summaryrefslogtreecommitdiff
path: root/security/apparmor/include/policy.h
AgeCommit message (Expand)AuthorFilesLines
2023-10-19apparmor: allow restricting unprivileged change_profileJohn Johansen1-0/+1
2023-10-19apparmor: refcount the pdbJohn Johansen1-12/+37
2023-10-19apparmor: pass cred through to audit info.John Johansen1-3/+6
2023-08-08apparmor: remove unused PROF_* macrosGONG, Ruiqi1-3/+0
2023-08-08apparmor: cleanup unused declarations in policy.hXiu Jianfeng1-6/+0
2022-10-25apparmor: refactor code that alloc null profilesJohn Johansen1-2/+4
2022-10-04apparmor: rework profile->rules to be a listJohn Johansen1-1/+16
2022-10-04apparmor: refactor profile rules and attachmentsJohn Johansen1-33/+51
2022-10-04apparmor: add the ability for policy to specify a permission tableJohn Johansen1-1/+4
2022-10-04apparmor: add user mode flagJohn Johansen1-0/+3
2022-10-04apparmor: extend permissions to support a label and tag stringJohn Johansen1-2/+4
2022-10-04apparmor: preparse for state being more than just an integerJohn Johansen1-7/+7
2022-10-04apparmor: convert policy lookup to use accept as an indexJohn Johansen1-0/+12
2022-10-04apparmor: convert xmatch to using the new shared policydb structJohn Johansen1-3/+1
2022-10-04apparmor: combine file_rules and aa_policydb into a single shared structJohn Johansen1-3/+11
2022-10-04apparmor: compute policydb permission on profile loadJohn Johansen1-0/+1
2022-10-04apparmor: convert xmatch to use aa_perms structureJohn Johansen1-1/+2
2022-10-04apparmor: compute xmatch permissions on profile loadMike Salvatore1-0/+2
2022-07-19apparmor: allow label to carry debug flagsJohn Johansen1-0/+4
2022-07-19apparmor: fix overlapping attachment computationJohn Johansen1-1/+1
2021-02-07apparmor: update policy capable checks to use a labelJohn Johansen1-2/+4
2019-06-19apparmor: fix PROFILE_MEDIATES for untrusted inputJohn Johansen1-1/+10
2019-06-05treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 441Thomas Gleixner1-5/+1
2018-10-03apparmor: Parse secmark policyMatthew Garrett1-0/+3
2018-03-14apparmor: remove POLICY_MEDIATES_SAFEJohn Johansen1-11/+1
2018-03-14apparmor: add base infastructure for socket mediationJohn Johansen1-0/+11
2018-02-09apparmor: convert attaching profiles via xattrs to use dfa matchingJohn Johansen1-2/+0
2018-02-09apparmor: Add support for attaching profiles via xattr, presence and valueMatthew Garrett1-0/+6
2017-10-26Revert "apparmor: add base infastructure for socket mediation"Linus Torvalds1-13/+0
2017-09-22apparmor: add base infastructure for socket mediationJohn Johansen1-0/+13
2017-06-11apparmor: switch from profiles to using labels on contextsJohn Johansen1-78/+32
2017-06-11apparmor: add fn to test if profile supports a given mediation classJohn Johansen1-0/+10
2017-06-11apparmor: provide finer control over policy managementJohn Johansen1-2/+6
2017-06-08apparmor: move permissions into their own file to be more easily sharedJohn Johansen1-0/+1
2017-06-08apparmor: allow profiles to provide info to disconnected pathsJohn Johansen1-0/+2
2017-02-21Merge branch 'next' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/...Linus Torvalds1-142/+57
2017-01-16apparmor: support querying extended trusted helper extra dataWilliam Hua1-0/+16
2017-01-16apparmor: change op from int to const char *John Johansen1-1/+2
2017-01-16apparmor: pass the subject profile into profile replace/removeJohn Johansen1-3/+4
2017-01-16apparmor: allow introspecting the loaded policy pre internal transformJohn Johansen1-2/+3
2017-01-16apparmor: add profile and ns params to aa_may_manage_policy()John Johansen1-1/+1
2017-01-16apparmor: add ns being viewed as a param to policy_admin_capable()John Johansen1-1/+1
2017-01-16apparmor: add ns being viewed as a param to policy_view_capable()John Johansen1-1/+3
2017-01-16apparmor: Make aa_remove_profile() callable from a different viewJohn Johansen1-1/+1
2017-01-16apparmor: name null-XXX profiles after the executableJohn Johansen1-1/+2
2017-01-16apparmor: pass gfp_t parameter into profile allocationJohn Johansen1-1/+1
2017-01-16apparmor: refactor prepare_ns() and make usable from different viewsJohn Johansen1-1/+2
2017-01-16apparmor: add fn to lookup profiles by fqnameJohn Johansen1-0/+2
2017-01-16apparmor: add strn version of lookup_profile fnJohn Johansen1-0/+2
2017-01-16apparmor: rename replacedby to proxyJohn Johansen1-10/+10