[PATCH v2 0/3] Allow individual features to be locked down
Nikolay Borisov
nik.borisov at suse.com
Mon Jul 28 11:15:14 UTC 2025
This simple change allows usecases where someone might want to lock only specific
feature at a finer granularity than integrity/confidentiality levels allows.
The first likely user of this is the CoCo subsystem where certain features will be
disabled.
Changes since v1:
* Added Patch 3 to incoroporate Serge's hardening suggestion
Nikolay Borisov (3):
lockdown: Switch implementation to using bitmap
lockdown/kunit: Introduce kunit tests
lockdown: Use snprintf in lockdown_read
security/lockdown/Kconfig | 5 +++
security/lockdown/Makefile | 1 +
security/lockdown/lockdown.c | 36 +++++++++++++++------
security/lockdown/lockdown_test.c | 54 +++++++++++++++++++++++++++++++
4 files changed, 86 insertions(+), 10 deletions(-)
create mode 100644 security/lockdown/lockdown_test.c
--
2.34.1
More information about the Linux-security-module-archive
mailing list