| /linux/security/ |
| H A D | lsm_init.c | 11 #include "lsm.h" 83 __setup("lsm=", lsm_choose_lsm); 97 __setup("lsm.debug", lsm_debug_enable); 101 * @lsm: LSM definition 104 static void __init lsm_enabled_set(struct lsm_info *lsm, bool enabled) in lsm_enabled_set() argument 110 if (!lsm->enabled || in lsm_enabled_set() 111 lsm->enabled == &lsm_enabled_true || in lsm_enabled_set() 112 lsm->enabled == &lsm_enabled_false) { in lsm_enabled_set() 113 lsm->enabled = enabled ? &lsm_enabled_true : &lsm_enabled_false; in lsm_enabled_set() 115 *lsm in lsm_enabled_set() 123 lsm_is_enabled(struct lsm_info * lsm) lsm_is_enabled() argument 132 lsm_order_exists(struct lsm_info * lsm) lsm_order_exists() argument 153 lsm_order_append(struct lsm_info * lsm,const char * src) lsm_order_append() argument 200 struct lsm_info *lsm; lsm_order_parse() local 285 lsm_prepare(struct lsm_info * lsm) lsm_prepare() argument 323 lsm_init_single(struct lsm_info * lsm) lsm_init_single() argument 385 struct lsm_info *lsm; early_security_init() local 408 struct lsm_info **lsm; security_init() local [all...] |
| H A D | Kconfig | 281 This can be controlled at boot with the "lsm=" parameter.
|
| /linux/security/integrity/ima/ |
| H A D | ima_policy.c | 124 } lsm[MAX_LSM_RULES]; 390 ima_filter_rule_free(entry->lsm[i].rule); in ima_lsm_free_rule() 391 kfree(entry->lsm[i].args_p); in ima_lsm_free_rule() 420 * lsm rules can change in ima_lsm_copy_rule() 426 memset(nentry->lsm, 0, sizeof_field(struct ima_rule_entry, lsm)); in ima_lsm_copy_rule() 429 if (!entry->lsm[i].args_p) in ima_lsm_copy_rule() 432 nentry->lsm[i].type = entry->lsm[i].type; in ima_lsm_copy_rule() 433 nentry->lsm[ in ima_lsm_copy_rule() 122 } lsm[MAX_LSM_RULES]; global() member [all...] |
| /linux/Documentation/translations/zh_CN/security/ |
| H A D | index.rst | 20 lsm 21 lsm-development
|
| H A D | lsm-development.rst | 4 :Original: Documentation/security/lsm-development.rst
|
| /linux/Documentation/bpf/ |
| H A D | prog_lsm.rst | 61 * ``"lsm/file_mprotect"`` indicates the LSM hook that the program must 67 SEC("lsm/file_mprotect") 134 `tools/testing/selftests/bpf/progs/lsm.c`_ and the corresponding 140 .. _tools/testing/selftests/bpf/progs/lsm.c: 141 …t.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/tools/testing/selftests/bpf/progs/lsm.c
|
| H A D | signing.rst | 281 SEC("lsm/bpf_prog_load") 319 existing ``security_bpf_prog()`` hook (``lsm/bpf_prog``), which fires from 341 with ``security_bpf_prog_free()`` (``lsm/bpf_prog_free``), which deletes the 357 SEC("lsm/bpf_prog") /* fires after load and on every later fd */
|
| /linux/security/keys/ |
| H A D | permission.c | 41 goto lsm; in key_task_permission() 89 lsm: in key_task_permission()
|
| /linux/tools/testing/selftests/bpf/prog_tests/ |
| H A D | signed_loader.c | 1227 struct test_signed_loader_lsm *lsm = NULL; in lsm_signature_verdict() local 1236 lsm = test_signed_loader_lsm__open_and_load(); in lsm_signature_verdict() 1237 if (!ASSERT_OK_PTR(lsm, "lsm_skel_load")) in lsm_signature_verdict() 1239 lsm->bss->monitored_tid = sys_gettid(); in lsm_signature_verdict() 1240 if (!ASSERT_OK(test_signed_loader_lsm__attach(lsm), "lsm_attach")) in lsm_signature_verdict() 1250 lsm->bss->seen = 0; in lsm_signature_verdict() 1258 if (!ASSERT_NEQ(lsm->bss->seen, 0, "bpf LSM in the active LSM set")) in lsm_signature_verdict() 1260 ASSERT_EQ(lsm->bss->seen, 1, "unsigned: one observed load"); in lsm_signature_verdict() 1261 ASSERT_EQ(lsm->bss->sig_verdict, BPF_SIG_UNSIGNED, "unsigned verdict"); in lsm_signature_verdict() 1262 ASSERT_EQ(lsm->bss->sig_keyring_type, BPF_SIG_KEYRING_NONE, "unsigned keyring type"); in lsm_signature_verdict() [all …]
|
| H A D | test_lsm.c | 11 #include "lsm.skel.h" 33 static int test_lsm(struct lsm *skel) in stack_mprotect() 79 struct lsm *skel = NULL; in test_lsm()
|
| /linux/security/safesetid/ |
| H A D | Makefile | 7 safesetid-y := lsm.o securityfs.o
|
| /linux/Documentation/userspace-api/ |
| H A D | lsm.rst | 72 * Documentation/security/lsm.rst 73 * Documentation/security/lsm-development.rst
|
| /linux/security/apparmor/ |
| H A D | Makefile | 7 path.o domain.o policy.o policy_unpack.o procattr.o lsm.o \
|
| /linux/Documentation/admin-guide/LSM/ |
| H A D | ipe.rst | 395 …CA42B51F68962354BA083122A20BB846F26765076DD8EED7B8F4DB auid=4294967295 ses=4294967295 lsm=ipe res=1 429 | lsm | string | No | The lsm name associated with the event … 439 …68962354BA083122A20BB846F26765076DD8EED7B8F4DB auid=4294967295 ses=4294967295 lsm=ipe res=1 errno=0 462 | lsm | string | No | The lsm name associated with the event … 504 …): enforcing=0 old_enforcing=1 auid=4294967295 ses=4294967295 enabled=1 old-enabled=1 lsm=ipe res=1 508 …): enforcing=1 old_enforcing=0 auid=4294967295 ses=4294967295 enabled=1 old-enabled=1 lsm=ipe res=1 531 | lsm | string | No | The lsm name associated with the event …
|
| /linux/tools/testing/selftests/ |
| H A D | Makefile | 69 TARGETS += lsm
|
| /linux/ |
| H A D | README | 80 * LSM Development: Documentation/security/lsm-development.rst
|
| H A D | MAINTAINERS | 6946 T: git https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/lsm.git 15262 T: git https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/lsm.git 24765 T: git https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/lsm.git 24766 F: include/linux/lsm/ 24771 F: include/uapi/linux/lsm.h 24773 F: tools/testing/selftests/lsm/
|
| /linux/Documentation/security/ |
| H A D | lsm.rst | 64 An interface `/sys/kernel/security/lsm` reports a comma separated list
|
| /linux/Documentation/ |
| H A D | .renames.txt | 939 security/LSM security/lsm-development
|