security subsystem · Supported
Maintainers
- M Paul Moore <paul@paul-moore.com>
- M James Morris <jmorris@namei.org>
- M "Serge E. Hallyn" <serge@hallyn.com>
Paths
- F
include/linux/lsm/ - F
include/linux/lsm_audit.h - F
include/linux/lsm_hook_defs.h - F
include/linux/lsm_hooks.h - F
include/linux/security.h - F
include/uapi/linux/lsm.h - F
security/ - F
tools/testing/selftests/lsm/ - F
rust/kernel/security.rs - X
security/selinux/
Last 30 days
Recent patches
Most-recent 30 patches in this subsystem on linux-modules (capped at 30), ordered by date desc.
-
COOLING11d
[PATCH v3 1/3] umh, treewide: Explicitly include linux/umh.h where needed
2026-09-11 · Petr Pavlu <petr.pavlu@suse.com> -
STALE68d
[PATCH v2 1/3] umh, treewide: Explicitly include linux/umh.h where needed
2026-07-21 · Petr Pavlu <petr.pavlu@suse.com> -
STALE85d
[PATCH 1/2] umh, treewide: Explicitly include linux/umh.h where needed
2026-07-08 · Petr Pavlu <petr.pavlu@suse.com> -
STALE115d
[PATCH 08/11] params: Convert generic kernel_param_ops .get helpers to seq_buf
2026-05-21 · Kees Cook <kees@kernel.org> -
STALE115d
[PATCH 09/11] treewide: Convert custom kernel_param_ops .get callbacks to seq_buf via cocci
2026-05-21 · Kees Cook <kees@kernel.org> -
STALE115d
[PATCH 04/11] treewide: Convert struct kernel_param_ops initializers to DEFINE_KERNEL_PARAM_OPS
2026-05-21 · Kees Cook <kees@kernel.org> -
COLD60d
[PATCH v5 12/14] module: Introduce hash-based integrity checking
2026-05-05 · Thomas Weißschuh <linux@weissschuh.net> -
COLD60d
REVIEWED: 7 (7M) [PATCH v5 02/14] lockdown: Make the relationship to MODULE_SIG a dependency
2026-05-05 · Thomas Weißschuh <linux@weissschuh.net> -
COLD60d
[PATCH v5 09/14] module: Move signature type check out of mod_check_sig()
2026-05-05 · Thomas Weißschuh <linux@weissschuh.net> -
STALE199d
[PATCH v2 2/2] tree-wide: rename do_exit() to task_exit()
2026-03-10 · Christian Brauner <brauner@kernel.org> -
STALE170d
[PATCH 20/61] apparmor: Prefer IS_ERR_OR_NULL over manual NULL check
2026-03-10 · Philipp Hahn <hidden> -
STALE191d
REVIEWED: 1 (1M) [PATCH v3 4/8] module: Give MODULE_SIG_STRING a more descriptive name
2026-03-05 · Thomas Weißschuh <hidden> -
STALE212d
REVIEWED: 1 (1M) [PATCH v2 4/8] module: Give MODULE_SIG_STRING a more descriptive name
2026-03-05 · Thomas Weißschuh <hidden> -
STALE213d
[PATCH 4/8] module: Give MODULE_SIG_STRING a more descriptive name
2026-03-02 · Thomas Weißschuh <hidden> -
STALE237d
REVIEWED: 5 (5M) [PATCH v16 3/7] pkcs7, x509: Rename ->digest to ->m
2026-02-02 · David Howells <dhowells@redhat.com> -
STALE242d
[PATCH v15 3/7] pkcs7, x509: Rename ->digest to ->m
2026-01-26 · David Howells <dhowells@redhat.com> -
STALE250d
[PATCH v14 3/5] pkcs7: Allow the signing algo to do whatever digestion it wants itself
2026-01-21 · David Howells <dhowells@redhat.com> -
STALE206d
[PATCH v4 15/17] module: Introduce hash-based integrity checking
2026-01-13 · Thomas Weißschuh <linux@weissschuh.net> -
STALE206d
[PATCH v4 14/17] lockdown: Make the relationship to MODULE_SIG a dependency
2026-01-13 · Thomas Weißschuh <linux@weissschuh.net> -
STALE206d
[PATCH v4 13/17] module: Report signature type to users
2026-01-13 · Thomas Weißschuh <linux@weissschuh.net> -
STALE206d
[PATCH v4 08/17] module: Deduplicate signature extraction
2026-01-13 · Thomas Weißschuh <linux@weissschuh.net> -
STALE206d
[PATCH v4 03/17] ima: efi: Drop unnecessary check for CONFIG_MODULE_SIG/CONFIG_KEXEC_SIG
2026-01-13 · Thomas Weißschuh <linux@weissschuh.net> -
STALE270d
[PATCH] KEYS: replace -EEXIST with -EBUSY
2025-12-20 · Daniel Gomez <da.gomez@kernel.org> -
STALE318d
[PATCH v4] ima: Access decompressed kernel module to verify appended signature
2025-11-19 · Coiby Xu <hidden> -
STALE318d
[PATCH v3] ima: Access decompressed kernel module to verify appended signature
2025-11-19 · Coiby Xu <hidden> -
STALE318d
[PATCH v2] lsm,ima: new LSM hook security_kernel_module_read_file to access decompressed kernel module
2025-10-31 · Coiby Xu <hidden> -
STALE369d
[PATCH RFC 006/104] KEYS: trusted: eat -ENOENT from the crypto API
2025-09-04 · Vegard Nossum <hidden> -
STALE481d
[PATCH RFC 1/1] module: Make use of platform keyring for module signature verify
2025-06-02 · Vitaly Kuznetsov <vkuznets@redhat.com> -
STALE313d
[PATCH v3 2/9] ima: efi: Drop unnecessary check for CONFIG_MODULE_SIG/CONFIG_KEXEC_SIG
2025-04-29 · Thomas Weißschuh <linux@weissschuh.net> -
STALE313d
[PATCH v3 9/9] module: Introduce hash-based integrity checking
2025-04-29 · Thomas Weißschuh <linux@weissschuh.net>
Quiet for 30+ days
Patches with no review trailers and no replies. Either the author is heads-down elsewhere or these slipped through. Oldest first.
-
STALE170d
[PATCH 20/61] apparmor: Prefer IS_ERR_OR_NULL over manual NULL check
2026-03-10 · Philipp Hahn <hidden> -
STALE68d
[PATCH v2 1/3] umh, treewide: Explicitly include linux/umh.h where needed
2026-07-21 · Petr Pavlu <petr.pavlu@suse.com>