack
- [PATCH v4 03/19] landlock: Split struct landlock_domain from struct landlock_ruleset
Günther Noack
- [PATCH 0/6] landlock: Add POSIX message queue scoping
Günther Noack
- [PATCH v2 3/6] landlock: Bump ABI for LANDLOCK_SCOPE_SYSV_MSG_QUEUE
Günther Noack
- [PATCH v2 4/6] selftests/landlock: Test LANDLOCK_SCOPE_SYSV_MSG_QUEUE
Günther Noack
- [PATCH v2 0/6] landlock: Add scoped access bit for SysV message queues
Günther Noack
- [PATCH v2 0/6] landlock: Add scoped access bit for SysV message queues
Günther Noack
- [PATCH v2 0/6] landlock: Add scoped access bit for SysV message queues
Günther Noack
- [PATCH v2 0/6] landlock: Add scoped access bit for SysV message queues
Günther Noack
- [PATCH v2 0/6] landlock: Add scoped access bit for SysV message queues
Günther Noack
- [PATCH] selftests/landlock: Fix snprintf truncation checks in test files
Günther Noack
- [PATCH v5 6/6] landlock: Add documentation for UDP support
Günther Noack
- [PATCH v11 2/9] landlock: Add API support and docs for the quiet flags
Günther Noack
- [PATCH v4 4/5] landlock: Document LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Günther Noack
- [PATCH v1] landlock: Demonstrate best-effort allowed_access filtering
Günther Noack
- [PATCH v6 2/6] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Günther Noack
- [PATCH 0/6] landlock: Support MPTCP bind and connect restrictions
Günther Noack
- [PATCH 1/6] samples/landlock: Implement best-effort fallback for network rules.
Günther Noack
- [PATCH 2/6] selftests/landlock: Generalize net test helpers for multiple socket types
Günther Noack
- [PATCH 3/6] landlock: Add MPTCP bind and connect access rights
Günther Noack
- [PATCH 4/6] selftests/landlock: Add MPTCP network access tests
Günther Noack
- [PATCH 5/6] samples/landlock: Support MPTCP access rights
Günther Noack
- [PATCH 6/6] landlock: Document MPTCP access rights
Günther Noack
- [PATCH v6] rust: aref: make `AlwaysRefCounted::inc_ref` an associated function
Miguel Ojeda
- [PATCH RESEND v3] hardening: Default randstruct off with rust for better allmodconfig support
Miguel Ojeda
- [PATCH v20 6/8] rust: Add missing SAFETY documentation for `ARef` example
Miguel Ojeda
- [PATCH] rust: security: replace `core::mem::zeroed` with `pin_init::zeroed`
Miguel Ojeda
- [RFC PATCH] smack: preserve low-integrity labels on copy via whitelist
Tang Peter
- [PATCH bpf-next 0/7] Add new way to add BPF LSM hooks
Anton Protopopov
- [PATCH bpf-next 1/7] bpf: Allow BPF LSM programs to attach to more hooks
Anton Protopopov
- [PATCH bpf-next 2/7] net, bpf: Add a generic netlink hook on msg_rcv
Anton Protopopov
- [PATCH bpf-next 3/7] net, bpf: Add bpf hooks for ethtool control path
Anton Protopopov
- [PATCH bpf-next 4/7] selftests/bpf: Extract some helpers from tests to the netlink library
Anton Protopopov
- [PATCH bpf-next 5/7] selftests/bpf: Add netdevsim helper library
Anton Protopopov
- [PATCH bpf-next 6/7] selftests/bpf: Add tests for the generic netlink BPF hook
Anton Protopopov
- [PATCH bpf-next 7/7] selftests/bpf: Add tests for BPF ethtool hooks
Anton Protopopov
- [PATCH bpf-next 1/7] bpf: Allow BPF LSM programs to attach to more hooks
Anton Protopopov
- [PATCH bpf-next 5/7] selftests/bpf: Add netdevsim helper library
Anton Protopopov
- [PATCH bpf-next 6/7] selftests/bpf: Add tests for the generic netlink BPF hook
Anton Protopopov
- [PATCH bpf-next 7/7] selftests/bpf: Add tests for BPF ethtool hooks
Anton Protopopov
- [PATCH bpf-next 2/7] net, bpf: Add a generic netlink hook on msg_rcv
Anton Protopopov
- [PATCH RFC 0/3] pidfd: add task path ioctls
Chen Linxuan via B4 Relay
- [PATCH RFC 1/3] fs: Introduce task path helpers
Chen Linxuan via B4 Relay
- [PATCH RFC 2/3] pidfd: Use scoped cleanup for task access
Chen Linxuan via B4 Relay
- [PATCH RFC 3/3] pidfd: Add task path ioctls
Chen Linxuan via B4 Relay
- [PATCH v2 0/3] pidfd: add task path ioctls
Chen Linxuan via B4 Relay
- [PATCH v2 1/3] fs: Introduce task path helpers
Chen Linxuan via B4 Relay
- [PATCH v2 2/3] pidfd: Use scoped cleanup for task access
Chen Linxuan via B4 Relay
- [PATCH v2 3/3] pidfd: Add task path ioctls
Chen Linxuan via B4 Relay
- [PATCH 0/2] lsm: expose mount idmaps to inode hooks
Daan De Meyer via B4 Relay
- [PATCH 1/2] lsm: expose mount idmaps to inode hooks
Daan De Meyer via B4 Relay
- [PATCH 2/2] selftests/bpf: verify mount idmaps reach inode hooks
Daan De Meyer via B4 Relay
- [PATCH v4 00/19] Landlock tracepoints
Steven Rostedt
- [PATCH v20 4/8] rust: page: convert to `Ownable`'
Alice Ryhl
- [PATCH] KEYS: trusted: Fix TPM teardown ordering
Jarkko Sakkinen
- [PATCH 2/4] kexec: add CRASH_ZEROIZE to wipe secrets before kdump
Jarkko Sakkinen
- [PATCH 4/4] security/keys: zeroize key payloads before kdump
Jarkko Sakkinen
- keys: request_key_auth shows a global pid in /proc/keys across pid namespaces
Jarkko Sakkinen
- keys: request_key_auth shows a global pid in /proc/keys across pid namespaces
Jarkko Sakkinen
- [PATCH] keys: fix lost wakeup when reaping a dead key type
Jarkko Sakkinen
- [PATCH 0/3] lib/crypto: Provide a function for zeroizing hmac_sha1_ctx
Jarkko Sakkinen
- [PATCH v2] keys: fix lost wakeup when reaping a dead key type
Jarkko Sakkinen
- [PATCH] keys: translate request_key_auth pid for the reading procfs instance
Jarkko Sakkinen
- [PATCH] keys: Fix key_user use-after-free during ownership changes
Jarkko Sakkinen
- [PATCH v2] KEYS: encrypted: fix integer overflow of datablob_len
Jarkko Sakkinen
- [PATCH v2] KEYS: encrypted: fix integer overflow of datablob_len
Jarkko Sakkinen
- [PATCH v2] KEYS: encrypted: fix integer overflow of datablob_len
Jarkko Sakkinen
- [PATCH] keys: reject descriptions that exceed the index length
Jarkko Sakkinen
- [BUG] security/keys: out-of-bounds in tpm2_unseal_trusted()
Jarkko Sakkinen
- [PATCH v3 07/20] tracing: Add __print_untrusted_str()
Mickaël Salaün
- [PATCH v3 03/20] landlock: Split struct landlock_domain from struct landlock_ruleset
Mickaël Salaün
- [PATCH v2 01/17] landlock: Prepare ruleset and domain type split
Mickaël Salaün
- [PATCH v2 03/17] landlock: Split struct landlock_domain from struct landlock_ruleset
Mickaël Salaün
- [PATCH v3 2/4] selftests/landlock: Test LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Mickaël Salaün
- [PATCH v3 1/4] landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Mickaël Salaün
- [PATCH v3 3/4] landlock: Document LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Mickaël Salaün
- [PATCH v3 1/4] landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Mickaël Salaün
- [PATCH v3 1/4] landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Mickaël Salaün
- [PATCH v4 0/5] Implement LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Mickaël Salaün
- [PATCH v4 00/19] Landlock tracepoints
Mickaël Salaün
- [PATCH v4 01/19] landlock: Prepare ruleset and domain type split
Mickaël Salaün
- [PATCH v4 02/19] landlock: Move domain query functions to domain.c
Mickaël Salaün
- [PATCH v4 03/19] landlock: Split struct landlock_domain from struct landlock_ruleset
Mickaël Salaün
- [PATCH v4 04/19] landlock: Split denial logging from audit into common framework
Mickaël Salaün
- [PATCH v4 05/19] landlock: Decouple the per-denial logging decision from CONFIG_AUDIT
Mickaël Salaün
- [PATCH v4 06/19] landlock: Consolidate access-right and scope names in a shared header
Mickaël Salaün
- [PATCH v4 07/19] landlock: Add create_ruleset and free_ruleset tracepoints
Mickaël Salaün
- [PATCH v4 08/19] landlock: Add landlock_add_rule_fs and landlock_add_rule_net tracepoints
Mickaël Salaün
- [PATCH v4 09/19] landlock: Add create_domain and free_domain tracepoints
Mickaël Salaün
- [PATCH v4 10/19] landlock: Add landlock_enforce_domain tracepoint
Mickaël Salaün
- [PATCH v4 11/19] landlock: Add tracepoints for rule checking
Mickaël Salaün
- [PATCH v4 12/19] landlock: Add landlock_deny_access_fs and landlock_deny_access_net
Mickaël Salaün
- [PATCH v4 13/19] landlock: Add tracepoints for ptrace and scope denials
Mickaël Salaün
- [PATCH v4 14/19] selftests/landlock: Add trace event test infrastructure and tests
Mickaël Salaün
- [PATCH v4 15/19] selftests/landlock: Add filesystem tracepoint tests
Mickaël Salaün
- [PATCH v4 16/19] selftests/landlock: Add network tracepoint tests
Mickaël Salaün
- [PATCH v4 17/19] selftests/landlock: Add scope and ptrace tracepoint tests
Mickaël Salaün
- [PATCH v4 18/19] selftests/landlock: Add landlock_enforce_domain trace tests
Mickaël Salaün
- [PATCH v4 19/19] landlock: Document tracepoints
Mickaël Salaün
- [PATCH v6 0/6] landlock: Restrict whiteout object creation
Mickaël Salaün
- [GIT PULL] Landlock update for v7.3-rc1
Mickaël Salaün
- [PATCH v1] selftests/landlock: Test abstract socket trace name limits
Mickaël Salaün
- [Bug] landlock: sun_path length underflow to SIZE_MAX in landlock_deny_scope_abstract_unix_socket TP_printk -> unbounded OOB read in trace reader
Mickaël Salaün
- [PATCH] ima: bound line scan in ima_read_policy() to fix OOB read
Roberto Sassu
- [PATCH] ima: select the SHA384 PCR bank for the boot aggregate
Roberto Sassu
- [PATCH] ima: select the SHA384 PCR bank for the boot aggregate
Roberto Sassu
- [GIT PULL] Smack patches for 7.3
Casey Schaufler
- [PATCH 0/7] Change skb secmarks to x-array indexes
Casey Schaufler
- [PATCH 1/7] net, smack: Create a function to set secmarks
Casey Schaufler
- [PATCH 2/7] LSM: Implement x array functions for secmarks
Casey Schaufler
- [PATCH 3/7] LSM: Two hooks for manipulating struct lsm_prop
Casey Schaufler
- [PATCH 4/7] SELinux: hooks for secctx_to_lsmprop and update_lsmprop
Casey Schaufler
- [PATCH 5/7] Smack: hooks for secctx_to_lsmprop and update_lsmprop
Casey Schaufler
- [PATCH 6/7] Apparmor: hooks for secctx_to_lsmprop and update_lsmprop
Casey Schaufler
- [PATCH 7/7] net, lsm: Change skb secmarks to x-array indexes
Casey Schaufler
- [RFC PATCH 0/3] smack: add file label preserve mechanism
Casey Schaufler
- Re: 回复: [RFC PATCH 0/3] smack: add file label preserve mechanism
Casey Schaufler
- Re: 回复: 回复: [RFC PATCH 0/3] smack: add file label preserve mechanism
Casey Schaufler
- [PATCH v2 01/15] lsm: Add the LSM policy object lifetime hooks
Casey Schaufler
- [PATCH 0/7] Change skb secmarks to x-array indexes
Casey Schaufler
- [PATCH 1/7] net, smack: Create a function to set secmarks
Casey Schaufler
- [PATCH 2/7] LSM: Implement x array functions for secmarks
Casey Schaufler
- [PATCH 3/7] LSM: Two hooks for manipulating struct lsm_prop
Casey Schaufler
- [PATCH 4/7] SELinux: hooks for secctx_to_lsmprop and update_lsmprop
Casey Schaufler
- [PATCH 5/7] Smack: hooks for secctx_to_lsmprop and update_lsmprop
Casey Schaufler
- [PATCH 6/7] Apparmor: hooks for secctx_to_lsmprop and update_lsmprop
Casey Schaufler
- [PATCH 7/7] net, lsm: Change skb secmarks to x-array indexes
Casey Schaufler
- [PATCH v5 13/14] kbuild: move handling of module stripping to Makefile.lib
Nicolas Schier
- [PATCH v5 14/14] kbuild: make CONFIG_MODULE_HASHES compatible with module stripping
Nicolas Schier
- [PATCH v5 1/2] treewide: Add a flag to detect the Apple T2 chip
Andy Shevchenko
- [PATCH] ima: select the SHA384 PCR bank for the boot aggregate
Singh, Jashandeep
- [PATCH] ima: select the SHA384 PCR bank for the boot aggregate
Singh, Jashandeep
- [PATCH] ima: select the SHA384 PCR bank for the boot aggregate
Singh, Jashandeep
- Subject: [REGRESSION] selinux: ~90% throughput drop in System V IPC (msg) since commit 7edea6e8c8e8
Stephen Smalley
- [PATCH 3/3] selinux: require EXECMEM or PTRACE for FOLL_FORCE introspection
Stephen Smalley
- [PATCH 3/3] selinux: require EXECMEM or PTRACE for FOLL_FORCE introspection
Stephen Smalley
- [PATCH v2 3/3] selinux: require PROCESS__PTRACE for FOLL_FORCE introspection
Stephen Smalley
- [PATCH 0/8] Extend PKWM to support user-created wrapping keys
Srish Srinivasan
- [PATCH 1/8] pseries/plpks: update PKS documentation and maintainer entry
Srish Srinivasan
- [PATCH 2/8] pseries/plpks: fix error handling in plpks_read_var()
Srish Srinivasan
- [PATCH 3/8] pseries/plpks: improve type consistency and parameter validation
Srish Srinivasan
- [PATCH 4/8] pseries/plpks: rename the default wrapping key macro
Srish Srinivasan
- [PATCH 5/8] pseries/plpks: hide wrapping_features when unsupported
Srish Srinivasan
- [PATCH 6/8] pseries/plpks: add HCALLs for PKWM wrapping key life cycle management
Srish Srinivasan
- [PATCH 7/8] keys/trusted_keys: enable PKWM wrapping key selection by label
Srish Srinivasan
- [PATCH 8/8] pseries/plpks/wrapkey: expose PKWM wrapping key management to userspace via sysfs
Srish Srinivasan
- [PATCH v4] keys/trusted_keys: move TPM-specific fields into trusted_tpm_options
Srish Srinivasan
- [PATCH 6/8] pseries/plpks: add HCALLs for PKWM wrapping key life cycle management
Srish Srinivasan
- [PATCH v2 00/10] Extend PKWM to support user-created wrapping keys
Srish Srinivasan
- [PATCH v2 01/10] pseries/plpks: update PKS documentation and maintainer entry
Srish Srinivasan
- [PATCH v2 02/10] pseries/plpks: fix error handling in plpks_read_var()
Srish Srinivasan
- [PATCH v2 03/10] pseries/plpks: improve type consistency and parameter validation
Srish Srinivasan
- [PATCH v2 04/10] keys/trusted_keys: propagate wrapping key generation errors
Srish Srinivasan
- [PATCH v2 05/10] pseries/plpks: rename the default wrapping key macro
Srish Srinivasan
- [PATCH v2 06/10] pseries/plpks: fix self-reference in plpks_var initializer
Srish Srinivasan
- [PATCH v2 07/10] pseries/plpks: hide wrapping_features when unsupported
Srish Srinivasan
- [PATCH v2 08/10] pseries/plpks: add HCALLs for PKWM wrapping key life cycle management
Srish Srinivasan
- [PATCH v2 09/10] keys/trusted_keys: enable PKWM wrapping key selection by label
Srish Srinivasan
- [PATCH v2 10/10] pseries/plpks/wrapkey: expose PKWM wrapping key management to userspace via sysfs
Srish Srinivasan
- [PATCH v3 0/4] Implement LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH v3 1/4] landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH v3 2/4] selftests/landlock: Test LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH v3 3/4] landlock: Document LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH v3 4/4] samples/landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS to sampler
Justin Suess
- [RFC PATCH 00/24] pidfd: add a minimal process spawn builder
Justin Suess
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Justin Suess
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Justin Suess
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Justin Suess
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Justin Suess
- [PATCH v3 1/4] landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH v4 0/5] Implement LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH v4 1/5] landlock: Check landlock_restrict_self(2)'s flags before privileges
Justin Suess
- [PATCH v4 3/5] selftests/landlock: Test LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH v4 4/5] landlock: Document LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH v4 5/5] samples/landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS to sampler
Justin Suess
- [PATCH v4 0/5] Implement LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Justin Suess
- [PATCH v4 2/5] landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
Justin Suess
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
Justin Suess
- [PATCH bpf-next 1/2] lsm: add bpf_security_locked_down() kfunc
Justin Suess
- [PATCH bpf-next 2/2] selftests/bpf: Test bpf_security_locked_down kfunc
Justin Suess
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
Justin Suess
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
Justin Suess
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
Justin Suess
- [PATCH v2 3/6] landlock: Bump ABI for LANDLOCK_SCOPE_SYSV_MSG_QUEUE
Justin Suess
- [PATCH v2 3/6] landlock: Bump ABI for LANDLOCK_SCOPE_SYSV_MSG_QUEUE
Justin Suess
- [PATCH v2 0/6] landlock: Add scoped access bit for SysV message queues
Justin Suess
- [PATCH v2 0/6] landlock: Add scoped access bit for SysV message queues
Justin Suess
- [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets
Justin Suess
- [PATCH v2 00/15] BPF interface for applying Landlock rulesets
Justin Suess
- [PATCH v2 01/15] lsm: Add the LSM policy object lifetime hooks
Justin Suess
- [PATCH v2 02/15] lsm: Add the bprm_apply_policy_object LSM hook
Justin Suess
- [PATCH v2 03/15] lsm: Move the lsm_for_each_hook() macro to security/lsm.h
Justin Suess
- [PATCH v2 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Justin Suess
- [PATCH v2 05/15] lsm: Add the bpf_lsm_policy_from_fd kfunc
Justin Suess
- [PATCH v2 06/15] lsm: Add the bpf_lsm_policy_acquire kfunc
Justin Suess
- [PATCH v2 07/15] lsm: Add the bpf_lsm_policy_apply_bprm kfunc
Justin Suess
- [PATCH v2 08/15] lsm: Document the LSM policy object interface
Justin Suess
- [PATCH v2 09/15] selftests/bpf: Add tests for the LSM policy object kfuncs
Justin Suess
- [PATCH v2 10/15] landlock: Expose the ruleset fd lookup to the rest of Landlock
Justin Suess
- [PATCH v2 11/15] landlock: Factor the credential restriction out of landlock_restrict_self()
Justin Suess
- [PATCH v2 12/15] landlock: Free rulesets after an RCU grace period
Justin Suess
- [PATCH v2 13/15] landlock: Implement the LSM policy object hooks
Justin Suess
- [PATCH v2 14/15] selftests/bpf: Test the LSM policy object kfuncs with Landlock
Justin Suess
- [PATCH v2 15/15] landlock: Document the BPF policy interface
Justin Suess
- [PATCH v2 01/15] lsm: Add the LSM policy object lifetime hooks
Justin Suess
- [PATCH] landlock: Fix use-after-free of the source's parent directory
Norbert Szetei
- [PATCH 3/6] landlock: Add MPTCP bind and connect access rights
Geliang Tang
- [PATCH v4] security: Expand task_setscheduler LSM hook
Aaron Tomlin
- [GIT PULL] capabilities update for v7.3
Linus Torvalds
- Subject: [REGRESSION] selinux: ~90% throughput drop in System V IPC (msg) since commit 7edea6e8c8e8
Jiri Vozar
- [PATCH v2] ima: fix out-of-bounds read in xattr_verify()
Lincoln Wallace
- [PATCH v3 04/12] landlock: Rename quiet_masks to quiet_access
Tingmao Wang
- [PATCH v3 05/12] landlock: Wrap per-layer access masks in struct layer_config
Tingmao Wang
- [PATCH v3 06/12] landlock: Copy the quiet mask in the ruleset merge helper
Tingmao Wang
- [PATCH v3 07/12] landlock: Enforce namespace use restrictions
Tingmao Wang
- [PATCH v3 08/12] landlock: Enforce capability restrictions
Tingmao Wang
- [PATCH v4 01/19] landlock: Prepare ruleset and domain type split
Tingmao Wang
- [PATCH v4 05/19] landlock: Decouple the per-denial logging decision from CONFIG_AUDIT
Tingmao Wang
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
David Windsor
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
David Windsor
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
David Windsor
- [PATCH v2 01/13] kexec: add CRASH_WIPE_SECRETS to wipe secrets before kdump
Lukas Wunner
- keys: request_key_auth shows a global pid in /proc/keys across pid namespaces
Maoyi Xie
- keys: request_key_auth shows a global pid in /proc/keys across pid namespaces
Maoyi Xie
- [PATCH] keys: translate request_key_auth pid for the reading procfs instance
Maoyi Xie
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
Xiujianfeng
- [PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
Xiujianfeng
- [PATCH] selftests/landlock: Fix snprintf truncation checks in test files
Wang Yan
- SafeSetID: GID transition policy lookup uses RUID as source, allowlist can be bypassed (setgid to any group including 0)
Yan Yanhx
- [PATCH] keys: Fix key_user use-after-free during ownership changes
Chengfeng Ye
- [PATCH] keys: Fix key_user use-after-free during ownership changes
Chengfeng Ye
- [PATCH] keys: Fix key_user use-after-free during ownership changes
Chengfeng Ye
- [PATCH 0/4] CRASH_ZEROIZE: Wipe secrets before kdump
Dave Young
- [PATCH 0/4] CRASH_ZEROIZE: Wipe secrets before kdump
Dave Young
- [PATCH 0/4] CRASH_ZEROIZE: Wipe secrets before kdump
Dave Young
- [PATCH] apparmor: fix cred UAF caused by begin_current_label_crit_section()
Peter Zijlstra
- [PATCH] ima: fix out-of-bounds read in xattr_verify()
Mimi Zohar
- [syzbot] [lsm?] [integrity?] possible deadlock in ima_file_truncate
Mimi Zohar
- [syzbot] [lsm?] [integrity?] possible deadlock in ima_file_truncate
Mimi Zohar
- [RFC] IMA: periodic runtime re-measurement of process .text/GOT
Mimi Zohar
- [PATCH 2/2] ima: don't measure/appraise files on configfs
Mimi Zohar
- [RFC] IMA: periodic runtime re-measurement of process .text/GOT
Mimi Zohar
- [RFC] IMA: periodic runtime re-measurement of process .text/GOT
Mimi Zohar
- [PATCH] ima: clean up IMA_MEASURE_PCR_IDX in Kconfig
Mimi Zohar
- [PATCH] ima: reject modsig if detached data cannot be supplied
Mimi Zohar
- [PATCH v2 1/2] configfs: move CONFIGFS_MAGIC definition to magic.h
Mimi Zohar
- [PATCH] ima: select the SHA384 PCR bank for the boot aggregate
Mimi Zohar
- [PATCH] ima: select the SHA384 PCR bank for the boot aggregate
Mimi Zohar
- [PATCH] ima: select the SHA384 PCR bank for the boot aggregate
Mimi Zohar
- [BUG] security/keys: out-of-bounds in tpm2_unseal_trusted()
co
- [PATCH -next,v3] ima: add cond_resched() in ima_calc_file_hash_tfm loop
cuigaosheng
- [PATCH] keys: Pin request_key_auth payload in instantiate paths
joeyli
- [PATCH bpf-next 2/2] selftests/bpf: Test bpf_security_locked_down kfunc
bot+bpf-ci at kernel.org
- [PATCH bpf-next 1/2] lsm: add bpf_security_locked_down() kfunc
bot+bpf-ci at kernel.org
- [PATCH bpf-next 1/7] bpf: Allow BPF LSM programs to attach to more hooks
bot+bpf-ci at kernel.org
- [PATCH bpf-next 5/7] selftests/bpf: Add netdevsim helper library
bot+bpf-ci at kernel.org
- [PATCH bpf-next 6/7] selftests/bpf: Add tests for the generic netlink BPF hook
bot+bpf-ci at kernel.org
- [PATCH bpf-next 2/7] net, bpf: Add a generic netlink hook on msg_rcv
bot+bpf-ci at kernel.org
- [PATCH bpf-next 7/7] selftests/bpf: Add tests for BPF ethtool hooks
bot+bpf-ci at kernel.org
- [PATCH v4 0/5] Fix quota evasion on xfs and add capable_noaudit
cem at kernel.org
- [PATCH v4 1/5] xfs: fix capability check in xfs
cem at kernel.org
- [PATCH v4 2/5] capability: Add new capable_noaudit
cem at kernel.org
- [PATCH v4 3/5] quota: Don't issue audit messages on quota enforcing
cem at kernel.org
- [PATCH v4 4/5] xfs: replace ns_capable_noaudit
cem at kernel.org
- [PATCH v4 5/5] capability: unexport has_capability_noaudit
cem at kernel.org
- [GIT PULL] selinux/selinux-pr-20260805
pr-tracker-bot at kernel.org
- [GIT PULL] selinux/selinux-pr-20260814
pr-tracker-bot at kernel.org
- [GIT PULL] Smack patches for 7.3
pr-tracker-bot at kernel.org
- [GIT PULL] lsm/lsm-pr-20260814
pr-tracker-bot at kernel.org
- [GIT PULL] Landlock update for v7.3-rc1
pr-tracker-bot at kernel.org
- [GIT PULL] capabilities update for v7.3
pr-tracker-bot at kernel.org
- [GIT PULL] AppArmor updates for v7.3
pr-tracker-bot at kernel.org
- [PATCH v4 1/5] xfs: fix capability check in xfs
sergeh at kernel.org
- [PATCH v4 2/5] capability: Add new capable_noaudit
sergeh at kernel.org
- [PATCH v4 5/5] capability: unexport has_capability_noaudit
sergeh at kernel.org
- [PATCH v4 0/5] Fix quota evasion on xfs and add capable_noaudit
sergeh at kernel.org
- [PATCH v4 4/5] xfs: replace ns_capable_noaudit
sergeh at kernel.org
- [Bug] landlock: sun_path length underflow to SIZE_MAX in landlock_deny_scope_abstract_unix_socket TP_printk -> unbounded OOB read in trace reader
poppet lovelace
- [syzbot] [lsm?] memory leak in prepare_creds (7)
syzbot
- [syzbot] [lsm?] [integrity?] possible deadlock in ima_file_truncate
syzbot
- [syzbot] [apparmor?] WARNING in aa_policy_destroy
syzbot
- [syzbot] [audit?] BUG: unable to handle kernel paging request in integrity_audit_message
syzbot
- [syzbot] [audit?] BUG: unable to handle kernel paging request in integrity_audit_message
syzbot
- [REGRESSION] Apparmor deadlock in 6.12.101 in complain mode
Mattias Åsander
- IT教育で、新規事業
石嶋紗季
Last message date:
Mon Aug 31 22:42:08 UTC 2026
Archived on: Tue Sep 1 01:05:55 UTC 2026
This archive was generated by
Pipermail 0.09 (Mailman edition).