summaryrefslogtreecommitdiff
path: root/security/integrity/ima
Commit message (Expand)AuthorAgeFilesLines
* Merge branch 'ima-kexec-fixes' into next-integrityMimi Zohar2021-02-101-0/+3
|\
| * ima: Free IMA measurement buffer after kexec syscallLakshmi Ramasubramanian2021-02-101-0/+2
| * ima: Free IMA measurement buffer on errorLakshmi Ramasubramanian2021-02-101-0/+1
* | IMA: Measure kernel version in early bootRaphael Gianotti2021-01-261-0/+5
* | IMA: define a builtin critical data measurement policyLakshmi Ramasubramanian2021-01-141-0/+12
* | IMA: extend critical data hook to limit the measurement based on a labelTushar Sugandhi2021-01-141-3/+5
* | IMA: limit critical data measurement based on a labelTushar Sugandhi2021-01-141-3/+34
* | IMA: add policy rule to measure critical dataTushar Sugandhi2021-01-141-4/+25
* | IMA: define a hook to measure kernel integrity critical dataTushar Sugandhi2021-01-143-1/+26
* | IMA: add support to measure buffer data hashTushar Sugandhi2021-01-145-9/+30
* | IMA: generalize keyring specific measurement constructsTushar Sugandhi2021-01-144-26/+35
|/
* Merge tag 'efi_updates_for_v5.11' of git://git.kernel.org/pub/scm/linux/kerne...Linus Torvalds2020-12-242-0/+77
|\
| * ima: generalize x86/EFI arch glue for other EFI architecturesChester Lin2020-11-062-0/+77
* | Merge tag 'integrity-v5.11' of git://git.kernel.org/pub/scm/linux/kernel/git/...Linus Torvalds2020-12-166-37/+54
|\ \
| * | ima: Don't modify file descriptor mode on the flyRoberto Sassu2020-11-291-15/+5
| * | ima: select ima-buf template for buffer measurementLakshmi Ramasubramanian2020-11-204-16/+37
| * | ima: defer arch_ima_get_secureboot() call to IMA init timeArd Biesheuvel2020-11-022-6/+12
* | | ima: Implement ima_inode_hashKP Singh2020-11-261-24/+54
|/ /
* | ima: Replace zero-length array with flexible-array memberGustavo A. R. Silva2020-10-291-1/+1
|/
* Merge tag 'integrity-v5.10' of git://git.kernel.org/pub/scm/linux/kernel/git/...Linus Torvalds2020-10-155-64/+143
|\
| * ima: Fix NULL pointer dereference in ima_file_hashKP Singh2020-09-161-0/+10
| * ima: Remove semicolon at the end of ima_get_binary_runtime_size()Roberto Sassu2020-09-151-1/+1
| * ima: Don't ignore errors from crypto_shash_update()Roberto Sassu2020-09-151-0/+2
| * ima: Use kmemdup rather than kmalloc+memcpyAlex Dewar2020-09-151-5/+4
| * ima: limit secure boot feedback scope for appraiseBruno Meneguele2020-09-091-9/+16
| * integrity: invalid kernel parameters feedbackBruno Meneguele2020-09-083-4/+13
| * ima: add check for enforced appraise optionBruno Meneguele2020-09-081-0/+2
| * ima: Fail rule parsing when asymmetric key measurement isn't supportableTyler Hicks2020-08-311-2/+4
| * ima: Pre-parse the list of keyrings in a KEY_CHECK ruleTyler Hicks2020-08-311-45/+93
* | fs/kernel_file_read: Add "offset" arg for partial readsKees Cook2020-10-051-1/+2
* | IMA: Add support for file reads without contentsScott Branden2020-10-051-6/+16
* | LSM: Add "contents" flag to kernel_read_file hookKees Cook2020-10-051-1/+9
* | firmware_loader: Use security_post_load_data()Kees Cook2020-10-051-10/+10
* | LSM: Introduce kernel_post_load_data() hookKees Cook2020-10-051-1/+23
* | fs/kernel_read_file: Add file_size output argumentKees Cook2020-10-051-1/+1
* | fs/kernel_read_file: Switch buffer size arg to size_tKees Cook2020-10-051-1/+1
* | fs/kernel_read_file: Remove redundant size argumentKees Cook2020-10-051-2/+4
* | fs/kernel_read_file: Split into separate include fileScott Branden2020-10-053-0/+3
* | fs/kernel_read_file: Remove FIRMWARE_PREALLOC_BUFFER enumKees Cook2020-10-052-5/+3
* | treewide: Use fallthrough pseudo-keywordGustavo A. R. Silva2020-08-233-7/+7
|/
* Merge tag 'for-v5.9' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris...Linus Torvalds2020-08-114-4/+4
|\
| * Replace HTTP links with HTTPS ones: securityAlexander A. Klimov2020-08-064-4/+4
* | ima: move APPRAISE_BOOTPARAM dependency on ARCH_POLICY to runtimeBruno Meneguele2020-07-202-1/+7
* | ima: AppArmor satisfies the audit rule requirementsTyler Hicks2020-07-201-1/+1
* | ima: Rename internal filter rule functionsTyler Hicks2020-07-202-25/+21
* | ima: Support additional conditionals in the KEXEC_CMDLINE hook functionTyler Hicks2020-07-207-22/+28
* | ima: Use the common function to detect LSM conditionals in a ruleTyler Hicks2020-07-201-9/+2
* | ima: Move comprehensive rule validation checks out of the token parserTyler Hicks2020-07-203-46/+37
* | ima: Use correct type for the args_p member of ima_rule_entry.lsm elementsTyler Hicks2020-07-201-9/+9
* | ima: Shallow copy the args_p member of ima_rule_entry.lsm elementsTyler Hicks2020-07-201-10/+8