- 51a3143 Merge branch 'linux-4.14.y' of https://github.com/openela/kernel-lts into android-4.14-phoenix by Tim Zimmermann · 9 months ago
- 003fe24 smack: Handle SMACK64TRANSMUTE in smack_inode_setsecurity() by Roberto Sassu · 1 year, 3 months ago
- d780b74 smack: Set SMACK64TRANSMUTE only for dirs in smack_inode_setxattr() by Roberto Sassu · 1 year, 3 months ago
- df91097 BACKPORT: selinux: enable use of both GFP_KERNEL and GFP_ATOMIC in convert_context() by GONG, Ruiqi · 2 years, 4 months ago
- 2ebc6e4 Merge branch 'linux-4.14.y' of https://github.com/openela/kernel-lts into android-4.14-phoenix by Tim Zimmermann · 12 months ago
- cdb04bf lsm: new security_file_ioctl_compat() hook by Alfred Piccioni · 1 year, 2 months ago
- 9f63fb1 apparmor: avoid crash when parsed profile name is empty by Fedor Pchelkin · 1 year, 2 months ago
- c6d9bca fortify: Explicitly disable Clang support by Kees Cook · 3 years, 10 months ago
- e2946b8 UPSTREAM: selinux: fix missing dput() before selinuxfs unmount by Stephen Smalley · 7 years ago
- 3b3807e Merge 4.14.326 into android-4.14-stable by Greg Kroah-Hartman · 1 year, 5 months ago
- fcebe4c smackfs: Prevent underflow in smk_set_cipso() by Dan Carpenter · 1 year, 8 months ago
- 9121d71 security: keys: perform capable check only on privileged operations by Christian Göttsche · 1 year, 10 months ago
- fce78ed Merge 4.14.322 into android-4.14-stable by Greg Kroah-Hartman · 1 year, 6 months ago
- 4868a24 integrity: Fix possible multiple allocation in integrity_inode_get() by Tianjia Zhang · 1 year, 9 months ago
- 3743d75 evm: Complete description of evm_inode_setattr() by Roberto Sassu · 2 years ago
- 89ea220 Merge 4.14.317 into android-4.14-stable by Greg Kroah-Hartman · 1 year, 9 months ago
- a03dc3d selinux: don't use make's grouped targets feature yet by Paul Moore · 1 year, 9 months ago
- 0efbe09 Merge 4.14.315 into android-4.14-stable by Greg Kroah-Hartman · 1 year, 9 months ago
- d8755b9 selinux: ensure av_permissions.h is built when needed by Paul Moore · 1 year, 11 months ago
- 2a7fa5e selinux: fix Makefile dependencies of flask.h by Ondrej Mosnacek · 1 year, 11 months ago
- dcf8e96 Merge 4.14.308 into android-4.14-stable by Greg Kroah-Hartman · 2 years ago
- 09fa241 ima: Align ima_file_mmap() parameters with mmap_file LSM hook by Roberto Sassu · 2 years, 1 month ago
- 4415bf5 Merge 4.14.305 into android-4.14 by Greg Kroah-Hartman · 2 years, 1 month ago
- 4a945ee tomoyo: fix broken dependency on *.conf.default by Masahiro Yamada · 2 years, 2 months ago
- 524b0e4 Merge 4.14.303 into android-4.14-stable by Greg Kroah-Hartman · 2 years, 1 month ago
- 818e5d2 device_cgroup: Roll back to original exceptions after copy failure by Wang Weiyang · 2 years, 4 months ago
- 26258f1 ima: Fix a potential NULL pointer access in ima_restore_measurement_list by Huaxin Lu · 2 years, 4 months ago
- 11d5fe7 apparmor: fix a memleak in multi_transaction_new() by Gaosheng Cui · 2 years, 6 months ago
- 8141990 ima: Fix misuse of dereference of pointer in template_desc_init_fields() by Xiu Jianfeng · 2 years, 3 months ago
- e0d9457 Merge 4.14.299 into android-4.14-stable by Greg Kroah-Hartman · 2 years, 4 months ago
- 6bb00eb capabilities: fix potential memleak on error path from vfs_getxattr_alloc() by Gaosheng Cui · 2 years, 4 months ago
- 334b337 Merge 4.14.291 into android-4.14-stable by Greg Kroah-Hartman · 2 years, 6 months ago
- 28c94b4 Merge 6c4e435b8d91 ("selftests: timers: clocksource-switch: fix passing errors from child") into android-mainline by Greg Kroah-Hartman · 2 years, 6 months ago
- d531947 apparmor: fix reference count leak in aa_pivotroot() by Xin Xiong · 2 years, 10 months ago
- c912dba apparmor: fix aa_label_asxprint return check by Tom Rix · 3 years ago
- 1fff357 apparmor: Fix failed mount permission check error message by John Johansen · 3 years, 1 month ago
- 0828d1d apparmor: fix quiet_denied for file rules by John Johansen · 3 years, 10 months ago
- 2dabe6a selinux: Add boundary check in put_entry() by Xiu Jianfeng · 2 years, 8 months ago
- b296bf0 Merge 4.14.276 into android-4.14-stable by Greg Kroah-Hartman · 2 years, 10 months ago
- 79dc407 Fix incorrect type in assignment of ipv6 port for audit by Casey Schaufler · 3 years ago
- 87b05d87 selinux: use correct type for context length by Christian Göttsche · 3 years ago
- f00f932 TOMOYO: fix __setup handlers return values by Randy Dunlap · 3 years ago
- 409d37b Merge 4.14.267 into android-4.14-stable by Greg Kroah-Hartman · 3 years ago
- d903c3b ima: Allow template selection with ima_template[_fmt]= after ima_hash= by Roberto Sassu · 3 years, 1 month ago
- 9021b24 ima: Remove ima_policy file before directory by Stefan Berger · 3 years, 1 month ago
- 340f61f integrity: check the return value of audit_log_start() by Xiaoke Wang · 3 years, 1 month ago
- f3a2f78 Merge 4.14.261 into android-4.14-stable by Greg Kroah-Hartman · 3 years, 2 months ago
- 8a26445 selinux: initialize proto variable in selinux_ip_postroute_compat() by Tom Rix · 3 years, 2 months ago
- cc48e33 Merge 4.14.256 into android-4.14-stable by Greg Kroah-Hartman · 3 years, 3 months ago
- 65b9b70 apparmor: fix error check by Tom Rix · 4 years, 5 months ago
- aa88387 smackfs: use netlbl_cfg_cipsov4_del() for deleting cipso_v4_doi by Tetsuo Handa · 3 years, 4 months ago
- 0b1ceda smackfs: use __GFP_NOFAIL for smk_cipso_doi() by Tetsuo Handa · 3 years, 4 months ago
- 8c03cc8a smackfs: Fix use-after-free in netlbl_catmap_walk() by Pawan Gupta · 3 years, 6 months ago
- 8125c6e evm: mark evm_fixmode as __ro_after_init by Austin Kim · 3 years, 4 months ago
- 84b7952 binder: use cred instead of task for selinux checks by Todd Kjos · 3 years, 4 months ago
- 9693ca7 BACKPORT: binder: use cred instead of task for selinux checks by Todd Kjos · 3 years, 4 months ago
- 620d928 UPSTREAM: security: selinux: allow per-file labeling for bpffs by Connor O'Brien · 5 years ago
- 1a9762f Merge 4.14.248 into android-4.14-stable by Greg Kroah-Hartman · 3 years, 5 months ago
- ea83438 apparmor: remove duplicate macro list_entry_is_head() by Andy Shevchenko · 4 years, 2 months ago
- 1dff798 Merge 4.14.247 into android-4.14-stable by Greg Kroah-Hartman · 3 years, 5 months ago
- 2e6c5173 Smack: Fix wrong semantics in smk_access_entry() by Tianjia Zhang · 3 years, 7 months ago
- a9c5853 IMA: remove -Wmissing-prototypes warning by Austin Kim · 3 years, 8 months ago
- 7b74d84 Merge 4.14.240 into android-4.14-stable by Greg Kroah-Hartman · 3 years, 7 months ago
- 5c2dca9 smackfs: restrict bytes count in smk_set_cipso() by Tetsuo Handa · 3 years, 11 months ago
- 3531c1c selinux: use __GFP_NOWARN with GFP_NOWAIT in the AVC by Minchan Kim · 3 years, 9 months ago
- 32d7afd ANDROID: selinux: modify RTM_GETNEIGH{TBL} by Bram Bonné · 3 years, 10 months ago
- 22dc72c Merge 4.14.233 into android-4.14-stable by Greg Kroah-Hartman · 3 years, 9 months ago
- c7de5df security: commoncap: fix -Wstringop-overread warning by Arnd Bergmann · 4 years ago
- 9da0274 Merge 4.14.226 into android-4.14-stable by Greg Kroah-Hartman · 4 years ago
- f95ea27 Revert 95ebabde382c ("capabilities: Don't allow writing ambiguous v3 file capabilities") by Eric W. Biederman · 4 years ago
- 496d5ba Merge 4.14.224 into android-4.14-stable by Greg Kroah-Hartman · 4 years ago
- c6e1d0e smackfs: restrict bytes count in smackfs write functions by Sabyrzhan Tasbolatov · 4 years, 1 month ago
- a2e73af Merge 4.14.223 into android-4.14-stable by Greg Kroah-Hartman · 4 years ago
- 5bbec09 KEYS: trusted: Fix migratable=1 failing by Jarkko Sakkinen · 4 years, 1 month ago
- ad26df1 certs: Fix blacklist flag type confusion by David Howells · 4 years, 3 months ago
- e516a30 capabilities: Don't allow writing ambiguous v3 file capabilities by Eric W. Biederman · 4 years, 2 months ago
- 005da2a ima: Free IMA measurement buffer after kexec syscall by Lakshmi Ramasubramanian · 4 years, 1 month ago
- 5db2c9e ima: Free IMA measurement buffer on error by Lakshmi Ramasubramanian · 4 years, 1 month ago
- c0303b0 Merge 4.14.222 into android-4.14-stable by Greg Kroah-Hartman · 4 years ago
- 83515cf cap: fix conversions on getxattr by Miklos Szeredi · 4 years, 1 month ago
- 564b1302 Merge 4.14.217 into android-4.14-stable by Greg Kroah-Hartman · 4 years, 1 month ago
- 2f121a8 dump_common_audit_data(): fix racy accesses to ->d_name by Al Viro · 4 years, 2 months ago
- 89616f1 Merge 4.14.213 into android-4.14-stable by Greg Kroah-Hartman · 4 years, 2 months ago
- 07c67ec ima: Don't modify file descriptor mode on the fly by Roberto Sassu · 4 years, 3 months ago
- 44f5d9f selinux: fix inode_doinit_with_dentry() LABEL_INVALID error handling by Paul Moore · 4 years, 4 months ago
- ce7acf72d selinux: fix error initialization in inode_doinit_with_dentry() by Tianyue Ren · 4 years, 5 months ago
- 76cc1c0 Merge 4.14.207 into android-4.14-stable by Greg Kroah-Hartman · 4 years, 3 months ago
- 531ef54 selinux: Fix error return code in sel_ib_pkey_sid_slow() by Chen Zhou · 4 years, 3 months ago
- 9ddf99d Merge 4.14.203 into android-4.14-stable by Greg Kroah-Hartman · 4 years, 4 months ago
- d0f7036 ima: Don't ignore errors from crypto_shash_update() by Roberto Sassu · 4 years, 6 months ago
- c1013a4 Merge 4.14.200 into android-4.14-stable by Greg Kroah-Hartman · 4 years, 5 months ago
- dd79c17 selinux: sel_avc_get_stat_idx should increase position index by Vasily Averin · 5 years ago
- a7eda6e BACKPORT: security: allow using Clang's zero initialization for stack variables by glider@google.com · 4 years, 8 months ago
- 831ff81 Merge 4.14.194 into android-4.14-stable by Greg Kroah-Hartman · 4 years, 6 months ago
- 75f8b5a Smack: prevent underflow in smk_set_cipso() by Dan Carpenter · 4 years, 7 months ago
- 12917b4 Smack: fix another vsscanf out of bounds by Dan Carpenter · 4 years, 7 months ago
- a963ddc Smack: fix use-after-free in smk_write_relabel_self() by Eric Biggers · 4 years, 8 months ago
- b726057 Merge 4.14.187 into android-4.14-stable by Greg Kroah-Hartman · 4 years, 8 months ago
- ecf8e18 apparmor: don't try to replace stale label in ptraceme check by Jann Horn · 6 years ago
- e570b0f Merge 4.14.186 into android-4.14-stable by Greg Kroah-Hartman · 4 years, 8 months ago