Linux Security Modules development
 help / color / mirror / Atom feed
 messages from 2026-08-12 20:18:26 to 2026-08-26 13:05:34 UTC [more...]

[PATCH 0/3] proc,security,selinux: let SELinux block FOLL_FORCE for /proc/self/mem
 2026-08-26 13:05 UTC  (36+ messages)
` [PATCH 1/3] proc: refactor /proc/$pid/mem to use struct as private_data
` [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
` [PATCH 3/3] selinux: require EXECMEM or PTRACE for FOLL_FORCE introspection

[PATCH] selftests/landlock: Fix snprintf truncation checks in test files
 2026-08-26 10:44 UTC  (3+ messages)

[PATCH] ima: bound line scan in ima_read_policy() to fix OOB read
 2026-08-26  9:51 UTC  (2+ messages)

[PATCH v20 0/8] rust: add `Ownable` trait and `Owned` type
 2026-08-26  9:29 UTC  (17+ messages)
` [PATCH v20 1/8] rust: alloc: add `KBox::into_non_null`
` [PATCH v20 2/8] rust: types: Add Ownable/Owned types
` [PATCH v20 3/8] rust: implement `ForeignOwnable` for `Owned`
` [PATCH v20 4/8] rust: page: convert to `Ownable`
  ` [PATCH v20 4/8] rust: page: convert to `Ownable`'
` [PATCH v20 5/8] rust: rename `AlwaysRefCounted` to `RefCounted`
` [PATCH v20 6/8] rust: Add missing SAFETY documentation for `ARef` example
` [PATCH v20 7/8] rust: Add `OwnableRefCounted`
` [PATCH v20 8/8] rust: page: add `from_raw()`

[PATCH v2 0/2] ima: don't measure/appraise files on configfs
 2026-08-26  8:07 UTC  (7+ messages)
` [PATCH v2 1/2] configfs: move CONFIGFS_MAGIC definition to magic.h
` [PATCH v2 2/2] ima: don't measure/appraise files on configfs

[RFC PATCH] smack: preserve low-integrity labels on copy via whitelist
 2026-08-26  3:33 UTC 

[RFC PATCH 00/24] pidfd: add a minimal process spawn builder
 2026-08-25 21:27 UTC  (7+ messages)
` [RFC PATCH 12/24] fork: let kernel callers create embryonic tasks

[PATCH v2 0/3] proc,security,selinux: let SELinux block FOLL_FORCE for /proc/self/mem
 2026-08-25 19:30 UTC  (5+ messages)
` [PATCH v2 1/3] proc: refactor /proc/$pid/mem to use struct as private_data
` [PATCH v2 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
` [PATCH v2 3/3] selinux: require PROCESS__PTRACE for FOLL_FORCE introspection

[PATCH] keys: translate request_key_auth pid for the reading procfs instance
 2026-08-25 14:10 UTC  (2+ messages)

[PATCH v2] keys: fix lost wakeup when reaping a dead key type
 2026-08-25 14:07 UTC  (2+ messages)

[Bug] landlock: sun_path length underflow to SIZE_MAX in landlock_deny_scope_abstract_unix_socket TP_printk -> unbounded OOB read in trace reader
 2026-08-25 13:00 UTC 

[PATCH] apparmor: fix NULL ctx->peer derefs in unix socket ctx updates
 2026-08-24 21:32 UTC  (2+ messages)

[RFC PATCH 0/3] smack: add file label preserve mechanism
 2026-08-24 17:57 UTC  (3+ messages)
    ` 回复: "
        ` 回复: "

[PATCH] ima: allow users to specify the pcr index with IMA_MEASURE_PCR_IDX
 2026-08-24 16:22 UTC 

[PATCH v2 0/6] landlock: Add scoped access bit for SysV message queues
 2026-08-24 16:03 UTC  (14+ messages)
` [PATCH v2 3/6] landlock: Bump ABI for LANDLOCK_SCOPE_SYSV_MSG_QUEUE
` [PATCH v2 4/6] selftests/landlock: Test LANDLOCK_SCOPE_SYSV_MSG_QUEUE

[PATCH] ima: reject modsig if detached data cannot be supplied
 2026-08-24 16:00 UTC  (2+ messages)

[PATCH] ima: clean up IMA_MEASURE_PCR_IDX in Kconfig
 2026-08-24 15:54 UTC  (3+ messages)

[RFC] IMA: periodic runtime re-measurement of process .text/GOT
 2026-08-24 14:22 UTC  (6+ messages)

[PATCH 0/2] lsm: expose mount idmaps to inode hooks
 2026-08-24 13:28 UTC  (3+ messages)
` [PATCH 1/2] "
` [PATCH 2/2] selftests/bpf: verify mount idmaps reach "

[PATCH] keys: reject descriptions that exceed the index length
 2026-08-24 11:30 UTC 

[syzbot] [apparmor?] WARNING in aa_policy_destroy
 2026-08-24  6:07 UTC 

[PATCH] keys: Fix key_user use-after-free during ownership changes
 2026-08-23 17:08 UTC  (2+ messages)

[PATCH] keys: Fix key_user use-after-free during ownership changes
 2026-08-23 15:28 UTC 

[GIT PULL] capabilities update for v7.3
 2026-08-22 21:06 UTC  (4+ messages)

[PATCH] landlock: Fix use-after-free of the source's parent directory
 2026-08-22 12:29 UTC 

[GIT PULL] Landlock update for v7.3-rc1
 2026-08-21 20:26 UTC  (2+ messages)

[PATCH RESEND v3] hardening: Default randstruct off with rust for better allmodconfig support
 2026-08-21 19:48 UTC  (3+ messages)

[PATCH 0/4] CRASH_ZEROIZE: Wipe secrets before kdump
 2026-08-21 14:28 UTC  (7+ messages)
` [PATCH 3/4] mm/secretmem: zeroize secret pages "

[PATCH 0/6] landlock: Add POSIX message queue scoping
 2026-08-21  8:46 UTC  (2+ messages)

[PATCH v4 0/5] Fix quota evasion on xfs and add capable_noaudit
 2026-08-21  7:35 UTC  (5+ messages)
` [PATCH v4 1/5] xfs: fix capability check in xfs

[PATCH 0/3] lib/crypto: Provide a function for zeroizing hmac_sha1_ctx
 2026-08-21  0:03 UTC  (4+ messages)

[PATCH] keys: fix lost wakeup when reaping a dead key type
 2026-08-20 23:28 UTC  (2+ messages)

keys: request_key_auth shows a global pid in /proc/keys across pid namespaces
 2026-08-20 21:57 UTC  (2+ messages)

[PATCH v4 00/19] Landlock tracepoints
 2026-08-20 10:45 UTC  (9+ messages)
` [PATCH v4 01/19] landlock: Prepare ruleset and domain type split
` [PATCH v4 03/19] landlock: Split struct landlock_domain from struct landlock_ruleset
` [PATCH v4 05/19] landlock: Decouple the per-denial logging decision from CONFIG_AUDIT
` [PATCH v4 09/19] landlock: Add create_domain and free_domain tracepoints

[PATCH RFC 0/3] pidfd: add task path ioctls
 2026-08-20  5:45 UTC  (4+ messages)
` [PATCH RFC 1/3] fs: Introduce task path helpers
` [PATCH RFC 2/3] pidfd: Use scoped cleanup for task access
` [PATCH RFC 3/3] pidfd: Add task path ioctls

[GIT PULL] lsm/lsm-pr-20260814
 2026-08-20  0:55 UTC  (2+ messages)

[GIT PULL] Smack patches for 7.3
 2026-08-20  0:55 UTC  (2+ messages)

[GIT PULL] selinux/selinux-pr-20260814
 2026-08-20  0:55 UTC  (2+ messages)

[PATCH 0/2] ima: don't measure/appraise files on configfs
 2026-08-19 18:39 UTC  (6+ messages)
` [PATCH 1/2] configfs: move CONFIGFS_MAGIC definition to magic.h
` [PATCH 2/2] ima: don't measure/appraise files on configfs

[PATCH bpf-next 0/2] lsm: give BPF programs a way to query locked_down state
 2026-08-18 20:41 UTC  (17+ messages)
` [PATCH bpf-next 1/2] lsm: add bpf_security_locked_down() kfunc
` [PATCH bpf-next 2/2] selftests/bpf: Test bpf_security_locked_down kfunc

[syzbot] [lsm?] [integrity?] possible deadlock in ima_file_truncate
 2026-08-18 19:39 UTC  (6+ messages)

[PATCH v2 00/13] CRASH_WIPE_SECRETS: Wipe secrets before kdump (was: CRASH_ZEROIZE)
 2026-08-18  9:03 UTC  (8+ messages)
` [PATCH v2 01/13] kexec: add CRASH_WIPE_SECRETS to wipe secrets before kdump

IT教育で、新規事業
 2026-08-18  2:02 UTC 

[REGRESSION] Apparmor deadlock in 6.12.101 in complain mode
 2026-08-17 12:21 UTC  (2+ messages)

[PATCH v6 0/6] landlock: Restrict whiteout object creation
 2026-08-14 10:47 UTC  (9+ messages)
` [PATCH v6 1/6] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test
` [PATCH v6 2/6] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
` [PATCH v6 3/6] selftests/landlock: Add tests for whiteout object creation
` [PATCH v6 4/6] selftests/landlock: Add audit test "
` [PATCH v6 5/6] selftests/landlock: Test whiteout object behaviour in OverlayFS renames
` [PATCH v6 6/6] landlock: Link the erratum documentation for whiteout objects

[PATCH 0/7] Change skb secmarks to x-array indexes
 2026-08-13 20:48 UTC  (8+ messages)
  ` [PATCH 1/7] net, smack: Create a function to set secmarks
  ` [PATCH 2/7] LSM: Implement x array functions for secmarks
  ` [PATCH 3/7] LSM: Two hooks for manipulating struct lsm_prop
  ` [PATCH 4/7] SELinux: hooks for secctx_to_lsmprop and update_lsmprop
  ` [PATCH 5/7] Smack: "
  ` [PATCH 6/7] Apparmor: "
  ` [PATCH 7/7] net, lsm: Change skb secmarks to x-array indexes

[PATCH] lsm: update the BUILD_BUG_ON() in audit_log_lsm_data()
 2026-08-13 18:37 UTC  (2+ messages)

[PATCH v4 0/5] landlock: Restrict whiteout object creation
 2026-08-12 20:18 UTC  (4+ messages)
` [PATCH v4 4/5] selftests/landlock: Test whiteout object behaviour in OverlayFS renames


This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox