diff options
author | Matthew Garrett | 2019-08-19 17:17:39 -0700 |
---|---|---|
committer | James Morris | 2019-08-19 21:54:15 -0700 |
commit | 000d388ed3bbed745f366ce71b2bb7c2ee70f449 (patch) | |
tree | 8df5d266713aa79f5009a515ec5db597a61aba30 /security/lockdown/Makefile | |
parent | 9e47d31d6a57b5babaca36d42b0d11b6db6019b7 (diff) |
security: Add a static lockdown policy LSM
While existing LSMs can be extended to handle lockdown policy,
distributions generally want to be able to apply a straightforward
static policy. This patch adds a simple LSM that can be configured to
reject either integrity or all lockdown queries, and can be configured
at runtime (through securityfs), boot time (via a kernel parameter) or
build time (via a kconfig option). Based on initial code by David
Howells.
Signed-off-by: Matthew Garrett <mjg59@google.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Cc: David Howells <dhowells@redhat.com>
Signed-off-by: James Morris <jmorris@namei.org>
Diffstat (limited to 'security/lockdown/Makefile')
-rw-r--r-- | security/lockdown/Makefile | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/security/lockdown/Makefile b/security/lockdown/Makefile new file mode 100644 index 000000000000..e3634b9017e7 --- /dev/null +++ b/security/lockdown/Makefile @@ -0,0 +1 @@ +obj-$(CONFIG_SECURITY_LOCKDOWN_LSM) += lockdown.o |