Show patches with: Submitter = Michael Weiß       |    State = Action Required       |    Archived = No       |   37 patches
Patch Series A/R/T S/W/F Date Submitter Delegate State
[RFC,v3,3/3] devguard: added device guard for mknod in non-initial userns [RFC,v3,1/3] bpf: cgroup: Introduce helper cgroup_bpf_current_enabled() - - - --- 2023-12-13 Michael Weiß New
[RFC,v3,2/3] fs: Make vfs_mknod() to check CAP_MKNOD in user namespace of sb [RFC,v3,1/3] bpf: cgroup: Introduce helper cgroup_bpf_current_enabled() - - - --- 2023-12-13 Michael Weiß New
[RFC,v3,1/3] bpf: cgroup: Introduce helper cgroup_bpf_current_enabled() [RFC,v3,1/3] bpf: cgroup: Introduce helper cgroup_bpf_current_enabled() - 1 - --- 2023-12-13 Michael Weiß New
[RESEND,RFC,v2,14/14] device_cgroup: Allow mknod in non-initial userns if guarded device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,13/14] bpf: cgroup: Introduce helper cgroup_bpf_current_enabled() device_cgroup: guard mknod for non-initial user namespace - 1 - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,12/14] bpf: Add flag BPF_DEVCG_ACC_MKNOD_UNS for device access device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,11/14] vfs: Wire up security hooks for lsm-based device guard in userns device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,10/14] lsm: Add security_sb_alloc_userns() hook device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,09/14] lsm: Add security_inode_mknod_nscap() hook device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,08/14] device_cgroup: Hide devcgroup functionality completely in lsm device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,07/14] drm/amdkfd: Switch from devcgroup_check_permission to security hook device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,06/14] block: Switch from devcgroup_check_permission to security hook device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,05/14] device_cgroup: Implement dev_permission() hook device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,04/14] lsm: Add security_dev_permission() hook device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,03/14] device_cgroup: Remove explicit devcgroup_inode hooks device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,02/14] vfs: Remove explicit devcgroup_inode calls device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RESEND,RFC,v2,01/14] device_cgroup: Implement devcgroup hooks as lsm security hooks device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-25 Michael Weiß New
[RFC,v2,14/14] device_cgroup: Allow mknod in non-initial userns if guarded device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,v2,13/14] bpf: cgroup: Introduce helper cgroup_bpf_current_enabled() device_cgroup: guard mknod for non-initial user namespace - 1 - --- 2023-10-18 Michael Weiß New
[RFC,v2,12/14] bpf: Add flag BPF_DEVCG_ACC_MKNOD_UNS for device access device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,v2,11/14] vfs: Wire up security hooks for lsm-based device guard in userns device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,v2,10/14] lsm: Add security_sb_alloc_userns() hook device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,v2,09/14] lsm: Add security_inode_mknod_nscap() hook device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,v2,08/14] device_cgroup: Hide devcgroup functionality completely in lsm device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,v2,07/14] drm/amdkfd: Switch from devcgroup_check_permission to security hook device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,v2,06/14] block: Switch from devcgroup_check_permission to security hook device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,v2,05/14] device_cgroup: Implement dev_permission() hook device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,v2,04/14] lsm: Add security_dev_permission() hook device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,v2,03/14] device_cgroup: Remove explicit devcgroup_inode hooks device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,v2,02/14] vfs: Remove explicit devcgroup_inode calls device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,v2,01/14] device_cgroup: Implement devcgroup hooks as lsm security hooks device_cgroup: guard mknod for non-initial user namespace - - - --- 2023-10-18 Michael Weiß New
[RFC,4/4] fs: allow mknod in non-initial userns using cgroup device guard bpf: cgroup device guard for non-initial user namespace - - - --- 2023-08-14 Michael Weiß New
[RFC,3/4] device_cgroup: wrapper for bpf cgroup device guard bpf: cgroup device guard for non-initial user namespace - - - --- 2023-08-14 Michael Weiß New
[RFC,2/4] bpf: provide cgroup_device_guard in bpf_prog_info to user space bpf: cgroup device guard for non-initial user namespace - - - --- 2023-08-14 Michael Weiß New
[RFC,1/4] bpf: add cgroup device guard to flag a cgroup device prog bpf: cgroup device guard for non-initial user namespace - - - --- 2023-08-14 Michael Weiß New
dm verity: log audit events for dm-verity target dm verity: log audit events for dm-verity target 1 - - --- 2023-03-01 Michael Weiß New
[1/1] squashfs: enable idmapped mounts [1/1] squashfs: enable idmapped mounts - 2 - --- 2022-10-24 Michael Weiß New