[PATCH v9 25/25] integrity: Remove LSM

Stefan Berger stefanb at linux.ibm.com
Mon Feb 12 19:50:22 UTC 2024



On 1/15/24 13:18, Roberto Sassu wrote:
> From: Roberto Sassu <roberto.sassu at huawei.com>
> 
> Since now IMA and EVM use their own integrity metadata, it is safe to
> remove the 'integrity' LSM, with its management of integrity metadata.
> 
> Keep the iint.c file only for loading IMA and EVM keys at boot, and for
> creating the integrity directory in securityfs (we need to keep it for
> retrocompatibility reasons).
> 
> Signed-off-by: Roberto Sassu <roberto.sassu at huawei.com>

Reviewed-by: Stefan Berger <stefanb at linux.ibm.com>



More information about the Linux-security-module-archive mailing list