Skip Research MenusResearch Menu
|
- Walter Steenvoorden (Sun 23 Apr 2006 - 01:32:57 EDT)
- kayo (Mon 17 Feb 2003 - 15:31:59 EST)
- david caplan (Thu 29 Aug 2002 - 13:32:25 EDT)
- Ed Street (Wed 24 Jul 2002 - 17:45:29 EDT)
- CHEN Mike (Wed 27 Feb 2002 - 07:32:29 EST)
- "Additional Documentation for..." -- where are these?
- "denied null" AVCs from qemu-kvm with latest rawhide policy
- "HASHTAB_OVERFLOW" undeclared
- "new" SELinux 2.4.22 UML kernel patch + sample Debian filesystem
- "Policy inclusion" tool ... ?
- "semanage login -l" is working on F8?
- "Unable to mount root fs on unknown-block(0,0)"
- "use"
- $1_cupsd_spool_t in lpr_macros.te
- $1_domain attribute
- $1_file_type policy patch
- 'chcon': possible weakness
- 'name_connect' undefined!
- (ANN: SELinux Policy Modules) announcement dealy
- (Capital Area) SE Linux user group
- (forw) [bruce@momjian.us: [ANNOUNCE] Need help on possible PG 8.4 security features]
- (fwd) Bug#270919: Can you test a new version of sysvinit?
- (new?) problems installing with checkinstall
- (no subject)
- (u|r)bacsep: initial testing
- .fonts-cache being created as user_home_dir_t
- .journal
- /bin/login
- /bin/passwd and a basic MLS install of Fedora 8
- /boot
- /dev entries which also need to be /.?u?dev'd
- /dev/mem error starting X11
- /dev/null and /dev/zero
- /dev/pts/* denials w/devfs
- /dev/pts/x use denials
- /dev/pty*
- /dev/random
- /dev/tty
- /etc/magic
- /etc/mtab and namespaces
- /etc/passwd labeling issues
- /etc/qt3/.qt*
- /etc/resolv.conf
- /etc/security/default_context vs. /etc/security/default_contexts
- /etc/selinux/ directory structure...
- /etc/selinux/mls/contexts files labeled default_context_t
- /halt and /.autofsck
- /proc and chcon
- /proc file context
- /proc woes
- /selinux/create + X windows = performance limiter
- /selinux/enforce permissions
- /tmp
- /tmp and others
- /tmp/.font-unix debian bug raised
- /usr/bin/checkpolicy ?
- /usr/bin/firefox not mozilla_exec_t, why?
- /usr/local policy patch
- /usr/sbin/fstab-sync from HAL
- /var
- /var/lock
- /var/tmp/kdecache-username
- 115
- 2 checkpolicy bugs
- 2 problems inetd & run_init ---
- 2.2 kernel series
- 2.4-based SELinux
- 2.4.13?
- 2.4.16 release, ipsec, roles and ECHILD errors
- 2.4.17 support?
- 2.4.19 lsm kernel patch
- 2.4.20
- 2.4.20 stability issues
- 2.4.23
- 2.4.x porting
- 2.6 error
- 2.6 install guide
- 2.6.0 selinux reiserfs labeling
- 2.6.0-test3
- 2.6.0-test3 and UML
- 2.6.0-test4 is released
- 2.6.0-test6 boot process failures
- 2.6.0-test6 login/avc denied
- 2.6.19.2 Oops
- 2.6.2-rc2 kernel...more comments
- 2.6.24-rc8-mm1 and SELinux MLS - not playing nice....
- 2.6.25
- 2.6.25-rc5
- 2.6.26 Debian kernel panic
- 2.6.26-rc5-mm1 selinux whine)
- 2.6.9-rc2-mm4-VP-S7 - ksoftirq and selinux oddity
- 2002050211
- 2003071106 on RH 7.2
- 2007 SELinux Symposium dates and call for papers
- 2007 SELinux Symposium papers and slides are posted
- 3.6.3 policy on fc10 and kerneloops
- 32bit -> 64bit x-compile fail (audit2why)
- 32bit / 64bit support
- 7 simple noobie questions = 1-line answers ok :)
- 7.1 installation
- 8.3 filenames
- ?
- ?????: VFS, NFS security bug? Should CAP_MKNOD and CAP_LINUX_IMMUTABLE be added to CAP_FS_MASK?
- [ 1/9 ] [ SEPOL ] Eliminate struct pointer typedefs
- [ 2/9 ] [ SEMANAGE ] Restore sepol compatibility
- [ 3/9 ] [ SEMANAGE ] Rename files
- [ 4/9 ] [ SEMANAGE ] Database initialization Stage 1
- [ 5/9 ] [ SEMANAGE ] Change database to singly-linked list
- [ 6/9 ] [ SEMANAGE ] Database Initialization Stage 2
- [ 7/9 ] [ SEMANAGE ] Backend separation (Init 3)
- [ 8/9 ] [ SEMANAGE ] Eliminate struct pointer typedefs
- [ 9/9 ] [ SEPOL ] User list function, Bugfixes
- [ LIBSEMANAGE ] Cleanup patch (resync-ed)
- [ libsemanage ] Key extract function
- [ libsemanage ] Relay libsepol records
- [ LIBSEMANAGE ] Runtime control over preservebools argument
- [ libsepol 0/6] Context reorganization
- [ libsepol 1/6] Fix memory leaks
- [ libsepol 10 ] Bugfixes for 0-9
- [ libsepol 2/6] Ports
- [ libsepol 3/6] Users
- [ libsepol 4/6] Booleans
- [ libsepol 5/6] Policydb_convert in legacy
- [ libsepol 6/6] Summary
- [ libsepol 7/6] Interfaces
- [ libsepol 8/6] Cache corrections
- [ libsepol 9 ] remove printf from write and services
- [ libsepol ] User, context, port records. Bugfixes.
- [ PATCH ] Cumulative patch - various fixes, untrusted_content_t, mozilla, gnome types
- [ PATCH ] hal - create netlink socket
- [ PATCH ] home_domain macro / x_client cleanup patch
- [ PATCH ] restrict_home
- [ PATCH ] X clients cleanup patch #2
- [ PATCH ] X clients cleanup Patch #3
- [ PATCH ]: evolution/thunderbird/gconf/orbit/other stuff - comments?
- [ PATCHES ] mozilla, gift, games, orbit, gconf, genhomedircon
- [ policycoreutils ] Resend: make restorecon print status messages to stdout
- [ RESEND ] [ SEMANAGE ] Debugging system
- [ RESEND ] Fedora Rawhide mplayer policy
- [ SELINUX ] [ POLICYCOREUTILS ] Convert setsebool -P to use libsemanage
- [ SELINUX ] Make rpm_execcon failure non-fatal in permissive mode.
- [ SEMANAGE 2 ] Booleans, parser fixes/improvements
- [ SEMANAGE 2 ] Database modification tracking, and cleanup
- [ SEMANAGE 2 ] Fix bug in dbase_file_flush
- [ SEMANAGE 2 ] Fix dbase transactions
- [ SEMANAGE 2 ] Seusers
- [ SEMANAGE 3 ] Common database code
- [ SEMANAGE 3 ] Fix evil strtol bug (breaks booleans)
- [ SEMANAGE 3 ] Push assert_noeof into parse_utils, fix bug
- [ SEMANAGE 3 ] Simplify and fix dbase_policydb_cache
- [ SEMANAGE 4 ] Copyright
- [ SEMANAGE 4 ] Order-preserving file dbase
- [ SEMANAGE ] [ SEPOL ] Backend iterate function
- [ SEMANAGE ] [ SEPOL ] Implement dbase_policydb_list
- [ SEMANAGE ] [ SEPOL ] More database work
- [ SEMANAGE ] [ SEPOL ] Pass handle to user/boolean/interface, and port APIs
- [ SEMANAGE ] Acquire/release read lock in databases
- [ SEMANAGE ] Add a few direct dbases to handle
- [ SEMANAGE ] Add more databases - booleans and interfaces
- [ SEMANAGE ] Add more error messages...
- [ SEMANAGE ] Add parse/print error messages
- [ SEMANAGE ] Assert whitespace between records
- [ SEMANAGE ] Break up interfaces.h, implement parsing helpers
- [ SEMANAGE ] Bugfix previous patches
- [ SEMANAGE ] Cleanup : move some things around
- [ SEMANAGE ] Clear obsoleted objects
- [ SEMANAGE ] Complete query APIs for in-policy objects
- [ SEMANAGE ] Completely split database per backend
- [ SEMANAGE ] dbase initialization/semanage_handle stub/fixes
- [ SEMANAGE ] Default database
- [ SEMANAGE ] Enable things for testing, add missing set relay
- [ SEMANAGE ] Fix and make consistent interface naming
- [ SEMANAGE ] Fix hidden declarations
- [ SEMANAGE ] Fix MLS parsing of users
- [ SEMANAGE ] Fix record handlers, add status codes
- [ SEMANAGE ] Implement dbase_file_set, fix memleak
- [ SEMANAGE ] Infrastucture patch
- [ SEMANAGE ] Install seusers, rename some files
- [ SEMANAGE ] Interfaces, more parser things
- [ SEMANAGE ] Introduce record table
- [ SEMANAGE ] More dbase things
- [ SEMANAGE ] More work on policy_components.c
- [ SEMANAGE ] Move local dbase initialization
- [ SEMANAGE ] Move seuser validation to proper place
- [ SEMANAGE ] Redesign dbase
- [ SEMANAGE ] Remove connection requirement from POLICYDB backend
- [ SEMANAGE ] Remove unused relay functions
- [ SEMANAGE ] Rename direct -> policydb as appropriate
- [ SEMANAGE ] Replace semanage debugging system
- [ SEMANAGE ] Resync to sepol changes
- [ SEMANAGE ] Resync to sepol changes (again)
- [ SEMANAGE ] Seuser database
- [ SEMANAGE ] Seuser record
- [ SEMANAGE ] Some seusers mapping validation
- [ SEMANAGE ] Stub iterate
- [ SEMANAGE ] Stub kernel booleans API
- [ SEMANAGE ] Stub out user/port functionality
- [ SEMANAGE ] Stub pserver backend
- [ SEMANAGE ] Stub record handlers
- [ SEMANAGE ] User and port apis - policy database
- [ SEMANAGE] Resync seuser parser
- [ SEPOL 2 ] [ SEMANAGE 4 ] Record bugfixes
- [ SEPOL 2 ] Context_to_record function
- [ SEPOL 2 ] Count functions
- [ SEPOL 2 ] More debug things
- [ SEPOL 3 ] Fix MLS memory leaks: interfaces/ports/users
- [ SEPOL 3 ] Improve/fix sepol_user_set_roles
- [ SEPOL 3 ] Interfaces, ports, booleans - record conversion fn
- [ SEPOL 4 ] user - to_record fn, mls cleanups
- [ SEPOL 5 ] Pass key to sepol
- [ SEPOL 6 ] Fix all the bugs
- [ SEPOL ] [ SEMANAGE 2] Fix spec for sepol_context_to_string
- [ SEPOL ] [ SEMANAGE ] Debug v3, some database things
- [ SEPOL ] [ SEMANAGE ] Fix record interfaces
- [ SEPOL ] Add sepol_policydb_mls_enabled, organize map file
- [ SEPOL ] Another debugging system
- [ SEPOL ] Check if policy file is MLS enabled
- [ SEPOL ] Context interface cleanup
- [ SEPOL ] Detach old debug system from new
- [ SEPOL ] Extract user records from binary policy
- [ SEPOL ] Fix memory leaks
- [ SEPOL ] Fix usage of context_destroy - correct memory leaks/null derefs
- [ SEPOL ] Fix user record memory leak
- [ SEPOL ] Further users cleanup
- [ SEPOL ] Mls cleanups
- [ SEPOL ] Mls cleanups (2)
- [ SEPOL ] Move more things to newer debug system
- [ SEPOL ] Reorganize users.c
- [ SEPOL ] Users/booleans - add some missing functions
- [ SEPOL/SEMANAGE ] Boolean record
- [ SEPOL/SEMANAGE ] Interface record
- [ SETSEBOOL ] Cleanup patch
- [ SETSEBOOL ] Fix memory leak
- [1/4] Labeling only policy for fireflier
- [10 / 9] [ SEMANAGE ] FIx placement of function table
- [2.6 patch] selinux: cleanups
- [2.6 patch] selinux: possible cleanups
- [2/4] Labeling only policy for fireflier (fireflier.pp)
- [20/37] SELinux: no BUG_ON(!ss_initialized) in selinux_clone_mnt_opts
- [3/4] Labeling only policy for fireflier (example module)
- [4/4] Labeling only policy for fireflier (install)
- [ANN] 2008 SELinux Developer Summit Schedule Published
- [ANN] 2009 SELinux Developer Summit Call for Participation
- [ANN] Apache/SELinux plus release
- [ANN] BusyBox SELinux support
- [ANN] CDS Framework 3.3
- [ANN] CDS Framework 3.6
- [ANN] Certifiable Linux Integration Platform (CLIP)
- [ANN] CLIP mail list
- [ANN] CLIP v3.1.0 for RHEL 5.3
- [ANN] Community developer server accounts available
- [ANN] Developer Summit Mailing List
- [ANN] Linux Event Dispatcher
- [ANN] Madison policy generation tools
- [ANN] New policy representation branch
- [ANN] Now v8.3 based SE-PostgreSQL is available
- [ANN] Reference Policy mail list
- [ANN] SE-PostgreSQL 1.0 Beta released
- [ANN] SE-PostgreSQL 8.2.3-1.0 alpha release
- [ANN] SE-PostgreSQL 8.2.4-1.0 Released
- [ANN] segatex-4.00 RPM,SRPM released !!
- [ANN] segatex_suite 2.0 released
- [ANN] SELinux kernel project page
- [ANN] SELinux Policy Editor 1.3.1
- [ANN] SELinux Policy Editor 2.0(seedit 2.0)
- [ANN] SELinux Policy Editor 2.1.0
- [ANN] SELinux Symposium Delegate Program
- [ANN] SELinux userland repository, wiki and bug tracking on oss.tresys.com
- [ANN] SELinux userspace release
- [ANN] selinuxnews.org registration open
- [ANN] SETools - 3.0
- [ANN] SETools - 3.0.1
- [ANN] setools 1.4.1 release
- [ANN] Setools 2.0 released
- [ANN] SETools 3.2 Release
- [ANN] SETools 3.3 Release
- [ANN] SETools 3.3.1 Release
- [ANN] SETools-2.1.0 release
- [ANN] SETools-2.1.1 release
- [ANN] Setools-2.4
- [ANN] Stable branch created for selinux core userland
- [ANN] Updated SELinux userspace release and URL change
- [ANN] visreport-0.2: log data visualization for NSA SELinux and Netfilter Iptables
- [ANN]segatex-4.00 released !
- [ANN]segatex-4.90 released
- [ANNOUNCE] [LTP] The Linux Test Project has been Released for DECEMBER 2007
- [ANNOUNCE] Flask Policy Parser (FPP)
- [ANNOUNCE] NUMA Testcases has been integrated to LTP
- [Announce] RHEL5 LSPP/EAL4 Certification Testsuite has been released
- [Announce] RHEL5 LSPP/EAL4 Certification Testsuite has been released again
- [ANNOUNCE] Setools version 1.4 released
- [ANNOUNCE] The Linux Test Project has been Released for AUGUST 2007
- [ANNOUNCE] The Linux Test Project has been Released for FEBRUARY 2008
- [ANNOUNCE] The Linux Test Project has been Released for JANUARY 2008
- [ANNOUNCE] The Linux Test Project has been Released for SEPTEMBER 2007
- [Announce][Patch] Enhanced MLS support
- [Announce][Patch] PaX support in SELinux
- [ANNOUNCE][RFC] sVirt: Integrating SELinux and Linux-based virtualization
- [ANNOUNCE][RFC] sVirt: Integrating SELinux and Linux-basedvirtualization
- [autotools] libselinux build system comments
- [autotools][patch] AC_INIT macro fixes
- [autotools][patch] AC_INIT VERSION info fix + checkpolicy test
- [autotools][patch] libsepol build system comments
- [BETTER PATCH] support for altroot in setfiles
- [BUG] Segfault on duplicate require of sensitivity
- [BUGTRAQ] Linux patches to solve /tmp race problem
- [Clip] Unexpected role change from custom role back to user_r
- [Clip] Unexpected role change from custom role back to user_r SOLVED
- [debian] - installation of mysqld requires chfn
- [DEBIAN] module-init-tools 3.1-pre2 WATCH OUT - write permission requested!
- [debian] postfix chroot setup from /etc/init.d/postfix isn't working.
- [DO NOT COMMIT PATCH 1/2] SELinux: place avc_cache hlist and lock together - DO NOT COMMIT!!!
- [DO NOT COMMIT PATCH 2/2] SELinux: make avc_cache per cpu - DO NOT COMMIT
- [DSE-Dev] [libsemanage] Also check for the uppoer bound on user ids in /etc/login.defs
- [DSE-Dev] [martin@martinorr.name: /selinux getattr messages]
- [DSE-Dev] refpolicy HEAD, Debian, ioctl on xconsole by syslogd
- [DSE-Dev] Refpolicy quilt series for Debian
- [DSE-Dev] refpolicy: domains need access to the apt's pty and fifos
- [DSE-Dev] refpolicy: patch for ldconfig from glibc 2.7, new patch
- [DSE-Dev] refpolicy: patch for ldconfig from glibc2.7, new patch
- [fcron announce] Fcron 2.9.4 - a replacement for Vixie cron and anacron
- [fedora-selinux-list-bounces@redhat.com: Your message to fedora-selinux-list awaits moderator approval]
- [Fwd: [Fwd: Leveraging Security-Enhanced Linux in Your Data Center]]
- [Fwd: [idea] web-application security powered by SELinux]
- [Fwd: [PATCH 1/1] mount: shared-subtree support for mount]
- [Fwd: [patch 1/1] selinux: Disable setxattr on mountpoint labeled filesystems]
- [Fwd: [patch 1/1] selinux: Extend selinuxfs context interface]
- [Fwd: [patch 1/1] selinux: MLS compatibility]
- [Fwd: [PATCH] Add SELinux module to 2.5.74-bk1]
- [Fwd: [Patch] libsemanage: remember and retrieve dontaudit settings]
- [Fwd: [PATCH] refpolicy: admin_kudzu changes]
- [Fwd: [PATCH] refpolicy: services_w3c changes]
- [Fwd: [PATCH] refpolicy: system_fstools changes]
- [Fwd: [PATCH] refpolicy: system_init changes]
- [Fwd: [PATCH] refpolicy: system_iptables changes]
- [Fwd: [PATCH] refpolicy: system_locallogin changes]
- [Fwd: [redhat-lspp] mqueue filesystem labeling]
- [Fwd: additions to strict policy]
- [Fwd: Bug#231561: setfiles ignores patterns beginning with a meta-character]
- [Fwd: cups AVC...]
- [Fwd: excessively verbose policy]
- [Fwd: f8 X policy]
- [Fwd: f8 X policy]]
- [Fwd: FC: PGP and NSA link arms to create secure Linux version]
- [Fwd: gnome login broken.... "null" avcs...]
- [Fwd: How should we handle polmatch avcs?]
- [Fwd: Latest Diff]
- [Fwd: libsemanage API]
- [Fwd: load_policy problem]
- [Fwd: New policy patch]
- [Fwd: Partial TOC for Comment]
- [Fwd: policycoreutils patches]
- [Fwd: restorecon single fs patch]
- [Fwd: target policy 2.5.9-2 in fc7 prevent mono]
- [Fwd: type class key]
- [Fwd: Unable to create files when using "context"option for NFS]
- [gentoo-hardened] mysql 4.1 requires shlib_t:file execmod?
- [GIT PULL] pull request for lblnet-2.6_testing
- [gov-eng] Multithreaded applications, SELinux, and RAM Protection
- [HACKERS] [RFC] PostgreSQL Access Control Extension (PGACE)
- [idea] file contexts "alternate" keyword
- [idea] multiple contexts.
- [idea] udev + selinux
- [idea] udev + selinux]
- [IPsec] IPsec Security Context drafts
- [ISN] IBM earns Linux certification
- [ISN] Music file flaws could threaten traders
- [kvm-devel] [RFC][PATCH 00/01]qemu VM entrypoints
- [Labeled-nfs] [nfsv4] New MAC label support Internet Draft posted to IETF website
- [Labeled-nfs] [PATCH 08/13] NFS: Introduce lifecycle managment for label attribute.
- [Labeled-nfs] [PATCH 09/13] NFS: Client implementation of SELINUX Labeling
- [Labeled-nfs] [PATCH 13/13] NFSD: Label change notification for NFSv4 Server
- [Labeled-nfs] [PATCH 6/7] NFSv4: Client implementation of MAC Labeling
- [Labeled-nfs] [RFC v3] Security Label Support for NFSv4
- [Labeled-nfs] [RFC v4] Security Label Support for NFSv4
- [Labeled-nfs] New MAC label support Internet Draft posted to IETF website
- [latest cvs]: build error on printer_device_t not recognised
- [libsemanage] Also check for the uppoer bound on user ids in /etc/login.defs
- [libvirt] [ANNOUNCE][RFC] sVirt: Integrating SELinux and Linux-based virtualization
- [libvirt] [RFC] sVirt v0.10 - initial prototype
- [Linux-aus] Security Miniconf at LCA2005 (fwd)
- [Linux-cachefs] [PATCH 00/14] Permit filesystem local caching [try #2]
- [Linux-cachefs] [PATCH 01/14] FS-Cache: Release page->private after failed readahead [try #2]
- [Linux-cachefs] [PATCH 02/14] FS-Cache: Recruit a couple of page flags for cache management [try #2]
- [Linux-cachefs] [PATCH 03/14] FS-Cache: Provide an add_wait_queue_tail() function [try #2]
- [Linux-cachefs] [PATCH 05/14] CacheFiles: Add missing copy_page export for ia64 [try #2]
- [Linux-cachefs] [PATCH 06/14] CacheFiles: Add a hook to write a single page of data to an inode [try #2]
- [Linux-cachefs] [PATCH 07/14] CacheFiles: Permit the page lock state to be monitored [try #2]
- [Linux-cachefs] [PATCH 08/14] CacheFiles: Export things for CacheFiles [try #2]
- [Linux-cachefs] [PATCH 09/14] CacheFiles: Permit a process's create SID to be overridden [try #2]
- [Linux-cachefs] [PATCH 10/14] CacheFiles: Add an act-as SID override in task_security_struct [try #2]
- [Linux-cachefs] [PATCH 11/14] CacheFiles: Permit an inode's security ID to be obtained [try #2]
- [Linux-cachefs] [PATCH 12/14] CacheFiles: Get the SID under which the CacheFiles module should operate [try #2]
- [Linux-cachefs] [PATCH 14/14] NFS: Use local caching [try #2]
- [Linux-privs-discuss] SELinux & Linux-privs projects
- [LTP] [PATCH] Fix running of the selinux tests
- [LTP] [RFC] LTP IMA patch
- [LTP] compilation error @ selinux tests
- [LTP] Fwd: [PATCH] Create $SELINUXTMPDIR in each of the tests
- [LTP] Fwd: [PATCH] Fix an errorneous using of a different return value in selinux_entrypoint test
- [LTP] LTP SELinux policy error
- [LTP] Se-Linux Updates for LTP
- [LTP][PATCH 1/2] Replacement of deprecated interfaces
- [LTP][PATCH 2/2] Add a new test case for bounds types
- [martin@martinorr.name: [DSE-Dev] /selinux getattr messages]
- [NFS] [PATCH] introduce version field to struct nfs_clone_mount
- [nfsv4] [Labeled-nfs] New MAC label support Internet Draft posted to IETF website
- [nfsv4] my thoughts on how Labeled NFSv4 draft should move forward
- [nfsv4] New MAC label support Internet Draft posted to IETF website
- [OFT] Minor DOD security issue
- [OpenAFS-devel] openafs / opendfs collaboration)
- [OpenAFS] selinux afs domain v 0.2
- [OT] a trouble with posting to '*.@tycho.nsa.gov'
- [OT] SELinux symposium BoFs and WiPs
- [OT] SELinux vs. other systems]
- [OT] voice at SecureOS BoF : Japan Linux Conference 2008
- [owner@bugs.debian.org: Bug#249496 acknowledged by developer (Bug#249496: fixed in dpkg 1.13.9)]
- [owner@bugs.debian.org: Bug#249499 acknowledged by developer (Bug#249499: fixed in pam 0.79-1)]
- [owner@bugs.debian.org: Bug#258725 acknowledged by developer (Bug#258725: fixed in hotplug 0.0.20040329-17)]
- [owner@bugs.debian.org: Bug#271030 acknowledged by developer (Bug#271030: fixed in xfree86 4.3.0.dfsg.1-9)]
- [owner@bugs.debian.org: Bug#283372 acknowledged by developer (Bug#283372: fixed in wdm 1.28-1)]
- [owner@bugs.debian.org: Bug#338543 acknowledged by developer (Bug#338543: fixed in linux-2.6 2.6.14-3)]
- [PAT CH 01/06] MLSXFRM: Granular IPSec associations for use in MLS environmen ts)
- [PATCH - policyrep] Add generic iterators and a linked-list data structure to libsepol
- [PATCH - policyrep] add objpool to libsepol
- [PATCH - policyrep] Add support for doxygen documentation in libsepol
- [PATCH - policyrep] Export symtab hash functions
- [PATCH - policyrep] hashtab iterator support
- [PATCH -mm] selinux: add selinux_install make option
- [PATCH -policyrep] Drop preservebools support from userland policy loader
- [PATCH -trunk][RFC] libselinux: drop setlocaldefs and preservebools support
- [PATCH -trunk][RFC] libsemanage: some optimizations
- [PATCH -trunk][RFC] setsebool: only use libsemanage for persistent boolean changes
- [PATCH -v1 1/3] SECURITY: new capable_noaudit interface
- [PATCH -v1 2/3] vm: use new has_capability_noaudit
- [PATCH -v1 3/3] filesystems: use has_capability_noaudit interface for reserved blocks checks
- [PATCH -v2 1/2] VM/SELinux: require CAP_SYS_RAWIO for all mmap_zero operations
- [PATCH -v2 1/3] SECURITY: new capable_noaudit interface
- [PATCH -v2 1/3] SELinux: fix selinux to safely handle any bugs even when not CONFIG_BUG
- [PATCH -v2 2/2] Security/SELinux: seperate lsm specific mmap_min_addr
- [PATCH -v2 2/3] SELinux: call capabilities code directory
- [PATCH -v2 2/3] vm: use new has_capability_noaudit
- [PATCH -v2 3/3] filesystems: use has_capability_noaudit interface for reserved blocks checks
- [PATCH -v2 3/3] SELinux: better printk when file with invalid label found
- [PATCH -v2] kernel: selinux: policy selectable handling of unknown classes and perms
- [PATCH -v2] libselinux: cache avc_compute_create results in the avc
- [PATCH -v2] NFS/LSM: allow NFS to control all of its own mount options
- [PATCH -v2] policycoreutils: get setfiles to skip mounts without seclabel
- [PATCH -v2] SELinux: /proc/mounts should show what it can
- [PATCH -v2] SELinux: Add get, set, and cloning of superblock security information
- [PATCH -v2] selinux: clean up avc node cache when disabling selinux
- [PATCH -v2] SELinux: Convert avc_audit to use lsm_audit.h
- [PATCH -v2] SELinux: create new open permission
- [PATCH -v2] SELinux: memory leak in security_context_to_sid_core
- [PATCH -v3 1/4] SECURITY: new capable_noaudit interface
- [PATCH -v3 2/4] vm: use new has_capability_noaudit
- [PATCH -v3 3/4] filesystems: use has_capability_noaudit interface for reserved blocks checks
- [PATCH -v3 4/4] SELinux: use new cap_noaudit interface
- [PATCH -v3] kernel: selinux: policy selectable handling of unknown classes and perms
- [PATCH -v3] LSM/SELinux: show LSM mount options in /proc/mounts
- [PATCH -v3] SELinux: /proc/mounts should show what it can
- [PATCH -v3] SELinux: Add get, set, and cloning of superblock security information
- [PATCH -v3] SELinux: Convert avc_audit to use lsm_audit.h
- [PATCH -v3] SELinux: memory leak in security_context_to_sid_core
- [PATCH -v4] kernel: selinux: policy selectable handling of unknown classes and perms
- [PATCH 0/10] Optionals in base take 2
- [patch 0/1] Add user object to libpolicyrep
- [PATCH 0/1] Latest network peer labeling patch
- [PATCH 0/1] NetLabel audit fixup
- [patch 0/1] NetLabel bugfix for 2.6.19
- [PATCH 0/1] NetLabel changes from yesterday's discussion
- [PATCH 0/1] NetLabel: patch against Venkat's secid patchset
- [PATCH 0/1] selinux: secid reconciliation fixes V01
- [PATCH 0/1] selinux: secid reconciliation fixes V01: Intro
- [PATCH 0/1] selinux: secid reconciliation fixes V02: Repost patchset with updates
- [PATCH 0/2] [PATCH 0/2] Updated NetLabel/secid-reconciliation bits and a bugfix
- [PATCH 0/2] A bugfix patchset for NetLabel
- [PATCH 0/2] Fix for the unlabeled NetLabel access check patch
- [PATCH 0/2] Fixes for 2.6.26
- [PATCH 0/2] Fixes for 2.6.29
- [PATCH 0/2] Introduce symtab_datum_t
- [patch 0/2] libselinux: add support for getting contexts for kernel initial SIDs from selinuxfs
- [Patch 0/2] libsemanage: remember and retrieve dontaudit settings
- [PATCH 0/2] NetLabel cleanups
- [PATCH 0/2] NetLabel policy additions for the reference policy
- [PATCH 0/2] new and improved range_transition statements
- [patch 0/2] policy capabilities and netpeer support
- [patch 0/2] policy capability support
- [PATCH 0/2] Rewrite setfiles to use matchpathcon
- [PATCH 0/2] sepolgen: update for the latest reference policy
- [PATCH 0/2] Small memory-leak patchset
- [PATCH 0/2] Two pretty trivial NetLabel bugfixes
- [PATCH 0/2] Ver 2 Introduce symtab_datum_t
- [PATCH 0/3] Collection of small NetLabel bugfixes
- [PATCH 0/3] Fix for IPsec leakage with SELinux enabled - V.03
- [patch 0/3] genhomedircon replacement in libsemanage
- [PATCH 0/3] Introduce credential record
- [PATCH 0/3] labeled-ipsec: Repost patchset with updates [Originally: mlsxfrm: Various Fixes]
- [patch 0/3] libsemanage: genhomedircon replacement
- [Patch 0/3] Loadable policy module infrastructure
- [PATCH 0/3] NetLabel: add the remaining CIPSO tag types from the IETF draft
- [PATCH 0/3] range_transition revisited
- [PATCH 0/3] secid reconciliation-v01: Repost patchset with up dates
- [PATCH 0/3] secid reconciliation-v01: Repost patchset with updates
- [patch 0/3] selinux: fix of selinuxfs inode number assigning and cleanup of selinuxfs
- [PATCH 0/3] Separate local file contexts into file_contexts.local
- [PATCH 0/3] Some quick policy patches based on the problems from earlier today
- [PATCH 0/3] Some SELinux patches for 2.6.26
- [Patch 0/3] Support context mount options that contain commas
- [PATCH 0/3] Thread/Child-Domain Assignment
- [PATCH 0/3] Thread/Child-Domain Assignment (rev.2)
- [PATCH 0/3] Thread/Child-Domain Assignment)
- [PATCH 0/3]: labeled ipsec policy
- [PATCH 0/4] features/fixes for rawhide and refpolicy
- [patch 0/4] libsemanage: genhomedircon regressions
- [patch 0/4] libsemanage: genhomedircon replacement
- [PATCH 0/4] NetLabel and MLS fixes for Reference Policy
- [PATCH 0/4] newrole suid functionality (take 2)
- [PATCH 0/4] Reference Policy patches for the new labeled networking code in 2.6.25
- [PATCH 0/4] selinux: add object class discovery
- [PATCH 0/4] SELinux: Validate kernel object classes and permissions
- [PATCH 0/4] Validate kernel object classes and permissions
- [PATCH 0/5] libselinux: add object class discovery
- [PATCH 0/5] libselinux: labeling API for userspace object managers
- [PATCH 0/5] libselinux: labeling API for userspace object managers (try 2)
- [PATCH 0/5] libselinux: labeling API for userspace objectmanagers
- [PATCH 0/5] libselinux: one large patch
- [patch 0/5] libsemanage: genhomedircon replacement v2
- [PATCH 0/5] libsepol unit tests
- [PATCH 0/5] NetLabel reference policy patches
- [PATCH 0/5] New labeled networking permissions for 2.6.25
- [PATCH 0/5] sysctl cleanup selinux fixes
- [PATCH 0/6] busybox -- SELinux option support for coreutils
- [PATCH 0/6] Drop legacy boolean/users support (setlocaldefs)
- [PATCH 0/6] Keys: Key management updates
- [PATCH 0/6] Keys: Key management updates [try #3]
- [PATCH 0/6] Labeled networking patches for 2.6.30
- [PATCH 0/6] netfilter integration
- [PATCH 0/6] netfilter integration take 2
- [PATCH 0/6] NetLabel fixes and reworked Netlink interface
- [PATCH 0/6] Various NetLabel fixes and cleanups
- [PATCH 0/7] labeled ipsec policy changes
- [PATCH 0/7] Latest NetLabel patch for 2.6.19
- [PATCH 0/7] Permit filesystem local caching
- [patch 0/7] quiet gcc warnings
- [PATCH 0/7] secid reconciliation-v02: Repost patchset with updates
- [PATCH 0/7] secid reconciliation-v03: Repost patchset with updates
- [PATCH 0/7] Updated patchset w/James' comments
- [PATCH 0/8] busybox -- libselinux utilities applets
- [PATCH 0/8] busybox -- SELinux option support for coreutils: ver3
- [PATCH 0/8] make newrole suid (take 3)
- [PATCH 0/9] secid reconciliation-v04: Repost patchset with updates
- [PATCH 00/10] MLSXFRM-v02: Repost patchset with updates
- [PATCH 00/11] The _entire_ secid reconciliation patchset (tada!)
- [PATCH 00/13] NetLabel cleanups for 2.6.20
- [PATCH 00/13] NetLabel cleanups for 2.6.20 [GIT]
- [PATCH 00/16] Permit filesystem local caching [try #3]
- [PATCH 00/19] Permit filesystem local caching and NFS superblock sharing
- [PATCH 00/22] Introduce credential record
- [PATCH 00/24] Introduce credential record
- [PATCH 00/26] Permit filesystem local caching
- [PATCH 00/27] Permit filesystem local caching
- [PATCH 00/27] Permit filesystem local caching [try #2]
- [PATCH 00/28] Permit filesystem local caching [try #2]
- [PATCH 00/33] libsemanage/libsepol object serialization and ps-api
- [patch 00/35] Second round of Fedora/RedHat SELinux changes
- [PATCH 00/37] Permit filesystem local caching
- [PATCH 00/37] Permit filesystem local caching [ver #34]
- [PATCH 00/45] Permit filesystem local caching [ver #35]
- [PATCH 01/06] MLSXFRM: Granular IPSec associations for use in MLS environments
- [PATCH 01/06] MLSXFRM: Granular IPSec associations for use in MLS environments)
- [PATCH 01/10] MLSXFRM-v02: Granular IPSec associations for use in MLS environments
- [PATCH 01/10] MLSXFRM: Granular IPSec associations for use in MLS environments
- [PATCH 01/11] secid reconciliation: new SELinux flask definitions
- [PATCH 01/13] NetLabel: use gfp_t instead of int where it makes sense
- [PATCH 01/13] SELinux: netif.c whitespace, syntax, and static declaraction cleanups
- [PATCH 01/13] VFS/Security: Rework inode_getsecurity and callers to return resulting buffer
- [PATCH 01/14] patch fix_use_before_init_in_nfsd4_list_rec_dir
- [PATCH 01/14] VFS: Factor out part of vfs_setxattr so it can be called from the SELinux hook for inode_setsecctx.
- [PATCH 01/16] FS-Cache: Release page->private after failed readahead [try #3]
- [PATCH 01/18] selinux: remove unused bprm_check_security hook
- [PATCH 01/24] CRED: Introduce a COW credentials record
- [PATCH 01/26] KEYS: Increase the payload size when instantiating a key
- [PATCH 01/27] KEYS: Increase the payload size when instantiating a key
- [PATCH 01/27] KEYS: Increase the payload size when instantiating a key [try #2]
- [PATCH 01/28] KEYS: Increase the payload size when instantiating a key [try #2]
- [PATCH 01/33] libsepol: basic serilization support
- [patch 01/35] anaconda policy update
- [PATCH 01/37] KEYS: Increase the payload size when instantiating a key
- [PATCH 01/37] KEYS: Increase the payload size when instantiating a key [ver #34]
- [PATCH 01/45] KEYS: Increase the payload size when instantiating a key [ver #35]
- [PATCH 02/06] MLSXFRM: Define new SELinux service routine
- [PATCH 02/10] MLSXFRM-v02: Define new SELinux service routine
- [PATCH 02/10] MLSXFRM: Define new SELinux service routine
- [PATCH 02/11] secid reconciliation: Add LSM hooks
- [PATCH 02/13] NetLabel: convert the unlabeled accept flag to use RCU
- [PATCH 02/13] SELinux: netlabel.c whitespace, syntax, and static declaraction cleanups
- [PATCH 02/13] VFS: Reorder vfs_getxattr to avoid unnecessary calls to the LSM
- [PATCH 02/14] LSM/SELinux: inode_{get,set,notify}secctx hooks to access LSM security context information.
- [PATCH 02/14] VFS: Factor out part of vfs_setxattr so it can be called from the SELinux hook for inode_setsecctx.
- [PATCH 02/16] FS-Cache: Recruit a couple of page flags for cache management [try #3]
- [PATCH 02/18] selinux: remove secondary ops call to bprm_committing_creds
- [PATCH 02/19] FS-Cache: Provide a filesystem-specific sync'able page bit
- [PATCH 02/22] CRED: Split the task security data and move part of it into struct cred
- [PATCH 02/24] CRED: Split the task security data and move part of it into struct cred
- [PATCH 02/26] KEYS: Check starting keyring as part of search
- [PATCH 02/27] KEYS: Check starting keyring as part of search
- [PATCH 02/27] KEYS: Check starting keyring as part of search [try #2]
- [PATCH 02/28] KEYS: Check starting keyring as part of search [try #2]
- [PATCH 02/33] libsepol: boolean serialization
- [patch 02/35] kudzu policy update
- [PATCH 02/37] KEYS: Check starting keyring as part of search
- [PATCH 02/37] KEYS: Check starting keyring as part of search [ver #34]
- [PATCH 02/45] KEYS: Check starting keyring as part of search [ver #35]
- [PATCH 03/06] MLSXFRM: Add security sid to sock
- [PATCH 03/10] MLSXFRM-v02: Add security sid to sock
- [PATCH 03/10] MLSXFRM: Add security sid to sock
- [PATCH 03/11] secid reconciliation: Invoke LSM hook for inbound traffic
- [PATCH 03/13] NetLabel: change netlbl_secattr_init() to return void
- [PATCH 03/13] Security: Add hook to get full security xattr name
- [PATCH 03/13] SELinux: netlink.c whitespace, syntax, and static declaraction cleanups
- [PATCH 03/14] LSM/SELinux: inode_{get,set,notify}secctx hooks to access LSM security context information.
- [PATCH 03/14] Security: Add hook to calculate context based on a negative dentry.
- [PATCH 03/16] FS-Cache: Provide an add_wait_queue_tail() function [try #3]
- [PATCH 03/18] selinux: remove secondary ops call to bprm_committed_creds
- [PATCH 03/19] FS-Cache: Release page->private after failed readahead
- [PATCH 03/22] CRED: Move the effective capabilities into the cred struct
- [PATCH 03/24] CRED: Alter security_task_getsecid() and similar to return both task SIDs
- [PATCH 03/26] KEYS: Allow the callout data to be passed as a blob rather than a string
- [PATCH 03/27] KEYS: Allow the callout data to be passed as a blob rather than a string
- [PATCH 03/27] KEYS: Allow the callout data to be passed as a blob rather than a string [try #2]
- [PATCH 03/28] KEYS: Allow the callout data to be passed as a blob rather than a string [try #2]
- [PATCH 03/33] libsepol: context serialization
- [patch 03/35] logrotate policy update
- [PATCH 03/37] KEYS: Allow the callout data to be passed as a blob rather than a string
- [PATCH 03/37] KEYS: Allow the callout data to be passed as a blob rather than a string [ver #34]
- [PATCH 03/45] KEYS: Allow the callout data to be passed as a blob rather than a string [ver #35]
- [PATCH 04/06] MLSXFRM: Flow based matching of xfrm policy and state
- [PATCH 04/10] MLSXFRM-v02: Add security sid to flowi
- [PATCH 04/10] MLSXFRM: Add security sid to flowi
- [PATCH 04/11] secid reconciliation: Invoke LSM hook for outbound traffic
- [PATCH 04/13] NetLabel: make netlbl_lsm_secattr struct easier/quicker to understand
- [PATCH 04/13] SELinux: netnode.c whitespace, syntax, and static declaraction cleanups
- [PATCH 04/13] VFS: Add label field to the iattr structure
- [PATCH 04/14] Security: Add hook to calculate context based on a negative dentry.
- [PATCH 04/14] Security: Add Hook to test if the particular xattr is part of a MAC model.
- [PATCH 04/18] selinux: remove secondary ops call to sb_mount
- [PATCH 04/19] FS-Cache: Make kAFS use FS-Cache
- [PATCH 04/22] CRED: Request a credential record for a kernel service
- [PATCH 04/24] CRED: Move the effective capabilities into the cred struct
- [PATCH 04/26] KEYS: Add keyctl function to get a security label
- [PATCH 04/27] KEYS: Add keyctl function to get a security label
- [PATCH 04/27] KEYS: Add keyctl function to get a security label [try #2]
- [PATCH 04/28] KEYS: Add keyctl function to get a security label [try #2]
- [PATCH 04/33] libsepol: interface serialization
- [patch 04/35] corenetwork policy update
- [PATCH 04/37] KEYS: Add keyctl function to get a security label
- [PATCH 04/37] KEYS: Add keyctl function to get a security label [ver #34]
- [PATCH 04/45] KEYS: Allow clients to set key perms in key_create_or_update() [ver #35]
- [PATCH 05/06] MLSXFRM: Add security context to acquire messages using netlink
- [PATCH 05/10] MLSXFRM-v02: Flow based matching of xfrm policy and state
- [PATCH 05/10] MLSXFRM: Flow based matching of xfrm policy and state
- [PATCH 05/11] secid reconciliation: Label locally generated IPv6 traffic
- [PATCH 05/13] NetLabel: check for a CIPSOv4 option before we do call into the CIPSOv4 layer
- [PATCH 05/13] Security: Add hook to calculate context based on a negative dentry.
- [PATCH 05/13] SELinux: nlmsgtab.c whitespace, syntax, and static declaraction cleanups
- [PATCH 05/14] Security: Add Hook to test if the particular xattr is part of a MAC model.
- [PATCH 05/14] SELinux: Add new labeling type native labels
- [PATCH 05/16] CacheFiles: Add missing copy_page export for ia64 [try #3]
- [PATCH 05/18] selinux: remove secondary ops call to sb_umount
- [PATCH 05/19] NFS: Use local caching
- [PATCH 05/22] FS-Cache: Release page->private after failed readahead
- [PATCH 05/24] CRED: Fix up the other credentials references
- [PATCH 05/26] Security: Change current->fs[ug]id to current_fs[ug]id()
- [PATCH 05/27] Security: Change current->fs[ug]id to current_fs[ug]id()
- [PATCH 05/27] Security: Change current->fs[ug]id to current_fs[ug]id() [try #2]
- [PATCH 05/28] Security: Change current->fs[ug]id to current_fs[ug]id() [try #2]
- [PATCH 05/33] libsepol: node serialization
- [patch 05/35] courier policy update
- [PATCH 05/37] Security: Change current->fs[ug]id to current_fs[ug]id()
- [PATCH 05/37] Security: Change current->fs[ug]id to current_fs[ug]id() [ver #34]
- [PATCH 05/45] KEYS: Don't generate user and user session keyrings unless they're accessed [ver #35]
- [PATCH 06/06] MLSXFRM: Add security context to acquire messages using PF_KEY
- [PATCH 06/10] MLSXFRM-v02: Add security context to acquire messages using netlink
- [PATCH 06/10] MLSXFRM: Add security context to acquire messages using netlink
- [PATCH 06/11] secid reconciliation: Label locally generated IPv4 traffic
- [PATCH 06/13] KConfig: Add KConfig entries for SELinux labeled NFS
- [PATCH 06/13] NetLabel: add tag verification when adding new CIPSOv4 DOI definitions
- [PATCH 06/13] SELinux: xfrm.c whitespace, syntax, and static declaraction cleanups
- [PATCH 06/14] KConfig: Add KConfig entries for Labeled NFS
- [PATCH 06/14] SELinux: Add new labeling type native labels
- [PATCH 06/16] CacheFiles: Add a hook to write a single page of data to an inode [try #3]
- [PATCH 06/18] selinux: remove secondary ops call to inode_link
- [PATCH 06/19] FS-Cache: NFS: Only obtain cache cookies on file open, not on inode read
- [PATCH 06/22] FS-Cache: Recruit a couple of page flags for cache management
- [PATCH 06/24] CRED: Request a credential record for a kernel service
- [PATCH 06/33] libsepol: port serialization
- [patch 06/35] soundserver policy update
- [PATCH 06/37] Security: Separate task security context from task_struct
- [PATCH 06/37] Security: Separate task security context from task_struct [ver #34]]
- [PATCH 06/45] KEYS: Make the keyring quotas controllable through /proc/sys [ver #35]
- [PATCH 06a/26] Extra task_struct -> task_security separation
- [PATCH 06b/26] Security: Make NFSD work with detached security
- [PATCH 07/10] MLSXFRM: Add security context to acquire messages using PF_KEY
- [PATCH 07/11] secid reconciliation: Enforcement for SELinux
- [PATCH 07/13] NetLabel: fixup the handling of CIPSOv4 tags to allow for multiple tag types
- [PATCH 07/13] NFSv4: Add label recommended attribute and NFSv4 flags
- [PATCH 07/13] SELinux: avtab.c whitespace, syntax, and static declaraction cleanups
- [PATCH 07/14] KConfig: Add KConfig entries for Labeled NFS
- [PATCH 07/14] NFSv4: Add label recommended attribute and NFSv4 flags
- [PATCH 07/16] CacheFiles: Permit the page lock state to be monitored [try #3]
- [PATCH 07/18] selinux: remove secondary ops call to inode_unlink
- [PATCH 07/19] CacheFiles: Add missing copy_page export for ia64
- [PATCH 07/22] FS-Cache: Provide an add_wait_queue_tail() function
- [PATCH 07/24] FS-Cache: Release page->private after failed readahead
- [PATCH 07/26] Security: De-embed task security record from task and use refcounting
- [PATCH 07/27] Security: De-embed task security record from task and use refcounting
- [PATCH 07/27] Security: De-embed task security record from task and use refcounting [try #2]
- [PATCH 07/28] SECURITY: De-embed task security record from task and use refcounting [try #2]
- [PATCH 07/33] libsepol: user serialization
- [patch 07/35] w3c policy addition
- [PATCH 07/37] Security: De-embed task security record from task and use refcounting
- [PATCH 07/37] Security: De-embed task security record from task and use refcounting [ver #34]
- [PATCH 07/45] KEYS: Make key_serial() a function if CONFIG_KEYS=y [ver #35]
- [PATCH 08/10] MLSXFRM-v02: Add flow labeling
- [PATCH 08/10] MLSXFRM: Add security context to acquire messag es using PF_KEY
- [PATCH 08/10] MLSXFRM: Add security context to acquire messages using PF_KEY
- [PATCH 08/11] secid reconciliation: Use secmark when classifying flow using skb
- [PATCH 08/13] NetLabel: return the correct error for translated CIPSOv4 tags
- [PATCH 08/13] NFS: Introduce lifecycle managment for label attribute.
- [PATCH 08/13] SELinux: conditional.c whitespace, syntax, and static declaraction cleanups
- [PATCH 08/14] NFS: Add security_label text mount option and handling code to NFS
- [PATCH 08/14] NFSv4: Add label recommended attribute and NFSv4 flags
- [PATCH 08/16] CacheFiles: Export things for CacheFiles [try #3]
- [PATCH 08/18] selinux: remove secondary ops call to inode_mknod
- [PATCH 08/19] CacheFiles: Add a function to write a single page of data to an inode
- [PATCH 08/24] FS-Cache: Recruit a couple of page flags for cache management
- [PATCH 08/26] Add a secctx_to_secid() LSM hook to go along with the existing
- [PATCH 08/27] Add a secctx_to_secid() LSM hook to go along with the existing
- [PATCH 08/27] Add a secctx_to_secid() LSM hook to go along with the existing [try #2]
- [PATCH 08/28] SECURITY: Allow kernel services to override LSM settings for task actions [try #2]
- [PATCH 08/33] libsemanage: DESTDIR support in INCLUDE and safe test target
- [patch 08/35] logging policy update
- [PATCH 08/37] Security: Add a kernel_service object class to SELinux
- [PATCH 08/37] Security: Add a kernel_service object class to SELinux [ver #34]
- [PATCH 08/45] KEYS: Add keyctl function to get a security label [ver #35]
- [PATCH 09/10] cr: restore LSM credentials
- [PATCH 09/10] MLSXFRM-v02: Default labeling of socket specific IPSec policies
- [PATCH 09/10] MLSXFRM: Default labeling of socket specific IPSec policies
- [PATCH 09/11] secid reconciliation: Track peersecid at connection establishment
- [PATCH 09/13] NetLabel: use the correct CIPSOv4 MLS label limits
- [PATCH 09/13] NFS: Client implementation of SELINUX Labeling
- [PATCH 09/13] SELinux: ebitmap.c whitespace, syntax, and static declaraction cleanups
- [PATCH 09/14] CacheFiles: Permit a process's create SID to be overridden [try #2]
- [PATCH 09/14] NFS: Add security_label text mount option and handling code to NFS
- [PATCH 09/14] NFS: Introduce lifecycle management for label attribute.
- [PATCH 09/16] CacheFiles: Permit a process's create SID to be overridden [try #3]
- [PATCH 09/18] selinux: remove secondary ops call to inode_follow_link
- [PATCH 09/19] CacheFiles: Permit the page lock state to be monitored
- [PATCH 09/22] CacheFiles: Add missing copy_page export for ia64
- [PATCH 09/24] FS-Cache: Provide an add_wait_queue_tail() function
- [PATCH 09/26] Security: Pre-add additional non-caching classes
- [PATCH 09/27] Security: Pre-add additional non-caching classes
- [PATCH 09/27] Security: Pre-add additional non-caching classes [try #2]
- [PATCH 09/28] FS-Cache: Release page->private after failed readahead [try #2]
- [PATCH 09/33] libsemanage: dbase/dconfig cleanup
- [patch 09/35] xen policy update
- [PATCH 09/37] Security: Allow kernel services to override LSM settings for task actions
- [PATCH 09/37] Security: Allow kernel services to override LSM settings for task actions [ver #34]
- [PATCH 09/45] Security: Change current->fs[ug]id to current_fs[ug]id() [ver #35]
- [PATCH 1/10] setfiles audit fix
- [patch 1/1] Add users to libpolicyrep
- [PATCH 1/1] cr: lsm: restore LSM contexts for ipc objects
- [PATCH 1/1] libselinux: helpful message when /selinux won't mount
- [patch 1/1] libsemanage: genhomedircon remove error on missing HOME_DIR or HOME_ROOT
- [patch 1/1] libsemanage: genhomedircon remove error on missing HOME_DIR or HOME_ROOT v2
- [PATCH 1/1] LSM/SELinux: {get,set}context hooks to access LSM security context information.
- [patch 1/1] make indent target update
- [PATCH 1/1] NetLabel: add audit support for configuration changes
- [PATCH 1/1] NetLabel: audit fixups due to delayed feedback
- [patch 1/1] NetLabel: protect the CIPSOv4 socket option from setsockopt()
- [PATCH 1/1] NetLabel: secid reconciliation support
- [PATCH 1/1] NetLabel: use SECINITSID_UNLABELED for a base SID
- [PATCH 1/1] REFPOL: Add new labeled networking permissions
- [PATCH 1/1] refpolicy: Do not want to transition to sysadm_t when upstart runs a shell
- [patch 1/1] removal of unused private.h from libsemanage
- [PATCH 1/1] Reworked patch for restorecon
- [PATCH 1/1] secid reconcialiation: Replace unlabeled_t with t he network_t
- [PATCH 1/1] secid reconcialiation: Replace unlabeled_t with the network_t
- [patch 1/1] SELinux AVC audit log ipaddr field support (for task_struct->curr_ip)
- [PATCH 1/1] selinux: add support for installing a dummy policy
- [PATCH 1/1] selinux: add support for installing a dummy policy (v2)
- [PATCH 1/1] SELINUX: Bug fix in security_sid_mls_copy
- [PATCH 1/1] selinux: Delete mls_copy_context
- [PATCH 1/1] selinux: Delete mls_copy_context - V.02
- [patch 1/1] selinux: detect dead booleans
- [PATCH 1/1] selinux: fix 2.6.20-rc6 build when no xfrm
- [PATCH 1/1] selinux: increment flow cache genid
- [PATCH 1/1] selinux: Null-out secmark after use
- [PATCH 1/1] selinux: Null-out secmark after use - V.02
- [PATCH 1/1] selinux: secid reconciliation fixes V02
- [PATCH 1/1] semanage_select_store fun
- [PATCH 1/2 -v3] Namespacing of security/selinux
- [PATCH 1/2 v3] Conditionally expand neverallows
- [PATCH 1/2] cipso: Fix documentation comment
- [PATCH 1/2] Conditionally expand neverallows
- [patch 1/2] Fix memory leaks in libsepol/checkpolicy
- [PATCH 1/2] Introduce symtab_datum_t
- [PATCH 1/2] Introduce symtab_datum_t.
- [PATCH 1/2] kernel support for new range_transition statements
- [patch 1/2] library policy capability support
- [patch 1/2] libselinux: add support for getting contexts for kernel initial SIDs from selinuxfs
- [PATCH 1/2] libselinux: class and permission mapping support
- [PATCH 1/2] libselinux: class and permission mapping support (try 2)
- [Patch 1/2] libsemanage: remember and retrieve dontaudit settings
- [PATCH 1/2] libsepol - fix assertion copying
- [Patch 1/2] libsepol: method to check disable dontaudit flag.
- [PATCH 1/2] LSM/SELinux: Interfaces to allow FS to control mount options
- [PATCH 1/2] LSM: Add inet_sys_snd_skb() LSM hook
- [PATCH 1/2] namespaces: introduce sys_hijack (v10)
- [PATCH 1/2] NetLabel: consolidate the struct socket/sock handling to just struct sock
- [PATCH 1/2] NetLabel: correct locking in selinux_netlbl_socket_setsid()
- [PATCH 1/2] NetLabel: perform input validation earlier on CIPSOv4 DOI add ops
- [PATCH 1/2] Optionally expand neverallows, propagate errors in policydb
- [PATCH 1/2] put neverallows in avtab, propagate errors in policydb
- [PATCH 1/2] Reference policy: NetLabel policy additions
- [PATCH 1/2] Rewrite setfiles to use matchpathcon
- [PATCH 1/2] security: Add security hook definitions for setmempolicy
- [PATCH 1/2] SELinux: do not check open on dir path walk
- [PATCH 1/2] SELinux: Made netnode cache adds faster
- [PATCH 1/2] SELinux: NULL terminate al contexts from disk
- [PATCH 1/2] SELinux: remove redundant pointer checks before calling kfree()
- [PATCH 1/2] SELinux: turn mount options strings into defines
- [PATCH 1/2] SELinux: use SECINITSID_NETMSG instead of SECINITSID_UNLABELED for NetLabel
- [PATCH 1/2] sepolgen: update ply to the latest version
- [PATCH 1/2] sysctl: Add a parent entry to ctl_table and set the parent entry.
- [PATCH 1/2] unshare system call patch - needed to test pam_namespace patch
- [PATCH 1/2] Ver 2 Introduce symtab_datum_t
- [patch 1/2] Version 22/Policy capability support
- [PATCH 1/2] VFS/Security: Rework inode_getsecurity and callers to return resulting buffer
- [PATCH 1/2] VFS: Factor out part of vfs_setxattr so it can be called from the SELinux hook for inode_setsecctx.
- [PATCH 1/2] VM/SELinux: require CAP_SYS_RAWIO for all mmap_zero operations
- [PATCH 1/3] CRED: Introduce a COW credentials record
- [PATCH 1/3] Fix for IPsec leakage with SELinux enabled - V.03
- [PATCH 1/3] Fix for IPsec leakage with SELinux enabled - V.03: Fix xfrm code
- [PATCH 1/3] labeled-ipsec: Various fixes
- [PATCH 1/3] libselinux: class and permission mapping support (try 3)
- [PATCH 1/3] libselinux: labeling support (try 3)
- [PATCH 1/3] libselinux: minor updates to AVC, mapping, callbacks
- [PATCH 1/3] libselinux: string and compute_create functions
- [PATCH 1/3] libselinux: string and compute_create functions (resend)
- [PATCH 1/3] libsemanage: database_file.c uninit'd deref
- [patch 1/3] libsemanage: genhomedircon replacement
- [PATCH 1/3] libsepol - fix aliased sensitivities
- [Patch 1/3] Loadable policy module infrastructure
- [PATCH 1/3] mlsxfrm: Various fixes
- [PATCH 1/3] mmap: protect from stack expantion into low vm addresses
- [PATCH 1/3] Move variable function in lsm_audit.h into SMACK private space
- [PATCH 1/3] NetLabel: convert to an extensibile/sparse category bitmap
- [PATCH 1/3] NetLabel: only deref the CIPSOv4 standard map fields when using standard mapping
- [PATCH 1/3] Optionally expand neverallows, propagate errors in policydb
- [PATCH 1/3] Refpolicy: allow the IPsec management tools to start at boot
- [PATCH 1/3] secid reconciliation-v01
- [PATCH 1/3] security: Extend task_kill hook to handle signals sent by AIO completion
- [Patch 1/3] SELinux: add support for quoted context mount option
- [PATCH 1/3] SELinux: Cleanup the secid/secctx conversion functions
- [PATCH 1/3] SELinux: Condense super block security structure flags and cleanup necessary code.
- [patch 1/3] selinux: explicitly number all selinuxfs inodes
- [PATCH 1/3] SELinux: fix selinux to safely handle any bugs even when not CONFIG_BUG
- [PATCH 1/3] SELinux: open code policy_rwlock
- [PATCH 1/3] Separate local file contexts into file_contexts.local
- [PATCH 1/3] support for extended range_transitions
- [PATCH 1/3] Thread/Child-Domain Assignment
- [PATCH 1/3] Thread/Child-Domain Assignment (rev.2)
- [PATCH 1/3] Thread/Child-Domain Assignment (rev.3)
- [PATCH 1/3] Thread/Child-Domain Assignment (rev.4)
- [PATCH 1/3] Thread/Child-Domain Assignment (rev.6)
- [PATCH 1/3]: labeled ipsec policy
- [PATCH 1/4 -v2] Namespacing of security/selinux
- [PATCH 1/4] Bug fix in polidydb_destroy
- [PATCH 1/4] features/fixes for rawhide and refpolicy
- [PATCH 1/4] libselinux flask definition update for context class
- [patch 1/4] libsemanage: genhomedircon initial cleanup
- [patch 1/4] libsemanage: validate homedir contexts
- [PATCH 1/4] make newrole suid
- [PATCH 1/4] Namespacing of security/selinux
- [PATCH 1/4] newrole suid functionality (take 2)
- [PATCH 1/4] Policy patches to add NetLabel to support to various domains
- [PATCH 1/4] REFPOL: Add "rogue" Fedora packet class permissions
- [PATCH 1/4] selinux: add support for querying object classes and permissions from the running policy
- [PATCH 1/4] SELinux: remove current object class and permission validation mechanism
- [PATCH 1/5] libselinux: labeling API basic front-end interface
- [PATCH 1/5] libselinux: rename existing name<->value functions for compat
- [patch 1/5] libsemanage: genhomedircon initial cleanup
- [PATCH 1/5] libsepol unit test infrastructure
- [PATCH 1/5] REFPOL: Add new labeled networking permissions
- [PATCH 1/5] SELinux: remove the unused ae.used
- [PATCH 1/5] sysctl: Remove declaration of nonexistent sysctl_init()
- [PATCH 1/5] Use the netmsg initial SID for NetLabel connections
- [PATCH 1/6] busybox -- SELinux option support for coreutils
- [PATCH 1/6] Keys: Sort out key quota system
- [PATCH 1/6] Keys: Sort out key quota system [try #3]
- [PATCH 1/6] libselinux: Drop setlocaldefs support from policy loading code
- [PATCH 1/6] libsepol: range_trans_clone memory leak
- [PATCH 1/6] lsm: Relocate the IPv4 security_inet_conn_request() hooks
- [PATCH 1/6] netfilter integration take 2: add netfilter_contexts path to libselinux
- [PATCH 1/6] netfilter integration: add netfilter_contexts path to libselinux
- [PATCH 1/6] NetLabel: correct improper handling of non-NetLabel peer contexts
- [PATCH 1/6] NetLabel: correctly initialize the NetLabel fields
- [PATCH 1/7] KEYS: Increase the payload size when instantiating a key
- [PATCH 1/7] labeled ipsec policy changes
- [PATCH 1/7] libselinux: labeling support (try 4)
- [PATCH 1/7] NetLabel: documentation
- [patch 1/7] quiet checkpolicy warnings
- [PATCH 1/7] secid reconciliation-v02
- [PATCH 1/7] secid reconciliation-v03
- [PATCH 1/7] Security: Add inode_{get,set}secid LSM hooks and security helper functions
- [PATCH 1/8] busybox -- SELinux option support for coreutils: ver3
- [PATCH 1/8] make newrole suid (take 3)
- [PATCH 1/8] SELinux avc.c non-trivial fixes.
- [PATCH 1/9] secid reconciliation-v04
- [PATCH 10/10] alias fix
- [PATCH 10/10] cr: lsm: restore file->f_security
- [PATCH 10/10] MLSXFRM-v02: Auto-labeling of child sockets
- [PATCH 10/10] MLSXFRM: Auto-labeling of child sockets
- [PATCH 10/11] secid reconciliation: various fixes
- [PATCH 10/13] NetLabel: use cipso_v4_doi_search() for local CIPSOv4 functions
- [PATCH 10/13] NFS: Extend nfs xattr handlers to accept the security namespace
- [PATCH 10/13] SELinux: hashtab.c whitespace, syntax, and static declaraction cleanups
- [PATCH 10/14] NFS: Introduce lifecycle management for label attribute.
- [PATCH 10/14] NFSv4: Introduce new label structure
- [PATCH 10/16] CacheFiles: Add an act-as SID override in task_security_struct [try #3]
- [PATCH 10/18] selinux: remove secondary ops call to inode_permission
- [PATCH 10/19] CacheFiles: Export things for CacheFiles
- [PATCH 10/22] CacheFiles: Add a hook to write a single page of data to an inode
- [PATCH 10/26] Security: Add a kernel_service object class to SELinux
- [PATCH 10/27] Security: Add a kernel_service object class to SELinux
- [PATCH 10/27] Security: Add a kernel_service object class to SELinux [try #2]
- [PATCH 10/28] FS-Cache: Recruit a couple of page flags for cache management [try #2]
- [PATCH 10/33] libsemanage: database serialization
- [patch 10/35] qemu policy update
- [PATCH 10/37] Security: Make NFSD work with detached security
- [PATCH 10/37] Security: Make NFSD work with detached security [ver #34]
- [PATCH 11/10] fix decl val index, other leaks
- [PATCH 11/11] secid reconciliation: support for NetLabel
- [PATCH 11/13] NetLabel: SELinux cleanups
- [PATCH 11/13] NFSD: Server implementation of MAC Labeling
- [PATCH 11/13] SELinux: mls.c whitespace, syntax, and static declaraction cleanups
- [PATCH 11/14] CacheFiles: Permit an inode's security ID to be obtained [try #2]
- [PATCH 11/14] NFS/RPC: Add the auth_seclabel security flavor to allow the process label to be sent to the server.
- [PATCH 11/14] NFSv4: Introduce new label structure
- [PATCH 11/16] CacheFiles: Permit an inode's security ID to be obtained [try #3]
- [PATCH 11/18] selinux: remove secondary ops call to inode_setattr
- [PATCH 11/22] CacheFiles: Permit the page lock state to be monitored
- [PATCH 11/24] CacheFiles: Add missing copy_page export for ia64
- [PATCH 11/26] Security: Allow kernel services to override LSM settings for task actions
- [PATCH 11/27] Security: Allow kernel services to override LSM settings for task actions
- [PATCH 11/27] Security: Allow kernel services to override LSM settings for task actions [try #2]
- [PATCH 11/28] FS-Cache: Provide an add_wait_queue_tail() function [try #2]
- [PATCH 11/33] libsemanage: endianness macros
- [patch 11/35] hotplug policy update
- [PATCH 11/37] FS-Cache: Release page->private after failed readahead
- [PATCH 11/37] FS-Cache: Release page->private after failed readahead [ver #34]
- [PATCH 11/45] Security: De-embed task security record from task and use refcounting [ver #35]
- [PATCH 12/13] NFS: Label change notification for NFSv4 Clients
- [PATCH 12/13] SELinux: peer secid consolidation for external network labeling
- [PATCH 12/13] SELinux: services.c whitespace, syntax, and static declaraction cleanups
- [PATCH 12/14] NFS: Client implementation of Labeled-NFS
- [PATCH 12/16] CacheFiles: Get the SID under which the CacheFiles module should operate [try #3]
- [PATCH 12/18] selinux: remove secondary ops call to file_mprotect
- [PATCH 12/19] CacheFiles: Permit a process's create SID to be overridden
- [PATCH 12/22] CacheFiles: Export things for CacheFiles
- [PATCH 12/24] CacheFiles: Add a hook to write a single page of data to an inode
- [PATCH 12/26] FS-Cache: Release page->private after failed readahead
- [PATCH 12/27] Security: Make NFSD work with detached security
- [PATCH 12/27] Security: Make NFSD work with detached security [try #2]
- [PATCH 12/33] libsemanage: basic serialization
- [patch 12/35] getty policy update
- [PATCH 12/37] FS-Cache: Recruit a couple of page flags for cache management
- [PATCH 12/37] FS-Cache: Recruit a couple of page flags for cache management [ver #34]
- [PATCH 12/45] Security: Add a kernel_service object class to SELinux [ver #35]
- [PATCH 13/13] NetLabel: honor the audit_enabled flag
- [PATCH 13/13] NFSD: Label change notification for NFSv4 Server
- [PATCH 13/13] selinux: remove secondary ops call to file_mprotect
- [PATCH 13/13] SELinux: sidtab.c whitespace, syntax, and static declaraction cleanups
- [PATCH 13/14] NFS: Extend NFS xattr handlers to accept the security namespace
- [PATCH 13/18] selinux: remove secondary ops call to task_create
- [PATCH 13/19] CacheFiles: Add an act-as SID override in task_security_struct
- [PATCH 13/24] CacheFiles: Permit the page lock state to be monitored
- [PATCH 13/26] FS-Cache: Recruit a couple of page flags for cache management
- [PATCH 13/27] FS-Cache: Release page->private after failed readahead
- [PATCH 13/27] FS-Cache: Release page->private after failed readahead [try #2]
- [PATCH 13/28] CacheFiles: Add missing copy_page export for ia64 [try #2]
- [PATCH 13/33] libsemanage: testing infrastructure
- [patch 13/35] ricci policy update
- [PATCH 13/37] FS-Cache: Provide an add_wait_queue_tail() function
- [PATCH 13/37] FS-Cache: Provide an add_wait_queue_tail() function [ver #34]
- [PATCH 13/45] Security: Allow kernel services to override LSM settings for task actions [ver #35]
- [PATCH 14/14] NFSD: Server implementation of MAC Labeling
- [PATCH 14/16] NFS: Use local caching [try #3]
- [PATCH 14/18] selinux: remove unused cred_commit hook
- [PATCH 14/19] CacheFiles: Permit an inode's security ID to be obtained
- [PATCH 14/22] NFS: Use local caching
- [PATCH 14/24] CacheFiles: Export things for CacheFiles
- [PATCH 14/26] FS-Cache: Provide an add_wait_queue_tail() function
- [PATCH 14/27] FS-Cache: Recruit a couple of page flags for cache management
- [PATCH 14/27] FS-Cache: Recruit a couple of page flags for cache management [try #2]
- [PATCH 14/28] CacheFiles: Be consistent about the use of mapping vs file->f_mapping in Ext3 [try #2]
- [PATCH 14/33] libsemanage: boolean serialization
- [patch 14/35] remotelogin policy update
- [PATCH 14/45] Security: Make NFSD work with detached security [ver #35]
- [PATCH 15/16] NFS: Configuration and mount option changes to enable local caching on NFS [try #3]
- [PATCH 15/18] selinux: remove secondary ops call to task_setrlimit
- [PATCH 15/19] CacheFiles: Get the SID under which the CacheFiles module should operate
- [PATCH 15/22] NFS: Configuration and mount option changes to enable local caching on NFS
- [PATCH 15/27] FS-Cache: Provide an add_wait_queue_tail() function
- [PATCH 15/27] FS-Cache: Provide an add_wait_queue_tail() function [try #2]
- [PATCH 15/28] CacheFiles: Add a hook to write a single page of data to an inode [try #2]
- [PATCH 15/33] libsemanage: context serialization
- [patch 15/35] kernel terminal policy update
- [PATCH 15/37] CacheFiles: Add missing copy_page export for ia64
- [PATCH 15/37] CacheFiles: Add missing copy_page export for ia64 [ver #34]
- [PATCH 15/45] FS-Cache: Release page->private after failed readahead [ver #35]
- [PATCH 16/16] NFS: Display local caching state [try #3]
- [PATCH 16/18] selinux: remove secondary ops call to task_kill
- [PATCH 16/19] CacheFiles: Deal with LSM when accessing the cache
- [PATCH 16/22] NFS: Display local caching state
- [PATCH 16/24] NFS: Use local caching
- [PATCH 16/26] CacheFiles: Add missing copy_page export for ia64
- [PATCH 16/28] CacheFiles: Permit the page lock state to be monitored [try #2]
- [PATCH 16/33] libsemanage: fcontext serialization
- [patch 16/35] usernet policy updates
- [PATCH 16/37] CacheFiles: Be consistent about the use of mapping vs file->f_mapping in Ext3
- [PATCH 16/37] CacheFiles: Be consistent about the use of mapping vs file->f_mapping in Ext3 [ver #34]
- [PATCH 16/45] FS-Cache: Recruit a couple of page flags for cache management [ver #35]
- [PATCH 17/18] selinux: remove secondary ops call to unix_stream_connect
- [PATCH 17/19] CacheFiles: Use the VFS wrappers for inode ops
- [PATCH 17/22] AFS: Add TestSetPageError()
- [PATCH 17/24] NFS: Configuration and mount option changes to enable local caching on NFS
- [PATCH 17/26] CacheFiles: Be consistent about the use of mapping vs file->f_mapping in Ext3
- [PATCH 17/27] CacheFiles: Add missing copy_page export for ia64
- [PATCH 17/27] CacheFiles: Add missing copy_page export for ia64 [try #2]
- [PATCH 17/28] CacheFiles: Export things for CacheFiles [try #2]
- [PATCH 17/33] libsemanage: interface serialization
- [patch 17/35] brctl policy update
- [PATCH 17/37] CacheFiles: Add a hook to write a single page of data to an inode
- [PATCH 17/37] CacheFiles: Add a hook to write a single page of data to an inode [ver #34]
- [PATCH 17/45] FS-Cache: Provide an add_wait_queue_tail() function [ver #35]
- [PATCH 18/18] selinux: remove secondary ops call to shm_shmat
- [PATCH 18/22] AFS: Add a function to excise a rejected write from the pagecache
- [PATCH 18/24] NFS: Display local caching state
- [PATCH 18/26] CacheFiles: Add a hook to write a single page of data to an inode
- [PATCH 18/27] CacheFiles: Be consistent about the use of mapping vs file->f_mapping in Ext3
- [PATCH 18/27] CacheFiles: Be consistent about the use of mapping vs file->f_mapping in Ext3 [try #2]
- [PATCH 18/33] libsemanage: node serialization
- [patch 18/35] fsadm policy update
- [PATCH 18/37] CacheFiles: Permit the page lock state to be monitored
- [PATCH 18/37] CacheFiles: Permit the page lock state to be monitored [ver #34]
- [PATCH 19/19] CacheFiles: Permit daemon to probe inuseness of a cache file
- [PATCH 19/22] AFS: Improve handling of a rejected writeback
- [PATCH 19/24] AFS: Add TestSetPageError()
- [PATCH 19/26] CacheFiles: Permit the page lock state to be monitored
- [PATCH 19/27] CacheFiles: Add a hook to write a single page of data to an inode
- [PATCH 19/27] CacheFiles: Add a hook to write a single page of data to an inode [try #2]
- [PATCH 19/28] NFS: Use local caching [try #2]
- [PATCH 19/33] libsemanage: port serialization
- [patch 19/35] kernel storage module policy updates
- [PATCH 19/37] CacheFiles: Export things for CacheFiles
- [PATCH 19/37] CacheFiles: Export things for CacheFiles [ver #34]
- [PATCH 19/45] Add missing consts to xattr function arguments [ver #35]
- [PATCH 2/10] fix parser bugs
- [PATCH 2/2 -v3] Namespacing of security/selinux
- [PATCH 2/2 take 2] userland support for new range_transition statements
- [PATCH 2/2 take 2] userland support for new range_transitionstatements
- [Patch 2/2 v2] libsemanage: maintain disable dontaudit state between handle commits
- [Patch 2/2 v3] libsemanage: maintain disable dontaudit state between handle commits
- [PATCH 2/2 v3] Refactor expander
- [Patch 2/2 v4] libsemanage: maintain disable dontaudit state between handle commits
- [Patch 2/2 v6] libsemanage: maintain disable dontaudit state between handle commits
- [Patch 2/2 v7] libsemanage: maintain disable dontaudit state between handle commits
- [PATCH 2/2-v2] NFS: use new LSM interfaces to explicitly set mount options
- [PATCH 2/2] - use common av_to_string implementation
- [patch 2/2] checkpolicy capability support
- [patch 2/2] Fix memory leaks in libsepol/checkpolicy
- [PATCH 2/2] fix several unaligned kernel accesses in the CIPSO engine
- [PATCH 2/2] hijack: update task_alloc_security
- [PATCH 2/2] Introduce symtab_datum_t
- [patch 2/2] libselinux: add support for getting contexts for kernel initial SIDs from selinuxfs
- [PATCH 2/2] libselinux: class and permission mapping support
- [PATCH 2/2] libselinux: class and permission mapping support (try 2)
- [Patch 2/2] libsemanage, libselinux: Get don't audit settings from handle and remember settings after commit.
- [Patch 2/2] libsemanage: create a don't audit flag
- [Patch 2/2] libsemanage: maintain disable dontaudit state between handle commits
- [Patch 2/2] libsemanage: remember and retrieve dontaudit settings
- [PATCH 2/2] LSM/SELinux: inode_{get,set,notify}secctx hooks to access LSM security context information.
- [PATCH 2/2] LSM/SELinux: inode_{get,set}secctx hooks to access LSM security context information.
- [PATCH 2/2] mempolicy: Insert security hook calls for setmempolicy
- [PATCH 2/2] mempolicy: Insert security hook calls for setmempolicy (Attempt 2)
- [PATCH 2/2] NET: fix memory leaks from security_secid_to_secctx()
- [PATCH 2/2] NetLabel: correct CIPSO tag handling when adding new DOI definitions
- [PATCH 2/2] NetLabel: correctly fill in unused CIPSOv4 level and category mappings
- [PATCH 2/2] NetLabel: enable dynamic activation/deactivation of NetLabel/SELinux enforcement
- [PATCH 2/2] NetLabel: fix a cache race condition
- [PATCH 2/2] NFS: use new LSM interfaces to explicitly set mount options
- [patch 2/2] Peersid capability support
- [PATCH 2/2] Refactor expander
- [PATCH 2/2] Refactor expansion of avtab
- [PATCH 2/2] Reference policy: Restrict NetLabel to same MLS label connections by default
- [PATCH 2/2] Rewrite setfiles to use matchpathcon
- [PATCH 2/2] SELinux: check seqno when updating an avc_node
- [PATCH 2/2] SELinux: display SELinux mount options in /proc/mounts
- [PATCH 2/2] SELinux: do not spam dmesg about unix domain sockets
- [PATCH 2/2] SELinux: Fix a RCU free problem with the netport cache
- [PATCH 2/2] selinux: Fix the NetLabel glue code for setsockopt()
- [PATCH 2/2] SELinux: selinux_file_mmap always enforce mapping the 0 page
- [PATCH 2/2] sepolgen: handle the latest reference policy
- [PATCH 2/2] sysctl: Restore the selinux path based label lookup for sysctls.
- [PATCH 2/2] unshare system call patch - needed to test pam_namespace
- [PATCH 2/2] userland support for new range_transition statements
- [PATCH 2/2] Ver 2 Introduce symtab_datum_t
- [PATCH 2/2] VFS: Reorder vfs_getxattr to avoid unnecessary calls to the LSM
- [PATCH 2/2] x86-64: seccomp: fix 32/64 syscall hole (fwd)
- [PATCH 2/3 -v2] mmap: round mmap hint address above mmap_min_addr
- [PATCH 2/3 v2] semantic MLS representation for range_trans_rules
- [PATCH 2/3 v3] semantic MLS representation for range_trans_rules
- [PATCH 2/3] CRED: Split the task security data and move part of it into struct cred
- [PATCH 2/3] labeled-ipsec: Return correct context for SO_PEERSEC
- [PATCH 2/3] libselinux: class and permission mapping support (try 3)
- [PATCH 2/3] libselinux: labeling support (try 3)
- [PATCH 2/3] libselinux: minor updates to AVC, mapping, callbacks
- [PATCH 2/3] libselinux: string and compute_create functions
- [PATCH 2/3] libsemanage: deref and double close of fp
- [patch 2/3] libsemanage: test functions
- [PATCH 2/3] libsepol - fix aliased sensitivities
- [Patch 2/3] Loadable policy module infrastructure
- [PATCH 2/3] Make lsm_priv union in lsm_audit.h anonymous
- [PATCH 2/3] mlsxfrm: Various fixes
- [PATCH 2/3] mmap: round mmap hint address above mmap_min_addr
- [Patch 2/3] mount: quote context option to avoid comma collision
- [PATCH 2/3] NetLabel: add the enumerated tag to the CIPSOv4 protocol
- [PATCH 2/3] NetLabel: better error handling involving mls_export_cat()
- [PATCH 2/3] Refactor expander
- [PATCH 2/3] Refpolicy: remove a duplicate rule in the ipsec.te file
- [PATCH 2/3] secid reconciliation-v01: add LSM hooks
- [PATCH 2/3] SELinux: Add new security mount option to indicate security label support.
|