LSM: Separate idea of "major" LSM from "exclusive" LSM
In order to both support old "security=" Legacy Major LSM selection, and handling real exclusivity, this creates LSM_FLAG_EXCLUSIVE and updates the selection logic to handle them. Signed-off-by:Kees Cook <keescook@chromium.org> Reviewed-by:
Casey Schaufler <casey@schaufler-ca.com>
Showing
- include/linux/lsm_hooks.h 1 addition, 0 deletionsinclude/linux/lsm_hooks.h
- security/apparmor/lsm.c 1 addition, 1 deletionsecurity/apparmor/lsm.c
- security/security.c 12 additions, 0 deletionssecurity/security.c
- security/selinux/hooks.c 1 addition, 1 deletionsecurity/selinux/hooks.c
- security/smack/smack_lsm.c 1 addition, 1 deletionsecurity/smack/smack_lsm.c
- security/tomoyo/tomoyo.c 1 addition, 1 deletionsecurity/tomoyo/tomoyo.c
Loading
Please register or sign in to comment