Home
last modified time | relevance | path

Searched refs:lsm (Results 1 – 19 of 19) sorted by relevance

/linux/security/
H A Dlsm_init.c11 #include "lsm.h"
83 __setup("lsm=", lsm_choose_lsm);
97 __setup("lsm.debug", lsm_debug_enable);
101 * @lsm: LSM definition
104 static void __init lsm_enabled_set(struct lsm_info *lsm, bool enabled) in lsm_enabled_set() argument
110 if (!lsm->enabled || in lsm_enabled_set()
111 lsm->enabled == &lsm_enabled_true || in lsm_enabled_set()
112 lsm->enabled == &lsm_enabled_false) { in lsm_enabled_set()
113 lsm->enabled = enabled ? &lsm_enabled_true : &lsm_enabled_false; in lsm_enabled_set()
115 *lsm in lsm_enabled_set()
123 lsm_is_enabled(struct lsm_info * lsm) lsm_is_enabled() argument
132 lsm_order_exists(struct lsm_info * lsm) lsm_order_exists() argument
153 lsm_order_append(struct lsm_info * lsm,const char * src) lsm_order_append() argument
200 struct lsm_info *lsm; lsm_order_parse() local
285 lsm_prepare(struct lsm_info * lsm) lsm_prepare() argument
323 lsm_init_single(struct lsm_info * lsm) lsm_init_single() argument
385 struct lsm_info *lsm; early_security_init() local
408 struct lsm_info **lsm; security_init() local
[all...]
H A DKconfig281 This can be controlled at boot with the "lsm=" parameter.
/linux/security/integrity/ima/
H A Dima_policy.c124 } lsm[MAX_LSM_RULES];
390 ima_filter_rule_free(entry->lsm[i].rule); in ima_lsm_free_rule()
391 kfree(entry->lsm[i].args_p); in ima_lsm_free_rule()
420 * lsm rules can change in ima_lsm_copy_rule()
426 memset(nentry->lsm, 0, sizeof_field(struct ima_rule_entry, lsm)); in ima_lsm_copy_rule()
429 if (!entry->lsm[i].args_p) in ima_lsm_copy_rule()
432 nentry->lsm[i].type = entry->lsm[i].type; in ima_lsm_copy_rule()
433 nentry->lsm[ in ima_lsm_copy_rule()
122 } lsm[MAX_LSM_RULES]; global() member
[all...]
/linux/Documentation/translations/zh_CN/security/
H A Dindex.rst20 lsm
21 lsm-development
H A Dlsm-development.rst4 :Original: Documentation/security/lsm-development.rst
/linux/Documentation/bpf/
H A Dprog_lsm.rst61 * ``"lsm/file_mprotect"`` indicates the LSM hook that the program must
67 SEC("lsm/file_mprotect")
134 `tools/testing/selftests/bpf/progs/lsm.c`_ and the corresponding
140 .. _tools/testing/selftests/bpf/progs/lsm.c:
141 …t.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/tools/testing/selftests/bpf/progs/lsm.c
H A Dsigning.rst281 SEC("lsm/bpf_prog_load")
319 existing ``security_bpf_prog()`` hook (``lsm/bpf_prog``), which fires from
341 with ``security_bpf_prog_free()`` (``lsm/bpf_prog_free``), which deletes the
357 SEC("lsm/bpf_prog") /* fires after load and on every later fd */
/linux/security/keys/
H A Dpermission.c41 goto lsm; in key_task_permission()
89 lsm: in key_task_permission()
/linux/tools/testing/selftests/bpf/prog_tests/
H A Dsigned_loader.c1227 struct test_signed_loader_lsm *lsm = NULL; in lsm_signature_verdict() local
1236 lsm = test_signed_loader_lsm__open_and_load(); in lsm_signature_verdict()
1237 if (!ASSERT_OK_PTR(lsm, "lsm_skel_load")) in lsm_signature_verdict()
1239 lsm->bss->monitored_tid = sys_gettid(); in lsm_signature_verdict()
1240 if (!ASSERT_OK(test_signed_loader_lsm__attach(lsm), "lsm_attach")) in lsm_signature_verdict()
1250 lsm->bss->seen = 0; in lsm_signature_verdict()
1258 if (!ASSERT_NEQ(lsm->bss->seen, 0, "bpf LSM in the active LSM set")) in lsm_signature_verdict()
1260 ASSERT_EQ(lsm->bss->seen, 1, "unsigned: one observed load"); in lsm_signature_verdict()
1261 ASSERT_EQ(lsm->bss->sig_verdict, BPF_SIG_UNSIGNED, "unsigned verdict"); in lsm_signature_verdict()
1262 ASSERT_EQ(lsm->bss->sig_keyring_type, BPF_SIG_KEYRING_NONE, "unsigned keyring type"); in lsm_signature_verdict()
[all …]
H A Dtest_lsm.c11 #include "lsm.skel.h"
33 static int test_lsm(struct lsm *skel) in stack_mprotect()
79 struct lsm *skel = NULL; in test_lsm()
/linux/security/safesetid/
H A DMakefile7 safesetid-y := lsm.o securityfs.o
/linux/Documentation/userspace-api/
H A Dlsm.rst72 * Documentation/security/lsm.rst
73 * Documentation/security/lsm-development.rst
/linux/security/apparmor/
H A DMakefile7 path.o domain.o policy.o policy_unpack.o procattr.o lsm.o \
/linux/Documentation/admin-guide/LSM/
H A Dipe.rst395 …CA42B51F68962354BA083122A20BB846F26765076DD8EED7B8F4DB auid=4294967295 ses=4294967295 lsm=ipe res=1
429 | lsm | string | No | The lsm name associated with the event …
439 …68962354BA083122A20BB846F26765076DD8EED7B8F4DB auid=4294967295 ses=4294967295 lsm=ipe res=1 errno=0
462 | lsm | string | No | The lsm name associated with the event …
504 …): enforcing=0 old_enforcing=1 auid=4294967295 ses=4294967295 enabled=1 old-enabled=1 lsm=ipe res=1
508 …): enforcing=1 old_enforcing=0 auid=4294967295 ses=4294967295 enabled=1 old-enabled=1 lsm=ipe res=1
531 | lsm | string | No | The lsm name associated with the event …
/linux/tools/testing/selftests/
H A DMakefile69 TARGETS += lsm
/linux/
H A DREADME80 * LSM Development: Documentation/security/lsm-development.rst
H A DMAINTAINERS6946 T: git https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/lsm.git
15262 T: git https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/lsm.git
24765 T: git https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/lsm.git
24766 F: include/linux/lsm/
24771 F: include/uapi/linux/lsm.h
24773 F: tools/testing/selftests/lsm/
/linux/Documentation/security/
H A Dlsm.rst64 An interface `/sys/kernel/security/lsm` reports a comma separated list
/linux/Documentation/
H A D.renames.txt939 security/LSM security/lsm-development