linux/security
Linus Torvalds c5096fec0c selinux/stable-7.2 PR 20260805
-----BEGIN PGP SIGNATURE-----
 
 iQJIBAABCgAyFiEES0KozwfymdVUl37v6iDy2pc3iXMFAmpzc6gUHHBhdWxAcGF1
 bC1tb29yZS5jb20ACgkQ6iDy2pc3iXPZug//SUeo33WvIYrLhlMYwPaVh9jqaR7c
 TG/bdUUofqPHxCXAMdmdqBVv3p3xU+7h6ds4CHFmgiWCUJ53ApbH+tl+lPxOzxTC
 awIWed5tJbFBiZ9ZQNc2hwaY5ETM0wQsVoZDAqWBZeu+Yf76ynjJN5fwxXRKBtcO
 7DJR/NpPj1lHdp6AR3rfB/RQUVhg/0CnlFYb04Ef5aIwZ8fdlFh99GaZsQtMZvfO
 do6Yud/iNyEsL42lp7Zf21Ejlq8ubToLUCKEMygT2iDhKBq69DbOgMABkH0m6Bco
 A98s1KYARddzxT98bzRZkhzxiun0r9QVprYWzFPGi+pMkXi5eG6qgEMq/tkST313
 kD3GsQPPQxY5k/AklD57/CoeI9rU7ioeZH/ZfFxDHupl5ExogI26VJ3h2obkdq3A
 aMZlr/rl5PPJD9qxjw8qFQd7Wn8A7Q1p041Bbf3pi1xxeVvdvP2z/e/MU9RQ7Xpr
 UIQNqd2QU3/uVstY743oximLRNQnRL7Aqq8r5KrbqeP9mlX6r+eEv2q0nBuqIAcR
 7FOnkIn86ptl6prbTbG1FEYeRVypxAGuJrA6dDv8h2r4c4BuRc1Za3vVqluXH2Vg
 OxExgrP2Dg1TMQFAse4dTQlGOltLl1FvTd9JBm1t3kxpi0pbby2mUcHg3xjC/Cbm
 8Dbxe9fEmsK+/jc=
 =YbZ/
 -----END PGP SIGNATURE-----

Merge tag 'selinux-pr-20260805' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux

Pull selinux fixes from Paul Moore:

 - Continue to improve the validation of SELinux policies during load

 - Fix a SELinux regression caused by bpffs changes in v7.2-rc1

 - Fix a SELinux preformance regression caused by SELinux changes in
   v7.2-rc1

* tag 'selinux-pr-20260805' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux:
  selinux: check level category sets once at load time
  selinux: require every boolean value to be defined
  selinux: reject an unclaimed class value in security_get_classes()
  selinux: require a class's permission values to cover its permission count
  selinux: do not cancel a policy conversion that never started
  selinux: bpf: check SBLABEL_MNT before isec init
  selinux: reject a class permission count below its inherited common
  selinux: reject a permission value exceeding the class permission count
2026-08-05 13:40:11 -07:00
..
apparmor apparmor: advertise the tcp fast open fix is applied 2026-06-23 22:15:15 -07:00
bpf bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized 2026-06-30 16:31:56 +02:00
integrity ima: Instantiate file_truncate and path_truncate hooks 2026-08-04 12:35:02 -04:00
ipe treewide: change inode->i_ino from unsigned long to u64 2026-03-06 14:31:28 +01:00
keys keys: make keyring key-chunk byte order agree with keyring_diff_objects() 2026-07-23 18:23:39 +03:00
landlock landlock: Update formatting 2026-07-10 12:59:10 +02:00
loadpin Convert 'alloc_flex' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
lockdown lockdown: move initcalls to the LSM framework 2025-10-22 19:24:27 -04:00
safesetid Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
selinux selinux: check level category sets once at load time 2026-08-04 10:57:46 -04:00
smack security,fs,nfs,net: update security_inode_listsecurity() interface 2026-05-01 11:29:33 -04:00
tomoyo tomoyo: use u64 for holding inode->i_ino value 2026-04-15 00:00:10 +09:00
yama Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
commoncap_test.c security: Add KUnit tests for kuid_root_in_ns and vfsuid_root_in_currentns 2026-01-09 11:28:28 -06:00
commoncap.c security: Add KUnit tests for kuid_root_in_ns and vfsuid_root_in_currentns 2026-01-09 11:28:28 -06:00
device_cgroup.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
inode.c securityfs: use kstrdup_const() to manage symlink targets 2026-03-17 17:13:36 -04:00
Kconfig proc: make PROC_MEM_FORCE_PTRACE the Kconfig default 2026-04-13 09:12:37 -07:00
Kconfig.hardening security/Kconfig.hardening: Remove tautological condition from CC_HAS_RANDSTRUCT 2026-05-27 15:20:04 -07:00
lsm_audit.c treewide: change inode->i_ino from unsigned long to u64 2026-03-06 14:31:28 +01:00
lsm_init.c lsm: add backing_file LSM hooks 2026-04-03 16:53:50 -04:00
lsm_notifier.c lsm: split the notifier code out into lsm_notifier.c 2025-10-22 19:24:15 -04:00
lsm_syscalls.c lsm: hold cred_guard_mutex for lsm_set_self_attr() 2026-05-14 16:47:59 -04:00
lsm.h lsm: add backing_file LSM hooks 2026-04-03 16:53:50 -04:00
Makefile lsm: split the init code out into lsm_init.c 2025-10-22 19:24:16 -04:00
min_addr.c lsm: preserve /proc/sys/vm/mmap_min_addr when !CONFIG_SECURITY 2026-01-29 13:56:53 -05:00
security.c security,fs,nfs,net: update security_inode_listsecurity() interface 2026-05-01 11:29:33 -04:00