android_kernel_motorola_sm6375/security
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Stephen Smalley 208e1a610e
UPSTREAM: selinux: clean up selinux_enabled/disabled/enforcing_boot
Rename selinux_enabled to selinux_enabled_boot to make it clear that
it only reflects whether SELinux was enabled at boot.  Replace the
references to it in the MAC_STATUS audit log in sel_write_enforce()
with hardcoded "1" values because this code is only reachable if SELinux
is enabled and does not change its value, and update the corresponding
MAC_STATUS audit log in sel_write_disable().  Stop clearing
selinux_enabled in selinux_disable() since it is not used outside of
initialization code that runs before selinux_disable() can be reached.
Mark both selinux_enabled_boot and selinux_enforcing_boot as __initdata
since they are only used in initialization code.

Wrap the disabled field in the struct selinux_state with
CONFIG_SECURITY_SELINUX_DISABLE since it is only used for
runtime disable.

Change-Id: I4e234d2b5fc70083d12ab9c47591d838ddb61d58
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: Paul Moore <paul@paul-moore.com>
2026-01-14 18:13:14 -08:00
..
apparmor BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
bpf UPSTREAM: bpf: Implement bpf_local_storage for inodes 2026-01-14 18:12:21 -08:00
integrity This is the 5.4.291 stable release 2025-03-13 14:53:52 +00:00
keys KEYS: trusted_tpm1: Compare HMAC values in constant time 2025-10-29 14:00:01 +01:00
loadpin
lockdown
safesetid
selinux UPSTREAM: selinux: clean up selinux_enabled/disabled/enforcing_boot 2026-01-14 18:13:14 -08:00
smack This is the 5.4.294 stable release 2025-06-05 07:11:21 +00:00
tomoyo tomoyo: don't emit warning in tomoyo_write_control() 2025-03-13 12:43:03 +01:00
yama BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
commoncap.c
device_cgroup.c
inode.c securityfs: don't pin dentries twice, once is enough... 2025-08-28 16:21:24 +02:00
Kconfig UPSTREAM: bpf: lsm: Initialize the BPF LSM hooks 2026-01-14 18:12:20 -08:00
Kconfig.hardening ANDROID: kernelci build-break for 64-bit riscv clang builds (5.4 only) 2025-01-31 16:42:47 -08:00
lsm_audit.c
Makefile UPSTREAM: bpf: lsm: Initialize the BPF LSM hooks 2026-01-14 18:12:20 -08:00
min_addr.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
security.c BACKPORT: security: Refactor declaration of LSM hooks 2025-12-23 13:36:10 -08:00