September 2026 Archives by author
Starting: Tue Sep 1 12:14:25 UTC 2026
Ending: Wed Sep 30 23:59:02 UTC 2026
Messages: 869
- [PATCH v3 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Serge Hallyn (AMD)
- [PATCH v2 0/8] sched: introduce for_each_process_rculock and for_each_thread_rculock
Lorenzo Stoakes (ARM)
- [PATCH v2 1/8] sched: introduce for_each_process_rculock and for_each_thread_rculock
Lorenzo Stoakes (ARM)
- [PATCH v2 2/8] mm/oom_kill: convert process/thread iterators to for_each_*_rculock
Lorenzo Stoakes (ARM)
- [PATCH v2 3/8] mm/ksm: convert process iterator to for_each_process_rculock
Lorenzo Stoakes (ARM)
- [PATCH v2 4/8] mm/memory-failure: convert process iterator to for_each_process_rculock
Lorenzo Stoakes (ARM)
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Lorenzo Stoakes (ARM)
- [PATCH v2 6/8] fs: convert process/thread iterators to for_each_*_rculock
Lorenzo Stoakes (ARM)
- [PATCH v2 7/8] lib: convert process iterator to for_each_process_rculock
Lorenzo Stoakes (ARM)
- [PATCH v2 8/8] security/landlock: convert thread iterator to for_each_thread_rculock
Lorenzo Stoakes (ARM)
- [PATCH v3 00/12] CRASH_MEMACTION: describe pages to a kdump kernel (was: CRASH_WIPE_SECRETS)
Lorenzo Stoakes (ARM)
- [PATCH v2 3/8] mm/ksm: convert process iterator to for_each_process_rculock
David Hildenbrand (Arm)
- [PATCH v3 00/12] CRASH_MEMACTION: describe pages to a kdump kernel (was: CRASH_WIPE_SECRETS)
David Hildenbrand (Arm)
- [PATCH v3 00/12] CRASH_MEMACTION: describe pages to a kdump kernel (was: CRASH_WIPE_SECRETS)
David Hildenbrand (Arm)
- [BUG] general protection fault in security_path_post_mknod
Farhad Alemi
- [PATCH] apparmor: lift path_name lookup in umount
Murilo Duarte M de Almeida
- [PATCH] Kconfig: purge twenty-nine legacy ghost options
Breno Rodrigues Alves
- [PATCH v2] Kconfig: purge twenty-eight legacy ghost options (v2)
Breno Rodrigues Alves
- [PATCH v3] Kconfig: fix typos in core makefiles/code and purge remaining ghosts (v3)
Breno Rodrigues Alves
- [PATCH v4] Kconfig: fix typos in core makefiles/code and purge remaining ghosts (v4)
Breno Rodrigues Alves
- [PATCH v5] Kconfig: fix typos in core makefiles and purge defective DVB debug (v5)
Breno Rodrigues Alves
- [PATCH v6 1/4] interconnect: mediatek: fix Makefile typo for mt8196
Breno Rodrigues Alves
- [PATCH v6 2/4] regulator: mtk-spmi: fix Makefile typo for mt6316
Breno Rodrigues Alves
- [PATCH v6 3/4] media: dvb-core: remove defective and unsafe ULE debug block
Breno Rodrigues Alves
- [PATCH v6 4/4] tree-wide: purge verified remaining legacy ghost options
Breno Rodrigues Alves
- [PATCH v7 1/3] interconnect: mediatek: fix Makefile typo for mt8196
Breno Rodrigues Alves
- [PATCH v7 2/3] regulator: mtk-spmi: fix Makefile typo for mt6316
Breno Rodrigues Alves
- [PATCH v7 3/3] media: dvb-core: extirpate defective and unsafe ULE debug block
Breno Rodrigues Alves
- [PATCH v8 1/3] interconnect: mediatek: fix Makefile typo for mt8196
Breno Rodrigues Alves
- [PATCH v8 2/3] regulator: mtk-spmi: fix Makefile typo for mt6316
Breno Rodrigues Alves
- [PATCH v8 3/3] media: dvb-core: extirpate defective and unsafe ULE debug block
Breno Rodrigues Alves
- [PATCH v9 1/3] interconnect: mediatek: fix Makefile typo for mt8196
Breno Rodrigues Alves
- [PATCH v9 2/3] regulator: mtk-spmi: fix Makefile typo for mt6316
Breno Rodrigues Alves
- [PATCH v9 3/3] media: dvb-core: extirpate defective and unsafe ULE debug block
Breno Rodrigues Alves
- [PATCH v10] media: dvb-core: extirpate defective and unsafe ULE debug block
Breno Rodrigues Alves
- [PATCH v11 1/3] interconnect: mediatek: fix Makefile typo for mt8196
Breno Rodrigues Alves
- [PATCH v11 2/3] regulator: mtk-spmi: fix Makefile typo for mt6316
Breno Rodrigues Alves
- [PATCH v11 3/3] media: dvb-core: extirpate defective and unsafe ULE debug block
Breno Rodrigues Alves
- [PATCH] media: dvb-core: purge unsafe ULE debug and fix pre-existing vulnerabilities
Breno Rodrigues Alves
- [PATCH v2] media: dvb-core: extirpate defective and unsafe ULE debug block
Breno Rodrigues Alves
- Request to withdraw all current and past patch submissions
Breno Rodrigues Alves
- [PATCH] Kconfig: purge twenty-nine legacy ghost options
Arnd Bergmann
- [PATCH] [v2] landlock: work around gcc-16 -Wuninitialized warning
Arnd Bergmann
- [PATCH] [v2] landlock: work around gcc-16 -Wuninitialized warning
Arnd Bergmann
- [PATCH] [v2] landlock: work around gcc-16 -Wuninitialized warning
Arnd Bergmann
- [PATCH] [v2] landlock: work around gcc-16 -Wuninitialized warning
Arnd Bergmann
- [PATCH v3 2/2] selftests/bpf: verify mount idmaps reach inode hooks
Matt Bobrowski
- [PATCH v3 2/2] selftests/bpf: verify mount idmaps reach inode hooks
Matt Bobrowski
- [PATCH] apparmor: fix NULL ctx->peer derefs in unix socket ctx updates
Salvatore Bonaccorso
- [PATCH bpf-next 4/8] bpf, lsm: Let BPF LSM provide xattrs at inode creation
Daniel Borkmann
- [PATCH] apparmor: handle NULL peer label in AF_UNIX context updates
Maciek Borzecki
- [PATCH] ima: allow users to specify the pcr index with IMA_MEASURE_PCR_IDX
Julian Braha
- [PATCH v2] ima: allow users to specify the pcr index with IMA_MEASURE_PCR_IDX
Julian Braha
- [PATCH 00/27] fs: port to const struct mnt_idmap
Christian Brauner
- [PATCH 01/27] userns: pass const uid_gid_map in lookup helpers
Christian Brauner
- [PATCH 02/27] fs: port mnt_idmap_{get,put}() to const mnt_idmap
Christian Brauner
- [PATCH 03/27] fs: port vfs{g,u}id helpers to const mnt_idmap
Christian Brauner
- [PATCH 04/27] fs: port fs{g,u}id helpers to const mnt_idmap
Christian Brauner
- [PATCH 05/27] fs: port i_{g,u}id_into_vfs{g,u}id() to const mnt_idmap
Christian Brauner
- [PATCH 06/27] fs: port i_{g,u}id_{needs_}update() to const mnt_idmap
Christian Brauner
- [PATCH 07/27] quota: port to const mnt_idmap
Christian Brauner
- [PATCH 08/27] fs: port privilege checking helpers to const mnt_idmap
Christian Brauner
- [PATCH 09/27] fs: port inode_owner_or_capable() to const mnt_idmap
Christian Brauner
- [PATCH 10/27] fs: port inode_init_owner() to const mnt_idmap
Christian Brauner
- [PATCH 11/27] fs: port acl to const mnt_idmap
Christian Brauner
- [PATCH 12/27] fs: port ->permission() to pass const mnt_idmap
Christian Brauner
- [PATCH 13/27] fs: port xattr to const mnt_idmap
Christian Brauner
- [PATCH 14/27] fs: port ->fileattr_set() to pass const mnt_idmap
Christian Brauner
- [PATCH 15/27] fs: port ->set_acl() to pass const mnt_idmap
Christian Brauner
- [PATCH 16/27] fs: port ->get_acl() to pass const mnt_idmap
Christian Brauner
- [PATCH 17/27] fs: port ->tmpfile() to pass const mnt_idmap
Christian Brauner
- [PATCH 18/27] fs: port ->mknod() to pass const mnt_idmap
Christian Brauner
- [PATCH 19/27] fs: port ->rename() to pass const mnt_idmap
Christian Brauner
- [PATCH 20/27] fs: port ->mkdir() to pass const mnt_idmap
Christian Brauner
- [PATCH 21/27] fs: port ->symlink() to pass const mnt_idmap
Christian Brauner
- [PATCH 22/27] fs: port ->create() to pass const mnt_idmap
Christian Brauner
- [PATCH 23/27] fs: port ->getattr() to pass const mnt_idmap
Christian Brauner
- [PATCH 24/27] fs: port ->setattr() to pass const mnt_idmap
Christian Brauner
- [PATCH 25/27] fs: port vfs_*() helpers to const mnt_idmap
Christian Brauner
- [PATCH 26/27] fs: port mnt_idmap() and file_mnt_idmap() to const mnt_idmap
Christian Brauner
- [PATCH 27/27] fs: make nop_mnt_idmap and invalid_mnt_idmap const
Christian Brauner
- [PATCH 0/2] lsm: expose mount idmaps to inode hooks
Christian Brauner
- [PATCH v2 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Christian Brauner
- [PATCH v2] lsm: expose mount idmaps to inode hooks
Christian Brauner
- [PATCH v3 0/2] lsm: expose mount idmaps to inode hooks
Christian Brauner
- [PATCH v3 0/3] proc,security,selinux: let SELinux block FOLL_FORCE for /proc/self/mem
Christian Brauner
- [PATCH 0/3] keys: Add well known IDs for fs-verity/dm-verity keys
Christian Brauner
- LSM boundaries. Was: [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Christian Brauner
- LSM boundaries. Was: [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Christian Brauner
- [PATCH v3 0/3] proc,security,selinux: let SELinux block FOLL_FORCE for /proc/self/mem
Christian Brauner
- [PATCH] lsm: initialize the security blob for the initial namespaces
Christian Brauner
- [PATCH v3] lsm,nscommon: initialize the security blob for the initial namespaces
Christian Brauner
- [PATCH v2 0/3] pidfd: add task path ioctls
Christian Brauner
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Christian Brauner
- [PATCH v6 0/8] lsm: Replace security_sb_mount with granular mount hooks
Christian Brauner
- [PATCH v3 1/2] integrity: Report error code in integrity_audit_msg() call sites
Enrico Bravi
- Re: [PATCH v3 1/2] integrity: Report error code in integrity_audit_msg() call sites
Enrico Bravi
- Re: [PATCH v4 1/2] integrity: Report error code in integrity_audit_msg() call sites
Enrico Bravi
- [PATCH v4] hardening: Default randstruct off with rust for better allmodconfig support
Mark Brown
- [PATCH] tomoyo: Enforce connect policy in TCP Fast Open
Matthieu Buffet
- [PATCH] apparmor: convert duplicated dfa transitions to match_char()
Maxime Bélair
- [PATCH] apparmor: fix table_size() integer overflow on 32 bit
Maxime Bélair
- [PATCH] apparmor: dedup perms entries when mapping older policy
Maxime Bélair
- [PATCH v5] Kconfig: fix typos in core makefiles and purge defective DVB debug (v5)
Dan Carpenter
- [PATCH v9 1/3] interconnect: mediatek: fix Makefile typo for mt8196
Dan Carpenter
- [RFC PATCH 00/24] pidfd: add a minimal process spawn builder
Li Chen
- [PATCH v4] hardening: Default randstruct off with rust for better allmodconfig support
Kees Cook
- [PATCH v4] hardening: Default randstruct off with rust for better allmodconfig support
Kees Cook
- [PATCH 1/7] seq_buf: Do not pop from an overflowed seq_buf
Kees Cook
- [PATCH v2 2/9] seq_buf: Do not pop from an overflowed seq_buf
Kees Cook
- [PATCH v3 02/11] seq_buf: Do not pop from an overflowed seq_buf
Kees Cook
- [PATCH] security: commoncap: clarify CAP_FS_SET comment in cap_task_fix_setuid()
Adriano Cordova
- [PATCH v2] security: commoncap: clarify CAP_FS_SET comment in cap_task_fix_setuid()
Adriano Cordova
- [PATCH] apparmor: resolve pivotroot paths before the failure audit
Adriano Cordova
- [PATCH] smackfs: reject out-of-range IPv4 octets in netlabel writes
Hongjian Dai
- [PATCH] smackfs: fix IPv6 netlabel prefix mask for non-16-aligned lengths
Hongjian Dai
- [PATCH security v1] apparmor: fix a use-after-free in aa_lookupn_ns()
Binbin Deng
- [PATCH security v1] apparmor: fix a use-after-free in aa_lookupn_ns()
Binbin Deng
- [PATCH v3] ipe: fix invalid sgid value in audit event documentation
Randy Dunlap
- [PATCH v3 12/12] kexec: Expose the crash memaction bitmap in debugfs
Randy Dunlap
- [Resend PATCH v2] ipe: fix typo
Manuel Ebner
- [PATCH v3] ipe: fix invalid sgid value in audit event documentation
Manuel Ebner
- [PATCH v3 1/3] umh, treewide: Explicitly include linux/umh.h where needed
Alex Elder
- [PATCH 00/27] fs: port to const struct mnt_idmap
Seth Forshee
- [PATCH] KEYS: trusted: Fix tpm2_load_cmd() boundary check
Stefano Garzarella
- [PATCH] KEYS: trusted: Fix tpm2_load_cmd() boundary check
Stefano Garzarella
- [PATCH] KEYS: trusted: Fix blob allocation size in tpm2_key_decode()
Stefano Garzarella
- [PATCH] MAINTAINERS: name the wufan/ipe next branch
Matthias Goergens
- [PATCH] MAINTAINERS: name the mic/linux next branch
Matthias Goergens
- [PATCH RFC -next 03/12] fs: pass struct path to xattr helpers
Amir Goldstein
- LSM boundaries. Was: [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Dr. Greg
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Dr. Greg
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Dr. Greg
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Dr. Greg
- [apparmor] [PATCH] apparmor: fix NULL ctx->peer derefs in unix socket ctx updates
Fabian Grünbichler
- [PATCH] apparmor: handle NULL peer label in AF_UNIX context updates
Fabian Grünbichler
- [PATCH v20 4/8] rust: page: convert to `Ownable`'
Gary Guo
- [PATCH v21 4/9] rust: rename `AlwaysRefCounted` to `RefCounted`.
Gary Guo
- [PATCH v3 00/12] CRASH_MEMACTION: describe pages to a kdump kernel (was: CRASH_WIPE_SECRETS)
Jan Sebastian Götte
- [PATCH v3 01/12] kexec: Add a crash memaction registry
Jan Sebastian Götte
- [PATCH v3 02/12] lib, kexec: Add a secret pool for key material
Jan Sebastian Götte
- [PATCH v3 03/12] mm: Wire up the crash memaction registry
Jan Sebastian Götte
- [PATCH v3 04/12] arm64: Enable the crash memaction registry
Jan Sebastian Götte
- [PATCH v3 05/12] dm crypt: Allocate key material from the secret pool
Jan Sebastian Götte
- [PATCH v3 06/12] crypto: api - Allocate tfms from the secret pool
Jan Sebastian Götte
- [PATCH v3 07/12] security/keys: Allocate key payloads from the secret pool
Jan Sebastian Götte
- [PATCH v3 08/12] mm: Add VM_CRASH_MARK
Jan Sebastian Götte
- [PATCH v3 09/12] mm/rmap: Mark folios mapped into crash_memaction-marked VMAs
Jan Sebastian Götte
- [PATCH v3 10/12] mm/madvise: Add MADV_CRASH_SECRET, MADV_CRASH_CACHE and MADV_CRASH_RESET
Jan Sebastian Götte
- [PATCH v3 11/12] Documentation/mm: Document the crash memaction registry
Jan Sebastian Götte
- [PATCH v3 12/12] kexec: Expose the crash memaction bitmap in debugfs
Jan Sebastian Götte
- [PATCH 0/3] keys: Add well known IDs for fs-verity/dm-verity keys
Andrew Halaney
- [PATCH 1/3] keys: add KEY_SPEC_DM_VERITY_KEYRING
Andrew Halaney
- [PATCH 2/3] keys: add KEY_SPEC_FS_VERITY_KEYRING
Andrew Halaney
- [PATCH 3/3] Documentation: keys: document IDs added since KEY_SPEC_REQKEY_AUTH_KEY
Andrew Halaney
- [PATCH 1/3] keys: add KEY_SPEC_DM_VERITY_KEYRING
Andrew Halaney
- [PATCH v3 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Serge E. Hallyn
- [PATCH v3 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Serge E. Hallyn
- [PATCH] security: commoncap: clarify CAP_FS_SET comment in cap_task_fix_setuid()
Serge E. Hallyn
- [RFC PATCH] security: Allow dropping bounding set process-wide
Serge E. Hallyn
- [PATCH v2] security: commoncap: clarify CAP_FS_SET comment in cap_task_fix_setuid()
Serge E. Hallyn
- [RFC] Proposal for a standard Competitive / Protected Session API in Linux
Serge E. Hallyn
- [RFC PATCH] security: Allow dropping bounding set process-wide
Serge E. Hallyn
- [RFC PATCH] security: Allow dropping bounding set process-wide
Serge E. Hallyn
- [RFC PATCH] security: Allow dropping bounding set process-wide
Serge E. Hallyn
- [RFC PATCH] security: Allow dropping bounding set process-wide
Serge E. Hallyn
- [PATCH v20 4/8] rust: page: convert to `Ownable`'
Andreas Hindborg
- [PATCH v20 4/8] rust: page: convert to `Ownable`'
Andreas Hindborg
- [PATCH v20 4/8] rust: page: convert to `Ownable`'
Andreas Hindborg
- [PATCH v20 4/8] rust: page: convert to `Ownable`'
Andreas Hindborg
- [PATCH v21 0/9] rust: add `Ownable` trait and `Owned` type
Andreas Hindborg
- [PATCH v21 1/9] rust: alloc: add `KBox::into_non_null`
Andreas Hindborg
- [PATCH v21 2/9] rust: types: Add Ownable/Owned types
Andreas Hindborg
- [PATCH v21 3/9] rust: implement `ForeignOwnable` for `Owned`
Andreas Hindborg
- [PATCH v21 4/9] rust: rename `AlwaysRefCounted` to `RefCounted`.
Andreas Hindborg
- [PATCH v21 5/9] rust: Add missing SAFETY documentation for `ARef` example
Andreas Hindborg
- [PATCH v21 6/9] rust: Add `OwnableRefCounted`
Andreas Hindborg
- [PATCH v21 7/9] rust: page: convert to `AlwaysRefCounted`
Andreas Hindborg
- [PATCH v21 8/9] rust: page: add `from_raw()`
Andreas Hindborg
- [PATCH v21 9/9] rust: page: add `ExclusivePage` for race-free page access
Andreas Hindborg
- [PATCH v21 6/9] rust: Add `OwnableRefCounted`
Andreas Hindborg
- [PATCH v21 9/9] rust: page: add `ExclusivePage` for race-free page access
Andreas Hindborg
- [PATCH v21 4/9] rust: rename `AlwaysRefCounted` to `RefCounted`.
Andreas Hindborg
- [PATCH v3 0/3] proc,security,selinux: let SELinux block FOLL_FORCE for /proc/self/mem
Jann Horn
- [PATCH v3 1/3] proc: refactor /proc/$pid/mem to use struct as private_data
Jann Horn
- [PATCH v3 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH v3 3/3] selinux: require PROCESS__PTRACE for FOLL_FORCE introspection
Jann Horn
- [PATCH v3 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Jann Horn
- [PATCH v3 0/3] proc,security,selinux: let SELinux block FOLL_FORCE for /proc/self/mem
Jann Horn
- [PATCH v2 1/3] fs: Introduce task path helpers
Jann Horn
- [PATCH v2 0/3] pidfd: add task path ioctls
Jann Horn
- [PATCH v2 0/3] pidfd: add task path ioctls
Jann Horn
- [PATCH 1/3] keys: add KEY_SPEC_DM_VERITY_KEYRING
David Howells
- [PATCH v2 09/13] security: keys: trusted: always clear the hmac_sha1_ctx before returning
Thomas Huth
- [PATCH v3 09/13] security: keys: trusted: always clear the hmac_sha1_ctx before returning
Thomas Huth
- [PATCH v4 09/13] security: keys: trusted: always clear the hmac_sha1_ctx before returning
Thomas Huth
- [PATCH] security: keys: Fix comment of search_process_keyrings_rcu()
Thomas Huth
- [PATCH] apparmor: handle NULL peer label in AF_UNIX context updates
Aurelien Jarno
- [PATCH v2] ima: discard modsig on detached-data binding failure
Jérémy Jean
- [PATCH] apparmor: check connect permission for SCTP
Jérémy Jean
- [PATCH v2 0/2] apparmor: check connect permission for SCTP
Jérémy Jean
- [PATCH v2 1/2] apparmor: check connect permission for SCTP
Jérémy Jean
- [PATCH v2 2/2] tests: add SCTP connect mediation regression test
Jérémy Jean
- [PATCH] lsm: remove redundant NULL check in security_init()
Sang-Heon Jeon
- [PATCH v2 1/7] net, smack: Create a function to set secmarks
John Johansen
- [PATCH v2 2/7] LSM: Implement x array functions for secmarks
John Johansen
- [PATCH v2 4/7] SELinux: hooks for secctx_to_lsmprop and update_lsmprop
John Johansen
- [PATCH v2 5/7] Smack: hooks for secctx_to_lsmprop and update_lsmprop
John Johansen
- [PATCH v2 7/7] net, lsm: Change skb secmarks to x-array indexes
John Johansen
- [PATCH v2 6/7] Apparmor: hooks for secctx_to_lsmprop and update_lsmprop
John Johansen
- [PATCH v2 3/7] LSM: Two hooks for manipulating struct lsm_prop
John Johansen
- [PATCH] apparmor: Fix label reference leak in aa_unix_file_perm()
John Johansen
- [PATCH] apparmor: Fix label reference leak in aa_unix_file_perm()
John Johansen
- [PATCH] Kconfig: purge twenty-nine legacy ghost options
Greg KH
- [PATCH] apparmor: Fix label reference leak in aa_unix_file_perm()
Greg KH
- [PATCH 01/27] userns: pass const uid_gid_map in lookup helpers
Jan Kara
- [PATCH 02/27] fs: port mnt_idmap_{get,put}() to const mnt_idmap
Jan Kara
- [PATCH 03/27] fs: port vfs{g,u}id helpers to const mnt_idmap
Jan Kara
- [PATCH 04/27] fs: port fs{g,u}id helpers to const mnt_idmap
Jan Kara
- [PATCH 05/27] fs: port i_{g,u}id_into_vfs{g,u}id() to const mnt_idmap
Jan Kara
- [PATCH 06/27] fs: port i_{g,u}id_{needs_}update() to const mnt_idmap
Jan Kara
- [PATCH 07/27] quota: port to const mnt_idmap
Jan Kara
- [PATCH 08/27] fs: port privilege checking helpers to const mnt_idmap
Jan Kara
- [PATCH 09/27] fs: port inode_owner_or_capable() to const mnt_idmap
Jan Kara
- [PATCH 10/27] fs: port inode_init_owner() to const mnt_idmap
Jan Kara
- [PATCH 11/27] fs: port acl to const mnt_idmap
Jan Kara
- [PATCH 12/27] fs: port ->permission() to pass const mnt_idmap
Jan Kara
- [PATCH 13/27] fs: port xattr to const mnt_idmap
Jan Kara
- [PATCH 14/27] fs: port ->fileattr_set() to pass const mnt_idmap
Jan Kara
- [PATCH 15/27] fs: port ->set_acl() to pass const mnt_idmap
Jan Kara
- [PATCH 16/27] fs: port ->get_acl() to pass const mnt_idmap
Jan Kara
- [PATCH 17/27] fs: port ->tmpfile() to pass const mnt_idmap
Jan Kara
- [PATCH 18/27] fs: port ->mknod() to pass const mnt_idmap
Jan Kara
- [PATCH 19/27] fs: port ->rename() to pass const mnt_idmap
Jan Kara
- [PATCH 20/27] fs: port ->mkdir() to pass const mnt_idmap
Jan Kara
- [PATCH 21/27] fs: port ->symlink() to pass const mnt_idmap
Jan Kara
- [PATCH 22/27] fs: port ->create() to pass const mnt_idmap
Jan Kara
- [PATCH 23/27] fs: port ->getattr() to pass const mnt_idmap
Jan Kara
- [PATCH 24/27] fs: port ->setattr() to pass const mnt_idmap
Jan Kara
- [PATCH 25/27] fs: port vfs_*() helpers to const mnt_idmap
Jan Kara
- [PATCH 26/27] fs: port mnt_idmap() and file_mnt_idmap() to const mnt_idmap
Jan Kara
- [PATCH 27/27] fs: make nop_mnt_idmap and invalid_mnt_idmap const
Jan Kara
- [PATCH 0/7] fs: preserve superblock inode walk positions across lock drops
Jan Kara
- [PATCH 1/7] fs: remove trailing whitespace from include/linux/fs.h
Jan Kara
- [PATCH 2/7] fs: introduce sb_for_each_inodes().
Jan Kara
- [PATCH 0/6] landlock: Add POSIX message queue scoping
Oxana Kharitonova
- [PATCH 0/6] landlock: Add POSIX message queue scoping
Oxana Kharitonova
- [PATCH bpf-next 0/7] Add new way to add BPF LSM hooks
Jakub Kicinski
- [PATCH] KEYS: trusted: Reject short TPM2 public areas
Daehyeon Ko
- [PATCH net] cipso: adjust cached option offsets when removing CIPSO
Daehyeon Ko
- [PATCH v2] certs: x509: duplicate cert->tbs when sig->algo_takes_data is set
Ignat Korchagin
- [PATCH] selftests: binderfs: skip the stress test without binderfs
Eva Kurchatova
- [PATCH v2] KEYS: encrypted: fix integer overflow of datablob_len
Cen Zhang (Microsoft Security FORGE Labs)
- [PATCH v2 0/3] integrity: Return error codes in audit messages
Frederick Lawler
- [PATCH v2 1/3] integrity: Replace all uses of integrity_audit_msg() with integrity_audit_message()
Frederick Lawler
- [PATCH v3 0/2] integrity: Return error codes in audit messages
Frederick Lawler
- [PATCH v3 1/2] integrity: Report error code in integrity_audit_msg() call sites
Frederick Lawler
- [PATCH v3 2/2] integrity: Replace integrity_audit_message() with integrity_audit_msg()
Frederick Lawler
- [PATCH v3 1/2] integrity: Report error code in integrity_audit_msg() call sites
Frederick Lawler
- [PATCH v4 0/2] integrity: Return error codes in audit messages
Frederick Lawler
- [PATCH v4 1/2] integrity: Report error code in integrity_audit_msg() call sites
Frederick Lawler
- [PATCH v4 2/2] integrity: Replace integrity_audit_message() with integrity_audit_msg()
Frederick Lawler
- [PATCH] apparmor: Fix label reference leak in aa_unix_file_perm()
Ryan Lee
- [PATCH] apparmor: check connect permission for SCTP
Ryan Lee
- [PATCH 5.15.y 1/2] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Sasha Levin
- [PATCH 5.15.y 2/2] selftests/landlock: Add tests for whiteout object creation
Sasha Levin
- [PATCH 5.15.y 2/2] selftests/landlock: Add tests for whiteout object creation
Sasha Levin
- [PATCH 5.15.y v2] selftests/landlock: Add tests for whiteout object creation
Sasha Levin
- [PATCH] apparmor: Fix label reference leak in aa_unix_file_perm()
Wentao Liang
- [PATCH] apparmor: Fix namespace reference leak in __aa_find_or_create_ns()
Wentao Liang
- [REGRESSION] apparmor: AF_UNIX datagram send slowdown after 6456ccbd2ff7
Chengfeng Lin
- [PATCH v2 0/3] pidfd: add task path ioctls
Chen Linxuan
- [PATCH v2 0/3] pidfd: add task path ioctls
Chen Linxuan
- [PATCH v2 0/3] pidfd: add task path ioctls
Chen Linxuan
- [PATCH v2 1/3] fs: Introduce task path helpers
Chen Linxuan
- [PATCH v2 0/3] pidfd: add task path ioctls
Chen Linxuan
- [PATCH v6 0/8] lsm: Replace security_sb_mount with granular mount hooks
Song Liu
- [PATCH v6 0/8] lsm: Replace security_sb_mount with granular mount hooks
Song Liu
- [PATCH v6 0/8] lsm: Replace security_sb_mount with granular mount hooks
Song Liu
- [PATCH 0/8] mm: introduce for_each_process_rcu and for_each_thread_rcu
Ye Liu
- [PATCH 8/8] security/landlock: convert thread iterator to for_each_thread_rcu
Ye Liu
- [PATCH v2 0/8] sched: introduce for_each_process_rculock and for_each_thread_rculock
Ye Liu
- [PATCH v2 1/8] sched: introduce for_each_process_rculock and for_each_thread_rculock
Ye Liu
- [PATCH v2 2/8] mm/oom_kill: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v2 3/8] mm/ksm: convert process iterator to for_each_process_rculock
Ye Liu
- [PATCH v2 4/8] mm/memory-failure: convert process iterator to for_each_process_rculock
Ye Liu
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v2 6/8] fs: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v2 7/8] lib: convert process iterator to for_each_process_rculock
Ye Liu
- [PATCH v2 8/8] security/landlock: convert thread iterator to for_each_thread_rculock
Ye Liu
- [PATCH v3 00/15] sched: introduce for_each_process_rculock and for_each_thread_rculock
Ye Liu
- [PATCH v3 01/15] sched: introduce for_each_process_rculock and for_each_thread_rculock
Ye Liu
- [PATCH v3 02/15] mm/oom_kill: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v3 03/15] mm/ksm: convert process iterator to for_each_process_rculock
Ye Liu
- [PATCH v3 04/15] mm/memory-failure: convert process iterator to for_each_process_rculock
Ye Liu
- [PATCH v3 05/15] cpu/hotplug: convert thread iterator to for_each_thread_rculock
Ye Liu
- [PATCH v3 06/15] freezer: convert thread iterator to for_each_thread_rculock
Ye Liu
- [PATCH v3 07/15] hung_task: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v3 08/15] locking/lockdep: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v3 09/15] rcu: convert process/thread iterator to for_each_process_thread_rculock
Ye Liu
- [PATCH v3 10/15] sched: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v3 11/15] tracing/fgraph: convert process/thread iterator to for_each_process_thread_rculock
Ye Liu
- [PATCH v3 12/15] unwind: convert process/thread iterator to for_each_process_thread_rculock
Ye Liu
- [PATCH v3 13/15] fs: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v3 14/15] lib: convert process iterator to for_each_process_rculock
Ye Liu
- [PATCH v3 15/15] security/landlock: convert thread iterator to for_each_thread_rculock
Ye Liu
- [PATCH v4 00/15] sched: introduce for_each_process_rculock and for_each_thread_rculock
Ye Liu
- [PATCH v4 01/15] sched: introduce for_each_process_rculock and for_each_thread_rculock
Ye Liu
- [PATCH v4 02/15] mm/oom_kill: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v4 03/15] mm/ksm: convert process iterator to for_each_process_rculock
Ye Liu
- [PATCH v4 04/15] mm/memory-failure: convert process iterator to for_each_process_rculock
Ye Liu
- [PATCH v4 05/15] cpu/hotplug: convert process iterator to for_each_process_rculock
Ye Liu
- [PATCH v4 06/15] freezer: convert thread iterator to for_each_thread_rculock
Ye Liu
- [PATCH v4 07/15] hung_task: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v4 08/15] locking/lockdep: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v4 09/15] rcu: convert process/thread iterator to for_each_process_thread_rculock
Ye Liu
- [PATCH v4 10/15] sched: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v4 11/15] tracing/fgraph: convert process/thread iterator to for_each_process_thread_rculock
Ye Liu
- [PATCH v4 12/15] unwind: convert process/thread iterator to for_each_process_thread_rculock
Ye Liu
- [PATCH v4 13/15] fs: convert process/thread iterators to for_each_*_rculock
Ye Liu
- [PATCH v4 14/15] lib: convert process iterator to for_each_process_rculock
Ye Liu
- [PATCH v4 15/15] security/landlock: convert thread iterator to for_each_thread_rculock
Ye Liu
- [RFC PATCH 0/2] Landlock signal scope and TIOCSIG
Christopher Lusk
- [RFC PATCH 1/2] tty: mediate TIOCSIG through task_kill LSM hooks
Christopher Lusk
- [RFC PATCH 2/2] selftests/landlock: cover TIOCSIG signal scoping
Christopher Lusk
- [RFC PATCH 1/2] tty: mediate TIOCSIG through task_kill LSM hooks
Christopher Lusk
- [RFC PATCH 0/2] Landlock signal scope and TIOCSIG
Christopher Lusk
- [PATCH] docs: landlock: clarify TTY signal scoping
Christopher Lusk
- [PATCH] docs: landlock: clarify TTY signal scoping
Christopher Lusk
- [PATCH v2] docs: landlock: clarify TTY signal scoping
Christopher Lusk
- [PATCH v3 0/2] landlock: clarify TTY signal scoping
Christopher Lusk
- [PATCH v3 1/2] docs: landlock: clarify TTY signal scoping
Christopher Lusk
- [PATCH v3 2/2] selftests/landlock: cover TTY signal scoping
Christopher Lusk
- [PATCH 15/16 net-next v2] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency
Fernando Fernandez Mancera
- [PATCH 15/16 net-next v3] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency
Fernando Fernandez Mancera
- [PATCH v2 0/7] fs/9p: Reuse inode based on path (in addition to qid)
Dominique Martinet
- [PATCH v4 09/15] rcu: convert process/thread iterator to for_each_process_thread_rculock
Paul E. McKenney
- [PATCH] keys: set persistent keyring timeout before destination linking
Karl Mehltretter
- [PATCH v2] keys: finalize persistent keyring timeout after link attempt
Karl Mehltretter
- [PATCH v3] keys: finalize persistent keyring timeout after link attempt
Karl Mehltretter
- [PATCH v3] keys: finalize persistent keyring timeout after link attempt
Karl Mehltretter
- [PATCH] apparmor: Fix the return value in split_token_from_name() kernel-doc
Karl Mehltretter
- [PATCH v4] keys: finalize persistent keyring timeout after link attempt
Karl Mehltretter
- [PATCH v3 1/2] lsm: expose mount idmaps to inode hooks
Daan De Meyer
- [PATCH bpf-next 1/7] bpf: Allow BPF LSM programs to attach to more hooks
Paul Moore
- [PATCH 11/27] fs: port acl to const mnt_idmap
Paul Moore
- [PATCH 12/27] fs: port ->permission() to pass const mnt_idmap
Paul Moore
- [PATCH 13/27] fs: port xattr to const mnt_idmap
Paul Moore
- [PATCH 17/27] fs: port ->tmpfile() to pass const mnt_idmap
Paul Moore
- [PATCH 18/27] fs: port ->mknod() to pass const mnt_idmap
Paul Moore
- [PATCH 24/27] fs: port ->setattr() to pass const mnt_idmap
Paul Moore
- [PATCH bpf-next 1/7] bpf: Allow BPF LSM programs to attach to more hooks
Paul Moore
- Re: [PATCH] MAINTAINERS, mailmap: update email address for Ondrej Mosnáček
Paul Moore
- [PATCH] MAINTAINERS, mailmap: update email address for Ondrej MosnáÄek
Paul Moore
- [GIT PULL] selinux/selinux-pr-20260903
Paul Moore
- [PATCH v3 0/2] lsm: expose mount idmaps to inode hooks
Paul Moore
- [PATCH v3 1/2] lsm: expose mount idmaps to inode hooks
Paul Moore
- [PATCH v3 2/2] selftests/bpf: verify mount idmaps reach inode hooks
Paul Moore
- [PATCH v3 3/12] security: Add LSM_AUDIT_DATA_NS for namespace audit records
Paul Moore
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Paul Moore
- [PATCH v2] cred: prevent slab cache merging for cred_jar
Paul Moore
- [PATCH] rust: security: replace `core::mem::zeroed` with `pin_init::zeroed`
Paul Moore
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Paul Moore
- [PATCH] rust: security: replace `core::mem::zeroed` with `pin_init::zeroed`
Paul Moore
- [PATCH] rust: security: replace `core::mem::zeroed` with `pin_init::zeroed`
Paul Moore
- [PATCH 2/2] lsm: fix size queries for getselfattr with NULL buffer
Paul Moore
- [PATCH v3 3/12] security: Add LSM_AUDIT_DATA_NS for namespace audit records
Paul Moore
- [PATCH v3 1/2] lsm: expose mount idmaps to inode hooks
Paul Moore
- [PATCH v3 1/2] lsm: expose mount idmaps to inode hooks
Paul Moore
- [PATCH v3 2/2] selftests/bpf: verify mount idmaps reach inode hooks
Paul Moore
- [PATCH v3 2/2] selftests/bpf: verify mount idmaps reach inode hooks
Paul Moore
- [PATCH 1/2] doc: LSM: describe CONFIG_LSM and lsm= as the selection mechanism
Paul Moore
- [PATCH 2/2] doc: LSM: fix module ordering description for /sys/kernel/security/lsm
Paul Moore
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Paul Moore
- LSM boundaries. Was: [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Paul Moore
- [PATCH v3 0/3] proc,security,selinux: let SELinux block FOLL_FORCE for /proc/self/mem
Paul Moore
- [PATCH v1 1/2] lsm: Preserve full ioctl commands in audit records
Paul Moore
- [PATCH v1 2/2] selftests/landlock: Check full ioctl commands in audit records
Paul Moore
- LSM boundaries. Was: [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Paul Moore
- [PATCH v3 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Paul Moore
- [PATCH] netlabel: calipso, x509: clean up ADDRSELECT on DOI removal and check AKID len
Paul Moore
- [PATCH] netlabel: cipso_v4: reject empty MLS level/cat lists and zero tail in cipso_v4_delopt()
Paul Moore
- [PATCH] ipv6: calipso: fix 8-bit hdrlen overflow and missing pskb_may_pull() in hop-by-hop options
Paul Moore
- [GIT PULL] selinux/selinux-pr-20260919
Paul Moore
- [PATCH v3 0/3] proc,security,selinux: let SELinux block FOLL_FORCE for /proc/self/mem
Paul Moore
- LSM boundaries. Was: [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Paul Moore
- [PATCH bpf-next 4/8] bpf, lsm: Let BPF LSM provide xattrs at inode creation
Paul Moore
- [PATCH bpf-next 4/8] bpf, lsm: Let BPF LSM provide xattrs at inode creation
Paul Moore
- [PATCH bpf-next 4/8] bpf, lsm: Let BPF LSM provide xattrs at inode creation
Paul Moore
- [PATCH bpf-next 4/8] bpf, lsm: Let BPF LSM provide xattrs at inode creation
Paul Moore
- [PATCH bpf-next 4/8] bpf, lsm: Let BPF LSM provide xattrs at inode creation
Paul Moore
- [PATCH bpf-next 4/8] bpf, lsm: Let BPF LSM provide xattrs at inode creation
Paul Moore
- [PATCH bpf-next 4/8] bpf, lsm: Let BPF LSM provide xattrs at inode creation
Paul Moore
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Paul Moore
- [PATCH v6 0/8] lsm: Replace security_sb_mount with granular mount hooks
Paul Moore
- [PATCH v6 0/8] lsm: Replace security_sb_mount with granular mount hooks
Paul Moore
- [PATCH v6 0/8] lsm: Replace security_sb_mount with granular mount hooks
Paul Moore
- [PATCH 15/16 net-next v2] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency
Paul Moore
- [PATCH] lsm: remove redundant NULL check in security_init()
Paul Moore
- [PATCH v3] lsm,nscommon: initialize the security blob for the initial namespaces
Paul Moore
- [PATCH v6 0/8] lsm: Replace security_sb_mount with granular mount hooks
Paul Moore
- [RFC PATCH] security: Allow dropping bounding set process-wide
Andrew G. Morgan
- [RFC PATCH] security: Allow dropping bounding set process-wide
Andrew G. Morgan
- [RFC PATCH] security: Allow dropping bounding set process-wide
Andrew G. Morgan
- Re: [PATCH] ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()
Bradley Morgan
- [RFC PATCH v2 1/3] capability: Move mk_kernel_cap() to header
Bradley Morgan
- Heads up: Moving to a different email address for my Linux kernel/SELinux contributions
Ondrej Mosnacek
- Heads up: Moving to a different email address for my Linux kernel/SELinux contributions
Ondrej Mosnáček
- [PATCH] MAINTAINERS, mailmap: update email address for Ondrej Mosnáček
Ondrej Mosnáček
- Re: [PATCH] MAINTAINERS, mailmap: update email address for Ondrej Mosnáček
Ondrej Mosnáček
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
K Prateek Nayak
- [PATCH v2 1/8] sched: introduce for_each_process_rculock and for_each_thread_rculock
Oleg Nesterov
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Oleg Nesterov
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Oleg Nesterov
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Oleg Nesterov
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Oleg Nesterov
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Oleg Nesterov
- [PATCH v4 02/15] mm/oom_kill: convert process/thread iterators to for_each_*_rculock
Oleg Nesterov
- [PATCH v4 03/15] mm/ksm: convert process iterator to for_each_process_rculock
Oleg Nesterov
- [PATCH v4 14/15] lib: convert process iterator to for_each_process_rculock
Oleg Nesterov
- [PATCH 8/8] security/landlock: convert thread iterator to for_each_thread_rcu
Günther Noack
- [PATCH] landlock: Fix use-after-free of the source's parent directory
Günther Noack
- [PATCH v1] landlock: Clean up ruleset validation checks
Günther Noack
- [PATCH v1 2/2] selftests/landlock: Check full ioctl commands in audit records
Günther Noack
- [PATCH v1 1/2] selftests/landlock: Fix trace variant formatting
Günther Noack
- [PATCH v1 2/2] selftests/landlock: Fix disconnected variant formatting
Günther Noack
- [RFC PATCH 0/2] Landlock signal scope and TIOCSIG
Günther Noack
- [RFC PATCH 0/2] Landlock signal scope and TIOCSIG
Günther Noack
- [PATCH] docs: landlock: clarify TTY signal scoping
Günther Noack
- [PATCH v2] docs: landlock: clarify TTY signal scoping
Günther Noack
- [PATCH] docs: landlock: clarify TTY signal scoping
Günther Noack
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Günther Noack
- [PATCH v1] landlock: Widen ruleset versions to 64 bits
Günther Noack
- [PATCH v2] docs: landlock: clarify TTY signal scoping
Günther Noack
- [PATCH 3/6] landlock: Add MPTCP bind and connect access rights
Günther Noack
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Günther Noack
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Günther Noack
- [PATCH RFC -next 09/12] landlock: Implement metadata access hooks
Günther Noack
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Günther Noack
- [PATCH v4] hardening: Default randstruct off with rust for better allmodconfig support
Miguel Ojeda
- [PATCH v20 6/8] rust: Add missing SAFETY documentation for `ARef` example
Miguel Ojeda
- [PATCH] rust: security: replace `core::mem::zeroed` with `pin_init::zeroed`
Miguel Ojeda
- [PATCH] rust: security: replace `core::mem::zeroed` with `pin_init::zeroed`
Miguel Ojeda
- [PATCH v2 1/8] sched: introduce for_each_process_rculock and for_each_thread_rculock
SJ Park
- [PATCH v2 4/8] mm/memory-failure: convert process iterator to for_each_process_rculock
SJ Park
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
SJ Park
- [PATCH v2 6/8] fs: convert process/thread iterators to for_each_*_rculock
SJ Park
- [PATCH v2 7/8] lib: convert process iterator to for_each_process_rculock
SJ Park
- [PATCH v2 8/8] security/landlock: convert thread iterator to for_each_thread_rculock
SJ Park
- [PATCH v3 0/3] Bring includes in linux/kmod.h up to date
Petr Pavlu
- [PATCH v3 1/3] umh, treewide: Explicitly include linux/umh.h where needed
Petr Pavlu
- [PATCH v3 2/3] time/jiffies: Include linux/sysctl.h for proc_int_u2k_conv_uop(), ...
Petr Pavlu
- [PATCH v3 3/3] module: Bring includes in linux/kmod.h up to date
Petr Pavlu
- [PATCH v3 0/3] Bring includes in linux/kmod.h up to date
Petr Pavlu
- [PATCH] KEYS: reject descriptions exceeding U16_MAX in __key_create_or_update()
Hui Peng
- [PATCH] ipv6: calipso: fix 8-bit hdrlen overflow and missing pskb_may_pull() in hop-by-hop options
Hui Peng
- [PATCH] netlabel: cipso_v4: reject empty MLS level/cat lists and zero tail in cipso_v4_delopt()
Hui Peng
- [PATCH] KEYS: asymmetric: fix out_len bounds check and in2_len union clobber in keyctl_pkey
Hui Peng
- [PATCH] netlabel: calipso, x509: clean up ADDRSELECT on DOI removal and check AKID len
Hui Peng
- [PATCH v2] certs: x509: duplicate cert->tbs when sig->algo_takes_data is set
Hui Peng
- [PATCH] smack: preserve low-integrity labels across file copy via whitelist
Tang Pengke
- [RFC PATCH] smack: preserve low-integrity labels on copy via whitelist
Tang Peter
- [PATCH v2 1/8] sched: introduce for_each_process_rculock and for_each_thread_rculock
Gregory Price
- [PATCH v2 2/8] mm/oom_kill: convert process/thread iterators to for_each_*_rculock
Gregory Price
- [PATCH v2 3/8] mm/ksm: convert process iterator to for_each_process_rculock
Gregory Price
- [PATCH v2 4/8] mm/memory-failure: convert process iterator to for_each_process_rculock
Gregory Price
- [PATCH v2 6/8] fs: convert process/thread iterators to for_each_*_rculock
Gregory Price
- [PATCH v2 7/8] lib: convert process iterator to for_each_process_rculock
Gregory Price
- [PATCH v2 8/8] security/landlock: convert thread iterator to for_each_thread_rculock
Gregory Price
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Gregory Price
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Gregory Price
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Gregory Price
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Gregory Price
- [PATCH bpf-next 0/7] Add new way to add BPF LSM hooks
Anton Protopopov
- [PATCH bpf-next 1/7] bpf: Allow BPF LSM programs to attach to more hooks
Anton Protopopov
- [PATCH bpf-next 0/7] Add new way to add BPF LSM hooks
Anton Protopopov
- [PATCH bpf-next 1/7] bpf: Allow BPF LSM programs to attach to more hooks
Anton Protopopov
- [PATCH bpf-next 0/7] Add new way to add BPF LSM hooks
Anton Protopopov
- [PATCH bpf-next 0/7] Add new way to add BPF LSM hooks
Anton Protopopov
- [PATCH v2] lsm: expose mount idmaps to inode hooks
Daan De Meyer via B4 Relay
- [PATCH v3 0/2] lsm: expose mount idmaps to inode hooks
Daan De Meyer via B4 Relay
- [PATCH v3 1/2] lsm: expose mount idmaps to inode hooks
Daan De Meyer via B4 Relay
- [PATCH v3 2/2] selftests/bpf: verify mount idmaps reach inode hooks
Daan De Meyer via B4 Relay
- [RFC] bpf-lsm: scoped one-shot userspace authorization binding for exec
Eric Robles
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Steven Rostedt
- [PATCH v3 12/15] unwind: convert process/thread iterator to for_each_process_thread_rculock
Steven Rostedt
- [PATCH v3 11/15] tracing/fgraph: convert process/thread iterator to for_each_process_thread_rculock
Steven Rostedt
- [RFC PATCH] security: Allow dropping bounding set process-wide
Jinjie Ruan
- [RFC PATCH] security: Allow dropping bounding set process-wide
Jinjie Ruan
- [RFC PATCH] security: Allow dropping bounding set process-wide
Jinjie Ruan
- [RFC PATCH] security: Allow dropping bounding set process-wide
Jinjie Ruan
- [PATCH] security: keys: Fix comment of search_process_keyrings_rcu()
Jinjie Ruan
- [RFC PATCH] security: Allow dropping bounding set process-wide
Jinjie Ruan
- [RFC PATCH] security: Allow dropping bounding set process-wide
Jinjie Ruan
- [RFC PATCH v2 0/3] security: Add PR_CAPBSET_DROP_MASK
Jinjie Ruan
- [RFC PATCH v2 1/3] capability: Move mk_kernel_cap() to header
Jinjie Ruan
- [RFC PATCH v2 2/3] security: Add PR_CAPBSET_DROP_MASK for process-wide bounding-set drops
Jinjie Ruan
- [RFC PATCH v2 3/3] selftests: prctl: add process-wide bounding-set drop tests
Jinjie Ruan
- [PATCH v20 4/8] rust: page: convert to `Ownable`'
Alice Ryhl
- [PATCH v20 4/8] rust: page: convert to `Ownable`'
Alice Ryhl
- [PATCH v20 4/8] rust: page: convert to `Ownable`'
Alice Ryhl
- [PATCH v20 4/8] rust: page: convert to `Ownable`'
Alice Ryhl
- [PATCH] rust: security: replace `core::mem::zeroed` with `pin_init::zeroed`
Alice Ryhl
- [PATCH v21 4/9] rust: rename `AlwaysRefCounted` to `RefCounted`.
Alice Ryhl
- [PATCH v21 5/9] rust: Add missing SAFETY documentation for `ARef` example
Alice Ryhl
- [PATCH v21 6/9] rust: Add `OwnableRefCounted`
Alice Ryhl
- [PATCH v21 7/9] rust: page: convert to `AlwaysRefCounted`
Alice Ryhl
- [PATCH v2] keys: reject descriptions that exceed the index length
Jarkko Sakkinen
- [PATCH v4] keys/trusted_keys: move TPM-specific fields into trusted_tpm_options
Jarkko Sakkinen
- [PATCH] keys: set persistent keyring timeout before destination linking
Jarkko Sakkinen
- [PATCH v5] keys/trusted_keys: move TPM-specific fields into struct trusted_key_tpm
Jarkko Sakkinen
- [PATCH] keys: set persistent keyring timeout before destination linking
Jarkko Sakkinen
- [PATCH v2] keys: finalize persistent keyring timeout after link attempt
Jarkko Sakkinen
- [PATCH] KEYS: trusted: Fix tpm2_load_cmd() boundary check
Jarkko Sakkinen
- [PATCH v3] keys: finalize persistent keyring timeout after link attempt
Jarkko Sakkinen
- [PATCH] KEYS: trusted: Fix tpm2_load_cmd() boundary check
Jarkko Sakkinen
- [PATCH 1/2] keys/trusted_keys: return immediately after TPM unseal failure
Jarkko Sakkinen
- [PATCH v6 2/2] keys/trusted_keys: move TPM-specific fields into struct trusted_key_tpm
Jarkko Sakkinen
- [PATCH 1/2] keys/trusted_keys: return immediately after TPM unseal failure
Jarkko Sakkinen
- [PATCH] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Jarkko Sakkinen
- [PATCH v3] keys: finalize persistent keyring timeout after link attempt
Jarkko Sakkinen
- [PATCH v2 1/2] keys/trusted_keys: return immediately after TPM unseal failure
Jarkko Sakkinen
- [PATCH v7 2/2] keys/trusted_keys: move TPM-specific fields into struct trusted_key_tpm
Jarkko Sakkinen
- [PATCH v2] keys: Fix key_user use-after-free during ownership changes
Jarkko Sakkinen
- [PATCH v3] KEYS: encrypted: fix integer overflow of datablob_len
Jarkko Sakkinen
- [PATCH v7 2/2] keys/trusted_keys: move TPM-specific fields into struct trusted_key_tpm
Jarkko Sakkinen
- [PATCH v3] KEYS: encrypted: fix integer overflow of datablob_len
Jarkko Sakkinen
- [PATCH v8 0/2] Move TPM-specific fields out of trusted_key_options
Jarkko Sakkinen
- [PATCH] KEYS: trusted: Fix tpm2_load_cmd() boundary check
Jarkko Sakkinen
- [PATCH v2] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Jarkko Sakkinen
- [PATCH v9 0/2] Move TPM-specific fields out of trusted_key_options
Jarkko Sakkinen
- [PATCH v4] keys: finalize persistent keyring timeout after link attempt
Jarkko Sakkinen
- [PATCH 1/3] keys: add KEY_SPEC_DM_VERITY_KEYRING
Jarkko Sakkinen
- [RFC PATCH 0/2] keys: Address lookup_user_key() mutability
Jarkko Sakkinen
- [RFC PATCH 1/2] keys: Return user session keyring on lookup
Jarkko Sakkinen
- [RFC PATCH 2/2] keys: Reject keyring creation with overridden credentials
Jarkko Sakkinen
- [PATCH 1/3] keys: add KEY_SPEC_DM_VERITY_KEYRING
Jarkko Sakkinen
- [PATCH v2] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Jarkko Sakkinen
- [PATCH] KEYS: reject descriptions exceeding U16_MAX in __key_create_or_update()
Jarkko Sakkinen
- [PATCH v2] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Jarkko Sakkinen
- [PATCH] KEYS: trusted: Fix blob allocation size in tpm2_key_decode()
Jarkko Sakkinen
- [PATCH] KEYS: trusted: Reject short TPM2 public areas
Jarkko Sakkinen
- [PATCH v3] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Jarkko Sakkinen
- [PATCH v3 1/2] keys: Protect key_user lifetime during ownership changes
Jarkko Sakkinen
- [PATCH v3 2/2] keys: Serialize ownership transfers with key accounting
Jarkko Sakkinen
- [PATCH v2] keys: Fix key_user use-after-free during ownership changes
Jarkko Sakkinen
- [PATCH] security: keys: Fix comment of search_process_keyrings_rcu()
Jarkko Sakkinen
- [PATCH] landlock: Fix use-after-free of the source's parent directory
Mickaël Salaün
- [PATCH v2] selftests/landlock: Test abstract socket trace name limits
Mickaël Salaün
- [PATCH v1] landlock: Clean up ruleset validation checks
Mickaël Salaün
- [PATCH v1 1/2] landlock: Bound escaped trace path output
Mickaël Salaün
- [PATCH v1 2/2] landlock: Test trace path output boundaries
Mickaël Salaün
- [PATCH v1 1/2] selftests/landlock: Fix trace variant formatting
Mickaël Salaün
- [PATCH v1 2/2] selftests/landlock: Fix disconnected variant formatting
Mickaël Salaün
- [GIT PULL] Landlock fix for v7.3-rc3
Mickaël Salaün
- [PATCH v3 3/12] security: Add LSM_AUDIT_DATA_NS for namespace audit records
Mickaël Salaün
- [PATCH v3 3/12] security: Add LSM_AUDIT_DATA_NS for namespace audit records
Mickaël Salaün
- [PATCH v1 0/2] lsm: Preserve full ioctl commands in audit records
Mickaël Salaün
- [PATCH v1 1/2] lsm: Preserve full ioctl commands in audit records
Mickaël Salaün
- [PATCH v1 2/2] selftests/landlock: Check full ioctl commands in audit records
Mickaël Salaün
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Mickaël Salaün
- [PATCH] [v2] landlock: work around gcc-16 -Wuninitialized warning
Mickaël Salaün
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Mickaël Salaün
- [PATCH 5.15.y 1/2] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Mickaël Salaün
- [PATCH 5.15.y 2/2] selftests/landlock: Add tests for whiteout object creation
Mickaël Salaün
- [PATCH] [v2] landlock: work around gcc-16 -Wuninitialized warning
Mickaël Salaün
- [PATCH 5.15.y 2/2] selftests/landlock: Add tests for whiteout object creation
Mickaël Salaün
- [PATCH v1 0/9] landlock: Fix tracepoint policy context
Mickaël Salaün
- [PATCH v1 1/9] landlock: Fix tracepoint fixed-width type names
Mickaël Salaün
- [PATCH v1 2/9] landlock: Fix filesystem denial blocker reporting
Mickaël Salaün
- [PATCH v1 3/9] landlock: Fix rule tracepoint context
Mickaël Salaün
- [PATCH v1 4/9] landlock: Fix network denial trace context
Mickaël Salaün
- [PATCH v1 5/9] landlock: Report the actual ptrace tracer
Mickaël Salaün
- [PATCH v1 6/9] landlock: Report the effective signal number
Mickaël Salaün
- [PATCH v1 7/9] selftests/landlock: Test filesystem denial blockers
Mickaël Salaün
- [PATCH v1 8/9] selftests/landlock: Test network denial context
Mickaël Salaün
- [PATCH v1 9/9] landlock: Fix tracepoint contract documentation
Mickaël Salaün
- [PATCH v1] landlock: Widen ruleset versions to 64 bits
Mickaël Salaün
- [RFC PATCH 0/2] Landlock signal scope and TIOCSIG
Mickaël Salaün
- [PATCH v2] docs: landlock: clarify TTY signal scoping
Mickaël Salaün
- [PATCH 5.15.y v2] selftests/landlock: Add tests for whiteout object creation
Mickaël Salaün
- [GIT PULL] Landlock fix for v7.3-rc5
Mickaël Salaün
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Mickaël Salaün
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Mickaël Salaün
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Mickaël Salaün
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Mickaël Salaün
- [PATCH v2 01/10] pseries/plpks: update PKS documentation and maintainer entry
R Nageswara Sastry
- [PATCH v2 02/10] pseries/plpks: fix error handling in plpks_read_var()
R Nageswara Sastry
- [PATCH v2 03/10] pseries/plpks: improve type consistency and parameter validation
R Nageswara Sastry
- [PATCH v2 04/10] keys/trusted_keys: propagate wrapping key generation errors
R Nageswara Sastry
- [PATCH v2 05/10] pseries/plpks: rename the default wrapping key macro
R Nageswara Sastry
- [PATCH v2 06/10] pseries/plpks: fix self-reference in plpks_var initializer
R Nageswara Sastry
- [PATCH v2 07/10] pseries/plpks: hide wrapping_features when unsupported
R Nageswara Sastry
- [PATCH v2 08/10] pseries/plpks: add HCALLs for PKWM wrapping key life cycle management
R Nageswara Sastry
- [PATCH v2 09/10] keys/trusted_keys: enable PKWM wrapping key selection by label
R Nageswara Sastry
- [PATCH v2 10/10] pseries/plpks/wrapkey: expose PKWM wrapping key management to userspace via sysfs
R Nageswara Sastry
- [PATCH v3] KEYS: encrypted: fix integer overflow of datablob_len
R Nageswara Sastry
- [PATCH 24/27] fs: port ->setattr() to pass const mnt_idmap
Casey Schaufler
- [PATCH v2 01/15] lsm: Add the LSM policy object lifetime hooks
Casey Schaufler
- [PATCH 0/7] Change skb secmarks to x-array indexes
Casey Schaufler
- [PATCH v2 0/7] Change skb secmarks to x-array indexes
Casey Schaufler
- [PATCH v2 1/7] net, smack: Create a function to set secmarks
Casey Schaufler
- [PATCH v2 2/7] LSM: Implement x array functions for secmarks
Casey Schaufler
- [PATCH v2 3/7] LSM: Two hooks for manipulating struct lsm_prop
Casey Schaufler
- [PATCH v2 4/7] SELinux: hooks for secctx_to_lsmprop and update_lsmprop
Casey Schaufler
- [PATCH v2 5/7] Smack: hooks for secctx_to_lsmprop and update_lsmprop
Casey Schaufler
- [PATCH v2 6/7] Apparmor: hooks for secctx_to_lsmprop and update_lsmprop
Casey Schaufler
- [PATCH v2 7/7] net, lsm: Change skb secmarks to x-array indexes
Casey Schaufler
- [PATCH v3 1/2] lsm: expose mount idmaps to inode hooks
Casey Schaufler
- [RFC PATCH] smack: preserve low-integrity labels on copy via whitelist
Casey Schaufler
- [PATCH] [v2] landlock: work around gcc-16 -Wuninitialized warning
Sebastian Andrzej Siewior
- [PATCH] [v2] landlock: work around gcc-16 -Wuninitialized warning
Sebastian Andrzej Siewior
- [PATCH] [v2] landlock: work around gcc-16 -Wuninitialized warning
Sebastian Andrzej Siewior
- [PATCH] lsm: initialize the security blob for the initial namespaces
Stephen Smalley
- [PATCH] lsm: initialize the security blob for the initial namespaces
Stephen Smalley
- [PATCH v2] lsm, nscommon: initialize the security blob for the initial namespaces
Stephen Smalley
- [PATCH] lsm: initialize the security blob for the initial namespaces
Stephen Smalley
- [PATCH v3] lsm, nscommon: initialize the security blob for the initial namespaces
Stephen Smalley
- [PATCH v4] keys/trusted_keys: move TPM-specific fields into trusted_tpm_options
Srish Srinivasan
- [PATCH v5] keys/trusted_keys: move TPM-specific fields into struct trusted_key_tpm
Srish Srinivasan
- [PATCH v6 0/2] Move TPM-specific fields out of trusted_key_options
Srish Srinivasan
- [PATCH 1/2] keys/trusted_keys: return immediately after TPM unseal failure
Srish Srinivasan
- [PATCH v6 2/2] keys/trusted_keys: move TPM-specific fields into struct trusted_key_tpm
Srish Srinivasan
- [PATCH v5] keys/trusted_keys: move TPM-specific fields into struct trusted_key_tpm
Srish Srinivasan
- [PATCH] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Srish Srinivasan
- [PATCH 1/2] keys/trusted_keys: return immediately after TPM unseal failure
Srish Srinivasan
- [PATCH v7 0/2] Move TPM-specific fields out of trusted_key_options
Srish Srinivasan
- [PATCH v2 1/2] keys/trusted_keys: return immediately after TPM unseal failure
Srish Srinivasan
- [PATCH v7 2/2] keys/trusted_keys: move TPM-specific fields into struct trusted_key_tpm
Srish Srinivasan
- [PATCH] KEYS: trusted: Fix tpm2_load_cmd() boundary check
Srish Srinivasan
- [PATCH v7 2/2] keys/trusted_keys: move TPM-specific fields into struct trusted_key_tpm
Srish Srinivasan
- [PATCH v8 0/2] Move TPM-specific fields out of trusted_key_options
Srish Srinivasan
- [PATCH v3 1/2] keys/trusted_keys: return immediately after TPM unseal failure
Srish Srinivasan
- [PATCH v8 2/2] keys/trusted_keys: move TPM-specific fields into struct trusted_key_tpm
Srish Srinivasan
- [PATCH] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Srish Srinivasan
- [PATCH v2] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Srish Srinivasan
- [PATCH v7 2/2] keys/trusted_keys: move TPM-specific fields into struct trusted_key_tpm
Srish Srinivasan
- [PATCH v9 0/2] Move TPM-specific fields out of trusted_key_options
Srish Srinivasan
- [PATCH v9 1/2] keys/trusted_keys: return immediately after TPM unseal failure
Srish Srinivasan
- [PATCH v9 2/2] keys/trusted_keys: move TPM-specific fields into struct trusted_key_tpm
Srish Srinivasan
- [PATCH v9 0/2] Move TPM-specific fields out of trusted_key_options
Srish Srinivasan
- [PATCH v2] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Srish Srinivasan
- [PATCH v2 00/10] Extend PKWM to support user-created wrapping keys
Srish Srinivasan
- [PATCH v2] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Srish Srinivasan
- [PATCH v2] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Srish Srinivasan
- [PATCH v3] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Srish Srinivasan
- [PATCH v3] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
Srish Srinivasan
- [PATCH] keys/trusted_keys: reuse TPM version in option handling
Srish Srinivasan
- [PATCH bpf-next 0/7] Add new way to add BPF LSM hooks
Alexei Starovoitov
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Alexei Starovoitov
- [PATCH bpf-next v3 07/15] lsm: Add the bpf_lsm_policy_apply_bprm kfunc
Alexei Starovoitov
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Alexei Starovoitov
- LSM boundaries. Was: [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Alexei Starovoitov
- LSM boundaries. Was: [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Alexei Starovoitov
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Alexei Starovoitov
- [PATCH v2 14/15] selftests/bpf: Test the LSM policy object kfuncs with Landlock
Justin Suess
- [PATCH v2 01/15] lsm: Add the LSM policy object lifetime hooks
Justin Suess
- [PATCH v2 01/15] lsm: Add the LSM policy object lifetime hooks
Justin Suess
- [PATCH bpf-next 0/7] Add new way to add BPF LSM hooks
Justin Suess
- [PATCH 8/8] security/landlock: convert thread iterator to for_each_thread_rcu
Justin Suess
- [PATCH bpf-next v3 00/15] BPF interface for applying Landlock rulesets
Justin Suess
- [PATCH bpf-next v3 01/15] lsm: Add the LSM policy object lifetime hooks
Justin Suess
- [PATCH bpf-next v3 02/15] lsm: Add the bprm_apply_policy_object LSM hook
Justin Suess
- [PATCH bpf-next v3 03/15] lsm: Move the lsm_for_each_hook() macro to security/lsm.h
Justin Suess
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Justin Suess
- [PATCH bpf-next v3 05/15] lsm: Add the bpf_lsm_policy_from_fd kfunc
Justin Suess
- [PATCH bpf-next v3 06/15] lsm: Add the bpf_lsm_policy_acquire kfunc
Justin Suess
- [PATCH bpf-next v3 07/15] lsm: Add the bpf_lsm_policy_apply_bprm kfunc
Justin Suess
- [PATCH bpf-next v3 08/15] lsm: Document the LSM policy object interface
Justin Suess
- [PATCH bpf-next v3 09/15] selftests/bpf: Add tests for the LSM policy object kfuncs
Justin Suess
- [PATCH bpf-next v3 10/15] landlock: Expose the ruleset fd lookup to the rest of Landlock
Justin Suess
- [PATCH bpf-next v3 11/15] landlock: Factor the credential restriction out of landlock_restrict_self()
Justin Suess
- [PATCH bpf-next v3 12/15] landlock: Free rulesets after an RCU grace period
Justin Suess
- [PATCH bpf-next v3 13/15] landlock: Implement the LSM policy object hooks
Justin Suess
- [PATCH bpf-next v3 14/15] selftests/bpf: Test the LSM policy object kfuncs with Landlock
Justin Suess
- [PATCH bpf-next v3 15/15] landlock: Document the BPF policy interface
Justin Suess
- [PATCH bpf-next v3 07/15] lsm: Add the bpf_lsm_policy_apply_bprm kfunc
Justin Suess
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Justin Suess
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Justin Suess
- [PATCH bpf-next v3 07/15] lsm: Add the bpf_lsm_policy_apply_bprm kfunc
Justin Suess
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Justin Suess
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
Justin Suess
- [PATCH bpf-next 4/8] bpf, lsm: Let BPF LSM provide xattrs at inode creation
Justin Suess
- [PATCH bpf-next 4/8] bpf, lsm: Let BPF LSM provide xattrs at inode creation
Justin Suess
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Justin Suess
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Justin Suess
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Justin Suess
- [PATCH 0/7] fs: preserve superblock inode walk positions across lock drops
Julian Sun
- [PATCH 1/7] fs: remove trailing whitespace from include/linux/fs.h
Julian Sun
- [PATCH 2/7] fs: introduce sb_for_each_inodes().
Julian Sun
- [PATCH 3/7] block: use sb_for_each_inodes() in sync_bdevs()
Julian Sun
- [PATCH 4/7] fs: use sb_for_each_inodes() API.
Julian Sun
- [PATCH 5/7] gfs2: use sb_for_each_inodes() for cooperative eviction
Julian Sun
- [PATCH 6/7] quota: use sb_for_each_inodes() in add_dquot_ref()
Julian Sun
- [PATCH 7/7] landlock: use sb_for_each_inodes() when detaching a superblock
Julian Sun
- [External] Re: [PATCH 0/7] fs: preserve superblock inode walk positions across lock drops
Julian Sun
- [External] Re: [PATCH 2/7] fs: introduce sb_for_each_inodes().
Julian Sun
- [PATCH 2/7] fs: introduce sb_for_each_inodes().
Julian Sun
- [PATCH 3/6] landlock: Add MPTCP bind and connect access rights
Geliang Tang
- [PATCH 3/6] landlock: Add MPTCP bind and connect access rights
Geliang Tang
- [PATCH] smack: reject relabel-self writes from io_uring workers
Nguyen Ngoc Thang
- [PATCH v2 0/3] pidfd: add task path ioctls
Florian Weimer
- [PATCH 1/7] kasan: Add .kunitconfig for KUnit tests
Bill Wendling
- [PATCH v21 9/9] rust: page: add `ExclusivePage` for race-free page access
Matthew Wilcox
- [PATCH bpf-next 4/8] bpf, lsm: Let BPF LSM provide xattrs at inode creation
David Windsor
- [Resend PATCH v2] ipe: fix typo
Fan Wu
- [PATCH v3] ipe: fix invalid sgid value in audit event documentation
Fan Wu
- [PATCH] dm-verity: clear LSM integrity state on suspend
Fan Wu
- [PATCH] dm-verity: clear LSM integrity state on suspend
Fan Wu
- [PATCH 0/2] ipe: fix two use-after-frees
Fan Wu
- [PATCH 1/2] ipe: fix use-after-free when auditing a newly loaded policy
Fan Wu
- [PATCH 2/2] ipe: protect the dm-verity root hash with RCU
Fan Wu
- [PATCH 0/2] ipe: fix two use-after-frees
Fan Wu
- [GIT PULL] IPE fixes for 7.3-rc5
Fan Wu
- [PATCH] MAINTAINERS: name the wufan/ipe next branch
Fan Wu
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Cai Xinchen
- [PATCH RFC -next 01/12] fs: pass struct path to notify_change()
Cai Xinchen
- [PATCH RFC -next 02/12] LSM: pass struct path to the inode_setsecctx hook
Cai Xinchen
- [PATCH RFC -next 03/12] fs: pass struct path to xattr helpers
Cai Xinchen
- [PATCH RFC -next 04/12] fs: pass struct path to POSIX ACL helpers
Cai Xinchen
- [PATCH RFC -next 05/12] LSM: pass struct path to the inode_setattr hook
Cai Xinchen
- [PATCH RFC -next 06/12] LSM: pass struct path to the inode xattr hooks
Cai Xinchen
- [PATCH RFC -next 07/12] LSM: pass struct path to the inode posix acl hooks
Cai Xinchen
- [PATCH RFC -next 08/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Cai Xinchen
- [PATCH RFC -next 09/12] landlock: Implement metadata access hooks
Cai Xinchen
- [PATCH RFC -next 10/12] selftests/landlock: Add tests for metadata access rights
Cai Xinchen
- [PATCH RFC -next 11/12] samples/landlock: Add metadata rights to sandboxer
Cai Xinchen
- [PATCH RFC -next 12/12] Documentation: Update landlock doc for metadata rights
Cai Xinchen
- [PATCH RFC -next 09/12] landlock: Implement metadata access hooks
Cai Xinchen
- [PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
Cai Xinchen
- [PATCH RFC -next 03/12] fs: pass struct path to xattr helpers
Cai Xinchen
- [PATCH] landlock: Fix domain leak on concurrent F_SETOWN and file release
Jiakai Xu
- [PATCH] keys: Fix key_user use-after-free during ownership changes
Chengfeng Ye
- [PATCH v2] keys: Fix key_user use-after-free during ownership changes
Chengfeng Ye
- [PATCH v3 0/2] keys: Fix ownership lifetime and accounting races
Chengfeng Ye
- [PATCH v3 1/2] keys: Protect key_user lifetime during ownership changes
Chengfeng Ye
- [PATCH v3 2/2] keys: Serialize ownership transfers with key accounting
Chengfeng Ye
- [PATCH v2] keys: Fix key_user use-after-free during ownership changes
Chengfeng Ye
- [PATCH RFC 0/3] security: ima: support TSM measurement registers
Yeoreum Yun
- [PATCH RFC 1/3] virt: coco: introduce tsm_default_tm() and tsm_mr_read()/write()
Yeoreum Yun
- [PATCH RFC 2/3] security: IMA: introduce ima_mr structure
Yeoreum Yun
- [PATCH RFC 3/3] security: IMA: use TSM measurement registers
Yeoreum Yun
- [PATCH v3] KEYS: encrypted: fix integer overflow of datablob_len
Cen Zhang
- [PATCH] apparmor: check accept index + 1 is in bounds
Guanglei Zhu
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Peter Zijlstra
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Peter Zijlstra
- [PATCH v2 5/8] kernel: convert process/thread iterators to for_each_*_rculock
Peter Zijlstra
- [PATCH v5] Kconfig: fix typos in core makefiles and purge defective DVB debug (v5)
Thomas Zimmermann
- [PATCH] ima: allow users to specify the pcr index with IMA_MEASURE_PCR_IDX
Mimi Zohar
- [PATCH] ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()
Mimi Zohar
- [PATCH v2] ima: allow users to specify the pcr index with IMA_MEASURE_PCR_IDX
Mimi Zohar
- [syzbot] [ext4?] possible deadlock in process_measurement (6)
Mimi Zohar
- [PATCH v2 0/3] integrity: Return error codes in audit messages
Mimi Zohar
- [PATCH v2 1/3] integrity: Replace all uses of integrity_audit_msg() with integrity_audit_message()
Mimi Zohar
- [PATCH v2 1/3] integrity: Replace all uses of integrity_audit_msg() with integrity_audit_message()
Mimi Zohar
- [PATCH v3 2/2] integrity: Replace integrity_audit_message() with integrity_audit_msg()
Mimi Zohar
- [PATCH bpf-next v3 11/15] landlock: Factor the credential restriction out of landlock_restrict_self()
bot+bpf-ci at kernel.org
- [PATCH bpf-next v3 04/15] lsm: Add the bpf_lsm_policy_release kfunc and policy object destructor
bot+bpf-ci at kernel.org
- [PATCH bpf-next v3 06/15] lsm: Add the bpf_lsm_policy_acquire kfunc
bot+bpf-ci at kernel.org
- [PATCH bpf-next v3 09/15] selftests/bpf: Add tests for the LSM policy object kfuncs
bot+bpf-ci at kernel.org
- [PATCH bpf-next v3 05/15] lsm: Add the bpf_lsm_policy_from_fd kfunc
bot+bpf-ci at kernel.org
- [PATCH bpf-next v3 14/15] selftests/bpf: Test the LSM policy object kfuncs with Landlock
bot+bpf-ci at kernel.org
- [PATCH bpf-next v3 12/15] landlock: Free rulesets after an RCU grace period
bot+bpf-ci at kernel.org
- [PATCH bpf-next v3 13/15] landlock: Implement the LSM policy object hooks
bot+bpf-ci at kernel.org
- [PATCH] netlabel: cipso_v4: reject empty MLS level/cat lists and zero tail in cipso_v4_delopt()
netdev-bot+sashiko at kernel.org
- [GIT PULL] selinux/selinux-pr-20260903
pr-tracker-bot at kernel.org
- [GIT PULL] Landlock fix for v7.3-rc3
pr-tracker-bot at kernel.org
- [GIT PULL] selinux/selinux-pr-20260919
pr-tracker-bot at kernel.org
- [GIT PULL] Landlock fix for v7.3-rc5
pr-tracker-bot at kernel.org
- [GIT PULL] IPE fixes for 7.3-rc5
pr-tracker-bot at kernel.org
- [PATCH v2] lsm,nscommon: initialize the security blob for the initial namespaces
sashiko-bot at kernel.org
- [PATCH v3] lsm,nscommon: initialize the security blob for the initial namespaces
sashiko-bot at kernel.org
- [PATCH v1 1/9] landlock: Fix tracepoint fixed-width type names
sashiko-bot at kernel.org
- [PATCH v1 5/9] landlock: Report the actual ptrace tracer
sashiko-bot at kernel.org
- [PATCH v1 2/9] landlock: Fix filesystem denial blocker reporting
sashiko-bot at kernel.org
- [PATCH v1 7/9] selftests/landlock: Test filesystem denial blockers
sashiko-bot at kernel.org
- [PATCH v1 6/9] landlock: Report the effective signal number
sashiko-bot at kernel.org
- [PATCH v1 4/9] landlock: Fix network denial trace context
sashiko-bot at kernel.org
- [PATCH v1 8/9] selftests/landlock: Test network denial context
sashiko-bot at kernel.org
- [PATCH v1 3/9] landlock: Fix rule tracepoint context
sashiko-bot at kernel.org
- [PATCH v1 9/9] landlock: Fix tracepoint contract documentation
sashiko-bot at kernel.org
- [PATCH v2 2/9] seq_buf: Do not pop from an overflowed seq_buf
sashiko-bot at kernel.org
- [PATCH] smack: reject relabel-self writes from io_uring workers
sashiko-bot at kernel.org
- [PATCH] security: commoncap: clarify CAP_FS_SET comment in cap_task_fix_setuid()
sashiko-bot at kernel.org
- [PATCH] KEYS: reject descriptions exceeding U16_MAX in __key_create_or_update()
sashiko-bot at kernel.org
- [PATCH] ipv6: calipso: fix 8-bit hdrlen overflow and missing pskb_may_pull() in hop-by-hop options
sashiko-bot at kernel.org
- [PATCH] netlabel: cipso_v4: reject empty MLS level/cat lists and zero tail in cipso_v4_delopt()
sashiko-bot at kernel.org
- [PATCH] KEYS: asymmetric: fix out_len bounds check and in2_len union clobber in keyctl_pkey
sashiko-bot at kernel.org
- [PATCH] netlabel: calipso, x509: clean up ADDRSELECT on DOI removal and check AKID len
sashiko-bot at kernel.org
- [PATCH v2] certs: x509: duplicate cert->tbs when sig->algo_takes_data is set
sashiko-bot at kernel.org
- [PATCH] smackfs: reject out-of-range IPv4 octets in netlabel writes
sashiko-bot at kernel.org
- [PATCH v2] security: commoncap: clarify CAP_FS_SET comment in cap_task_fix_setuid()
sashiko-bot at kernel.org
- [PATCH v4 01/15] sched: introduce for_each_process_rculock and for_each_thread_rculock
sashiko-bot at kernel.org
- [PATCH v4 02/15] mm/oom_kill: convert process/thread iterators to for_each_*_rculock
sashiko-bot at kernel.org
- [PATCH v4 03/15] mm/ksm: convert process iterator to for_each_process_rculock
sashiko-bot at kernel.org
- [PATCH v4 04/15] mm/memory-failure: convert process iterator to for_each_process_rculock
sashiko-bot at kernel.org
- [PATCH v4 05/15] cpu/hotplug: convert process iterator to for_each_process_rculock
sashiko-bot at kernel.org
- [PATCH v4 06/15] freezer: convert thread iterator to for_each_thread_rculock
sashiko-bot at kernel.org
- [PATCH v4 07/15] hung_task: convert process/thread iterators to for_each_*_rculock
sashiko-bot at kernel.org
- [PATCH v4 08/15] locking/lockdep: convert process/thread iterators to for_each_*_rculock
sashiko-bot at kernel.org
- [PATCH v4 09/15] rcu: convert process/thread iterator to for_each_process_thread_rculock
sashiko-bot at kernel.org
- [PATCH v4 10/15] sched: convert process/thread iterators to for_each_*_rculock
sashiko-bot at kernel.org
- [PATCH v4 11/15] tracing/fgraph: convert process/thread iterator to for_each_process_thread_rculock
sashiko-bot at kernel.org
- [PATCH v4 12/15] unwind: convert process/thread iterator to for_each_process_thread_rculock
sashiko-bot at kernel.org
- [PATCH v4 13/15] fs: convert process/thread iterators to for_each_*_rculock
sashiko-bot at kernel.org
- [PATCH v4 14/15] lib: convert process iterator to for_each_process_rculock
sashiko-bot at kernel.org
- [PATCH v4 15/15] security/landlock: convert thread iterator to for_each_thread_rculock
sashiko-bot at kernel.org
- [PATCH] dm-verity: clear LSM integrity state on suspend
sashiko-bot at kernel.org
- [RFC PATCH] security: Allow dropping bounding set process-wide
sashiko-bot at kernel.org
- [PATCH v1] landlock: Widen ruleset versions to 64 bits
sashiko-bot at kernel.org
- [PATCH] smackfs: fix IPv6 netlabel prefix mask for non-16-aligned lengths
sashiko-bot at kernel.org
- [PATCH 1/2] ipe: fix use-after-free when auditing a newly loaded policy
sashiko-bot at kernel.org
- [PATCH 2/2] ipe: protect the dm-verity root hash with RCU
sashiko-bot at kernel.org
- [PATCH security v1] apparmor: fix a use-after-free in aa_lookupn_ns()
sashiko-bot at kernel.org
- [PATCH 5.15.y v2] selftests/landlock: Add tests for whiteout object creation
sashiko-bot at kernel.org
- [PATCH v3 1/2] docs: landlock: clarify TTY signal scoping
sashiko-bot at kernel.org
- [PATCH v3 2/2] selftests/landlock: cover TTY signal scoping
sashiko-bot at kernel.org
- [PATCH] KEYS: trusted: Fix blob allocation size in tpm2_key_decode()
sashiko-bot at kernel.org
- [RFC PATCH 1/2] keys: Return user session keyring on lookup
sashiko-bot at kernel.org
- [RFC PATCH 2/2] keys: Reject keyring creation with overridden credentials
sashiko-bot at kernel.org
- [PATCH v2] ima: discard modsig on detached-data binding failure
sashiko-bot at kernel.org
- [PATCH] landlock: Fix domain leak on concurrent F_SETOWN and file release
sashiko-bot at kernel.org
- [PATCH v4 2/2] integrity: Replace integrity_audit_message() with integrity_audit_msg()
sashiko-bot at kernel.org
- [PATCH v4 1/2] integrity: Report error code in integrity_audit_msg() call sites
sashiko-bot at kernel.org
- [PATCH] KEYS: trusted: Reject short TPM2 public areas
sashiko-bot at kernel.org
- [PATCH] selftests: binderfs: skip the stress test without binderfs
sashiko-bot at kernel.org
- [PATCH] apparmor: check connect permission for SCTP
sashiko-bot at kernel.org
- [PATCH security v1] apparmor: fix a use-after-free in aa_lookupn_ns()
sashiko-bot at kernel.org
- [PATCH v3] keys/trusted/tpm2: Validate TPM2_Create object sizes separately
sashiko-bot at kernel.org
- [PATCH v3 2/2] keys: Serialize ownership transfers with key accounting
sashiko-bot at kernel.org
- [PATCH v3 1/2] keys: Protect key_user lifetime during ownership changes
sashiko-bot at kernel.org
- [PATCH] security: keys: Fix comment of search_process_keyrings_rcu()
sashiko-bot at kernel.org
- [PATCH] lsm: remove redundant NULL check in security_init()
sashiko-bot at kernel.org
- [PATCH v3 11/12] Documentation/mm: Document the crash memaction registry
sashiko-bot at kernel.org
- [PATCH v3 07/12] security/keys: Allocate key payloads from the secret pool
sashiko-bot at kernel.org
- [PATCH v3 06/12] crypto: api - Allocate tfms from the secret pool
sashiko-bot at kernel.org
- [PATCH v3 05/12] dm crypt: Allocate key material from the secret pool
sashiko-bot at kernel.org
- [PATCH v3 08/12] mm: Add VM_CRASH_MARK
sashiko-bot at kernel.org
- [PATCH v3 04/12] arm64: Enable the crash memaction registry
sashiko-bot at kernel.org
- [PATCH v3 10/12] mm/madvise: Add MADV_CRASH_SECRET, MADV_CRASH_CACHE and MADV_CRASH_RESET
sashiko-bot at kernel.org
- [PATCH v3 02/12] lib, kexec: Add a secret pool for key material
sashiko-bot at kernel.org
- [PATCH v3 01/12] kexec: Add a crash memaction registry
sashiko-bot at kernel.org
- [PATCH v3 03/12] mm: Wire up the crash memaction registry
sashiko-bot at kernel.org
- [PATCH v3 12/12] kexec: Expose the crash memaction bitmap in debugfs
sashiko-bot at kernel.org
- [PATCH v3 09/12] mm/rmap: Mark folios mapped into crash_memaction-marked VMAs
sashiko-bot at kernel.org
- [PATCH] apparmor: resolve pivotroot paths before the failure audit
sashiko-bot at kernel.org
- [RFC PATCH v2 1/3] capability: Move mk_kernel_cap() to header
sashiko-bot at kernel.org
- [RFC PATCH v2 3/3] selftests: prctl: add process-wide bounding-set drop tests
sashiko-bot at kernel.org
- [RFC PATCH v2 2/3] security: Add PR_CAPBSET_DROP_MASK for process-wide bounding-set drops
sashiko-bot at kernel.org
- [PATCH 01/16 net-next v2] ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack
sashiko-bot at kernel.org
- [PATCH 15/16 net-next v2] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency
sashiko-bot at kernel.org
- [PATCH] smack: preserve low-integrity labels across file copy via whitelist
sashiko-bot at kernel.org
- [PATCH] KEYS: Fix add_key() race with keyring restriction
sashiko-bot at kernel.org
- [PATCH] keys/trusted_keys: reuse TPM version in option handling
sashiko-bot at kernel.org
- [PATCH RFC 2/3] security: IMA: introduce ima_mr structure
sashiko-bot at kernel.org
- [PATCH RFC 1/3] virt: coco: introduce tsm_default_tm() and tsm_mr_read()/write()
sashiko-bot at kernel.org
- [PATCH RFC 3/3] security: IMA: use TSM measurement registers
sashiko-bot at kernel.org
- [PATCH net] cipso: adjust cached option offsets when removing CIPSO
sashiko-bot at kernel.org
- [PATCH v3 02/11] seq_buf: Do not pop from an overflowed seq_buf
sashiko-bot at kernel.org
- [PATCH] KEYS: Fix add_key() race with keyring restriction
tjdqudcks0424 at naver.com
- [PATCH v2] media: dvb-core: extirpate defective and unsafe ULE debug block
kernel test robot
- [PATCH v2] media: dvb-core: extirpate defective and unsafe ULE debug block
kernel test robot
- [PATCH v5] Kconfig: fix typos in core makefiles and purge defective DVB debug (v5)
kernel test robot
- [syzbot] [integrity?] [lsm?] possible deadlock in configfs_read_iter
syzbot
- [syzbot] [ext4?] possible deadlock in process_measurement (6)
syzbot
- [syzbot] [lsm?] [io-uring?] kernel BUG in commit_creds (3)
syzbot
- 優しい社長のNG行動
ナレッジリンク
- [RFC] Proposal for a standard Competitive / Protected Session API in Linux
洛神葵
- [RFC] Proposal for a standard Competitive / Protected Session API in Linux
洛神葵
Last message date:
Wed Sep 30 23:59:02 UTC 2026
Archived on: Thu Oct 1 00:48:37 UTC 2026
This archive was generated by
Pipermail 0.09 (Mailman edition).