2016-06-16KEYS: potential uninitialized variableDan Carpenter1-1/+1
2016-06-03KEYS: Add placeholder for KDF usage with DHStephan Mueller4-6/+13
2016-05-27Merge branch 'for-linus' of git:// Torvalds1-1/+1
2016-05-27switch ->setxattr() to passing dentry and inode separatelyAl Viro1-1/+1
2016-05-26Yama: fix double-spinlock and user access in atomic contextJann Horn1-6/+63
2016-05-20security/integrity/ima/ima_policy.c: use %pU to output UUID in printable formatAndy Shevchenko1-12/+2
2016-05-19Merge branch 'next' of git:// Torvalds34-185/+909
2016-05-17Merge git:// Torvalds1-1/+3
2016-05-17Merge branch 'work.const-path' of git:// Torvalds13-106/+83
2016-05-17Merge branch 'for-linus' of git:// Torvalds4-14/+15
2016-05-17Merge branch 'timers-core-for-linus' of git:// Torvalds2-2/+2
2016-05-17LSM: LoadPin: provide enablement CONFIGKees Cook2-6/+15
2016-05-17Merge branch 'ovl-fixes' into for-linusAl Viro1-2/+2
2016-05-09Merge git:// S. Miller1-2/+2
2016-05-06Merge branch 'stable-4.7' of git:// in...James Morris5-60/+127
2016-05-06Merge tag 'keys-next-20160505' of git:// Morris19-112/+516
2016-05-04Yama: use atomic allocations when reportingSasha Levin1-2/+2
2016-05-04Merge branch 'keys-trust' into keys-nextDavid Howells10-62/+128
2016-05-04ima: fix the string representation of the LSM/IMA hook enumeration orderingMimi Zohar1-2/+2
2016-05-01ima: add support for creating files using the mknodat syscallMimi Zohar2-1/+29
2016-05-01ima: fix ima_inode_post_setattrMimi Zohar2-1/+2
2016-04-26selinux: apply execstack check on thread stacksStephen Smalley1-2/+3
2016-04-26selinux: distinguish non-init user namespace capability checksStephen Smalley2-17/+25
2016-04-22security: Introduce security_settime64()Baolin Wang2-2/+2
2016-04-21LSM: LoadPin for kernel file loading restrictionsKees Cook6-0/+205
2016-04-21Yama: consolidate error reportingKees Cook1-10/+21
2016-04-20rtnetlink: add new RTM_GETSTATS message to dump link statsRoopa Prabhu1-1/+3
2016-04-19selinux: check ss_initialized before revalidating an inode labelPaul Moore1-1/+1
2016-04-19selinux: delay inode label lookup as long as possiblePaul Moore1-8/+13
2016-04-19selinux: don't revalidate an inode's label when explicitly setting itPaul Moore1-2/+11
2016-04-14selinux: Change bool variable name to index.Prarit Bhargava2-4/+4
2016-04-12KEYS: Add KEYCTL_DH_COMPUTE commandMat Martineau6-0/+193
2016-04-12Security: Keys: Big keys stored encryptedKirill Marinushkin2-18/+184
2016-04-12KEYS: user_update should use copy of payload made during preparsingDavid Howells1-31/+11
2016-04-12security: integrity: Remove select to deleted option PUBLIC_KEY_ALGO_RSAAndreas Ziegler1-1/+0
2016-04-11IMA: Use the the system trusted keyrings instead of .ima_mokDavid Howells4-53/+32
2016-04-11KEYS: Remove KEY_FLAG_TRUSTED and KEY_ALLOC_TRUSTEDDavid Howells3-39/+4
2016-04-11KEYS: Move the point of trust determination to __key_link()David Howells2-4/+35
2016-04-11KEYS: Add a facility to restrict new links into a keyringDavid Howells8-33/+124
2016-04-11->getxattr(): pass dentry and inode as separate argumentsAl Viro4-10/+11
2016-04-11security: drop the unused hook skb_owned_byPaolo Abeni1-1/+0
2016-04-10don't bother with ->d_inode->i_sb - it's always equal to ->d_sbAl Viro3-4/+4
2016-04-05selinux: restrict kernel module loadingJeff Vander Stoep2-1/+48
2016-04-05selinux: consolidate the ptrace parent lookup codePaul Moore1-21/+17
2016-04-05selinux: simply inode label states to INVALID and INITIALIZEDPaul Moore2-4/+3
2016-04-05selinux: don't revalidate inodes in selinux_socket_getpeersec_dgram()Paul Moore1-3/+5
2016-03-28constify ima_d_path()Al Viro2-2/+2
2016-03-28constify security_sb_pivotroot()Al Viro2-2/+2
2016-03-28constify security_path_chroot()Al Viro2-2/+2
2016-03-28constify security_path_{link,rename}Al Viro3-9/+9