Linux Security Modules development
 help / color / mirror / Atom feed
 messages from 2026-10-03 02:51:53 to 2026-10-08 14:27:26 UTC [more...]

[PATCH 00/27] landlock: Selftest fixes and cleanups
 2026-10-08 14:25 UTC  (18+ messages)
` [PATCH 01/27] selftests/landlock: Propagate grandchild failures in unix_scoping
` [PATCH 02/27] selftests/landlock: Propagate EXPECT failures from forked children
` [PATCH 03/27] selftests/landlock: Check the thread result in audit.thread
` [PATCH 04/27] selftests/landlock: Zero-initialize the buffer in inconsistent_attr
` [PATCH 05/27] selftests/landlock: Fix the openat() success check in fs_bench
` [PATCH 06/27] selftests/landlock: Fix the reported clock tick rate "
` [PATCH 07/27] selftests/landlock: Fix the ruleset_fd check in empty_or_same_ruleset
` [PATCH 08/27] selftests/landlock: Handle a missing control message in recv_fd()
` [PATCH 09/27] selftests/landlock: Assert tracefs_extract_field() results that are used
` [PATCH 10/27] selftests/landlock: Assert audit initialization in fixture setups
` [PATCH 11/27] selftests/landlock: Assert helper results that are used afterwards
` [PATCH 12/27] selftests/landlock: Assert audit_count_records() before using its result
` [PATCH 13/27] selftests/landlock: Fix memory leak in audit_init_filter_exe()
` [PATCH 14/27] selftests/landlock: Make audit_message large enough for any exe filter
` [PATCH 15/27] selftests/landlock: Close leaked file descriptors
` [PATCH 16/27] selftests/landlock: Check errno for combined VERSION and ERRATA flags
` [PATCH 17/27] selftests/landlock: Fix SIGURG handler setup in scoped_signal_test

[RFC PATCH 0/2] keys: Address lookup_user_key() mutability
 2026-10-08 14:26 UTC  (6+ messages)

[PATCH 0/5] capabilities: close the ways around the CAP_SETFCAP rule for uid 0
 2026-10-08 13:57 UTC  (12+ messages)
` [PATCH 1/5] cred: record how far up CAP_SETFCAP reaches
` [PATCH 2/5] userns: don't let setns() lend the right to map uid 0
` [PATCH 3/5] userns: check the writer too before mapping "
` [PATCH 4/5] capabilities: limit fscaps to where CAP_SETFCAP reaches
` [PATCH 5/5] capabilities: don't let ptrace borrow CAP_SETFCAP

[PATCH] landlock: Move the domain layer counter out of the anonymous union
 2026-10-08 11:49 UTC  (4+ messages)

[PATCH RFC 0/3] security: ima: support TSM measurement registers
 2026-10-08 11:10 UTC  (5+ messages)

[PATCH] keys: Avoid the owner account dereference in named keyring lookup
 2026-10-08  6:44 UTC  (2+ messages)

[PATCH] keys: Protect the type name while describing a key
 2026-10-08  6:41 UTC  (2+ messages)

[PATCH 6.6.y 0/2] apparmor: backport CVE-2026-45893, CVE-2026-46254
 2026-10-08  5:56 UTC  (6+ messages)
` [PATCH 6.6.y 1/2] AppArmor: Allow apparmor to handle unaligned dfa tables
` [PATCH 6.6.y 2/2] apparmor: Fix & Optimize table creation from possibly unaligned memory

[PATCH] apparmor: avoid potential double free when remapping DFA tables
 2026-10-08  3:31 UTC  (2+ messages)

[PATCH net v2] cipso: adjust cached option offsets when removing CIPSO
 2026-10-08  2:30 UTC  (5+ messages)

[PATCH net] calipso: update payload_len when removing the CALIPSO option
 2026-10-07 20:45 UTC  (2+ messages)

[PATCH net-next] calipso: hash the cache key, not the option start, in calipso_cache_add()
 2026-10-07 15:33 UTC  (2+ messages)

[PATCH 1/3] keys: add KEY_SPEC_DM_VERITY_KEYRING
 2026-10-07 15:30 UTC  (7+ messages)
` [PATCH 0/3] keys: Add well known IDs for fs-verity/dm-verity keys

[syzbot] [lsm?] general protection fault in smack_inode_permission (4)
 2026-10-07 15:22 UTC  (2+ messages)

[PATCH v5 0/8] Landlock: Namespace and capability control
 2026-10-07 10:23 UTC  (17+ messages)
` [PATCH v5 1/8] landlock: Rename quiet_masks to quiet_access
` [PATCH v5 2/8] landlock: Wrap per-layer access masks in struct layer_config
` [PATCH v5 3/8] landlock: Enforce namespace use restrictions
` [PATCH v5 4/8] landlock: Enforce capability restrictions
` [PATCH v5 5/8] selftests/landlock: Add namespace restriction tests
` [PATCH v5 6/8] selftests/landlock: Add capability "
` [PATCH v5 7/8] samples/landlock: Add capability and namespace restriction support
` [PATCH v5 8/8] landlock: Add documentation for capability and namespace restrictions

[PATCH] keys: make keyring indexes independent of kernel addresses
 2026-10-06 22:46 UTC  (2+ messages)

[PATCH 0/6] ipe: cleanups, an audit fix and updated links
 2026-10-06 16:59 UTC  (14+ messages)
` [PATCH 1/6] ipe: constify token_default()
` [PATCH 2/6] ipe: use designated initializers for audit name tables
` [PATCH 3/6] ipe: check parser token table sizes
` [PATCH 4/6] ipe: correct policy text ownership comment
` [PATCH 5/6] ipe: fix enforcement audit
` [PATCH 6/6] ipe: update the project and test suite links

[PATCH RFC -next 00/12] landlock: Add READ_METADATA and WRITE_METADATA access rights
 2026-10-06 15:31 UTC  (5+ messages)
` [PATCH RFC -next 03/12] fs: pass struct path to xattr helpers
` [PATCH RFC -next 07/12] LSM: pass struct path to the inode posix acl hooks

[RFC PATCH bpf-next 00/12] fs: unified VFS ancestor walk for Landlock and BPF
 2026-10-06 14:58 UTC  (34+ messages)
` [RFC PATCH bpf-next 01/12] namei: introduce __path_walk_parent()
` [RFC PATCH bpf-next 02/12] namei: add vfs_walk_ancestors()
` [RFC PATCH bpf-next 03/12] landlock: convert ancestor walk to vfs_walk_ancestors()
` [RFC PATCH bpf-next 04/12] bpf: mark struct path trusted
` [RFC PATCH bpf-next 05/12] namei: make vfs_walk_ancestors() stepwise
` [RFC PATCH bpf-next 06/12] bpf: add a path ancestor iterator
` [RFC PATCH bpf-next 07/12] selftests/bpf: exercise the "
` [RFC PATCH bpf-next 08/12] fs: add mnt_undo_legitimize()
` [RFC PATCH bpf-next 09/12] namei: add an rcu-walk mode to the ancestor walk
` [RFC PATCH bpf-next 10/12] bpf: support "__uninit" iterator arguments in generic kfuncs
` [RFC PATCH bpf-next 11/12] bpf: add a lockless path ancestor iterator
` [RFC PATCH bpf-next 12/12] selftests/bpf: exercise the "

[PATCH] landlock: Fix superblock use-after-free in release_inode()
 2026-10-06 11:08 UTC  (2+ messages)

[PATCH v4 0/8] Landlock: Namespace and capability control
 2026-10-06  9:57 UTC  (10+ messages)
` [PATCH v4 5/8] selftests/landlock: Add namespace restriction tests
` [PATCH v4 6/8] selftests/landlock: Add capability "
` [PATCH v4 7/8] samples/landlock: Add capability and namespace restriction support

[PATCH net] cipso: adjust cached option offsets when removing CIPSO
 2026-10-05 22:38 UTC  (2+ messages)

[PATCH v2] keys/trusted_keys: reuse TPM version in option handling
 2026-10-05 21:57 UTC  (6+ messages)

[PATCH v4 00/11] seq_buf: Add seq_buf_strlen()
 2026-10-05 16:43 UTC  (38+ messages)
` [PATCH v4 01/11] seq_buf: Do not print an empty line from an overflowed seq_buf_do_printk()
` [PATCH v4 02/11] seq_buf: Do not pop from an overflowed seq_buf
` [PATCH v4 03/11] seq_buf: Copy what fits when seq_buf_puts() and seq_buf_putmem() overflow
` [PATCH v4 04/11] seq_buf: Clear what a writer did not claim when a seq_buf overflows
` [PATCH v4 05/11] seq_buf: Add seq_buf_strlen()
` [PATCH v4 06/11] seq_buf: Add seq_buf_terminate()
` [PATCH v4 07/11] bpf: Remove dead newline stripping from format_disasm_line()
` [PATCH v4 08/11] seq_buf: Add seq_buf_init_append()
` [PATCH v4 09/11] powerpc/papr_scm: Return the string length from the sysfs show functions
` [PATCH v4 10/11] nvdimm: ndtest: Return the string length from flags_show()
` [PATCH v4 11/11] docs: core-api: Document the seq_buf API

[PATCH v5 02/12] seq_buf: Do not pop from an overflowed seq_buf
 2026-10-05 16:02 UTC  (2+ messages)

[GIT PULL] selinux/selinux-pr-20261005
 2026-10-05 14:41 UTC  (2+ messages)

[PATCH v3] keys/trusted_keys: reuse TPM version in option handling
 2026-10-05  7:39 UTC  (2+ messages)

[PATCH v3 0/2] keys: Fix ownership lifetime and accounting races
 2026-10-05  6:39 UTC  (8+ messages)
` [PATCH v3 1/2] keys: Protect key_user lifetime during ownership changes
` [PATCH v3 2/2] keys: Serialize ownership transfers with key accounting

[PATCH 0/2] SafeSetID: use real GID for GID policy lookups
 2026-10-04 22:05 UTC  (6+ messages)
` [PATCH 1/2] security: safesetid: use real GID for GID policy lookup
` [PATCH 2/2] selftests/safesetid: test GID policy with mismatched real IDs

[PATCH] tomoyo: Enforce connect policy in TCP Fast Open
 2026-10-04 14:20 UTC  (4+ messages)

[PATCH 01/11] params: bound array element output to the caller's page buffer
 2026-10-04 10:47 UTC  (2+ messages)

[syzbot] Monthly lsm report (Oct 2026)
 2026-10-03  4:33 UTC 


This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox