mirror of
https://github.com/torvalds/linux.git
synced 2026-09-25 21:21:09 -04:00
While existing LSMs can be extended to handle lockdown policy, distributions generally want to be able to apply a straightforward static policy. This patch adds a simple LSM that can be configured to reject either integrity or all lockdown queries, and can be configured at runtime (through securityfs), boot time (via a kernel parameter) or build time (via a kconfig option). Based on initial code by David Howells. Signed-off-by: Matthew Garrett <[email protected]> Reviewed-by: Kees Cook <[email protected]> Cc: David Howells <[email protected]> Signed-off-by: James Morris <[email protected]>
2 lines
50 B
Makefile
2 lines
50 B
Makefile
obj-$(CONFIG_SECURITY_LOCKDOWN_LSM) += lockdown.o
|