linux/security/apparmor/include
Maxime Bélair 17b5758bf3 apparmor: Initial support for compressed policies
This patch allows policies to be compressed in userspace and be sent to
the kernel through the existing ".load" and ".replace" kernel interfaces.

The benefits of this approach are:
 - Save kernel time when loading policies
 - Allow userspace to provide a higher level of compression than the one
   provided by the kernel (ZSTD_CLEVEL_DEFAULT), thus saving space.
 - Allow small embedded systems to only store the compressed version of
   policies in userspace, saving memory.

Userspace-compressed policies improve system time by up to ~30% for big
profiles.

Signed-off-by: Maxime Bélair <maxime.belair@canonical.com>
Signed-off-by: John Johansen <john.johansen@canonical.com>
2026-06-29 10:27:02 -07:00
..
af_unix.h apparmor: fix regression in fs based unix sockets when using old abi 2025-07-15 22:39:43 -07:00
apparmor.h apparmor: add fine grained af_unix mediation 2025-01-18 06:47:12 -08:00
apparmorfs.h apparmor: make include headers self-contained 2026-06-29 10:26:36 -07:00
audit.h apparmor: add support loading per permission tagging 2026-01-29 01:27:47 -08:00
capability.h apparmor: make include headers self-contained 2026-06-29 10:26:36 -07:00
cred.h apparmor: refactor/cleanup cred helper fns. 2026-01-29 01:27:54 -08:00
crypto.h apparmor: move initcalls to the LSM framework 2025-10-22 19:24:27 -04:00
domain.h apparmor: extend permissions to support a label and tag string 2022-10-03 14:49:03 -07:00
file.h apparmor: fix some kernel-doc issues in header files 2025-05-17 01:52:25 -07:00
ipc.h apparmor: add support for profiles to define the kill signal 2025-01-18 06:47:12 -08:00
label.h apparmor: add a conditional version of get_newest_label 2026-06-13 20:14:06 -07:00
lib.h apparmor: make fn_label_build() capable of handling not supported 2026-06-13 20:14:07 -07:00
match.h apparmor: fix differential encoding verification 2026-03-09 16:05:43 -07:00
mount.h apparmor: Fix regression in mount mediation 2023-10-18 16:01:32 -07:00
net.h apparmor: make sure unix socket labeling is correctly updated. 2025-07-20 02:19:27 -07:00
path.h apparmor: make include headers self-contained 2026-06-29 10:26:36 -07:00
perms.h apparmor: fix some kernel-doc issues in header files 2025-05-17 01:52:25 -07:00
policy_compat.h apparmor: isolate policy backwards compatibility to its own file 2022-10-03 14:49:03 -07:00
policy_ns.h apparmor: fix: limit the number of levels of policy namespaces 2026-03-09 16:05:43 -07:00
policy_unpack.h apparmor: Initial support for compressed policies 2026-06-29 10:27:02 -07:00
policy.h apparmor: Initial support for compressed policies 2026-06-29 10:27:02 -07:00
procattr.h apparmor: make include headers self-contained 2026-06-29 10:26:36 -07:00
resource.h apparmor: pass cred through to audit info. 2023-10-18 15:30:38 -07:00
secid.h lsm: replace context+len with lsm_context 2024-12-04 14:42:31 -05:00
sig_names.h apparmor: add support for profiles to define the kill signal 2025-01-18 06:47:12 -08:00
signal.h apparmor: add support for profiles to define the kill signal 2025-01-18 06:47:12 -08:00
task.h apparmor: make include headers self-contained 2026-06-29 10:26:36 -07:00