Merge branch 'next' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
Pull security subsystem updates from James Morris: "Highlights: IMA: - provide ">" and "<" operators for fowner/uid/euid rules KEYS: - add a system blacklist keyring - add KEYCTL_RESTRICT_KEYRING, exposes keyring link restriction functionality to userland via keyctl() LSM: - harden LSM API with __ro_after_init - add prlmit security hook, implement for SELinux - revive security_task_alloc hook TPM: - implement contextual TPM command 'spaces'" * 'next' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security: (98 commits) tpm: Fix reference count to main device tpm_tis: convert to using locality callbacks tpm: fix handling of the TPM 2.0 event logs tpm_crb: remove a cruft constant keys: select CONFIG_CRYPTO when selecting DH / KDF apparmor: Make path_max parameter readonly apparmor: fix parameters so that the permission test is bypassed at boot apparmor: fix invalid reference to index variable of iterator line 836 apparmor: use SHASH_DESC_ON_STACK security/apparmor/lsm.c: set debug messages apparmor: fix boolreturn.cocci warnings Smack: Use GFP_KERNEL for smk_netlbl_mls(). smack: fix double free in smack_parse_opts_str() KEYS: add SP800-56A KDF support for DH KEYS: Keyring asymmetric key restrict method with chaining KEYS: Restrict asymmetric key linkage using a specific keychain KEYS: Add a lookup_restriction function for the asymmetric key type KEYS: Add KEYCTL_RESTRICT_KEYRING KEYS: Consistent ordering for __key_link_begin and restrict check KEYS: Add an optional lookup_restriction hook to key_type ...
No related branches found
No related tags found
Showing
- Documentation/crypto/asymmetric-keys.txt 51 additions, 0 deletionsDocumentation/crypto/asymmetric-keys.txt
- Documentation/security/keys.txt 76 additions, 24 deletionsDocumentation/security/keys.txt
- certs/Kconfig 18 additions, 0 deletionscerts/Kconfig
- certs/Makefile 6 additions, 0 deletionscerts/Makefile
- certs/blacklist.c 174 additions, 0 deletionscerts/blacklist.c
- certs/blacklist.h 3 additions, 0 deletionscerts/blacklist.h
- certs/blacklist_hashes.c 6 additions, 0 deletionscerts/blacklist_hashes.c
- certs/blacklist_nohashes.c 5 additions, 0 deletionscerts/blacklist_nohashes.c
- certs/system_keyring.c 31 additions, 8 deletionscerts/system_keyring.c
- crypto/asymmetric_keys/asymmetric_type.c 94 additions, 8 deletionscrypto/asymmetric_keys/asymmetric_type.c
- crypto/asymmetric_keys/pkcs7_parser.h 1 addition, 0 deletionscrypto/asymmetric_keys/pkcs7_parser.h
- crypto/asymmetric_keys/pkcs7_verify.c 24 additions, 8 deletionscrypto/asymmetric_keys/pkcs7_verify.c
- crypto/asymmetric_keys/restrict.c 158 additions, 3 deletionscrypto/asymmetric_keys/restrict.c
- crypto/asymmetric_keys/x509_parser.h 1 addition, 0 deletionscrypto/asymmetric_keys/x509_parser.h
- crypto/asymmetric_keys/x509_public_key.c 15 additions, 0 deletionscrypto/asymmetric_keys/x509_public_key.c
- drivers/char/tpm/Kconfig 2 additions, 1 deletiondrivers/char/tpm/Kconfig
- drivers/char/tpm/Makefile 2 additions, 1 deletiondrivers/char/tpm/Makefile
- drivers/char/tpm/st33zp24/i2c.c 20 additions, 3 deletionsdrivers/char/tpm/st33zp24/i2c.c
- drivers/char/tpm/st33zp24/spi.c 20 additions, 3 deletionsdrivers/char/tpm/st33zp24/spi.c
- drivers/char/tpm/st33zp24/st33zp24.c 6 additions, 6 deletionsdrivers/char/tpm/st33zp24/st33zp24.c
Loading
Please register or sign in to comment