Home
last modified time | relevance | path

Searched refs:enforce (Results 1 – 25 of 55) sorted by relevance

123

/linux/security/loadpin/
H A Dloadpin.c47 static int enforce = IS_ENABLED(CONFIG_SECURITY_LOADPIN_ENFORCE); variable
71 .data = &enforce,
118 if (enforce) { in loadpin_sb_free_security()
142 if (!enforce) { in loadpin_check()
174 if (unlikely(!enforce)) { in loadpin_check()
257 enforce ? "" : "not "); in loadpin_init()
439 module_param(enforce, int, 0);
440 MODULE_PARM_DESC(enforce, "Enforce module/firmware pinning");
/linux/security/ipe/
H A Deval.c23 bool enforce = true; variable
378 if (!READ_ONCE(enforce)) in ipe_evaluate_event()
392 module_param(enforce, bool, 0400);
393 MODULE_PARM_DESC(enforce, "Start IPE in enforce or permissive mode");
H A Dfs.c86 old_value = READ_ONCE(enforce); in setenforce()
93 WRITE_ONCE(enforce, new_value); in setenforce()
113 result = ((READ_ONCE(enforce)) ? "1" : "0"); in getenforce()
H A Deval.h19 extern bool enforce;
H A Daudit.c146 op, audit_hook_names[ctx->hook], READ_ONCE(enforce), in ipe_audit_match()
260 * @new_enforce: The new value enforce to be set.
261 * @old_enforce: The old value currently in enforce.
/linux/Documentation/admin-guide/LSM/
H A DLoadPin.rst9 and/or unchangeable filesystem to enforce module and firmware loading
14 "``loadpin.enforce``". By default, it is enabled, but can be disabled at
15 boot ("``loadpin.enforce=0``").
H A Dipe.rst39 checks, allowing IPE to enforce policies that trust files protected by
45 For the IPE policy, specifically, it grants the ability to enforce
235 are signed through the PKCS#7 message format to enforce some level of
299 only enforce the policy marked active. Note that only one policy can be active
334 The default mode is enforce, and can be changed via the kernel command
335 line parameter ``ipe.enforce=(0|1)``, or the securityfs node
336 ``/sys/kernel/security/ipe/enforce``.
/linux/include/linux/
H A Dpage-flags.h385 #define PF_ANY(page, enforce) PF_POISONED_CHECK(page) argument
386 #define PF_HEAD(page, enforce) PF_POISONED_CHECK(compound_head(page)) argument
387 #define PF_NO_TAIL(page, enforce) ({ \ argument
388 VM_BUG_ON_PGFLAGS(enforce && PageTail(page), page); \
390 #define PF_NO_COMPOUND(page, enforce) ({ \ argument
391 VM_BUG_ON_PGFLAGS(enforce && PageCompound(page), page); \
393 #define PF_SECOND(page, enforce) ({ \ argument
/linux/Documentation/userspace-api/
H A Dcheck_exec.rst10 are intended for script interpreters and dynamic linkers to enforce a
31 set to 1 (i.e. always enforce restrictions).
75 Programs should only enforce consistent restrictions according to the
/linux/Documentation/admin-guide/device-mapper/
H A Ddm-ebs.rst48 offset 128 sectors, enforce 2KiB underlying device block size.
/linux/Documentation/hwmon/
H A Docc.rst121 Maximum power cap that the OCC can enforce in
123 power[1-n]_cap_min Minimum power cap that the OCC can enforce in
H A Df71805f.rst160 enforce this limit though.
/linux/Documentation/scsi/
H A Dscsi.rst24 will enforce the correct ordering of loading and unloading modules in
/linux/security/selinux/
H A DKconfig38 /sys/fs/selinux/enforce.
/linux/Documentation/mm/
H A Dksm.rst35 Every "chain" and all "dups" linked into a "chain" enforce the
/linux/Documentation/arch/arm64/
H A Dcpu-hotplug.rst59 brought online. Firmware can enforce its policy via PSCI's return codes. e.g.
/linux/security/integrity/
H A DKconfig83 The .machine keyring can be configured to enforce CA restriction
/linux/Documentation/admin-guide/cgroup-v1/
H A Ddevices.rst8 Implement a cgroup to track and enforce open and mknod restrictions
/linux/Documentation/process/
H A Dkernel-enforcement-statement.rst11 Although there is a right to enforce the separate copyright interests in the
/linux/Documentation/arch/riscv/
H A Dcmodx.rst10 program must enforce its own synchronization with the unprivileged fence.i
/linux/Documentation/bpf/
H A Dgraph_ds_impl.rst77 the same map_value and will enforce that the correct lock is held when
116 obvious. The verifier could enforce the same semantics as for ``bpf_obj_drop``,
/linux/Documentation/arch/x86/
H A Dxstate.rst27 enabling, the kernel can enforce userspace applications to have
/linux/arch/arm64/boot/dts/rockchip/
H A Drk3588-jaguar-pre-ict-tester.dtso83 * issue. Therefore, let's enforce a pull-up (which is
/linux/Documentation/arch/powerpc/
H A Ddexcr.rst25 enforce aspects for the kernel and userspace.
/linux/Documentation/edac/
H A Dmemory_repair.rst106 5. Drivers should enforce that live repair is safe. In systems where memory

123