Eric Biggers
|
b2724d5802
security/integrity: constify some read-only data
|
7 жил өмнө |
Linus Torvalds
|
92d4a03674
Merge branch 'next-general' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
|
7 жил өмнө |
Mimi Zohar
|
4f0496d8ff
ima: based on policy warn about loading firmware (pre-allocated buffer)
|
7 жил өмнө |
Mimi Zohar
|
c77b8cdf74
module: replace the existing LSM hook in init_module
|
7 жил өмнө |
Mimi Zohar
|
fed2512a7c
ima: based on policy require signed firmware (sysfs fallback)
|
7 жил өмнө |
Mimi Zohar
|
16c267aac8
ima: based on policy require signed kexec kernel images
|
7 жил өмнө |
Al Viro
|
6035a27b25
IMA: don't propagate opened through the entire thing
|
7 жил өмнө |
Yisheng Xie
|
b4df86085a
ima: use match_string() helper
|
7 жил өмнө |
Mimi Zohar
|
fd90bc559b
ima: based on policy verify firmware signatures (pre-allocated buffer)
|
7 жил өмнө |
Petr Vorel
|
4ecd9934ba
ima: Remove unused variable ima_initialized
|
7 жил өмнө |
Petr Vorel
|
ab60368ab6
ima: Fallback to the builtin hash algorithm
|
7 жил өмнө |
Mimi Zohar
|
9e67028e76
ima: fail signature verification based on policy
|
7 жил өмнө |
Mimi Zohar
|
d77ccdc644
ima: re-evaluate files on privileged mounted filesystems
|
7 жил өмнө |
Matthew Garrett
|
d906c10d8a
IMA: Support using new creds in appraisal policy
|
7 жил өмнө |
Goffredo Baroncelli
|
c472c07bfe
iversion: Rename make inode_cmp_iversion{+raw} to inode_eq_iversion{+raw}
|
7 жил өмнө |
Linus Torvalds
|
3c29548f87
Merge branch 'next-integrity' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
|
7 жил өмнө |
Jeff Layton
|
3b370b215f
IMA: switch IMA over to new i_version API
|
7 жил өмнө |
Sascha Hauer
|
a2a2c3c858
ima: Use i_version only when filesystem supports it
|
8 жил өмнө |
Bruno E. O. Meneguele
|
9c655be064
ima: log message to module appraisal error
|
7 жил өмнө |
Roberto Sassu
|
4e8581eefe
ima: pass filename to ima_rdwr_violation_check()
|
7 жил өмнө |
Mimi Zohar
|
da1b0029f5
ima: support new "hash" and "dont_hash" policy actions
|
9 жил өмнө |
Sascha Hauer
|
ac0bf025d2
ima: Use i_version only when filesystem supports it
|
7 жил өмнө |
Dmitry Kasatkin
|
0d73a55208
ima: re-introduce own integrity cache lock
|
7 жил өмнө |
Bruno E. O. Meneguele
|
7c9bc0983f
ima: check signature enforcement against cmdline param instead of CONFIG
|
7 жил өмнө |
Boshi Wang
|
ebe7c0a7be
ima: fix hash algorithm initialization
|
7 жил өмнө |
Christoph Hellwig
|
a7d3d0392a
integrity: use kernel_read_file_from_path() to read x509 certs
|
8 жил өмнө |
Mimi Zohar
|
f3cc6b25dc
ima: always measure and audit files in policy
|
8 жил өмнө |
Lans Zhang
|
20f482ab9e
ima: allow to check MAY_APPEND
|
8 жил өмнө |
Mimi Zohar
|
bc15ed663e
ima: fix ima_d_path() possible race with rename
|
8 жил өмнө |
Mimi Zohar
|
3f23d624de
ima: store the builtin/custom template definitions in a list
|
8 жил өмнө |