Re: [PATCH V34 03/29] security: Add a static lockdown policy LSM

2019-06-22 Thread Kees Cook
On Fri, Jun 21, 2019 at 05:03:32PM -0700, Matthew Garrett wrote: > While existing LSMs can be extended to handle lockdown policy, > distributions generally want to be able to apply a straightforward > static policy. This patch adds a simple LSM that can be configured to > reject either integrity

[PATCH V34 03/29] security: Add a static lockdown policy LSM

2019-06-21 Thread Matthew Garrett
While existing LSMs can be extended to handle lockdown policy, distributions generally want to be able to apply a straightforward static policy. This patch adds a simple LSM that can be configured to reject either integrity or all lockdown queries, and can be configured at runtime (through