[PATCH RFC 00/11] LSM: Stacking for major security modules

James Morris jmorris at namei.org
Thu Apr 6 22:24:47 UTC 2017


On Thu, 6 Apr 2017, Stephen Smalley wrote:

> Yes, but in the meantime, if you want to be able to test
> CONFIG_SECURITY_STACKING=y with modules in enforcing mode on
> distributions that enable a major security module, it seems like you
> need to provide some way of handling this compatibly.

Regardless of the config option, we can't break existing userspace. This 
is a long-standing Linux kernel development rule.

You'll need to implement new interfaces for any changes.


-- 
James Morris
<jmorris at namei.org>

--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html



More information about the Linux-security-module-archive mailing list