authorMatthew Garrett <matthewgarrett@google.com>2019-08-19 17:17:39 -0700
committerJames Morris <jmorris@namei.org>2019-08-19 21:54:15 -0700
commit000d388ed3bbed745f366ce71b2bb7c2ee70f449 (patch)
parentsecurity: Add a "locked down" LSM hook (diff)
security: Add a static lockdown policy LSM
While existing LSMs can be extended to handle lockdown policy, distributions generally want to be able to apply a straightforward static policy. This patch adds a simple LSM that can be configured to reject either integrity or all lockdown queries, and can be configured at runtime (through securityfs), boot time (via a kernel parameter) or build time (via a kconfig option). Based on initial code by David Howells. Signed-off-by: Matthew Garrett <mjg59@google.com> Reviewed-by: Kees Cook <keescook@chromium.org> Cc: David Howells <dhowells@redhat.com> Signed-off-by: James Morris <jmorris@namei.org>
