| Commit message (Expand) | Author | Age | Files | Lines |
| * | MAC: mac_policy.h: Declare common MAC sysctl and jail parameters' nodes | Olivier Certner | 2025-01-16 | 1 | -2/+0 |
| * | sys: Remove $FreeBSD$: two-line .h pattern | Warner Losh | 2023-08-16 | 2 | -4/+0 |
| * | IfAPI: Add if_get/setmaclabel() and use it. | Justin Hibbits | 2023-01-31 | 1 | -1/+1 |
| * | security: clean up empty lines in .c and .h files | Mateusz Guzik | 2020-09-01 | 1 | -2/+1 |
| * | Mark more nodes as CTLFLAG_MPSAFE or CTLFLAG_NEEDGIANT (17 of many) | Pawel Biernacki | 2020-02-26 | 1 | -1/+2 |
| * | sys/security: minor spelling fixes. | Pedro F. Giffuni | 2016-05-06 | 2 | -2/+2 |
| * | Pull in r267961 and r267973 again. Fix for issues reported will follow. | Hans Petter Selasky | 2014-06-28 | 1 | -6/+3 |
| * | Revert r267961, r267973: | Glen Barber | 2014-06-27 | 1 | -3/+6 |
| * | Extend the meaning of the CTLFLAG_TUN flag to automatically check if | Hans Petter Selasky | 2014-06-27 | 1 | -6/+3 |
| * | Remove AppleTalk support. | Gleb Smirnoff | 2014-03-14 | 1 | -13/+0 |
| * | Implement read(2)/write(2) and neccessary lseek(2) for posix shmfd. | Konstantin Belousov | 2013-08-21 | 1 | -0/+38 |
| * | Check vplabel for NULL before dereferencing it. Fixes a panic | Christian Brueffer | 2012-05-03 | 1 | -0/+3 |
| * | Remove direct access to si_name. | Ed Schouten | 2012-02-10 | 1 | -9/+11 |
| * | Mark all SYSCTL_NODEs static that have no corresponding SYSCTL_DECLs. | Ed Schouten | 2011-11-07 | 1 | -1/+1 |
| * | Remove two dublicated assignments. | Christian Brueffer | 2011-10-08 | 1 | -3/+0 |
| * | Correct several issues in the integration of POSIX shared memory objects | Robert Watson | 2011-09-02 | 1 | -1/+206 |
| * | Update device-labeling logic for Biba, LOMAC, and MLS to recognize new-style | Robert Watson | 2010-03-02 | 1 | -0/+1 |
| * | Continue work to optimize performance of "options MAC" when no MAC policy | Robert Watson | 2009-06-03 | 1 | -9/+38 |
| * | Get rid of VSTAT and replace it with VSTAT_PERMS, which is somewhat | Edward Tomasz Napierala | 2009-03-29 | 1 | -2/+2 |
| * | Remove 'uio' argument from MAC Framework and MAC policy entry points for | Robert Watson | 2009-03-08 | 1 | -4/+2 |
| * | Rather than having MAC policies explicitly declare what object types | Robert Watson | 2009-01-10 | 1 | -22/+1 |
| * | Use MPC_OBJECT_IP6Q to indicate labeling of struct ip6q rather than | Robert Watson | 2009-01-10 | 1 | -0/+1 |
| * | Introduce accmode_t. This is required for NFSv4 ACLs - it will be neccessary | Edward Tomasz Napierala | 2008-10-28 | 1 | -3/+3 |
| * | Rename three MAC entry points from _proc_ to _cred_ to reflect the fact | Robert Watson | 2008-10-28 | 1 | -38/+38 |
| * | Implement MAC policy support for IPv6 fragment reassembly queues, | Robert Watson | 2008-10-26 | 1 | -1/+53 |
| * | Add a mac_inpcb_check_visible implementation to all MAC policies | Bjoern A. Zeeb | 2008-10-17 | 1 | -0/+19 |
| * | Introduce two related changes to the TrustedBSD MAC Framework: | Robert Watson | 2008-08-23 | 1 | -1/+21 |
| * | Minor style tweaks. | Robert Watson | 2008-08-02 | 1 | -9/+4 |
| * | Rework the lifetime management of the kernel implementation of POSIX | John Baldwin | 2008-06-27 | 1 | -6/+25 |
| * | Remove the posixsem_check_destroy() MAC check. It is semantically identical | John Baldwin | 2008-06-23 | 1 | -1/+0 |
| * | The TrustedBSD MAC Framework named struct ipq instances 'ipq', which is the | Robert Watson | 2008-06-13 | 1 | -10/+10 |
| * | Properly return the error from mls_subject_privileged() in the ifnet | Robert Watson | 2008-01-28 | 1 | -3/+1 |
| * | Resort TrustedBSD MAC Framework policy entry point implementations and | Robert Watson | 2007-10-29 | 1 | -897/+904 |
| * | Garbage collect mac_mbuf_create_multicast_encap TrustedBSD MAC Framework | Robert Watson | 2007-10-28 | 1 | -14/+0 |
| * | Continue to move from generic network entry points in the TrustedBSD MAC | Robert Watson | 2007-10-28 | 1 | -13/+26 |
| * | Move towards more explicit support for various network protocol stacks | Robert Watson | 2007-10-28 | 1 | -13/+49 |
| * | Rename 'mac_mbuf_create_from_firewall' to 'mac_netinet_firewall_send' as | Robert Watson | 2007-10-26 | 1 | -4/+4 |
| * | Normalize TCP syncache-related MAC Framework entry points to match most | Robert Watson | 2007-10-25 | 1 | -6/+6 |
| * | Rename mac_associate_nfsd_label() to mac_proc_associate_nfsd(), and move | Robert Watson | 2007-10-25 | 1 | -12/+12 |
| * | Consistently name functions for mac_<policy> as <policy>_whatever rather | Robert Watson | 2007-10-25 | 1 | -729/+720 |
| * | Merge first in a series of TrustedBSD MAC Framework KPI changes | Robert Watson | 2007-10-24 | 1 | -293/+298 |
| * | Canonicalize naming of local variables for struct ksem and associated | Robert Watson | 2007-10-21 | 1 | -9/+9 |
| * | Rename mac_check_vnode_delete() MAC Framework and MAC Policy entry | Robert Watson | 2007-09-10 | 1 | -25/+25 |
| * | When checking labels during a vnode link operation in MLS, use the file | Robert Watson | 2007-07-23 | 1 | -1/+1 |
| * | Rename mac*devfsdirent*() to mac*devfs*() to synchronize with SEDarwin, | Robert Watson | 2007-04-23 | 1 | -4/+5 |
| * | Apply variable name normalization to MAC policies: adopt global conventions | Robert Watson | 2007-04-23 | 1 | -216/+213 |
| * | In the MAC Framework implementation, file systems have two per-mountpoint | Robert Watson | 2007-04-22 | 1 | -12/+8 |
| * | Allow MAC policy modules to control access to audit configuration system | Robert Watson | 2007-04-21 | 1 | -0/+40 |
| * | Introduce accessor functions mac_label_get() and mac_label_set() to replace | Robert Watson | 2007-02-06 | 1 | -2/+2 |
| * | Continue 7-CURRENT MAC Framework rearrangement and cleanup: | Robert Watson | 2007-02-06 | 1 | -1/+0 |