linux/security
Linus Torvalds 8fc574321e selinux/stable-7.2 PR 20260717
-----BEGIN PGP SIGNATURE-----
 
 iQJIBAABCgAyFiEES0KozwfymdVUl37v6iDy2pc3iXMFAmpaXtgUHHBhdWxAcGF1
 bC1tb29yZS5jb20ACgkQ6iDy2pc3iXPAGxAAyCWrUecMqUOJTSYbTl5hjRqR6w9U
 +h1hfFaiukGgEokG9qrFBR7MTgei0ybcyt2d/Mn8r2Mz1C0kK4tBjtT8ho1tqVZD
 5ANfti4ffhw6H83ZHRf5h18vwNXldHjBsEwjthySRYwlK2KsV4tW/+WFCStdWzCH
 TOpUShUlkIMvibNbKf6vvqk75jP/SCZLpjsRBD+gdRSkXqcFLLqXrK+FiAw4NKXE
 z7nRc0KK161eT4GM+KPBYkC9hE6+PntamYL10nDgrz1r3hp/B2Wx66bO36NR7XvA
 5omsa/hJW7aXoQtXTxlf2+AuhYKjig+KYdxhidU8jKVXc16fUn4UmeUZJRvoDQKW
 ryjPALVnbBIrw/e+nDYV0wsJD6q8xAE3LuIQIMir661ZMtf7umdmm6G1anyhKYHe
 oLgjKyOiaGaY9WeW+g+bO29pmcpnmPPyiNI2KRkLsfgeCB2JKECDLyjZboCNjWGV
 ykdmt3kXndlaEwpmxvJBFCb4WlB2mKpCz6HxgNhM2jPu5X4MwS6fkrvIlBNHcdTg
 o2Sz5cuQLcnpD9A91AhKmKdxNYNeT7H4KlMm8x/8vRHNQbmi72WE7kkuEj09augt
 qeO8kbeq7dm13wY72MzNOQXwiNtmeCUDPwehud86Hqg0iZDDyB2RGWtn14AWQhGb
 Kmpyx9QglgeUEyc=
 =4P+L
 -----END PGP SIGNATURE-----

Merge tag 'selinux-pr-20260717' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux

Pull selinux fix from Paul Moore:
 "A single SELinux patch to correct a problem with the overlayfs mmap()
  and mprotect() fixes from earlier this year where we inadvertenly
  included an additional SELinux execmem permission check on some
  operations"

* tag 'selinux-pr-20260717' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux:
  selinux: fix incorrect execmem checks on overlayfs
2026-07-17 11:04:46 -07:00
..
apparmor apparmor: advertise the tcp fast open fix is applied 2026-06-23 22:15:15 -07:00
bpf bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized 2026-06-30 16:31:56 +02:00
integrity ima: Support staging and deleting N measurements records 2026-06-08 11:43:34 -04:00
ipe treewide: change inode->i_ino from unsigned long to u64 2026-03-06 14:31:28 +01:00
keys keys: keyctl_pkey: replace BUG with return -EOPNOTSUPP 2026-06-15 15:19:13 +03:00
landlock landlock: Update formatting 2026-07-10 12:59:10 +02:00
loadpin Convert 'alloc_flex' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
lockdown lockdown: move initcalls to the LSM framework 2025-10-22 19:24:27 -04:00
safesetid Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
selinux selinux: fix incorrect execmem checks on overlayfs 2026-07-14 18:10:20 -04:00
smack security,fs,nfs,net: update security_inode_listsecurity() interface 2026-05-01 11:29:33 -04:00
tomoyo tomoyo: use u64 for holding inode->i_ino value 2026-04-15 00:00:10 +09:00
yama Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
commoncap_test.c security: Add KUnit tests for kuid_root_in_ns and vfsuid_root_in_currentns 2026-01-09 11:28:28 -06:00
commoncap.c security: Add KUnit tests for kuid_root_in_ns and vfsuid_root_in_currentns 2026-01-09 11:28:28 -06:00
device_cgroup.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
inode.c securityfs: use kstrdup_const() to manage symlink targets 2026-03-17 17:13:36 -04:00
Kconfig proc: make PROC_MEM_FORCE_PTRACE the Kconfig default 2026-04-13 09:12:37 -07:00
Kconfig.hardening security/Kconfig.hardening: Remove tautological condition from CC_HAS_RANDSTRUCT 2026-05-27 15:20:04 -07:00
lsm_audit.c treewide: change inode->i_ino from unsigned long to u64 2026-03-06 14:31:28 +01:00
lsm_init.c lsm: add backing_file LSM hooks 2026-04-03 16:53:50 -04:00
lsm_notifier.c
lsm_syscalls.c lsm: hold cred_guard_mutex for lsm_set_self_attr() 2026-05-14 16:47:59 -04:00
lsm.h lsm: add backing_file LSM hooks 2026-04-03 16:53:50 -04:00
Makefile
min_addr.c lsm: preserve /proc/sys/vm/mmap_min_addr when !CONFIG_SECURITY 2026-01-29 13:56:53 -05:00
security.c security,fs,nfs,net: update security_inode_listsecurity() interface 2026-05-01 11:29:33 -04:00